
PyPsPipeJack
Python implementation of OpenPsPipeJack

Python implementation of OpenPsPipeJack

CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification…

Manipulating and Abusing Windows Access Tokens.

A basic emulation of an "RPC Backdoor"

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

RunasCs - Csharp and open version of windows builtin runas.exe

Infect Shared Files In Memory for Lateral Movement

A windows token impersonation tool

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

Rusty Impersonate

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Ask a TGS on behalf of another user without password

Lateral Movement Using DCOM and DLL Hijacking

Some scripts to abuse kerberos using Powershell


DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely