
Atlas
Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Generates malicious LNK files to coerce Net-NTLMv2 hashes via Windows Shell UNC handling, with custom SMB listener and relay integration for…

CVE-2021-42287/CVE-2021-42278 exploits in powershell

Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

Local privilege escalation PoC for CVE-2026-24294, abusing SMB arbitrary port and NTLM reflection to achieve SYSTEM on Windows Server 2025.

Kerberos relaying and unconstrained delegation abuse toolkit

Detection-aware BloodHound attack-path scoring - the quietest route to your objective, calibrated across five detection tiers…

Python implementation of OpenPsPipeJack

CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification…

Manipulating and Abusing Windows Access Tokens.

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

A basic emulation of an "RPC Backdoor"

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

RunasCs - Csharp and open version of windows builtin runas.exe

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Infect Shared Files In Memory for Lateral Movement

A windows token impersonation tool