
DCOMUploadExec
DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

There are many cheat sheets out there, but this is mine.

PrintNightmare (CVE-2021-34527) PoC Exploit


Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine…

Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

Mythic C2 agent targeting Linux and Windows hosts written in Rust

A Tool to use PowerShell Remoting / WinRM to execute PowerShell commands on remote hosts through WinRM double hop technique.

Multithreaded C# .NET assembly for enumerating local administrative privileges across Windows hosts via SMB, WMI, and WinRM, with BloodHound…