
PrintSpoofer-ReflectiveDLL
The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.


Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…

Code execution/injection technique using DLL PEB module structure manipulation

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

Local & remote Windows DLL Proxying

A C2 post-exploitation framework

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

DLL Planting in the Slack 4.33.73 - CVE-2023-38820

Lateral Movement Using DCOM and DLL Hijacking


Feature-rich Post Exploitation Framework with Network Pivoting capabilities.

PowerSploit - A PowerShell Post-Exploitation Framework

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.


A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.