
DCOMIllusionist
DCOM in memory and fileless lateral movement techniques through .Net deserilization

DCOM in memory and fileless lateral movement techniques through .Net deserilization

CVE-2019-1040 with Exchange

Code execution/injection technique using DLL PEB module structure manipulation

Fully modular persistence framework

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

Rapid psexec-style attack tool using Samba for remote command execution, credential dumping, and lateral movement across Windows networks with hash…

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

Abusing Azure services over C2

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

Check for valid credentials across a network over SMB

A collection of tools for dealing with TrickBot

Weaponizing DCOM for NTLM Authentication Coercions

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

C# port of WMImplant which uses either CIM or WMI to query remote systems

A Post exploitation tool written in C# uses either CIM or WMI to query remote systems.

Open Source C&C Specification

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…