
getSPNless
Python tool to automatically perform SPN-less RBCD attacks.

Python tool to automatically perform SPN-less RBCD attacks.

A Tool to use PowerShell Remoting / WinRM to execute PowerShell commands on remote hosts through WinRM double hop technique.

Pass the Hash to a named pipe for token Impersonation

Deploy payloads to *Nix systems en masse

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

Modified version of the passing-the-hash tool collection made to work straight out of the box

Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

Manipulating and Abusing Windows Access Tokens.

C# tool leveraging WinDivert driver to intercept and redirect Windows port 445 traffic for NTLM relay attacks via Cobalt Strike, enabling lateral…

Firecat is a penetration testing tool that allows you to punch reverse TCP tunnels out of a compromised network.

Python script that patches the termsrv.dll file on Windows to enable multiple concurrent RDP sessions, supporting Windows 10 versions 1703 through…

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

Fileless lateral movement tool using WMI Event Subscriptions to execute .NET assemblies in memory, with shellcode injection via named pipes for…

A SOCKS proxy for Citrix.

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

Fileless lateral movement tool using WMI Event Filters and MSBuild execution to deploy shellcode on remote Windows systems via LogFileEventConsumer.