
acltoolkit
Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

CVE 2020-1472 Script de validación

Tools and Techniques for Red Team / Penetration Testing

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Fileless lateral movement tool using WMI Event Filters and MSBuild execution to deploy shellcode on remote Windows systems via LogFileEventConsumer.

psexecsvc - a python implementation of PSExec's native service implementation

A windows token impersonation tool

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

Windows Session Hijacking via COM

Infect Shared Files In Memory for Lateral Movement

C# implementation of SMBExec for remote command execution on Windows targets using NTLM password hashes, enabling lateral movement and pass-the-hash…

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

Automated 802.1x Bypass