
HiveJack
This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

Dump Kerberos tickets from the KCM database of SSSD

From deobfuscating code.js to root, CVE-2023-0386

Malicious shortcut generator for collecting NTLM hashes from insecure file shares.

Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-software in…

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine…

Various tips & tricks

Reverse Tunneling made easy for pentesters, by pentesters https://sysdream.com/

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

RedSnarf is a pen-testing / red-teaming tool for Windows environments

Open source C2 server created for stealth red team operations


Collection of PowerShell functions a Red Teamer may use in an engagement

psexecsvc - a python implementation of PSExec's native service implementation