



BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

Open Source C&C Specification

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Weaponizing DCOM for NTLM Authentication Coercions

Weaponizing DCOM for NTLM Authentication Coercions

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it


Various tips & tricks

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root


psexecsvc - a python implementation of PSExec's native service implementation

This cheatsheet maps common impacket workflows to their modern alternatives

Abusing Azure services over C2

A BloodHound collector for Microsoft Configuration Manager

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…