
thanatos
Mythic C2 agent targeting Linux and Windows hosts written in Rust

Mythic C2 agent targeting Linux and Windows hosts written in Rust

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

conduct lateral movement attack by leveraging unfiltered services display name to smuggle binaries as chunks into the target machine

Retrieve and display information about active user sessions on remote computers. No admin privileges required.

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

Fully modular persistence framework

A C# Command & Control framework

A script to automate keystrokes through a graphical desktop program.

C# port of WMImplant which uses either CIM or WMI to query remote systems

My experiments in weaponizing Nim (https://nim-lang.org/)

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

Curated wordlists for brute-forcing SSH private key filenames, aiding penetration testers in locating keys via LFI or enumeration during lateral…

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…