
SharpSecDump
.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

Network Pivoting Toolkit

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

C# tool for lateral movement through WSUS by creating, approving, and deploying malicious updates to target Windows clients in Active Directory…

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

Miscellaneous Tools

Hijack Putty sessions in order to sniff conversation and inject Linux commands.

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

A collection of proof-of-concept source code and scripts for executing remote commands over WinRM using the WSMan.Automation COM object

.NET Project for performing Authenticated Remote Execution

Multiplayer pivoting solution

Some scripts to abuse kerberos using Powershell


A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

Process injection alternative