
SessionHop
Windows Session Hijacking via COM

Windows Session Hijacking via COM

Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

Manipulating and Abusing Windows Access Tokens.

Infect Shared Files In Memory for Lateral Movement

A SOCKS proxy for Citrix.

Python implementation of OpenPsPipeJack

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

Python script that patches the termsrv.dll file on Windows to enable multiple concurrent RDP sessions, supporting Windows 10 versions 1703 through…

Generates malicious LNK files to coerce Net-NTLMv2 hashes via Windows Shell UNC handling, with custom SMB listener and relay integration for…

Tools and Techniques for Red Team / Penetration Testing

Remote Desktop Protocol .NET Console Application for Authenticated Command Execution

AdaptixC2 is a highly modular advanced redteam toolkit

PowerShell Pass The Hash Utils

Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.

The Shadow Attack Framework

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

Remote operations commands implemented using Beacon Object Files

RunasCs - Csharp and open version of windows builtin runas.exe