
Internal-Monologue
Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

The Shadow Attack Framework

A Bypass Anti-virus Software Lateral Movement Command Execution Tool

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

RedSnarf is a pen-testing / red-teaming tool for Windows environments

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

PowerShell MachineAccountQuota and DNS exploit tools

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Dominate Active Directory with PowerShell.

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

SharpSploit is a .NET post-exploitation library written in C#

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Open source C2 server created for stealth red team operations

A framework for constructing self-spreading binaries