
DCOMUploadExec
DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

PowerShell-based post-exploitation framework for lateral movement in Active Directory environments. Executes in-memory with named-pipe command…

Fileless lateral movement tool using WMI Event Subscriptions to execute .NET assemblies in memory, with shellcode injection via named pipes for…

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

A little tool to play with the Seclogon service

Pass the Hash to a named pipe for token Impersonation

Collection of tools that reflect the network dimension into Bloodhound's data

Ask a TGS on behalf of another user without password

Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality

Lateral Movement Using DCOM and DLL Hijacking

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

Powershell script for enumerating vulnerable DCOM Applications

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

Windows Session Hijacking via COM

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Pass the Hash to a named pipe for token Impersonation

CVE-2019-1040 with Exchange