
MalSCCM
Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

Manipulating and Abusing Windows Access Tokens.

An automated SMB relay exploitation script.

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.

Infect Shared Files In Memory for Lateral Movement

PrintNightmare (CVE-2021-34527) PoC Exploit

A basic emulation of an "RPC Backdoor"

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

C# tool leveraging WinDivert driver to intercept and redirect Windows port 445 traffic for NTLM relay attacks via Cobalt Strike, enabling lateral…

Local & remote Windows DLL Proxying

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

C# implementation of SMBExec for remote command execution on Windows targets using NTLM password hashes, enabling lateral movement and pass-the-hash…

SSH spreading made easy for red teams in a hurry

Local SYSTEM auth trigger for relaying

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass