
ExecuteAssembly
Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Mythic C2 agent targeting Linux and Windows hosts written in Rust

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework

Partial python implementation of SharpGPOAbuse

StandIn is a small .NET35/45 AD post-exploitation toolkit

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

Get file less command execution for lateral movement.

.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

A reverse shell with terminal support, data tunneling, and advanced pivoting capabilities.

Network Pivoting Toolkit

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

A tool for security professionals to access and interact with remote Microsoft Windows based systems.

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).