
RPC-Backdoor
A basic emulation of an "RPC Backdoor"

A basic emulation of an "RPC Backdoor"

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

Local & remote Windows DLL Proxying

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…


The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

Local SYSTEM auth trigger for relaying

A Powershell implementation of PrivExchange designed to run under the current user's context

PrintNightmare (CVE-2021-34527) PoC Exploit

Rusty Impersonate

Python tool to automatically perform SPN-less RBCD attacks.

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

SSH spreading made easy for red teams in a hurry

A SOCKS proxy for Citrix.

Exploitation of CVE-2025-29969

A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.