
CVE-2026-24294
Local privilege escalation PoC for CVE-2026-24294, abusing SMB arbitrary port and NTLM reflection to achieve SYSTEM on Windows Server 2025.

Local privilege escalation PoC for CVE-2026-24294, abusing SMB arbitrary port and NTLM reflection to achieve SYSTEM on Windows Server 2025.

Dump Kerberos tickets from the KCM database of SSSD

A script to automate keystrokes through a graphical desktop program.

Impersonate Logged In Accounts & Execute Commands

CVE-2021-42287/CVE-2021-42278 exploits in powershell

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others

Impacket-based exploit for PrintNightmare (CVE-2021-1675/CVE-2021-34527) enabling remote DLL execution via SMB, with scanning and mitigation guidance.

Bash-based post-exploitation tool for semi-automated network pivoting, enabling lateral movement through compromised systems during penetration tests.

Common library for tools implementing GPO attack vectors

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…


Exploit for CVE-2021-36934

Impacket-based exploit for CVE-2021-1675 (PrintNightmare) enabling remote or local DLL execution on Windows Domain Controllers with SMB payload…

MakeMeEnterpriseAdmin

A "Exposed Dangerous Method or Function" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure Cloud Print Management", Version…