
printnightmare
Proof-of-concept implementation of CVE-2021-34527 (PrintNightmare) for exploiting Windows Print Spooler remote code execution and privilege…

Proof-of-concept implementation of CVE-2021-34527 (PrintNightmare) for exploiting Windows Print Spooler remote code execution and privilege…

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

Windows Privilege Escalation from User to Domain Admin.

Tools for Kerberos PKINIT and relaying to AD CS

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

Hijack Putty sessions in order to sniff conversation and inject Linux commands.

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

A Powershell implementation of PrivExchange designed to run under the current user's context

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

Proof of conept to exploit vulnerable proxycommand configurations on ssh clients (CVE-2023-51385)