
SharpGPOAbuse
SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

DejaVU - Open Source Deception Framework

A basic emulation of an "RPC Backdoor"

Multithreaded C# .NET assembly for enumerating local administrative privileges across Windows hosts via SMB, WMI, and WinRM, with BloodHound…

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

Dump Kerberos tickets from the KCM database of SSSD

Malicious shortcut generator for collecting NTLM hashes from insecure file shares.

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation


SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Common library for tools implementing GPO attack vectors