
PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework

PowerSploit - A PowerShell Post-Exploitation Framework

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.


The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

A C2 post-exploitation framework

DLL Planting in the Slack 4.33.73 - CVE-2023-38820

Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…


SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.


Lateral Movement Using DCOM and DLL Hijacking

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.

Local & remote Windows DLL Proxying

Feature-rich Post Exploitation Framework with Network Pivoting capabilities.

A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Code execution/injection technique using DLL PEB module structure manipulation

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.