
PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework

PowerSploit - A PowerShell Post-Exploitation Framework

Credentials gathering tool automating remote procdump and parse of lsass process.

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

Proof-of-concept for CVE-2025-47962 demonstrating local privilege escalation via DLL hijacking in Windows IpOverUsbSvc service due to insecure…

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using…

Windows process injection methods

Process injection alternative

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.

Red Teaming & Pentesting checklists for various engagements

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

My experiments in weaponizing Nim (https://nim-lang.org/)

Proof-of-concept exploit for CVE-2021-21300, demonstrating remote code execution via malicious git repository cloning with symlink and filter abuse…

Docker CVE-2022-37708