
oxide_hive
Exploit for CVE-2021-36934

Exploit for CVE-2021-36934

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine…

psexecsvc - a python implementation of PSExec's native service implementation

Bash-based post-exploitation tool for semi-automated network pivoting, enabling lateral movement through compromised systems during penetration tests.

Incriminator is an OpenSource Project with educational purposes that allows you to incriminate other devices during a cybercrime.

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Freedom Fighting Mode: open source hacking harness

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

SMBeagle - Fileshare auditing tool.

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY,…

Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.

Scripts to test and exploit the Zerologon vulnerability (CVE-2020-1472) in Active Directory, enabling password reset and hash dumping of domain…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

This C# tool sprays for admin access over the entire domain

If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on…


Powershell script for enumerating vulnerable DCOM Applications