
ZerologonWithImpacket-CVE2020-1472
A practical proof-of-concept for CVE-2020-1472 (Zerologon) using the Impacket library to exploit Netlogon vulnerability and perform unauthorized…

A practical proof-of-concept for CVE-2020-1472 (Zerologon) using the Impacket library to exploit Netlogon vulnerability and perform unauthorized…

Modified version of the passing-the-hash tool collection made to work straight out of the box

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

SharpSploit is a .NET post-exploitation library written in C#

Common library for tools implementing GPO attack vectors

A collection of proof-of-concept source code and scripts for executing remote commands over WinRM using the WSMan.Automation COM object

Collection of beacon BOF written to learn windows and cobaltstrike

Collects and analyzes AD and Azure AD authentication logs to detect lateral movement attacks using graph-based anomaly detection, visualizing…

More examples using the Impacket library designed for learning purposes.

Local SYSTEM auth trigger for relaying

Collection of tools that reflect the network dimension into Bloodhound's data

List of Awesome CobaltStrike Resources

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

Rust-based proof-of-concept that generates Windows Library (.library-ms) files with configurable network paths to demonstrate CVE-2025-24071 NTLM…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

Windows RPC firewall that audits, detects, and blocks malicious remote procedure calls to prevent lateral movement, reconnaissance, and exploitation…

Docker CVE-2022-37708