
NegoExRelay
Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

C# tool leveraging WinDivert driver to intercept and redirect Windows port 445 traffic for NTLM relay attacks via Cobalt Strike, enabling lateral…

Kerberos relaying and unconstrained delegation abuse toolkit

C# utility that uses WMI to run "cmd.exe /c netstat -n", save the output to a file, then use SMB to read and delete the file remotely

CVE-2020-13941: Abusing UNC Paths in Windows Environments in Apache Solr

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

conduct lateral movement attack by leveraging unfiltered services display name to smuggle binaries as chunks into the target machine

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

StandIn is a small .NET35/45 AD post-exploitation toolkit

Code execution/injection technique using DLL PEB module structure manipulation

LOKI (Limited Obstructive Keyboard Impersonator) is a RDP File Transfer Tool Using Keypresses