
RedTeam-Tools
Tools and Techniques for Red Team / Penetration Testing

Tools and Techniques for Red Team / Penetration Testing

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

Lateral Movement Using DCOM and DLL Hijacking

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Local & remote Windows DLL Proxying

Write-up for another forgotten Windows vulnerability (0day): Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape,…

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

C&C Botnet written in Python with fabric

Ping Exfiltration Command and Control (PiX-C2)

CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5

A fully featured Windows backdoor that uses email as a C&C server

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

POC Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An…

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…