
Hwacha
Deploy payloads to *Nix systems en masse

Deploy payloads to *Nix systems en masse

Proof-of-concept exploit for CVE-2024-57394: low-privilege file restoration to System32 enabling DLL hijacking and local privilege escalation to…

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

C# Reflective loader for unmanaged binaries.

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

Tools and Techniques for Red Team / Penetration Testing

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

Lateral Movement Using DCOM and DLL Hijacking

Local & remote Windows DLL Proxying

CVE-2021-42287/CVE-2021-42278 exploits in powershell

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Proof-of-concept exploit for Windows local privilege escalation (CVE-2023-21746) abusing NTLM local authentication to gain SYSTEM privileges via SMB…

Proof-of-concept exploit demonstrating CVE-2020-25265 and CVE-2020-25266, using a crafted MP3 file to achieve arbitrary code execution via…

Exploit for CVE-2024-32002, a Git RCE vulnerability that uses recursive submodule cloning and symlinks to execute arbitrary commands on Windows and…