


PowerSploit - A PowerShell Post-Exploitation Framework

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

Microsoft signed ActiveDirectory PowerShell module

New version of RottenPotato as a C++ DLL and standalone C++ binary - no need for meterpreter or other tools.

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory

Lateral Movement Using DCOM and DLL Hijacking

A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.

Code execution/injection technique using DLL PEB module structure manipulation

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.