
lsarelayx
System-wide NTLM relay tool that hooks Windows authentication APIs to relay incoming NTLM connections, downgrade Kerberos, and dump NetNTLM hashes…

System-wide NTLM relay tool that hooks Windows authentication APIs to relay incoming NTLM connections, downgrade Kerberos, and dump NetNTLM hashes…

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Electron-based Android RAT with server-side control panel and client-side backdoor APK generator for remote device administration and penetration…

DCOM-based privilege escalation tool for Windows Server 2012-2022 and Windows 8-11, elevating users with ImpersonatePrivilege to NT AUTHORITY\SYSTEM…

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis

PowerShell toolkit for AD CS auditing based on the PSPKI toolkit.

PowerShell-based RAT using WMI for remote command execution, lateral movement, and C2 communication. Enables file operations, process management,…

Open source pre-operation C2 server based on python and powershell

Kerberos Resource-Based Constrained Delegation Attack from Outside using Impacket

Python framework for generating polymorphic Windows executables with multi-layer RC4 encryption, junkcode injection, and binary metadata spoofing to…

Cloudflare Turnstile 绕过工具 | Cloudflare Bypass Tool based on SeleniumBase UC Mode | 支持 Mac/Windows/Linux

Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CVE-2020-17087…

HTTP request smuggling vulnerability scanner that detects CL.TE and TE.CL desync attacks using multiple payload types, with configurable verification…

A simple python tool based on Impacket that tests servers for various known NTLM vulnerabilities

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Lord Of Active Directory - automatic vulnerable active directory on AWS