
impersonate-proxy
A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Python implementation of OpenPsPipeJack

CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification…


KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Manipulating and Abusing Windows Access Tokens.


Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

RunasCs - Csharp and open version of windows builtin runas.exe

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Rusty Impersonate

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Ask a TGS on behalf of another user without password

Lateral Movement Using DCOM and DLL Hijacking

Some scripts to abuse kerberos using Powershell