
DCOMUploadExec
DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Lateral Movement Using DCOM and DLL Hijacking

CVE-2019-1040 with Exchange

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

Rusty Impersonate

Module-based AWS exploitation framework for red team testing and blue team analysis. Emulates attack patterns in the AWS control plane with unique UA…

Exploitation of CVE-2025-29969

mssql 终端连接工具|命令执行

CVE-2021-42287/CVE-2021-42278 exploits in powershell

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others

Impacket-based exploit for PrintNightmare (CVE-2021-1675/CVE-2021-34527) enabling remote DLL execution via SMB, with scanning and mitigation guidance.

Common library for tools implementing GPO attack vectors


Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…