
GraphSpy
Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

This is the tool to dump the LSASS process on modern Windows 11

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

Windows privilege escalation discovery tool that parses Process Monitor boot logs to identify DLL hijacking, weak ACLs, and other elevation paths,…

Shell Simulation over Net-SNMP with extend functionality

PowerSploit - A PowerShell Post-Exploitation Framework

Kernel-mode process killer exploiting CVE-2026-0828 (BYOVD) to terminate protected processes via a vulnerable signed driver, bypassing PPL and…

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

Exploits a KSLD anti-rootkit driver vulnerability (IOCTL 0x222044) to bypass PPL protection and access sensitive process memory, enabling local…

Penetration testing utility and antivirus assessment tool.

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

Leaked Windows processes handles identification tool

Credentials gathering tool automating remote procdump and parse of lsass process.

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

File upload vulnerability scanner and exploitation tool.

Process Herpaderping proof of concept, tool, and technical deep dive. Process Herpaderping bypasses security products by obscuring the intentions of…

The swiss army knife of LSASS dumping