
mimikatz
A little tool to play with Windows security

A little tool to play with Windows security

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Trying to tame the three-headed dog.

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Remote operations commands implemented using Beacon Object Files

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

Script to steal passwords from ssh.

Comprehensive self-paced manual on Windows identity, Kerberos, and PKI internals, covering credential dumping, ticket forgery, domain persistence,…

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

Linux persistence toolkit with 11 modules for SSH key backdoors, cronjobs, systemd services, LKM rootkits, and LD_PRELOAD privilege escalation.…

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crystal, Python and Rust

The SSH Multiplex Backdoor Tool

A WiFi Pineapple infecting worm.

CVE-2023-23192