
SharpADWS
Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

Trying to tame the three-headed dog.

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

A framework for constructing self-spreading binaries

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

TCP Port Redirection Utility

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

Fully modular persistence framework

Local & remote Windows DLL Proxying

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

Proof-of-concept for CVE-2024-37726: local privilege escalation in MSI Center via arbitrary file overwrite using symlink/junction attacks and OpLock…

A Windows Remote Administration Tool in Visual Basic with UNC paths

exp for CVE-2019-0887

Automated Persistence and Lateral Movement using GCP Patch Management

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

MakeMeEnterpriseAdmin