
BEAR-C2
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Trying to tame the three-headed dog.

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…



Manipulating and Abusing Windows Access Tokens.

Check for valid credentials across a network over SMB

Windows Session Hijacking via COM

Exploit for CVE-2020-1472 (ZeroLogon) that resets the domain controller account password and enables DCSync for full domain compromise.

.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

Steam Client Service Local Privilege Escalation Vulnerability

Post-exploitation credential harvesting toolkit that injects into password managers and Windows utilities to capture credentials via DLL proxying,…

Automated 802.1x Bypass

Python library and client for token manipulations and impersonations for privilege escalation on Windows