
RedGhost
Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Trying to tame the three-headed dog.

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…


VMware Aria Operations for Logs CVE-2023-34051

Manipulating and Abusing Windows Access Tokens.

Check for valid credentials across a network over SMB

Dominate Active Directory with PowerShell.

Windows Session Hijacking via COM

Exploit for CVE-2020-1472 (ZeroLogon) that resets the domain controller account password and enables DCSync for full domain compromise.

.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

Simple POC library to execute arbitrary calls proxying them via NdrServerCall2 or similar

Post-exploitation credential harvesting toolkit that injects into password managers and Windows utilities to capture credentials via DLL proxying,…

Automated 802.1x Bypass

Detection-aware BloodHound attack-path scoring - the quietest route to your objective, calibrated across five detection tiers…

Python library and client for token manipulations and impersonations for privilege escalation on Windows