
Girsh
Automatically spawn a reverse shell fully interactive for Linux or Windows victim

Automatically spawn a reverse shell fully interactive for Linux or Windows victim

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-software in…

LSTAR - CobaltStrike Translated to EN

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

Ask a TGS on behalf of another user without password

Python codes of my blog.

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

Get file less command execution for lateral movement.

A Windows Remote Administration Tool in Visual Basic with UNC paths

cve-2025-23266-migration-bypass

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

Different methods to get current username without using whoami