
MoveKit
Cobalt Strike kit for Lateral Movement

Cobalt Strike kit for Lateral Movement

Remote Administration Tool for Windows

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

OSWE, OSEP, OSED, OSEE

SharpSploit is a .NET post-exploitation library written in C#

PowerShell Runspace Post Exploitation Toolkit

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

Hide your Powershell script in plain sight. Bypass all Powershell security features

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

C# implementation of harmj0y's PowerView

A C# Command & Control framework

Cobalt Strike BOF for in-process .NET assembly execution with AMSI/ETW bypass, custom AppDomain, and named pipe/mailslot output redirection.

.NET 4.0 CLR Project to retrieve Chromium data, such as cookies, history and saved logins.

.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

.NET Project for Attacking vCenter

.NET 2.0 CLR project to retrieve saved browser credentials from Google Chrome, Mozilla Firefox and Microsoft Internet Explorer/Edge.