
Get-NetNTLM
Powershell module to get the NetNTLMv2 hash of the current user

Powershell module to get the NetNTLMv2 hash of the current user

Offset Independent Credential Extraction Tool

Brute Ratel C4 BOF that exploits a registry symlink race condition in Windows Accessibility ATConfig to escalate privileges to SYSTEM by writing…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

Modern tactical exploitation toolkit.

A C# tool to output crackable DPAPI hashes from user MasterKeys

Windows绕过EDR实现DumpHash

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

cve-2020-1472 复现利用及其exp



A simple implementation/code smash of a bunch of other repos

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

Exploit for CVE-2014-4210 targeting WebLogic deserialization, with post-exploitation features including ransomware deployment, C2 integration, and…

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

cve-2020-1472_Tool collection