
Invoke-TheHash
PowerShell Pass The Hash Utils

PowerShell Pass The Hash Utils

Kerberos relaying and unconstrained delegation abuse toolkit

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

The Shadow Attack Framework

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

RunasCs - Csharp and open version of windows builtin runas.exe


Fileless lateral movement tool using WMI Event Filters and MSBuild execution to deploy shellcode on remote Windows systems via LogFileEventConsumer.

Stop Windows Defender programmatically

Get file less command execution for lateral movement.

.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

Network Pivoting Toolkit

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.