
WMEye
Fileless lateral movement tool using WMI Event Filters and MSBuild execution to deploy shellcode on remote Windows systems via LogFileEventConsumer.

Fileless lateral movement tool using WMI Event Filters and MSBuild execution to deploy shellcode on remote Windows systems via LogFileEventConsumer.

A windows token impersonation tool

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

Pass the Hash to a named pipe for token Impersonation

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Powershell script for enumerating vulnerable DCOM Applications

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

Windows Session Hijacking via COM

Pass the Hash to a named pipe for token Impersonation

Check for valid credentials across a network over SMB

Manipulating and Abusing Windows Access Tokens.

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

Firecat is a penetration testing tool that allows you to punch reverse TCP tunnels out of a compromised network.

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

Leverage WindowsApp createdump tool to obtain an lsass dump

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.