


Get file less command execution for lateral movement.

.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

Stop Windows Defender programmatically

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

SSHPry v2 - Spy & Control os SSH Connected client's TTY

A User Impersonation tool - via Token or Shellcode injection

.NET Project for performing Authenticated Remote Execution


Some scripts to abuse kerberos using Powershell

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Multiplayer pivoting solution

Process injection alternative

Network Pivoting Toolkit

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

PowerShell-based post-exploitation framework for lateral movement in Active Directory environments. Executes in-memory with named-pipe command…