
evilrdp
RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

Powershell script for enumerating vulnerable DCOM Applications

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

Windows Session Hijacking via COM

Pass the Hash to a named pipe for token Impersonation

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

Manipulating and Abusing Windows Access Tokens.

An automated SMB relay exploitation script.

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.

Infect Shared Files In Memory for Lateral Movement

A basic emulation of an "RPC Backdoor"

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Local & remote Windows DLL Proxying

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…