
MalSeclogon
A little tool to play with the Seclogon service

A little tool to play with the Seclogon service

Pass the Hash to a named pipe for token Impersonation

Miscellaneous Tools

Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. Implemented in C#, C++, Crystal, Python and…

Lateral Movement Using DCOM and DLL Hijacking

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Ask a TGS on behalf of another user without password

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Check for valid credentials across a network over SMB

Manipulating and Abusing Windows Access Tokens.

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.

Pass the Hash to a named pipe for token Impersonation

A basic emulation of an "RPC Backdoor"

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

Local & remote Windows DLL Proxying

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

Python library and client for token manipulations and impersonations for privilege escalation on Windows