
TokenStealer
Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Firecat is a penetration testing tool that allows you to punch reverse TCP tunnels out of a compromised network.

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

Rusty Impersonate

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

Leverage WindowsApp createdump tool to obtain an lsass dump

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

A SOCKS proxy for Citrix.

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

A C# implementation of dumping credentials from Windows Credential Manager

Dump Kerberos tickets from the KCM database of SSSD

A script to automate keystrokes through a graphical desktop program.

Impersonate Logged In Accounts & Execute Commands

CVE-2021-42287/CVE-2021-42278 exploits in powershell