
DCOMrade
Powershell script for enumerating vulnerable DCOM Applications

Powershell script for enumerating vulnerable DCOM Applications

A script to automate keystrokes through a graphical desktop program.

A fully featured Windows backdoor that uses email as a C&C server

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

Ping Exfiltration Command and Control (PiX-C2)

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

A Golang implant that uses Slack as a command and control server

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

An automated SMB relay exploitation script.

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.