
ZeroLogon-to-Shell
Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

A small utility to translate NTDS.dit files to SQLite format.

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Get file less command execution for lateral movement.

A Windows Remote Administration Tool in Visual Basic with UNC paths

Ask a TGS on behalf of another user without password

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

This is just a quick note on how to exploit these vulnerabilities to get root.

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

Different methods to get current username without using whoami

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

Authenticated command injection exploit for QuickBox Pro v2.1.8, providing remote code execution as www-data and privilege escalation to root via…

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability

cve-2025-23266-migration-bypass

Pentest TeamCity using Metasploit

A collection of selenium tests that might aid it takeover of a selenium node