
TokenStealer
Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Bash-based post-exploitation tool for semi-automated network pivoting, enabling lateral movement through compromised systems during penetration tests.

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

[unmaintained] Post-exploitation tool

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…

A collection of scripts which may come in handy during your freedom fighting activities.

Exploit script for CVE-2020-1472 (ZeroLogon) with automated privilege escalation, credential dumping via secretsdump, and lateral movement using…

Fileless lateral movement tool using WMI Event Filters and MSBuild execution to deploy shellcode on remote Windows systems via LogFileEventConsumer.

Post-exploitation credential harvesting toolkit that injects into password managers and Windows utilities to capture credentials via DLL proxying,…

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

Some scripts to abuse kerberos using Powershell

A windows token impersonation tool

Pass the Hash to a named pipe for token Impersonation

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

Pass the Hash to a named pipe for token Impersonation

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

Firecat is a penetration testing tool that allows you to punch reverse TCP tunnels out of a compromised network.

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…