
LinEnum
Scripted Local Linux Enumeration & Privilege Escalation Checks

Scripted Local Linux Enumeration & Privilege Escalation Checks

Kernel mode WinDbg extension and PoCs for token privilege investigation.

Collection of offensive PowerShell projects for reconnaissance, privilege escalation, and post-exploitation during penetration testing engagements.

C# tool for auditing Windows privilege escalation vulnerabilities, porting PowerUp checks for misconfigurations like unquoted service paths,…

Linux post exploitation privilege escalation enumeration

Slui File Handler Hijack UAC Bypass Local Privilege Escalation

PowerShell script that audits Windows service binaries for writable permissions, identifying privilege escalation vectors by checking ACLs on…

Escalate Service Account To LocalSystem via Kerberos

Offensive tool to trigger network authentications as SYSTEM

Weaponized web shell

From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller

C# tool for LSASS minidump with multiple evasion techniques including indirect syscalls, ETW patching, and PPL bypass via driver or WER fault.…

C# version of Powermad

Dumping LSASS with a duplicated handle from custom LSA plugin

Inject code into a legitimate process

Take over macOS Electron apps' TCC permissions

Cobalt Strike BOF that exploits a Windows Protected Process Light bypass to dump protected processes, enabling credential access from LSASS.

Injects x64 managed DLLs into GUI processes via SetWindowsHook, with a modular C# payload runner and LSASS dump POC for red-team/offensive Windows…