
ranger
A tool for security professionals to access and interact with remote Microsoft Windows based systems.

A tool for security professionals to access and interact with remote Microsoft Windows based systems.

Rapid psexec-style attack tool using Samba for remote command execution, credential dumping, and lateral movement across Windows networks with hash…

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

Python library and client for token manipulations and impersonations for privilege escalation on Windows

A Windows Remote Administration Tool in Visual Basic with UNC paths

A windows token impersonation tool

Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…

Manipulating and Abusing Windows Access Tokens.

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

RunasCs - Csharp and open version of windows builtin runas.exe

Stop Windows Defender programmatically

Leverage WindowsApp createdump tool to obtain an lsass dump

A C# implementation of dumping credentials from Windows Credential Manager

Proof-of-concept module for CVE-2026-54121 (Certighost), exploiting AD CS enrollment validation via rogue LDAP/SMB listeners to impersonate a Domain…

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…