
RedGhost
Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…

Trying to tame the three-headed dog.

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

Fixed No Virus Manual Automatic Loader exe no zip because zip picks up the anti virus detector.

Manipulating and Abusing Windows Access Tokens.

VMware Aria Operations for Logs CVE-2023-34051


Exploit for CVE-2020-1472 (ZeroLogon) that resets the domain controller account password and enables DCSync for full domain compromise.

Unauthenticated Privilege Escalation via Account Takeover

Windows Session Hijacking via COM

CVE-2021-3156-Exploit-Demo

Controlled proof-of-concept assessment and exploitation report for CVE-2021-4034 (PwnKit) local privilege escalation in pkexec/polkit, with forensic…

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

CVE-2023-4911 (Looney Tunables) analysis report and Docker reproduction lab

Python library and client for token manipulations and impersonations for privilege escalation on Windows

Detection-aware BloodHound attack-path scoring - the quietest route to your objective, calibrated across five detection tiers…

The Shadow Attack Framework