
SQLRecon
A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.


In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

windows-kernel-exploits Windows平台提权漏洞集合

A collection of scripts for assessing Microsoft Azure security

Windows Local Privilege Escalation Cookbook

Crack any Microsoft Windows users password without any privilege (Guest account included)

The Shadow Attack Framework

MSDAT: Microsoft SQL Database Attacking Tool

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various…


PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

Powershell script to do domain auditing automation

KslDump — Why bring your own knife when Defender already left one in the kitchen?

Windows COM hijacking persistence tool with search, classic, Task Scheduler, and TreatAs modes. Available as .NET executable and Cobalt Strike BOF…

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.