
KrbRelay
Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…

Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

Windows protocol library, including SMB and RPC implementations, among others.

Windows Privilege Escalation from User to Domain Admin.

A basic emulation of an "RPC Backdoor"

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.

WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler

A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…


Proof-of-concept exploit for CVE-2022-22814 demonstrating local privilege escalation on Windows via vulnerable ASUS SystemDiagnosis ALPC RPC…

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various…

Local SYSTEM auth trigger for relaying

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…

Proof-of-concept tool that chains DNS injection, NTLM relay, and RPC-based coercion to test authentication relay paths in Windows Active Directory…

Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…