
PyPsPipeJack
Python implementation of OpenPsPipeJack

Python implementation of OpenPsPipeJack

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

Manipulating and Abusing Windows Access Tokens.

RunasCs - Csharp and open version of windows builtin runas.exe

Stop Windows Defender programmatically

A windows token impersonation tool

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Rusty Impersonate

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Acunetix 0day RCE

Impersonate Logged In Accounts & Execute Commands

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Kioptrix Level 1 writeup - CVE-2003-0201 Samba trans2open

Exploit for CVE-2024-22274 that creates a privileged user and spawns a root SSH shell on a target host using provided credentials.

Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…