
Titanis
Windows protocol library, including SMB and RPC implementations, among others.

Windows protocol library, including SMB and RPC implementations, among others.

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

The DCERPC only printerbug.py version

Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…

Local SYSTEM auth trigger for relaying

WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler

Proof-of-concept tool that chains DNS injection, NTLM relay, and RPC-based coercion to test authentication relay paths in Windows Active Directory…

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various…

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…


it's a CVE-2023-28229 (Patched), but feel free to use it for check any outdated software or reseach

Proof-of-concept exploit for Windows CNG KeyIso RPC elevation of privilege and sandbox escape, demonstrating exploitation of CVE-2023-28229.

UAC bypass by abusing RPC and debug objects.

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

Windows Privilege Escalation from User to Domain Admin.

PoC for CVE-2022-41120/CVE-2022-44704: arbitrary file delete/write in Sysmon via ClipboardChange RPC leading to local privilege escalation on Windows.

Some Service DCOM Object and SeImpersonatePrivilege abuse.