
Shocker-TJNULL-OSCP-
Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…

Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…

A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to…

Exploit script for CVE-2020-1472 (ZeroLogon) with automated privilege escalation, credential dumping via secretsdump, and lateral movement using…

Exploit for CVE-2024-22274 that creates a privileged user and spawns a root SSH shell on a target host using provided credentials.

RunasCs - Csharp and open version of windows builtin runas.exe

Stop Windows Defender programmatically

A User Impersonation tool - via Token or Shellcode injection

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

A windows token impersonation tool

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

Pass the Hash to a named pipe for token Impersonation

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Collection of tools that reflect the network dimension into Bloodhound's data

Windows Session Hijacking via COM

Pass the Hash to a named pipe for token Impersonation

Manipulating and Abusing Windows Access Tokens.

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…