
zerologon
Scripts to test and exploit the Zerologon vulnerability (CVE-2020-1472) in Active Directory, enabling password reset and hash dumping of domain…

Scripts to test and exploit the Zerologon vulnerability (CVE-2020-1472) in Active Directory, enabling password reset and hash dumping of domain…

Python exploit for CVE-2020-1472 (Zerologon) targeting Netlogon authentication to compromise Active Directory domain controllers and escalate…

Exploit for CVE-2020-1472 (Zerologon) targeting Windows Netlogon to achieve privilege escalation and domain controller compromise.

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

The Shadow Attack Framework

RunasCs - Csharp and open version of windows builtin runas.exe

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).


Process injection alternative

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

Collection of tools that reflect the network dimension into Bloodhound's data

Ask a TGS on behalf of another user without password

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

PrintNightmare (CVE-2021-34527) PoC Exploit

Python library and client for token manipulations and impersonations for privilege escalation on Windows

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Impersonate Logged In Accounts & Execute Commands

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…