
GhostTask
A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

A little tool to play with the Seclogon service

Pass the Hash to a named pipe for token Impersonation

Miscellaneous Tools

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Ask a TGS on behalf of another user without password

CVE-2019-1040 with Exchange

Manipulating and Abusing Windows Access Tokens.

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.

Pass the Hash to a named pipe for token Impersonation

A basic emulation of an "RPC Backdoor"

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

Local & remote Windows DLL Proxying

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

Local SYSTEM auth trigger for relaying

A Powershell implementation of PrivExchange designed to run under the current user's context

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation