

Proof-of-concept module for CVE-2026-54121 (Certighost), exploiting AD CS enrollment validation via rogue LDAP/SMB listeners to impersonate a Domain…

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

Exploit for CVE-2021-36934

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

Vulnerable Samba 3.0.24 environment for reproducing CVE-2007-2447 command execution, intended for exploit testing and security research.

Exploit code for CVE-2021-1675, a Windows Print Spooler remote code execution vulnerability, demonstrating the attack and providing a…

A little tool to play with the Seclogon service

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

Python tool to automatically perform SPN-less RBCD attacks.

Pass the Hash to a named pipe for token Impersonation

Manipulating and Abusing Windows Access Tokens.

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

Windows Session Hijacking via COM

Trying to tame the three-headed dog.

A windows token impersonation tool