
RemoteKeyStrokes
A script to automate keystrokes through a graphical desktop program.

A script to automate keystrokes through a graphical desktop program.


eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

A Golang implant that uses Slack as a command and control server

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

Collection of tools that reflect the network dimension into Bloodhound's data

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

CVE 2020-1472 Script de validación

Tools and Techniques for Red Team / Penetration Testing