
TokenStealer
Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Exploit script for CVE-2020-1472 (ZeroLogon) with automated privilege escalation, credential dumping via secretsdump, and lateral movement using…

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.

A windows token impersonation tool

Pass the Hash to a named pipe for token Impersonation

Pass the Hash to a named pipe for token Impersonation

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

The Shadow Attack Framework

RunasCs - Csharp and open version of windows builtin runas.exe

Collection of tools that reflect the network dimension into Bloodhound's data

Windows Session Hijacking via COM

Manipulating and Abusing Windows Access Tokens.

Python library and client for token manipulations and impersonations for privilege escalation on Windows

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Impersonate Logged In Accounts & Execute Commands

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…