
KrbRelay
Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…

Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…

This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing…

ToRat is a Remote Administation tool written in Go using Tor as a transport mechanism and RPC for communication

Windows protocol library, including SMB and RPC implementations, among others.

A basic emulation of an "RPC Backdoor"

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

Apache Hadoop YARN ResourceManager - Unauthenticated RCE PoC

WPTaskScheduler RPC Persistence & CVE-2024-49039 via Task Scheduler

A personalized/enhanced re-creation of the Darkhotel "Double Star" APT exploit chain with a focus on Windows 8.1 and mixed with some of my own…

A repository that maps commonly used attacks using MSRPC protocols to ATT&CK

A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various…

Local SYSTEM auth trigger for relaying

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…

0 Click RCE exploit for CVE-2026-34159 Lama.cpp RPC server

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

The poc for CVE-2022-26809 RCE via RPC will be updated here.

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.