
fakelogonscreen
Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

A Golang implant that uses Slack as a command and control server

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

Collection of tools that reflect the network dimension into Bloodhound's data

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

SetupHijack is a security research tool that exploits race conditions and insecure file handling in Windows applications installer and update…

An automated SMB relay exploitation script.

C# tool for red team operations that extracts contacts, mailbox metadata, and searches emails via Outlook COM object, with built-in Programmatic…

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.

Firecat is a penetration testing tool that allows you to punch reverse TCP tunnels out of a compromised network.

Nacker is a tool to circumvent 802.1x Network Access Control (NAC) on a wired LAN. Nacker will help you locate any non-802.1x configurable hosts on…

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.