
WSMan-WinRM
A collection of proof-of-concept source code and scripts for executing remote commands over WinRM using the WSMan.Automation COM object

A collection of proof-of-concept source code and scripts for executing remote commands over WinRM using the WSMan.Automation COM object

Abuse SCCM servers to deploy malicious applications to managed hosts for lateral movement and red team operations.

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

Automated rogue access point setup tool.

Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process.

A basic emulation of an "RPC Backdoor"

Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…


Local SYSTEM auth trigger for relaying

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

Python library and client for token manipulations and impersonations for privilege escalation on Windows


Rusty Impersonate

Leverage WindowsApp createdump tool to obtain an lsass dump

SSH spreading made easy for red teams in a hurry

A SOCKS proxy for Citrix.