
pth-toolkit
Modified version of the passing-the-hash tool collection made to work straight out of the box

Modified version of the passing-the-hash tool collection made to work straight out of the box

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

Collection of tools that reflect the network dimension into Bloodhound's data

Some scripts to abuse kerberos using Powershell

Hijack Putty sessions in order to sniff conversation and inject Linux commands.

Fully modular persistence framework

A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its…

C# implementation of SMBExec for remote command execution on Windows targets using NTLM password hashes, enabling lateral movement and pass-the-hash…

C# tool leveraging WinDivert driver to intercept and redirect Windows port 445 traffic for NTLM relay attacks via Cobalt Strike, enabling lateral…

A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.

Module-based AWS exploitation framework for red team testing and blue team analysis. Emulates attack patterns in the AWS control plane with unique UA…

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Create local administrators in Windows using the SAMR API. In C#, Crystal, Python, Rust, Golang, Nim and Deno (Javascript)

LOKI (Limited Obstructive Keyboard Impersonator) is a RDP File Transfer Tool Using Keypresses

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

Common library for tools implementing GPO attack vectors

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

Proof-of-concept exploit for CVE-2024-57394: low-privilege file restoration to System32 enabling DLL hijacking and local privilege escalation to…