
SharpImpersonation
A User Impersonation tool - via Token or Shellcode injection

A User Impersonation tool - via Token or Shellcode injection

Pass the Hash to a named pipe for token Impersonation

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

Pastejacking - PasteZort

Creates Fake Auth prompt to capture users plaintext passwords

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

Phishing with a fake reCAPTCHA

transform your payload.exe into one fake word doc (.ppt)

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

Impersonate Logged In Accounts & Execute Commands

Tool Information Gathering & social engineering Write By [Python,JS,PHP]

Some scripts to abuse kerberos using Powershell

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

AI-powered LinkedIn engagement assistant

A social engineering tool designed to seamlessly locate profiles using usernames while offering convenient reverse image search functionality.

Exploit for CVE-2022-27226

Proof-of-concept module for CVE-2026-54121 (Certighost), exploiting AD CS enrollment validation via rogue LDAP/SMB listeners to impersonate a Domain…