
SharpNamedPipePTH
Pass the Hash to a named pipe for token Impersonation

Pass the Hash to a named pipe for token Impersonation

🐐 GoAT (Golang Advanced Trojan) is a trojan that uses Twitter as a C&C server

Weaponizing DCOM for NTLM Authentication Coercions

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

Encrypted C2 framework for post-exploitation and lateral movement, supporting PowerShell implants and custom modules for red team engagements.

BOF POC of the DSCourier project / invoking WinGet via COM

Windows service agent for CALDERA adversary emulation platform. Installed on target computers to communicate with the CALDERA server, enabling…

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

A DNS spoofer tool written in Python3.

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

Penetration testing framework with AI-driven decision engine

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

强大的内网渗透辅助工具集-让Yasso像风一样 支持rdp,ssh,redis,postgres,mongodb,mssql,mysql,winrm等服务爆破,快速的端口扫描,强大的web指纹识别,各种内置服务的一键利用(包括ssh完全交互式登陆,mssql提权,redis一键利用,mysql数据库…

RunasCs - Csharp and open version of windows builtin runas.exe

Passive network security sniffer that analyzes 28 protocols (ARP, STP, OSPF, VLAN, SCADA) to detect vulnerabilities in network equipment without…

Ask a TGS on behalf of another user without password

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…