
BadSamba
This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

High-performance multi-protocol AAA server for RADIUS, DHCPv4/v6, DNS, TACACS+, and VMPS, centralizing network authentication, authorization, and…

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

Hook PasswordChangeNotify


MakeMeEnterpriseAdmin

An automated SMB relay exploitation script.

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.


PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

LOKI (Limited Obstructive Keyboard Impersonator) is a RDP File Transfer Tool Using Keypresses

Impersonate Logged In Accounts & Execute Commands

A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

Scripts to clone CA certificates for use in HTTPS client attacks.

Firecat is a penetration testing tool that allows you to punch reverse TCP tunnels out of a compromised network.

Local & remote Windows DLL Proxying

Common library for tools implementing GPO attack vectors