
SCShell
Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

Red Team oriented C# Simple HTTP & WebDAV Server with Net-NTLM hashes capture functionality

Lateral Movement Using DCOM and DLL Hijacking

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

A windows token impersonation tool

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

Fully modular persistence framework

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

An exploitation demo of Outlook Elevation of Privilege Vulnerability

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

.NET Project for performing Authenticated Remote Execution

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

Active Directory ACL abuse toolkit for privilege escalation, DCSync, object ownership modification, and lateral movement via logon script…

C# Reflective loader for unmanaged binaries.

Impacket-based exploit for PrintNightmare (CVE-2021-1675/34527) enabling remote or local DLL execution against Windows print spooler services.

Windows Privilege Escalation from User to Domain Admin.

PrintNightmare (CVE-2021-34527) PoC Exploit