
cve-2020-1472
Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

MakeMeEnterpriseAdmin

PowerShell script to validate domain controllers against CVE-2020-1472 (Netlogon EoP) by checking installed hotfixes via WMI, outputting compliance…

Hook PasswordChangeNotify

Python exploit for CVE-2020-1472 (Zerologon) targeting Netlogon authentication bypass to escalate privileges and compromise Active Directory domain…


.Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py

Proof-of-concept exploit for CVE-2020-16152: LFI-to-RCE in Aerohive/Extreme Networks HiveOS via PHP string truncation and log poisoning, enabling…

C# implementation of SMBExec for remote command execution on Windows targets using NTLM password hashes, enabling lateral movement and pass-the-hash…

PowerSploit - A PowerShell Post-Exploitation Framework

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

Network Attack wifi attack vlan attack arp attack Mac Attack Attack revealed etc../

Reverse Tunneling made easy for pentesters, by pentesters https://sysdream.com/

Aynı ağda bulunan hedef bilgisayarlar üzerinde ARP zehirlemesi(poisoning) yapmak ve ağ trafiğini izlemenizi sağlamak için yazılmış iki scripttir.


CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

A collection of proof-of-concept source code and scripts for executing remote commands over WinRM using the WSMan.Automation COM object