
CPLDCOMTrigger
Python script leveraging Impacket to trigger CPL file loading into memory via DCOM IOpenControlPanel interface for lateral movement and code…

Python script leveraging Impacket to trigger CPL file loading into memory via DCOM IOpenControlPanel interface for lateral movement and code…

CPL remote trigger

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Windows Session Hijacking via COM

Socks proxy, and reverse socks server using powershell.

BOF for Kerberos abuse (an implementation of some important features of the Rubeus).

C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527

Exploit for Checkmk CVE-2024-0670 with automated file transfer, reverse shell, and privilege escalation via RunasCs for penetration testing…

CVE-2025-33073

Trying to tame the three-headed dog.

Weaponizing DCOM for NTLM Authentication Coercions

The DCERPC only printerbug.py version

Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

Rusty Impersonate

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…

PowerShell-based post-exploitation framework for lateral movement in Active Directory environments. Executes in-memory with named-pipe command…

PunkBuster LPI to NT AUTHORITY\SYSTEM