
SessionHop
Windows Session Hijacking via COM

Windows Session Hijacking via COM

Pass the Hash to a named pipe for token Impersonation

Check for valid credentials across a network over SMB

Manipulating and Abusing Windows Access Tokens.

Pastejacking - PasteZort

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

Firecat is a penetration testing tool that allows you to punch reverse TCP tunnels out of a compromised network.

Nacker is a tool to circumvent 802.1x Network Access Control (NAC) on a wired LAN. Nacker will help you locate any non-802.1x configurable hosts on…

Cobalt Strike BOF that spawns a process using another user's token and injects Beacon shellcode, enabling post-exploitation and lateral movement via…

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

Leverage WindowsApp createdump tool to obtain an lsass dump

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

conduct lateral movement attack by leveraging unfiltered services display name to smuggle binaries as chunks into the target machine
