Skip to content
View Mag1cByt3s's full-sized avatar
❄️
Nix
❄️
Nix

Organizations

@Red-Flake

Block or report Mag1cByt3s

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
47 stars written in C#
Clear filter

PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

C# 19,231 3,341 Updated Feb 4, 2026

Trying to tame the three-headed dog.

C# 4,861 863 Updated Nov 14, 2025

.NET IPv4/IPv6 machine-in-the-middle tool for penetration testers

C# 2,898 467 Updated Nov 19, 2025

a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )

C# 2,716 260 Updated Feb 2, 2026

Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019

C# 1,805 233 Updated Sep 4, 2024

Avalonia-based .NET Decompiler (port of ILSpy)

C# 1,779 195 Updated Jul 21, 2025

Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities

C# 1,657 274 Updated Nov 28, 2020

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

C# 1,626 211 Updated Aug 6, 2022

RunasCs - Csharp and open version of windows builtin runas.exe

C# 1,334 158 Updated Jul 12, 2024

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by…

C# 1,292 155 Updated Dec 15, 2020

C# implementation of harmj0y's PowerView

C# 1,080 197 Updated Mar 22, 2024

Framework for Kerberos relaying

C# 939 131 Updated May 29, 2022

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!

C# 906 74 Updated Oct 30, 2025

Windows 权限提升 BadPotato

C# 888 141 Updated May 10, 2020

SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Directory Web Services (ADWS) protocol.

C# 852 91 Updated Feb 3, 2024

StandIn is a small .NET35/45 AD post-exploitation toolkit

C# 829 137 Updated Dec 2, 2023

Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability).

C# 815 130 Updated Dec 14, 2023

A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage PowerShell reverse shell.

C# 811 148 Updated Mar 28, 2025

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

C# 777 128 Updated Oct 16, 2025

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)

C# 698 97 Updated May 7, 2025

Original PoC for CVE-2023-32784

C# 644 59 Updated Aug 17, 2023

Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework

C# 635 97 Updated May 8, 2025

A tool to help query AD via the LDAP protocol

C# 605 58 Updated Sep 25, 2024

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

C# 585 61 Updated Mar 19, 2024

Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!

C# 534 57 Updated May 9, 2025

DeadPotato is a windows privilege escalation utility from the Potato family of exploits, leveraging the SeImpersonate right to obtain SYSTEM privileges. This script has been customized from the ori…

C# 457 46 Updated Aug 17, 2024

SeImpersonate privilege escalation tool for Windows 8 - 11 and Windows Server 2012 - 2022 with extensive PowerShell and .NET reflection support.

C# 452 50 Updated May 16, 2024

C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.

C# 431 76 Updated Sep 1, 2024

Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC

C# 419 51 Updated Sep 29, 2025
Next