Stars
Proof-of-Concept tool to authenticate to an LDAP/S server with a certificate through Schannel
Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)
Get file less command execution for lateral movement.
Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework
Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).
.NET 2.0 CLR project to retrieve saved browser credentials from Google Chrome, Mozilla Firefox and Microsoft Internet Explorer/Edge.
A tool to exploit .NET Remoting Services
Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential exploits for Privilege Escalation in Windows environments.
A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.
SeImpersonate privilege escalation tool for Windows 8 - 11 and Windows Server 2012 - 2022 with extensive PowerShell and .NET reflection support.
A User Impersonation tool - via Token or Shellcode injection
Materials for the workshop "Red Team Ops: Havoc 101"
Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain
A BloodHound collector for Microsoft Configuration Manager
MaLDAPtive is a framework for LDAP SearchFilter parsing, obfuscation, deobfuscation and detection.
Evil SQL Client (ESC) is an interactive .NET SQL console client with enhanced SQL Server discovery, access, and data exfiltration features. While ESC can be a handy SQL Client for daily tasks, it w…
Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domain joined machies
An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails configured in it.
Lateral Movement as loggedon User via Speech Named Pipe COM & ISpeechNamedPipe + COM Hijacking
A variety of AV evasion techniques written in C# for practice.
Programmatically start WebClient from an unprivileged session to enable that juicy privesc.