SAERXCIT/LibTP_Gadget
Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.
Crystal Palace library for proxying Nt API calls via the Threadpool. Updated for call gadgets.
Impacket is a collection of Python classes for working with network protocols.
The Red Sun vulnerability repository
psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus
Repository hosting the bluehammer vulnerability
KslDump — Why bring your own knife when Defender already left one in the kitchen?
Lateral movement with DCOM DLL hijacking
Using call gadgets to break the call stack signature used by Elastic on proxying a module load. Provided as a Crystal Palace shared library. Format inspired by rasta-mouse's LibTP.
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
This project is aimed at freely providing technical guides on various hacking topics.
A simple PowerShell function parsing a Procmon CSV output to extract accessed filesystem and registry paths and using @itm4n's PrivescCheck's functions `Get-ModifiablePath` and `Get-ModifiableRegistryPath` to find paths modifiable by the user.
A .net OLE/COM viewer and inspector to merge functionality of OleView and Test Container
A little tool to play with Windows security
C# Data Collector for BloodHound
HookDetector identifies DLL-imported functions that have been hooked in its own process.
Privilege Escalation Enumeration Script for Windows
Enables the requested privilege in its parent process: the shell calling it
regdiff.py diffs two registry hives
A swiss army knife for pentesting networks