TarlogicSecurity / EoPLoadDriver
Proof of concept for abusing SeLoadDriverPrivilege (Privilege Escalation in Windows)
☆125Updated 6 years ago
Related projects ⓘ
Alternatives and complementary repositories for EoPLoadDriver
- Scripts created to help with post exploitation of a Windows host☆95Updated 3 years ago
- Weaponizing for privileged file writes bugs with windows problem reporting☆207Updated 2 years ago
- A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.☆163Updated 2 years ago
- ☆127Updated 5 months ago
- Loads a custom dll in system32 via diaghub.☆68Updated 4 years ago
- Run Rubeus via Rundll32☆198Updated 4 years ago
- One Token To Rule Them All https://labs.mwrinfosecurity.com/blog/incognito-v2-0-released/☆144Updated 4 years ago
- Impersonating authentication over HTTP and/or named pipes.☆119Updated 3 years ago
- Bypass for PowerShell Constrained Language Mode☆373Updated 2 years ago
- Use SE_BACKUP_NAME/SeBackupPrivilege to access objects you shouldn't have access to☆287Updated 11 years ago
- ☆70Updated 4 years ago
- Juicy Potato for x86 Windows☆117Updated 5 years ago
- C implementation of the file-less UAC exploit☆74Updated 8 years ago
- ☆348Updated 3 years ago
- Trigen is a Python script which uses different combinations of Win32 function calls in generated VBA to execute shellcode.☆199Updated 7 years ago
- POC for NetworkService PrivEsc☆123Updated 4 years ago
- Automating juicy potato local privilege escalation exploit for penetration testers☆138Updated 3 years ago
- Use CVE-2020-0668 to perform an arbitrary privileged file move operation.☆211Updated 4 years ago
- Extracts Key Values from .keytab files☆214Updated 4 years ago
- ☆198Updated last year
- A meterpreter extension for applying hooks to avoid windows defender memory scans☆239Updated 4 years ago
- Custom Metasploit post module to executing a .NET Assembly from Meterpreter session☆341Updated 4 years ago
- A collection of proof-of-concept source code and scripts for executing remote commands over WinRM using the WSMan.Automation COM object☆221Updated 4 years ago
- RACE is a PowerShell module for executing ACL attacks against Windows targets.☆211Updated last year
- 64bit Windows 10 shellcode that injects all processes with Meterpreter reverse shells.☆127Updated last year
- Example DLL to load from Windows NetShell☆177Updated 8 years ago
- C++ Windows Reverse Shell - Universal DLL Hijack | SSL Encryption | Statically Linked☆86Updated 4 years ago
- A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts t…☆59Updated 5 years ago
- Bypass AMSI by patching AmsiScanBuffer☆251Updated 3 years ago
- Proof-of-concept code for various bugs☆106Updated 2 weeks ago