WKL-Sec / WMIExecLinks
Set of python scripts which perform different ways of command execution via WMI protocol.
☆164Updated 2 years ago
Alternatives and similar repositories for WMIExec
Users that are interested in WMIExec are comparing it to the libraries listed below
Sorting:
- Lateral Movement☆126Updated 2 years ago
- ACL abuse swiss-knife☆125Updated 2 years ago
- Exploit for CVE-2023-27532 against Veeam Backup & Replication☆115Updated 2 years ago
- Useful Cobalt Strike Beacon Object Files (BOFs) used during red teaming and penetration testing engagements.☆138Updated 3 years ago
- ☆163Updated 2 years ago
- Use ESC1 to perform a makeshift DCSync and dump hashes☆210Updated 2 years ago
- A RunAs clone with the ability to specify the password as an argument.☆112Updated 2 years ago
- The BackupOperatorToolkit contains different techniques allowing you to escalate from Backup Operator to Domain Admin☆178Updated 2 years ago
- ☆93Updated 2 years ago
- ☆222Updated last year
- A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY☆89Updated 3 years ago
- To audit the security of read-only domain controllers☆118Updated 2 years ago
- Python script for automating the creation of serverless cloud redirectors from Cobalt Strike malleable C2 profiles☆202Updated last year
- ☆169Updated last year
- Havoc C2 profile generator☆102Updated 6 months ago
- A technique to coerce a Windows SQL Server to authenticate on an arbitrary machine.☆132Updated 2 years ago
- A C# port from Invoke-GhostTask☆119Updated 2 years ago
- Active Directory Authentication Library☆86Updated 2 months ago
- Abuse leaked token handles.☆134Updated 2 years ago
- Weaponized HellsGate/SigFlip☆205Updated 2 years ago
- ☆238Updated last year
- My implementation of the GIUDA project in C++☆188Updated 2 years ago
- C or BOF file to extract WebKit master key to decrypt user cookie☆207Updated last year
- Evasive Golang Loader☆137Updated last year
- PoC for using MS Windows printers for persistence / command and control via Internet Printing☆149Updated last year
- ☆102Updated 2 years ago
- ☆120Updated 9 months ago
- Uses rpcdump to locate the ADCS server, and identify if ESC8 is vulnerable from unauthenticated perspective.☆82Updated last year
- Github as C2 Demonstration , free API = free C2 Infrastructure☆145Updated 2 years ago
- Repository contains psexec, which will help to exploit the forgotten pipe☆172Updated last year