POC for CVE-2025-54918 and a technical demonstration.
☆64Jan 12, 2026Updated 7 months ago
Alternatives and similar repositories for CVE-2025-54918-POC
Users that are interested in CVE-2025-54918-POC are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Impacket with --remove-mic-partial☆50Jan 8, 2026Updated 7 months ago
- Enable EFS service as low priv user (PE & BOF)☆21Jul 6, 2025Updated last year
- Active Directory engagement workspace that combines offline tradecraft, operator-ready commands, attack path analysis, and automated play…☆23Jun 24, 2026Updated 2 months ago
- The DCERPC only printerbug.py version☆234Oct 30, 2025Updated 10 months ago
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆135Jul 23, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.☆224Jan 6, 2026Updated 7 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 8 months ago
- a minimalistic winrm client written in python☆49Apr 17, 2026Updated 4 months ago
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆121Oct 20, 2024Updated last year
- ☆24Jul 7, 2026Updated last month
- An impacket-lite cli tool that combines many useful impacket functions using a single session.☆60Updated this week
- Generate and Manage KeyCredentialLinks☆258Jul 17, 2026Updated last month
- Windows remote execution multitool☆815Mar 25, 2026Updated 5 months ago
- RPC to WebClient startup☆60Aug 19, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Dominate the domain. Relay to royalty.☆352Mar 31, 2026Updated 4 months ago
- The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencie…☆183Sep 3, 2025Updated 11 months ago
- SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.☆431Sep 26, 2025Updated 11 months ago
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory — no OpenProcess, no auditable AP…☆147Apr 22, 2026Updated 4 months ago
- WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.☆129Jun 24, 2026Updated 2 months ago
- ☆39Jan 7, 2025Updated last year
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆189May 31, 2026Updated 3 months ago
- Python tool to automatically perform SPN-less RBCD attacks.☆132Jan 7, 2026Updated 7 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆141Aug 25, 2025Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will auto…☆15Apr 2, 2026Updated 4 months ago
- BOF POC of the DSCourier project / invoking WinGet via COM☆90Apr 23, 2026Updated 4 months ago
- A POC for developing BOFs for Sliver, Havoc, Cobalt Strike or most COFFLoaders in Rust.☆76Aug 24, 2025Updated last year
- BOF that finds all the Nt* system call stubs within NTDLL and overwrites with clean syscall stubs (user land hook evasion)☆220Feb 6, 2025Updated last year
- Sleep replacement that executes real, varied work to break behavioral pattern matching by EDR and anti-cheat systems☆78Jul 20, 2026Updated last month
- C2 Framework - Advanced Red Team Tool☆22Jun 1, 2026Updated 2 months ago
- Bof of RegPwn by MDSec☆129Mar 15, 2026Updated 5 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆340Feb 2, 2026Updated 6 months ago
- Obex – Blocking unwanted DLLs in user mode☆281Sep 18, 2025Updated 11 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- KslDump — Why bring your own knife when Defender already left one in the kitchen?☆400Apr 13, 2026Updated 4 months ago
- A Model Context Protocol (MCP) server to converse with data in Bloodhound☆127Aug 19, 2026Updated last week
- Beacon Object Files (BOFs) for Cobalt Strike and Havoc C2. Implementations of Active Directory attacks and post-exploitation techniques.☆118Jan 26, 2026Updated 7 months ago
- Arbitrary file read exploit for the Windows UPnP Device Host service.☆20Jun 5, 2026Updated 2 months ago
- A searchable, copy-pasteable library of pentesting commands focused on Active Directory. Runs entirely in your browser.☆27Apr 21, 2026Updated 4 months ago
- A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and stati…☆256Mar 15, 2026Updated 5 months ago
- ☆194Oct 21, 2025Updated 10 months ago