[Linux] Two Privilege Escalation techniques abusing sudo token
☆732Apr 14, 2019Updated 6 years ago
Alternatives and similar repositories for sudo_inject
Users that are interested in sudo_inject are comparing it to the libraries listed below
Sorting:
- Linux privilege escalation exploit via snapd (CVE-2019-7304)☆682May 9, 2019Updated 6 years ago
- Some of my exploits.☆600Feb 25, 2021Updated 5 years ago
- PoC code for CVE-2019-0841 Privilege Escalation vulnerability☆242Apr 9, 2019Updated 6 years ago
- Fileless lateral movement tool that relies on ChangeServiceConfigA to run command☆1,607Jul 10, 2023Updated 2 years ago
- Red Team Scripts by d0nkeys (ex SnadoTeam)☆702Jul 27, 2020Updated 5 years ago
- A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specifi…☆2,446Oct 3, 2025Updated 5 months ago
- Privilege Escalation Project - Windows / Linux / Mac☆2,602Oct 4, 2024Updated last year
- Viewgen is a ViewState tool capable of generating both signed and encrypted payloads with leaked validation keys☆657Feb 1, 2025Updated last year
- DEPRECATED SharpRoast is a C# port of various PowerView's Kerberoasting functionality.☆251Sep 25, 2018Updated 7 years ago
- ☆299Nov 9, 2020Updated 5 years ago
- Bypassing disabled exec functions in PHP (c) CRLF☆406Oct 2, 2020Updated 5 years ago
- A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts t…☆2,737Dec 18, 2021Updated 4 years ago
- C# Targeted Attack Reconnissance Tools☆120Jan 11, 2021Updated 5 years ago
- Active Directory Integrated DNS dumping by any authenticated user☆1,135Apr 4, 2025Updated 11 months ago
- Perform a MitM attack and extract clear text credentials from RDP connections☆1,449Nov 20, 2025Updated 3 months ago
- Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks.☆1,081Apr 5, 2022Updated 3 years ago
- HTA encryption tool for RedTeams☆1,422Nov 9, 2022Updated 3 years ago
- PowerShell MachineAccountQuota and DNS exploit tools☆1,438Jan 11, 2023Updated 3 years ago
- PowerShell and Cobalt Strike scripts for lateral movement using Excel 4.0 / XLM macros via DCOM (direct shellcode injection in Excel.exe)☆328Mar 26, 2019Updated 6 years ago
- Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans☆584Sep 7, 2021Updated 4 years ago
- Automation for internal Windows Penetrationtest / AD-Security☆3,644Aug 28, 2025Updated 6 months ago
- Privilege Escalation: Weaponizing CVE-2019-1405 and CVE-2019-1322☆350Nov 14, 2019Updated 6 years ago
- A tool to abuse Exchange services☆2,302Jun 10, 2024Updated last year
- Payload Generation Framework☆1,972Aug 21, 2024Updated last year
- ntlm relay attack to Exchange Web Services☆334Jan 15, 2018Updated 8 years ago
- Proof of concept for CVE-2019-0708☆1,186Dec 2, 2021Updated 4 years ago
- Extracting Clear Text Passwords from mstsc.exe using API Hooking.☆1,429Jul 20, 2024Updated last year
- Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities☆1,659Nov 28, 2020Updated 5 years ago
- The exploit samples database is a repository for **RCE** (remote code execution) exploits and Proof-of-Concepts for **WINDOWS**, the samp…☆746Dec 11, 2023Updated 2 years ago
- SharPyShell - tiny and obfuscated ASP.NET webshell for C# web applications☆1,051Nov 26, 2023Updated 2 years ago
- Token Privilege Research☆872Sep 1, 2017Updated 8 years ago
- GTRS - Google Translator Reverse Shell☆624Sep 26, 2025Updated 5 months ago
- An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.☆305Sep 7, 2022Updated 3 years ago
- There is no pre-auth RCE in Jenkins since May 2017, but this is the one!☆607May 17, 2019Updated 6 years ago
- Steal Net-NTLM Hash using Bad-PDF☆1,142Oct 20, 2025Updated 4 months ago
- Powershell script for enumerating vulnerable DCOM Applications☆266Nov 30, 2018Updated 7 years ago
- Auto Root Exploit Tool☆536Jun 15, 2023Updated 2 years ago
- CVE-2019-0604☆133Mar 22, 2019Updated 6 years ago
- Process Injection☆766Oct 24, 2021Updated 4 years ago