Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. Implemented in C#, C++, Crystal, Python and Rust
☆124Feb 17, 2026Updated 2 weeks ago
Alternatives and similar repositories for AutoPtT
Users that are interested in AutoPtT are comparing it to the libraries listed below
Sorting:
- Fast Windows post-exploitation wins after initial access.☆29Jan 28, 2026Updated last month
- A BOF to create a scheduled task using a COM object.☆16Dec 3, 2024Updated last year
- Cobaltstrike UDRL with memory evasion☆15May 16, 2024Updated last year
- A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA …☆163Nov 2, 2025Updated 4 months ago
- BOF to terminate a process via PID as argument☆28Sep 7, 2025Updated 5 months ago
- This repo contains useful scripts that AI created for me which I would have been too lazy for☆92Feb 22, 2026Updated last week
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆166Jan 12, 2026Updated last month
- Remote administration toolkit for windows, based on Hidden VNC: file manager, keystroke logger, powershell☆37Nov 23, 2025Updated 3 months ago
- PowerShell collector for adding SCCM attack paths to BloodHound with OpenGraph☆75Updated this week
- A PoC for the dMSA Active Directory Domain Takeover deemed BadSuccessor☆48Jul 20, 2025Updated 7 months ago
- A tool for leveraging elevated acess over a computer to boot the computer into Windows Safe Mode, alter settings, and then boot back into…☆16Nov 6, 2021Updated 4 years ago
- ☆38Feb 26, 2025Updated last year
- Decrypt Veeam database passwords☆222Dec 8, 2025Updated 2 months ago
- Proof of Concept (PoC) implant for creating custom Cobalt Strike Beacons☆170Feb 11, 2026Updated 3 weeks ago
- Alternative Read and Write primitives using Rtl* functions the unintended way.☆79Aug 25, 2025Updated 6 months ago
- BOF to run PE in Cobalt Strike Beacon without console creation☆186Nov 23, 2025Updated 3 months ago
- Unauthenticated start EFS service on remote Windows host (make PetitPotam great again)☆129Oct 23, 2025Updated 4 months ago
- Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#…☆339Feb 2, 2026Updated last month
- Create a lnk shortcut file for Windows☆24Apr 23, 2019Updated 6 years ago
- A tool that supports finding and abusing whitelisted programs to allow arbitrary file writing into the executable folder of Antivirus sof…☆81Nov 1, 2025Updated 4 months ago
- Script to extract the cached credentials from SSSD, getting Active Directory credentials from Unix systems☆24Jun 14, 2023Updated 2 years ago
- ☆100Sep 1, 2024Updated last year
- Nemesis agent for Mythic☆28Dec 11, 2025Updated 2 months ago
- Moonwalk++: Simple POC Combining StackMoonwalking and Memory Encryption☆202Dec 17, 2025Updated 2 months ago
- Identify Azure AD resources that issue tokens without MFA enforcement using the ROPC grant flow.☆83Feb 2, 2026Updated last month
- Impersonate Tokens using only NTAPI functions☆84Apr 4, 2025Updated 11 months ago
- RedAudit is a next-generation Windows forensic and security assessment framework featuring a live cyber-operations GUI built for real inv…☆35Nov 15, 2025Updated 3 months ago
- A C and Go /proc/pid/maps cloak of invisibilty for shared object files☆21Nov 19, 2025Updated 3 months ago
- ☆12Nov 25, 2024Updated last year
- Dump Kerberos tickets☆45Aug 4, 2025Updated 7 months ago
- A version of NetLoader, Execute Assemblies and Bypass ETW and AMSI using Hardware Breakpoints☆123Jul 11, 2025Updated 7 months ago
- ☆31Jul 26, 2024Updated last year
- UDC2 implementation that provides an ICMP C2 channel☆115Nov 24, 2025Updated 3 months ago
- BOF for Kerberos abuse (an implementation of some important features of the Rubeus).☆546Nov 23, 2025Updated 3 months ago
- Advanced In-Memory PowerShell Process Injection Framework☆73Jul 16, 2025Updated 7 months ago
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆95Jul 3, 2025Updated 8 months ago
- Assess the security of your Active Directory with few or all privileges.☆346Updated this week
- Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP.☆250Jun 11, 2024Updated last year
- ☆30Oct 13, 2025Updated 4 months ago