snovvcrash / KrbRelayUp
KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).
☆12Updated 2 years ago
Alternatives and similar repositories for KrbRelayUp:
Users that are interested in KrbRelayUp are comparing it to the libraries listed below
- Modified version of PEAS client for offensive operations☆38Updated 2 years ago
- A script that greps composite key-like strings from a KeePassXC process dump, then uses a customized version of pykeepass library to unlo…☆31Updated 2 years ago
- Port forwarding via MSRPC (445/tcp) [WIP]☆32Updated 3 years ago
- ☆15Updated 2 years ago
- ☆24Updated 3 years ago
- Perform Windows domain enumeration via LDAP☆36Updated 2 years ago
- Convert ldapdomaindump to Bloodhound☆78Updated last year
- Python script to exploit CVE-2022-22954 and then exploit CVE-2022-22960☆2Updated 2 years ago
- SharpReg is a simple code set to interact with the Remote Registry service api and is compatible with Cobalt Strike.☆27Updated 4 years ago
- Secretsdump C# version only supporting local (live) operation☆48Updated last year
- Execute Mimikatz with different technique☆51Updated 3 years ago
- Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged p…☆49Updated 2 years ago
- Add SD for controlled computer object to a target object for RBCD using LDAP☆38Updated 3 years ago
- ☆17Updated 4 years ago
- Generate AES128/256 Kerberos keys for an AD account using a plaintext password and Python3☆50Updated 2 years ago
- IOXIDResolver from AirBus Security/PingCastle☆47Updated 4 years ago
- C# .Net 5.0 project to build BOF (Beacon Object Files) in mass☆28Updated last year
- OffensivePipeline allows to download, compile (without Visual Studio) and obfuscate C# tools for Red Team exercises.☆90Updated 2 years ago
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆53Updated 3 years ago
- Cobalt Strike profile generator using Jenkins to automate the heavy lifting☆34Updated 2 years ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆41Updated 4 months ago
- Standalone Cobalt Strike operation logging Aggressor script for Ghostwriter 2.0+☆25Updated 6 months ago
- WhoAmI by asking the LDAP service on a domain controller.☆61Updated 3 years ago
- Active Directory ACL exploitation with BloodHound☆12Updated 3 years ago
- My BloodHound custom queries☆23Updated 2 years ago
- ☆21Updated last year
- Matryoshka loader is a tool that red team operators can leverage to generate shellcode for Microsoft Office document phishing payloads.☆40Updated 3 years ago
- Tomcat backdoor based on CS blog☆27Updated last year
- Finding SSL Blindspots for Red Teams☆32Updated 4 years ago
- Create PDFs with HTML smuggling attachments that save on opening the document.☆29Updated last year