uziii2208 / CVE-2025-33073Links
Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.
☆63Updated last month
Alternatives and similar repositories for CVE-2025-33073
Users that are interested in CVE-2025-33073 are comparing it to the libraries listed below
Sorting:
- SpicyAD is a C# Active Directory penetration testing tool designed for authorized security assessments. It combines multiple AD attack te…☆82Updated last week
- PfSense Stored XSS lead to Arbitrary Code Execution exploit☆49Updated 11 months ago
- ☆59Updated last year
- Go collector for adding Ansible WorX and Ansible Tower attack paths to BloodHound with OpenGraph☆61Updated last week
- ☆55Updated last month
- Docker container for running CobaltStrike 4.10☆37Updated last year
- A tool to easily perform GitHub Device Code Phishing on red team engagements☆69Updated 3 weeks ago
- Retrieve LAPS passwords from a domain. The tools is inspired in pyLAPS.☆86Updated 9 months ago
- Deploy a phishing infrastructure on the fly.☆78Updated last year
- Tamper Active Directory user attributes to collect their hashes with MS-SNTP☆41Updated 11 months ago
- Permanently disable EDRs as local admin☆123Updated last week
- Decrypt Chromium based browser passwords with PowerShell.☆129Updated last month
- A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.☆72Updated last month
- Generate password spraying lists based on the pwdLastSet-attribute of users.☆55Updated 2 years ago
- Scripts I use to deploy Havoc on Linode and setup categorization and SSL☆42Updated last year
- POC for CVE-2024-3183 (FreeIPA Rosting)☆26Updated last year
- ☆62Updated 2 weeks ago
- This tool exploits Golden DMSA attack against delegated Managed Service Accounts.☆89Updated 5 months ago
- A small red team course☆40Updated 2 years ago
- Fully automated windows credentials dumper, for SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with…☆79Updated last year
- Dump Kerberos tickets from the KCM database of SSSD☆52Updated last year
- This is a GRE PoC code for Talks: From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion☆90Updated 4 months ago
- Impacket with added MSSQL Relay server☆49Updated 2 weeks ago
- Kooky cURL-powered replacement for reverse shell via /dev/tcp☆75Updated last week
- Enumerate valid users within Microsoft Teams and OneDrive with clean output.☆59Updated 10 months ago
- Repo for all my exploits/PoCs☆53Updated 7 months ago
- Automated script for obfuscating, rebranding and renaming the Havoc C2 Framework to evade AV/EDR and C2 hunters.☆47Updated 4 months ago
- A proof-of-concept C2 channel through DuckDuckGo's image proxy service☆76Updated 2 years ago
- A tool that allows you to extract a client-specific wordlist from the LDAP of an Active Directory.☆57Updated 5 months ago
- this script adds the ability to encode shellcode (.bin) in XOR,chacha20, AES. You can choose between 2 loaders (Myph / 221b)☆83Updated 2 years ago