A rewritten and enhanced WinRM execution tool based on wmiexec and winrmexec, providing a comprehensive remote management shell with advanced capabilities for Windows target systems.
☆83Aug 24, 2026Updated this week
Alternatives and similar repositories for PwnRM
Users that are interested in PwnRM are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Active Directory forensic framework☆16May 18, 2026Updated 3 months ago
- An (WIP) EDR Evasion tool for x64 Windows & Linux binaries that utilizes Nanomites, written in Rust.☆35May 8, 2026Updated 3 months ago
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆29Jul 23, 2026Updated last month
- PowerShell & Python tools developed for CTFs and certification exams☆72Aug 10, 2025Updated last year
- Polymorphic x64 shellcode loader — indirect syscalls, phantom DLL hollowing, call stack spoofing, patchless AMSI/ETW bypass, zero CRT …☆24May 24, 2026Updated 3 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.☆67Nov 14, 2025Updated 9 months ago
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- Dumping all keys from a keytab file☆20Dec 1, 2025Updated 8 months ago
- Safe Harbor is a BOF that streamlines process reconnaissance for red team operations by identifying trusted, low-noise targets to maintai…☆81Oct 27, 2025Updated 10 months ago
- Arsenal of modules to beacon postex☆107Mar 13, 2026Updated 5 months ago
- ADAttributeHound is an OpenGraph extension for BloodHound that exports Active Directory custom attributes as node properties.☆22Jun 18, 2026Updated 2 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆50Jul 23, 2026Updated last month
- Python tool to automatically perform SPN-less RBCD attacks.☆132Jan 7, 2026Updated 7 months ago
- Bof of RegPwn by MDSec☆129Mar 15, 2026Updated 5 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆106Apr 4, 2026Updated 4 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 8 months ago
- BOF for extracting Edge credentials from the main browser process.☆50May 5, 2026Updated 3 months ago
- Pure PowerShell port of PassTheCert tool to authenticate to an LDAP/S server with a certificate through Schannel☆61Apr 13, 2025Updated last year
- An MCP Server for Pwndoc (Pentesting Reporting Tool)☆43Jan 23, 2026Updated 7 months ago
- A BOF for lazy people☆24Apr 4, 2024Updated 2 years ago
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 4 months ago
- Cobalt Strike notifications via NTFY.☆15Sep 24, 2024Updated last year
- A PoC Cobalt Strike UDRL written in Rust☆34Jun 20, 2026Updated 2 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Windows SSH Misconfiguration Discovery Tool - Map lateral movement paths through misconfigured SSH services in Active Directory environme…☆92May 11, 2026Updated 3 months ago
- RBCD Attack Path enumeration tool for attackers and defenders☆15Apr 25, 2026Updated 4 months ago
- CVE-2020-17103 adapted for C2 with split-binary SYSTEM callback☆45May 20, 2026Updated 3 months ago
- Step through PE functions or shellcode instruction-by-instruction (amd64)☆42May 4, 2026Updated 3 months ago
- Tool to enumerate privileged Scheduled Tasks on Remote Systems☆312Updated this week
- SpicyAD is a C# Active Directory penetration testing tool designed for authorized security assessments. It combines multiple AD attack te…☆106Jun 25, 2026Updated 2 months ago
- An executable that simplifies adding the msds-AllowedToActOnBehalfOfOtherIdentity attribute for RBCD☆50Mar 10, 2025Updated last year
- Next-Generation BOF Template | BOF Linter | Obj Rewriter☆60Dec 4, 2025Updated 8 months ago
- Aliasr is a modern, feature-rich TUI launcher for pentest commands.☆117Apr 23, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Tailscale/Headscale C2 profile and agent for Mythic☆34Mar 14, 2026Updated 5 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆36Jul 23, 2026Updated last month
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆40Apr 6, 2026Updated 4 months ago
- ☆23Jul 6, 2025Updated last year
- A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS ac…☆161Jun 10, 2026Updated 2 months ago
- Active network shares enumeration tool.☆38Jul 17, 2026Updated last month
- Remote service-staging tool built on Impacket, designed for BOF-style lateral movement workflows that lets you upload custom service load…☆127Dec 7, 2025Updated 8 months ago