PwnRM is an operator-grade Active Directory post-exploitation platform engineered directly upon the native Microsoft PowerShell Remoting Protocol (MS-PSRP) and WS-Management (MS-WSMV) standards.
☆92Sep 4, 2026Updated last month
Alternatives and similar repositories for PwnRM
Users that are interested in PwnRM are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 5 months ago
- Active Directory forensic framework☆16May 18, 2026Updated 4 months ago
- PowerShell tool to enumerate existing exclusions in Windows Defender as low privileged user☆12Oct 14, 2024Updated last year
- Havoc BOF implementation of BYOVD attack to terminate PPL-protected EDR processes using a signed Microsoft kernel driver.☆39Apr 6, 2026Updated 6 months ago
- An (WIP) EDR Evasion tool for x64 Windows & Linux binaries that utilizes Nanomites, written in Rust.☆35May 8, 2026Updated 5 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Object file loader implemented as a post-ex DLL for asynchronous BOF execution.☆28Jul 23, 2026Updated 2 months ago
- Polymorphic x64 shellcode loader — indirect syscalls, phantom DLL hollowing, call stack spoofing, patchless AMSI/ETW bypass, zero CRT …☆29May 24, 2026Updated 4 months ago
- Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.☆67Nov 14, 2025Updated 10 months ago
- PowerShell & Python tools developed for CTFs and certification exams☆72Sep 24, 2026Updated 2 weeks ago
- Python tool to automatically perform SPN-less RBCD attacks.☆132Jan 7, 2026Updated 9 months ago
- Dumping all keys from a keytab file☆19Dec 1, 2025Updated 10 months ago
- ADAttributeHound is an OpenGraph extension for BloodHound that exports Active Directory custom attributes as node properties.☆23Jun 18, 2026Updated 3 months ago
- Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.☆51Jul 23, 2026Updated 2 months ago
- A modern, fast, and pentester-friendly NFS client built for red teams, security researchers, and anyone who wants full control over remot…☆27Sep 1, 2026Updated last month
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Sliver agents for Mythic☆50Nov 18, 2024Updated last year
- Safe Harbor is a BOF that streamlines process reconnaissance for red team operations by identifying trusted, low-noise targets to maintai…☆81Oct 27, 2025Updated 11 months ago
- Arsenal of modules to beacon postex☆105Mar 13, 2026Updated 6 months ago
- Bof of RegPwn by MDSec☆129Mar 15, 2026Updated 6 months ago
- BOF for extracting Edge credentials from the main browser process.☆51May 5, 2026Updated 5 months ago
- A BOF for lazy people☆24Apr 4, 2024Updated 2 years ago
- Pure PowerShell port of PassTheCert tool to authenticate to an LDAP/S server with a certificate through Schannel☆63Apr 13, 2025Updated last year
- Automated Penetration Testing Mind Map with Artificial Intelligence☆54Jun 29, 2025Updated last year
- Cobalt Strike notifications via NTFY.☆15Sep 24, 2024Updated 2 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- AV Evasion, a Red Team Tool - Fiber, APC, PNG and UUID☆21Sep 7, 2021Updated 5 years ago
- ASPX Web Shell with COFF Loader☆135Mar 10, 2026Updated 6 months ago
- Remote service-staging tool built on Impacket, designed for BOF-style lateral movement workflows that lets you upload custom service load…☆129Dec 7, 2025Updated 10 months ago
- CVE-2020-17103 adapted for C2 with split-binary SYSTEM callback☆46May 20, 2026Updated 4 months ago
- Step through PE functions or shellcode instruction-by-instruction (amd64)☆42May 4, 2026Updated 5 months ago
- Cobalt Strike BOF to freeze EDR/AV processes and dump LSASS using WerFaultSecure.exe PPL bypass☆145Jan 29, 2026Updated 8 months ago
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆107Apr 4, 2026Updated 6 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆117Dec 21, 2025Updated 9 months ago
- An executable that simplifies adding the msds-AllowedToActOnBehalfOfOtherIdentity attribute for RBCD☆49Mar 10, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Next-Generation BOF Template | BOF Linter | Obj Rewriter☆60Dec 4, 2025Updated 10 months ago
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆35Jul 23, 2026Updated 2 months ago
- ☆23Jul 6, 2025Updated last year
- An MCP Server for Pwndoc (Pentesting Reporting Tool)☆43Jan 23, 2026Updated 8 months ago
- PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.☆75Oct 22, 2025Updated 11 months ago
- Tool to enumerate privileged Scheduled Tasks on Remote Systems☆311Aug 29, 2026Updated last month
- Windows SSH Misconfiguration Discovery Tool - Map lateral movement paths through misconfigured SSH services in Active Directory environme…☆93May 11, 2026Updated 4 months ago