mirror of
https://github.com/mthcht/ThreatHunting-Keywords
synced 2026-06-08 16:12:28 +00:00
755048bf5e
very few additions and some corrections
1.2 MiB
1.2 MiB
| 1 | keyword | metadata_keyword_regex | metadata_keyword_type | metadata_tool | metadata_description | metadata_tool_techniques | metadata_tool_tactics | metadata_malwares_name | metadata_groups_name | metadata_category | metadata_link | metadata_enable_endpoint_detection | metadata_enable_proxy_detection | metadata_tags | metadata_comment | metadata_severity_score | metadata_popularity_score | metadata_github_stars | metadata_github_forks | metadata_github_updated_at | metadata_github_created_at | metadata_entry_id |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2 | * "Sniffy boi sniffin"* | .{0,1000}\s\"Sniffy\sboi\ssniffin\".{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 0 | #content | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 15 |
| 3 | * $lse_find_opts * | .{0,1000}\s\$lse_find_opts\s.{0,1000} | offensive_tool_keyword | linux-smart-enumeration | Linux enumeration tool for privilege escalation and discovery | T1087.004 - T1016 - T1548.001 - T1046 | TA0007 - TA0004 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/diego-treitos/linux-smart-enumeration | 1 | 0 | #linux | N/A | 9 | 10 | 3575 | 584 | 2023-12-25T14:46:47Z | 2019-02-13T11:02:21Z | 20 |
| 4 | * /potato.local* | .{0,1000}\s\/potato\.local.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | N/A | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 88 |
| 5 | * /s4uproxytarget:* /s4utransitiedservices:* | .{0,1000}\s\/s4uproxytarget\:.{0,1000}\s\/s4utransitiedservices\:.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 97 |
| 6 | * = "KRBRELAYUP"* | .{0,1000}\s\=\s\"KRBRELAYUP\".{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 140 |
| 7 | * = "NeverGonnaRunAroundAndDesertYou"* | .{0,1000}\s\=\s\"NeverGonnaRunAroundAndDesertYou\".{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/cube0x0/CVE-2021-1675 | 1 | 0 | #content | N/A | 10 | 10 | 1879 | 582 | 2021-07-20T15:28:13Z | 2021-06-29T17:24:14Z | 141 |
| 8 | * ACEshark.py* | .{0,1000}\sACEshark\.py.{0,1000} | offensive_tool_keyword | ACEshark | uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries | T1058 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/t3l3machus/ACEshark | 1 | 0 | N/A | N/A | 6 | 2 | 109 | 19 | 2025-01-15T07:01:48Z | 2024-12-28T10:42:29Z | 179 |
| 9 | * ADAPE.ps1* | .{0,1000}\sADAPE\.ps1.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 0 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 198 |
| 10 | * addcomputer_LDAP_spn.py* | .{0,1000}\saddcomputer_LDAP_spn\.py.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 211 |
| 11 | * addcomputer_with_spns.py * | .{0,1000}\saddcomputer_with_spns\.py\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 212 |
| 12 | * adm2sys.py* | .{0,1000}\sadm2sys\.py.{0,1000} | offensive_tool_keyword | PyExec | This is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses. | T1134 - T1055 - T1548.002 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/OlivierLaflamme/PyExec | 1 | 0 | N/A | N/A | 9 | 1 | 11 | 7 | 2019-09-11T13:56:04Z | 2019-09-11T13:54:15Z | 230 |
| 13 | * audit AlwaysInstallElevated* | .{0,1000}\saudit\sAlwaysInstallElevated.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 320 |
| 14 | * audit CachedGPPPassword* | .{0,1000}\saudit\sCachedGPPPassword.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 321 |
| 15 | * audit DomainGPPPassword* | .{0,1000}\saudit\sDomainGPPPassword.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 322 |
| 16 | * audit HijackablePaths* | .{0,1000}\saudit\sHijackablePaths.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 323 |
| 17 | * audit McAfeeSitelistFiles* | .{0,1000}\saudit\sMcAfeeSitelistFiles.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 324 |
| 18 | * audit ModifiableScheduledTask* | .{0,1000}\saudit\sModifiableScheduledTask.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 325 |
| 19 | * audit ModifiableServiceBinaries* | .{0,1000}\saudit\sModifiableServiceBinaries.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 326 |
| 20 | * audit ModifiableServiceRegistryKeys* | .{0,1000}\saudit\sModifiableServiceRegistryKeys.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 327 |
| 21 | * audit ModifiableServices* | .{0,1000}\saudit\sModifiableServices.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 328 |
| 22 | * audit ProcessDLLHijack* | .{0,1000}\saudit\sProcessDLLHijack.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 329 |
| 23 | * audit RegistryAutoLogons* | .{0,1000}\saudit\sRegistryAutoLogons.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 330 |
| 24 | * audit RegistryAutoruns* | .{0,1000}\saudit\sRegistryAutoruns.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 331 |
| 25 | * audit TokenPrivileges* | .{0,1000}\saudit\sTokenPrivileges.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 332 |
| 26 | * audit UnattendedInstallFiles* | .{0,1000}\saudit\sUnattendedInstallFiles.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 333 |
| 27 | * audit UnquotedServicePath* | .{0,1000}\saudit\sUnquotedServicePath.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 334 |
| 28 | * BadWindowsService.exe* | .{0,1000}\sBadWindowsService\.exe.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 0 | N/A | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 370 |
| 29 | * Bat-Potato.bat* | .{0,1000}\sBat\-Potato\.bat.{0,1000} | offensive_tool_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 0 | N/A | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 377 |
| 30 | * beRoot.exe* | .{0,1000}\sbeRoot\.exe.{0,1000} | offensive_tool_keyword | BeRoot | Privilege Escalation Project - Windows / Linux / Mac | T1068 - T1055 - T1078 - T1548 - T1003 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/AlessandroZ/BeRoot | 1 | 0 | #linux | N/A | 10 | 10 | 2523 | 459 | 2024-10-04T11:54:01Z | 2017-04-14T12:47:31Z | 383 |
| 31 | * beRoot.py* | .{0,1000}\sbeRoot\.py.{0,1000} | offensive_tool_keyword | BeRoot | Privilege Escalation Project - Windows / Linux / Mac | T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/AlessandroZ/BeRoot | 1 | 0 | #linux | N/A | 10 | 10 | 2523 | 459 | 2024-10-04T11:54:01Z | 2017-04-14T12:47:31Z | 384 |
| 32 | * BITSInject.py* | .{0,1000}\sBITSInject\.py.{0,1000} | offensive_tool_keyword | BITSInject | A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account | T1197 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/SafeBreach-Labs/BITSInject | 1 | 0 | N/A | N/A | 8 | 1 | 99 | 18 | 2019-08-24T22:02:12Z | 2017-07-03T12:39:38Z | 396 |
| 33 | * BITSJobPayloads.py* | .{0,1000}\sBITSJobPayloads\.py.{0,1000} | offensive_tool_keyword | BITSInject | A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account | T1197 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/SafeBreach-Labs/BITSInject | 1 | 0 | N/A | N/A | 8 | 1 | 99 | 18 | 2019-08-24T22:02:12Z | 2017-07-03T12:39:38Z | 397 |
| 34 | * C:\temp\w.log* | .{0,1000}\sC\:\\temp\\w\.log.{0,1000} | offensive_tool_keyword | SharpEfsPotato | Local privilege escalation from SeImpersonatePrivilege using EfsRpc. | T1548.002 - T1134.002 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/bugch3ck/SharpEfsPotato | 1 | 0 | N/A | N/A | 10 | 4 | 317 | 46 | 2022-10-17T12:35:06Z | 2022-10-17T12:20:47Z | 520 |
| 35 | * Clone_Token /Process:* /Command:* | .{0,1000}\sClone_Token\s\/Process\:.{0,1000}\s\/Command\:.{0,1000} | offensive_tool_keyword | Tokenvator | A tool to elevate privilege with Windows Tokens | T1134 - T1078 | TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/0xbadjuju/Tokenvator | 1 | 0 | N/A | N/A | N/A | 10 | 1038 | 201 | 2023-10-06T13:17:05Z | 2017-12-08T01:29:11Z | 611 |
| 36 | * CMSFRottenPotato::* | .{0,1000}\sCMSFRottenPotato\:\:.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | #content | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 619 |
| 37 | * CoercedPotato.cpp* | .{0,1000}\sCoercedPotato\.cpp.{0,1000} | offensive_tool_keyword | CoercedPotatoRDLL | Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege | T1055 - T1134 - T1548 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/sokaRepo/CoercedPotatoRDLL | 1 | 0 | N/A | N/A | 10 | 3 | 204 | 31 | 2023-11-23T18:58:41Z | 2023-11-23T13:22:38Z | 628 |
| 38 | * --config * --just-clean --cleaning-file * | .{0,1000}\s\-\-config\s.{0,1000}\s\-\-just\-clean\s\-\-cleaning\-file\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 669 |
| 39 | * -dc-host * -spn * -impersonate * | .{0,1000}\s\-dc\-host\s.{0,1000}\s\-spn\s.{0,1000}\s\-impersonate\s.{0,1000} | offensive_tool_keyword | Pachine | Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation) | T1068 - T1078 - T1059.006 | TA0003 - TA0004 - TA0002 | N/A | Black Basta | Privilege Escalation | https://github.com/ly4k/Pachine | 1 | 0 | N/A | N/A | 8 | 3 | 275 | 37 | 2022-01-13T12:35:19Z | 2021-12-13T23:15:05Z | 787 |
| 40 | * -dll add_user.dll -dir * | .{0,1000}\s\-dll\sadd_user\.dll\s\-dir\s.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 865 | |
| 41 | * -dll add_user.dll -printer * | .{0,1000}\s\-dll\sadd_user\.dll\s\-printer\s.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 866 | |
| 42 | * --exploit=DCOM* | .{0,1000}\s\-\-exploit\=DCOM.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 1134 |
| 43 | * --exploit=DCOM* | .{0,1000}\s\-\-exploit\=DCOM.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 1135 |
| 44 | * --exploit=EfsRpc* | .{0,1000}\s\-\-exploit\=EfsRpc.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 1136 |
| 45 | * --exploit=PrintSpoofer* | .{0,1000}\s\-\-exploit\=PrintSpoofer.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 1137 |
| 46 | * --exploit=WinRM* | .{0,1000}\s\-\-exploit\=WinRM.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 1138 |
| 47 | * --ForceShadowCred* | .{0,1000}\s\-\-ForceShadowCred.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 1213 |
| 48 | * Get-ServiceFromRegistry -Name Spooler* | .{0,1000}\sGet\-ServiceFromRegistry\s\-Name\sSpooler.{0,1000} | offensive_tool_keyword | PrivescCheck | Privilege Escalation Enumeration Script for Windows | T1053 - T1088 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrivescCheck | 1 | 0 | N/A | N/A | 10 | 10 | 3230 | 460 | 2025-03-05T14:44:17Z | 2020-01-16T12:28:10Z | 1330 |
| 49 | * gtfobin_update.py* | .{0,1000}\sgtfobin_update\.py.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | N/A | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 1393 |
| 50 | * gtfonow.py* | .{0,1000}\sgtfonow\.py.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | N/A | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 1394 |
| 51 | * -hashes lm:nt -gpo-id * -powershell * | .{0,1000}\s\-hashes\slm\:nt\s\-gpo\-id\s.{0,1000}\s\-powershell\s.{0,1000} | offensive_tool_keyword | pyGPOAbuse | python implementation of SharpGPOAbuse | T1566.001 - T1059.006 - T1112 | TA0001 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/Hackndo/pyGPOAbuse | 1 | 0 | N/A | N/A | 8 | 5 | 416 | 48 | 2024-02-18T19:23:57Z | 2020-05-10T21:21:27Z | 1413 |
| 52 | * havoc_bof.py* | .{0,1000}\shavoc_bof\.py.{0,1000} | offensive_tool_keyword | PoolPartyBof | A beacon object file implementation of PoolParty Process Injection Technique | T1055.011 - T1055 - T1620 | TA0005 | N/A | Black Basta | Privilege Escalation | https://github.com/0xEr3bus/PoolPartyBof | 1 | 0 | N/A | N/A | 10 | 4 | 380 | 44 | 2023-12-21T19:00:20Z | 2023-12-11T19:28:20Z | 1417 |
| 53 | * import LinpeasBaseBuilder* | .{0,1000}\simport\sLinpeasBaseBuilder.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 1642 |
| 54 | * import LinpeasBuilder* | .{0,1000}\simport\sLinpeasBuilder.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 1643 |
| 55 | * import PEASLoaded* | .{0,1000}\simport\sPEASLoaded.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 1644 |
| 56 | * import PEASRecord* | .{0,1000}\simport\sPEASRecord.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 1645 |
| 57 | * install autobloody* | .{0,1000}\sinstall\sautobloody.{0,1000} | offensive_tool_keyword | autobloody | Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/CravateRouge/autobloody | 1 | 0 | #linux | N/A | 10 | 6 | 545 | 54 | 2024-11-14T13:07:54Z | 2022-09-07T13:34:30Z | 1676 |
| 58 | * Invoke-Nightmare* | .{0,1000}\sInvoke\-Nightmare.{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/calebstewart/CVE-2021-1675 | 1 | 0 | N/A | N/A | 10 | 10 | 1049 | 230 | 2021-07-05T08:54:06Z | 2021-07-01T23:45:58Z | 1748 |
| 59 | * JuicyPotatoNG* | .{0,1000}\sJuicyPotatoNG.{0,1000} | offensive_tool_keyword | JuicyPotatoNG | Another Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | FoxKitten - APT33 - Volatile Cedar - Sandworm | Privilege Escalation | https://github.com/antonioCoco/JuicyPotatoNG | 1 | 0 | N/A | N/A | 10 | 9 | 844 | 101 | 2022-11-12T01:48:39Z | 2022-09-21T17:08:35Z | 1829 |
| 60 | * libpwn.c* | .{0,1000}\slibpwn\.c.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | N/A | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 1950 |
| 61 | * libpwn.so* | .{0,1000}\slibpwn\.so.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | N/A | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 1951 |
| 62 | * linpeas.sh * | .{0,1000}\slinpeas\.sh\s.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | #linux | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 1953 |
| 63 | * -linpeas=http://* | .{0,1000}\s\-linpeas\=http\:\/\/.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 1955 |
| 64 | * -linpeas=http://127.0.0.1/linpeas.sh* | .{0,1000}\s\-linpeas\=http\:\/\/127\.0\.0\.1\/linpeas\.sh.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 1956 |
| 65 | * MakeMeEnterpriseAdmin.ps1 | .{0,1000}\sMakeMeEnterpriseAdmin\.ps1 | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 2112 |
| 66 | * --maketoken --username * --password * --domain * | .{0,1000}\s\-\-maketoken\s\-\-username\s.{0,1000}\s\-\-password\s.{0,1000}\s\-\-domain\s.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 2113 |
| 67 | * -name .htpasswd* | .{0,1000}\s\-name\s\.htpasswd.{0,1000} | offensive_tool_keyword | linuxprivchecker | search for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploits | T1210.001 - T1082 - T1088 - T1547.001 | TA0002 - TA0004 - TA0006 - TA0007 - TA0008 | N/A | N/A | Privilege Escalation | https://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py | 1 | 0 | #linux | N/A | 7 | 10 | 1645 | 524 | 2022-01-31T10:32:08Z | 2016-04-19T13:31:46Z | 2243 |
| 68 | * namespace SharpPrintNightmare* | .{0,1000}\snamespace\sSharpPrintNightmare.{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/cube0x0/CVE-2021-1675 | 1 | 0 | #content | N/A | 10 | 10 | 1879 | 582 | 2021-07-20T15:28:13Z | 2021-06-29T17:24:14Z | 2252 |
| 69 | * ouned_smbserver.py* | .{0,1000}\souned_smbserver\.py.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 2465 |
| 70 | * -p 4444 -c powershell* | .{0,1000}\s\-p\s4444\s\-c\spowershell.{0,1000} | offensive_tool_keyword | RustPotato | A Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privileges | T1134.001 - T1055.011 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/emdnaia/RustPotato | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2025-01-06T18:10:17Z | 2025-01-06T19:44:57Z | 2483 |
| 71 | * -p 4644 -n mal* | .{0,1000}\s\-p\s4644\s\-n\smal.{0,1000} | offensive_tool_keyword | Gotato | Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported. | T1003.003 - T1056.002 - T1550.001 - T1090 | TA0005 - TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/iammaguire/Gotato | 1 | 0 | N/A | N/A | 9 | 2 | 112 | 16 | 2021-06-07T21:19:58Z | 2021-06-05T22:32:48Z | 2484 |
| 72 | * -perm -2000 -o -perm -4000* | .{0,1000}\s\-perm\s\-2000\s\-o\s\-perm\s\-4000.{0,1000} | offensive_tool_keyword | linuxprivchecker | search for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploits | T1210.001 - T1082 - T1088 - T1547.001 | TA0002 - TA0004 - TA0006 - TA0007 - TA0008 | N/A | N/A | Privilege Escalation | https://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py | 1 | 0 | #linux | N/A | 7 | 10 | 1645 | 524 | 2022-01-31T10:32:08Z | 2016-04-19T13:31:46Z | 2583 |
| 73 | * PetitPotato.cpp* | .{0,1000}\sPetitPotato\.cpp.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 2594 |
| 74 | * Powermad.ps1* | .{0,1000}\sPowermad\.ps1.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 2651 |
| 75 | * printing the golden data, format inspired by Responder :D* | .{0,1000}\sprinting\sthe\sgolden\sdata,\sformat\sinspired\sby\sResponder\s\:D.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 2669 |
| 76 | * privesc.ps1* | .{0,1000}\sprivesc\.ps1.{0,1000} | offensive_tool_keyword | Privesc | Windows PowerShell script that finds misconfiguration issues which can lead to privilege escalation | T1068 - T1548 - T1082 - T1078 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/enjoiz/Privesc | 1 | 0 | N/A | N/A | 10 | 6 | 595 | 97 | 2024-12-01T15:24:41Z | 2015-11-19T13:22:01Z | 2673 |
| 77 | * Process spawned with stolen token!* | .{0,1000}\sProcess\sspawned\swith\sstolen\stoken!.{0,1000} | offensive_tool_keyword | Gotato | Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported. | T1003.003 - T1056.002 - T1550.001 - T1090 | TA0005 - TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/iammaguire/Gotato | 1 | 0 | N/A | N/A | 9 | 2 | 112 | 16 | 2021-06-07T21:19:58Z | 2021-06-05T22:32:48Z | 2677 |
| 78 | * psgetsys.ps1* | .{0,1000}\spsgetsys\.ps1.{0,1000} | offensive_tool_keyword | psgetsystem | getsystem via parent process using ps1 & embeded c# | T1134 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/psgetsystem | 1 | 0 | N/A | N/A | 10 | 5 | 406 | 88 | 2023-10-26T07:13:08Z | 2018-02-02T11:28:22Z | 2694 |
| 79 | * rasman.exe* | .{0,1000}\srasman\.exe.{0,1000} | offensive_tool_keyword | RasmanPotato | using RasMan service for privilege escalation | T1548.002 - T1055.002 - T1055.001 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/crisprss/RasmanPotato | 1 | 0 | N/A | N/A | 10 | 4 | 371 | 53 | 2023-02-06T10:27:41Z | 2023-02-06T09:41:51Z | 2770 |
| 80 | * Remotely download Trojan files to * | .{0,1000}\sRemotely\sdownload\sTrojan\sfiles\sto\s.{0,1000} | offensive_tool_keyword | Telemetry | Abusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges. | T1053 - T1547 - T1059 | TA0003 - TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Imanfeng/Telemetry | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 13 | 2020-07-02T09:41:27Z | 2020-06-24T16:30:44Z | 2842 |
| 81 | * RemotePotato0.zip* | .{0,1000}\sRemotePotato0\.zip.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 2849 |
| 82 | * -Report PrivescCheck_* | .{0,1000}\s\-Report\sPrivescCheck_.{0,1000} | offensive_tool_keyword | PrivescCheck | Privilege Escalation Enumeration Script for Windows | T1053 - T1088 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrivescCheck | 1 | 0 | N/A | N/A | 10 | 10 | 3230 | 460 | 2025-03-05T14:44:17Z | 2020-01-16T12:28:10Z | 2861 |
| 83 | * -Report PrivescCheck_* | .{0,1000}\s\-Report\sPrivescCheck_.{0,1000} | offensive_tool_keyword | PrivescCheck | Privilege Escalation Enumeration Script for Windows | T1053 - T1088 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrivescCheck | 1 | 0 | N/A | N/A | 10 | 10 | 3230 | 460 | 2025-03-05T14:44:17Z | 2020-01-16T12:28:10Z | 2862 |
| 84 | * --revshell* | .{0,1000}\s\-\-revshell.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 0 | N/A | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 2885 |
| 85 | * RogueOxidResolver must be run remotely* | .{0,1000}\sRogueOxidResolver\smust\sbe\srun\sremotely.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 2914 |
| 86 | * rwf.py * | .{0,1000}\srwf\.py\s.{0,1000} | offensive_tool_keyword | VDR | Vulnerable driver research tool - result and exploit PoCs | T1547.009 - T1210 - T1068 - T1055 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/TakahiroHaruyama/VDR | 1 | 0 | N/A | N/A | 10 | 2 | 192 | 29 | 2023-11-01T00:06:55Z | 2023-10-23T08:34:44Z | 2955 |
| 87 | * -s 127.0.0.1 -e * -a connect -u ntlm* | .{0,1000}\s\-s\s127\.0\.0\.1\s\-e\s.{0,1000}\s\-a\sconnect\s\-u\sntlm.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 2964 |
| 88 | * SharpEfsPotato* | .{0,1000}\sSharpEfsPotato.{0,1000} | offensive_tool_keyword | SharpEfsPotato | Local privilege escalation from SeImpersonatePrivilege using EfsRpc. | T1548.002 - T1134.002 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/bugch3ck/SharpEfsPotato | 1 | 0 | N/A | N/A | 10 | 4 | 317 | 46 | 2022-10-17T12:35:06Z | 2022-10-17T12:20:47Z | 3086 |
| 89 | * SharpElevator.exe* | .{0,1000}\sSharpElevator\.exe.{0,1000} | offensive_tool_keyword | SharpElevator | SharpElevator is a C# implementation of Elevator for UAC bypass | T1548.002 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/SharpElevator | 1 | 0 | N/A | N/A | 10 | 1 | 51 | 12 | 2022-08-31T18:09:10Z | 2022-08-29T19:52:53Z | 3087 |
| 90 | * spawn C:\Windows\Temp\beacon.exe* | .{0,1000}\sspawn\sC\:\\Windows\\Temp\\beacon\.exe.{0,1000} | offensive_tool_keyword | CoercedPotatoRDLL | Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege | T1055 - T1134 - T1548 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/sokaRepo/CoercedPotatoRDLL | 1 | 0 | N/A | N/A | 10 | 3 | 204 | 31 | 2023-11-23T18:58:41Z | 2023-11-23T13:22:38Z | 3300 |
| 91 | * spawn C:\Windows\Temp\loader.exe* | .{0,1000}\sspawn\sC\:\\Windows\\Temp\\loader\.exe.{0,1000} | offensive_tool_keyword | CoercedPotatoRDLL | Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege | T1055 - T1134 - T1548 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/sokaRepo/CoercedPotatoRDLL | 1 | 0 | N/A | N/A | 10 | 3 | 204 | 31 | 2023-11-23T18:58:41Z | 2023-11-23T13:22:38Z | 3301 |
| 92 | * spawn -m adcs -d * -dc * | .{0,1000}\sspawn\s\-m\sadcs\s\-d\s.{0,1000}\s\-dc\s.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 3302 |
| 93 | * spawn -m shadowcred -d * | .{0,1000}\sspawn\s\-m\sshadowcred\s\-d\s.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 3303 |
| 94 | * --spoofppid --ppid * | .{0,1000}\s\-\-spoofppid\s\-\-ppid\s.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 3316 |
| 95 | * SpoolFool.ps1* | .{0,1000}\sSpoolFool\.ps1.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 3318 | |
| 96 | * -Steal -ProcessID * | .{0,1000}\s\-Steal\s\-ProcessID\s.{0,1000} | offensive_tool_keyword | Token-Impersonation | Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required) | T1134.001 - T1134.002 | TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/Leo4j/Token-Impersonation | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2024-03-20T17:07:13Z | 2023-11-02T10:46:24Z | 3404 |
| 97 | * steal_token /process:* /command:* | .{0,1000}\ssteal_token\s\/process\:.{0,1000}\s\/command\:.{0,1000} | offensive_tool_keyword | Tokenvator | A tool to elevate privilege with Windows Tokens | T1134 - T1078 | TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/0xbadjuju/Tokenvator | 1 | 0 | N/A | N/A | N/A | 10 | 1038 | 201 | 2023-10-06T13:17:05Z | 2017-12-08T01:29:11Z | 3405 |
| 98 | * Sweetpotato.exe* | .{0,1000}\sSweetpotato\.exe.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 3437 |
| 99 | * -t BindShell -p *pwned\pipe\spoolss* | .{0,1000}\s\-t\sBindShell\s\-p\s.{0,1000}pwned\\pipe\\spoolss.{0,1000} | offensive_tool_keyword | MultiPotato | get SYSTEM via SeImpersonate privileges | T1548.002 - T1134.002 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S3cur3Th1sSh1t/MultiPotato | 1 | 0 | N/A | N/A | 10 | 6 | 518 | 92 | 2021-11-20T16:20:23Z | 2021-11-19T15:50:55Z | 3450 |
| 100 | * -t CreateProcessAsUserW -p *pwned\pipe\spoolss* -e *.exe* | .{0,1000}\s\-t\sCreateProcessAsUserW\s\-p\s.{0,1000}pwned\\pipe\\spoolss.{0,1000}\s\-e\s.{0,1000}\.exe.{0,1000} | offensive_tool_keyword | MultiPotato | get SYSTEM via SeImpersonate privileges | T1548.002 - T1134.002 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S3cur3Th1sSh1t/MultiPotato | 1 | 0 | N/A | N/A | 10 | 6 | 518 | 92 | 2021-11-20T16:20:23Z | 2021-11-19T15:50:55Z | 3452 |
| 101 | * test_privesc.py* | .{0,1000}\stest_privesc\.py.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | N/A | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 3504 |
| 102 | * Token-Impersonation.ps1* | .{0,1000}\sToken\-Impersonation\.ps1.{0,1000} | offensive_tool_keyword | Token-Impersonation | Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required) | T1134.001 - T1134.002 | TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/Leo4j/Token-Impersonation | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2024-03-20T17:07:13Z | 2023-11-02T10:46:24Z | 3534 |
| 103 | * tokenvator * | .{0,1000}\stokenvator\s.{0,1000} | offensive_tool_keyword | Tokenvator | A tool to elevate privilege with Windows Tokens | T1134 - T1078 | TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/0xbadjuju/Tokenvator | 1 | 0 | N/A | N/A | N/A | 10 | 1038 | 201 | 2023-10-06T13:17:05Z | 2017-12-08T01:29:11Z | 3538 |
| 104 | * UAC-TokenMagic.ps1* | .{0,1000}\sUAC\-TokenMagic\.ps1.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 3606 |
| 105 | * WinPEAS - Windows local Privilege Escalation Awesome Script* | .{0,1000}\sWinPEAS\s\-\sWindows\slocal\sPrivilege\sEscalation\sAwesome\sScript.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 3727 |
| 106 | * winPEAS.ps1* | .{0,1000}\swinPEAS\.ps1.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 3729 |
| 107 | * You need to have an elevated context to dump other users' Kerberos tickets :(* | .{0,1000}\sYou\sneed\sto\shave\san\selevated\scontext\sto\sdump\sother\susers\'\sKerberos\stickets\s\:\(.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 3785 |
| 108 | *!! >> if you did this while in the root shell, the terminal will be messed up << !!* | .{0,1000}!!\s\>\>\sif\syou\sdid\sthis\swhile\sin\sthe\sroot\sshell,\sthe\sterminal\swill\sbe\smessed\sup\s\<\<\s!!.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 3795 |
| 109 | *"localadmin123!"* | .{0,1000}\"localadmin123!\".{0,1000} | offensive_tool_keyword | LocalAdminSharp | .NET executable to use when dealing with privilege escalation on Windows to gain local administrator access | T1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/notdodo/LocalAdminSharp | 1 | 0 | N/A | N/A | 10 | 2 | 157 | 17 | 2022-11-01T17:45:43Z | 2022-01-01T10:35:09Z | 3851 |
| 110 | *"UACBypassedService"* | .{0,1000}\"UACBypassedService\".{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 3878 |
| 111 | *#include "RogueOxidResolver.h* | .{0,1000}\#include\s\"RogueOxidResolver\.h.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 3931 |
| 112 | *$DriverName = "Totally Not Malicious"* | .{0,1000}\$DriverName\s\=\s\"Totally\sNot\sMalicious\".{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/calebstewart/CVE-2021-1675 | 1 | 0 | #content | N/A | 10 | 10 | 1049 | 230 | 2021-07-05T08:54:06Z | 2021-07-01T23:45:58Z | 3955 |
| 113 | *$Kerberoast* | .{0,1000}\$Kerberoast.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 0 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 3995 |
| 114 | *$LolDriversVulnerable* | .{0,1000}\$LolDriversVulnerable.{0,1000} | offensive_tool_keyword | PrivescCheck | Privilege Escalation Enumeration Script for Windows | T1053 - T1088 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrivescCheck | 1 | 0 | N/A | N/A | 10 | 10 | 3230 | 460 | 2025-03-05T14:44:17Z | 2020-01-16T12:28:10Z | 3997 |
| 115 | *$StealToken* | .{0,1000}\$StealToken.{0,1000} | offensive_tool_keyword | Token-Impersonation | Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required) | T1134.001 - T1134.002 | TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/Leo4j/Token-Impersonation | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2024-03-20T17:07:13Z | 2023-11-02T10:46:24Z | 4019 |
| 116 | *(msds-supportedencryptiontypes=0)(msds-supportedencryptiontypes:1.2.840.113556.1.4.803:=4)))* | .{0,1000}\(msds\-supportedencryptiontypes\=0\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.803\:\=4\)\)\).{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 4083 |
| 117 | *./lse.sh* | .{0,1000}\.\/lse\.sh.{0,1000} | offensive_tool_keyword | linux-smart-enumeration | Linux enumeration tool for privilege escalation and discovery | T1087.004 - T1016 - T1548.001 - T1046 | TA0007 - TA0004 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/diego-treitos/linux-smart-enumeration | 1 | 0 | #linux | N/A | 9 | 10 | 3575 | 584 | 2023-12-25T14:46:47Z | 2019-02-13T11:02:21Z | 4165 |
| 118 | *./pachine.py* | .{0,1000}\.\/pachine\.py.{0,1000} | offensive_tool_keyword | Pachine | Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation) | T1068 - T1078 - T1059.006 | TA0003 - TA0004 - TA0002 | N/A | Black Basta | Privilege Escalation | https://github.com/ly4k/Pachine | 1 | 0 | #linux | N/A | 8 | 3 | 275 | 37 | 2022-01-13T12:35:19Z | 2021-12-13T23:15:05Z | 4179 |
| 119 | *./peass.rb* | .{0,1000}\.\/peass\.rb.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #linux | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 4182 |
| 120 | *./rwf.py* | .{0,1000}\.\/rwf\.py.{0,1000} | offensive_tool_keyword | VDR | Vulnerable driver research tool - result and exploit PoCs | T1547.009 - T1210 - T1068 - T1055 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/TakahiroHaruyama/VDR | 1 | 0 | #linux | N/A | 10 | 2 | 192 | 29 | 2023-11-01T00:06:55Z | 2023-10-23T08:34:44Z | 4196 |
| 121 | *.ACEshark.log* | .{0,1000}\.ACEshark\.log.{0,1000} | offensive_tool_keyword | ACEshark | uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries | T1058 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/t3l3machus/ACEshark | 1 | 0 | #logfile | N/A | 6 | 2 | 109 | 19 | 2025-01-15T07:01:48Z | 2024-12-28T10:42:29Z | 4238 |
| 122 | *.exe -lolbas log* | .{0,1000}\.exe\s\s\-lolbas\slog.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 4324 |
| 123 | *.exe /i /s cmd * | .{0,1000}\.exe\s\/i\s\/s\scmd\s.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4336 |
| 124 | *.exe /i /s cmd.exe* | .{0,1000}\.exe\s\/i\s\/s\scmd\.exe.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4337 |
| 125 | *.exe /i /s powershell* | .{0,1000}\.exe\s\/i\s\/s\spowershell.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4338 |
| 126 | *.exe /i /s pwsh* | .{0,1000}\.exe\s\/i\s\/s\spwsh.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4339 |
| 127 | *.exe /s /i cmd.exe* | .{0,1000}\.exe\s\/s\s\/i\scmd\.exe.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4344 |
| 128 | *.exe /s /i powershell* | .{0,1000}\.exe\s\/s\s\/i\spowershell.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4345 |
| 129 | *.exe /s /i pwsh* | .{0,1000}\.exe\s\/s\s\/i\spwsh.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4346 |
| 130 | *.exe 3 cmd* | .{0,1000}\.exe\s3\scmd.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 4349 |
| 131 | *.exe --adcs * --remote * | .{0,1000}\.exe\s\-\-adcs\s.{0,1000}\s\-\-remote\s.{0,1000} | offensive_tool_keyword | ADCSPwn | A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service | T1550.002 - T1078.003 - T1110.003 - T1649 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/bats3c/ADCSPwn | 1 | 0 | N/A | N/A | 10 | 9 | 838 | 127 | 2023-03-20T20:30:40Z | 2021-07-30T15:04:41Z | 4374 |
| 132 | *.exe AlwaysInstallElevated* | .{0,1000}\.exe\sAlwaysInstallElevated.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4375 |
| 133 | *.exe audit ModifiableServices* | .{0,1000}\.exe\saudit\sModifiableServices.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4388 |
| 134 | *.exe CachedGPPPassword* | .{0,1000}\.exe\sCachedGPPPassword.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4399 |
| 135 | *.exe -cmd "cmd /c whoami"* | .{0,1000}\.exe\s\-cmd\s\"cmd\s\/c\swhoami\".{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 4405 |
| 136 | *.exe -d 1 -c cmd.exe* | .{0,1000}\.exe\s\-d\s1\s\-c\scmd\.exe.{0,1000} | offensive_tool_keyword | printspoofer | Abusing impersonation privileges through the Printer Bug | T1134 - T1003 - T1055 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrintSpoofer | 1 | 0 | N/A | N/A | 10 | 10 | 1971 | 342 | 2020-09-10T17:49:41Z | 2020-04-28T08:26:29Z | 4420 |
| 137 | *.exe -d 3 -c *powershell -ep bypass* | .{0,1000}\.exe\s\-d\s3\s\-c\s.{0,1000}powershell\s\-ep\sbypass.{0,1000} | offensive_tool_keyword | printspoofer | Abusing Impersonation Privileges on Windows 10 and Server 2019 | T1548.002 - T1055.001 - T1055.002 | TA0005 - TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrintSpoofer | 1 | 0 | N/A | N/A | 10 | 10 | 1971 | 342 | 2020-09-10T17:49:41Z | 2020-04-28T08:26:29Z | 4421 |
| 138 | *.exe DomainGPPPassword* | .{0,1000}\.exe\sDomainGPPPassword.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4426 |
| 139 | *.exe --exec --pid * --prog *cmd.exe* | .{0,1000}\.exe\s\-\-exec\s\-\-pid\s.{0,1000}\s\-\-prog\s.{0,1000}cmd\.exe.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 4441 |
| 140 | *.exe HijackablePaths* | .{0,1000}\.exe\sHijackablePaths.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4467 |
| 141 | *.exe -i -c powershell -e netlogon* | .{0,1000}\.exe\s\-i\s\-c\spowershell\s\-e\snetlogon.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 4469 |
| 142 | *.exe -i -c powershell.exe* | .{0,1000}\.exe\s\-i\s\-c\spowershell\.exe.{0,1000} | offensive_tool_keyword | printspoofer | Abusing impersonation privileges through the Printer Bug | T1134 - T1003 - T1055 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrintSpoofer | 1 | 0 | N/A | N/A | 10 | 10 | 1971 | 342 | 2020-09-10T17:49:41Z | 2020-04-28T08:26:29Z | 4470 |
| 143 | *.exe -i -s cmd * | .{0,1000}\.exe\s\-i\s\-s\scmd\s.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4471 |
| 144 | *.exe -i -s cmd * | .{0,1000}\.exe\s\-i\s\-s\scmd\s.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4472 |
| 145 | *.exe -i -s cmd.exe* | .{0,1000}\.exe\s\-i\s\-s\scmd\.exe.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4473 |
| 146 | *.exe -i -s powershell* | .{0,1000}\.exe\s\-i\s\-s\spowershell.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4474 |
| 147 | *.exe -i -s pwsh* | .{0,1000}\.exe\s\-i\s\-s\spwsh.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4475 |
| 148 | *.exe --impersonate --pid * | .{0,1000}\.exe\s\-\-impersonate\s\-\-pid\s.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 4476 |
| 149 | *.exe krbscm -c *cmd.exe* | .{0,1000}\.exe\skrbscm\s\-c\s.{0,1000}cmd\.exe.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 4511 |
| 150 | *.exe -l * -c {B91D5831-B1BD-4608-8198-D72E155020F7}* | .{0,1000}\.exe\s\-l\s.{0,1000}\s\-c\s\{B91D5831\-B1BD\-4608\-8198\-D72E155020F7\}.{0,1000} | offensive_tool_keyword | JuicyPotatoNG | Another Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | FoxKitten - APT33 - Volatile Cedar - Sandworm | Privilege Escalation | https://github.com/antonioCoco/JuicyPotatoNG | 1 | 0 | N/A | N/A | 10 | 9 | 844 | 101 | 2022-11-12T01:48:39Z | 2022-09-21T17:08:35Z | 4513 |
| 151 | *.exe -l * -c {F7FD3FD6-9994-452D-8DA7-9A8FD87AEEF4} -a* | .{0,1000}\.exe\s\-l\s.{0,1000}\s\-c\s\{F7FD3FD6\-9994\-452D\-8DA7\-9A8FD87AEEF4\}\s\-a.{0,1000} | offensive_tool_keyword | JuicyPotatoNG | Another Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | FoxKitten - APT33 - Volatile Cedar - Sandworm | Privilege Escalation | https://github.com/antonioCoco/JuicyPotatoNG | 1 | 0 | N/A | N/A | 10 | 9 | 844 | 101 | 2022-11-12T01:48:39Z | 2022-09-21T17:08:35Z | 4514 |
| 152 | *.exe -linpeas=* | .{0,1000}\.exe\s\-linpeas\=.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 4517 |
| 153 | *.exe -lolbas* | .{0,1000}\.exe\s\-lolbas.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 4524 |
| 154 | *.exe -m exec -c "whoami /priv* | .{0,1000}\.exe\s\-m\sexec\s\-c\s\"whoami\s\/priv.{0,1000} | offensive_tool_keyword | PrivFu | execute process as NT SERVICE\TrustedInstaller group account | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | TrustExec | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 4525 |
| 155 | *.exe -m exec -s -e S-1-5-20* | .{0,1000}\.exe\s\-m\sexec\s\-s\s\-e\sS\-1\-5\-20.{0,1000} | offensive_tool_keyword | PrivFu | execute process as NT SERVICE\TrustedInstaller group account | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | TrustExec | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 4526 |
| 156 | *.exe -m find -r tcb* | .{0,1000}\.exe\s\-m\sfind\s\-r\stcb.{0,1000} | offensive_tool_keyword | PrivFu | manage user right without secpol.msc | T1059 - T1078 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | UserRightsUtil | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 4527 |
| 157 | *.exe -m sid -l -s S-1-5-18* | .{0,1000}\.exe\s\-m\ssid\s\-l\s\-s\sS\-1\-5\-18.{0,1000} | offensive_tool_keyword | PrivFu | execute process as NT SERVICE\TrustedInstaller group account | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | TrustExec | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 4528 |
| 158 | *.exe McAfeeSitelistFiles* | .{0,1000}\.exe\sMcAfeeSitelistFiles.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4535 |
| 159 | *.exe ModifiableScheduledTask* | .{0,1000}\.exe\sModifiableScheduledTask.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4538 |
| 160 | *.exe ModifiableServiceBinaries* | .{0,1000}\.exe\sModifiableServiceBinaries.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4539 |
| 161 | *.exe ModifiableServiceRegistryKeys* | .{0,1000}\.exe\sModifiableServiceRegistryKeys.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4540 |
| 162 | *.exe ModifiableServices* | .{0,1000}\.exe\sModifiableServices.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4541 |
| 163 | *.exe ProcessDLLHijack* | .{0,1000}\.exe\sProcessDLLHijack.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4573 |
| 164 | *.exe rbcd -m * -p * -c *cmd.exe* | .{0,1000}\.exe\srbcd\s\-m\s.{0,1000}\s\-p\s.{0,1000}\s\-c\s.{0,1000}cmd\.exe.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 4583 |
| 165 | *.exe RegistryAutoLogons* | .{0,1000}\.exe\sRegistryAutoLogons.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4585 |
| 166 | *.exe RegistryAutoruns* | .{0,1000}\.exe\sRegistryAutoruns.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4586 |
| 167 | *.exe relay -Domain * -CreateNewComputerAccount * | .{0,1000}\.exe\srelay\s\-Domain\s.{0,1000}\s\-CreateNewComputerAccount\s.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 4587 |
| 168 | *.exe -s -i cmd.exe* | .{0,1000}\.exe\s\-s\s\-i\scmd\.exe.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4591 |
| 169 | *.exe -s -i powershell* | .{0,1000}\.exe\s\-s\s\-i\spowershell.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4592 |
| 170 | *.exe -s -i pwsh* | .{0,1000}\.exe\s\-s\s\-i\spwsh.{0,1000} | greyware_tool_keyword | psexec | privilege escalation to local system with psexec | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Privilege Escalation | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 4593 |
| 171 | *.exe shadowcred -c * -f* | .{0,1000}\.exe\sshadowcred\s\-c\s.{0,1000}\s\-f.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 4609 |
| 172 | *.exe TokenPrivileges* | .{0,1000}\.exe\sTokenPrivileges.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4630 |
| 173 | *.exe -uac | .{0,1000}\.exe\s\-uac | offensive_tool_keyword | elevationstation | elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative | T1548.002 - T1055 - T1574.002 - T1078.003 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/g3tsyst3m/elevationstation | 1 | 0 | N/A | N/A | N/A | 4 | 368 | 45 | 2023-11-02T23:52:51Z | 2023-06-10T03:30:59Z | 4636 |
| 174 | *.exe UnattendedInstallFiles* | .{0,1000}\.exe\sUnattendedInstallFiles.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4637 |
| 175 | *.exe UnquotedServicePath* | .{0,1000}\.exe\sUnquotedServicePath.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 4638 |
| 176 | *.ps1 -GPP -PView -Kerberoast* | .{0,1000}\.ps1\s\-GPP\s\-PView\s\-Kerberoast.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 0 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 4761 |
| 177 | *.ps1 -PrivEsc* | .{0,1000}\.ps1\s\-PrivEsc.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 0 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 4763 |
| 178 | *.py * --coerce-to * | .{0,1000}\.py\s.{0,1000}\s\-\-coerce\-to\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 4795 |
| 179 | *.py * --just-coerce * | .{0,1000}\.py\s.{0,1000}\s\-\-just\-coerce\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 4798 |
| 180 | *.py -t ldap://* --no-wcf-server --escalate-user * | .{0,1000}\.py\s\-t\sldap\:\/\/.{0,1000}\s\-\-no\-wcf\-server\s\-\-escalate\-user\s.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 4843 |
| 181 | *.server_DoElevationRequest((Get-NtProcess -ProcessId $pid)*"cmd.exe"*C:\"* | .{0,1000}\.server_DoElevationRequest\(\(Get\-NtProcess\s\-ProcessId\s\$pid\).{0,1000}\"cmd\.exe\".{0,1000}C\:\\\".{0,1000} | greyware_tool_keyword | sudo | sudo on windows allowing privilege escalation | T1068 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://www.tiraniddo.dev/2024/02/sudo-on-windows-quick-rundown.html | 1 | 0 | #linux | N/A | 7 | 8 | N/A | N/A | N/A | N/A | 4884 |
| 182 | *.sh *--checksec* | .{0,1000}\.sh\s.{0,1000}\-\-checksec.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 4886 |
| 183 | *.sh *cvelist-file:* | .{0,1000}\.sh\s.{0,1000}cvelist\-file\:.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 4887 |
| 184 | */.ACEshark* | .{0,1000}\/\.ACEshark.{0,1000} | offensive_tool_keyword | ACEshark | uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries | T1058 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/t3l3machus/ACEshark | 1 | 0 | N/A | N/A | 6 | 2 | 109 | 19 | 2025-01-15T07:01:48Z | 2024-12-28T10:42:29Z | 5001 |
| 185 | */ACE_Get-KerberosTicketCache.ps1* | .{0,1000}\/ACE_Get\-KerberosTicketCache\.ps1.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 1 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 5108 |
| 186 | */ACEshark.git* | .{0,1000}\/ACEshark\.git.{0,1000} | offensive_tool_keyword | ACEshark | uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries | T1058 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/t3l3machus/ACEshark | 1 | 1 | N/A | N/A | 6 | 2 | 109 | 19 | 2025-01-15T07:01:48Z | 2024-12-28T10:42:29Z | 5111 |
| 187 | */ACEshark.py* | .{0,1000}\/ACEshark\.py.{0,1000} | offensive_tool_keyword | ACEshark | uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries | T1058 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/t3l3machus/ACEshark | 1 | 1 | N/A | N/A | 6 | 2 | 109 | 19 | 2025-01-15T07:01:48Z | 2024-12-28T10:42:29Z | 5112 |
| 188 | */ADAPE.ps1* | .{0,1000}\/ADAPE\.ps1.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 1 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 5132 |
| 189 | */ADAPE-Script.git* | .{0,1000}\/ADAPE\-Script\.git.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 1 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 5133 |
| 190 | */ADCSPwn.git* | .{0,1000}\/ADCSPwn\.git.{0,1000} | offensive_tool_keyword | ADCSPwn | A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service | T1550.002 - T1078.003 - T1110.003 - T1649 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/bats3c/ADCSPwn | 1 | 1 | N/A | N/A | 10 | 9 | 838 | 127 | 2023-03-20T20:30:40Z | 2021-07-30T15:04:41Z | 5163 |
| 191 | */addcomputer_LDAP_spn.py* | .{0,1000}\/addcomputer_LDAP_spn\.py.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 1 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 5170 |
| 192 | */addcomputer_with_spns.py* | .{0,1000}\/addcomputer_with_spns\.py.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 1 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 5171 |
| 193 | */adm2sys.py* | .{0,1000}\/adm2sys\.py.{0,1000} | offensive_tool_keyword | PyExec | This is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses. | T1134 - T1055 - T1548.002 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/OlivierLaflamme/PyExec | 1 | 1 | N/A | N/A | 9 | 1 | 11 | 7 | 2019-09-11T13:56:04Z | 2019-09-11T13:54:15Z | 5204 |
| 194 | */Admin2Sys.git* | .{0,1000}\/Admin2Sys\.git.{0,1000} | offensive_tool_keyword | Admin2Sys | Admin2Sys it's a C++ malware to escalate privileges from Administrator account to NT AUTORITY SYSTEM | T1055.002 - T1078.003 - T1068 | TA0002 - TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/S12cybersecurity/Admin2Sys | 1 | 1 | N/A | N/A | 10 | 1 | 54 | 19 | 2023-05-01T19:32:41Z | 2023-05-01T18:50:51Z | 5207 |
| 195 | */autobloody.git* | .{0,1000}\/autobloody\.git.{0,1000} | offensive_tool_keyword | autobloody | Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/CravateRouge/autobloody | 1 | 1 | #linux | N/A | 10 | 6 | 545 | 54 | 2024-11-14T13:07:54Z | 2022-09-07T13:34:30Z | 5473 |
| 196 | */autobloody/archive* | .{0,1000}\/autobloody\/archive.{0,1000} | offensive_tool_keyword | autobloody | Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/CravateRouge/autobloody | 1 | 1 | #linux | N/A | 10 | 6 | 545 | 54 | 2024-11-14T13:07:54Z | 2022-09-07T13:34:30Z | 5474 |
| 197 | */BackgroundShell.exe* | .{0,1000}\/BackgroundShell\.exe.{0,1000} | offensive_tool_keyword | PrivFu | SeTcbPrivilege exploitation | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 1 | N/A | PrivFu\PowerOfTcb | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 5532 |
| 198 | */BackupOperatorToDA.git* | .{0,1000}\/BackupOperatorToDA\.git.{0,1000} | offensive_tool_keyword | BackupOperatorToDA | From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller | T1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003 | TA0005 - TA0001 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/mpgn/BackupOperatorToDA | 1 | 1 | N/A | N/A | 10 | 5 | 421 | 53 | 2025-01-04T14:16:46Z | 2022-02-15T20:51:46Z | 5544 |
| 199 | */BadPotato.exe* | .{0,1000}\/BadPotato\.exe.{0,1000} | offensive_tool_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 1 | N/A | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 5551 |
| 200 | */BadPotato.git* | .{0,1000}\/BadPotato\.git.{0,1000} | offensive_tool_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 1 | N/A | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 5552 |
| 201 | */BadWindowsService.exe* | .{0,1000}\/BadWindowsService\.exe.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 1 | N/A | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 5559 |
| 202 | */BadWindowsService.git* | .{0,1000}\/BadWindowsService\.git.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 1 | N/A | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 5560 |
| 203 | */Bat-Potato.bat* | .{0,1000}\/Bat\-Potato\.bat.{0,1000} | offensive_tool_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 1 | N/A | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 5574 |
| 204 | */Bat-Potato.git* | .{0,1000}\/Bat\-Potato\.git.{0,1000} | offensive_tool_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 1 | N/A | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 5575 |
| 205 | */beRoot.exe* | .{0,1000}\/beRoot\.exe.{0,1000} | offensive_tool_keyword | BeRoot | Privilege Escalation Project - Windows / Linux / Mac | T1068 - T1055 - T1078 - T1548 - T1003 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/AlessandroZ/BeRoot | 1 | 1 | #linux | N/A | 10 | 10 | 2523 | 459 | 2024-10-04T11:54:01Z | 2017-04-14T12:47:31Z | 5599 |
| 206 | */BeRoot.git* | .{0,1000}\/BeRoot\.git.{0,1000} | offensive_tool_keyword | BeRoot | Privilege Escalation Project - Windows / Linux / Mac | T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/AlessandroZ/BeRoot | 1 | 1 | #linux | N/A | 10 | 10 | 2523 | 459 | 2024-10-04T11:54:01Z | 2017-04-14T12:47:31Z | 5600 |
| 207 | */beRoot.py* | .{0,1000}\/beRoot\.py.{0,1000} | offensive_tool_keyword | BeRoot | Privilege Escalation Project - Windows / Linux / Mac | T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/AlessandroZ/BeRoot | 1 | 1 | #linux | N/A | 10 | 10 | 2523 | 459 | 2024-10-04T11:54:01Z | 2017-04-14T12:47:31Z | 5601 |
| 208 | */beRoot.zip* | .{0,1000}\/beRoot\.zip.{0,1000} | offensive_tool_keyword | BeRoot | Privilege Escalation Project - Windows / Linux / Mac | T1068 - T1055 - T1078 - T1548 - T1003 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/AlessandroZ/BeRoot | 1 | 0 | #linux | N/A | 10 | 10 | 2523 | 459 | 2024-10-04T11:54:01Z | 2017-04-14T12:47:31Z | 5603 |
| 209 | */bin-sploits/*.zip* | .{0,1000}\/bin\-sploits\/.{0,1000}\.zip.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 5670 |
| 210 | */BITSInject.git* | .{0,1000}\/BITSInject\.git.{0,1000} | offensive_tool_keyword | BITSInject | A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account | T1197 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/SafeBreach-Labs/BITSInject | 1 | 1 | N/A | N/A | 8 | 1 | 99 | 18 | 2019-08-24T22:02:12Z | 2017-07-03T12:39:38Z | 5679 |
| 211 | */BITSInject.py* | .{0,1000}\/BITSInject\.py.{0,1000} | offensive_tool_keyword | BITSInject | A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account | T1197 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/SafeBreach-Labs/BITSInject | 1 | 1 | N/A | N/A | 8 | 1 | 99 | 18 | 2019-08-24T22:02:12Z | 2017-07-03T12:39:38Z | 5680 |
| 212 | */BITSJobPayloads.py* | .{0,1000}\/BITSJobPayloads\.py.{0,1000} | offensive_tool_keyword | BITSInject | A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account | T1197 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/SafeBreach-Labs/BITSInject | 1 | 1 | N/A | N/A | 8 | 1 | 99 | 18 | 2019-08-24T22:02:12Z | 2017-07-03T12:39:38Z | 5681 |
| 213 | */bloodyAD.git* | .{0,1000}\/bloodyAD\.git.{0,1000} | offensive_tool_keyword | bloodyAD | BloodyAD is an Active Directory Privilege Escalation Framework | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/CravateRouge/bloodyAD | 1 | 1 | N/A | N/A | 10 | 10 | 1590 | 145 | 2025-04-10T10:47:16Z | 2021-10-11T15:07:26Z | 5726 |
| 214 | */clown-newuser.c* | .{0,1000}\/clown\-newuser\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 6096 |
| 215 | */CoercedPotato.cpp* | .{0,1000}\/CoercedPotato\.cpp.{0,1000} | offensive_tool_keyword | CoercedPotatoRDLL | Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege | T1055 - T1134 - T1548 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/sokaRepo/CoercedPotatoRDLL | 1 | 1 | N/A | N/A | 10 | 3 | 204 | 31 | 2023-11-23T18:58:41Z | 2023-11-23T13:22:38Z | 6139 |
| 216 | */CoercedPotato.git* | .{0,1000}\/CoercedPotato\.git.{0,1000} | offensive_tool_keyword | CoercedPotato | CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022. | T1548.002 - T1134.002 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Prepouce/CoercedPotato | 1 | 1 | N/A | N/A | 10 | 4 | 366 | 66 | 2024-08-26T08:09:00Z | 2023-09-11T19:04:29Z | 6140 |
| 217 | */CoercedPotatoRDLL.git* | .{0,1000}\/CoercedPotatoRDLL\.git.{0,1000} | offensive_tool_keyword | CoercedPotatoRDLL | Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege | T1055 - T1134 - T1548 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/sokaRepo/CoercedPotatoRDLL | 1 | 1 | N/A | N/A | 10 | 3 | 204 | 31 | 2023-11-23T18:58:41Z | 2023-11-23T13:22:38Z | 6141 |
| 218 | */Crassus.git* | .{0,1000}\/Crassus\.git.{0,1000} | offensive_tool_keyword | Crassus | Crassus Windows privilege escalation discovery tool | T1068 - T1003 - T1003.003 - T1046 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/vu-ls/Crassus | 1 | 1 | N/A | N/A | 10 | 6 | 571 | 59 | 2024-11-08T14:11:39Z | 2023-01-12T21:01:52Z | 6226 |
| 219 | */Crassus-main* | .{0,1000}\/Crassus\-main.{0,1000} | offensive_tool_keyword | Crassus | Crassus Windows privilege escalation discovery tool | T1068 - T1003 - T1003.003 - T1046 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/vu-ls/Crassus | 1 | 1 | N/A | N/A | 10 | 6 | 571 | 59 | 2024-11-08T14:11:39Z | 2023-01-12T21:01:52Z | 6227 |
| 220 | */CVE*/chocobo_root* | .{0,1000}\/CVE.{0,1000}\/chocobo_root.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 6349 |
| 221 | */CVE-2009-2698/katon.c* | .{0,1000}\/CVE\-2009\-2698\/katon\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 6353 |
| 222 | */CVE-2021-1675.git* | .{0,1000}\/CVE\-2021\-1675\.git.{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/cube0x0/CVE-2021-1675 | 1 | 1 | N/A | N/A | 10 | 10 | 1879 | 582 | 2021-07-20T15:28:13Z | 2021-06-29T17:24:14Z | 6360 |
| 223 | */CVE-2024-1086.git* | .{0,1000}\/CVE\-2024\-1086\.git.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 1 | #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 6377 |
| 224 | */CVE-2024-21338.git* | .{0,1000}\/CVE\-2024\-21338\.git.{0,1000} | offensive_tool_keyword | POC | Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled. | T1055.011 - T1548.002 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/hakaioffsec/CVE-2024-21338 | 1 | 1 | N/A | N/A | 9 | 3 | 292 | 60 | 2024-04-16T21:00:14Z | 2024-04-13T05:53:02Z | 6378 |
| 225 | */CVE-2024-49138-POC.git* | .{0,1000}\/CVE\-2024\-49138\-POC\.git.{0,1000} | offensive_tool_keyword | POC | Windows Privilege escalation POC exploitation for CVE-2024-49138 | T1068 - T1058 - T1203 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/emdnaia/CVE-2024-49138-POC | 1 | 1 | N/A | N/A | 9 | 1 | 1 | 0 | 2025-01-15T01:01:21Z | 2025-01-15T02:11:49Z | 6380 |
| 226 | */DavRelayUp.git* | .{0,1000}\/DavRelayUp\.git.{0,1000} | offensive_tool_keyword | DavRelayUp | DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced | T1078 - T1078.004 - T1068 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/ShorSec/DavRelayUp | 1 | 1 | N/A | N/A | 9 | 6 | 542 | 81 | 2023-06-05T09:17:06Z | 2023-06-05T07:49:39Z | 6441 |
| 227 | */DavRelayUp/* | .{0,1000}\/DavRelayUp\/.{0,1000} | offensive_tool_keyword | DavRelayUp | DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced | T1078 - T1078.004 - T1068 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/ShorSec/DavRelayUp | 1 | 1 | N/A | N/A | 9 | 6 | 542 | 81 | 2023-06-05T09:17:06Z | 2023-06-05T07:49:39Z | 6442 |
| 228 | */dazzleUP.git* | .{0,1000}\/dazzleUP\.git.{0,1000} | offensive_tool_keyword | dazzleUP | A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems. | T1068 - T1088 - T1210 - T1210.002 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/hlldz/dazzleUP | 1 | 1 | N/A | N/A | 9 | 5 | 490 | 69 | 2020-07-23T08:48:43Z | 2020-07-21T21:06:46Z | 6444 |
| 229 | */DCOMPotato.git* | .{0,1000}\/DCOMPotato\.git.{0,1000} | offensive_tool_keyword | DCOMPotato | Service DCOM Object and SeImpersonatePrivilege abuse. | T1548.002 - T1134.002 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/zcgonvh/DCOMPotato | 1 | 1 | N/A | N/A | 10 | 4 | 356 | 48 | 2022-12-09T01:57:53Z | 2022-12-08T14:56:13Z | 6460 |
| 230 | */DeadPotato.git* | .{0,1000}\/DeadPotato\.git.{0,1000} | offensive_tool_keyword | DeadPotato | DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | N/A | N/A | Privilege Escalation | https://github.com/lypd0/DeadPotato | 1 | 1 | N/A | N/A | 10 | 4 | 382 | 45 | 2024-08-17T06:08:29Z | 2024-07-31T01:08:30Z | 6482 |
| 231 | */DesktopShell.exe* | .{0,1000}\/DesktopShell\.exe.{0,1000} | offensive_tool_keyword | PrivFu | SeTcbPrivilege exploitation | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 1 | N/A | PrivFu\PowerOfTcb | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 6548 |
| 232 | */DirCreate2System.git* | .{0,1000}\/DirCreate2System\.git.{0,1000} | offensive_tool_keyword | DirCreate2System | Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting | T1068 - T1059.001 - T1070.004 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/binderlabs/DirCreate2System | 1 | 1 | N/A | N/A | 8 | 4 | 357 | 38 | 2022-12-19T17:00:43Z | 2022-12-15T03:49:55Z | 6584 |
| 233 | */DirCreate2System.git* | .{0,1000}\/DirCreate2System\.git.{0,1000} | offensive_tool_keyword | DirCreate2System | Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting | T1068 - T1059.001 - T1070.004 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/binderlabs/DirCreate2System | 1 | 1 | N/A | N/A | 8 | 4 | 357 | 38 | 2022-12-19T17:00:43Z | 2022-12-15T03:49:55Z | 6585 |
| 234 | */DirtyCLR.git* | .{0,1000}\/DirtyCLR\.git.{0,1000} | offensive_tool_keyword | DirtyCLR | An App Domain Manager Injection DLL PoC | T1055.001 - T1546.016 - T1055.013 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/ipSlav/DirtyCLR | 1 | 1 | N/A | N/A | 7 | 2 | 170 | 19 | 2023-12-14T21:22:12Z | 2023-12-11T11:29:36Z | 6592 |
| 235 | */dirtypipez.c* | .{0,1000}\/dirtypipez\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 6596 |
| 236 | */dirtypipez.c* | .{0,1000}\/dirtypipez\.c.{0,1000} | offensive_tool_keyword | POC | exploit the Linux Dirty Pipe vulnerability | T1068 - T1078.003 - T1071.004 - T1072 - T1105 | TA0004 - TA0006? | N/A | N/A | Privilege Escalation | https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits | 1 | 1 | #linux | N/A | 10 | 6 | 595 | 148 | 2023-05-20T05:55:45Z | 2022-03-12T20:57:24Z | 6599 |
| 237 | */download/linpeas.sh* | .{0,1000}\/download\/linpeas\.sh.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 6752 |
| 238 | */echoac-poc.git* | .{0,1000}\/echoac\-poc\.git.{0,1000} | offensive_tool_keyword | echoac-poc | poc stealing the Kernel's KPROCESS/EPROCESS block and writing it to a newly spawned shell to elevate its privileges to the highest possible - nt authority\system | T1068 - T1203 - T1059.003 | TA0002 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/kite03/echoac-poc | 1 | 1 | N/A | N/A | 8 | 2 | 138 | 25 | 2024-01-09T16:44:00Z | 2023-06-28T00:52:22Z | 6883 |
| 239 | */EfsPotato.git* | .{0,1000}\/EfsPotato\.git.{0,1000} | offensive_tool_keyword | EfsPotato | Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability) | T1068 - T1055.002 - T1070.004 | TA0003 - TA0005 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/zcgonvh/EfsPotato | 1 | 1 | N/A | N/A | 10 | 8 | 771 | 125 | 2023-12-14T14:30:15Z | 2021-07-26T21:36:16Z | 6903 |
| 240 | */elevateit.bat* | .{0,1000}\/elevateit\.bat.{0,1000} | offensive_tool_keyword | elevationstation | elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative | T1548.002 - T1055 - T1574.002 - T1078.003 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/g3tsyst3m/elevationstation | 1 | 1 | N/A | N/A | N/A | 4 | 368 | 45 | 2023-11-02T23:52:51Z | 2023-06-10T03:30:59Z | 6913 |
| 241 | */Elevator.git* | .{0,1000}\/Elevator\.git.{0,1000} | offensive_tool_keyword | Elevator | UAC bypass by abusing RPC and debug objects. | T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Kudaes/Elevator | 1 | 1 | N/A | N/A | 10 | 7 | 614 | 69 | 2023-10-19T08:51:09Z | 2022-08-25T21:39:28Z | 6915 |
| 242 | */etc/passwd*/.sudo_as_admin_successful* | .{0,1000}\/etc\/passwd.{0,1000}\/\.sudo_as_admin_successful.{0,1000} | offensive_tool_keyword | linux-smart-enumeration | Linux enumeration tool for privilege escalation and discovery | T1087.004 - T1016 - T1548.001 - T1046 | TA0007 - TA0004 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/diego-treitos/linux-smart-enumeration | 1 | 0 | #linux | N/A | 9 | 10 | 3575 | 584 | 2023-12-25T14:46:47Z | 2019-02-13T11:02:21Z | 7015 |
| 243 | */evil.dll* | .{0,1000}\/evil\.dll.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | N/A | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 7067 |
| 244 | */exploit.cron.sh* | .{0,1000}\/exploit\.cron\.sh.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 7138 |
| 245 | */exploit.ldpreload.sh* | .{0,1000}\/exploit\.ldpreload\.sh.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 7141 |
| 246 | */full-nelson.c* | .{0,1000}\/full\-nelson\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 7310 |
| 247 | */full-nelson64* | .{0,1000}\/full\-nelson64.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 7311 |
| 248 | */GodPotato.git* | .{0,1000}\/GodPotato\.git.{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 1 | N/A | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 7557 |
| 249 | */Gotato.git* | .{0,1000}\/Gotato\.git.{0,1000} | offensive_tool_keyword | Gotato | Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported. | T1003.003 - T1056.002 - T1550.001 - T1090 | TA0005 - TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/iammaguire/Gotato | 1 | 1 | N/A | N/A | 9 | 2 | 112 | 16 | 2021-06-07T21:19:58Z | 2021-06-05T22:32:48Z | 7601 |
| 250 | */gotato.go* | .{0,1000}\/gotato\.go.{0,1000} | offensive_tool_keyword | Gotato | Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported. | T1003.003 - T1056.002 - T1550.001 - T1090 | TA0005 - TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/iammaguire/Gotato | 1 | 1 | N/A | N/A | 9 | 2 | 112 | 16 | 2021-06-07T21:19:58Z | 2021-06-05T22:32:48Z | 7602 |
| 251 | */gtfobin_update.py* | .{0,1000}\/gtfobin_update\.py.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 1 | N/A | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 7672 |
| 252 | */gtfobins.go* | .{0,1000}\/gtfobins\.go.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux | N/A | N/A | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 7673 |
| 253 | */gtfobins.py* | .{0,1000}\/gtfobins\.py.{0,1000} | offensive_tool_keyword | BeRoot | Privilege Escalation Project - Windows / Linux / Mac | T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/AlessandroZ/BeRoot | 1 | 1 | #linux | N/A | 10 | 10 | 2523 | 459 | 2024-10-04T11:54:01Z | 2017-04-14T12:47:31Z | 7674 |
| 254 | */gtfonow.py* | .{0,1000}\/gtfonow\.py.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 1 | N/A | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 7675 |
| 255 | */havoc_bof.py* | .{0,1000}\/havoc_bof\.py.{0,1000} | offensive_tool_keyword | PoolPartyBof | A beacon object file implementation of PoolParty Process Injection Technique | T1055.011 - T1055 - T1620 | TA0005 | N/A | Black Basta | Privilege Escalation | https://github.com/0xEr3bus/PoolPartyBof | 1 | 1 | N/A | N/A | 10 | 4 | 380 | 44 | 2023-12-21T19:00:20Z | 2023-12-11T19:28:20Z | 7740 |
| 256 | */home/lowpriv/* | .{0,1000}\/home\/lowpriv\/.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | #linux | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 7795 |
| 257 | */IDiagnosticProfileUAC* | .{0,1000}\/IDiagnosticProfileUAC.{0,1000} | offensive_tool_keyword | IDiagnosticProfileUAC | UAC bypass using auto-elevated COM object Virtual Factory for DiagCpl | T1548.002 - T1059.003 - T1027.002 | TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/Wh04m1001/IDiagnosticProfileUAC | 1 | 1 | N/A | N/A | 10 | 2 | 182 | 32 | 2022-07-02T20:31:47Z | 2022-07-02T19:55:42Z | 8012 |
| 258 | */Ikeext-Privesc.git* | .{0,1000}\/Ikeext\-Privesc\.git.{0,1000} | offensive_tool_keyword | Ikeext-Privesc | Windows IKEEXT DLL Hijacking Exploit Tool | T1546.011 - T1574.009 - T1036.004 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/securycore/Ikeext-Privesc | 1 | 1 | N/A | N/A | 10 | 1 | 33 | 52 | 2018-02-25T13:45:15Z | 2018-02-27T11:18:56Z | 8024 |
| 259 | */Inveigh.ps1* | .{0,1000}\/Inveigh\.ps1.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 1 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 8119 |
| 260 | */Invoke-RunAsSystem.git* | .{0,1000}\/Invoke\-RunAsSystem\.git.{0,1000} | offensive_tool_keyword | Invoke-RunAsSystem | A simple script to elevate current session to SYSTEM (needs to be run as Administrator) | T1548.002 - T1059.001 | TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/Leo4j/Invoke-RunAsSystem | 1 | 1 | N/A | N/A | 8 | 1 | 14 | 1 | 2024-11-11T17:18:20Z | 2023-08-24T15:12:40Z | 8162 |
| 261 | */JuicyPotato.exe* | .{0,1000}\/JuicyPotato\.exe.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 1 | N/A | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 8263 |
| 262 | */JuicyPotato.git* | .{0,1000}\/JuicyPotato\.git.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 1 | N/A | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 8264 |
| 263 | */JuicyPotato_x32.exe* | .{0,1000}\/JuicyPotato_x32\.exe.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 1 | N/A | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 8267 |
| 264 | */JuicyPotato_x64.exe* | .{0,1000}\/JuicyPotato_x64\.exe.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 1 | N/A | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 8268 |
| 265 | */JuicyPotatoNG.git* | .{0,1000}\/JuicyPotatoNG\.git.{0,1000} | offensive_tool_keyword | JuicyPotatoNG | Another Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | FoxKitten - APT33 - Volatile Cedar - Sandworm | Privilege Escalation | https://github.com/antonioCoco/JuicyPotatoNG | 1 | 1 | N/A | N/A | 10 | 9 | 844 | 101 | 2022-11-12T01:48:39Z | 2022-09-21T17:08:35Z | 8269 |
| 266 | */JuicyPotato-webshell/* | .{0,1000}\/JuicyPotato\-webshell\/.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 1 | N/A | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 8270 |
| 267 | */KExecDD.git* | .{0,1000}\/KExecDD\.git.{0,1000} | offensive_tool_keyword | KExecDD | Admin to Kernel code execution using the KSecDD driver | T1068 - T1055.011 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/floesen/KExecDD | 1 | 1 | N/A | N/A | 8 | 3 | 244 | 41 | 2024-04-19T09:58:14Z | 2024-04-19T08:54:49Z | 8338 |
| 268 | */KrbRelayUp.git* | .{0,1000}\/KrbRelayUp\.git.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 1 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 8409 |
| 269 | */LinEnum.git* | .{0,1000}\/LinEnum\.git.{0,1000} | offensive_tool_keyword | LinEnum | Scripted Local Linux Enumeration & Privilege Escalation Checks | T1046 - T1087.001 - T1057 - T1082 - T1016 - T1135 - T1049 - T1059.004 - T1007 - T1069.001 - T1083 - T1018 | TA0007 - TA0009 - TA0002 - TA0003 - TA0001 | N/A | N/A | Privilege Escalation | https://github.com/rebootuser/LinEnum | 1 | 1 | #linux | N/A | 10 | 10 | 7309 | 2011 | 2023-09-06T18:02:29Z | 2013-08-20T06:26:58Z | 8526 |
| 270 | */LinEnum/* | .{0,1000}\/LinEnum\/.{0,1000} | offensive_tool_keyword | LinEnum | Scripted Local Linux Enumeration & Privilege Escalation Checks | T1046 - T1087.001 - T1057 - T1082 - T1016 - T1135 - T1049 - T1059.004 - T1007 - T1069.001 - T1083 - T1018 | TA0007 - TA0009 - TA0002 - TA0003 - TA0001 | N/A | N/A | Privilege Escalation | https://github.com/rebootuser/LinEnum | 1 | 1 | #linux | N/A | 10 | 10 | 7309 | 2011 | 2023-09-06T18:02:29Z | 2013-08-20T06:26:58Z | 8527 |
| 271 | */linpeas.sh* | .{0,1000}\/linpeas\.sh.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 1 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 8532 |
| 272 | */linpeas.sh* | .{0,1000}\/linpeas\.sh.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 1 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 8533 |
| 273 | */linpeas.txt* | .{0,1000}\/linpeas\.txt.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 1 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 8534 |
| 274 | */linpeasBaseBuilder.py* | .{0,1000}\/linpeasBaseBuilder\.py.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 8535 |
| 275 | */linpeasBuilder.py* | .{0,1000}\/linpeasBuilder\.py.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 8536 |
| 276 | */linux_ldso_dynamic.c* | .{0,1000}\/linux_ldso_dynamic\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 8537 |
| 277 | */linux_ldso_hwcap.c* | .{0,1000}\/linux_ldso_hwcap\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 8538 |
| 278 | */linux_ldso_hwcap_64.c* | .{0,1000}\/linux_ldso_hwcap_64\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 8539 |
| 279 | */linux_offset2lib.c* | .{0,1000}\/linux_offset2lib\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 8540 |
| 280 | */linuxprivchecker.git* | .{0,1000}\/linuxprivchecker\.git.{0,1000} | offensive_tool_keyword | linuxprivchecker | search for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploits | T1210.001 - T1082 - T1088 - T1547.001 | TA0002 - TA0004 - TA0006 - TA0007 - TA0008 | N/A | N/A | Privilege Escalation | https://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py | 1 | 1 | #linux | N/A | 7 | 10 | 1645 | 524 | 2022-01-31T10:32:08Z | 2016-04-19T13:31:46Z | 8548 |
| 281 | */linux-smart-enumeration.git* | .{0,1000}\/linux\-smart\-enumeration\.git.{0,1000} | offensive_tool_keyword | linux-smart-enumeration | Linux enumeration tool for privilege escalation and discovery | T1087.004 - T1016 - T1548.001 - T1046 | TA0007 - TA0004 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/diego-treitos/linux-smart-enumeration | 1 | 1 | #linux | N/A | 9 | 10 | 3575 | 584 | 2023-12-25T14:46:47Z | 2019-02-13T11:02:21Z | 8549 |
| 282 | */LocalAdminSharp.git* | .{0,1000}\/LocalAdminSharp\.git.{0,1000} | offensive_tool_keyword | LocalAdminSharp | .NET executable to use when dealing with privilege escalation on Windows to gain local administrator access | T1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/notdodo/LocalAdminSharp | 1 | 1 | N/A | N/A | 10 | 2 | 157 | 17 | 2022-11-01T17:45:43Z | 2022-01-01T10:35:09Z | 8580 |
| 283 | */LocalAdminSharp.sln* | .{0,1000}\/LocalAdminSharp\.sln.{0,1000} | offensive_tool_keyword | LocalAdminSharp | .NET executable to use when dealing with privilege escalation on Windows to gain local administrator access | T1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/notdodo/LocalAdminSharp | 1 | 1 | N/A | N/A | 10 | 2 | 157 | 17 | 2022-11-01T17:45:43Z | 2022-01-01T10:35:09Z | 8581 |
| 284 | */local-exploits/master/CVE* | .{0,1000}\/local\-exploits\/master\/CVE.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 8584 |
| 285 | */LocalPotato.git* | .{0,1000}\/LocalPotato\.git.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 1 | N/A | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 8585 |
| 286 | */localroot/2.6.x/elflbl* | .{0,1000}\/localroot\/2\.6\.x\/elflbl.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 8587 |
| 287 | */localroot/2.6.x/h00lyshit* | .{0,1000}\/localroot\/2\.6\.x\/h00lyshit.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 8588 |
| 288 | */ly4k/Pachine* | .{0,1000}\/ly4k\/Pachine.{0,1000} | offensive_tool_keyword | Pachine | Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation) | T1068 - T1078 - T1059.006 | TA0003 - TA0004 - TA0002 | N/A | Black Basta | Privilege Escalation | https://github.com/ly4k/Pachine | 1 | 1 | N/A | N/A | 8 | 3 | 275 | 37 | 2022-01-13T12:35:19Z | 2021-12-13T23:15:05Z | 8670 |
| 289 | */MakeMeAdmin * x64.msi* | .{0,1000}\/MakeMeAdmin\s.{0,1000}\sx64\.msi.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 1 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 8699 |
| 290 | */MakeMeAdmin.git* | .{0,1000}\/MakeMeAdmin\.git.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 1 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 8700 |
| 291 | */MakeMeAdmin/tarball* | .{0,1000}\/MakeMeAdmin\/tarball.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 1 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 8701 |
| 292 | */MakeMeAdmin/tree/v*/Installers* | .{0,1000}\/MakeMeAdmin\/tree\/v.{0,1000}\/Installers.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 1 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 8702 |
| 293 | */MakeMeAdmin/zipball* | .{0,1000}\/MakeMeAdmin\/zipball.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 1 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 8703 |
| 294 | */MakeMeEnterpriseAdmin.ps1* | .{0,1000}\/MakeMeEnterpriseAdmin\.ps1.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 1 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 8704 |
| 295 | */MakeMeEnterpriseAdmin.ps1* | .{0,1000}\/MakeMeEnterpriseAdmin\.ps1.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 1 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 8705 |
| 296 | */memodipper64* | .{0,1000}\/memodipper64.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 8753 |
| 297 | */mempodipper.c* | .{0,1000}\/mempodipper\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 8756 |
| 298 | */MonkeyWorks.git* | .{0,1000}\/MonkeyWorks\.git.{0,1000} | offensive_tool_keyword | Tokenvator | A tool to elevate privilege with Windows Tokens | T1134 - T1078 | TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/0xbadjuju/Tokenvator | 1 | 1 | N/A | N/A | N/A | 10 | 1038 | 201 | 2023-10-06T13:17:05Z | 2017-12-08T01:29:11Z | 8892 |
| 299 | */MultiPotato.git* | .{0,1000}\/MultiPotato\.git.{0,1000} | offensive_tool_keyword | MultiPotato | get SYSTEM via SeImpersonate privileges | T1548.002 - T1134.002 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S3cur3Th1sSh1t/MultiPotato | 1 | 1 | N/A | N/A | 10 | 6 | 518 | 92 | 2021-11-20T16:20:23Z | 2021-11-19T15:50:55Z | 8967 |
| 300 | */mzet-/les-res* | .{0,1000}\/mzet\-\/les\-res.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 8995 |
| 301 | */nginxed-root.sh* | .{0,1000}\/nginxed\-root\.sh.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 9134 |
| 302 | */NoFilter.cpp* | .{0,1000}\/NoFilter\.cpp.{0,1000} | offensive_tool_keyword | NoFilter | Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine. | T1548 - T1548.002 - T1055 - T1055.004 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/NoFilter | 1 | 1 | N/A | N/A | 9 | 3 | 298 | 48 | 2024-10-29T07:30:35Z | 2023-07-30T09:25:38Z | 9226 |
| 303 | */NoFilter.exe* | .{0,1000}\/NoFilter\.exe.{0,1000} | offensive_tool_keyword | NoFilter | Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine. | T1548 - T1548.002 - T1055 - T1055.004 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/NoFilter | 1 | 1 | N/A | N/A | 9 | 3 | 298 | 48 | 2024-10-29T07:30:35Z | 2023-07-30T09:25:38Z | 9227 |
| 304 | */NoFilter.git* | .{0,1000}\/NoFilter\.git.{0,1000} | offensive_tool_keyword | NoFilter | Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine. | T1548 - T1548.002 - T1055 - T1055.004 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/NoFilter | 1 | 1 | N/A | N/A | 9 | 3 | 298 | 48 | 2024-10-29T07:30:35Z | 2023-07-30T09:25:38Z | 9228 |
| 305 | */NoFilter.sln* | .{0,1000}\/NoFilter\.sln.{0,1000} | offensive_tool_keyword | NoFilter | Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine. | T1548 - T1548.002 - T1055 - T1055.004 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/NoFilter | 1 | 1 | N/A | N/A | 9 | 3 | 298 | 48 | 2024-10-29T07:30:35Z | 2023-07-30T09:25:38Z | 9229 |
| 306 | */NoFilter.vcxproj* | .{0,1000}\/NoFilter\.vcxproj.{0,1000} | offensive_tool_keyword | NoFilter | Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine. | T1548 - T1548.002 - T1055 - T1055.004 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/NoFilter | 1 | 1 | N/A | N/A | 9 | 3 | 298 | 48 | 2024-10-29T07:30:35Z | 2023-07-30T09:25:38Z | 9230 |
| 307 | */NotQuite0DayFriday/zip/trunk* | .{0,1000}\/NotQuite0DayFriday\/zip\/trunk.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 9243 |
| 308 | */NTLMRelay2Self* | .{0,1000}\/NTLMRelay2Self.{0,1000} | offensive_tool_keyword | NTLMRelay2Self | An other No-Fix LPE - NTLMRelay2Self over HTTP (Webdav). | T1078 - T1078.004 - T1557 - T1557.001 - T1068 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/med0x2e/NTLMRelay2Self | 1 | 1 | N/A | N/A | 10 | 5 | 400 | 42 | 2024-01-27T08:52:03Z | 2022-04-30T10:05:02Z | 9292 |
| 309 | */NtRights/* | .{0,1000}\/NtRights\/.{0,1000} | offensive_tool_keyword | NtRights | tool for adding privileges from the commandline | T1548.002 - T1059.003 - T1027.002 | TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/gtworek/PSBits/tree/master/NtRights | 1 | 1 | N/A | N/A | 7 | 10 | 3337 | 542 | 2025-03-12T19:59:23Z | 2019-06-29T13:22:36Z | 9317 |
| 310 | */OfficeInjector.exe* | .{0,1000}\/OfficeInjector\.exe.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 1 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 9366 |
| 311 | */OUned.git* | .{0,1000}\/OUned\.git.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 1 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 9453 |
| 312 | */ouned_smbserver.py* | .{0,1000}\/ouned_smbserver\.py.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 1 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 9454 |
| 313 | */p_cve-2014-9322.tar.gz* | .{0,1000}\/p_cve\-2014\-9322\.tar\.gz.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 9471 |
| 314 | */PEASS-ng.git* | .{0,1000}\/PEASS\-ng\.git.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 1 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 9588 |
| 315 | */PEASS-ng.git* | .{0,1000}\/PEASS\-ng\.git.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 9589 |
| 316 | */PEASS-ng/* | .{0,1000}\/PEASS\-ng\/.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 1 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 9590 |
| 317 | */PEASS-ng/releases/* | .{0,1000}\/PEASS\-ng\/releases\/.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 9591 |
| 318 | */perf_swevent64* | .{0,1000}\/perf_swevent64.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 9603 |
| 319 | */Perfusion.exe* | .{0,1000}\/Perfusion\.exe.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 1 | N/A | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 9604 |
| 320 | */Perfusion.git* | .{0,1000}\/Perfusion\.git.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 1 | N/A | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 9605 |
| 321 | */PerfusionDll.dll* | .{0,1000}\/PerfusionDll\.dll.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 1 | N/A | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 9606 |
| 322 | */PetitPotato.cpp* | .{0,1000}\/PetitPotato\.cpp.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 1 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 9641 |
| 323 | */PetitPotato.git* | .{0,1000}\/PetitPotato\.git.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 1 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 9642 |
| 324 | */PetitPotato-1.0.0.zip* | .{0,1000}\/PetitPotato\-1\.0\.0\.zip.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 1 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 9643 |
| 325 | */pipe/RustPotato* | .{0,1000}\/pipe\/RustPotato.{0,1000} | offensive_tool_keyword | RustPotato | A Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privileges | T1134.001 - T1055.011 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/emdnaia/RustPotato | 1 | 0 | #content #namedpipe | N/A | 10 | 1 | 0 | 0 | 2025-01-06T18:10:17Z | 2025-01-06T19:44:57Z | 9699 |
| 326 | */PoC/PrivilegeEscalation* | .{0,1000}\/PoC\/PrivilegeEscalation.{0,1000} | offensive_tool_keyword | echoac-poc | poc stealing the Kernel's KPROCESS/EPROCESS block and writing it to a newly spawned shell to elevate its privileges to the highest possible - nt authority\system | T1068 - T1203 - T1059.003 | TA0002 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/kite03/echoac-poc | 1 | 1 | N/A | N/A | 8 | 2 | 138 | 25 | 2024-01-09T16:44:00Z | 2023-06-28T00:52:22Z | 9720 |
| 327 | */PoolPartyBof.git* | .{0,1000}\/PoolPartyBof\.git.{0,1000} | offensive_tool_keyword | PoolPartyBof | A beacon object file implementation of PoolParty Process Injection Technique | T1055.011 - T1055 - T1620 | TA0005 | N/A | Black Basta | Privilege Escalation | https://github.com/0xEr3bus/PoolPartyBof | 1 | 1 | N/A | N/A | 10 | 4 | 380 | 44 | 2023-12-21T19:00:20Z | 2023-12-11T19:28:20Z | 9734 |
| 328 | */PoolPartyBof/releases/download/* | .{0,1000}\/PoolPartyBof\/releases\/download\/.{0,1000} | offensive_tool_keyword | PoolPartyBof | A beacon object file implementation of PoolParty Process Injection Technique | T1055.011 - T1055 - T1620 | TA0005 | N/A | Black Basta | Privilege Escalation | https://github.com/0xEr3bus/PoolPartyBof | 1 | 1 | N/A | N/A | 10 | 4 | 380 | 44 | 2023-12-21T19:00:20Z | 2023-12-11T19:28:20Z | 9736 |
| 329 | */PoolPartyBof/tarball/* | .{0,1000}\/PoolPartyBof\/tarball\/.{0,1000} | offensive_tool_keyword | PoolPartyBof | A beacon object file implementation of PoolParty Process Injection Technique | T1055.011 - T1055 - T1620 | TA0005 | N/A | Black Basta | Privilege Escalation | https://github.com/0xEr3bus/PoolPartyBof | 1 | 1 | N/A | N/A | 10 | 4 | 380 | 44 | 2023-12-21T19:00:20Z | 2023-12-11T19:28:20Z | 9737 |
| 330 | */PoolPartyBof/zipball/* | .{0,1000}\/PoolPartyBof\/zipball\/.{0,1000} | offensive_tool_keyword | PoolPartyBof | A beacon object file implementation of PoolParty Process Injection Technique | T1055.011 - T1055 - T1620 | TA0005 | N/A | Black Basta | Privilege Escalation | https://github.com/0xEr3bus/PoolPartyBof | 1 | 1 | N/A | N/A | 10 | 4 | 380 | 44 | 2023-12-21T19:00:20Z | 2023-12-11T19:28:20Z | 9738 |
| 331 | */Powermad.ps1* | .{0,1000}\/Powermad\.ps1.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 1 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 9813 |
| 332 | */PowerUp.ps1* | .{0,1000}\/PowerUp\.ps1.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 1 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 9830 |
| 333 | */PowerView.ps1* | .{0,1000}\/PowerView\.ps1.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 1 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 9835 |
| 334 | */prefetch-tool.git* | .{0,1000}\/prefetch\-tool\.git.{0,1000} | offensive_tool_keyword | prefetch-tool | Windows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitation | T1564.007 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/exploits-forsale/prefetch-tool | 1 | 1 | N/A | N/A | 8 | 1 | 90 | 10 | 2024-04-26T05:40:32Z | 2024-04-26T05:00:27Z | 9860 |
| 335 | */PrintNightmare.git* | .{0,1000}\/PrintNightmare\.git.{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/outflanknl/PrintNightmare | 1 | 1 | N/A | N/A | 10 | 4 | 337 | 67 | 2021-09-13T08:45:26Z | 2021-09-13T08:44:02Z | 9876 |
| 336 | */PrintSpoofer.exe* | .{0,1000}\/PrintSpoofer\.exe.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 1 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 9883 |
| 337 | */PrintSpoofer.git* | .{0,1000}\/PrintSpoofer\.git.{0,1000} | offensive_tool_keyword | PrintSpoofer | Abusing Impersonation Privileges on Windows 10 and Server 2019 | T1548.002 - T1055.001 - T1055.002 | TA0005 - TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrintSpoofer | 1 | 1 | N/A | N/A | 10 | 10 | 1971 | 342 | 2020-09-10T17:49:41Z | 2020-04-28T08:26:29Z | 9884 |
| 338 | */PrintSpoofer.git* | .{0,1000}\/PrintSpoofer\.git.{0,1000} | offensive_tool_keyword | printspoofer | Abusing impersonation privileges through the Printer Bug | T1134 - T1003 - T1055 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrintSpoofer | 1 | 1 | N/A | N/A | 10 | 10 | 1971 | 342 | 2020-09-10T17:49:41Z | 2020-04-28T08:26:29Z | 9885 |
| 339 | */PrivEditor.dll* | .{0,1000}\/PrivEditor\.dll.{0,1000} | offensive_tool_keyword | PrivFu | Kernel Mode WinDbg extension for token privilege edit | T1055 - T1078 - T1134 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 9888 |
| 340 | */Privesc.git* | .{0,1000}\/Privesc\.git.{0,1000} | offensive_tool_keyword | Privesc | Windows PowerShell script that finds misconfiguration issues which can lead to privilege escalation | T1068 - T1548 - T1082 - T1078 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/enjoiz/Privesc | 1 | 1 | N/A | N/A | 10 | 6 | 595 | 97 | 2024-12-01T15:24:41Z | 2015-11-19T13:22:01Z | 9889 |
| 341 | */privesc.ps1* | .{0,1000}\/privesc\.ps1.{0,1000} | offensive_tool_keyword | Privesc | Windows PowerShell script that finds misconfiguration issues which can lead to privilege escalation | T1068 - T1548 - T1082 - T1078 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/enjoiz/Privesc | 1 | 1 | N/A | N/A | 10 | 6 | 595 | 97 | 2024-12-01T15:24:41Z | 2015-11-19T13:22:01Z | 9890 |
| 342 | */PrivEsc.psm1* | .{0,1000}\/PrivEsc\.psm1.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 1 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 9891 |
| 343 | */PrivescCheck* | .{0,1000}\/PrivescCheck.{0,1000} | offensive_tool_keyword | PrivescCheck | Privilege Escalation Enumeration Script for Windows | T1053 - T1088 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrivescCheck | 1 | 1 | N/A | N/A | 10 | 10 | 3230 | 460 | 2025-03-05T14:44:17Z | 2020-01-16T12:28:10Z | 9893 |
| 344 | */PrivExchange.git* | .{0,1000}\/PrivExchange\.git.{0,1000} | offensive_tool_keyword | privexchange | Exchange your privileges for Domain Admin privs by abusing Exchange | T1053.005 - T1078 - T1069.002 | TA0002 - TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/dirkjanm/PrivExchange | 1 | 1 | N/A | N/A | N/A | 10 | 1011 | 173 | 2020-01-23T19:48:51Z | 2019-01-21T17:39:47Z | 9896 |
| 345 | */PrivFu.git* | .{0,1000}\/PrivFu\.git.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 9898 |
| 346 | */Privileger.git* | .{0,1000}\/Privileger\.git.{0,1000} | offensive_tool_keyword | Privileger | Privileger is a tool to work with Windows Privileges | T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/MzHmO/Privileger | 1 | 1 | N/A | N/A | 8 | 2 | 136 | 32 | 2023-02-07T07:28:40Z | 2023-01-31T11:24:37Z | 9901 |
| 347 | */PrivKit.git* | .{0,1000}\/PrivKit\.git.{0,1000} | offensive_tool_keyword | PrivKit | PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS. | T1548.002 - T1059.003 - T1027.002 | TA0005 | N/A | N/A | Privilege Escalation | https://github.com/mertdas/PrivKit | 1 | 1 | N/A | N/A | 9 | 5 | 405 | 47 | 2024-06-15T16:54:32Z | 2023-03-20T04:19:40Z | 9902 |
| 348 | */PrivKit/* | .{0,1000}\/PrivKit\/.{0,1000} | offensive_tool_keyword | PrivKit | PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS. | T1548.002 - T1059.003 - T1027.002 | TA0005 | N/A | N/A | Privilege Escalation | https://github.com/mertdas/PrivKit | 1 | 1 | N/A | N/A | 9 | 5 | 405 | 47 | 2024-06-15T16:54:32Z | 2023-03-20T04:19:40Z | 9903 |
| 349 | */psgetsys.ps1* | .{0,1000}\/psgetsys\.ps1.{0,1000} | offensive_tool_keyword | psgetsystem | getsystem via parent process using ps1 & embeded c# | T1134 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/psgetsystem | 1 | 1 | N/A | N/A | 10 | 5 | 406 | 88 | 2023-10-26T07:13:08Z | 2018-02-02T11:28:22Z | 9968 |
| 350 | */psgetsystem.git* | .{0,1000}\/psgetsystem\.git.{0,1000} | offensive_tool_keyword | psgetsystem | getsystem via parent process using ps1 & embeded c# | T1134 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/psgetsystem | 1 | 1 | N/A | N/A | 10 | 5 | 406 | 88 | 2023-10-26T07:13:08Z | 2018-02-02T11:28:22Z | 9969 |
| 351 | */PView.psm1* | .{0,1000}\/PView\.psm1.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 1 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 10034 |
| 352 | */PyExec.git* | .{0,1000}\/PyExec\.git.{0,1000} | offensive_tool_keyword | PyExec | This is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses. | T1134 - T1055 - T1548.002 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/OlivierLaflamme/PyExec | 1 | 1 | N/A | N/A | 9 | 1 | 11 | 7 | 2019-09-11T13:56:04Z | 2019-09-11T13:54:15Z | 10066 |
| 353 | */raceabrt.c* | .{0,1000}\/raceabrt\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 10141 |
| 354 | */rasman.exe* | .{0,1000}\/rasman\.exe.{0,1000} | offensive_tool_keyword | RasmanPotato | using RasMan service for privilege escalation | T1548.002 - T1055.002 - T1055.001 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/crisprss/RasmanPotato | 1 | 1 | N/A | N/A | 10 | 4 | 371 | 53 | 2023-02-06T10:27:41Z | 2023-02-06T09:41:51Z | 10157 |
| 355 | */RasmanPotato* | .{0,1000}\/RasmanPotato.{0,1000} | offensive_tool_keyword | RasmanPotato | using RasMan service for privilege escalation | T1548.002 - T1055.002 - T1055.001 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/crisprss/RasmanPotato | 1 | 1 | N/A | N/A | 10 | 4 | 371 | 53 | 2023-02-06T10:27:41Z | 2023-02-06T09:41:51Z | 10158 |
| 356 | */releases/download/Binaries/DeadPotato* | .{0,1000}\/releases\/download\/Binaries\/DeadPotato.{0,1000} | offensive_tool_keyword | DeadPotato | DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | N/A | N/A | Privilege Escalation | https://github.com/lypd0/DeadPotato | 1 | 1 | N/A | N/A | 10 | 4 | 382 | 45 | 2024-08-17T06:08:29Z | 2024-07-31T01:08:30Z | 10340 |
| 357 | */releases/latest/download/lse.sh* | .{0,1000}\/releases\/latest\/download\/lse\.sh.{0,1000} | offensive_tool_keyword | linux-smart-enumeration | Linux enumeration tool for privilege escalation and discovery | T1087.004 - T1016 - T1548.001 - T1046 | TA0007 - TA0004 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/diego-treitos/linux-smart-enumeration | 1 | 1 | #linux | N/A | 9 | 10 | 3575 | 584 | 2023-12-25T14:46:47Z | 2019-02-13T11:02:21Z | 10351 |
| 358 | */RemotePotato0.git* | .{0,1000}\/RemotePotato0\.git.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 1 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 10397 |
| 359 | */RemotePotato0.zip* | .{0,1000}\/RemotePotato0\.zip.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 1 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 10398 |
| 360 | */RoguePotato.git* | .{0,1000}\/RoguePotato\.git.{0,1000} | offensive_tool_keyword | RoguePotato | Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RoguePotato | 1 | 1 | N/A | N/A | 10 | 10 | 1081 | 131 | 2021-01-09T20:43:07Z | 2020-05-10T17:38:28Z | 10496 |
| 361 | */RogueWinRM.git* | .{0,1000}\/RogueWinRM\.git.{0,1000} | offensive_tool_keyword | RogueWinRM | RogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not running | T1548.003 - T1134.002 - T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RogueWinRM | 1 | 1 | N/A | N/A | 10 | 8 | 788 | 107 | 2020-02-23T19:26:41Z | 2019-12-02T22:58:03Z | 10497 |
| 362 | */RottenPotatoNG.git* | .{0,1000}\/RottenPotatoNG\.git.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 1 | N/A | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 10527 |
| 363 | */RustPotato.git* | .{0,1000}\/RustPotato\.git.{0,1000} | offensive_tool_keyword | RustPotato | A Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privileges | T1134.001 - T1055.011 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/emdnaia/RustPotato | 1 | 1 | N/A | N/A | 10 | 1 | 0 | 0 | 2025-01-06T18:10:17Z | 2025-01-06T19:44:57Z | 10647 |
| 364 | */S4UTomato.git* | .{0,1000}\/S4UTomato\.git.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 1 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 10659 |
| 365 | */SeAuditPrivilegePoC.exe* | .{0,1000}\/SeAuditPrivilegePoC\.exe.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 10763 |
| 366 | */SeBackupPrivilegePoC.exe* | .{0,1000}\/SeBackupPrivilegePoC\.exe.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 10765 |
| 367 | */SecondaryLogonVariant.exe* | .{0,1000}\/SecondaryLogonVariant\.exe.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 10767 |
| 368 | */SeManageVolumeExploit.git* | .{0,1000}\/SeManageVolumeExploit\.git.{0,1000} | offensive_tool_keyword | SeManageVolumeExploit | This exploit grants full permission on C:\ drive for all users on the machine | T1046 - T1098 - T1222.002 | TA0007 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/CsEnox/SeManageVolumeExploit | 1 | 1 | N/A | N/A | 10 | 2 | 110 | 17 | 2023-05-29T05:41:16Z | 2021-10-11T01:17:04Z | 10783 |
| 369 | */ServiceName:TokenDriver* | .{0,1000}\/ServiceName\:TokenDriver.{0,1000} | offensive_tool_keyword | Tokenvator | A tool to elevate privilege with Windows Tokens | T1134 - T1078 | TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/0xbadjuju/Tokenvator | 1 | 1 | N/A | N/A | N/A | 10 | 1038 | 201 | 2023-10-06T13:17:05Z | 2017-12-08T01:29:11Z | 10801 |
| 370 | */SharpEfsPotato* | .{0,1000}\/SharpEfsPotato.{0,1000} | offensive_tool_keyword | SharpEfsPotato | Local privilege escalation from SeImpersonatePrivilege using EfsRpc. | T1548.002 - T1134.002 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/bugch3ck/SharpEfsPotato | 1 | 1 | N/A | N/A | 10 | 4 | 317 | 46 | 2022-10-17T12:35:06Z | 2022-10-17T12:20:47Z | 10957 |
| 371 | */SharpElevator.exe* | .{0,1000}\/SharpElevator\.exe.{0,1000} | offensive_tool_keyword | SharpElevator | SharpElevator is a C# implementation of Elevator for UAC bypass | T1548.002 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/SharpElevator | 1 | 1 | N/A | N/A | 10 | 1 | 51 | 12 | 2022-08-31T18:09:10Z | 2022-08-29T19:52:53Z | 10958 |
| 372 | */SharpElevator.git* | .{0,1000}\/SharpElevator\.git.{0,1000} | offensive_tool_keyword | SharpElevator | SharpElevator is a C# implementation of Elevator for UAC bypass | T1548.002 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/SharpElevator | 1 | 1 | N/A | N/A | 10 | 1 | 51 | 12 | 2022-08-31T18:09:10Z | 2022-08-29T19:52:53Z | 10959 |
| 373 | */SharpUp.git* | .{0,1000}\/SharpUp\.git.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 1 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 11148 |
| 374 | */ShimInjector.exe* | .{0,1000}\/ShimInjector\.exe.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 11232 |
| 375 | */ShimMe.git* | .{0,1000}\/ShimMe\.git.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 1 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 11233 |
| 376 | */SigmaPotato.git* | .{0,1000}\/SigmaPotato\.git.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 1 | N/A | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 11254 |
| 377 | */SigmaPotato/releases/download/* | .{0,1000}\/SigmaPotato\/releases\/download\/.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 1 | N/A | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 11255 |
| 378 | */SpoolFool.exe* | .{0,1000}\/SpoolFool\.exe.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 1 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 11540 | |
| 379 | */SpoolFool.git* | .{0,1000}\/SpoolFool\.git.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 1 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 11541 | |
| 380 | */SpoolFool.ps1* | .{0,1000}\/SpoolFool\.ps1.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 1 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 11542 | |
| 381 | */Sweetpotato.exe* | .{0,1000}\/Sweetpotato\.exe.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 1 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 11749 |
| 382 | */SweetPotato.git* | .{0,1000}\/SweetPotato\.git.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 1 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 11750 |
| 383 | */SweetPotato-master.zip* | .{0,1000}\/SweetPotato\-master\.zip.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 1 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 11752 |
| 384 | */SwitchPriv.exe* | .{0,1000}\/SwitchPriv\.exe.{0,1000} | offensive_tool_keyword | PrivFu | enable or disable specific token privileges for a process | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | SwitchPriv | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 11753 |
| 385 | */Telemetry.git* | .{0,1000}\/Telemetry\.git.{0,1000} | offensive_tool_keyword | Telemetry | Abusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges. | T1053 - T1547 - T1059 | TA0003 - TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Imanfeng/Telemetry | 1 | 1 | N/A | N/A | 9 | 2 | 140 | 13 | 2020-07-02T09:41:27Z | 2020-06-24T16:30:44Z | 11858 |
| 386 | */test_privesc.py* | .{0,1000}\/test_privesc\.py.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 1 | N/A | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 11864 |
| 387 | */timeoutpwn64* | .{0,1000}\/timeoutpwn64.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 11925 |
| 388 | */tmp/beacon_x64.bin* | .{0,1000}\/tmp\/beacon_x64\.bin.{0,1000} | offensive_tool_keyword | PoolPartyBof | A beacon object file implementation of PoolParty Process Injection Technique | T1055.011 - T1055 - T1620 | TA0005 | N/A | Black Basta | Privilege Escalation | https://github.com/0xEr3bus/PoolPartyBof | 1 | 0 | #linux | N/A | 10 | 4 | 380 | 44 | 2023-12-21T19:00:20Z | 2023-12-11T19:28:20Z | 11954 |
| 389 | */tmp/exploit* | .{0,1000}\/tmp\/exploit.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 11968 |
| 390 | */tmp/gtfokey.pub* | .{0,1000}\/tmp\/gtfokey\.pub.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | #linux | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 11974 |
| 391 | */tmp/libpwn.c* | .{0,1000}\/tmp\/libpwn\.c.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | #linux | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 11977 |
| 392 | */tmp/libpwn.so* | .{0,1000}\/tmp\/libpwn\.so.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | #linux | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 11978 |
| 393 | */tmp/passwd.bak* | .{0,1000}\/tmp\/passwd\.bak.{0,1000} | offensive_tool_keyword | POC | exploit the Linux Dirty Pipe vulnerability | T1068 - T1078.003 - T1071.004 - T1072 - T1105 | TA0004 - TA0006? | N/A | N/A | Privilege Escalation | https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits | 1 | 0 | #linux | N/A | 10 | 6 | 595 | 148 | 2023-05-20T05:55:45Z | 2022-03-12T20:57:24Z | 11983 |
| 394 | */tmp/r00tshell* | .{0,1000}\/tmp\/r00tshell.{0,1000} | offensive_tool_keyword | exploit-db | privilege escalation exploit pattern on https://www.exploit-db.com/exploits/38576 | T1068 - T1548 - T1055 - T1088 - T1134 - T1221 - T1543 - T1547 - T1574 | TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://www.exploit-db.com/exploits/38576 | 1 | 0 | #linux | linux privesc | 10 | 10 | N/A | N/A | N/A | N/A | 11989 |
| 395 | */tmp/shellcode.bin* | .{0,1000}\/tmp\/shellcode\.bin.{0,1000} | offensive_tool_keyword | PoolPartyBof | A beacon object file implementation of PoolParty Process Injection Technique | T1055.011 - T1055 - T1620 | TA0005 | N/A | Black Basta | Privilege Escalation | https://github.com/0xEr3bus/PoolPartyBof | 1 | 0 | #linux | N/A | 10 | 4 | 380 | 44 | 2023-12-21T19:00:20Z | 2023-12-11T19:28:20Z | 11993 |
| 396 | */tmp/traitor.so* | .{0,1000}\/tmp\/traitor\.so.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 12002 |
| 397 | */TokenAssignor.exe* | .{0,1000}\/TokenAssignor\.exe.{0,1000} | offensive_tool_keyword | PrivFu | Tool to execute token assigned process | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | TokenAssignor | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 12010 |
| 398 | */Token-Impersonation.git* | .{0,1000}\/Token\-Impersonation\.git.{0,1000} | offensive_tool_keyword | Token-Impersonation | Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required) | T1134.001 - T1134.002 | TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/Leo4j/Token-Impersonation | 1 | 1 | N/A | N/A | 8 | 1 | 7 | 3 | 2024-03-20T17:07:13Z | 2023-11-02T10:46:24Z | 12014 |
| 399 | */Token-Impersonation.ps1* | .{0,1000}\/Token\-Impersonation\.ps1.{0,1000} | offensive_tool_keyword | Token-Impersonation | Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required) | T1134.001 - T1134.002 | TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/Leo4j/Token-Impersonation | 1 | 1 | N/A | N/A | 8 | 1 | 7 | 3 | 2024-03-20T17:07:13Z | 2023-11-02T10:46:24Z | 12015 |
| 400 | */TokenPlayer.git* | .{0,1000}\/TokenPlayer\.git.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 1 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 12016 |
| 401 | */TokenStealing* | .{0,1000}\/TokenStealing.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 12018 |
| 402 | */TokenStealing.exe* | .{0,1000}\/TokenStealing\.exe.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 1 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 12019 |
| 403 | */Tokenvator/* | .{0,1000}\/Tokenvator\/.{0,1000} | offensive_tool_keyword | Tokenvator | A tool to elevate privilege with Windows Tokens | T1134 - T1078 | TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/0xbadjuju/Tokenvator | 1 | 1 | N/A | N/A | N/A | 10 | 1038 | 201 | 2023-10-06T13:17:05Z | 2017-12-08T01:29:11Z | 12027 |
| 404 | */tomcat-RH-root.sh* | .{0,1000}\/tomcat\-RH\-root\.sh.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 1 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 12029 |
| 405 | */traitor/pkg/backdoor* | .{0,1000}\/traitor\/pkg\/backdoor.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 12073 |
| 406 | */traitor/releases/download/* | .{0,1000}\/traitor\/releases\/download\/.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 12074 |
| 407 | */traitor-386* | .{0,1000}\/traitor\-386.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 12075 |
| 408 | */traitor-amd64* | .{0,1000}\/traitor\-amd64.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 12076 |
| 409 | */traitor-arm64* | .{0,1000}\/traitor\-arm64.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 12077 |
| 410 | */UAC-BOF-Bonanza.git* | .{0,1000}\/UAC\-BOF\-Bonanza\.git.{0,1000} | offensive_tool_keyword | cobaltstrike | Collection of UAC Bypass Techniques Weaponized as BOFs | T1548.002 - T1203 - T1055 - T1134.002 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/icyguider/UAC-BOF-Bonanza | 1 | 1 | N/A | N/A | 10 | 6 | 500 | 65 | 2024-02-21T22:07:54Z | 2024-02-16T14:47:13Z | 12204 |
| 411 | */UAC-TokenMagic.ps1* | .{0,1000}\/UAC\-TokenMagic\.ps1.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 1 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 12211 |
| 412 | */UserNamespaceOverlayfsSetuidWriteExec/* | .{0,1000}\/UserNamespaceOverlayfsSetuidWriteExec\/.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 12258 |
| 413 | */UserRightsUtil.exe* | .{0,1000}\/UserRightsUtil\.exe.{0,1000} | offensive_tool_keyword | PrivFu | manage user right without secpol.msc | T1059 - T1078 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | UserRightsUtil | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 12259 |
| 414 | */VDR.git* | .{0,1000}\/VDR\.git.{0,1000} | offensive_tool_keyword | VDR | Vulnerable driver research tool - result and exploit PoCs | T1547.009 - T1210 - T1068 - T1055 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/TakahiroHaruyama/VDR | 1 | 1 | N/A | N/A | 10 | 2 | 192 | 29 | 2023-11-01T00:06:55Z | 2023-10-23T08:34:44Z | 12425 |
| 415 | */VDR-main.zip | .{0,1000}\/VDR\-main\.zip | offensive_tool_keyword | VDR | Vulnerable driver research tool - result and exploit PoCs | T1547.009 - T1210 - T1068 - T1055 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/TakahiroHaruyama/VDR | 1 | 1 | N/A | N/A | 10 | 2 | 192 | 29 | 2023-11-01T00:06:55Z | 2023-10-23T08:34:44Z | 12426 |
| 416 | */vnik_v1.c* | .{0,1000}\/vnik_v1\.c.{0,1000} | offensive_tool_keyword | linux-exploit-suggester | Linux privilege escalation auditing tool | T1078 - T1068 - T1055 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/The-Z-Labs/linux-exploit-suggester | 1 | 0 | #linux | N/A | 10 | 10 | 5909 | 1133 | 2024-02-17T11:44:50Z | 2016-10-06T21:55:51Z | 12474 |
| 417 | */webdavshare/potato.local* | .{0,1000}\/webdavshare\/potato\.local.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | N/A | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 12533 |
| 418 | */WerTrigger.git* | .{0,1000}\/WerTrigger\.git.{0,1000} | offensive_tool_keyword | WerTrigger | Weaponizing for privileged file writes bugs with windows problem reporting | T1059.003 - T1055.001 - T1127.001 - T1546.008 | TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/sailay1996/WerTrigger | 1 | 1 | N/A | N/A | 9 | 3 | 221 | 36 | 2022-05-10T17:36:49Z | 2020-05-20T11:27:56Z | 12559 |
| 419 | */WfpTokenDup.exe* | .{0,1000}\/WfpTokenDup\.exe.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 12560 |
| 420 | */Windows_MSKSSRV_LPE_CVE-2023-36802.git* | .{0,1000}\/Windows_MSKSSRV_LPE_CVE\-2023\-36802\.git.{0,1000} | offensive_tool_keyword | Windows_MSKSSRV_LPE_CVE-2023-36802 | Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POC | T1068 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802 | 1 | 1 | N/A | N/A | 10 | 2 | 161 | 38 | 2023-10-10T17:44:17Z | 2023-10-09T17:32:15Z | 12598 |
| 421 | */winPEAS.exe* | .{0,1000}\/winPEAS\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 12623 |
| 422 | */winPEAS.ps1* | .{0,1000}\/winPEAS\.ps1.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 12627 |
| 423 | */winPEASany.exe* | .{0,1000}\/winPEASany\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 12628 |
| 424 | */winPEASany_ofs.exe* | .{0,1000}\/winPEASany_ofs\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 12630 |
| 425 | */winPEASany_ofs.exe* | .{0,1000}\/winPEASany_ofs\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 12631 |
| 426 | */winPEAS-Obfuscated.exe* | .{0,1000}\/winPEAS\-Obfuscated\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 12632 |
| 427 | */winPEASx64.exe* | .{0,1000}\/winPEASx64\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 12633 |
| 428 | */winPEASx86.exe* | .{0,1000}\/winPEASx86\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 1 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 12634 |
| 429 | */ZeroHVCI.exe* | .{0,1000}\/ZeroHVCI\.exe.{0,1000} | offensive_tool_keyword | ZeroHVCI | Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229 | T1068 - T1564 - T1014 - T1499 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/zer0condition/ZeroHVCI | 1 | 1 | N/A | N/A | 7 | 2 | 198 | 43 | 2024-10-26T17:08:38Z | 2024-07-20T07:29:18Z | 12810 |
| 430 | */ZeroHVCI.git* | .{0,1000}\/ZeroHVCI\.git.{0,1000} | offensive_tool_keyword | ZeroHVCI | Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229 | T1068 - T1564 - T1014 - T1499 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/zer0condition/ZeroHVCI | 1 | 1 | N/A | N/A | 7 | 2 | 198 | 43 | 2024-10-26T17:08:38Z | 2024-07-20T07:29:18Z | 12811 |
| 431 | *:\users\public\*.bat* | .{0,1000}\:\\users\\public\\.{0,1000}\.bat.{0,1000} | offensive_tool_keyword | _ | scripts in public user folder | T1036 - T1055 - T1574 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12853 |
| 432 | *:\users\public\*.hta* | .{0,1000}\:\\users\\public\\.{0,1000}\.ps1.{0,1000} | offensive_tool_keyword | _ | scripts in public user folder | T1036 - T1055 - T1574 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12854 |
| 433 | *:\users\public\*.ps1* | .{0,1000}\:\\users\\public\\.{0,1000}\.ps1.{0,1000} | offensive_tool_keyword | _ | scripts in public user folder | T1036 - T1055 - T1574 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12855 |
| 434 | *:\users\public\*.vbs* | .{0,1000}\:\\users\\public\\.{0,1000}\.vbs.{0,1000} | offensive_tool_keyword | _ | scripts in public user folder | T1036 - T1055 - T1574 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 12856 |
| 435 | *:CreateProcessFromParent((Get-Process "lsass").Id* | .{0,1000}\:CreateProcessFromParent\(\(Get\-Process\s\"lsass\"\)\.Id.{0,1000} | offensive_tool_keyword | psgetsystem | getsystem via parent process using ps1 & embeded c# | T1134 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/psgetsystem | 1 | 0 | N/A | N/A | 10 | 5 | 406 | 88 | 2023-10-26T07:13:08Z | 2018-02-02T11:28:22Z | 12868 |
| 436 | *[!] Couldn't capture the user credential hash :* | .{0,1000}\[!\]\sCouldn\'t\scapture\sthe\suser\scredential\shash\s\:.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 12899 |
| 437 | *[!] Couldn't communicate with the fake RPC Server* | .{0,1000}\[!\]\sCouldn\'t\scommunicate\swith\sthe\sfake\sRPC\sServer.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 12901 |
| 438 | *[!] Couldn't receive the type2 message from the fake RPC Server* | .{0,1000}\[!\]\sCouldn\'t\sreceive\sthe\stype2\smessage\sfrom\sthe\sfake\sRPC\sServer.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 12902 |
| 439 | *[!] Elevated process spawned!* | .{0,1000}\[!\]\sElevated\sprocess\sspawned!.{0,1000} | offensive_tool_keyword | Elevator | UAC bypass by abusing RPC and debug objects. | T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Kudaes/Elevator | 1 | 0 | #content | N/A | 10 | 7 | 614 | 69 | 2023-10-19T08:51:09Z | 2022-08-25T21:39:28Z | 12909 |
| 440 | *[!] Failed to delete Performance registry key.* | .{0,1000}\[!\]\sFailed\sto\sdelete\sPerformance\sregistry\skey\..{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 0 | #content | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 12915 |
| 441 | *[!] Found exploitable sgid binary* | .{0,1000}\[!\]\sFound\sexploitable\ssgid\sbinary.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | #content | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 12929 |
| 442 | *[!] Found exploitable Sudo NOPASSWD binary* | .{0,1000}\[!\]\sFound\sexploitable\sSudo\sNOPASSWD\sbinary.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | #content #linux | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 12930 |
| 443 | *[!] Found exploitable suid binary* | .{0,1000}\[!\]\sFound\sexploitable\ssuid\sbinary.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | #content | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 12931 |
| 444 | *[!] HTTP reflected DCOM authentication failed * | .{0,1000}\[!\]\sHTTP\sreflected\sDCOM\sauthentication\sfailed\s.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | #content | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 12934 |
| 445 | *[!] Modifialbe scheduled tasks were not evaluated due to permissions* | .{0,1000}\[!\]\sModifialbe\sscheduled\stasks\swere\snot\sevaluated\sdue\sto\spermissions.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | #content | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 12947 |
| 446 | *[!] Rasman service is not running!* | .{0,1000}\[!\]\sRasman\sservice\sis\snot\srunning!.{0,1000} | offensive_tool_keyword | RasmanPotato | using RasMan service for privilege escalation | T1548.002 - T1055.002 - T1055.001 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/crisprss/RasmanPotato | 1 | 0 | #content | N/A | 10 | 4 | 371 | 53 | 2023-02-06T10:27:41Z | 2023-02-06T09:41:51Z | 12954 |
| 447 | *[!] SMB reflected DCOM authentication failed* | .{0,1000}\[!\]\sSMB\sreflected\sDCOM\sauthentication\sfailed.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | #content | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 12959 |
| 448 | *[-] Exploit failed! * | .{0,1000}\[\-\]\sExploit\sfailed!\s.{0,1000} | offensive_tool_keyword | JuicyPotatoNG | Another Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | FoxKitten - APT33 - Volatile Cedar - Sandworm | Privilege Escalation | https://github.com/antonioCoco/JuicyPotatoNG | 1 | 0 | #content | N/A | 10 | 9 | 844 | 101 | 2022-11-12T01:48:39Z | 2022-09-21T17:08:35Z | 13006 |
| 449 | *[-] Failed to decrypt TGT using supplied password/hash. If this TGT was requested with no preauth then the password supplied may be incorrect or the data was encrypted with a different type of encryption than expected* | .{0,1000}\[\-\]\sFailed\sto\sdecrypt\sTGT\susing\ssupplied\spassword\/hash\.\sIf\sthis\sTGT\swas\srequested\swith\sno\spreauth\sthen\sthe\spassword\ssupplied\smay\sbe\sincorrect\sor\sthe\sdata\swas\sencrypted\swith\sa\sdifferent\stype\sof\sencryption\sthan\sexpected.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13008 |
| 450 | *[-] Failed to delete Performance DLL* | .{0,1000}\[\-\]\sFailed\sto\sdelete\sPerformance\sDLL.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 0 | #content | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 13009 |
| 451 | *[-] Failed to start reverse shell* | .{0,1000}\[\-\]\sFailed\sto\sstart\sreverse\sshell.{0,1000} | offensive_tool_keyword | RustPotato | A Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privileges | T1134.001 - T1055.011 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/emdnaia/RustPotato | 1 | 0 | #content | N/A | 10 | 1 | 0 | 0 | 2025-01-06T18:10:17Z | 2025-01-06T19:44:57Z | 13013 |
| 452 | *[+] Arbitrary Directory Creation to SYSTEM Shell technique !* | .{0,1000}\[\+\]\sArbitrary\sDirectory\sCreation\sto\sSYSTEM\sShell\stechnique\s!.{0,1000} | offensive_tool_keyword | DirCreate2System | Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting | T1068 - T1059.001 - T1070.004 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/binderlabs/DirCreate2System | 1 | 0 | #content | N/A | 8 | 4 | 357 | 38 | 2022-12-19T17:00:43Z | 2022-12-15T03:49:55Z | 13048 |
| 453 | *[+] AS-REQ w/o preauth successful!* | .{0,1000}\[\+\]\sAS\-REQ\sw\/o\spreauth\ssuccessful!.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | #content | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 13050 |
| 454 | *[+] Attempting DCOM NTLM relaying with CLSID* | .{0,1000}\[\+\]\sAttempting\sDCOM\sNTLM\srelaying\swith\sCLSID.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | #content | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 13053 |
| 455 | *[+] Attempting NP impersonation using method EfsRpc to launch * | .{0,1000}\[\+\]\sAttempting\sNP\simpersonation\susing\smethod\sEfsRpc\sto\slaunch\s.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | #content | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 13054 |
| 456 | *[+] Attempting NP impersonation using method PrintSpoofer to launch * | .{0,1000}\[\+\]\sAttempting\sNP\simpersonation\susing\smethod\sPrintSpoofer\sto\slaunch\s.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | #content | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 13055 |
| 457 | *[+] Building GTFOBins lists* | .{0,1000}\[\+\]\sBuilding\sGTFOBins\slists.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | #content | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 13071 |
| 458 | *[+] Building linux exploit suggesters* | .{0,1000}\[\+\]\sBuilding\slinux\sexploit\ssuggesters.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | #content #linux | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 13072 |
| 459 | *[+] Building S4U2proxy request for service: * | .{0,1000}\[\+\]\sBuilding\sS4U2proxy\srequest\sfor\sservice\:\s.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13073 |
| 460 | *[+] Building S4U2self * | .{0,1000}\[\+\]\sBuilding\sS4U2self\s.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13074 |
| 461 | *[+] cross realm S4U2Self success!* | .{0,1000}\[\+\]\scross\srealm\sS4U2Self\ssuccess!.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | #content | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 13094 |
| 462 | *[+] Downloading Fat Linpeas binaries* | .{0,1000}\[\+\]\sDownloading\sFat\sLinpeas\sbinaries.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | #content | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 13106 |
| 463 | *[+] dropping suid shell* | .{0,1000}\[\+\]\sdropping\ssuid\sshell.{0,1000} | offensive_tool_keyword | POC | exploit the Linux Dirty Pipe vulnerability | T1068 - T1078.003 - T1071.004 - T1072 - T1105 | TA0004 - TA0006? | N/A | N/A | Privilege Escalation | https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits | 1 | 0 | #content #linux | N/A | 10 | 6 | 595 | 148 | 2023-05-20T05:55:45Z | 2022-03-12T20:57:24Z | 13112 |
| 464 | *[+] Exploit Completed* | .{0,1000}\[\+\]\sExploit\sCompleted.{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/calebstewart/CVE-2021-1675 | 1 | 0 | #content | N/A | 10 | 10 | 1049 | 230 | 2021-07-05T08:54:06Z | 2021-07-01T23:45:58Z | 13136 |
| 465 | *[+] Exploit completed. Got a SYSTEM token! :)* | .{0,1000}\[\+\]\sExploit\scompleted\.\sGot\sa\sSYSTEM\stoken!\s\:\).{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 0 | #content | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 13137 |
| 466 | *[+] Exploit successful! * | .{0,1000}\[\+\]\sExploit\ssuccessful!\s.{0,1000} | offensive_tool_keyword | JuicyPotatoNG | Another Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | FoxKitten - APT33 - Volatile Cedar - Sandworm | Privilege Escalation | https://github.com/antonioCoco/JuicyPotatoNG | 1 | 0 | #content | N/A | 10 | 9 | 844 | 101 | 2022-11-12T01:48:39Z | 2022-09-21T17:08:35Z | 13138 |
| 467 | *[+] Exploit worked* it should execute your command as SYSTEM!* | .{0,1000}\[\+\]\sExploit\sworked.{0,1000}\sit\sshould\sexecute\syour\scommand\sas\sSYSTEM!.{0,1000} | offensive_tool_keyword | CoercedPotatoRDLL | Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege | T1055 - T1134 - T1548 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/sokaRepo/CoercedPotatoRDLL | 1 | 0 | #content | N/A | 10 | 3 | 204 | 31 | 2023-11-23T18:58:41Z | 2023-11-23T13:22:38Z | 13139 |
| 468 | *[+] Finding directory to hijack* | .{0,1000}\[\+\]\sFinding\sdirectory\sto\shijack.{0,1000} | offensive_tool_keyword | DirCreate2System | Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting | T1068 - T1059.001 - T1070.004 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/binderlabs/DirCreate2System | 1 | 0 | #content | N/A | 8 | 4 | 357 | 38 | 2022-12-19T17:00:43Z | 2022-12-15T03:49:55Z | 13142 |
| 469 | *[+] Getting credentials using U2U* | .{0,1000}\[\+\]\sGetting\scredentials\susing\sU2U.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13152 |
| 470 | *[+] Got a S4U logon token (Handle = * | .{0,1000}\[\+\]\sGot\sa\sS4U\slogon\stoken\s\(Handle\s\=\s.{0,1000} | offensive_tool_keyword | PrivFu | execute process as NT SERVICE\TrustedInstaller group account | T1059 - T1078 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #content | TrustExec | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 13155 |
| 471 | *[+] Got Krb Auth from NT/System. Relaying to ADCS now* | .{0,1000}\[\+\]\sGot\sKrb\sAuth\sfrom\sNT\/System\.\sRelaying\sto\sADCS\snow.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13156 |
| 472 | *[+] Got Krb Auth from NT/SYSTEM. Relying to LDAP now* | .{0,1000}\[\+\]\sGot\sKrb\sAuth\sfrom\sNT\/SYSTEM\.\sRelying\sto\sLDAP\snow.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13160 |
| 473 | *[+] hacked the exterior layer of the datacenter mainframe* | .{0,1000}\[\+\]\shacked\sthe\sexterior\slayer\sof\sthe\sdatacenter\smainframe.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #content #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 13165 |
| 474 | *[+] Hijackable DLL: * | .{0,1000}\[\+\]\sHijackable\sDLL\:\s.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | #content | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 13167 |
| 475 | *[+] hijacking suid binary* | .{0,1000}\[\+\]\shijacking\ssuid\sbinary.{0,1000} | offensive_tool_keyword | POC | exploit the Linux Dirty Pipe vulnerability | T1068 - T1078.003 - T1071.004 - T1072 - T1105 | TA0004 - TA0006? | N/A | N/A | Privilege Escalation | https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits | 1 | 0 | #content #linux | N/A | 10 | 6 | 595 | 148 | 2023-05-20T05:55:45Z | 2022-03-12T20:57:24Z | 13168 |
| 476 | *[+] HKLM\\SAM is saved successfully* | .{0,1000}\[\+\]\sHKLM\\\\SAM\sis\ssaved\ssuccessfully.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #content | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 13171 |
| 477 | *[+] HTTP Client Auth Context swapped with SYSTEM * | .{0,1000}\[\+\]\sHTTP\sClient\sAuth\sContext\sswapped\swith\sSYSTEM\s.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | #content | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 13174 |
| 478 | *[+] HTTP reflected DCOM authentication succeeded!* | .{0,1000}\[\+\]\sHTTP\sreflected\sDCOM\sauthentication\ssucceeded!.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | #content | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 13175 |
| 479 | *[+] Impersonating user * to target SPN * | .{0,1000}\[\+\]\sImpersonating\suser\s.{0,1000}\sto\starget\sSPN\s.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13178 |
| 480 | *[+] Impersonation as smss.exe* | .{0,1000}\[\+\]\sImpersonation\sas\ssmss\.exe.{0,1000} | offensive_tool_keyword | PrivFu | execute process as NT SERVICE\TrustedInstaller group account | T1059 - T1078 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #content | TrustExec | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 13179 |
| 481 | *[+] Impersonation as winlogon.exe is successful* | .{0,1000}\[\+\]\sImpersonation\sas\swinlogon\.exe\sis\ssuccessful.{0,1000} | offensive_tool_keyword | PrivFu | SeTcbPrivilege exploitation | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | #content | PrivFu\PowerOfTcb | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 13180 |
| 482 | *[+] Impersonation successful using token from PID * | .{0,1000}\[\+\]\sImpersonation\ssuccessful\susing\stoken\sfrom\sPID\s.{0,1000} | offensive_tool_keyword | Token-Impersonation | Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required) | T1134.001 - T1134.002 | TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/Leo4j/Token-Impersonation | 1 | 0 | #content | N/A | 8 | 1 | 7 | 3 | 2024-03-20T17:07:13Z | 2023-11-02T10:46:24Z | 13181 |
| 483 | *[+] Invoking EfsRpcAddUsersToFile with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcAddUsersToFile\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13192 |
| 484 | *[+] Invoking EfsRpcAddUsersToFileEx with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcAddUsersToFileEx\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13193 |
| 485 | *[+] Invoking EfsRpcDecryptFileSrv with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcDecryptFileSrv\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13194 |
| 486 | *[+] Invoking EfsRpcDuplicateEncryptionInfoFile with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcDuplicateEncryptionInfoFile\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13195 |
| 487 | *[+] Invoking EfsRpcDuplicateEncryptionInfoFile with target path:* | .{0,1000}\[\+\]\sInvoking\sEfsRpcDuplicateEncryptionInfoFile\swith\starget\spath\:.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13196 |
| 488 | *[+] Invoking EfsRpcEncryptFileSrv with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcEncryptFileSrv\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13197 |
| 489 | *[+] Invoking EfsRpcFileKeyInfo with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcFileKeyInfo\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13198 |
| 490 | *[+] Invoking EfsRpcFileKeyInfoEx with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcFileKeyInfoEx\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13199 |
| 491 | *[+] Invoking EfsRpcGetEncryptedFileMetadata with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcGetEncryptedFileMetadata\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13200 |
| 492 | *[+] Invoking EfsRpcOpenFileRaw with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcOpenFileRaw\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13201 |
| 493 | *[+] Invoking EfsRpcQueryRecoveryAgents with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcQueryRecoveryAgents\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13202 |
| 494 | *[+] Invoking EfsRpcQueryUsersOnFile with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcQueryUsersOnFile\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13203 |
| 495 | *[+] Invoking EfsRpcRemoveUsersFromFile with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcRemoveUsersFromFile\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13204 |
| 496 | *[+] Invoking EfsRpcSetEncryptedFileMetadata with target path: * | .{0,1000}\[\+\]\sInvoking\sEfsRpcSetEncryptedFileMetadata\swith\starget\spath\:\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13205 |
| 497 | *[+] Malicious named pipe running on * | .{0,1000}\[\+\]\sMalicious\snamed\spipe\srunning\son\s.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #content | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13224 |
| 498 | *[+] overwriting modprobe_path with different PIDs * | .{0,1000}\[\+\]\soverwriting\smodprobe_path\swith\sdifferent\sPIDs\s.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #content #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 13245 |
| 499 | *[+] Poc By @404death * | .{0,1000}\[\+\]\sPoc\sBy\s\@404death\s.{0,1000} | offensive_tool_keyword | DirCreate2System | Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting | T1068 - T1059.001 - T1070.004 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/binderlabs/DirCreate2System | 1 | 0 | #content | N/A | 8 | 4 | 357 | 38 | 2022-12-19T17:00:43Z | 2022-12-15T03:49:55Z | 13258 |
| 500 | *[+] popping root shell* | .{0,1000}\[\+\]\spopping\sroot\sshell.{0,1000} | offensive_tool_keyword | POC | exploit the Linux Dirty Pipe vulnerability | T1068 - T1078.003 - T1071.004 - T1072 - T1105 | TA0004 - TA0006? | N/A | N/A | Privilege Escalation | https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits | 1 | 0 | #content #linux | N/A | 10 | 6 | 595 | 148 | 2023-05-20T05:55:45Z | 2022-03-12T20:57:24Z | 13261 |
| 501 | *[+] Potenatially Hijackable DLL: * | .{0,1000}\[\+\]\sPotenatially\sHijackable\sDLL\:\s.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | #content | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 13262 |
| 502 | *[+] Rasman service is error* | .{0,1000}\[\+\]\sRasman\sservice\sis\serror.{0,1000} | offensive_tool_keyword | RasmanPotato | using RasMan service for privilege escalation | T1548.002 - T1055.002 - T1055.001 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/crisprss/RasmanPotato | 1 | 0 | #content | N/A | 10 | 4 | 371 | 53 | 2023-02-06T10:27:41Z | 2023-02-06T09:41:51Z | 13276 |
| 503 | *[+] Rasman service is running!* | .{0,1000}\[\+\]\sRasman\sservice\sis\srunning!.{0,1000} | offensive_tool_keyword | RasmanPotato | using RasMan service for privilege escalation | T1548.002 - T1055.002 - T1055.001 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/crisprss/RasmanPotato | 1 | 0 | #content | N/A | 10 | 4 | 371 | 53 | 2023-02-06T10:27:41Z | 2023-02-06T09:41:51Z | 13277 |
| 504 | *[+] Relaying seems successfull, check ntlmrelayx output!* | .{0,1000}\[\+\]\sRelaying\sseems\ssuccessfull,\scheck\sntlmrelayx\soutput!.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 13283 |
| 505 | *[+] Run the spawn method for SYSTEM shell:* | .{0,1000}\[\+\]\sRun\sthe\sspawn\smethod\sfor\sSYSTEM\sshell\:.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13290 |
| 506 | *[+] RUNNING ALL KNOWN EXPLOITS* | .{0,1000}\[\+\]\sRUNNING\sALL\sKNOWN\sEXPLOITS.{0,1000} | offensive_tool_keyword | CoercedPotato | CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022. | T1548.002 - T1134.002 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Prepouce/CoercedPotato | 1 | 0 | #content | N/A | 10 | 4 | 366 | 66 | 2024-08-26T08:09:00Z | 2023-09-11T19:04:29Z | 13291 |
| 507 | *[+] running normal privesc* | .{0,1000}\[\+\]\srunning\snormal\sprivesc.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #content #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 13292 |
| 508 | *[+] S4U2proxy success!* | .{0,1000}\[\+\]\sS4U2proxy\ssuccess!.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13294 |
| 509 | *[+] S4U2proxy success!* | .{0,1000}\[\+\]\sS4U2proxy\ssuccess!.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | #content | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 13295 |
| 510 | *[+] S4U2self success!* | .{0,1000}\[\+\]\sS4U2self\ssuccess!.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13296 |
| 511 | *[+] S4U2self success!* | .{0,1000}\[\+\]\sS4U2self\ssuccess!.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | #content | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 13297 |
| 512 | *[+] Sending S4U2proxy request to domain controller * | .{0,1000}\[\+\]\sSending\sS4U2proxy\srequest\sto\sdomain\scontroller\s.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13304 |
| 513 | *[+] Sending S4U2proxy request via KDC proxy: * | .{0,1000}\[\+\]\sSending\sS4U2proxy\srequest\svia\sKDC\sproxy\:\s.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13305 |
| 514 | *[+] Sending S4U2proxy request via KDC proxy:* | .{0,1000}\[\+\]\sSending\sS4U2proxy\srequest\svia\sKDC\sproxy\:.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13306 |
| 515 | *[+] Sending S4U2self request to * | .{0,1000}\[\+\]\sSending\sS4U2self\srequest\sto\s.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13307 |
| 516 | *[+] Sending S4U2self request via KDC proxy:* | .{0,1000}\[\+\]\sSending\sS4U2self\srequest\svia\sKDC\sproxy\:.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #content | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 13308 |
| 517 | *[+] Server connected to our evil RPC pipe* | .{0,1000}\[\+\]\sServer\sconnected\sto\sour\sevil\sRPC\spipe.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | #content | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 13311 |
| 518 | *[+] SeTcbPrivilege is enabled successfully* | .{0,1000}\[\+\]\sSeTcbPrivilege\sis\senabled\ssuccessfully.{0,1000} | offensive_tool_keyword | PrivFu | SeTcbPrivilege exploitation | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | #content | PrivFu\PowerOfTcb | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 13312 |
| 519 | *[+] SMB reflected DCOM authentication succeeded!* | .{0,1000}\[\+\]\sSMB\sreflected\sDCOM\sauthentication\ssucceeded!.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | #content | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 13321 |
| 520 | *[+] SMB reflected DCOM authentication succeeded!* | .{0,1000}\[\+\]\sSMB\sreflected\sDCOM\sauthentication\ssucceeded!.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | #content | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 13322 |
| 521 | *[+] Spawning root shell* | .{0,1000}\[\+\]\sSpawning\sroot\sshell.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | #content | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 13324 |
| 522 | *[+] Spawning SYSTEM shell* | .{0,1000}\[\+\]\sSpawning\sSYSTEM\sshell.{0,1000} | offensive_tool_keyword | DirCreate2System | Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting | T1068 - T1059.001 - T1070.004 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/binderlabs/DirCreate2System | 1 | 0 | #content | N/A | 8 | 4 | 357 | 38 | 2022-12-19T17:00:43Z | 2022-12-15T03:49:55Z | 13325 |
| 523 | *[+] Stole token from* | .{0,1000}\[\+\]\sStole\stoken\sfrom.{0,1000} | offensive_tool_keyword | Gotato | Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported. | T1003.003 - T1056.002 - T1550.001 - T1090 | TA0005 - TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/iammaguire/Gotato | 1 | 0 | #content | N/A | 9 | 2 | 112 | 16 | 2021-06-07T21:19:58Z | 2021-06-05T22:32:48Z | 13331 |
| 524 | *[+] successfully breached the mainframe as real-PID * | .{0,1000}\[\+\]\ssuccessfully\sbreached\sthe\smainframe\sas\sreal\-PID\s.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #content #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 13339 |
| 525 | *[+] Successfully downloaded GPO from fakedc to * | .{0,1000}\[\+\]\sSuccessfully\sdownloaded\sGPO\sfrom\sfakedc\sto\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | #content | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 13342 |
| 526 | *[+] Successfully injected malicious scheduled task* | .{0,1000}\[\+\]\sSuccessfully\sinjected\smalicious\sscheduled\stask.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | #content | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 13346 |
| 527 | *[+] Successfully set the spool directory to: * | .{0,1000}\[\+\]\sSuccessfully\sset\sthe\sspool\sdirectory\sto\:\s.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #content | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 13351 | |
| 528 | *[+] Successfully spoofed gPLink for OU * | .{0,1000}\[\+\]\sSuccessfully\sspoofed\sgPLink\sfor\sOU\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | #content | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 13353 |
| 529 | *[+] Successfully updated extension names of fakedc GPO* | .{0,1000}\[\+\]\sSuccessfully\supdated\sextension\snames\sof\sfakedc\sGPO.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | #content | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 13354 |
| 530 | *[+] Successfully uploaded GPO to SMB server * | .{0,1000}\[\+\]\sSuccessfully\suploaded\sGPO\sto\sSMB\sserver\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | #content | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 13355 |
| 531 | *[+] Triggering name pipe access on evil PIPE * | .{0,1000}\[\+\]\sTriggering\sname\spipe\saccess\son\sevil\sPIPE\s.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | #content | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 13374 |
| 532 | *[+] User hash stolen!* | .{0,1000}\[\+\]\sUser\shash\sstolen!.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 13387 |
| 533 | *[+] WOOT! Created elevated process * | .{0,1000}\[\+\]\sWOOT!\sCreated\selevated\sprocess\s.{0,1000} | offensive_tool_keyword | SharpElevator | SharpElevator is a C# implementation of Elevator for UAC bypass | T1548.002 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/SharpElevator | 1 | 0 | #content | N/A | 10 | 1 | 51 | 12 | 2022-08-31T18:09:10Z | 2022-08-29T19:52:53Z | 13420 |
| 534 | *[+]ImpersonateLoggedOnUser() succeed!* | .{0,1000}\[\+\]ImpersonateLoggedOnUser\(\)\ssucceed!.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | #content | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 13424 |
| 535 | *[winPEAS.Program]::Main(* | .{0,1000}\[winPEAS\.Program\]\:\:Main\(.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 13521 |
| 536 | *\\.\pipe\coerced\pipe\spoolss* | .{0,1000}\\\\\.\\pipe\\coerced\\pipe\\spoolss.{0,1000} | offensive_tool_keyword | CoercedPotatoRDLL | Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege | T1055 - T1134 - T1548 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/sokaRepo/CoercedPotatoRDLL | 1 | 0 | #namedpipe | N/A | 10 | 3 | 204 | 31 | 2023-11-23T18:58:41Z | 2023-11-23T13:22:38Z | 13585 |
| 537 | *\\.\pipe\PrivFu* | .{0,1000}\\\\\.\\pipe\\PrivFu.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #namedpipe | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 13598 |
| 538 | *\\.\pipe\pwned/pipe/srvsvc* | .{0,1000}\\\\\.\\pipe\\pwned\/pipe\/srvsvc.{0,1000} | offensive_tool_keyword | MultiPotato | get SYSTEM via SeImpersonate privileges | T1548.002 - T1134.002 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S3cur3Th1sSh1t/MultiPotato | 1 | 0 | #namedpipe | N/A | 10 | 6 | 518 | 92 | 2021-11-20T16:20:23Z | 2021-11-19T15:50:55Z | 13599 |
| 539 | *\\\\.\\pipe\\coerced\\pipe\\spoolss* | .{0,1000}\\\\\\\\\.\\\\pipe\\\\coerced\\\\pipe\\\\spoolss.{0,1000} | offensive_tool_keyword | CoercedPotato | CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022. | T1548.002 - T1134.002 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Prepouce/CoercedPotato | 1 | 0 | #namedpipe | N/A | 10 | 4 | 366 | 66 | 2024-08-26T08:09:00Z | 2023-09-11T19:04:29Z | 13627 |
| 540 | *\\\\.\\pipe\\coerced\\pipe\\srvsvc* | .{0,1000}\\\\\\\\\.\\\\pipe\\\\coerced\\\\pipe\\\\srvsvc.{0,1000} | offensive_tool_keyword | CoercedPotato | CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022. | T1548.002 - T1134.002 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Prepouce/CoercedPotato | 1 | 0 | #namedpipe | N/A | 10 | 4 | 366 | 66 | 2024-08-26T08:09:00Z | 2023-09-11T19:04:29Z | 13628 |
| 541 | *\\\\.\\pipe\\ElevationPipe* | .{0,1000}\\\\\\\\\.\\\\pipe\\\\ElevationPipe.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | #namedpipe | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 13630 |
| 542 | *\\\\.\\pipe\\innocent* | .{0,1000}\\\\\\\\\.\\\\pipe\\\\innocent.{0,1000} | offensive_tool_keyword | Windows_MSKSSRV_LPE_CVE-2023-36802 | Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POC | T1068 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802 | 1 | 0 | #namedpipe | N/A | 10 | 2 | 161 | 38 | 2023-10-10T17:44:17Z | 2023-10-09T17:32:15Z | 13632 |
| 543 | *\\\\.\\pipe\\ioring_in* | .{0,1000}\\\\\\\\\.\\\\pipe\\\\ioring_in.{0,1000} | offensive_tool_keyword | Windows_MSKSSRV_LPE_CVE-2023-36802 | Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POC | T1068 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802 | 1 | 0 | #namedpipe | N/A | 10 | 2 | 161 | 38 | 2023-10-10T17:44:17Z | 2023-10-09T17:32:15Z | 13633 |
| 544 | *\\\\.\\pipe\\ioring_out* | .{0,1000}\\\\\\\\\.\\\\pipe\\\\ioring_out.{0,1000} | offensive_tool_keyword | Windows_MSKSSRV_LPE_CVE-2023-36802 | Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POC | T1068 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802 | 1 | 0 | #namedpipe | N/A | 10 | 2 | 161 | 38 | 2023-10-10T17:44:17Z | 2023-10-09T17:32:15Z | 13634 |
| 545 | *\\\\.\\pipe\\mal* | .{0,1000}\\\\\\\\\.\\\\pipe\\\\mal.{0,1000} | offensive_tool_keyword | Gotato | Generic impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported. | T1003.003 - T1056.002 - T1550.001 - T1090 | TA0005 - TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/iammaguire/Gotato | 1 | 0 | #namedpipe | N/A | 9 | 2 | 112 | 16 | 2021-06-07T21:19:58Z | 2021-06-05T22:32:48Z | 13636 |
| 546 | *\\\\.\\pipe\\warpzone8* | .{0,1000}\\\\\\\\\.\\\\pipe\\\\warpzone8.{0,1000} | offensive_tool_keyword | elevationstation | elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative | T1548.002 - T1055 - T1574.002 - T1078.003 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/g3tsyst3m/elevationstation | 1 | 0 | #namedpipe | N/A | N/A | 4 | 368 | 45 | 2023-11-02T23:52:51Z | 2023-06-10T03:30:59Z | 13645 |
| 547 | *\\\\{attacker_ip}\\* | .{0,1000}\\\\\\\\\{attacker_ip\}\\\\.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 13646 |
| 548 | *\\\\{coerce_to}\\* | .{0,1000}\\\\\\\\\{coerce_to\}\\\\.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 13647 |
| 549 | *\\\\127.0.0.1\\pipe\\warpzone8* | .{0,1000}\\\\\\\\127\.0\.0\.1\\\\pipe\\\\warpzone8.{0,1000} | offensive_tool_keyword | elevationstation | elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative | T1548.002 - T1055 - T1574.002 - T1078.003 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/g3tsyst3m/elevationstation | 1 | 0 | #namedpipe | N/A | N/A | 4 | 368 | 45 | 2023-11-02T23:52:51Z | 2023-06-10T03:30:59Z | 13648 |
| 550 | *\\Debug\\Injected.dll* | .{0,1000}\\\\Debug\\\\Injected\.dll.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 13654 |
| 551 | *\\HackSysExtremeVulnerableDriver* | .{0,1000}\\\\HackSysExtremeVulnerableDriver.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 13663 |
| 552 | *\\localhost/pipe/petit\* | .{0,1000}\\\\localhost\/pipe\/petit\\.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13664 |
| 553 | *\\pipe\\GodPotato* | .{0,1000}\\\\pipe\\\\GodPotato.{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 0 | #namedpipe | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 13672 |
| 554 | *\\pipe\\petit\\pipe\\srvsvc* | .{0,1000}\\\\pipe\\\\petit\\\\pipe\\\\srvsvc.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #namedpipe | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 13676 |
| 555 | *\\pipe\\RustPotato* | .{0,1000}\\\\pipe\\\\RustPotato.{0,1000} | offensive_tool_keyword | RustPotato | A Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privileges | T1134.001 - T1055.011 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/emdnaia/RustPotato | 1 | 0 | #content #namedpipe | N/A | 10 | 1 | 0 | 0 | 2025-01-06T18:10:17Z | 2025-01-06T19:44:57Z | 13677 |
| 556 | *\\pipe\\SigmaPotato* | .{0,1000}\\\\pipe\\\\SigmaPotato.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 0 | #namedpipe | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 13678 |
| 557 | *\\Release\\Injected.dll* | .{0,1000}\\\\Release\\\\Injected\.dll.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 13683 |
| 558 | *\\temp\\Injected.dll* | .{0,1000}\\\\temp\\\\Injected\.dll.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 13689 |
| 559 | *\127.0.0.1/pipe/coerced* | .{0,1000}\\127\.0\.0\.1\/pipe\/coerced.{0,1000} | offensive_tool_keyword | CoercedPotatoRDLL | Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege | T1055 - T1134 - T1548 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/sokaRepo/CoercedPotatoRDLL | 1 | 0 | N/A | N/A | 10 | 3 | 204 | 31 | 2023-11-23T18:58:41Z | 2023-11-23T13:22:38Z | 13715 |
| 560 | *\ACE_Get-KerberosTicketCache.ps1* | .{0,1000}\\ACE_Get\-KerberosTicketCache\.ps1.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 13777 |
| 561 | *\ACEshark.log* | .{0,1000}\\ACEshark\.log.{0,1000} | offensive_tool_keyword | ACEshark | uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries | T1058 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/t3l3machus/ACEshark | 1 | 0 | #logfile | N/A | 6 | 2 | 109 | 19 | 2025-01-15T07:01:48Z | 2024-12-28T10:42:29Z | 13779 |
| 562 | *\ACEshark.py* | .{0,1000}\\ACEshark\.py.{0,1000} | offensive_tool_keyword | ACEshark | uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries | T1058 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/t3l3machus/ACEshark | 1 | 0 | N/A | N/A | 6 | 2 | 109 | 19 | 2025-01-15T07:01:48Z | 2024-12-28T10:42:29Z | 13780 |
| 563 | *\ADAPE.ps1* | .{0,1000}\\ADAPE\.ps1.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 0 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 13791 |
| 564 | *\ADCSPwn* | .{0,1000}\\ADCSPwn.{0,1000} | offensive_tool_keyword | ADCSPwn | A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service | T1550.002 - T1078.003 - T1110.003 - T1649 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/bats3c/ADCSPwn | 1 | 0 | N/A | N/A | 10 | 9 | 838 | 127 | 2023-03-20T20:30:40Z | 2021-07-30T15:04:41Z | 13807 |
| 565 | *\addcomputer_LDAP_spn.py* | .{0,1000}\\addcomputer_LDAP_spn\.py.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 13814 |
| 566 | *\addcomputer_with_spns.py* | .{0,1000}\\addcomputer_with_spns\.py.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 13815 |
| 567 | *\AddUser.dll* | .{0,1000}\\AddUser\.dll.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 13823 | |
| 568 | *\AddUser.sln* | .{0,1000}\\AddUser\.sln.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 13824 | |
| 569 | *\adm2sys.py* | .{0,1000}\\adm2sys\.py.{0,1000} | offensive_tool_keyword | PyExec | This is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses. | T1134 - T1055 - T1548.002 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/OlivierLaflamme/PyExec | 1 | 0 | N/A | N/A | 9 | 1 | 11 | 7 | 2019-09-11T13:56:04Z | 2019-09-11T13:54:15Z | 13853 |
| 570 | *\AlwaysInstallElevated.cs* | .{0,1000}\\AlwaysInstallElevated\.cs.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 13908 |
| 571 | *\BackgroundShell.exe* | .{0,1000}\\BackgroundShell\.exe.{0,1000} | offensive_tool_keyword | PrivFu | SeTcbPrivilege exploitation | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | PrivFu\PowerOfTcb | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 14199 |
| 572 | *\BackupOperatorToDA* | .{0,1000}\\BackupOperatorToDA.{0,1000} | offensive_tool_keyword | BackupOperatorToDA | From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller | T1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003 | TA0005 - TA0001 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/mpgn/BackupOperatorToDA | 1 | 0 | N/A | N/A | 10 | 5 | 421 | 53 | 2025-01-04T14:16:46Z | 2022-02-15T20:51:46Z | 14208 |
| 573 | *\BadPotato.csproj* | .{0,1000}\\BadPotato\.csproj.{0,1000} | offensive_tool_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | N/A | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 14216 |
| 574 | *\BadPotato.exe* | .{0,1000}\\BadPotato\.exe.{0,1000} | offensive_tool_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | N/A | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 14218 |
| 575 | *\BadWindowsService.cs* | .{0,1000}\\BadWindowsService\.cs.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 0 | N/A | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 14224 |
| 576 | *\BadWindowsService.exe* | .{0,1000}\\BadWindowsService\.exe.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 0 | N/A | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 14225 |
| 577 | *\BadWindowsService.sln* | .{0,1000}\\BadWindowsService\.sln.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 0 | N/A | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 14226 |
| 578 | *\Bat-Potato.bat* | .{0,1000}\\Bat\-Potato\.bat.{0,1000} | signature_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 0 | N/A | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 14276 |
| 579 | *\beRoot.exe* | .{0,1000}\\beRoot\.exe.{0,1000} | offensive_tool_keyword | BeRoot | Privilege Escalation Project - Windows / Linux / Mac | T1068 - T1055 - T1078 - T1548 - T1003 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/AlessandroZ/BeRoot | 1 | 0 | #linux | N/A | 10 | 10 | 2523 | 459 | 2024-10-04T11:54:01Z | 2017-04-14T12:47:31Z | 14287 |
| 580 | *\BITSInject.py* | .{0,1000}\\BITSInject\.py.{0,1000} | offensive_tool_keyword | BITSInject | A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account | T1197 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/SafeBreach-Labs/BITSInject | 1 | 0 | N/A | N/A | 8 | 1 | 99 | 18 | 2019-08-24T22:02:12Z | 2017-07-03T12:39:38Z | 14323 |
| 581 | *\BITSInject-master* | .{0,1000}\\BITSInject\-master.{0,1000} | offensive_tool_keyword | BITSInject | A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account | T1197 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/SafeBreach-Labs/BITSInject | 1 | 0 | N/A | N/A | 8 | 1 | 99 | 18 | 2019-08-24T22:02:12Z | 2017-07-03T12:39:38Z | 14324 |
| 582 | *\BITSJobPayloads.py* | .{0,1000}\\BITSJobPayloads\.py.{0,1000} | offensive_tool_keyword | BITSInject | A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account | T1197 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/SafeBreach-Labs/BITSInject | 1 | 0 | N/A | N/A | 8 | 1 | 99 | 18 | 2019-08-24T22:02:12Z | 2017-07-03T12:39:38Z | 14325 |
| 583 | *\bypassuac.txt* | .{0,1000}\\bypassuac\.txt.{0,1000} | offensive_tool_keyword | cobaltstrike | Collection of UAC Bypass Techniques Weaponized as BOFs | T1548.002 - T1203 - T1055 - T1134.002 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/icyguider/UAC-BOF-Bonanza | 1 | 0 | N/A | N/A | 10 | 6 | 500 | 65 | 2024-02-21T22:07:54Z | 2024-02-16T14:47:13Z | 14427 |
| 584 | *\C$\wh0nqs.txt.* | .{0,1000}\\C\$\\wh0nqs\.txt\..{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 14432 |
| 585 | *\CachedGPPPassword.cs* | .{0,1000}\\CachedGPPPassword\.cs.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 14455 |
| 586 | *\CoercedPotato.cpp* | .{0,1000}\\CoercedPotato\.cpp.{0,1000} | offensive_tool_keyword | CoercedPotatoRDLL | Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege | T1055 - T1134 - T1548 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/sokaRepo/CoercedPotatoRDLL | 1 | 0 | N/A | N/A | 10 | 3 | 204 | 31 | 2023-11-23T18:58:41Z | 2023-11-23T13:22:38Z | 14573 |
| 587 | *\Crassus-main* | .{0,1000}\\Crassus\-main.{0,1000} | offensive_tool_keyword | Crassus | Crassus Windows privilege escalation discovery tool | T1068 - T1003 - T1003.003 - T1046 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/vu-ls/Crassus | 1 | 0 | N/A | N/A | 10 | 6 | 571 | 59 | 2024-11-08T14:11:39Z | 2023-01-12T21:01:52Z | 14647 |
| 588 | *\CreateTokenVariant.exe* | .{0,1000}\\CreateTokenVariant\.exe.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 14655 |
| 589 | *\CurrentControlSet\Services\BadWindowsService* | .{0,1000}\\CurrentControlSet\\Services\\BadWindowsService.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 0 | #registry | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 14711 |
| 590 | *\CVE-2024-49138-POC-main* | .{0,1000}\\CVE\-2024\-49138\-POC\-main.{0,1000} | offensive_tool_keyword | POC | Windows Privilege escalation POC exploitation for CVE-2024-49138 | T1068 - T1058 - T1203 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/emdnaia/CVE-2024-49138-POC | 1 | 0 | N/A | N/A | 9 | 1 | 1 | 0 | 2025-01-15T01:01:21Z | 2025-01-15T02:11:49Z | 14752 |
| 591 | *\DeadPotato\pipe\epmapper* | .{0,1000}\\DeadPotato\\pipe\\epmapper.{0,1000} | offensive_tool_keyword | DeadPotato | DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | N/A | N/A | Privilege Escalation | https://github.com/lypd0/DeadPotato | 1 | 0 | #namedpipe | N/A | 10 | 4 | 382 | 45 | 2024-08-17T06:08:29Z | 2024-07-31T01:08:30Z | 14836 |
| 592 | *\Debug\Injected.dll* | .{0,1000}\\Debug\\Injected\.dll.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 14838 |
| 593 | *\DesktopShell.exe* | .{0,1000}\\DesktopShell\.exe.{0,1000} | offensive_tool_keyword | PrivFu | SeTcbPrivilege exploitation | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | PrivFu\PowerOfTcb | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 14912 |
| 594 | *\dircreate2system.pdb* | .{0,1000}\\dircreate2system\.pdb.{0,1000} | offensive_tool_keyword | DirCreate2System | Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting | T1068 - T1059.001 - T1070.004 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/binderlabs/DirCreate2System | 1 | 0 | N/A | N/A | 8 | 4 | 357 | 38 | 2022-12-19T17:00:43Z | 2022-12-15T03:49:55Z | 14936 |
| 595 | *\dircreate2system.sln* | .{0,1000}dircreate2system\.sln.{0,1000} | offensive_tool_keyword | DirCreate2System | Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting | T1068 - T1059.001 - T1070.004 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/binderlabs/DirCreate2System | 1 | 0 | N/A | N/A | 8 | 4 | 357 | 38 | 2022-12-19T17:00:43Z | 2022-12-15T03:49:55Z | 14937 |
| 596 | *\DirCreate2System\bin\* | .{0,1000}\\DirCreate2System\\bin\\.{0,1000} | offensive_tool_keyword | DirCreate2System | Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting | T1068 - T1059.001 - T1070.004 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/binderlabs/DirCreate2System | 1 | 0 | N/A | N/A | 8 | 4 | 357 | 38 | 2022-12-19T17:00:43Z | 2022-12-15T03:49:55Z | 14938 |
| 597 | *\DirtyCLR.sln* | .{0,1000}\\DirtyCLR\.sln.{0,1000} | offensive_tool_keyword | DirtyCLR | An App Domain Manager Injection DLL PoC | T1055.001 - T1546.016 - T1055.013 | TA0005 - TA0004 | N/A | Black Basta | Privilege Escalation | https://github.com/ipSlav/DirtyCLR | 1 | 0 | N/A | N/A | 7 | 2 | 170 | 19 | 2023-12-14T21:22:12Z | 2023-12-11T11:29:36Z | 14943 |
| 598 | *\DirtyCLR-main* | .{0,1000}\\DirtyCLR\-main.{0,1000} | offensive_tool_keyword | DirtyCLR | An App Domain Manager Injection DLL PoC | T1055.001 - T1546.016 - T1055.013 | TA0005 - TA0004 | N/A | Black Basta | Privilege Escalation | https://github.com/ipSlav/DirtyCLR | 1 | 0 | N/A | N/A | 7 | 2 | 170 | 19 | 2023-12-14T21:22:12Z | 2023-12-11T11:29:36Z | 14944 |
| 599 | *\DomainGPPPassword.cs* | .{0,1000}\\DomainGPPPassword\.cs.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 15024 |
| 600 | *\elevateit.bat* | .{0,1000}\\elevateit\.bat.{0,1000} | offensive_tool_keyword | elevationstation | elevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternative | T1548.002 - T1055 - T1574.002 - T1078.003 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/g3tsyst3m/elevationstation | 1 | 0 | N/A | N/A | N/A | 4 | 368 | 45 | 2023-11-02T23:52:51Z | 2023-06-10T03:30:59Z | 15254 |
| 601 | *\elevator.exe -* | .{0,1000}\\elevator\.exe\s\-.{0,1000} | offensive_tool_keyword | Elevator | UAC bypass by abusing RPC and debug objects. | T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Kudaes/Elevator | 1 | 0 | N/A | N/A | 10 | 7 | 614 | 69 | 2023-10-19T08:51:09Z | 2022-08-25T21:39:28Z | 15255 |
| 602 | *\Elevator\target\release* | .{0,1000}\\Elevator\\target\\release.{0,1000} | offensive_tool_keyword | Elevator | UAC bypass by abusing RPC and debug objects. | T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Kudaes/Elevator | 1 | 0 | N/A | N/A | 10 | 7 | 614 | 69 | 2023-10-19T08:51:09Z | 2022-08-25T21:39:28Z | 15256 |
| 603 | *\evil.dll* | .{0,1000}\\evil\.dll.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | N/A | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 15335 |
| 604 | *\exploit.c | .{0,1000}\\exploit\.c | offensive_tool_keyword | Windows_MSKSSRV_LPE_CVE-2023-36802 | Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POC | T1068 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802 | 1 | 0 | N/A | N/A | 10 | 2 | 161 | 38 | 2023-10-10T17:44:17Z | 2023-10-09T17:32:15Z | 15389 |
| 605 | *\exploit.exe* | .{0,1000}\\exploit\.exe.{0,1000} | offensive_tool_keyword | Windows_MSKSSRV_LPE_CVE-2023-36802 | Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POC | T1068 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-36802 | 1 | 0 | N/A | N/A | 10 | 2 | 161 | 38 | 2023-10-10T17:44:17Z | 2023-10-09T17:32:15Z | 15392 |
| 606 | *\ExploitableSystem.txt* | .{0,1000}\\ExploitableSystem\.txt.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 0 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 15394 |
| 607 | *\Godpotato\* | .{0,1000}\\Godpotato\\.{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 15661 |
| 608 | *\GodPotato\pipe\epmapper* | .{0,1000}\\GodPotato\\pipe\\epmapper.{0,1000} | offensive_tool_keyword | DeadPotato | DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | N/A | N/A | Privilege Escalation | https://github.com/lypd0/DeadPotato | 1 | 0 | #namedpipe | N/A | 10 | 4 | 382 | 45 | 2024-08-17T06:08:29Z | 2024-07-31T01:08:30Z | 15662 |
| 609 | *\gtfonow.py* | .{0,1000}\\gtfonow\.py.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | N/A | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 15746 |
| 610 | *\HijackablePaths.cs* | .{0,1000}\\HijackablePaths\.cs.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 15796 |
| 611 | *\IDiagnosticProfileUAC* | .{0,1000}\\IDiagnosticProfileUAC.{0,1000} | offensive_tool_keyword | IDiagnosticProfileUAC | UAC bypass using auto-elevated COM object Virtual Factory for DiagCpl | T1548.002 - T1059.003 - T1027.002 | TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/Wh04m1001/IDiagnosticProfileUAC | 1 | 0 | N/A | N/A | 10 | 2 | 182 | 32 | 2022-07-02T20:31:47Z | 2022-07-02T19:55:42Z | 15872 |
| 612 | *\Ikeext-Privesc* | .{0,1000}\\Ikeext\-Privesc.{0,1000} | offensive_tool_keyword | Ikeext-Privesc | Windows IKEEXT DLL Hijacking Exploit Tool | T1546.011 - T1574.009 - T1036.004 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/securycore/Ikeext-Privesc | 1 | 0 | N/A | N/A | 10 | 1 | 33 | 52 | 2018-02-25T13:45:15Z | 2018-02-27T11:18:56Z | 15884 |
| 613 | *\JuicyPotato.exe* | .{0,1000}\\JuicyPotato\.exe.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | N/A | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 16038 |
| 614 | *\JuicyPotato.pdb* | .{0,1000}\\JuicyPotato\.pdb.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/jakobfriedl/precompiled-binaries | 1 | 0 | N/A | N/A | 10 | 2 | 138 | 38 | 2025-03-06T13:02:11Z | 2023-08-08T12:21:46Z | 16039 |
| 615 | *\JuicyPotato.pdb* | .{0,1000}\\JuicyPotato\.pdb.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | #content | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 16040 |
| 616 | *\JuicyPotato_x32.exe* | .{0,1000}\\JuicyPotato_x32\.exe.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | N/A | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 16045 |
| 617 | *\JuicyPotato_x64.exe* | .{0,1000}\\JuicyPotato_x64\.exe.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | N/A | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 16046 |
| 618 | *\JuicyPotato-master* | .{0,1000}\\JuicyPotato\-master.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | N/A | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 16047 |
| 619 | *\JuicyPotatoNG* | .{0,1000}\\JuicyPotatoNG.{0,1000} | offensive_tool_keyword | JuicyPotatoNG | Another Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | FoxKitten - APT33 - Volatile Cedar - Sandworm | Privilege Escalation | https://github.com/antonioCoco/JuicyPotatoNG | 1 | 0 | N/A | N/A | 10 | 9 | 844 | 101 | 2022-11-12T01:48:39Z | 2022-09-21T17:08:35Z | 16048 |
| 620 | *\JuicyPotato-shellcode\* | .{0,1000}\\JuicyPotato\-shellcode\\.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | N/A | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 16049 |
| 621 | *\Juicy-Potato-x86-master* | .{0,1000}\\Juicy\-Potato\-x86\-master.{0,1000} | offensive_tool_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 0 | N/A | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 16050 |
| 622 | *\KernelTokens.sys* | .{0,1000}\\KernelTokens\.sys.{0,1000} | offensive_tool_keyword | Tokenvator | A tool to elevate privilege with Windows Tokens | T1134 - T1078 | TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/0xbadjuju/Tokenvator | 1 | 0 | N/A | N/A | N/A | 10 | 1038 | 201 | 2023-10-06T13:17:05Z | 2017-12-08T01:29:11Z | 16113 |
| 623 | *\KExecDD-main* | .{0,1000}\\KExecDD\-main.{0,1000} | offensive_tool_keyword | KExecDD | Admin to Kernel code execution using the KSecDD driver | T1068 - T1055.011 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/floesen/KExecDD | 1 | 0 | N/A | N/A | 8 | 3 | 244 | 41 | 2024-04-19T09:58:14Z | 2024-04-19T08:54:49Z | 16114 |
| 624 | *\KrbRelayUp.lib* | .{0,1000}\\KrbRelayUp\.lib.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 16180 |
| 625 | *\KrbSCM.cs* | .{0,1000}\\KrbSCM\.cs.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 16181 |
| 626 | *\LocalAdminSharp.sln* | .{0,1000}\\LocalAdminSharp\.sln.{0,1000} | offensive_tool_keyword | LocalAdminSharp | .NET executable to use when dealing with privilege escalation on Windows to gain local administrator access | T1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/notdodo/LocalAdminSharp | 1 | 0 | N/A | N/A | 10 | 2 | 157 | 17 | 2022-11-01T17:45:43Z | 2022-01-01T10:35:09Z | 16328 |
| 627 | *\LocalPotato\*.cpp* | .{0,1000}\\LocalPotato\\.{0,1000}\.cpp.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | N/A | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 16332 |
| 628 | *\LocalPotato\*.exe* | .{0,1000}\\LocalPotato\\.{0,1000}\.exe.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | N/A | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 16333 |
| 629 | *\MakeMeAdmin * x64 Debug.msi* | .{0,1000}\\MakeMeAdmin\s.{0,1000}\sx64\sDebug\.msi.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 16436 |
| 630 | *\MakeMeAdmin * x64.msi* | .{0,1000}\\MakeMeAdmin\s.{0,1000}\sx64\.msi.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 16437 |
| 631 | *\MakeMeAdmin.sln* | .{0,1000}\\MakeMeAdmin\.sln.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 16438 |
| 632 | *\MakeMeAdmin-main* | .{0,1000}\\MakeMeAdmin\-main.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 16439 |
| 633 | *\MakeMeEnterpriseAdmin.ps1 | .{0,1000}\\MakeMeEnterpriseAdmin\.ps1 | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 16440 |
| 634 | *\MakeMeEnterpriseAdmin.ps1* | .{0,1000}\\MakeMeEnterpriseAdmin\.ps1.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 16441 |
| 635 | *\modifiableautorun.o* | .{0,1000}\\modifiableautorun\.o.{0,1000} | offensive_tool_keyword | PrivKit | PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS. | T1548.002 - T1059.003 - T1027.002 | TA0005 | N/A | N/A | Privilege Escalation | https://github.com/mertdas/PrivKit | 1 | 0 | N/A | N/A | 9 | 5 | 405 | 47 | 2024-06-15T16:54:32Z | 2023-03-20T04:19:40Z | 16649 |
| 636 | *\MSFRottenPotato.cpp* | .{0,1000}\\MSFRottenPotato\.cpp.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | N/A | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 16673 |
| 637 | *\MSFRottenPotato.log* | .{0,1000}\\MSFRottenPotato\.log.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | N/A | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 16675 |
| 638 | *\MSFRottenPotato.sln* | .{0,1000}\\MSFRottenPotato\.sln.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | N/A | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 16676 |
| 639 | *\MSFRottenPotatoTestHarness.* | .{0,1000}\\MSFRottenPotatoTestHarness\..{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | N/A | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 16677 |
| 640 | *\NamedPipeClient.exe* | .{0,1000}\\NamedPipeClient\.exe.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 16719 |
| 641 | *\NamedPipeClient.exe* | .{0,1000}\\NamedPipeClient\.exe.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 16720 |
| 642 | *\NoFilter.cpp* | .{0,1000}\\NoFilter\.cpp.{0,1000} | offensive_tool_keyword | NoFilter | Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine. | T1548 - T1548.002 - T1055 - T1055.004 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/NoFilter | 1 | 0 | N/A | N/A | 9 | 3 | 298 | 48 | 2024-10-29T07:30:35Z | 2023-07-30T09:25:38Z | 16945 |
| 643 | *\NoFilter.exe* | .{0,1000}\\NoFilter\.exe.{0,1000} | offensive_tool_keyword | NoFilter | Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine. | T1548 - T1548.002 - T1055 - T1055.004 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/NoFilter | 1 | 0 | N/A | N/A | 9 | 3 | 298 | 48 | 2024-10-29T07:30:35Z | 2023-07-30T09:25:38Z | 16946 |
| 644 | *\NoFilter.sln* | .{0,1000}\\NoFilter\.sln.{0,1000} | offensive_tool_keyword | NoFilter | Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine. | T1548 - T1548.002 - T1055 - T1055.004 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/NoFilter | 1 | 0 | N/A | N/A | 9 | 3 | 298 | 48 | 2024-10-29T07:30:35Z | 2023-07-30T09:25:38Z | 16947 |
| 645 | *\NoFilter.vcxproj* | .{0,1000}\\NoFilter\.vcxproj.{0,1000} | offensive_tool_keyword | NoFilter | Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine. | T1548 - T1548.002 - T1055 - T1055.004 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/NoFilter | 1 | 0 | N/A | N/A | 9 | 3 | 298 | 48 | 2024-10-29T07:30:35Z | 2023-07-30T09:25:38Z | 16948 |
| 646 | *\NTLMRelay2Self* | .{0,1000}\\NTLMRelay2Self.{0,1000} | offensive_tool_keyword | NTLMRelay2Self | An other No-Fix LPE - NTLMRelay2Self over HTTP (Webdav). | T1078 - T1078.004 - T1557 - T1557.001 - T1068 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/med0x2e/NTLMRelay2Self | 1 | 0 | N/A | N/A | 10 | 5 | 400 | 42 | 2024-01-27T08:52:03Z | 2022-04-30T10:05:02Z | 16995 |
| 647 | *\NtRights\* | .{0,1000}\\NtRights\\.{0,1000} | offensive_tool_keyword | NtRights | tool for adding privileges from the commandline | T1548.002 - T1059.003 - T1027.002 | TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/gtworek/PSBits/tree/master/NtRights | 1 | 0 | N/A | N/A | 7 | 10 | 3337 | 542 | 2025-03-12T19:59:23Z | 2019-06-29T13:22:36Z | 17007 |
| 648 | *\OfficeInjector.exe* | .{0,1000}\\OfficeInjector\.exe.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 17034 |
| 649 | *\ouned_smbserver.py* | .{0,1000}\\ouned_smbserver\.py.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 17062 |
| 650 | *\PEASS-ng* | .{0,1000}\\PEASS\-ng.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 17180 |
| 651 | *\Perfusion.cpp* | .{0,1000}\\Perfusion\.cpp.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 0 | N/A | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 17185 |
| 652 | *\Perfusion.exe* | .{0,1000}\\Perfusion\.exe.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 0 | N/A | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 17186 |
| 653 | *\Perfusion.sln* | .{0,1000}\\Perfusion\.sln.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 0 | N/A | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 17187 |
| 654 | *\PerfusionDll.cpp* | .{0,1000}\\PerfusionDll\.cpp.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 0 | N/A | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 17188 |
| 655 | *\PerfusionDll.dll* | .{0,1000}\\PerfusionDll\.dll.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 0 | N/A | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 17189 |
| 656 | *\PerfusionDll.log* | .{0,1000}\\PerfusionDll\.log.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 0 | N/A | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 17190 |
| 657 | *\petit\pipe\srvsvc* | .{0,1000}\\petit\\pipe\\srvsvc.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | #namedpipe | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17218 |
| 658 | *\PetitPotato.cpp* | .{0,1000}\\PetitPotato\.cpp.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17221 |
| 659 | *\PetitPotato.log* | .{0,1000}\\PetitPotato\.log.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17222 |
| 660 | *\petitpotato.obj* | .{0,1000}\\petitpotato\.obj.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17223 |
| 661 | *\petitpotato.pdb* | .{0,1000}\\petitpotato\.pdb.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17224 |
| 662 | *\PetitPotato.sln* | .{0,1000}\\PetitPotato\.sln.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17225 |
| 663 | *\PetitPotato.tlog* | .{0,1000}\\PetitPotato\.tlog.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17226 |
| 664 | *\PetitPotato.vcxproj* | .{0,1000}\\PetitPotato\.vcxproj.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17227 |
| 665 | *\petitpotato\x64\* | .{0,1000}\\petitpotato\\x64\\.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17228 |
| 666 | *\PetitPotato-1.0.0.zip* | .{0,1000}\\PetitPotato\-1\.0\.0\.zip.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17229 |
| 667 | *\PetitPotato-1.0.0\* | .{0,1000}\\PetitPotato\-1\.0\.0\\.{0,1000} | offensive_tool_keyword | PetitPotato | Local privilege escalation via PetitPotam (Abusing impersonate privileges) | T1134.005 - T1548.001 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/PetitPotato | 1 | 0 | N/A | N/A | 10 | 5 | 430 | 52 | 2023-03-30T10:45:00Z | 2022-04-19T19:59:19Z | 17230 |
| 668 | *\pipe\ElevationPipe* | .{0,1000}\\pipe\\ElevationPipe.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | #namedpipe | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 17270 |
| 669 | *\pipe\GodPotato* | .{0,1000}\\pipe\\GodPotato.{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 0 | #namedpipe | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 17271 |
| 670 | *\pipe\RustPotato* | .{0,1000}\\pipe\\RustPotato.{0,1000} | offensive_tool_keyword | RustPotato | A Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privileges | T1134.001 - T1055.011 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/emdnaia/RustPotato | 1 | 0 | #content #namedpipe | N/A | 10 | 1 | 0 | 0 | 2025-01-06T18:10:17Z | 2025-01-06T19:44:57Z | 17279 |
| 671 | *\pipe\SigmaPotato* | .{0,1000}\\pipe\\SigmaPotato.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 0 | #namedpipe | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 17280 |
| 672 | *\PoC\PrivilegeEscalation* | .{0,1000}\\PoC\\PrivilegeEscalation.{0,1000} | offensive_tool_keyword | echoac-poc | poc stealing the Kernel's KPROCESS/EPROCESS block and writing it to a newly spawned shell to elevate its privileges to the highest possible - nt authority\system | T1068 - T1203 - T1059.003 | TA0002 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/kite03/echoac-poc | 1 | 0 | N/A | N/A | 8 | 2 | 138 | 25 | 2024-01-09T16:44:00Z | 2023-06-28T00:52:22Z | 17309 |
| 673 | *\Potato.exe* | .{0,1000}\\Potato\.exe.{0,1000} | offensive_tool_keyword | potato | Potato Privilege Escalation on Windows | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/foxglovesec/Potato | 1 | 0 | N/A | N/A | 7 | 8 | 721 | 165 | 2021-01-16T20:34:04Z | 2016-02-09T11:28:17Z | 17349 |
| 674 | *\Potato\obj\Release\Potato.pdb* | .{0,1000}\\Potato\\obj\\Release\\Potato\.pdb.{0,1000} | offensive_tool_keyword | potato | Potato Privilege Escalation on Windows | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/foxglovesec/Potato | 1 | 0 | #content | N/A | 7 | 8 | 721 | 165 | 2021-01-16T20:34:04Z | 2016-02-09T11:28:17Z | 17350 |
| 675 | *\PotatoTrigger.cpp* | .{0,1000}PotatoTrigger\.cpp.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | N/A | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 17351 |
| 676 | *\Powermad.ps1* | .{0,1000}\\Powermad\.ps1.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 17374 |
| 677 | *\prefetch_leak.h* | .{0,1000}\\prefetch_leak\.h.{0,1000} | offensive_tool_keyword | prefetch-tool | Windows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitation | T1564.007 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/exploits-forsale/prefetch-tool | 1 | 0 | N/A | N/A | 8 | 1 | 90 | 10 | 2024-04-26T05:40:32Z | 2024-04-26T05:00:27Z | 17444 |
| 678 | *\prefetch_tool.sln* | .{0,1000}\\prefetch_tool\.sln.{0,1000} | offensive_tool_keyword | prefetch-tool | Windows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitation | T1564.007 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/exploits-forsale/prefetch-tool | 1 | 0 | N/A | N/A | 8 | 1 | 90 | 10 | 2024-04-26T05:40:32Z | 2024-04-26T05:00:27Z | 17445 |
| 679 | *\prefetch_tool.vcxproj* | .{0,1000}\\prefetch_tool\.vcxproj.{0,1000} | offensive_tool_keyword | prefetch-tool | Windows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitation | T1564.007 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/exploits-forsale/prefetch-tool | 1 | 0 | N/A | N/A | 8 | 1 | 90 | 10 | 2024-04-26T05:40:32Z | 2024-04-26T05:00:27Z | 17446 |
| 680 | *\PrintNightmare.* | .{0,1000}\\PrintNightmare\..{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/outflanknl/PrintNightmare | 1 | 0 | N/A | N/A | 10 | 4 | 337 | 67 | 2021-09-13T08:45:26Z | 2021-09-13T08:44:02Z | 17456 |
| 681 | *\PrintSpoofer.cs* | .{0,1000}\\PrintSpoofer\.cs.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 17458 |
| 682 | *\PrintSpoofer.exe* | .{0,1000}\\PrintSpoofer\.exe.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 17465 |
| 683 | *\PrintSpoofer-1.0.zip* | .{0,1000}\\PrintSpoofer\-1\.0\.zip.{0,1000} | offensive_tool_keyword | printspoofer | Abusing impersonation privileges through the Printer Bug | T1134 - T1003 - T1055 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrintSpoofer | 1 | 0 | N/A | N/A | 10 | 10 | 1971 | 342 | 2020-09-10T17:49:41Z | 2020-04-28T08:26:29Z | 17466 |
| 684 | *\PrivEditor.dll* | .{0,1000}\\PrivEditor\.dll.{0,1000} | offensive_tool_keyword | PrivFu | Kernel Mode WinDbg extension for token privilege edit | T1055 - T1078 - T1134 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 17467 |
| 685 | *\PrivEditor\* | .{0,1000}\\PrivEditor\\.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 17468 |
| 686 | *\privesc.ps1* | .{0,1000}\\privesc\.ps1.{0,1000} | offensive_tool_keyword | Privesc | Windows PowerShell script that finds misconfiguration issues which can lead to privilege escalation | T1068 - T1548 - T1082 - T1078 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/enjoiz/Privesc | 1 | 0 | N/A | N/A | 10 | 6 | 595 | 97 | 2024-12-01T15:24:41Z | 2015-11-19T13:22:01Z | 17469 |
| 687 | *\PrivEsc.txt* | .{0,1000}\\PrivEsc\.txt.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 0 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 17470 |
| 688 | *\PrivescCheck* | .{0,1000}\\PrivescCheck.{0,1000} | offensive_tool_keyword | PrivescCheck | Privilege Escalation Enumeration Script for Windows | T1053 - T1088 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrivescCheck | 1 | 0 | N/A | N/A | 10 | 10 | 3230 | 460 | 2025-03-05T14:44:17Z | 2020-01-16T12:28:10Z | 17471 |
| 689 | *\PrivescCheck_* | .{0,1000}\\PrivescCheck_.{0,1000} | offensive_tool_keyword | PrivescCheck | Privilege Escalation Enumeration Script for Windows | T1053 - T1088 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrivescCheck | 1 | 0 | N/A | N/A | 10 | 10 | 3230 | 460 | 2025-03-05T14:44:17Z | 2020-01-16T12:28:10Z | 17473 |
| 690 | *\PrivescCheck_* | .{0,1000}\\PrivescCheck_.{0,1000} | offensive_tool_keyword | PrivescCheck | Privilege Escalation Enumeration Script for Windows | T1053 - T1088 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrivescCheck | 1 | 0 | N/A | N/A | 10 | 10 | 3230 | 460 | 2025-03-05T14:44:17Z | 2020-01-16T12:28:10Z | 17474 |
| 691 | *\Privesc-master* | .{0,1000}\\Privesc\-master.{0,1000} | offensive_tool_keyword | Privesc | Windows PowerShell script that finds misconfiguration issues which can lead to privilege escalation | T1068 - T1548 - T1082 - T1078 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/enjoiz/Privesc | 1 | 0 | N/A | N/A | 10 | 6 | 595 | 97 | 2024-12-01T15:24:41Z | 2015-11-19T13:22:01Z | 17475 |
| 692 | *\PrivFu.txt* | .{0,1000}\\PrivFu\.txt.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 17477 |
| 693 | *\PrivKit\* | .{0,1000}\\PrivKit\\.{0,1000} | offensive_tool_keyword | PrivKit | PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS. | T1548.002 - T1059.003 - T1027.002 | TA0005 | N/A | N/A | Privilege Escalation | https://github.com/mertdas/PrivKit | 1 | 0 | N/A | N/A | 9 | 5 | 405 | 47 | 2024-06-15T16:54:32Z | 2023-03-20T04:19:40Z | 17479 |
| 694 | *\ProcessDLLHijack.cs* | .{0,1000}\\ProcessDLLHijack\.cs.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 17485 |
| 695 | *\ProcessSpoofing.h* | .{0,1000}\\ProcessSpoofing\.h.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 17487 |
| 696 | *\Program Files\Bad Windows Service* | .{0,1000}\\Program\sFiles\\Bad\sWindows\sService.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 0 | N/A | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 17514 |
| 697 | *\psgetsys.ps1* | .{0,1000}\\psgetsys\.ps1.{0,1000} | offensive_tool_keyword | psgetsystem | getsystem via parent process using ps1 & embeded c# | T1134 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/psgetsystem | 1 | 0 | N/A | N/A | 10 | 5 | 406 | 88 | 2023-10-26T07:13:08Z | 2018-02-02T11:28:22Z | 17608 |
| 698 | *\RasMan.cpp* | .{0,1000}RasMan\.cpp.{0,1000} | offensive_tool_keyword | RasmanPotato | using RasMan service for privilege escalation | T1548.002 - T1055.002 - T1055.001 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/crisprss/RasmanPotato | 1 | 0 | N/A | N/A | 10 | 4 | 371 | 53 | 2023-02-06T10:27:41Z | 2023-02-06T09:41:51Z | 17745 |
| 699 | *\rasman.exe* | .{0,1000}\\rasman\.exe.{0,1000} | offensive_tool_keyword | RasmanPotato | using RasMan service for privilege escalation | T1548.002 - T1055.002 - T1055.001 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/crisprss/RasmanPotato | 1 | 0 | N/A | N/A | 10 | 4 | 371 | 53 | 2023-02-06T10:27:41Z | 2023-02-06T09:41:51Z | 17746 |
| 700 | *\RasMan.sln* | .{0,1000}RasMan\.sln.{0,1000} | offensive_tool_keyword | RasmanPotato | using RasMan service for privilege escalation | T1548.002 - T1055.002 - T1055.001 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/crisprss/RasmanPotato | 1 | 0 | N/A | N/A | 10 | 4 | 371 | 53 | 2023-02-06T10:27:41Z | 2023-02-06T09:41:51Z | 17747 |
| 701 | *\RasmanPotato* | .{0,1000}\\RasmanPotato.{0,1000} | offensive_tool_keyword | RasmanPotato | using RasMan service for privilege escalation | T1548.002 - T1055.002 - T1055.001 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/crisprss/RasmanPotato | 1 | 0 | N/A | N/A | 10 | 4 | 371 | 53 | 2023-02-06T10:27:41Z | 2023-02-06T09:41:51Z | 17748 |
| 702 | *\Relay\Attacks\ShadowCred.cs* | .{0,1000}\\Relay\\Attacks\\ShadowCred\.cs.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | N/A | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 17894 |
| 703 | *\Release\Injected.dll* | .{0,1000}\\Release\\Injected\.dll.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 17898 |
| 704 | *\Release\SpoolFool.pdb* | .{0,1000}\\Release\\SpoolFool\.pdb.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 17902 | |
| 705 | *\RemotePotato0.cpp* | .{0,1000}\\RemotePotato0\.cpp.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 18005 |
| 706 | *\RemotePotato0.sln* | .{0,1000}\\RemotePotato0\.sln.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 18006 |
| 707 | *\RemotePotato0.zip* | .{0,1000}\\RemotePotato0\.zip.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 18007 |
| 708 | *\RemotePotato0-main.zip* | .{0,1000}\\RemotePotato0\-main\.zip.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 18008 |
| 709 | *\RemotePotato0-main\* | .{0,1000}\\RemotePotato0\-main\\.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 18009 |
| 710 | *\Resources\mimikatz.exe* | .{0,1000}\\Resources\\mimikatz\.exe.{0,1000} | offensive_tool_keyword | DeadPotato | DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | N/A | N/A | Privilege Escalation | https://github.com/lypd0/DeadPotato | 1 | 0 | N/A | N/A | 10 | 4 | 382 | 45 | 2024-08-17T06:08:29Z | 2024-07-31T01:08:30Z | 18026 |
| 711 | *\RogueOxidResolver.cpp* | .{0,1000}\\RogueOxidResolver\.cpp.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | N/A | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 18090 |
| 712 | *\RogueWinRM.sln* | .{0,1000}\\RogueWinRM\.sln.{0,1000} | offensive_tool_keyword | RogueWinRM | RogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not running | T1548.003 - T1134.002 - T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RogueWinRM | 1 | 0 | N/A | N/A | 10 | 8 | 788 | 107 | 2020-02-23T19:26:41Z | 2019-12-02T22:58:03Z | 18091 |
| 713 | *\RogueWinRM\* | .{0,1000}\\RogueWinRM\\.{0,1000} | offensive_tool_keyword | RogueWinRM | RogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not running | T1548.003 - T1134.002 - T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RogueWinRM | 1 | 0 | N/A | N/A | 10 | 8 | 788 | 107 | 2020-02-23T19:26:41Z | 2019-12-02T22:58:03Z | 18092 |
| 714 | *\RottenPotatoNG-main* | .{0,1000}\\RottenPotatoNG\-main.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | N/A | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 18107 |
| 715 | *\RottenPotatoNG-master* | .{0,1000}\\RottenPotatoNG\-master.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | N/A | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 18108 |
| 716 | *\RustPotato-main* | .{0,1000}\\RustPotato\-main.{0,1000} | offensive_tool_keyword | RustPotato | A Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privileges | T1134.001 - T1055.011 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/emdnaia/RustPotato | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2025-01-06T18:10:17Z | 2025-01-06T19:44:57Z | 18237 |
| 717 | *\S4U.Exe* | .{0,1000}\\S4U\.Exe.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 18246 |
| 718 | *\S4uDelegator.* | .{0,1000}\\S4uDelegator\..{0,1000} | offensive_tool_keyword | PrivFu | perform S4U logon with SeTcbPrivilege | T1134 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | S4uDelegator | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 18247 |
| 719 | *\S4UTomato\* | .{0,1000}\\S4UTomato\\.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 18248 |
| 720 | *\SeAuditPrivilegePoC.exe* | .{0,1000}\\SeAuditPrivilegePoC\.exe.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 18343 |
| 721 | *\SeBackupPrivilegePoC.exe* | .{0,1000}\\SeBackupPrivilegePoC\.exe.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 18344 |
| 722 | *\SecondaryLogonVariant.exe* | .{0,1000}\\SecondaryLogonVariant\.exe.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 18345 |
| 723 | *\SeRestorePrivilegeTestFile.txt* | .{0,1000}\\SeRestorePrivilegeTestFile\.txt.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 18355 |
| 724 | *\ShadowCredentials.cs* | .{0,1000}\\ShadowCredentials\.cs.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 18402 |
| 725 | *\ShareFinder.txt* | .{0,1000}\\ShareFinder\.txt.{0,1000} | offensive_tool_keyword | ADAPE-Script | Active Directory Assessment and Privilege Escalation Script | T1178 - T1087 - T1482 | TA0002 - TA0004 - TA0007 | N/A | Black Basta | Privilege Escalation | https://github.com/cjoan75/ADAPE-Script | 1 | 0 | N/A | N/A | 8 | 1 | 0 | 0 | 2020-07-11T00:53:24Z | 2020-08-09T16:52:35Z | 18421 |
| 726 | *\SharpEfsPotato* | .{0,1000}\\SharpEfsPotato.{0,1000} | offensive_tool_keyword | SharpEfsPotato | Local privilege escalation from SeImpersonatePrivilege using EfsRpc. | T1548.002 - T1134.002 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/bugch3ck/SharpEfsPotato | 1 | 0 | N/A | N/A | 10 | 4 | 317 | 46 | 2022-10-17T12:35:06Z | 2022-10-17T12:20:47Z | 18526 |
| 727 | *\SharpElevator.cs* | .{0,1000}\\SharpElevator\.cs.{0,1000} | offensive_tool_keyword | SharpElevator | SharpElevator is a C# implementation of Elevator for UAC bypass | T1548.002 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/SharpElevator | 1 | 0 | N/A | N/A | 10 | 1 | 51 | 12 | 2022-08-31T18:09:10Z | 2022-08-29T19:52:53Z | 18529 |
| 728 | *\SharpElevator.exe* | .{0,1000}\\SharpElevator\.exe.{0,1000} | offensive_tool_keyword | SharpElevator | SharpElevator is a C# implementation of Elevator for UAC bypass | T1548.002 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/SharpElevator | 1 | 0 | N/A | N/A | 10 | 1 | 51 | 12 | 2022-08-31T18:09:10Z | 2022-08-29T19:52:53Z | 18530 |
| 729 | *\SharpElevator.sln* | .{0,1000}\\SharpElevator\.sln.{0,1000} | offensive_tool_keyword | SharpElevator | SharpElevator is a C# implementation of Elevator for UAC bypass | T1548.002 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/SharpElevator | 1 | 0 | N/A | N/A | 10 | 1 | 51 | 12 | 2022-08-31T18:09:10Z | 2022-08-29T19:52:53Z | 18531 |
| 730 | *\SharpUp.csproj* | .{0,1000}\\SharpUp\.csproj.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 18732 |
| 731 | *\SharpUp.sln* | .{0,1000}SharpUp.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 18739 |
| 732 | *\SharpUp\* | .{0,1000}\\SharpUp\\.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 18740 |
| 733 | *\SharpUp-master* | .{0,1000}\\SharpUp\-master.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 18741 |
| 734 | *\ShimInjector.cpp* | .{0,1000}\\ShimInjector\.cpp.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 18802 |
| 735 | *\ShimInjector.cpp* | .{0,1000}\\ShimInjector\.cpp.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 18803 |
| 736 | *\ShimInjector.exe* | .{0,1000}\\ShimInjector\.exe.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 18804 |
| 737 | *\SigmaPotato.csproj* | .{0,1000}\\SigmaPotato\.csproj.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 0 | N/A | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 18818 |
| 738 | *\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\TelemetryController\fun* | .{0,1000}\\SOFTWARE\\Microsoft\\Windows\sNT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\fun.{0,1000} | offensive_tool_keyword | Telemetry | Abusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges. | T1053 - T1547 - T1059 | TA0003 - TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Imanfeng/Telemetry | 1 | 0 | #registry | N/A | 9 | 2 | 140 | 13 | 2020-07-02T09:41:27Z | 2020-06-24T16:30:44Z | 18963 |
| 739 | *\SOFTWARE\Policies\Sinclair Community College\Make Me Admin* | .{0,1000}\\SOFTWARE\\Policies\\Sinclair\sCommunity\sCollege\\Make\sMe\sAdmin.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | #registry | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 18970 |
| 740 | *\SOFTWARE\Sinclair Community College\Make Me Admin* | .{0,1000}\\SOFTWARE\\Sinclair\sCommunity\sCollege\\Make\sMe\sAdmin.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | #registry | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 18971 |
| 741 | *\SpoolFool.exe* | .{0,1000}\\SpoolFool\.exe.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 19053 | |
| 742 | *\SpoolFool.ps1* | .{0,1000}\\SpoolFool\.ps1.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 19054 | |
| 743 | *\SpoolFool.sln* | .{0,1000}\\SpoolFool\.sln.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 19055 | |
| 744 | *\SpoolFool-main* | .{0,1000}\\SpoolFool\-main.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 19056 | |
| 745 | *\src\check\Credentials.ps1* | .{0,1000}\\src\\check\\Credentials\.ps1.{0,1000} | offensive_tool_keyword | PrivescCheck | Privilege Escalation Enumeration Script for Windows | T1053 - T1088 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrivescCheck | 1 | 0 | N/A | N/A | 10 | 10 | 3230 | 460 | 2025-03-05T14:44:17Z | 2020-01-16T12:28:10Z | 19079 |
| 746 | *\Sweetpotato.exe* | .{0,1000}\\Sweetpotato\.exe.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 19189 |
| 747 | *\SweetPotato\Program.cs* | .{0,1000}\\SweetPotato\\Program\.cs.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 19190 |
| 748 | *\SweetPotato-master.zip* | .{0,1000}\\SweetPotato\-master\.zip.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | N/A | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 19191 |
| 749 | *\SwitchPriv.exe* | .{0,1000}\\SwitchPriv\.exe.{0,1000} | offensive_tool_keyword | PrivFu | enable or disable specific token privileges for a process | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | SwitchPriv | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19192 |
| 750 | *\SwitchPriv.sln* | .{0,1000}\\SwitchPriv\.sln.{0,1000} | offensive_tool_keyword | PrivFu | enable or disable specific token privileges for a process | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | SwitchPriv | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19193 |
| 751 | *\temp\Injected.dll* | .{0,1000}\\temp\\Injected\.dll.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | N/A | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 19290 |
| 752 | *\TokenAssignor.exe* | .{0,1000}\\TokenAssignor\.exe.{0,1000} | offensive_tool_keyword | PrivFu | Tool to execute token assigned process | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | TokenAssignor | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19368 |
| 753 | *\TokenDump.exe* | .{0,1000}\\TokenDump\.exe.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19371 |
| 754 | *\Token-Impersonation.ps1* | .{0,1000}\\Token\-Impersonation\.ps1.{0,1000} | offensive_tool_keyword | Token-Impersonation | Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required) | T1134.001 - T1134.002 | TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/Leo4j/Token-Impersonation | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2024-03-20T17:07:13Z | 2023-11-02T10:46:24Z | 19376 |
| 755 | *\TokenPlayer.cpp* | .{0,1000}\\TokenPlayer\.cpp.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 19377 |
| 756 | *\TokenPlayer.exe* | .{0,1000}\\TokenPlayer\.exe.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 19378 |
| 757 | *\TokenPlayer\TokenPlayer\* | .{0,1000}\\TokenPlayer\\TokenPlayer\\.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 19379 |
| 758 | *\tokenprivileges.c* | .{0,1000}\\tokenprivileges\.c.{0,1000} | offensive_tool_keyword | PrivKit | PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS. | T1548.002 - T1059.003 - T1027.002 | TA0005 | N/A | N/A | Privilege Escalation | https://github.com/mertdas/PrivKit | 1 | 0 | N/A | N/A | 9 | 5 | 405 | 47 | 2024-06-15T16:54:32Z | 2023-03-20T04:19:40Z | 19380 |
| 759 | *\tokenprivileges.o* | .{0,1000}\\tokenprivileges\.o.{0,1000} | offensive_tool_keyword | PrivKit | PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS. | T1548.002 - T1059.003 - T1027.002 | TA0005 | N/A | N/A | Privilege Escalation | https://github.com/mertdas/PrivKit | 1 | 0 | N/A | N/A | 9 | 5 | 405 | 47 | 2024-06-15T16:54:32Z | 2023-03-20T04:19:40Z | 19381 |
| 760 | *\TokenStealing.exe* | .{0,1000}\\TokenStealing\.exe.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19382 |
| 761 | *\Tokenvator\* | .{0,1000}\\Tokenvator\\.{0,1000} | offensive_tool_keyword | Tokenvator | A tool to elevate privilege with Windows Tokens | T1134 - T1078 | TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/0xbadjuju/Tokenvator | 1 | 0 | N/A | N/A | N/A | 10 | 1038 | 201 | 2023-10-06T13:17:05Z | 2017-12-08T01:29:11Z | 19387 |
| 762 | *\TrustExec.exe* | .{0,1000}\\TrustExec\.exe.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19430 |
| 763 | *\TrustExec.exe* | .{0,1000}\\TrustExec\.exe.{0,1000} | offensive_tool_keyword | PrivFu | execute process as NT SERVICE\TrustedInstaller group account | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | TrustExec | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19431 |
| 764 | *\tStifle.exe* | .{0,1000}\\tStifle\.exe.{0,1000} | offensive_tool_keyword | Stifle | .NET Post-Exploitation Utility for Abusing Explicit Certificate Mappings in ADCS | T1550.003 - T1552.004 - T1606.002 | TA0006 - TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/logangoins/Stifle | 1 | 0 | #content | N/A | 7 | 2 | 140 | 9 | 2025-02-10T04:58:46Z | 2025-02-08T06:13:43Z | 19436 |
| 765 | *\UACBypassedService* | .{0,1000}\\UACBypassedService.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 19488 |
| 766 | *\UAC-TokenMagic.ps1* | .{0,1000}\\UAC\-TokenMagic\.ps1.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 19493 |
| 767 | *\UnquotedServicePath.cs* | .{0,1000}\\UnquotedServicePath\.cs.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 19523 |
| 768 | *\unquotedsvcpath.o* | .{0,1000}\\unquotedsvcpath\.o.{0,1000} | offensive_tool_keyword | PrivKit | PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS. | T1548.002 - T1059.003 - T1027.002 | TA0005 | N/A | N/A | Privilege Escalation | https://github.com/mertdas/PrivKit | 1 | 0 | N/A | N/A | 9 | 5 | 405 | 47 | 2024-06-15T16:54:32Z | 2023-03-20T04:19:40Z | 19524 |
| 769 | *\UserRightsUtil.exe* | .{0,1000}\\UserRightsUtil\.exe.{0,1000} | offensive_tool_keyword | PrivFu | manage user right without secpol.msc | T1059 - T1078 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | UserRightsUtil | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19539 |
| 770 | *\Users\Public\nc.exe* | .{0,1000}\\Users\\Public\\nc\.exe.{0,1000} | offensive_tool_keyword | Windows-Privilege-Escalation | Windows Privilege Escalation Techniques and Scripts | T1055 - T1548 - T1078 | TA0004 - TA0005 - TA0040 | N/A | N/A | Privilege Escalation | https://github.com/frizb/Windows-Privilege-Escalation | 1 | 0 | N/A | N/A | N/A | 9 | 861 | 190 | 2020-03-25T22:35:02Z | 2017-05-12T13:09:50Z | 19563 |
| 771 | *\VDR-main.zip | .{0,1000}\\VDR\-main\.zip | offensive_tool_keyword | VDR | Vulnerable driver research tool - result and exploit PoCs | T1547.009 - T1210 - T1068 - T1055 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/TakahiroHaruyama/VDR | 1 | 0 | N/A | N/A | 10 | 2 | 192 | 29 | 2023-11-01T00:06:55Z | 2023-10-23T08:34:44Z | 19599 |
| 772 | *\WfpTokenDup.exe* | .{0,1000}\\WfpTokenDup\.exe.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19695 |
| 773 | *\windows\temp\nc64.exe* | .{0,1000}\\windows\\temp\\nc64\.exe.{0,1000} | offensive_tool_keyword | RogueWinRM | RogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not running | T1548.003 - T1134.002 - T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RogueWinRM | 1 | 0 | N/A | N/A | 10 | 8 | 788 | 107 | 2020-02-23T19:26:41Z | 2019-12-02T22:58:03Z | 19748 |
| 774 | *\winPEAS.exe* | .{0,1000}\\winPEAS\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 19782 |
| 775 | *\winPEAS.ps1* | .{0,1000}\\winPEAS\.ps1.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 19786 |
| 776 | *\winPEAS.sln* | .{0,1000}\\winPEAS\.sln.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 19787 |
| 777 | *\winPEASany.exe* | .{0,1000}\\winPEASany\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 19788 |
| 778 | *\winPEASany_ofs.exe* | .{0,1000}\\winPEASany_ofs\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 19790 |
| 779 | *\winPEASany_ofs.exe* | .{0,1000}\\winPEASany_ofs\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 19791 |
| 780 | *\winPEASexe\* | .{0,1000}\\winPEASexe\\.{0,1000} | offensive_tool_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 19792 |
| 781 | *\winPEAS-Obfuscated.exe* | .{0,1000}\\winPEAS\-Obfuscated\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 19793 |
| 782 | *\winPEASx64.exe* | .{0,1000}\\winPEASx64\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 19794 |
| 783 | *\winPEASx86.exe* | .{0,1000}\\winPEASx86\.exe.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | N/A | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 19795 |
| 784 | *\ZeroHVCI.cpp* | .{0,1000}\\ZeroHVCI\.cpp.{0,1000} | offensive_tool_keyword | ZeroHVCI | Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229 | T1068 - T1564 - T1014 - T1499 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/zer0condition/ZeroHVCI | 1 | 0 | N/A | N/A | 7 | 2 | 198 | 43 | 2024-10-26T17:08:38Z | 2024-07-20T07:29:18Z | 19950 |
| 785 | *\ZeroHVCI.exe* | .{0,1000}\\ZeroHVCI\.exe.{0,1000} | offensive_tool_keyword | ZeroHVCI | Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229 | T1068 - T1564 - T1014 - T1499 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/zer0condition/ZeroHVCI | 1 | 0 | N/A | N/A | 7 | 2 | 198 | 43 | 2024-10-26T17:08:38Z | 2024-07-20T07:29:18Z | 19951 |
| 786 | *\ZeroHVCI.sln* | .{0,1000}\\ZeroHVCI\.sln.{0,1000} | offensive_tool_keyword | ZeroHVCI | Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229 | T1068 - T1564 - T1014 - T1499 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/zer0condition/ZeroHVCI | 1 | 0 | N/A | N/A | 7 | 2 | 198 | 43 | 2024-10-26T17:08:38Z | 2024-07-20T07:29:18Z | 19952 |
| 787 | *\ZeroHVCI-master* | .{0,1000}\\ZeroHVCI\-master.{0,1000} | offensive_tool_keyword | ZeroHVCI | Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229 | T1068 - T1564 - T1014 - T1499 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/zer0condition/ZeroHVCI | 1 | 0 | N/A | N/A | 7 | 2 | 198 | 43 | 2024-10-26T17:08:38Z | 2024-07-20T07:29:18Z | 19953 |
| 788 | *] - caution! this means that exploit is not fileless* | .{0,1000}\]\s\-\scaution!\sthis\smeans\sthat\sexploit\sis\snot\sfileless.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #content #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 19976 |
| 789 | *] Bruteforcing %d CLSIDs* | .{0,1000}\]\sBruteforcing\s\%d\sCLSIDs.{0,1000} | offensive_tool_keyword | JuicyPotatoNG | Another Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | FoxKitten - APT33 - Volatile Cedar - Sandworm | Privilege Escalation | https://github.com/antonioCoco/JuicyPotatoNG | 1 | 0 | N/A | N/A | 10 | 9 | 844 | 101 | 2022-11-12T01:48:39Z | 2022-09-21T17:08:35Z | 19983 |
| 790 | *] Cloning GPO * from fakedc | .{0,1000}\]\sCloning\sGPO\s.{0,1000}\sfrom\sfakedc\s | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 20006 |
| 791 | *] Completed Privesc Checks in * | .{0,1000}\]\sCompleted\sPrivesc\sChecks\sin\s.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 20009 |
| 792 | *] dumping runtime core memory of the root smart contract* | .{0,1000}\]\sdumping\sruntime\score\smemory\sof\sthe\sroot\ssmart\scontract.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #content #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 20019 |
| 793 | *] executing xss local file write to hijack systemd user* | .{0,1000}\]\sexecuting\sxss\slocal\sfile\swrite\sto\shijack\ssystemd\suser.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #content #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 20025 |
| 794 | *] going to escalate the quantum privilege of wifi driver* | .{0,1000}\]\sgoing\sto\sescalate\sthe\squantum\sprivilege\sof\swifi\sdriver.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #content #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 20030 |
| 795 | *] going to inject sql payload into the external mainframe smart contract interface* | .{0,1000}\]\sgoing\sto\sinject\ssql\spayload\sinto\sthe\sexternal\smainframe\ssmart\scontract\sinterface.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #content #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 20031 |
| 796 | *] Granting read and execute to SYSTEM on DLL: * | .{0,1000}\]\sGranting\sread\sand\sexecute\sto\sSYSTEM\son\sDLL\:\s.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | N/A | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 20032 | |
| 797 | *] Injecting malicious scheduled task into downloaded GPO* | .{0,1000}\]\sInjecting\smalicious\sscheduled\stask\sinto\sdownloaded\sGPO.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 20043 |
| 798 | *] Modifying * attribute of GPO on fakedc to * | .{0,1000}\]\sModifying\s.{0,1000}\sattribute\sof\sGPO\son\sfakedc\sto\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 20053 |
| 799 | *] Modifying gPCFileSysPath attribute of GPO on fakedc to * | .{0,1000}\]\sModifying\sgPCFileSysPath\sattribute\sof\sGPO\son\sfakedc\sto\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 20054 |
| 800 | *] QueueUserAPC Inject shellcode completed, enjoy!* | .{0,1000}\]\sQueueUserAPC\sInject\sshellcode\scompleted,\senjoy!.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | #content | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 20060 |
| 801 | *] Received DCOM NTLM type 3 authentication from the privileged client* | .{0,1000}\]\sReceived\sDCOM\sNTLM\stype\s3\sauthentication\sfrom\sthe\sprivileged\sclient.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | N/A | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 20061 |
| 802 | *] Retrieving the S4U2Self referral from * | .{0,1000}\]\sRetrieving\sthe\sS4U2Self\sreferral\sfrom\s.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 20064 |
| 803 | *] Roasted hashes written to : * | .{0,1000}\]\sRoasted\shashes\swritten\sto\s\:\s.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 20065 |
| 804 | *] sending network-based smb hypertrojan with credentials* | .{0,1000}\]\ssending\snetwork\-based\ssmb\shypertrojan\swith\scredentials.{0,1000} | offensive_tool_keyword | POC | local privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6 | T1068 - T1548.002 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Notselwyn/CVE-2024-1086 | 1 | 0 | #content #linux | CVE-2024-1086 POC | 10 | 10 | 2357 | 314 | 2024-04-17T16:09:54Z | 2024-03-20T21:16:41Z | 20069 |
| 805 | *] Sending S4U2proxy request * | .{0,1000}\]\sSending\sS4U2proxy\srequest\s.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 20070 |
| 806 | *] Spoofing gPLink to * | .{0,1000}\]\sSpoofing\sgPLink\sto\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 20072 |
| 807 | *] Starting RogueOxidResolver RPC Server listening on port* | .{0,1000}\]\sStarting\sRogueOxidResolver\sRPC\sServer\slistening\son\sport.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 20078 |
| 808 | *] Starting the NTLM relay attack, launch ntlmrelayx on * | .{0,1000}\]\sStarting\sthe\sNTLM\srelay\sattack,\slaunch\sntlmrelayx\son\s.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 20080 |
| 809 | *] Starting the RPC server to capture the credentials hash from the user authentication!!* | .{0,1000}\]\sStarting\sthe\sRPC\sserver\sto\scapture\sthe\scredentials\shash\sfrom\sthe\suser\sauthentication!!.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #content | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 20081 |
| 810 | *]Spawning Process with Spoofed Parent* | .{0,1000}\]Spawning\sProcess\swith\sSpoofed\sParent.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | N/A | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 20099 |
| 811 | *<BadPotato.exe>* | .{0,1000}\<BadPotato\.exe\>.{0,1000} | offensive_tool_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | #originalfilename | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 20205 |
| 812 | *<title>PrivescCheck Report</title>* | .{0,1000}\<title\>PrivescCheck\sReport\<\/title\>.{0,1000} | offensive_tool_keyword | PrivescCheck | Privilege Escalation Enumeration Script for Windows | T1053 - T1088 | TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/PrivescCheck | 1 | 0 | N/A | N/A | 10 | 10 | 3230 | 460 | 2025-03-05T14:44:17Z | 2020-01-16T12:28:10Z | 20260 |
| 813 | *=== LAUNCHING SMB SERVER AND WAITING FOR GPT REQUESTS ===* | .{0,1000}\=\=\=\sLAUNCHING\sSMB\sSERVER\sAND\sWAITING\sFOR\sGPT\sREQUESTS\s\=\=\=.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 20274 |
| 814 | *=== SharpUp: Running Privilege Escalation Checks ===* | .{0,1000}\=\=\=\sSharpUp\:\sRunning\sPrivilege\sEscalation\sChecks\s\=\=\=.{0,1000} | offensive_tool_keyword | SharpUp | SharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented. | T1003 - T1082 - T1057 - T1069 - T1083 | TA0004 - TA0007 | N/A | N/A | Privilege Escalation | https://github.com/GhostPack/SharpUp | 1 | 0 | N/A | N/A | N/A | 10 | 1344 | 253 | 2024-02-14T16:38:26Z | 2018-07-24T17:39:33Z | 20276 |
| 815 | *=== SPOOFING THE GPLINK ATTRIBUTE OF THE TARGET OU ===* | .{0,1000}\=\=\=\sSPOOFING\sTHE\sGPLINK\sATTRIBUTE\sOF\sTHE\sTARGET\sOU\s\=\=\=.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 20277 |
| 816 | *=== WAITING (GPT REQUESTS WILL BE FORWARDED TO SMB SERVER) ===* | .{0,1000}\=\=\=\sWAITING\s\(GPT\sREQUESTS\sWILL\sBE\sFORWARDED\sTO\sSMB\sSERVER\)\s\=\=\=.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 20278 |
| 817 | *=== WAITING (SMB NTLM AUTHENTICATION COERCED TO * | .{0,1000}\=\=\=\sWAITING\s\(SMB\sNTLM\sAUTHENTICATION\sCOERCED\sTO\s.{0,1000} | offensive_tool_keyword | Ouned | The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | T1484 - T1210 | TA0001 - TA0004 - TA0005 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/synacktiv/Ouned | 1 | 0 | N/A | N/A | 10 | 2 | 112 | 14 | 2025-03-29T14:20:38Z | 2024-04-17T10:18:04Z | 20279 |
| 818 | *>ADCSPwn<* | .{0,1000}\>ADCSPwn\<.{0,1000} | offensive_tool_keyword | ADCSPwn | A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service | T1550.002 - T1078.003 - T1110.003 - T1649 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/bats3c/ADCSPwn | 1 | 0 | N/A | N/A | 10 | 9 | 838 | 127 | 2023-03-20T20:30:40Z | 2021-07-30T15:04:41Z | 20316 |
| 819 | *>BadPotato<* | .{0,1000}\>BadPotato\<.{0,1000} | offensive_tool_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | #productname | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 20340 |
| 820 | *>CreateAssignTokenVariant<* | .{0,1000}\>CreateAssignTokenVariant\<.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20359 |
| 821 | *>CreateImpersonateTokenVariant<* | .{0,1000}\>CreateImpersonateTokenVariant\<.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20360 |
| 822 | *>DeadPotato<* | .{0,1000}\>DeadPotato\<.{0,1000} | offensive_tool_keyword | DeadPotato | DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | N/A | N/A | Privilege Escalation | https://github.com/lypd0/DeadPotato | 1 | 0 | N/A | N/A | 10 | 4 | 382 | 45 | 2024-08-17T06:08:29Z | 2024-07-31T01:08:30Z | 20368 |
| 823 | *>DebugInjectionVariant<* | .{0,1000}\>DebugInjectionVariant\<.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20369 |
| 824 | *>DebugUpdateProcVariant<* | .{0,1000}\>DebugUpdateProcVariant\<.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20370 |
| 825 | *>DirtyCLR<* | .{0,1000}\>DirtyCLR\<.{0,1000} | offensive_tool_keyword | DirtyCLR | An App Domain Manager Injection DLL PoC | T1055.001 - T1546.016 - T1055.013 | TA0005 - TA0004 | N/A | Black Basta | Privilege Escalation | https://github.com/ipSlav/DirtyCLR | 1 | 0 | N/A | N/A | 7 | 2 | 170 | 19 | 2023-12-14T21:22:12Z | 2023-12-11T11:29:36Z | 20377 |
| 826 | *>EfsPotato<* | .{0,1000}\>EfsPotato\<.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20384 |
| 827 | *>Enables users to elevate themselves to administrator-level rights.<* | .{0,1000}\>Enables\susers\sto\selevate\sthemselves\sto\sadministrator\-level\srights\.\<.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 20387 |
| 828 | *>Make Me Admin<* | .{0,1000}\>Make\sMe\sAdmin\<.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 20436 |
| 829 | *>MakeMeAdmin<* | .{0,1000}\>MakeMeAdmin\<.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | N/A | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 20437 |
| 830 | *>NamedPipeImpersonation<* | .{0,1000}\>NamedPipeImpersonation\<.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20454 |
| 831 | *>PrintSpoofer<* | .{0,1000}\>PrintSpoofer\<.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20483 |
| 832 | *>RestoreServiceModificationVariant<* | .{0,1000}\>RestoreServiceModificationVariant\<.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20504 |
| 833 | *>S4uDelegator<* | .{0,1000}\>S4uDelegator\<.{0,1000} | offensive_tool_keyword | PrivFu | perform S4U logon with SeTcbPrivilege | T1134 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | S4uDelegator | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20511 |
| 834 | *>S4ULogonShell<* | .{0,1000}\>S4ULogonShell\<.{0,1000} | offensive_tool_keyword | PrivFu | SeTcbPrivilege exploitation | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | PrivFu\PowerOfTcb | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20512 |
| 835 | *>SeAuditPrivilegePoC<* | .{0,1000}\>SeAuditPrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20517 |
| 836 | *>SeBackupPrivilegePoC<* | .{0,1000}\>SeBackupPrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20518 |
| 837 | *>SecondaryLogonVariant<* | .{0,1000}\>SecondaryLogonVariant\<.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20519 |
| 838 | *>SeCreatePagefilePrivilegePoC<* | .{0,1000}\>SeCreatePagefilePrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20520 |
| 839 | *>SeCreateTokenPrivilegePoC<* | .{0,1000}\>SeCreateTokenPrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20521 |
| 840 | *>SeDebugPrivilegePoC<* | .{0,1000}\>SeDebugPrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20522 |
| 841 | *>SeRestorePrivilegePoC<* | .{0,1000}\>SeRestorePrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20523 |
| 842 | *>SeSecurityPrivilegePoC<* | .{0,1000}\>SeSecurityPrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20524 |
| 843 | *>SeShutdownPrivilegePoC<* | .{0,1000}\>SeShutdownPrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20525 |
| 844 | *>SeSystemEnvironmentPrivilegePoC<* | .{0,1000}\>SeSystemEnvironmentPrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20526 |
| 845 | *>SeTakeOwnershipPrivilegePoC<* | .{0,1000}\>SeTakeOwnershipPrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20529 |
| 846 | *>SeTcbPrivilegePoC<* | .{0,1000}\>SeTcbPrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20530 |
| 847 | *>SeTrustedCredManAccessPrivilegePoC<* | .{0,1000}\>SeTrustedCredManAccessPrivilegePoC\<.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20531 |
| 848 | *>TakeOwnershipServiceModificationVariant<* | .{0,1000}\>TakeOwnershipServiceModificationVariant\<.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20597 |
| 849 | *>TcbS4uImpersonationVariant<* | .{0,1000}\>TcbS4uImpersonationVariant\<.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20598 |
| 850 | *>TokenStealing<* | .{0,1000}\>TokenStealing\<.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20604 |
| 851 | *>UACBypassedService<* | .{0,1000}\>UACBypassedService\<.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 20607 |
| 852 | *>UserRightsUtil<* | .{0,1000}\>UserRightsUtil\<.{0,1000} | offensive_tool_keyword | PrivFu | manage user right without secpol.msc | T1059 - T1078 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | UserRightsUtil | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20611 |
| 853 | *>WfpTokenDup<* | .{0,1000}\>WfpTokenDup\<.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | N/A | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20619 |
| 854 | *008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050* | .{0,1000}008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20670 |
| 855 | *008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050* | .{0,1000}008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20671 |
| 856 | *008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050* | .{0,1000}008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20672 |
| 857 | *00a2407eb70a40f0054d83e92cc9e8e85b010bfcc75ab5bab1ced62f81622d92* | .{0,1000}00a2407eb70a40f0054d83e92cc9e8e85b010bfcc75ab5bab1ced62f81622d92.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20679 |
| 858 | *00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a* | .{0,1000}00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20688 |
| 859 | *00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a* | .{0,1000}00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20689 |
| 860 | *00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a* | .{0,1000}00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20690 |
| 861 | *00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a* | .{0,1000}00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20691 |
| 862 | *01ccc2ba607a0aa44e7bd6690dc5d93001ad70b03ad817142f7f9abb4c911abb* | .{0,1000}01ccc2ba607a0aa44e7bd6690dc5d93001ad70b03ad817142f7f9abb4c911abb.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20759 |
| 863 | *01cf2c956d813b4dddcde5f3349ada814764aa45d9579e8dde063c891f62d1d4* | .{0,1000}01cf2c956d813b4dddcde5f3349ada814764aa45d9579e8dde063c891f62d1d4.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux #filehash | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 20760 |
| 864 | *0212bde3715a349a6b684dd54548638b5899be8d62a1e25559937e494e3cce54* | .{0,1000}0212bde3715a349a6b684dd54548638b5899be8d62a1e25559937e494e3cce54.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | #filehash | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 20778 |
| 865 | *026389a44b0e1797d97afd0c333f778fe8c066e9edf4c0b847872263a27451f0* | .{0,1000}026389a44b0e1797d97afd0c333f778fe8c066e9edf4c0b847872263a27451f0.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20803 |
| 866 | *0266d99789720ec1a83a397127c478885b3f3ff02026a3fb06d3a10e523a9cc0* | .{0,1000}0266d99789720ec1a83a397127c478885b3f3ff02026a3fb06d3a10e523a9cc0.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20804 |
| 867 | *0269fd0001afa23edd1206484dccce04b49e0ec0daa65234126a6f3c42f35a46* | .{0,1000}0269fd0001afa23edd1206484dccce04b49e0ec0daa65234126a6f3c42f35a46.{0,1000} | offensive_tool_keyword | ZeroHVCI | Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229 | T1068 - T1564 - T1014 - T1499 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/zer0condition/ZeroHVCI | 1 | 0 | #filehash | N/A | 7 | 2 | 198 | 43 | 2024-10-26T17:08:38Z | 2024-07-20T07:29:18Z | 20805 |
| 868 | *0286bd5f-1a56-4251-8758-adb0338d4e98* | .{0,1000}0286bd5f\-1a56\-4251\-8758\-adb0338d4e98.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | #GUIDproject | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 20824 |
| 869 | *02ac483d126c4b08d880cfab52f1904323006b4778f43f536bb83bb38c2a9f2e* | .{0,1000}02ac483d126c4b08d880cfab52f1904323006b4778f43f536bb83bb38c2a9f2e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20832 |
| 870 | *02cbcc3c3b79a7f81165838af0605d7238e8c5ad7a6e2d59d7795c1f137fe7a4* | .{0,1000}02cbcc3c3b79a7f81165838af0605d7238e8c5ad7a6e2d59d7795c1f137fe7a4.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | #filehash | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 20840 |
| 871 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20849 |
| 872 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20850 |
| 873 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20851 |
| 874 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20852 |
| 875 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20853 |
| 876 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20854 |
| 877 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20855 |
| 878 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20856 |
| 879 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20857 |
| 880 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20858 |
| 881 | *02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e* | .{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20859 |
| 882 | *036b5e87804f5996d8009b8d06f95a307227c6835a51ce64427cae7189cf86d2* | .{0,1000}036b5e87804f5996d8009b8d06f95a307227c6835a51ce64427cae7189cf86d2.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | #filehash | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 20894 |
| 883 | *03b99b08166cc1f4ef733078b9756cd12d39824acd022a2aca1da5f888094538* | .{0,1000}03b99b08166cc1f4ef733078b9756cd12d39824acd022a2aca1da5f888094538.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20921 |
| 884 | *03c1585bf3e2e6013e2f8cd34d34eedc9c4195dc72628a779db43cdd16b1a7cc* | .{0,1000}03c1585bf3e2e6013e2f8cd34d34eedc9c4195dc72628a779db43cdd16b1a7cc.{0,1000} | offensive_tool_keyword | PrivFu | perform S4U logon with SeTcbPrivilege | T1134 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #filehash | S4uDelegator | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 20924 |
| 885 | *03e1412cfc9954592a8c8b93d151ce20083d7a1797b3eb8b15e6098179627b73* | .{0,1000}03e1412cfc9954592a8c8b93d151ce20083d7a1797b3eb8b15e6098179627b73.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20934 |
| 886 | *03fdcd35cfb237327c0813ce931a62ffcf837302f8e0285ff1c8085ee30f2828* | .{0,1000}03fdcd35cfb237327c0813ce931a62ffcf837302f8e0285ff1c8085ee30f2828.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux #filehash | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 20942 |
| 887 | *046f841782518838690b1ad7916ea33c68cd32cfdd9c87aabc7d85425b0f20ed* | .{0,1000}046f841782518838690b1ad7916ea33c68cd32cfdd9c87aabc7d85425b0f20ed.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 20988 |
| 888 | *04a57cd7fa95b8851ef4d45aa6b30b9c89dbbbe7b8a1780a15c34b9a81f9ef91* | .{0,1000}04a57cd7fa95b8851ef4d45aa6b30b9c89dbbbe7b8a1780a15c34b9a81f9ef91.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | #filehash | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 21001 |
| 889 | *04FC654C-D89A-44F9-9E34-6D95CE152E9D* | .{0,1000}04FC654C\-D89A\-44F9\-9E34\-6D95CE152E9D.{0,1000} | offensive_tool_keyword | PrivFu | Kernel mode WinDbg extension and PoCs for token privilege investigation. | T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001 | TA0007 - TA0008 - TA0002 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #GUIDproject | N/A | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 21020 |
| 890 | *050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23* | .{0,1000}050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21026 |
| 891 | *050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23* | .{0,1000}050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21027 |
| 892 | *050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23* | .{0,1000}050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21028 |
| 893 | *050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23* | .{0,1000}050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21029 |
| 894 | *050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23* | .{0,1000}050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21030 |
| 895 | *050dcd051a109b6bd8804e769242ec4e1c087bdd2fb45880c2affeebb630cf77* | .{0,1000}050dcd051a109b6bd8804e769242ec4e1c087bdd2fb45880c2affeebb630cf77.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | #filehash | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 21031 |
| 896 | *0527a14f-1591-4d94-943e-d6d784a50549* | .{0,1000}0527a14f\-1591\-4d94\-943e\-d6d784a50549.{0,1000} | offensive_tool_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | #GUIDproject | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 21039 |
| 897 | *053c976a6b035d2c3daefe986d293fcb1d92ffd0f535a649ee61218c66721555* | .{0,1000}053c976a6b035d2c3daefe986d293fcb1d92ffd0f535a649ee61218c66721555.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | #filehash | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 21042 |
| 898 | *057432add809186a039ba449a5988101aad9f9e55119b90e34b49e9f14835b3a* | .{0,1000}057432add809186a039ba449a5988101aad9f9e55119b90e34b49e9f14835b3a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21052 |
| 899 | *05c10f59c21e200d25112a44581eab14d4793bfdc4f4cad8a9e6b0d231f4f1aa* | .{0,1000}05c10f59c21e200d25112a44581eab14d4793bfdc4f4cad8a9e6b0d231f4f1aa.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux #filehash | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 21073 |
| 900 | *063bc732edb5ca68d2122d0311ddb46dd38ff05074945566d1fa067c3579d767* | .{0,1000}063bc732edb5ca68d2122d0311ddb46dd38ff05074945566d1fa067c3579d767.{0,1000} | offensive_tool_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | #filehash | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 21099 |
| 901 | *06f14218e0f7b881a61c998824e6709b313b5c8baaa87a8d15986b0c5cf2b7cb* | .{0,1000}06f14218e0f7b881a61c998824e6709b313b5c8baaa87a8d15986b0c5cf2b7cb.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21150 |
| 902 | *0705092d4c2a8e0475d1f686166b9b1ecb999c0133a0eaf8a7b8fd902dc64930* | .{0,1000}0705092d4c2a8e0475d1f686166b9b1ecb999c0133a0eaf8a7b8fd902dc64930.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21156 |
| 903 | *07400fb1198a8326fead8180f927e62e218885a4940b9879082d2adf49064ea5* | .{0,1000}07400fb1198a8326fead8180f927e62e218885a4940b9879082d2adf49064ea5.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21173 |
| 904 | *07628592-5A22-4C0A-9330-6C90BD7A94B6* | .{0,1000}07628592\-5A22\-4C0A\-9330\-6C90BD7A94B6.{0,1000} | offensive_tool_keyword | LocalAdminSharp | .NET executable to use when dealing with privilege escalation on Windows to gain local administrator access | T1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/notdodo/LocalAdminSharp | 1 | 0 | #GUIDproject | N/A | 10 | 2 | 157 | 17 | 2022-11-01T17:45:43Z | 2022-01-01T10:35:09Z | 21183 |
| 905 | *0817eb1eeb9b25430a2666b8bd637d83e8c3c10ba14a8f6db0b0d3147ce3ab4a* | .{0,1000}0817eb1eeb9b25430a2666b8bd637d83e8c3c10ba14a8f6db0b0d3147ce3ab4a.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #filehash | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 21241 |
| 906 | *0971A047-A45A-43F4-B7D8-16AC1114B524* | .{0,1000}0971A047\-A45A\-43F4\-B7D8\-16AC1114B524.{0,1000} | offensive_tool_keyword | BackupOperatorToDA | From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller | T1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003 | TA0005 - TA0001 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/mpgn/BackupOperatorToDA | 1 | 0 | #GUIDproject | N/A | 10 | 5 | 421 | 53 | 2025-01-04T14:16:46Z | 2022-02-15T20:51:46Z | 21341 |
| 907 | *0999e7ec2eaa95fded99e6b8cb3ffd5ae372a896731cef3eb5bdb0b8977e64f4* | .{0,1000}0999e7ec2eaa95fded99e6b8cb3ffd5ae372a896731cef3eb5bdb0b8977e64f4.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21353 |
| 908 | *09d9169b42e10b354ce44c9bdb8f06c52506f14f39f6378e52b3c2eac1d27866* | .{0,1000}09d9169b42e10b354ce44c9bdb8f06c52506f14f39f6378e52b3c2eac1d27866.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21371 |
| 909 | *09e0c32321b7bc4b6d95f4a36d9030ce2333d67ffff15e4ff51631c3c4aa319d* | .{0,1000}09e0c32321b7bc4b6d95f4a36d9030ce2333d67ffff15e4ff51631c3c4aa319d.{0,1000} | offensive_tool_keyword | BITSInject | A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account | T1197 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/SafeBreach-Labs/BITSInject | 1 | 0 | #filehash | N/A | 8 | 1 | 99 | 18 | 2019-08-24T22:02:12Z | 2017-07-03T12:39:38Z | 21373 |
| 910 | *0a2dbf9faa4445dfca15c92c6048cfca1e98ad9981f3c8349e7ffa34e62f638d* | .{0,1000}0a2dbf9faa4445dfca15c92c6048cfca1e98ad9981f3c8349e7ffa34e62f638d.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21394 |
| 911 | *0a33c2da28a068610b62a369635506fbd4a15233867c9c1e3041948006177cb6* | .{0,1000}0a33c2da28a068610b62a369635506fbd4a15233867c9c1e3041948006177cb6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21395 |
| 912 | *0A78E156-D03F-4667-B70E-4E9B4AA1D491* | .{0,1000}0A78E156\-D03F\-4667\-B70E\-4E9B4AA1D491.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #GUIDproject | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 21409 |
| 913 | *0ADFD1F0-7C15-4A22-87B4-F67E046ECD96* | .{0,1000}0ADFD1F0\-7C15\-4A22\-87B4\-F67E046ECD96.{0,1000} | offensive_tool_keyword | TokenPlayer | Manipulating and Abusing Windows Access Tokens | T1134 - T1484 - T1055 - T1078 | TA0004 - TA0005 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/S1ckB0y1337/TokenPlayer | 1 | 0 | #GUIDproject | N/A | 10 | 3 | 274 | 45 | 2021-01-15T16:07:47Z | 2020-08-20T23:05:49Z | 21433 |
| 914 | *0ae164e1f157f452b32b06e43b828d792daa447b535b08330f942ade8b87d70b* | .{0,1000}0ae164e1f157f452b32b06e43b828d792daa447b535b08330f942ade8b87d70b.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21436 |
| 915 | *0b3502ac778c671bad537e6433a8f58ec4e1f9a7ab34d37a7bb1bf8c08b2dcf7* | .{0,1000}0b3502ac778c671bad537e6433a8f58ec4e1f9a7ab34d37a7bb1bf8c08b2dcf7.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21455 |
| 916 | *0b5f0373ab8388f655fe01309ff6a58e96e969d8a94a06b5a05dce11c998f2f0* | .{0,1000}0b5f0373ab8388f655fe01309ff6a58e96e969d8a94a06b5a05dce11c998f2f0.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21464 |
| 917 | *0b6a762812a1fbfda681951fbd60bcaa919b99e6e61df84a251f800bb4479a0e* | .{0,1000}0b6a762812a1fbfda681951fbd60bcaa919b99e6e61df84a251f800bb4479a0e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21466 |
| 918 | *0ba663873a7926866e3dd717b970f7e651700d00e9d99f667dfd473eafa81b8a* | .{0,1000}0ba663873a7926866e3dd717b970f7e651700d00e9d99f667dfd473eafa81b8a.{0,1000} | offensive_tool_keyword | KExecDD | Admin to Kernel code execution using the KSecDD driver | T1068 - T1055.011 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/floesen/KExecDD | 1 | 0 | #filehash | N/A | 8 | 3 | 244 | 41 | 2024-04-19T09:58:14Z | 2024-04-19T08:54:49Z | 21485 |
| 919 | *0bb4b892f67fdf903ed5e5df2c85c5ccb71669c298736cf24284412de435509a* | .{0,1000}0bb4b892f67fdf903ed5e5df2c85c5ccb71669c298736cf24284412de435509a.{0,1000} | offensive_tool_keyword | ADCSPwn | A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service | T1550.002 - T1078.003 - T1110.003 - T1649 | TA0004 - TA0006 | N/A | N/A | Privilege Escalation | https://github.com/bats3c/ADCSPwn | 1 | 0 | #filehash | N/A | 10 | 9 | 838 | 127 | 2023-03-20T20:30:40Z | 2021-07-30T15:04:41Z | 21489 |
| 920 | *0c021fa1272bc222489a6a54e46a10c85d57d758071b310afc66441f72d4a482* | .{0,1000}0c021fa1272bc222489a6a54e46a10c85d57d758071b310afc66441f72d4a482.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21513 |
| 921 | *0c2c7f0208bac76684a0e8f5960772b22014f417a81caba157b0b512e13404b2* | .{0,1000}0c2c7f0208bac76684a0e8f5960772b22014f417a81caba157b0b512e13404b2.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21527 |
| 922 | *0ca801fdfa8a5040b2e60608fe9ff7fc987ef7d361e389ddcc8d1568b8832230* | .{0,1000}0ca801fdfa8a5040b2e60608fe9ff7fc987ef7d361e389ddcc8d1568b8832230.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21565 |
| 923 | *0CC923FB-E1FD-456B-9FE4-9EBA5A3DC2FC* | .{0,1000}0CC923FB\-E1FD\-456B\-9FE4\-9EBA5A3DC2FC.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | #GUIDproject | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 21574 |
| 924 | *0CD16C7B-2A65-44E5-AB74-843BD23241D3* | .{0,1000}0CD16C7B\-2A65\-44E5\-AB74\-843BD23241D3.{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/outflanknl/PrintNightmare | 1 | 0 | #GUIDproject | N/A | 10 | 4 | 337 | 67 | 2021-09-13T08:45:26Z | 2021-09-13T08:44:02Z | 21577 |
| 925 | *0cf16d4d70941be216c787a44a7401c9c9547016952a2c699579d4e4bb9c8110* | .{0,1000}0cf16d4d70941be216c787a44a7401c9c9547016952a2c699579d4e4bb9c8110.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | #filehash | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 21585 |
| 926 | *0d8cac6cbe2019d99a5260f4c934d9a4c9c7022d141006cfc0f87fdc3f8ae4ab* | .{0,1000}0d8cac6cbe2019d99a5260f4c934d9a4c9c7022d141006cfc0f87fdc3f8ae4ab.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux #filehash | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 21633 |
| 927 | *0d8f5888bc6e02085496b4a070b39169bdea67051b1a9f7af21b29de9615842e* | .{0,1000}0d8f5888bc6e02085496b4a070b39169bdea67051b1a9f7af21b29de9615842e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21637 |
| 928 | *0defeb7a564d2f4f237d89ae63065e78af68b0febda5927f25722696593bf42e* | .{0,1000}0defeb7a564d2f4f237d89ae63065e78af68b0febda5927f25722696593bf42e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21669 |
| 929 | *0e9af89e0f2faa8d7f92d6e9538e19f82c701c798031d890978845e388b85ba6* | .{0,1000}0e9af89e0f2faa8d7f92d6e9538e19f82c701c798031d890978845e388b85ba6.{0,1000} | offensive_tool_keyword | ACEshark | uncover potential privilege escalation vectors by analyzing windows service configurations and Access Control Entries | T1058 - T1548 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/t3l3machus/ACEshark | 1 | 0 | #filehash | N/A | 6 | 2 | 109 | 19 | 2025-01-15T07:01:48Z | 2024-12-28T10:42:29Z | 21723 |
| 930 | *0eec76148fd7a3b1eb54d3fa71c30b5370d410e1eb81231ff0e9e66de3598aea* | .{0,1000}0eec76148fd7a3b1eb54d3fa71c30b5370d410e1eb81231ff0e9e66de3598aea.{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/outflanknl/PrintNightmare | 1 | 0 | #filehash | N/A | 10 | 4 | 337 | 67 | 2021-09-13T08:45:26Z | 2021-09-13T08:44:02Z | 21742 |
| 931 | *0f56c703e9b7ddeb90646927bac05a5c6d95308c8e13b88e5d4f4b572423e036* | .{0,1000}0f56c703e9b7ddeb90646927bac05a5c6d95308c8e13b88e5d4f4b572423e036.{0,1000} | offensive_tool_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 0 | #filehash | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 21767 |
| 932 | *0f7b6ddc0ef44701c4ab1284610d51d36b4e79d68fb0e184d122533d77cbfb63* | .{0,1000}0f7b6ddc0ef44701c4ab1284610d51d36b4e79d68fb0e184d122533d77cbfb63.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21782 |
| 933 | *0fb342f94f359c9f54205a979854b7a3a3910bb7e118f0fc44cead28ebd81f0d* | .{0,1000}0fb342f94f359c9f54205a979854b7a3a3910bb7e118f0fc44cead28ebd81f0d.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | #filehash | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 21800 |
| 934 | *0x4xel/Bat-Potato* | .{0,1000}0x4xel\/Bat\-Potato.{0,1000} | offensive_tool_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 1 | N/A | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 21833 |
| 935 | *0xbadjuju/Tokenvator* | .{0,1000}0xbadjuju\/Tokenvator.{0,1000} | offensive_tool_keyword | Tokenvator | A tool to elevate privilege with Windows Tokens | T1134 - T1078 | TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/0xbadjuju/Tokenvator | 1 | 1 | N/A | N/A | N/A | 10 | 1038 | 201 | 2023-10-06T13:17:05Z | 2017-12-08T01:29:11Z | 21841 |
| 936 | *0xEr3bus/PoolPartyBof* | .{0,1000}0xEr3bus\/PoolPartyBof.{0,1000} | offensive_tool_keyword | PoolPartyBof | A beacon object file implementation of PoolParty Process Injection Technique | T1055.011 - T1055 - T1620 | TA0005 | N/A | Black Basta | Privilege Escalation | https://github.com/0xEr3bus/PoolPartyBof | 1 | 1 | N/A | N/A | 10 | 4 | 380 | 44 | 2023-12-21T19:00:20Z | 2023-12-11T19:28:20Z | 21848 |
| 937 | *105C2C6D-1C0A-4535-A231-80E355EFB112* | .{0,1000}105C2C6D\-1C0A\-4535\-A231\-80E355EFB112.{0,1000} | offensive_tool_keyword | RoguePotato | Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RoguePotato | 1 | 0 | #GUIDproject | N/A | 10 | 10 | 1081 | 131 | 2021-01-09T20:43:07Z | 2020-05-10T17:38:28Z | 21888 |
| 938 | *10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab* | .{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21922 |
| 939 | *10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab* | .{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21923 |
| 940 | *10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab* | .{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21924 |
| 941 | *10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab* | .{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21925 |
| 942 | *10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab* | .{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21926 |
| 943 | *10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab* | .{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21927 |
| 944 | *10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab* | .{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21928 |
| 945 | *10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab* | .{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21929 |
| 946 | *10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab* | .{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21930 |
| 947 | *1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57* | .{0,1000}1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21938 |
| 948 | *1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57* | .{0,1000}1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21939 |
| 949 | *1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57* | .{0,1000}1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21940 |
| 950 | *1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a* | .{0,1000}1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21942 |
| 951 | *1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a* | .{0,1000}1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21943 |
| 952 | *1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a* | .{0,1000}1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21944 |
| 953 | *1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a* | .{0,1000}1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21945 |
| 954 | *1141183bf4a5fdb8a92a4bb9ae2278ec6391e1bc96ebee10245ad8a416372bd9* | .{0,1000}1141183bf4a5fdb8a92a4bb9ae2278ec6391e1bc96ebee10245ad8a416372bd9.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | #filehash | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 21958 |
| 955 | *1141183bf4a5fdb8a92a4bb9ae2278ec6391e1bc96ebee10245ad8a416372bd9* | .{0,1000}1141183bf4a5fdb8a92a4bb9ae2278ec6391e1bc96ebee10245ad8a416372bd9.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | #filehash | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 21959 |
| 956 | *1189360f7da03490a9f0f3ce283d487335a4db24232d6fabfd17bc7ec4e53392* | .{0,1000}1189360f7da03490a9f0f3ce283d487335a4db24232d6fabfd17bc7ec4e53392.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux #filehash | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 21974 |
| 957 | *11a92a7c6a84715416eb8a1c033a6a8db9a70494bfc08c9f09734e599be76cef* | .{0,1000}11a92a7c6a84715416eb8a1c033a6a8db9a70494bfc08c9f09734e599be76cef.{0,1000} | offensive_tool_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #filehash | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 21982 | |
| 958 | *11b29c6bbbcb4bf9dc59b7b308de0da0f13e5f6116a3f10dffe76f4f927ccd8b* | .{0,1000}11b29c6bbbcb4bf9dc59b7b308de0da0f13e5f6116a3f10dffe76f4f927ccd8b.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21984 |
| 959 | *11cb4947c8f8e84c34512070b1ead707af5e948b82937f32e15df293269e678d* | .{0,1000}11cb4947c8f8e84c34512070b1ead707af5e948b82937f32e15df293269e678d.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 21991 |
| 960 | *12545d5c24427a6dc3e63d63472bb344ad1d67f323756f1430b48ae2acdf322d* | .{0,1000}12545d5c24427a6dc3e63d63472bb344ad1d67f323756f1430b48ae2acdf322d.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22030 |
| 961 | *127.0.0.1/C$/Windows/System32/utilman.exe* | .{0,1000}127\.0\.0\.1\/C\$\/Windows\/System32\/utilman\.exe.{0,1000} | offensive_tool_keyword | potato | Potato Privilege Escalation on Windows | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/foxglovesec/Potato | 1 | 0 | #content | N/A | 7 | 8 | 721 | 165 | 2021-01-16T20:34:04Z | 2016-02-09T11:28:17Z | 22039 |
| 962 | *127.0.0.1/pipe/coerced\\C$* | .{0,1000}127\.0\.0\.1\/pipe\/coerced\\\\C\$.{0,1000} | offensive_tool_keyword | CoercedPotato | CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022. | T1548.002 - T1134.002 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Prepouce/CoercedPotato | 1 | 0 | N/A | N/A | 10 | 4 | 366 | 66 | 2024-08-26T08:09:00Z | 2023-09-11T19:04:29Z | 22041 |
| 963 | *130af28d5a846c7f961a6a0a1188e1688501d8c0c4a3df4c1451005f1fc162fa* | .{0,1000}130af28d5a846c7f961a6a0a1188e1688501d8c0c4a3df4c1451005f1fc162fa.{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 0 | #filehash | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 22101 |
| 964 | *1312202e1f36db3f8bb319c6a886ba558373b83dd9d8bd54a8fc42ae156d81cb* | .{0,1000}1312202e1f36db3f8bb319c6a886ba558373b83dd9d8bd54a8fc42ae156d81cb.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux #filehash | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 22105 |
| 965 | *13827593b510bd2cb72270a7bd4aecfe90043112f1a70b879a36b0eaf1efcfa2* | .{0,1000}13827593b510bd2cb72270a7bd4aecfe90043112f1a70b879a36b0eaf1efcfa2.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22138 |
| 966 | *1460d78f92f67929b451732af1d24752026b9d91fd85faec196460f7d4cac9f9* | .{0,1000}1460d78f92f67929b451732af1d24752026b9d91fd85faec196460f7d4cac9f9.{0,1000} | offensive_tool_keyword | PrivFu | SeTcbPrivilege exploitation | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | #filehash | PrivFu\PowerOfTcb | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 22193 |
| 967 | *146ca286f362290e96eda2a0b7cd9feb4e971763ba194731d1826e12e593439d* | .{0,1000}146ca286f362290e96eda2a0b7cd9feb4e971763ba194731d1826e12e593439d.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | #filehash | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 22198 |
| 968 | *148b284dead436f9dbbc23f7e4861901ddc7f1d2cc03c49b8b0379ff6b5633b4* | .{0,1000}148b284dead436f9dbbc23f7e4861901ddc7f1d2cc03c49b8b0379ff6b5633b4.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 0 | #filehash | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 22206 |
| 969 | *14a0ceba63b3d76d7d30653112a0b43e3a2ef1f07a8030d7a949696b5c3065f6* | .{0,1000}14a0ceba63b3d76d7d30653112a0b43e3a2ef1f07a8030d7a949696b5c3065f6.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 0 | #filehash | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 22209 |
| 970 | *156e71ab72393301c2a27995c869afd9972b5fcf4f3a7e92e8335358f11e0306* | .{0,1000}156e71ab72393301c2a27995c869afd9972b5fcf4f3a7e92e8335358f11e0306.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22259 |
| 971 | *1605d453-7d62-4198-a436-27e48ef828eb* | .{0,1000}1605d453\-7d62\-4198\-a436\-27e48ef828eb.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | #GUIDproject | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 22292 |
| 972 | *17914e2d97784ef7aaf52f9f8b04db77cad036308c6b3584fa0fa172ad1da077* | .{0,1000}17914e2d97784ef7aaf52f9f8b04db77cad036308c6b3584fa0fa172ad1da077.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux #filehash | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 22404 |
| 973 | *1812fedbe3078c546fb0b59bd0d1ef35110969a49515f3c7fd1a519469d01104* | .{0,1000}1812fedbe3078c546fb0b59bd0d1ef35110969a49515f3c7fd1a519469d01104.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22432 |
| 974 | *182e81c156f653dea62d0aaa97c23887cf99907e16503654bc1fb55405073903* | .{0,1000}182e81c156f653dea62d0aaa97c23887cf99907e16503654bc1fb55405073903.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | #filehash | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 22441 |
| 975 | *186789b7b7c4973d4f941582a796c3ced5ae7fbc4527cf19040e740d380c4106* | .{0,1000}186789b7b7c4973d4f941582a796c3ced5ae7fbc4527cf19040e740d380c4106.{0,1000} | offensive_tool_keyword | Stifle | .NET Post-Exploitation Utility for Abusing Explicit Certificate Mappings in ADCS | T1550.003 - T1552.004 - T1606.002 | TA0006 - TA0003 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/logangoins/Stifle | 1 | 0 | #filehash | N/A | 7 | 2 | 140 | 9 | 2025-02-10T04:58:46Z | 2025-02-08T06:13:43Z | 22457 |
| 976 | *18841fe957995a34a5b74eb0a894cad7ee2c10d1c33f1955c1623279e81b9343* | .{0,1000}18841fe957995a34a5b74eb0a894cad7ee2c10d1c33f1955c1623279e81b9343.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22465 |
| 977 | *18950aed7a4061673d241d5548f425779a3fa89e734a28b2b91fed786894a698* | .{0,1000}18950aed7a4061673d241d5548f425779a3fa89e734a28b2b91fed786894a698.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22468 |
| 978 | *192f251afb217d7b5080564ef78df67235cf0e47bd78a458706a5dd958a9d093* | .{0,1000}192f251afb217d7b5080564ef78df67235cf0e47bd78a458706a5dd958a9d093.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22510 |
| 979 | *19344cc373b3ed325dd8fcbd5ea333922495486b206c6098c7314f055e194646* | .{0,1000}19344cc373b3ed325dd8fcbd5ea333922495486b206c6098c7314f055e194646.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22513 |
| 980 | *1990a0005ec6cd1b0cbfaa53cb51f27622f17e14df230215cb9921e1b2552a47* | .{0,1000}1990a0005ec6cd1b0cbfaa53cb51f27622f17e14df230215cb9921e1b2552a47.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22540 |
| 981 | *1a550baec33973542f4a634762c680be12e21c3c91eb62e68558bfb5c96bbf5e* | .{0,1000}1a550baec33973542f4a634762c680be12e21c3c91eb62e68558bfb5c96bbf5e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22596 |
| 982 | *1a88b6412bb1e6349948bc6abdc0eebb5df61cc8c0a7ec9709310a77dbc7bccb* | .{0,1000}1a88b6412bb1e6349948bc6abdc0eebb5df61cc8c0a7ec9709310a77dbc7bccb.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 0 | #filehash | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 22610 |
| 983 | *1ac39556a986e4338e44ab2e94fcc34fd12cd690feeef22161d255bd1067d7e1* | .{0,1000}1ac39556a986e4338e44ab2e94fcc34fd12cd690feeef22161d255bd1067d7e1.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22627 |
| 984 | *1ada2351bf027363a8dd71c06a73a7450f52f6b85a0bd08e0e51d83b379172d7* | .{0,1000}1ada2351bf027363a8dd71c06a73a7450f52f6b85a0bd08e0e51d83b379172d7.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22636 |
| 985 | *1B1F64B3-B8A4-4BBB-BB66-F020E2D4F288* | .{0,1000}1B1F64B3\-B8A4\-4BBB\-BB66\-F020E2D4F288.{0,1000} | offensive_tool_keyword | Perfusion | Exploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012) | T1068 - T1055 - T1548.002 | TA0003 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/itm4n/Perfusion | 1 | 0 | #GUIDproject | N/A | 10 | 5 | 419 | 75 | 2021-04-22T16:20:32Z | 2021-02-11T18:28:22Z | 22659 |
| 986 | *1b220d5538e63244c3b81a0c7a83ebb9ac7b0cdaed9f3e84057a812d7192b9b2* | .{0,1000}1b220d5538e63244c3b81a0c7a83ebb9ac7b0cdaed9f3e84057a812d7192b9b2.{0,1000} | offensive_tool_keyword | GTFONow | Automatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins. | T1548.003 - T1548.002 - T1548.001 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Frissi0n/GTFONow | 1 | 0 | #filehash | N/A | 6 | 6 | 566 | 73 | 2024-11-10T08:38:30Z | 2021-01-18T21:16:40Z | 22661 |
| 987 | *1B3C96A3-F698-472B-B786-6FED7A205159* | .{0,1000}1B3C96A3\-F698\-472B\-B786\-6FED7A205159.{0,1000} | offensive_tool_keyword | localpotato | The LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege. | T1550.002 - T1078.003 - T1005 - T1070.004 | TA0004 - TA0006 - TA0002 | N/A | N/A | Privilege Escalation | https://github.com/decoder-it/LocalPotato | 1 | 0 | #GUIDproject | N/A | 10 | 7 | 691 | 92 | 2023-11-07T01:09:08Z | 2023-01-04T18:22:29Z | 22668 |
| 988 | *1ba53ac62c21cd1f829f4d4cb0ee06906cd3bfd0cf78da267c3b7d9acfb6d27b* | .{0,1000}1ba53ac62c21cd1f829f4d4cb0ee06906cd3bfd0cf78da267c3b7d9acfb6d27b.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22702 |
| 989 | *1BF9C10F-6F89-4520-9D2E-AAF17D17BA5E* | .{0,1000}1BF9C10F\-6F89\-4520\-9D2E\-AAF17D17BA5E.{0,1000} | offensive_tool_keyword | SweetPotato | Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019 | T1548 - T1055 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/CCob/SweetPotato | 1 | 0 | #GUIDproject | N/A | 10 | 10 | 1697 | 228 | 2024-09-04T17:09:30Z | 2020-04-12T17:40:03Z | 22721 |
| 990 | *1c14d0d58efdd3244a1fd4398ef9c65e96bfe4faccc168e7ace84728da908d9e* | .{0,1000}1c14d0d58efdd3244a1fd4398ef9c65e96bfe4faccc168e7ace84728da908d9e.{0,1000} | offensive_tool_keyword | PrivFu | enable or disable specific token privileges for a process | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #filehash | SwitchPriv | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 22730 |
| 991 | *1c291548b59d3af8b3c225cb7e019b86a3cb706eec437b275528699898bcdb3a* | .{0,1000}1c291548b59d3af8b3c225cb7e019b86a3cb706eec437b275528699898bcdb3a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22734 |
| 992 | *1c6b60ff20f7c26a7436d966fc741ecd05dc2b3326de1ebcd7fcf6142ac24409* | .{0,1000}1c6b60ff20f7c26a7436d966fc741ecd05dc2b3326de1ebcd7fcf6142ac24409.{0,1000} | offensive_tool_keyword | RemotePotato0 | Windows Privilege Escalation from User to Domain Admin. | T1078.002 - T1078.003 - T1078.004 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/antonioCoco/RemotePotato0 | 1 | 0 | #filehash | N/A | 10 | 10 | 1382 | 215 | 2022-12-18T01:52:53Z | 2021-02-08T22:02:19Z | 22749 |
| 993 | *1cad3b4c47e6f3d4f97c3299b8d1498bd2a4cd3c7eb26f255f693bbcd46fe516* | .{0,1000}1cad3b4c47e6f3d4f97c3299b8d1498bd2a4cd3c7eb26f255f693bbcd46fe516.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #filehash | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 22768 |
| 994 | *1d6d4c0b001fc20d404d6e2ec3625d9fc245c31484023e2ac7a3b123eec8cce1* | .{0,1000}1d6d4c0b001fc20d404d6e2ec3625d9fc245c31484023e2ac7a3b123eec8cce1.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | #filehash | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 22823 |
| 995 | *1e53b8773c0796d3bed82c67ced0fa96ec2565a697035826a8cec638c6454c7b* | .{0,1000}1e53b8773c0796d3bed82c67ced0fa96ec2565a697035826a8cec638c6454c7b.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22891 |
| 996 | *1eb987e0-23a5-415e-9194-cd961314441b* | .{0,1000}1eb987e0\-23a5\-415e\-9194\-cd961314441b.{0,1000} | offensive_tool_keyword | PrivFu | SeTcbPrivilege exploitation | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | #GUIDproject | PrivFu\PowerOfTcb | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 22926 |
| 997 | *1f09a88ab2eca35f7e5abd4cc2f11a8f25cd7a060a5c3a943ee88e66fa241dd0* | .{0,1000}1f09a88ab2eca35f7e5abd4cc2f11a8f25cd7a060a5c3a943ee88e66fa241dd0.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22954 |
| 998 | *1f350bc4b39f1e89f64366e08af152badfb9756d600b5e611af2433b1e0d3687* | .{0,1000}1f350bc4b39f1e89f64366e08af152badfb9756d600b5e611af2433b1e0d3687.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22970 |
| 999 | *1f63e243a7469526eb57f6d08a8d14fbb58290eb999247a005679809fc307edb* | .{0,1000}1f63e243a7469526eb57f6d08a8d14fbb58290eb999247a005679809fc307edb.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 22983 |
| 1000 | *205acf53b1ebc226645925788768bf52c0701d3227fedc7565cb803862cee602* | .{0,1000}205acf53b1ebc226645925788768bf52c0701d3227fedc7565cb803862cee602.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23060 |
| 1001 | *205acf53b1ebc226645925788768bf52c0701d3227fedc7565cb803862cee602* | .{0,1000}205acf53b1ebc226645925788768bf52c0701d3227fedc7565cb803862cee602.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23061 |
| 1002 | *20b948d35e9e730e5aaa00f8de01107af773b93313fed752ae63afcd45353073* | .{0,1000}20b948d35e9e730e5aaa00f8de01107af773b93313fed752ae63afcd45353073.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux #filehash | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 23085 |
| 1003 | *22048db7a9a636d9bebbce5d6e883f87942a5fe9546341bf66d234b89772df4b* | .{0,1000}22048db7a9a636d9bebbce5d6e883f87942a5fe9546341bf66d234b89772df4b.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23174 |
| 1004 | *220dea762dec11fe8d6a5b7a24b6af9e4b72dfc084e2b1b835ab661323486ecc* | .{0,1000}220dea762dec11fe8d6a5b7a24b6af9e4b72dfc084e2b1b835ab661323486ecc.{0,1000} | offensive_tool_keyword | ShimMe | Injects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection. | T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070 | TA0004 - TA0005 - TA0006 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/ShimMe | 1 | 0 | #filehash | N/A | 9 | 2 | 140 | 20 | 2024-10-29T07:33:38Z | 2024-08-04T10:03:28Z | 23179 |
| 1005 | *227c72ed-494a-4d29-9170-5e5994c12f5c* | .{0,1000}227c72ed\-494a\-4d29\-9170\-5e5994c12f5c.{0,1000} | offensive_tool_keyword | POC | Windows Privilege escalation POC exploitation for CVE-2024-49138 | T1068 - T1058 - T1203 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/emdnaia/CVE-2024-49138-POC | 1 | 0 | #GUIDproject | N/A | 9 | 1 | 1 | 0 | 2025-01-15T01:01:21Z | 2025-01-15T02:11:49Z | 23218 |
| 1006 | *2297A528-E866-4056-814A-D01C1C305A38* | .{0,1000}2297A528\-E866\-4056\-814A\-D01C1C305A38.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #GUIDproject | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 23224 |
| 1007 | *233c1188ee1bfe659c4403fda91ac1ce114d9f44f6478cbbe9e8fa22b1e6c600* | .{0,1000}233c1188ee1bfe659c4403fda91ac1ce114d9f44f6478cbbe9e8fa22b1e6c600.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23269 |
| 1008 | *233d78a0eb44c9b9d7a92ee810f90dec29ab1778536c1b9f5d16c988ac0c70ab* | .{0,1000}233d78a0eb44c9b9d7a92ee810f90dec29ab1778536c1b9f5d16c988ac0c70ab.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23272 |
| 1009 | *234cfdd1b014e769ee31cda9b6dd0a17c05f028a6e059e5bd4d01175e986dfb0* | .{0,1000}234cfdd1b014e769ee31cda9b6dd0a17c05f028a6e059e5bd4d01175e986dfb0.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23274 |
| 1010 | *23779f962171cb3bb425ed7cc6aca741338b9340ede2eb8fa70aad40ddcfca8f* | .{0,1000}23779f962171cb3bb425ed7cc6aca741338b9340ede2eb8fa70aad40ddcfca8f.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23283 |
| 1011 | *24d861124682031773ac0f6df9e5011b18a8d925c8c22469330826e64ccc2bab* | .{0,1000}24d861124682031773ac0f6df9e5011b18a8d925c8c22469330826e64ccc2bab.{0,1000} | offensive_tool_keyword | linuxprivchecker | search for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploits | T1210.001 - T1082 - T1088 - T1547.001 | TA0002 - TA0004 - TA0006 - TA0007 - TA0008 | N/A | N/A | Privilege Escalation | https://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py | 1 | 0 | #filehash #linux | N/A | 7 | 10 | 1645 | 524 | 2022-01-31T10:32:08Z | 2016-04-19T13:31:46Z | 23375 |
| 1012 | *24fe09ac811357d1a5ddd63652604def847cb2d4f81c01ecfe563ead611783e3* | .{0,1000}24fe09ac811357d1a5ddd63652604def847cb2d4f81c01ecfe563ead611783e3.{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 0 | #filehash | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 23384 |
| 1013 | *24fe09ac811357d1a5ddd63652604def847cb2d4f81c01ecfe563ead611783e3* | .{0,1000}24fe09ac811357d1a5ddd63652604def847cb2d4f81c01ecfe563ead611783e3.{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 0 | #filehash | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 23385 |
| 1014 | *2507ccefca7ad5cc4247bae065b0fefb7c3b16cf2d1190535473a05f213d5004* | .{0,1000}2507ccefca7ad5cc4247bae065b0fefb7c3b16cf2d1190535473a05f213d5004.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23388 |
| 1015 | *26085f4768e13063e5dde27f0e313854ce91aa032a7b26d4f57ebc03a6628560* | .{0,1000}26085f4768e13063e5dde27f0e313854ce91aa032a7b26d4f57ebc03a6628560.{0,1000} | offensive_tool_keyword | KExecDD | Admin to Kernel code execution using the KSecDD driver | T1068 - T1055.011 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/floesen/KExecDD | 1 | 0 | #filehash | N/A | 8 | 3 | 244 | 41 | 2024-04-19T09:58:14Z | 2024-04-19T08:54:49Z | 23459 |
| 1016 | *261f880e-4bee-428d-9f64-c29292002c19* | .{0,1000}261f880e\-4bee\-428d\-9f64\-c29292002c19.{0,1000} | offensive_tool_keyword | JuicyPotatoNG | Another Windows Local Privilege Escalation from Service Account to System | T1055.002 - T1078.003 - T1070.004 | TA0005 - TA0004 - TA0002 | N/A | FoxKitten - APT33 - Volatile Cedar - Sandworm | Privilege Escalation | https://github.com/antonioCoco/JuicyPotatoNG | 1 | 0 | #GUIDproject | N/A | 10 | 9 | 844 | 101 | 2022-11-12T01:48:39Z | 2022-09-21T17:08:35Z | 23467 |
| 1017 | *266fa73ded3a2a2dc421e5605dc2fa2bff53d999fe3adebc44ffa989c33061bf* | .{0,1000}266fa73ded3a2a2dc421e5605dc2fa2bff53d999fe3adebc44ffa989c33061bf.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23487 |
| 1018 | *26de444c20c30bd7d731ff5322fca24dc5f442f43daaa5d840edfcc594e17465* | .{0,1000}26de444c20c30bd7d731ff5322fca24dc5f442f43daaa5d840edfcc594e17465.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23525 |
| 1019 | *272dd72f9bdff7973ed8b642bf8713ece481e208a77fd03b6a24f2b520e1d49e* | .{0,1000}272dd72f9bdff7973ed8b642bf8713ece481e208a77fd03b6a24f2b520e1d49e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23546 |
| 1020 | *27744baf01464354d336015e1051fdc6706235549f5e62e0230e139eb743b4bb* | .{0,1000}27744baf01464354d336015e1051fdc6706235549f5e62e0230e139eb743b4bb.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23565 |
| 1021 | *27E42E24-9F76-44E2-B1D6-82F68D5C4466* | .{0,1000}27E42E24\-9F76\-44E2\-B1D6\-82F68D5C4466.{0,1000} | offensive_tool_keyword | POC | Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled. | T1055.011 - T1548.002 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/hakaioffsec/CVE-2024-21338 | 1 | 0 | #GUIDproject | N/A | 9 | 3 | 292 | 60 | 2024-04-16T21:00:14Z | 2024-04-13T05:53:02Z | 23589 |
| 1022 | *288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd* | .{0,1000}288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23629 |
| 1023 | *288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd* | .{0,1000}288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23630 |
| 1024 | *288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd* | .{0,1000}288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23631 |
| 1025 | *28a29dffc8a5924a97a67798c91db2b75d5b2841ec3c810886fa5554fe2e899d* | .{0,1000}28a29dffc8a5924a97a67798c91db2b75d5b2841ec3c810886fa5554fe2e899d.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23636 |
| 1026 | *290083a0a3dac6b3c05ab3e01fb5cdfb128c0175914f1fe64cdb1a5e247d43f0* | .{0,1000}290083a0a3dac6b3c05ab3e01fb5cdfb128c0175914f1fe64cdb1a5e247d43f0.{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/cube0x0/CVE-2021-1675 | 1 | 0 | #filehash | N/A | 10 | 10 | 1879 | 582 | 2021-07-20T15:28:13Z | 2021-06-29T17:24:14Z | 23659 |
| 1027 | *291cf10eee25d10b0ddaddfb68b643dab252c1466fa4e813bb753b19b6604ef1* | .{0,1000}291cf10eee25d10b0ddaddfb68b643dab252c1466fa4e813bb753b19b6604ef1.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23669 |
| 1028 | *296176cf45851a6671437cced0cbfaf3aadf9c5d717ea973f911928a36a78442* | .{0,1000}296176cf45851a6671437cced0cbfaf3aadf9c5d717ea973f911928a36a78442.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | #filehash | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 23691 |
| 1029 | *2AD3951D-DEA6-4CF7-88BE-4C73344AC9DA* | .{0,1000}2AD3951D\-DEA6\-4CF7\-88BE\-4C73344AC9DA.{0,1000} | offensive_tool_keyword | PrivFu | ArtsOfGetSystem privesc tools | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | #GUIDproject | ArtsOfGetSystem | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 23775 |
| 1030 | *2AE886C3-3272-40BE-8D3C-EBAEDE9E61E1* | .{0,1000}2AE886C3\-3272\-40BE\-8D3C\-EBAEDE9E61E1.{0,1000} | offensive_tool_keyword | DeadPotato | DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | N/A | N/A | Privilege Escalation | https://github.com/lypd0/DeadPotato | 1 | 0 | #GUIDproject | N/A | 10 | 4 | 382 | 45 | 2024-08-17T06:08:29Z | 2024-07-31T01:08:30Z | 23780 |
| 1031 | *2AE886C3-3272-40BE-8D3C-EBAEDE9E61E1* | .{0,1000}2AE886C3\-3272\-40BE\-8D3C\-EBAEDE9E61E1.{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 0 | #GUIDproject | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 23781 |
| 1032 | *2AE886C3-3272-40BE-8D3C-EBAEDE9E61E1* | .{0,1000}2AE886C3\-3272\-40BE\-8D3C\-EBAEDE9E61E1.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 0 | #GUIDproject | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 23782 |
| 1033 | *2b0ae5d810f64cc33f7f5df193aa56c3f39d85b0447242491da024b0a1b1a45a* | .{0,1000}2b0ae5d810f64cc33f7f5df193aa56c3f39d85b0447242491da024b0a1b1a45a.{0,1000} | offensive_tool_keyword | PrivFu | get SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privileges | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #filehash | KernelWritePoCs | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 23789 |
| 1034 | *2B704D89-41B9-4051-A51C-36A82ACEBE10* | .{0,1000}2B704D89\-41B9\-4051\-A51C\-36A82ACEBE10.{0,1000} | offensive_tool_keyword | PrivFu | SeTcbPrivilege exploitation | T1134 - T1134.001 - T1078 - T1059 - T1075 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu/ | 1 | 0 | #GUIDproject | PrivFu\PowerOfTcb | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 23816 |
| 1035 | *2b8c3873a05907a9f2d211fdc992666345d060c7376b6e9760fb800a4a54076c* | .{0,1000}2b8c3873a05907a9f2d211fdc992666345d060c7376b6e9760fb800a4a54076c.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23817 |
| 1036 | *2c96a3a04b62c87a9e5179230186d006f49dca951b230c1db6a543d5ee5ef2b6* | .{0,1000}2c96a3a04b62c87a9e5179230186d006f49dca951b230c1db6a543d5ee5ef2b6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23890 |
| 1037 | *2cc9517df6d1839ac8bd5077a34ad43f2377e0e4fc9c024f5f9e44b150b94baf* | .{0,1000}2cc9517df6d1839ac8bd5077a34ad43f2377e0e4fc9c024f5f9e44b150b94baf.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23900 |
| 1038 | *2CFB9E9E-479D-4E23-9A8E-18C92E06B731* | .{0,1000}2CFB9E9E\-479D\-4E23\-9A8E\-18C92E06B731.{0,1000} | offensive_tool_keyword | NoFilter | Tool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine. | T1548 - T1548.002 - T1055 - T1055.004 | TA0004 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/deepinstinct/NoFilter | 1 | 0 | #GUIDproject | N/A | 9 | 3 | 298 | 48 | 2024-10-29T07:30:35Z | 2023-07-30T09:25:38Z | 23912 |
| 1039 | *2daeb177f86c873780c59e59fa8c424e45aea199bf5fb3e935310b043d41787f* | .{0,1000}2daeb177f86c873780c59e59fa8c424e45aea199bf5fb3e935310b043d41787f.{0,1000} | offensive_tool_keyword | PrintNightmare | PrintNightmare exploitation | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | https://github.com/cube0x0/CVE-2021-1675 | 1 | 0 | #filehash | N/A | 10 | 10 | 1879 | 582 | 2021-07-20T15:28:13Z | 2021-06-29T17:24:14Z | 23959 |
| 1040 | *2e179a37f42864951b1151bba266fff17c45e6cacf0fbc8ebf8d8ad9ab45ada9* | .{0,1000}2e179a37f42864951b1151bba266fff17c45e6cacf0fbc8ebf8d8ad9ab45ada9.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 23984 |
| 1041 | *2e67c9adb1962e9b5c9a025b2901fc01e2a214b53f5552656a07f2057307f6e5* | .{0,1000}2e67c9adb1962e9b5c9a025b2901fc01e2a214b53f5552656a07f2057307f6e5.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | #filehash | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 24001 |
| 1042 | *2ebd756e16d30a5270d5b850eac35b51f1448536adb37e1b415669d51b67c775* | .{0,1000}2ebd756e16d30a5270d5b850eac35b51f1448536adb37e1b415669d51b67c775.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24040 |
| 1043 | *2ebd756e16d30a5270d5b850eac35b51f1448536adb37e1b415669d51b67c775* | .{0,1000}2ebd756e16d30a5270d5b850eac35b51f1448536adb37e1b415669d51b67c775.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24041 |
| 1044 | *2ec87edb4eba79beefc686363936786094dacb8616bdbcccbec2cefc367f080b* | .{0,1000}2ec87edb4eba79beefc686363936786094dacb8616bdbcccbec2cefc367f080b.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24045 |
| 1045 | *2ec87edb4eba79beefc686363936786094dacb8616bdbcccbec2cefc367f080b* | .{0,1000}2ec87edb4eba79beefc686363936786094dacb8616bdbcccbec2cefc367f080b.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24046 |
| 1046 | *2f00a05b-263d-4fcc-846b-da82bd684603* | .{0,1000}2f00a05b\-263d\-4fcc\-846b\-da82bd684603.{0,1000} | offensive_tool_keyword | Telemetry | Abusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges. | T1053 - T1547 - T1059 | TA0003 - TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Imanfeng/Telemetry | 1 | 0 | #GUIDproject | N/A | 9 | 2 | 140 | 13 | 2020-07-02T09:41:27Z | 2020-06-24T16:30:44Z | 24074 |
| 1047 | *2fc2426035652b2ecfc952407b4d22ab78b9ae554da8f2466bccf48fa2a3870a* | .{0,1000}2fc2426035652b2ecfc952407b4d22ab78b9ae554da8f2466bccf48fa2a3870a.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #filehash | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 24125 |
| 1048 | *3027a212272957298bf4d32505370fa63fb162d6a6a6ec091af9d7626317a858* | .{0,1000}3027a212272957298bf4d32505370fa63fb162d6a6a6ec091af9d7626317a858.{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 0 | #filehash | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 24165 |
| 1049 | *3027a212272957298bf4d32505370fa63fb162d6a6a6ec091af9d7626317a858* | .{0,1000}3027a212272957298bf4d32505370fa63fb162d6a6a6ec091af9d7626317a858.{0,1000} | offensive_tool_keyword | godpotato | GodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities. | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | N/A | Privilege Escalation | https://github.com/BeichenDream/GodPotato | 1 | 0 | #filehash | N/A | 10 | 10 | 1938 | 236 | 2023-11-24T19:22:31Z | 2022-12-23T14:37:00Z | 24166 |
| 1050 | *3188b14bc09838bf33b57704649237b1c1d343189edaf142cfcf9608c4a41e5d* | .{0,1000}3188b14bc09838bf33b57704649237b1c1d343189edaf142cfcf9608c4a41e5d.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24264 |
| 1051 | *31afc2becc2f46a5f993745e453b13146ca804c48eab0c5b41ba859286cad77a* | .{0,1000}31afc2becc2f46a5f993745e453b13146ca804c48eab0c5b41ba859286cad77a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24279 |
| 1052 | *320ed251abc046f440dc0e76d00864d6cf5f65dee61988898d86c18e5513a8c9* | .{0,1000}320ed251abc046f440dc0e76d00864d6cf5f65dee61988898d86c18e5513a8c9.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 0 | #filehash | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 24305 |
| 1053 | *329797f116972ec9d9ef719592d687908a2dd4bd5066900bee5452225ca8beb3* | .{0,1000}329797f116972ec9d9ef719592d687908a2dd4bd5066900bee5452225ca8beb3.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24338 |
| 1054 | *337cd6f66f324a1e30d9bae046f10577318da2126f3981dfff99c6def8799bd4* | .{0,1000}337cd6f66f324a1e30d9bae046f10577318da2126f3981dfff99c6def8799bd4.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24407 |
| 1055 | *337ED7BE-969A-40C4-A356-BE99561F4633* | .{0,1000}337ED7BE\-969A\-40C4\-A356\-BE99561F4633.{0,1000} | offensive_tool_keyword | CoercedPotato | CoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022. | T1548.002 - T1134.002 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/Prepouce/CoercedPotato | 1 | 0 | #GUIDproject | N/A | 10 | 4 | 366 | 66 | 2024-08-26T08:09:00Z | 2023-09-11T19:04:29Z | 24409 |
| 1056 | *337ED7BE-969A-40C4-A356-BE99561F4633* | .{0,1000}337ED7BE\-969A\-40C4\-A356\-BE99561F4633.{0,1000} | offensive_tool_keyword | CoercedPotatoRDLL | Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege | T1055 - T1134 - T1548 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/sokaRepo/CoercedPotatoRDLL | 1 | 0 | #GUIDproject | N/A | 10 | 3 | 204 | 31 | 2023-11-23T18:58:41Z | 2023-11-23T13:22:38Z | 24410 |
| 1057 | *347e20ccd42d4346d9a1cb3255d77b493d3b1b52be12f72ccaa9085d6b5dd30f* | .{0,1000}347e20ccd42d4346d9a1cb3255d77b493d3b1b52be12f72ccaa9085d6b5dd30f.{0,1000} | offensive_tool_keyword | BadWindowsService | An insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilities | T1068 - T1211 - T1050 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/BadWindowsService | 1 | 0 | #filehash | N/A | 10 | 1 | 58 | 10 | 2022-08-25T14:22:25Z | 2022-08-19T15:38:05Z | 24478 |
| 1058 | *348980f606af2f76e3fb4ac9e1e66f3eb42da0091e72695942a3e97ff7977c0b* | .{0,1000}348980f606af2f76e3fb4ac9e1e66f3eb42da0091e72695942a3e97ff7977c0b.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux #filehash | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 24484 |
| 1059 | *34b4ac22a90064a96fcea9ff8e3f5f3bd089af9672d0e5313d3b1b8f0f0a9125* | .{0,1000}34b4ac22a90064a96fcea9ff8e3f5f3bd089af9672d0e5313d3b1b8f0f0a9125.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24496 |
| 1060 | *351268e508cccd1a0bf2c53e605a5db1df85b8c5d4095a4ef0e2d9bb997b39a2* | .{0,1000}351268e508cccd1a0bf2c53e605a5db1df85b8c5d4095a4ef0e2d9bb997b39a2.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24518 |
| 1061 | *351b7ea09ad99959f21e0c21bef93112ec360ccef4bc0cbaaed390a16631326b* | .{0,1000}351b7ea09ad99959f21e0c21bef93112ec360ccef4bc0cbaaed390a16631326b.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 0 | #filehash | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 24521 |
| 1062 | *358282c9584c5b32ce5aa55238c71fc7d4cb405e5b7f0ef5e2db4950a4a34b4f* | .{0,1000}358282c9584c5b32ce5aa55238c71fc7d4cb405e5b7f0ef5e2db4950a4a34b4f.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24548 |
| 1063 | *363a083ee261a6b87743076d1f38062c4e23d0938817c63dea8716b694c78c7a* | .{0,1000}363a083ee261a6b87743076d1f38062c4e23d0938817c63dea8716b694c78c7a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24587 |
| 1064 | *36a795ba9dfe58c4e8cac8b24ada8cbee9b598dc7af6ee076de0b09750aea29a* | .{0,1000}36a795ba9dfe58c4e8cac8b24ada8cbee9b598dc7af6ee076de0b09750aea29a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24616 |
| 1065 | *36c88f1852f3c162bf64d973bb6f69ffb7e22503015e104716fc51eaddcbe875* | .{0,1000}36c88f1852f3c162bf64d973bb6f69ffb7e22503015e104716fc51eaddcbe875.{0,1000} | offensive_tool_keyword | DirCreate2System | Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting | T1068 - T1059.001 - T1070.004 | TA0003 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/binderlabs/DirCreate2System | 1 | 0 | #filehash | N/A | 8 | 4 | 357 | 38 | 2022-12-19T17:00:43Z | 2022-12-15T03:49:55Z | 24628 |
| 1066 | *36f45e69b0d6ce0325647dbe792399267ce73266f5cc72ca6f2bd845ba5513c9* | .{0,1000}36f45e69b0d6ce0325647dbe792399267ce73266f5cc72ca6f2bd845ba5513c9.{0,1000} | offensive_tool_keyword | PrivFu | enable or disable specific token privileges for a process | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #filehash | SwitchPriv | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 24642 |
| 1067 | *3727823313bffb3ba255f6bd4be4239a6b6816ead83aa024cec2459e4ef2cbf1* | .{0,1000}3727823313bffb3ba255f6bd4be4239a6b6816ead83aa024cec2459e4ef2cbf1.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24662 |
| 1068 | *37447f986ad651df8ea39416f5d5289fda6d3d48155e7ae257c086f9a2478de0* | .{0,1000}37447f986ad651df8ea39416f5d5289fda6d3d48155e7ae257c086f9a2478de0.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | #filehash | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 24668 |
| 1069 | *378f6e87219651f96e607e40c229e5f17df4ad71836409881fe3cc77c6780ac7* | .{0,1000}378f6e87219651f96e607e40c229e5f17df4ad71836409881fe3cc77c6780ac7.{0,1000} | offensive_tool_keyword | SharpElevator | SharpElevator is a C# implementation of Elevator for UAC bypass | T1548.002 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/SharpElevator | 1 | 0 | #filehash | N/A | 10 | 1 | 51 | 12 | 2022-08-31T18:09:10Z | 2022-08-29T19:52:53Z | 24686 |
| 1070 | *37ee54a15c44f222327a9d77243113c2b0efb07451eca2f887d314b6e0963f86* | .{0,1000}37ee54a15c44f222327a9d77243113c2b0efb07451eca2f887d314b6e0963f86.{0,1000} | offensive_tool_keyword | SigmaPotato | SeImpersonate privilege escalation tool | T1134 - T1055 - T1543 | TA0004 - TA0005 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/tylerdotrar/SigmaPotato | 1 | 0 | #filehash | N/A | 9 | 4 | 326 | 38 | 2024-05-16T23:46:04Z | 2023-09-09T01:35:42Z | 24709 |
| 1071 | *39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6* | .{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24797 |
| 1072 | *39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6* | .{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24798 |
| 1073 | *39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6* | .{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24799 |
| 1074 | *39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6* | .{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24800 |
| 1075 | *39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6* | .{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24801 |
| 1076 | *39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6* | .{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24802 |
| 1077 | *39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6* | .{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24803 |
| 1078 | *39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6* | .{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24804 |
| 1079 | *39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6* | .{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24805 |
| 1080 | *3a0b118ddd6b02426aba9ead93a576f7b99997cf6f07907147dd0d3294ff8887* | .{0,1000}3a0b118ddd6b02426aba9ead93a576f7b99997cf6f07907147dd0d3294ff8887.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | #filehash | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 24861 |
| 1081 | *3aa113440e9f684df0d0f889c69ae914a40b07c10a340d1fad4f8365286fe19d* | .{0,1000}3aa113440e9f684df0d0f889c69ae914a40b07c10a340d1fad4f8365286fe19d.{0,1000} | offensive_tool_keyword | KrbRelayUp | a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). | T1558 - T1210 | TA0004 - TA0003 | N/A | Dispossessor - Back Basta | Privilege Escalation | https://github.com/Dec0ne/KrbRelayUp | 1 | 0 | #filehash | N/A | 10 | 10 | 1580 | 209 | 2022-08-06T12:23:58Z | 2022-04-24T21:33:00Z | 24911 |
| 1082 | *3b02572ebc1fa9eb22898bc2f17f72d50775a18d4c6ff3094ea19e5b5f25c949* | .{0,1000}3b02572ebc1fa9eb22898bc2f17f72d50775a18d4c6ff3094ea19e5b5f25c949.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24932 |
| 1083 | *3b730f6be970c1671b68792fe163427a15e0fa4426b1d635d9f7e74872f91a7d* | .{0,1000}3b730f6be970c1671b68792fe163427a15e0fa4426b1d635d9f7e74872f91a7d.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 24957 |
| 1084 | *3c3a96d02e34589d314b230c417b122970e492282767211866c8ac042e8bd556* | .{0,1000}3c3a96d02e34589d314b230c417b122970e492282767211866c8ac042e8bd556.{0,1000} | offensive_tool_keyword | S4UTomato | Escalate Service Account To LocalSystem via Kerberos | T1558 - T1558.002 - T1548.002 - T1078 - T1078.004 | TA0006 - TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/wh0amitz/S4UTomato | 1 | 0 | #filehash | N/A | 10 | 4 | 394 | 76 | 2023-09-14T08:53:19Z | 2023-07-30T11:51:57Z | 25017 |
| 1085 | *3cb401fdba1a0e74389ac9998005805f1d3e8ed70018d282f5885410d48725e1* | .{0,1000}3cb401fdba1a0e74389ac9998005805f1d3e8ed70018d282f5885410d48725e1.{0,1000} | offensive_tool_keyword | traitor | Automatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easy | T1068 - T1548.004 - T1611 - T1203 - T1059.004 | TA0004 - TA0001 - TA0002 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/liamg/traitor | 1 | 0 | #linux #filehash | N/A | 10 | 10 | 6853 | 651 | 2024-03-12T21:01:14Z | 2021-01-24T10:50:15Z | 25050 |
| 1086 | *3cd433ed1ca4566eade23d65399ebc7399e230fcdbde56deb29891e0213aefc1* | .{0,1000}3cd433ed1ca4566eade23d65399ebc7399e230fcdbde56deb29891e0213aefc1.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25057 |
| 1087 | *3ce51c89b8367bae6cae0ff3fa4bbe420df215568e10af5f7b29b3e19048a2e8* | .{0,1000}3ce51c89b8367bae6cae0ff3fa4bbe420df215568e10af5f7b29b3e19048a2e8.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25063 |
| 1088 | *3e3092fdc0f518823e6cdbff46f7ad327bee6bca9477a826279c7a76bffa7bce* | .{0,1000}3e3092fdc0f518823e6cdbff46f7ad327bee6bca9477a826279c7a76bffa7bce.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25136 |
| 1089 | *3e55d1d13465cb7e706efa6d4ddf120b35200d694c619889de3d3190236e780a* | .{0,1000}3e55d1d13465cb7e706efa6d4ddf120b35200d694c619889de3d3190236e780a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25149 |
| 1090 | *3e667715625410352da4236f16184e38c442b2af48fd6f8899b954578c974c8b* | .{0,1000}3e667715625410352da4236f16184e38c442b2af48fd6f8899b954578c974c8b.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25154 |
| 1091 | *3e6ea66956ca27686fdb0b1a7fa1a86ddec39e72aa892958bf9f3b4c5dbce7df* | .{0,1000}3e6ea66956ca27686fdb0b1a7fa1a86ddec39e72aa892958bf9f3b4c5dbce7df.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25159 |
| 1092 | *3e95f084c11e971e4b30805e59d4cef87b5698ba21ce72b8a228b4e33c069754* | .{0,1000}3e95f084c11e971e4b30805e59d4cef87b5698ba21ce72b8a228b4e33c069754.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25171 |
| 1093 | *3eca25646f5d9435a6d13eaed2781aaa5efad2a3e512e154892f7a5cde46805f* | .{0,1000}3eca25646f5d9435a6d13eaed2781aaa5efad2a3e512e154892f7a5cde46805f.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25187 |
| 1094 | *3ef06f25d21583d9c1158704c593f3276a1056cf6d23f8c56d8dac84df5320de* | .{0,1000}3ef06f25d21583d9c1158704c593f3276a1056cf6d23f8c56d8dac84df5320de.{0,1000} | offensive_tool_keyword | DeadPotato | DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | N/A | N/A | Privilege Escalation | https://github.com/lypd0/DeadPotato | 1 | 0 | #filehash | N/A | 10 | 4 | 382 | 45 | 2024-08-17T06:08:29Z | 2024-07-31T01:08:30Z | 25201 |
| 1095 | *3ef598c9422361f5ce5252d0c4261d88889b51c2c9794ca6a72c6669e77526b1* | .{0,1000}3ef598c9422361f5ce5252d0c4261d88889b51c2c9794ca6a72c6669e77526b1.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25202 |
| 1096 | *3f4dc752db705589bdb8e487a55dbdc6891c13c557ec0383701fc5b94d8f8264* | .{0,1000}3f4dc752db705589bdb8e487a55dbdc6891c13c557ec0383701fc5b94d8f8264.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25227 |
| 1097 | *3f7216ab8b49c48f550b68c1e5b8d55f10ff60506090ff19e8b6654186b7bf5c* | .{0,1000}3f7216ab8b49c48f550b68c1e5b8d55f10ff60506090ff19e8b6654186b7bf5c.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25239 |
| 1098 | *40e7b75207030fb9603977b5b4fb3a8e67f73a243f004cc6eac07114f2ae061a* | .{0,1000}40e7b75207030fb9603977b5b4fb3a8e67f73a243f004cc6eac07114f2ae061a.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25370 |
| 1099 | *410D25CC-A75E-4B65-8D24-05FA4D8AE0B9* | .{0,1000}410D25CC\-A75E\-4B65\-8D24\-05FA4D8AE0B9.{0,1000} | offensive_tool_keyword | PrivFu | Tool to execute token assigned process | T1055 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #GUIDproject | TokenAssignor | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 25384 |
| 1100 | *413be3fa27650bb8202b36a93755e57a56faf88d98f38a8c546ac6117c70575e* | .{0,1000}413be3fa27650bb8202b36a93755e57a56faf88d98f38a8c546ac6117c70575e.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25394 |
| 1101 | *4164003E-BA47-4A95-8586-D5AAC399C050* | .{0,1000}4164003E\-BA47\-4A95\-8586\-D5AAC399C050.{0,1000} | offensive_tool_keyword | JuicyPotato | Windows Local Privilege Escalation from Service Account to System | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/uknowsec/JuicyPotato | 1 | 0 | #GUIDproject | N/A | 10 | 2 | 190 | 46 | 2021-07-01T05:28:41Z | 2021-06-10T12:06:13Z | 25407 |
| 1102 | *4164003E-BA47-4A95-8586-D5AAC399C050* | .{0,1000}4164003E\-BA47\-4A95\-8586\-D5AAC399C050.{0,1000} | offensive_tool_keyword | RottenPotatoNG | perform the RottenPotato attack and get a handle to a privileged token | T1134.001 - T1055.012 - T1547.001 | TA0004 | N/A | Sandworm | Privilege Escalation | https://github.com/breenmachine/RottenPotatoNG | 1 | 0 | #GUIDproject | N/A | 8 | 10 | 935 | 183 | 2017-12-29T14:38:47Z | 2017-12-29T13:19:03Z | 25408 |
| 1103 | *416656DC-D499-498B-8ACF-6502A13EFC9E* | .{0,1000}416656DC\-D499\-498B\-8ACF\-6502A13EFC9E.{0,1000} | offensive_tool_keyword | MakeMeAdmin | Enables users to elevate themselves to administrator-level rights | T1078 - T1059 - T1087 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/pseymour/MakeMeAdmin | 1 | 0 | #GUIDproject | N/A | 9 | 5 | 430 | 94 | 2024-12-22T02:56:23Z | 2018-05-29T19:42:58Z | 25409 |
| 1104 | *42560ffa5cc3bf26dd9cf38c0bc8e2dbf853646128af8ca713e579023ff42ada* | .{0,1000}42560ffa5cc3bf26dd9cf38c0bc8e2dbf853646128af8ca713e579023ff42ada.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25478 |
| 1105 | *4278e1122672d9c4029ec7c7f3a0e5180d7ad34a24519e80059b8fc9c5ea4df2* | .{0,1000}4278e1122672d9c4029ec7c7f3a0e5180d7ad34a24519e80059b8fc9c5ea4df2.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25492 |
| 1106 | *42BDEFC0-0BAE-43DF-97BB-C805ABFBD078* | .{0,1000}42BDEFC0\-0BAE\-43DF\-97BB\-C805ABFBD078.{0,1000} | offensive_tool_keyword | SharpElevator | SharpElevator is a C# implementation of Elevator for UAC bypass | T1548.002 - T1548 | TA0004 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/eladshamir/SharpElevator | 1 | 0 | #GUIDproject | N/A | 10 | 1 | 51 | 12 | 2022-08-31T18:09:10Z | 2022-08-29T19:52:53Z | 25516 |
| 1107 | *42e10ec6f9a5276060bade151ccd929325daa8ac8910ee26de5e6eebe10f77aa* | .{0,1000}42e10ec6f9a5276060bade151ccd929325daa8ac8910ee26de5e6eebe10f77aa.{0,1000} | offensive_tool_keyword | Token-Impersonation | Make a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required) | T1134.001 - T1134.002 | TA0004 - TA0009 | N/A | N/A | Privilege Escalation | https://github.com/Leo4j/Token-Impersonation | 1 | 0 | #filehash | N/A | 8 | 1 | 7 | 3 | 2024-03-20T17:07:13Z | 2023-11-02T10:46:24Z | 25524 |
| 1108 | *4349B8A8-F17B-44D5-AE4D-21BE9C9D1573* | .{0,1000}4349B8A8\-F17B\-44D5\-AE4D\-21BE9C9D1573.{0,1000} | offensive_tool_keyword | PrivFu | PoCs for sensitive token privileges such SeDebugPrivilege | T1068 - T1134 - T1134.001 - T1078 - T1059 | TA0004 - TA0009 - TA0003 | N/A | N/A | Privilege Escalation | https://github.com/daem0nc0re/PrivFu | 1 | 0 | #GUIDproject | PrivilegedOperations | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 25549 |
| 1109 | *438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6* | .{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25571 |
| 1110 | *438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6* | .{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25572 |
| 1111 | *438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6* | .{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25573 |
| 1112 | *438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6* | .{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25574 |
| 1113 | *438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6* | .{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25575 |
| 1114 | *438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6* | .{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25576 |
| 1115 | *438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6* | .{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25577 |
| 1116 | *438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6* | .{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000} | offensive_tool_keyword | PEASS-ng | PEASS-ng - Privilege Escalation Awesome Scripts suite | T1098 | TA0004 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/peass-ng/PEASS-ng | 1 | 0 | #filehash | N/A | 10 | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 25578 |
| The file is too large to be shown. View Raw |