Files
mthcht-ThreatHunting-Keywords/Privilege_Escalation_category_detection.csv
mthcht 755048bf5e Mars and April 2025 update
very few additions and some corrections
2025-04-24 05:55:50 +02:00

1.2 MiB

1keywordmetadata_keyword_regexmetadata_keyword_typemetadata_toolmetadata_descriptionmetadata_tool_techniquesmetadata_tool_tacticsmetadata_malwares_namemetadata_groups_namemetadata_categorymetadata_linkmetadata_enable_endpoint_detectionmetadata_enable_proxy_detectionmetadata_tagsmetadata_commentmetadata_severity_scoremetadata_popularity_scoremetadata_github_starsmetadata_github_forksmetadata_github_updated_atmetadata_github_created_atmetadata_entry_id
2* "Sniffy boi sniffin"*.{0,1000}\s\"Sniffy\sboi\ssniffin\".{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script10#contentN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z15
3* $lse_find_opts *.{0,1000}\s\$lse_find_opts\s.{0,1000}offensive_tool_keywordlinux-smart-enumerationLinux enumeration tool for privilege escalation and discoveryT1087.004 - T1016 - T1548.001 - T1046TA0007 - TA0004 - TA0002N/AN/APrivilege Escalationhttps://github.com/diego-treitos/linux-smart-enumeration10#linuxN/A91035755842023-12-25T14:46:47Z2019-02-13T11:02:21Z20
4* /potato.local*.{0,1000}\s\/potato\.local.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10N/AN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z88
5* /s4uproxytarget:* /s4utransitiedservices:*.{0,1000}\s\/s4uproxytarget\:.{0,1000}\s\/s4utransitiedservices\:.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z97
6* = "KRBRELAYUP"*.{0,1000}\s\=\s\"KRBRELAYUP\".{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z140
7* = "NeverGonnaRunAroundAndDesertYou"*.{0,1000}\s\=\s\"NeverGonnaRunAroundAndDesertYou\".{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/cube0x0/CVE-2021-167510#contentN/A101018795822021-07-20T15:28:13Z2021-06-29T17:24:14Z141
8* ACEshark.py*.{0,1000}\sACEshark\.py.{0,1000}offensive_tool_keywordACEsharkuncover potential privilege escalation vectors by analyzing windows service configurations and Access Control EntriesT1058 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/t3l3machus/ACEshark10N/AN/A62109192025-01-15T07:01:48Z2024-12-28T10:42:29Z179
9* ADAPE.ps1*.{0,1000}\sADAPE\.ps1.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script10N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z198
10* addcomputer_LDAP_spn.py*.{0,1000}\saddcomputer_LDAP_spn\.py.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z211
11* addcomputer_with_spns.py *.{0,1000}\saddcomputer_with_spns\.py\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z212
12* adm2sys.py*.{0,1000}\sadm2sys\.py.{0,1000}offensive_tool_keywordPyExecThis is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses.T1134 - T1055 - T1548.002TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/OlivierLaflamme/PyExec10N/AN/A911172019-09-11T13:56:04Z2019-09-11T13:54:15Z230
13* audit AlwaysInstallElevated*.{0,1000}\saudit\sAlwaysInstallElevated.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z320
14* audit CachedGPPPassword*.{0,1000}\saudit\sCachedGPPPassword.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z321
15* audit DomainGPPPassword*.{0,1000}\saudit\sDomainGPPPassword.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z322
16* audit HijackablePaths*.{0,1000}\saudit\sHijackablePaths.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z323
17* audit McAfeeSitelistFiles*.{0,1000}\saudit\sMcAfeeSitelistFiles.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z324
18* audit ModifiableScheduledTask*.{0,1000}\saudit\sModifiableScheduledTask.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z325
19* audit ModifiableServiceBinaries*.{0,1000}\saudit\sModifiableServiceBinaries.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z326
20* audit ModifiableServiceRegistryKeys*.{0,1000}\saudit\sModifiableServiceRegistryKeys.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z327
21* audit ModifiableServices*.{0,1000}\saudit\sModifiableServices.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z328
22* audit ProcessDLLHijack*.{0,1000}\saudit\sProcessDLLHijack.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z329
23* audit RegistryAutoLogons*.{0,1000}\saudit\sRegistryAutoLogons.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z330
24* audit RegistryAutoruns*.{0,1000}\saudit\sRegistryAutoruns.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z331
25* audit TokenPrivileges*.{0,1000}\saudit\sTokenPrivileges.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z332
26* audit UnattendedInstallFiles*.{0,1000}\saudit\sUnattendedInstallFiles.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z333
27* audit UnquotedServicePath*.{0,1000}\saudit\sUnquotedServicePath.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z334
28* BadWindowsService.exe*.{0,1000}\sBadWindowsService\.exe.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService10N/AN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z370
29* Bat-Potato.bat*.{0,1000}\sBat\-Potato\.bat.{0,1000}offensive_tool_keywordBat-PotatoAutomating Juicy Potato Local Privilege Escalation CMD exploit for penetration testersT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/0x4xel/Bat-Potato10N/AN/A10142112022-12-13T20:19:51Z2022-12-12T20:50:22Z377
30* beRoot.exe*.{0,1000}\sbeRoot\.exe.{0,1000}offensive_tool_keywordBeRootPrivilege Escalation Project - Windows / Linux / Mac T1068 - T1055 - T1078 - T1548 - T1003TA0004N/AN/APrivilege Escalationhttps://github.com/AlessandroZ/BeRoot10#linuxN/A101025234592024-10-04T11:54:01Z2017-04-14T12:47:31Z383
31* beRoot.py*.{0,1000}\sbeRoot\.py.{0,1000}offensive_tool_keywordBeRootPrivilege Escalation Project - Windows / Linux / Mac T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007TA0004N/AN/APrivilege Escalationhttps://github.com/AlessandroZ/BeRoot10#linuxN/A101025234592024-10-04T11:54:01Z2017-04-14T12:47:31Z384
32* BITSInject.py*.{0,1000}\sBITSInject\.py.{0,1000}offensive_tool_keywordBITSInjectA one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM accountT1197TA0004N/AN/APrivilege Escalationhttps://github.com/SafeBreach-Labs/BITSInject10N/AN/A8199182019-08-24T22:02:12Z2017-07-03T12:39:38Z396
33* BITSJobPayloads.py*.{0,1000}\sBITSJobPayloads\.py.{0,1000}offensive_tool_keywordBITSInjectA one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM accountT1197TA0004N/AN/APrivilege Escalationhttps://github.com/SafeBreach-Labs/BITSInject10N/AN/A8199182019-08-24T22:02:12Z2017-07-03T12:39:38Z397
34* C:\temp\w.log*.{0,1000}\sC\:\\temp\\w\.log.{0,1000}offensive_tool_keywordSharpEfsPotatoLocal privilege escalation from SeImpersonatePrivilege using EfsRpc.T1548.002 - T1134.002TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/bugch3ck/SharpEfsPotato10N/AN/A104317462022-10-17T12:35:06Z2022-10-17T12:20:47Z520
35* Clone_Token /Process:* /Command:*.{0,1000}\sClone_Token\s\/Process\:.{0,1000}\s\/Command\:.{0,1000}offensive_tool_keywordTokenvatorA tool to elevate privilege with Windows TokensT1134 - T1078TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/0xbadjuju/Tokenvator10N/AN/AN/A1010382012023-10-06T13:17:05Z2017-12-08T01:29:11Z611
36* CMSFRottenPotato::*.{0,1000}\sCMSFRottenPotato\:\:.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10#contentN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z619
37* CoercedPotato.cpp*.{0,1000}\sCoercedPotato\.cpp.{0,1000}offensive_tool_keywordCoercedPotatoRDLLReflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilegeT1055 - T1134 - T1548TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/sokaRepo/CoercedPotatoRDLL10N/AN/A103204312023-11-23T18:58:41Z2023-11-23T13:22:38Z628
38* --config * --just-clean --cleaning-file *.{0,1000}\s\-\-config\s.{0,1000}\s\-\-just\-clean\s\-\-cleaning\-file\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z669
39* -dc-host * -spn * -impersonate *.{0,1000}\s\-dc\-host\s.{0,1000}\s\-spn\s.{0,1000}\s\-impersonate\s.{0,1000}offensive_tool_keywordPachinePython implementation for CVE-2021-42278 (Active Directory Privilege Escalation)T1068 - T1078 - T1059.006TA0003 - TA0004 - TA0002N/ABlack BastaPrivilege Escalationhttps://github.com/ly4k/Pachine10N/AN/A83275372022-01-13T12:35:19Z2021-12-13T23:15:05Z787
40* -dll add_user.dll -dir *.{0,1000}\s\-dll\sadd_user\.dll\s\-dir\s.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z865
41* -dll add_user.dll -printer *.{0,1000}\s\-dll\sadd_user\.dll\s\-printer\s.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z866
42* --exploit=DCOM*.{0,1000}\s\-\-exploit\=DCOM.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z1134
43* --exploit=DCOM*.{0,1000}\s\-\-exploit\=DCOM.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z1135
44* --exploit=EfsRpc*.{0,1000}\s\-\-exploit\=EfsRpc.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z1136
45* --exploit=PrintSpoofer*.{0,1000}\s\-\-exploit\=PrintSpoofer.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z1137
46* --exploit=WinRM*.{0,1000}\s\-\-exploit\=WinRM.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z1138
47* --ForceShadowCred*.{0,1000}\s\-\-ForceShadowCred.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z1213
48* Get-ServiceFromRegistry -Name Spooler*.{0,1000}\sGet\-ServiceFromRegistry\s\-Name\sSpooler.{0,1000}offensive_tool_keywordPrivescCheckPrivilege Escalation Enumeration Script for WindowsT1053 - T1088TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrivescCheck10N/AN/A101032304602025-03-05T14:44:17Z2020-01-16T12:28:10Z1330
49* gtfobin_update.py*.{0,1000}\sgtfobin_update\.py.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10N/AN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z1393
50* gtfonow.py*.{0,1000}\sgtfonow\.py.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10N/AN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z1394
51* -hashes lm:nt -gpo-id * -powershell *.{0,1000}\s\-hashes\slm\:nt\s\-gpo\-id\s.{0,1000}\s\-powershell\s.{0,1000}offensive_tool_keywordpyGPOAbusepython implementation of SharpGPOAbuseT1566.001 - T1059.006 - T1112TA0001 - TA0002N/AN/APrivilege Escalationhttps://github.com/Hackndo/pyGPOAbuse10N/AN/A85416482024-02-18T19:23:57Z2020-05-10T21:21:27Z1413
52* havoc_bof.py*.{0,1000}\shavoc_bof\.py.{0,1000}offensive_tool_keywordPoolPartyBofA beacon object file implementation of PoolParty Process Injection TechniqueT1055.011 - T1055 - T1620TA0005N/ABlack BastaPrivilege Escalationhttps://github.com/0xEr3bus/PoolPartyBof10N/AN/A104380442023-12-21T19:00:20Z2023-12-11T19:28:20Z1417
53* import LinpeasBaseBuilder*.{0,1000}\simport\sLinpeasBaseBuilder.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z1642
54* import LinpeasBuilder*.{0,1000}\simport\sLinpeasBuilder.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z1643
55* import PEASLoaded*.{0,1000}\simport\sPEASLoaded.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z1644
56* import PEASRecord*.{0,1000}\simport\sPEASRecord.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z1645
57* install autobloody*.{0,1000}\sinstall\sautobloody.{0,1000}offensive_tool_keywordautobloodyTool to automatically exploit Active Directory privilege escalation paths shown by BloodHoundT1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/AN/APrivilege Escalationhttps://github.com/CravateRouge/autobloody10#linuxN/A106545542024-11-14T13:07:54Z2022-09-07T13:34:30Z1676
58* Invoke-Nightmare*.{0,1000}\sInvoke\-Nightmare.{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/calebstewart/CVE-2021-167510N/AN/A101010492302021-07-05T08:54:06Z2021-07-01T23:45:58Z1748
59* JuicyPotatoNG*.{0,1000}\sJuicyPotatoNG.{0,1000}offensive_tool_keywordJuicyPotatoNGAnother Windows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AFoxKitten - APT33 - Volatile Cedar - SandwormPrivilege Escalationhttps://github.com/antonioCoco/JuicyPotatoNG10N/AN/A1098441012022-11-12T01:48:39Z2022-09-21T17:08:35Z1829
60* libpwn.c*.{0,1000}\slibpwn\.c.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10N/AN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z1950
61* libpwn.so*.{0,1000}\slibpwn\.so.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10N/AN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z1951
62* linpeas.sh *.{0,1000}\slinpeas\.sh\s.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10#linuxN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z1953
63* -linpeas=http://*.{0,1000}\s\-linpeas\=http\:\/\/.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z1955
64* -linpeas=http://127.0.0.1/linpeas.sh*.{0,1000}\s\-linpeas\=http\:\/\/127\.0\.0\.1\/linpeas\.sh.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z1956
65* MakeMeEnterpriseAdmin.ps1.{0,1000}\sMakeMeEnterpriseAdmin\.ps1offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z2112
66* --maketoken --username * --password * --domain *.{0,1000}\s\-\-maketoken\s\-\-username\s.{0,1000}\s\-\-password\s.{0,1000}\s\-\-domain\s.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z2113
67* -name .htpasswd*.{0,1000}\s\-name\s\.htpasswd.{0,1000}offensive_tool_keywordlinuxprivcheckersearch for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploitsT1210.001 - T1082 - T1088 - T1547.001TA0002 - TA0004 - TA0006 - TA0007 - TA0008N/AN/APrivilege Escalationhttps://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py10#linuxN/A71016455242022-01-31T10:32:08Z2016-04-19T13:31:46Z2243
68* namespace SharpPrintNightmare*.{0,1000}\snamespace\sSharpPrintNightmare.{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/cube0x0/CVE-2021-167510#contentN/A101018795822021-07-20T15:28:13Z2021-06-29T17:24:14Z2252
69* ouned_smbserver.py*.{0,1000}\souned_smbserver\.py.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z2465
70* -p 4444 -c powershell*.{0,1000}\s\-p\s4444\s\-c\spowershell.{0,1000}offensive_tool_keywordRustPotatoA Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privilegesT1134.001 - T1055.011TA0004N/AN/APrivilege Escalationhttps://github.com/emdnaia/RustPotato10N/AN/A101002025-01-06T18:10:17Z2025-01-06T19:44:57Z2483
71* -p 4644 -n mal*.{0,1000}\s\-p\s4644\s\-n\smal.{0,1000}offensive_tool_keywordGotatoGeneric impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.T1003.003 - T1056.002 - T1550.001 - T1090TA0005 - TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/iammaguire/Gotato10N/AN/A92112162021-06-07T21:19:58Z2021-06-05T22:32:48Z2484
72* -perm -2000 -o -perm -4000*.{0,1000}\s\-perm\s\-2000\s\-o\s\-perm\s\-4000.{0,1000}offensive_tool_keywordlinuxprivcheckersearch for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploitsT1210.001 - T1082 - T1088 - T1547.001TA0002 - TA0004 - TA0006 - TA0007 - TA0008N/AN/APrivilege Escalationhttps://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py10#linuxN/A71016455242022-01-31T10:32:08Z2016-04-19T13:31:46Z2583
73* PetitPotato.cpp*.{0,1000}\sPetitPotato\.cpp.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z2594
74* Powermad.ps1*.{0,1000}\sPowermad\.ps1.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z2651
75* printing the golden data, format inspired by Responder :D*.{0,1000}\sprinting\sthe\sgolden\sdata,\sformat\sinspired\sby\sResponder\s\:D.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z2669
76* privesc.ps1*.{0,1000}\sprivesc\.ps1.{0,1000}offensive_tool_keywordPrivescWindows PowerShell script that finds misconfiguration issues which can lead to privilege escalationT1068 - T1548 - T1082 - T1078TA0004N/AN/APrivilege Escalationhttps://github.com/enjoiz/Privesc10N/AN/A106595972024-12-01T15:24:41Z2015-11-19T13:22:01Z2673
77* Process spawned with stolen token!*.{0,1000}\sProcess\sspawned\swith\sstolen\stoken!.{0,1000}offensive_tool_keywordGotatoGeneric impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.T1003.003 - T1056.002 - T1550.001 - T1090TA0005 - TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/iammaguire/Gotato10N/AN/A92112162021-06-07T21:19:58Z2021-06-05T22:32:48Z2677
78* psgetsys.ps1*.{0,1000}\spsgetsys\.ps1.{0,1000}offensive_tool_keywordpsgetsystemgetsystem via parent process using ps1 & embeded c#T1134 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/decoder-it/psgetsystem10N/AN/A105406882023-10-26T07:13:08Z2018-02-02T11:28:22Z2694
79* rasman.exe*.{0,1000}\srasman\.exe.{0,1000}offensive_tool_keywordRasmanPotatousing RasMan service for privilege escalationT1548.002 - T1055.002 - T1055.001 TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/crisprss/RasmanPotato10N/AN/A104371532023-02-06T10:27:41Z2023-02-06T09:41:51Z2770
80* Remotely download Trojan files to *.{0,1000}\sRemotely\sdownload\sTrojan\sfiles\sto\s.{0,1000}offensive_tool_keywordTelemetryAbusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges.T1053 - T1547 - T1059TA0003 - TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/Imanfeng/Telemetry10N/AN/A92140132020-07-02T09:41:27Z2020-06-24T16:30:44Z2842
81* RemotePotato0.zip*.{0,1000}\sRemotePotato0\.zip.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z2849
82* -Report PrivescCheck_*.{0,1000}\s\-Report\sPrivescCheck_.{0,1000}offensive_tool_keywordPrivescCheckPrivilege Escalation Enumeration Script for WindowsT1053 - T1088TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrivescCheck10N/AN/A101032304602025-03-05T14:44:17Z2020-01-16T12:28:10Z2861
83* -Report PrivescCheck_*.{0,1000}\s\-Report\sPrivescCheck_.{0,1000}offensive_tool_keywordPrivescCheckPrivilege Escalation Enumeration Script for WindowsT1053 - T1088TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrivescCheck10N/AN/A101032304602025-03-05T14:44:17Z2020-01-16T12:28:10Z2862
84* --revshell*.{0,1000}\s\-\-revshell.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato10N/AN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z2885
85* RogueOxidResolver must be run remotely*.{0,1000}\sRogueOxidResolver\smust\sbe\srun\sremotely.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z2914
86* rwf.py *.{0,1000}\srwf\.py\s.{0,1000}offensive_tool_keywordVDRVulnerable driver research tool - result and exploit PoCsT1547.009 - T1210 - T1068 - T1055TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/TakahiroHaruyama/VDR10N/AN/A102192292023-11-01T00:06:55Z2023-10-23T08:34:44Z2955
87* -s 127.0.0.1 -e * -a connect -u ntlm*.{0,1000}\s\-s\s127\.0\.0\.1\s\-e\s.{0,1000}\s\-a\sconnect\s\-u\sntlm.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z2964
88* SharpEfsPotato*.{0,1000}\sSharpEfsPotato.{0,1000}offensive_tool_keywordSharpEfsPotatoLocal privilege escalation from SeImpersonatePrivilege using EfsRpc.T1548.002 - T1134.002TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/bugch3ck/SharpEfsPotato10N/AN/A104317462022-10-17T12:35:06Z2022-10-17T12:20:47Z3086
89* SharpElevator.exe*.{0,1000}\sSharpElevator\.exe.{0,1000}offensive_tool_keywordSharpElevatorSharpElevator is a C# implementation of Elevator for UAC bypassT1548.002 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/SharpElevator10N/AN/A10151122022-08-31T18:09:10Z2022-08-29T19:52:53Z3087
90* spawn C:\Windows\Temp\beacon.exe*.{0,1000}\sspawn\sC\:\\Windows\\Temp\\beacon\.exe.{0,1000}offensive_tool_keywordCoercedPotatoRDLLReflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilegeT1055 - T1134 - T1548TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/sokaRepo/CoercedPotatoRDLL10N/AN/A103204312023-11-23T18:58:41Z2023-11-23T13:22:38Z3300
91* spawn C:\Windows\Temp\loader.exe*.{0,1000}\sspawn\sC\:\\Windows\\Temp\\loader\.exe.{0,1000}offensive_tool_keywordCoercedPotatoRDLLReflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilegeT1055 - T1134 - T1548TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/sokaRepo/CoercedPotatoRDLL10N/AN/A103204312023-11-23T18:58:41Z2023-11-23T13:22:38Z3301
92* spawn -m adcs -d * -dc *.{0,1000}\sspawn\s\-m\sadcs\s\-d\s.{0,1000}\s\-dc\s.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z3302
93* spawn -m shadowcred -d *.{0,1000}\sspawn\s\-m\sshadowcred\s\-d\s.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z3303
94* --spoofppid --ppid *.{0,1000}\s\-\-spoofppid\s\-\-ppid\s.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z3316
95* SpoolFool.ps1*.{0,1000}\sSpoolFool\.ps1.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z3318
96* -Steal -ProcessID *.{0,1000}\s\-Steal\s\-ProcessID\s.{0,1000}offensive_tool_keywordToken-ImpersonationMake a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)T1134.001 - T1134.002TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/Leo4j/Token-Impersonation10N/AN/A81732024-03-20T17:07:13Z2023-11-02T10:46:24Z3404
97* steal_token /process:* /command:*.{0,1000}\ssteal_token\s\/process\:.{0,1000}\s\/command\:.{0,1000}offensive_tool_keywordTokenvatorA tool to elevate privilege with Windows TokensT1134 - T1078TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/0xbadjuju/Tokenvator10N/AN/AN/A1010382012023-10-06T13:17:05Z2017-12-08T01:29:11Z3405
98* Sweetpotato.exe*.{0,1000}\sSweetpotato\.exe.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z3437
99* -t BindShell -p *pwned\pipe\spoolss*.{0,1000}\s\-t\sBindShell\s\-p\s.{0,1000}pwned\\pipe\\spoolss.{0,1000}offensive_tool_keywordMultiPotatoget SYSTEM via SeImpersonate privilegesT1548.002 - T1134.002TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/S3cur3Th1sSh1t/MultiPotato10N/AN/A106518922021-11-20T16:20:23Z2021-11-19T15:50:55Z3450
100* -t CreateProcessAsUserW -p *pwned\pipe\spoolss* -e *.exe*.{0,1000}\s\-t\sCreateProcessAsUserW\s\-p\s.{0,1000}pwned\\pipe\\spoolss.{0,1000}\s\-e\s.{0,1000}\.exe.{0,1000}offensive_tool_keywordMultiPotatoget SYSTEM via SeImpersonate privilegesT1548.002 - T1134.002TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/S3cur3Th1sSh1t/MultiPotato10N/AN/A106518922021-11-20T16:20:23Z2021-11-19T15:50:55Z3452
101* test_privesc.py*.{0,1000}\stest_privesc\.py.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10N/AN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z3504
102* Token-Impersonation.ps1*.{0,1000}\sToken\-Impersonation\.ps1.{0,1000}offensive_tool_keywordToken-ImpersonationMake a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)T1134.001 - T1134.002TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/Leo4j/Token-Impersonation10N/AN/A81732024-03-20T17:07:13Z2023-11-02T10:46:24Z3534
103* tokenvator *.{0,1000}\stokenvator\s.{0,1000}offensive_tool_keywordTokenvatorA tool to elevate privilege with Windows TokensT1134 - T1078TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/0xbadjuju/Tokenvator10N/AN/AN/A1010382012023-10-06T13:17:05Z2017-12-08T01:29:11Z3538
104* UAC-TokenMagic.ps1*.{0,1000}\sUAC\-TokenMagic\.ps1.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z3606
105* WinPEAS - Windows local Privilege Escalation Awesome Script*.{0,1000}\sWinPEAS\s\-\sWindows\slocal\sPrivilege\sEscalation\sAwesome\sScript.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z3727
106* winPEAS.ps1*.{0,1000}\swinPEAS\.ps1.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z3729
107* You need to have an elevated context to dump other users' Kerberos tickets :(*.{0,1000}\sYou\sneed\sto\shave\san\selevated\scontext\sto\sdump\sother\susers\'\sKerberos\stickets\s\:\(.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z3785
108*!! >> if you did this while in the root shell, the terminal will be messed up << !!*.{0,1000}!!\s\>\>\sif\syou\sdid\sthis\swhile\sin\sthe\sroot\sshell,\sthe\sterminal\swill\sbe\smessed\sup\s\<\<\s!!.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z3795
109*"localadmin123!"*.{0,1000}\"localadmin123!\".{0,1000}offensive_tool_keywordLocalAdminSharp.NET executable to use when dealing with privilege escalation on Windows to gain local administrator accessT1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004TA0004N/AN/APrivilege Escalationhttps://github.com/notdodo/LocalAdminSharp10N/AN/A102157172022-11-01T17:45:43Z2022-01-01T10:35:09Z3851
110*"UACBypassedService"*.{0,1000}\"UACBypassedService\".{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z3878
111*#include "RogueOxidResolver.h*.{0,1000}\#include\s\"RogueOxidResolver\.h.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z3931
112*$DriverName = "Totally Not Malicious"*.{0,1000}\$DriverName\s\=\s\"Totally\sNot\sMalicious\".{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/calebstewart/CVE-2021-167510#contentN/A101010492302021-07-05T08:54:06Z2021-07-01T23:45:58Z3955
113*$Kerberoast*.{0,1000}\$Kerberoast.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script10N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z3995
114*$LolDriversVulnerable*.{0,1000}\$LolDriversVulnerable.{0,1000}offensive_tool_keywordPrivescCheckPrivilege Escalation Enumeration Script for WindowsT1053 - T1088TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrivescCheck10N/AN/A101032304602025-03-05T14:44:17Z2020-01-16T12:28:10Z3997
115*$StealToken*.{0,1000}\$StealToken.{0,1000}offensive_tool_keywordToken-ImpersonationMake a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)T1134.001 - T1134.002TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/Leo4j/Token-Impersonation10N/AN/A81732024-03-20T17:07:13Z2023-11-02T10:46:24Z4019
116*(msds-supportedencryptiontypes=0)(msds-supportedencryptiontypes:1.2.840.113556.1.4.803:=4)))*.{0,1000}\(msds\-supportedencryptiontypes\=0\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.803\:\=4\)\)\).{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z4083
117*./lse.sh*.{0,1000}\.\/lse\.sh.{0,1000}offensive_tool_keywordlinux-smart-enumerationLinux enumeration tool for privilege escalation and discoveryT1087.004 - T1016 - T1548.001 - T1046TA0007 - TA0004 - TA0002N/AN/APrivilege Escalationhttps://github.com/diego-treitos/linux-smart-enumeration10#linuxN/A91035755842023-12-25T14:46:47Z2019-02-13T11:02:21Z4165
118*./pachine.py*.{0,1000}\.\/pachine\.py.{0,1000}offensive_tool_keywordPachinePython implementation for CVE-2021-42278 (Active Directory Privilege Escalation)T1068 - T1078 - T1059.006TA0003 - TA0004 - TA0002N/ABlack BastaPrivilege Escalationhttps://github.com/ly4k/Pachine10#linuxN/A83275372022-01-13T12:35:19Z2021-12-13T23:15:05Z4179
119*./peass.rb*.{0,1000}\.\/peass\.rb.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#linuxN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z4182
120*./rwf.py*.{0,1000}\.\/rwf\.py.{0,1000}offensive_tool_keywordVDRVulnerable driver research tool - result and exploit PoCsT1547.009 - T1210 - T1068 - T1055TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/TakahiroHaruyama/VDR10#linuxN/A102192292023-11-01T00:06:55Z2023-10-23T08:34:44Z4196
121*.ACEshark.log*.{0,1000}\.ACEshark\.log.{0,1000}offensive_tool_keywordACEsharkuncover potential privilege escalation vectors by analyzing windows service configurations and Access Control EntriesT1058 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/t3l3machus/ACEshark10#logfileN/A62109192025-01-15T07:01:48Z2024-12-28T10:42:29Z4238
122*.exe -lolbas log*.{0,1000}\.exe\s\s\-lolbas\slog.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z4324
123*.exe /i /s cmd *.{0,1000}\.exe\s\/i\s\/s\scmd\s.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4336
124*.exe /i /s cmd.exe*.{0,1000}\.exe\s\/i\s\/s\scmd\.exe.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4337
125*.exe /i /s powershell*.{0,1000}\.exe\s\/i\s\/s\spowershell.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4338
126*.exe /i /s pwsh*.{0,1000}\.exe\s\/i\s\/s\spwsh.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4339
127*.exe /s /i cmd.exe*.{0,1000}\.exe\s\/s\s\/i\scmd\.exe.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4344
128*.exe /s /i powershell*.{0,1000}\.exe\s\/s\s\/i\spowershell.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4345
129*.exe /s /i pwsh*.{0,1000}\.exe\s\/s\s\/i\spwsh.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4346
130*.exe 3 cmd*.{0,1000}\.exe\s3\scmd.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z4349
131*.exe --adcs * --remote *.{0,1000}\.exe\s\-\-adcs\s.{0,1000}\s\-\-remote\s.{0,1000}offensive_tool_keywordADCSPwnA tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate serviceT1550.002 - T1078.003 - T1110.003 - T1649TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/bats3c/ADCSPwn10N/AN/A1098381272023-03-20T20:30:40Z2021-07-30T15:04:41Z4374
132*.exe AlwaysInstallElevated*.{0,1000}\.exe\sAlwaysInstallElevated.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4375
133*.exe audit ModifiableServices*.{0,1000}\.exe\saudit\sModifiableServices.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4388
134*.exe CachedGPPPassword*.{0,1000}\.exe\sCachedGPPPassword.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4399
135*.exe -cmd "cmd /c whoami"*.{0,1000}\.exe\s\-cmd\s\"cmd\s\/c\swhoami\".{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato10N/AN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z4405
136*.exe -d 1 -c cmd.exe*.{0,1000}\.exe\s\-d\s1\s\-c\scmd\.exe.{0,1000}offensive_tool_keywordprintspooferAbusing impersonation privileges through the Printer BugT1134 - T1003 - T1055TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/PrintSpoofer10N/AN/A101019713422020-09-10T17:49:41Z2020-04-28T08:26:29Z4420
137*.exe -d 3 -c *powershell -ep bypass*.{0,1000}\.exe\s\-d\s3\s\-c\s.{0,1000}powershell\s\-ep\sbypass.{0,1000}offensive_tool_keywordprintspooferAbusing Impersonation Privileges on Windows 10 and Server 2019T1548.002 - T1055.001 - T1055.002TA0005 - TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrintSpoofer10N/AN/A101019713422020-09-10T17:49:41Z2020-04-28T08:26:29Z4421
138*.exe DomainGPPPassword*.{0,1000}\.exe\sDomainGPPPassword.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4426
139*.exe --exec --pid * --prog *cmd.exe*.{0,1000}\.exe\s\-\-exec\s\-\-pid\s.{0,1000}\s\-\-prog\s.{0,1000}cmd\.exe.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z4441
140*.exe HijackablePaths*.{0,1000}\.exe\sHijackablePaths.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4467
141*.exe -i -c powershell -e netlogon*.{0,1000}\.exe\s\-i\s\-c\spowershell\s\-e\snetlogon.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z4469
142*.exe -i -c powershell.exe*.{0,1000}\.exe\s\-i\s\-c\spowershell\.exe.{0,1000}offensive_tool_keywordprintspooferAbusing impersonation privileges through the Printer BugT1134 - T1003 - T1055TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/PrintSpoofer10N/AN/A101019713422020-09-10T17:49:41Z2020-04-28T08:26:29Z4470
143*.exe -i -s cmd *.{0,1000}\.exe\s\-i\s\-s\scmd\s.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4471
144*.exe -i -s cmd *.{0,1000}\.exe\s\-i\s\-s\scmd\s.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4472
145*.exe -i -s cmd.exe*.{0,1000}\.exe\s\-i\s\-s\scmd\.exe.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4473
146*.exe -i -s powershell*.{0,1000}\.exe\s\-i\s\-s\spowershell.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4474
147*.exe -i -s pwsh*.{0,1000}\.exe\s\-i\s\-s\spwsh.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4475
148*.exe --impersonate --pid *.{0,1000}\.exe\s\-\-impersonate\s\-\-pid\s.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z4476
149*.exe krbscm -c *cmd.exe*.{0,1000}\.exe\skrbscm\s\-c\s.{0,1000}cmd\.exe.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z4511
150*.exe -l * -c {B91D5831-B1BD-4608-8198-D72E155020F7}*.{0,1000}\.exe\s\-l\s.{0,1000}\s\-c\s\{B91D5831\-B1BD\-4608\-8198\-D72E155020F7\}.{0,1000}offensive_tool_keywordJuicyPotatoNGAnother Windows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AFoxKitten - APT33 - Volatile Cedar - SandwormPrivilege Escalationhttps://github.com/antonioCoco/JuicyPotatoNG10N/AN/A1098441012022-11-12T01:48:39Z2022-09-21T17:08:35Z4513
151*.exe -l * -c {F7FD3FD6-9994-452D-8DA7-9A8FD87AEEF4} -a*.{0,1000}\.exe\s\-l\s.{0,1000}\s\-c\s\{F7FD3FD6\-9994\-452D\-8DA7\-9A8FD87AEEF4\}\s\-a.{0,1000}offensive_tool_keywordJuicyPotatoNGAnother Windows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AFoxKitten - APT33 - Volatile Cedar - SandwormPrivilege Escalationhttps://github.com/antonioCoco/JuicyPotatoNG10N/AN/A1098441012022-11-12T01:48:39Z2022-09-21T17:08:35Z4514
152*.exe -linpeas=*.{0,1000}\.exe\s\-linpeas\=.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z4517
153*.exe -lolbas*.{0,1000}\.exe\s\-lolbas.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z4524
154*.exe -m exec -c "whoami /priv*.{0,1000}\.exe\s\-m\sexec\s\-c\s\"whoami\s\/priv.{0,1000}offensive_tool_keywordPrivFuexecute process as NT SERVICE\TrustedInstaller group accountT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/ATrustExec1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z4525
155*.exe -m exec -s -e S-1-5-20*.{0,1000}\.exe\s\-m\sexec\s\-s\s\-e\sS\-1\-5\-20.{0,1000}offensive_tool_keywordPrivFuexecute process as NT SERVICE\TrustedInstaller group accountT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/ATrustExec1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z4526
156*.exe -m find -r tcb*.{0,1000}\.exe\s\-m\sfind\s\-r\stcb.{0,1000}offensive_tool_keywordPrivFumanage user right without secpol.mscT1059 - T1078TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AUserRightsUtil1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z4527
157*.exe -m sid -l -s S-1-5-18*.{0,1000}\.exe\s\-m\ssid\s\-l\s\-s\sS\-1\-5\-18.{0,1000}offensive_tool_keywordPrivFuexecute process as NT SERVICE\TrustedInstaller group accountT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/ATrustExec1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z4528
158*.exe McAfeeSitelistFiles*.{0,1000}\.exe\sMcAfeeSitelistFiles.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4535
159*.exe ModifiableScheduledTask*.{0,1000}\.exe\sModifiableScheduledTask.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4538
160*.exe ModifiableServiceBinaries*.{0,1000}\.exe\sModifiableServiceBinaries.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4539
161*.exe ModifiableServiceRegistryKeys*.{0,1000}\.exe\sModifiableServiceRegistryKeys.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4540
162*.exe ModifiableServices*.{0,1000}\.exe\sModifiableServices.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4541
163*.exe ProcessDLLHijack*.{0,1000}\.exe\sProcessDLLHijack.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4573
164*.exe rbcd -m * -p * -c *cmd.exe*.{0,1000}\.exe\srbcd\s\-m\s.{0,1000}\s\-p\s.{0,1000}\s\-c\s.{0,1000}cmd\.exe.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z4583
165*.exe RegistryAutoLogons*.{0,1000}\.exe\sRegistryAutoLogons.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4585
166*.exe RegistryAutoruns*.{0,1000}\.exe\sRegistryAutoruns.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4586
167*.exe relay -Domain * -CreateNewComputerAccount *.{0,1000}\.exe\srelay\s\-Domain\s.{0,1000}\s\-CreateNewComputerAccount\s.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z4587
168*.exe -s -i cmd.exe*.{0,1000}\.exe\s\-s\s\-i\scmd\.exe.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4591
169*.exe -s -i powershell*.{0,1000}\.exe\s\-s\s\-i\spowershell.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4592
170*.exe -s -i pwsh*.{0,1000}\.exe\s\-s\s\-i\spwsh.{0,1000}greyware_tool_keywordpsexecprivilege escalation to local system with psexecT1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002TA0002 - TA0004 - TA0008 - TA0011N/ATurla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - DispossessorPrivilege Escalationhttps://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A4593
171*.exe shadowcred -c * -f*.{0,1000}\.exe\sshadowcred\s\-c\s.{0,1000}\s\-f.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z4609
172*.exe TokenPrivileges*.{0,1000}\.exe\sTokenPrivileges.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4630
173*.exe -uac.{0,1000}\.exe\s\-uacoffensive_tool_keywordelevationstationelevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternativeT1548.002 - T1055 - T1574.002 - T1078.003TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/g3tsyst3m/elevationstation10N/AN/AN/A4368452023-11-02T23:52:51Z2023-06-10T03:30:59Z4636
174*.exe UnattendedInstallFiles*.{0,1000}\.exe\sUnattendedInstallFiles.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4637
175*.exe UnquotedServicePath*.{0,1000}\.exe\sUnquotedServicePath.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z4638
176*.ps1 -GPP -PView -Kerberoast*.{0,1000}\.ps1\s\-GPP\s\-PView\s\-Kerberoast.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script10N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z4761
177*.ps1 -PrivEsc*.{0,1000}\.ps1\s\-PrivEsc.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script10N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z4763
178*.py * --coerce-to *.{0,1000}\.py\s.{0,1000}\s\-\-coerce\-to\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z4795
179*.py * --just-coerce *.{0,1000}\.py\s.{0,1000}\s\-\-just\-coerce\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z4798
180*.py -t ldap://* --no-wcf-server --escalate-user *.{0,1000}\.py\s\-t\sldap\:\/\/.{0,1000}\s\-\-no\-wcf\-server\s\-\-escalate\-user\s.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z4843
181*.server_DoElevationRequest((Get-NtProcess -ProcessId $pid)*"cmd.exe"*C:\"*.{0,1000}\.server_DoElevationRequest\(\(Get\-NtProcess\s\-ProcessId\s\$pid\).{0,1000}\"cmd\.exe\".{0,1000}C\:\\\".{0,1000}greyware_tool_keywordsudosudo on windows allowing privilege escalationT1068 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://www.tiraniddo.dev/2024/02/sudo-on-windows-quick-rundown.html10#linuxN/A78N/AN/AN/AN/A4884
182*.sh *--checksec*.{0,1000}\.sh\s.{0,1000}\-\-checksec.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z4886
183*.sh *cvelist-file:*.{0,1000}\.sh\s.{0,1000}cvelist\-file\:.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z4887
184*/.ACEshark*.{0,1000}\/\.ACEshark.{0,1000}offensive_tool_keywordACEsharkuncover potential privilege escalation vectors by analyzing windows service configurations and Access Control EntriesT1058 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/t3l3machus/ACEshark10N/AN/A62109192025-01-15T07:01:48Z2024-12-28T10:42:29Z5001
185*/ACE_Get-KerberosTicketCache.ps1*.{0,1000}\/ACE_Get\-KerberosTicketCache\.ps1.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato11N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z5108
186*/ACEshark.git*.{0,1000}\/ACEshark\.git.{0,1000}offensive_tool_keywordACEsharkuncover potential privilege escalation vectors by analyzing windows service configurations and Access Control EntriesT1058 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/t3l3machus/ACEshark11N/AN/A62109192025-01-15T07:01:48Z2024-12-28T10:42:29Z5111
187*/ACEshark.py*.{0,1000}\/ACEshark\.py.{0,1000}offensive_tool_keywordACEsharkuncover potential privilege escalation vectors by analyzing windows service configurations and Access Control EntriesT1058 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/t3l3machus/ACEshark11N/AN/A62109192025-01-15T07:01:48Z2024-12-28T10:42:29Z5112
188*/ADAPE.ps1*.{0,1000}\/ADAPE\.ps1.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script11N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z5132
189*/ADAPE-Script.git*.{0,1000}\/ADAPE\-Script\.git.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script11N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z5133
190*/ADCSPwn.git*.{0,1000}\/ADCSPwn\.git.{0,1000}offensive_tool_keywordADCSPwnA tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate serviceT1550.002 - T1078.003 - T1110.003 - T1649TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/bats3c/ADCSPwn11N/AN/A1098381272023-03-20T20:30:40Z2021-07-30T15:04:41Z5163
191*/addcomputer_LDAP_spn.py*.{0,1000}\/addcomputer_LDAP_spn\.py.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned11N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z5170
192*/addcomputer_with_spns.py*.{0,1000}\/addcomputer_with_spns\.py.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned11N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z5171
193*/adm2sys.py*.{0,1000}\/adm2sys\.py.{0,1000}offensive_tool_keywordPyExecThis is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses.T1134 - T1055 - T1548.002TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/OlivierLaflamme/PyExec11N/AN/A911172019-09-11T13:56:04Z2019-09-11T13:54:15Z5204
194*/Admin2Sys.git*.{0,1000}\/Admin2Sys\.git.{0,1000}offensive_tool_keywordAdmin2SysAdmin2Sys it's a C++ malware to escalate privileges from Administrator account to NT AUTORITY SYSTEMT1055.002 - T1078.003 - T1068TA0002 - TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/S12cybersecurity/Admin2Sys11N/AN/A10154192023-05-01T19:32:41Z2023-05-01T18:50:51Z5207
195*/autobloody.git*.{0,1000}\/autobloody\.git.{0,1000}offensive_tool_keywordautobloodyTool to automatically exploit Active Directory privilege escalation paths shown by BloodHoundT1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/AN/APrivilege Escalationhttps://github.com/CravateRouge/autobloody11#linuxN/A106545542024-11-14T13:07:54Z2022-09-07T13:34:30Z5473
196*/autobloody/archive*.{0,1000}\/autobloody\/archive.{0,1000}offensive_tool_keywordautobloodyTool to automatically exploit Active Directory privilege escalation paths shown by BloodHoundT1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/AN/APrivilege Escalationhttps://github.com/CravateRouge/autobloody11#linuxN/A106545542024-11-14T13:07:54Z2022-09-07T13:34:30Z5474
197*/BackgroundShell.exe*.{0,1000}\/BackgroundShell\.exe.{0,1000}offensive_tool_keywordPrivFuSeTcbPrivilege exploitationT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/11N/APrivFu\PowerOfTcb1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z5532
198*/BackupOperatorToDA.git*.{0,1000}\/BackupOperatorToDA\.git.{0,1000}offensive_tool_keywordBackupOperatorToDAFrom an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain ControllerT1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003TA0005 - TA0001 - TA0003N/AN/APrivilege Escalationhttps://github.com/mpgn/BackupOperatorToDA11N/AN/A105421532025-01-04T14:16:46Z2022-02-15T20:51:46Z5544
199*/BadPotato.exe*.{0,1000}\/BadPotato\.exe.{0,1000}offensive_tool_keywordBadPotatoWindows Privilege Escalation Exploit BadPotatoT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareEarth LuscaPrivilege Escalationhttps://github.com/BeichenDream/BadPotato11N/AN/A1098361362020-05-10T15:42:21Z2020-05-10T10:01:20Z5551
200*/BadPotato.git*.{0,1000}\/BadPotato\.git.{0,1000}offensive_tool_keywordBadPotatoWindows Privilege Escalation Exploit BadPotatoT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareEarth LuscaPrivilege Escalationhttps://github.com/BeichenDream/BadPotato11N/AN/A1098361362020-05-10T15:42:21Z2020-05-10T10:01:20Z5552
201*/BadWindowsService.exe*.{0,1000}\/BadWindowsService\.exe.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService11N/AN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z5559
202*/BadWindowsService.git*.{0,1000}\/BadWindowsService\.git.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService11N/AN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z5560
203*/Bat-Potato.bat*.{0,1000}\/Bat\-Potato\.bat.{0,1000}offensive_tool_keywordBat-PotatoAutomating Juicy Potato Local Privilege Escalation CMD exploit for penetration testersT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/0x4xel/Bat-Potato11N/AN/A10142112022-12-13T20:19:51Z2022-12-12T20:50:22Z5574
204*/Bat-Potato.git*.{0,1000}\/Bat\-Potato\.git.{0,1000}offensive_tool_keywordBat-PotatoAutomating Juicy Potato Local Privilege Escalation CMD exploit for penetration testersT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/0x4xel/Bat-Potato11N/AN/A10142112022-12-13T20:19:51Z2022-12-12T20:50:22Z5575
205*/beRoot.exe*.{0,1000}\/beRoot\.exe.{0,1000}offensive_tool_keywordBeRootPrivilege Escalation Project - Windows / Linux / Mac T1068 - T1055 - T1078 - T1548 - T1003TA0004N/AN/APrivilege Escalationhttps://github.com/AlessandroZ/BeRoot11#linuxN/A101025234592024-10-04T11:54:01Z2017-04-14T12:47:31Z5599
206*/BeRoot.git*.{0,1000}\/BeRoot\.git.{0,1000}offensive_tool_keywordBeRootPrivilege Escalation Project - Windows / Linux / Mac T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007TA0004N/AN/APrivilege Escalationhttps://github.com/AlessandroZ/BeRoot11#linuxN/A101025234592024-10-04T11:54:01Z2017-04-14T12:47:31Z5600
207*/beRoot.py*.{0,1000}\/beRoot\.py.{0,1000}offensive_tool_keywordBeRootPrivilege Escalation Project - Windows / Linux / Mac T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007TA0004N/AN/APrivilege Escalationhttps://github.com/AlessandroZ/BeRoot11#linuxN/A101025234592024-10-04T11:54:01Z2017-04-14T12:47:31Z5601
208*/beRoot.zip*.{0,1000}\/beRoot\.zip.{0,1000}offensive_tool_keywordBeRootPrivilege Escalation Project - Windows / Linux / Mac T1068 - T1055 - T1078 - T1548 - T1003TA0004N/AN/APrivilege Escalationhttps://github.com/AlessandroZ/BeRoot10#linuxN/A101025234592024-10-04T11:54:01Z2017-04-14T12:47:31Z5603
209*/bin-sploits/*.zip*.{0,1000}\/bin\-sploits\/.{0,1000}\.zip.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z5670
210*/BITSInject.git*.{0,1000}\/BITSInject\.git.{0,1000}offensive_tool_keywordBITSInjectA one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM accountT1197TA0004N/AN/APrivilege Escalationhttps://github.com/SafeBreach-Labs/BITSInject11N/AN/A8199182019-08-24T22:02:12Z2017-07-03T12:39:38Z5679
211*/BITSInject.py*.{0,1000}\/BITSInject\.py.{0,1000}offensive_tool_keywordBITSInjectA one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM accountT1197TA0004N/AN/APrivilege Escalationhttps://github.com/SafeBreach-Labs/BITSInject11N/AN/A8199182019-08-24T22:02:12Z2017-07-03T12:39:38Z5680
212*/BITSJobPayloads.py*.{0,1000}\/BITSJobPayloads\.py.{0,1000}offensive_tool_keywordBITSInjectA one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM accountT1197TA0004N/AN/APrivilege Escalationhttps://github.com/SafeBreach-Labs/BITSInject11N/AN/A8199182019-08-24T22:02:12Z2017-07-03T12:39:38Z5681
213*/bloodyAD.git*.{0,1000}\/bloodyAD\.git.{0,1000}offensive_tool_keywordbloodyADBloodyAD is an Active Directory Privilege Escalation FrameworkT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AN/APrivilege Escalationhttps://github.com/CravateRouge/bloodyAD11N/AN/A101015901452025-04-10T10:47:16Z2021-10-11T15:07:26Z5726
214*/clown-newuser.c*.{0,1000}\/clown\-newuser\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z6096
215*/CoercedPotato.cpp*.{0,1000}\/CoercedPotato\.cpp.{0,1000}offensive_tool_keywordCoercedPotatoRDLLReflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilegeT1055 - T1134 - T1548TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/sokaRepo/CoercedPotatoRDLL11N/AN/A103204312023-11-23T18:58:41Z2023-11-23T13:22:38Z6139
216*/CoercedPotato.git*.{0,1000}\/CoercedPotato\.git.{0,1000}offensive_tool_keywordCoercedPotatoCoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.T1548.002 - T1134.002TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Prepouce/CoercedPotato11N/AN/A104366662024-08-26T08:09:00Z2023-09-11T19:04:29Z6140
217*/CoercedPotatoRDLL.git*.{0,1000}\/CoercedPotatoRDLL\.git.{0,1000}offensive_tool_keywordCoercedPotatoRDLLReflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilegeT1055 - T1134 - T1548TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/sokaRepo/CoercedPotatoRDLL11N/AN/A103204312023-11-23T18:58:41Z2023-11-23T13:22:38Z6141
218*/Crassus.git*.{0,1000}\/Crassus\.git.{0,1000}offensive_tool_keywordCrassusCrassus Windows privilege escalation discovery toolT1068 - T1003 - T1003.003 - T1046TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/vu-ls/Crassus11N/AN/A106571592024-11-08T14:11:39Z2023-01-12T21:01:52Z6226
219*/Crassus-main*.{0,1000}\/Crassus\-main.{0,1000}offensive_tool_keywordCrassusCrassus Windows privilege escalation discovery toolT1068 - T1003 - T1003.003 - T1046TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/vu-ls/Crassus11N/AN/A106571592024-11-08T14:11:39Z2023-01-12T21:01:52Z6227
220*/CVE*/chocobo_root*.{0,1000}\/CVE.{0,1000}\/chocobo_root.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z6349
221*/CVE-2009-2698/katon.c*.{0,1000}\/CVE\-2009\-2698\/katon\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z6353
222*/CVE-2021-1675.git*.{0,1000}\/CVE\-2021\-1675\.git.{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/cube0x0/CVE-2021-167511N/AN/A101018795822021-07-20T15:28:13Z2021-06-29T17:24:14Z6360
223*/CVE-2024-1086.git*.{0,1000}\/CVE\-2024\-1086\.git.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108611#linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z6377
224*/CVE-2024-21338.git*.{0,1000}\/CVE\-2024\-21338\.git.{0,1000}offensive_tool_keywordPOCLocal Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.T1055.011 - T1548.002TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/hakaioffsec/CVE-2024-2133811N/AN/A93292602024-04-16T21:00:14Z2024-04-13T05:53:02Z6378
225*/CVE-2024-49138-POC.git*.{0,1000}\/CVE\-2024\-49138\-POC\.git.{0,1000}offensive_tool_keywordPOCWindows Privilege escalation POC exploitation for CVE-2024-49138T1068 - T1058 - T1203TA0004N/AN/APrivilege Escalationhttps://github.com/emdnaia/CVE-2024-49138-POC11N/AN/A91102025-01-15T01:01:21Z2025-01-15T02:11:49Z6380
226*/DavRelayUp.git*.{0,1000}\/DavRelayUp\.git.{0,1000}offensive_tool_keywordDavRelayUpDavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforcedT1078 - T1078.004 - T1068TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/ShorSec/DavRelayUp11N/AN/A96542812023-06-05T09:17:06Z2023-06-05T07:49:39Z6441
227*/DavRelayUp/*.{0,1000}\/DavRelayUp\/.{0,1000}offensive_tool_keywordDavRelayUpDavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforcedT1078 - T1078.004 - T1068TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/ShorSec/DavRelayUp11N/AN/A96542812023-06-05T09:17:06Z2023-06-05T07:49:39Z6442
228*/dazzleUP.git*.{0,1000}\/dazzleUP\.git.{0,1000}offensive_tool_keyworddazzleUPA tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems.T1068 - T1088 - T1210 - T1210.002TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/hlldz/dazzleUP11N/AN/A95490692020-07-23T08:48:43Z2020-07-21T21:06:46Z6444
229*/DCOMPotato.git*.{0,1000}\/DCOMPotato\.git.{0,1000}offensive_tool_keywordDCOMPotatoService DCOM Object and SeImpersonatePrivilege abuse.T1548.002 - T1134.002TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/zcgonvh/DCOMPotato11N/AN/A104356482022-12-09T01:57:53Z2022-12-08T14:56:13Z6460
230*/DeadPotato.git*.{0,1000}\/DeadPotato\.git.{0,1000}offensive_tool_keywordDeadPotatoDeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privilegesT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011N/AN/APrivilege Escalationhttps://github.com/lypd0/DeadPotato11N/AN/A104382452024-08-17T06:08:29Z2024-07-31T01:08:30Z6482
231*/DesktopShell.exe*.{0,1000}\/DesktopShell\.exe.{0,1000}offensive_tool_keywordPrivFuSeTcbPrivilege exploitationT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/11N/APrivFu\PowerOfTcb1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z6548
232*/DirCreate2System.git*.{0,1000}\/DirCreate2System\.git.{0,1000}offensive_tool_keywordDirCreate2SystemWeaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error ReportingT1068 - T1059.001 - T1070.004TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/binderlabs/DirCreate2System11N/AN/A84357382022-12-19T17:00:43Z2022-12-15T03:49:55Z6584
233*/DirCreate2System.git*.{0,1000}\/DirCreate2System\.git.{0,1000}offensive_tool_keywordDirCreate2SystemWeaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error ReportingT1068 - T1059.001 - T1070.004TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/binderlabs/DirCreate2System11N/AN/A84357382022-12-19T17:00:43Z2022-12-15T03:49:55Z6585
234*/DirtyCLR.git*.{0,1000}\/DirtyCLR\.git.{0,1000}offensive_tool_keywordDirtyCLRAn App Domain Manager Injection DLL PoCT1055.001 - T1546.016 - T1055.013TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/ipSlav/DirtyCLR11N/AN/A72170192023-12-14T21:22:12Z2023-12-11T11:29:36Z6592
235*/dirtypipez.c*.{0,1000}\/dirtypipez\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z6596
236*/dirtypipez.c*.{0,1000}\/dirtypipez\.c.{0,1000}offensive_tool_keywordPOCexploit the Linux Dirty Pipe vulnerabilityT1068 - T1078.003 - T1071.004 - T1072 - T1105TA0004 - TA0006?N/AN/APrivilege Escalationhttps://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits11#linuxN/A1065951482023-05-20T05:55:45Z2022-03-12T20:57:24Z6599
237*/download/linpeas.sh*.{0,1000}\/download\/linpeas\.sh.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z6752
238*/echoac-poc.git*.{0,1000}\/echoac\-poc\.git.{0,1000}offensive_tool_keywordechoac-pocpoc stealing the Kernel's KPROCESS/EPROCESS block and writing it to a newly spawned shell to elevate its privileges to the highest possible - nt authority\systemT1068 - T1203 - T1059.003TA0002 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/kite03/echoac-poc11N/AN/A82138252024-01-09T16:44:00Z2023-06-28T00:52:22Z6883
239*/EfsPotato.git*.{0,1000}\/EfsPotato\.git.{0,1000}offensive_tool_keywordEfsPotatoExploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability)T1068 - T1055.002 - T1070.004TA0003 - TA0005 - TA0002N/AN/APrivilege Escalationhttps://github.com/zcgonvh/EfsPotato11N/AN/A1087711252023-12-14T14:30:15Z2021-07-26T21:36:16Z6903
240*/elevateit.bat*.{0,1000}\/elevateit\.bat.{0,1000}offensive_tool_keywordelevationstationelevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternativeT1548.002 - T1055 - T1574.002 - T1078.003TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/g3tsyst3m/elevationstation11N/AN/AN/A4368452023-11-02T23:52:51Z2023-06-10T03:30:59Z6913
241*/Elevator.git*.{0,1000}\/Elevator\.git.{0,1000}offensive_tool_keywordElevatorUAC bypass by abusing RPC and debug objects.T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Kudaes/Elevator11N/AN/A107614692023-10-19T08:51:09Z2022-08-25T21:39:28Z6915
242*/etc/passwd*/.sudo_as_admin_successful*.{0,1000}\/etc\/passwd.{0,1000}\/\.sudo_as_admin_successful.{0,1000}offensive_tool_keywordlinux-smart-enumerationLinux enumeration tool for privilege escalation and discoveryT1087.004 - T1016 - T1548.001 - T1046TA0007 - TA0004 - TA0002N/AN/APrivilege Escalationhttps://github.com/diego-treitos/linux-smart-enumeration10#linuxN/A91035755842023-12-25T14:46:47Z2019-02-13T11:02:21Z7015
243*/evil.dll*.{0,1000}\/evil\.dll.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10N/AN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z7067
244*/exploit.cron.sh*.{0,1000}\/exploit\.cron\.sh.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z7138
245*/exploit.ldpreload.sh*.{0,1000}\/exploit\.ldpreload\.sh.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z7141
246*/full-nelson.c*.{0,1000}\/full\-nelson\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z7310
247*/full-nelson64*.{0,1000}\/full\-nelson64.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z7311
248*/GodPotato.git*.{0,1000}\/GodPotato\.git.{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato11N/AN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z7557
249*/Gotato.git*.{0,1000}\/Gotato\.git.{0,1000}offensive_tool_keywordGotatoGeneric impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.T1003.003 - T1056.002 - T1550.001 - T1090TA0005 - TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/iammaguire/Gotato11N/AN/A92112162021-06-07T21:19:58Z2021-06-05T22:32:48Z7601
250*/gotato.go*.{0,1000}\/gotato\.go.{0,1000}offensive_tool_keywordGotatoGeneric impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.T1003.003 - T1056.002 - T1550.001 - T1090TA0005 - TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/iammaguire/Gotato11N/AN/A92112162021-06-07T21:19:58Z2021-06-05T22:32:48Z7602
251*/gtfobin_update.py*.{0,1000}\/gtfobin_update\.py.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow11N/AN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z7672
252*/gtfobins.go*.{0,1000}\/gtfobins\.go.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linuxN/AN/A1068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z7673
253*/gtfobins.py*.{0,1000}\/gtfobins\.py.{0,1000}offensive_tool_keywordBeRootPrivilege Escalation Project - Windows / Linux / Mac T1053.005 - T1069.002 - T1069.001 - T1053.003 - T1087.001 - T1087.002 - T1082 - T1135 - T1049 - T1007TA0004N/AN/APrivilege Escalationhttps://github.com/AlessandroZ/BeRoot11#linuxN/A101025234592024-10-04T11:54:01Z2017-04-14T12:47:31Z7674
254*/gtfonow.py*.{0,1000}\/gtfonow\.py.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow11N/AN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z7675
255*/havoc_bof.py*.{0,1000}\/havoc_bof\.py.{0,1000}offensive_tool_keywordPoolPartyBofA beacon object file implementation of PoolParty Process Injection TechniqueT1055.011 - T1055 - T1620TA0005N/ABlack BastaPrivilege Escalationhttps://github.com/0xEr3bus/PoolPartyBof11N/AN/A104380442023-12-21T19:00:20Z2023-12-11T19:28:20Z7740
256*/home/lowpriv/*.{0,1000}\/home\/lowpriv\/.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10#linuxN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z7795
257*/IDiagnosticProfileUAC*.{0,1000}\/IDiagnosticProfileUAC.{0,1000}offensive_tool_keywordIDiagnosticProfileUACUAC bypass using auto-elevated COM object Virtual Factory for DiagCplT1548.002 - T1059.003 - T1027.002TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/Wh04m1001/IDiagnosticProfileUAC11N/AN/A102182322022-07-02T20:31:47Z2022-07-02T19:55:42Z8012
258*/Ikeext-Privesc.git*.{0,1000}\/Ikeext\-Privesc\.git.{0,1000}offensive_tool_keywordIkeext-PrivescWindows IKEEXT DLL Hijacking Exploit ToolT1546.011 - T1574.009 - T1036.004TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/securycore/Ikeext-Privesc11N/AN/A10133522018-02-25T13:45:15Z2018-02-27T11:18:56Z8024
259*/Inveigh.ps1*.{0,1000}\/Inveigh\.ps1.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script11N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z8119
260*/Invoke-RunAsSystem.git*.{0,1000}\/Invoke\-RunAsSystem\.git.{0,1000}offensive_tool_keywordInvoke-RunAsSystemA simple script to elevate current session to SYSTEM (needs to be run as Administrator)T1548.002 - T1059.001TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/Leo4j/Invoke-RunAsSystem11N/AN/A811412024-11-11T17:18:20Z2023-08-24T15:12:40Z8162
261*/JuicyPotato.exe*.{0,1000}\/JuicyPotato\.exe.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato11N/AN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z8263
262*/JuicyPotato.git*.{0,1000}\/JuicyPotato\.git.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato11N/AN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z8264
263*/JuicyPotato_x32.exe*.{0,1000}\/JuicyPotato_x32\.exe.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato11N/AN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z8267
264*/JuicyPotato_x64.exe*.{0,1000}\/JuicyPotato_x64\.exe.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato11N/AN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z8268
265*/JuicyPotatoNG.git*.{0,1000}\/JuicyPotatoNG\.git.{0,1000}offensive_tool_keywordJuicyPotatoNGAnother Windows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AFoxKitten - APT33 - Volatile Cedar - SandwormPrivilege Escalationhttps://github.com/antonioCoco/JuicyPotatoNG11N/AN/A1098441012022-11-12T01:48:39Z2022-09-21T17:08:35Z8269
266*/JuicyPotato-webshell/*.{0,1000}\/JuicyPotato\-webshell\/.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato11N/AN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z8270
267*/KExecDD.git*.{0,1000}\/KExecDD\.git.{0,1000}offensive_tool_keywordKExecDDAdmin to Kernel code execution using the KSecDD driverT1068 - T1055.011TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/floesen/KExecDD11N/AN/A83244412024-04-19T09:58:14Z2024-04-19T08:54:49Z8338
268*/KrbRelayUp.git*.{0,1000}\/KrbRelayUp\.git.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp11N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z8409
269*/LinEnum.git*.{0,1000}\/LinEnum\.git.{0,1000}offensive_tool_keywordLinEnumScripted Local Linux Enumeration & Privilege Escalation ChecksT1046 - T1087.001 - T1057 - T1082 - T1016 - T1135 - T1049 - T1059.004 - T1007 - T1069.001 - T1083 - T1018TA0007 - TA0009 - TA0002 - TA0003 - TA0001N/AN/APrivilege Escalationhttps://github.com/rebootuser/LinEnum11#linuxN/A1010730920112023-09-06T18:02:29Z2013-08-20T06:26:58Z8526
270*/LinEnum/*.{0,1000}\/LinEnum\/.{0,1000}offensive_tool_keywordLinEnumScripted Local Linux Enumeration & Privilege Escalation ChecksT1046 - T1087.001 - T1057 - T1082 - T1016 - T1135 - T1049 - T1059.004 - T1007 - T1069.001 - T1083 - T1018TA0007 - TA0009 - TA0002 - TA0003 - TA0001N/AN/APrivilege Escalationhttps://github.com/rebootuser/LinEnum11#linuxN/A1010730920112023-09-06T18:02:29Z2013-08-20T06:26:58Z8527
271*/linpeas.sh*.{0,1000}\/linpeas\.sh.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng11N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z8532
272*/linpeas.sh*.{0,1000}\/linpeas\.sh.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng11N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z8533
273*/linpeas.txt*.{0,1000}\/linpeas\.txt.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng11N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z8534
274*/linpeasBaseBuilder.py*.{0,1000}\/linpeasBaseBuilder\.py.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z8535
275*/linpeasBuilder.py*.{0,1000}\/linpeasBuilder\.py.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z8536
276*/linux_ldso_dynamic.c*.{0,1000}\/linux_ldso_dynamic\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z8537
277*/linux_ldso_hwcap.c*.{0,1000}\/linux_ldso_hwcap\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z8538
278*/linux_ldso_hwcap_64.c*.{0,1000}\/linux_ldso_hwcap_64\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z8539
279*/linux_offset2lib.c*.{0,1000}\/linux_offset2lib\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z8540
280*/linuxprivchecker.git*.{0,1000}\/linuxprivchecker\.git.{0,1000}offensive_tool_keywordlinuxprivcheckersearch for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploitsT1210.001 - T1082 - T1088 - T1547.001TA0002 - TA0004 - TA0006 - TA0007 - TA0008N/AN/APrivilege Escalationhttps://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py11#linuxN/A71016455242022-01-31T10:32:08Z2016-04-19T13:31:46Z8548
281*/linux-smart-enumeration.git*.{0,1000}\/linux\-smart\-enumeration\.git.{0,1000}offensive_tool_keywordlinux-smart-enumerationLinux enumeration tool for privilege escalation and discoveryT1087.004 - T1016 - T1548.001 - T1046TA0007 - TA0004 - TA0002N/AN/APrivilege Escalationhttps://github.com/diego-treitos/linux-smart-enumeration11#linuxN/A91035755842023-12-25T14:46:47Z2019-02-13T11:02:21Z8549
282*/LocalAdminSharp.git*.{0,1000}\/LocalAdminSharp\.git.{0,1000}offensive_tool_keywordLocalAdminSharp.NET executable to use when dealing with privilege escalation on Windows to gain local administrator accessT1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004TA0004N/AN/APrivilege Escalationhttps://github.com/notdodo/LocalAdminSharp11N/AN/A102157172022-11-01T17:45:43Z2022-01-01T10:35:09Z8580
283*/LocalAdminSharp.sln*.{0,1000}\/LocalAdminSharp\.sln.{0,1000}offensive_tool_keywordLocalAdminSharp.NET executable to use when dealing with privilege escalation on Windows to gain local administrator accessT1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004TA0004N/AN/APrivilege Escalationhttps://github.com/notdodo/LocalAdminSharp11N/AN/A102157172022-11-01T17:45:43Z2022-01-01T10:35:09Z8581
284*/local-exploits/master/CVE*.{0,1000}\/local\-exploits\/master\/CVE.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z8584
285*/LocalPotato.git*.{0,1000}\/LocalPotato\.git.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato11N/AN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z8585
286*/localroot/2.6.x/elflbl*.{0,1000}\/localroot\/2\.6\.x\/elflbl.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z8587
287*/localroot/2.6.x/h00lyshit*.{0,1000}\/localroot\/2\.6\.x\/h00lyshit.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z8588
288*/ly4k/Pachine*.{0,1000}\/ly4k\/Pachine.{0,1000}offensive_tool_keywordPachinePython implementation for CVE-2021-42278 (Active Directory Privilege Escalation)T1068 - T1078 - T1059.006TA0003 - TA0004 - TA0002N/ABlack BastaPrivilege Escalationhttps://github.com/ly4k/Pachine11N/AN/A83275372022-01-13T12:35:19Z2021-12-13T23:15:05Z8670
289*/MakeMeAdmin * x64.msi*.{0,1000}\/MakeMeAdmin\s.{0,1000}\sx64\.msi.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin11N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z8699
290*/MakeMeAdmin.git*.{0,1000}\/MakeMeAdmin\.git.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin11N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z8700
291*/MakeMeAdmin/tarball*.{0,1000}\/MakeMeAdmin\/tarball.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin11N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z8701
292*/MakeMeAdmin/tree/v*/Installers*.{0,1000}\/MakeMeAdmin\/tree\/v.{0,1000}\/Installers.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin11N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z8702
293*/MakeMeAdmin/zipball*.{0,1000}\/MakeMeAdmin\/zipball.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin11N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z8703
294*/MakeMeEnterpriseAdmin.ps1*.{0,1000}\/MakeMeEnterpriseAdmin\.ps1.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp11N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z8704
295*/MakeMeEnterpriseAdmin.ps1*.{0,1000}\/MakeMeEnterpriseAdmin\.ps1.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato11N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z8705
296*/memodipper64*.{0,1000}\/memodipper64.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z8753
297*/mempodipper.c*.{0,1000}\/mempodipper\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z8756
298*/MonkeyWorks.git*.{0,1000}\/MonkeyWorks\.git.{0,1000}offensive_tool_keywordTokenvatorA tool to elevate privilege with Windows TokensT1134 - T1078TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/0xbadjuju/Tokenvator11N/AN/AN/A1010382012023-10-06T13:17:05Z2017-12-08T01:29:11Z8892
299*/MultiPotato.git*.{0,1000}\/MultiPotato\.git.{0,1000}offensive_tool_keywordMultiPotatoget SYSTEM via SeImpersonate privilegesT1548.002 - T1134.002TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/S3cur3Th1sSh1t/MultiPotato11N/AN/A106518922021-11-20T16:20:23Z2021-11-19T15:50:55Z8967
300*/mzet-/les-res*.{0,1000}\/mzet\-\/les\-res.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z8995
301*/nginxed-root.sh*.{0,1000}\/nginxed\-root\.sh.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z9134
302*/NoFilter.cpp*.{0,1000}\/NoFilter\.cpp.{0,1000}offensive_tool_keywordNoFilterTool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.T1548 - T1548.002 - T1055 - T1055.004TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/deepinstinct/NoFilter11N/AN/A93298482024-10-29T07:30:35Z2023-07-30T09:25:38Z9226
303*/NoFilter.exe*.{0,1000}\/NoFilter\.exe.{0,1000}offensive_tool_keywordNoFilterTool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.T1548 - T1548.002 - T1055 - T1055.004TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/deepinstinct/NoFilter11N/AN/A93298482024-10-29T07:30:35Z2023-07-30T09:25:38Z9227
304*/NoFilter.git*.{0,1000}\/NoFilter\.git.{0,1000}offensive_tool_keywordNoFilterTool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.T1548 - T1548.002 - T1055 - T1055.004TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/deepinstinct/NoFilter11N/AN/A93298482024-10-29T07:30:35Z2023-07-30T09:25:38Z9228
305*/NoFilter.sln*.{0,1000}\/NoFilter\.sln.{0,1000}offensive_tool_keywordNoFilterTool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.T1548 - T1548.002 - T1055 - T1055.004TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/deepinstinct/NoFilter11N/AN/A93298482024-10-29T07:30:35Z2023-07-30T09:25:38Z9229
306*/NoFilter.vcxproj*.{0,1000}\/NoFilter\.vcxproj.{0,1000}offensive_tool_keywordNoFilterTool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.T1548 - T1548.002 - T1055 - T1055.004TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/deepinstinct/NoFilter11N/AN/A93298482024-10-29T07:30:35Z2023-07-30T09:25:38Z9230
307*/NotQuite0DayFriday/zip/trunk*.{0,1000}\/NotQuite0DayFriday\/zip\/trunk.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z9243
308*/NTLMRelay2Self*.{0,1000}\/NTLMRelay2Self.{0,1000}offensive_tool_keywordNTLMRelay2SelfAn other No-Fix LPE - NTLMRelay2Self over HTTP (Webdav).T1078 - T1078.004 - T1557 - T1557.001 - T1068TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/med0x2e/NTLMRelay2Self11N/AN/A105400422024-01-27T08:52:03Z2022-04-30T10:05:02Z9292
309*/NtRights/*.{0,1000}\/NtRights\/.{0,1000}offensive_tool_keywordNtRightstool for adding privileges from the commandlineT1548.002 - T1059.003 - T1027.002TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/gtworek/PSBits/tree/master/NtRights11N/AN/A71033375422025-03-12T19:59:23Z2019-06-29T13:22:36Z9317
310*/OfficeInjector.exe*.{0,1000}\/OfficeInjector\.exe.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe11N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z9366
311*/OUned.git*.{0,1000}\/OUned\.git.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned11N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z9453
312*/ouned_smbserver.py*.{0,1000}\/ouned_smbserver\.py.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned11N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z9454
313*/p_cve-2014-9322.tar.gz*.{0,1000}\/p_cve\-2014\-9322\.tar\.gz.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z9471
314*/PEASS-ng.git*.{0,1000}\/PEASS\-ng\.git.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng11N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z9588
315*/PEASS-ng.git*.{0,1000}\/PEASS\-ng\.git.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z9589
316*/PEASS-ng/*.{0,1000}\/PEASS\-ng\/.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng11N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z9590
317*/PEASS-ng/releases/*.{0,1000}\/PEASS\-ng\/releases\/.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z9591
318*/perf_swevent64*.{0,1000}\/perf_swevent64.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z9603
319*/Perfusion.exe*.{0,1000}\/Perfusion\.exe.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion11N/AN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z9604
320*/Perfusion.git*.{0,1000}\/Perfusion\.git.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion11N/AN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z9605
321*/PerfusionDll.dll*.{0,1000}\/PerfusionDll\.dll.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion11N/AN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z9606
322*/PetitPotato.cpp*.{0,1000}\/PetitPotato\.cpp.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato11N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z9641
323*/PetitPotato.git*.{0,1000}\/PetitPotato\.git.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato11N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z9642
324*/PetitPotato-1.0.0.zip*.{0,1000}\/PetitPotato\-1\.0\.0\.zip.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato11N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z9643
325*/pipe/RustPotato*.{0,1000}\/pipe\/RustPotato.{0,1000}offensive_tool_keywordRustPotatoA Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privilegesT1134.001 - T1055.011TA0004N/AN/APrivilege Escalationhttps://github.com/emdnaia/RustPotato10#content #namedpipeN/A101002025-01-06T18:10:17Z2025-01-06T19:44:57Z9699
326*/PoC/PrivilegeEscalation*.{0,1000}\/PoC\/PrivilegeEscalation.{0,1000}offensive_tool_keywordechoac-pocpoc stealing the Kernel's KPROCESS/EPROCESS block and writing it to a newly spawned shell to elevate its privileges to the highest possible - nt authority\systemT1068 - T1203 - T1059.003TA0002 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/kite03/echoac-poc11N/AN/A82138252024-01-09T16:44:00Z2023-06-28T00:52:22Z9720
327*/PoolPartyBof.git*.{0,1000}\/PoolPartyBof\.git.{0,1000}offensive_tool_keywordPoolPartyBofA beacon object file implementation of PoolParty Process Injection TechniqueT1055.011 - T1055 - T1620TA0005N/ABlack BastaPrivilege Escalationhttps://github.com/0xEr3bus/PoolPartyBof11N/AN/A104380442023-12-21T19:00:20Z2023-12-11T19:28:20Z9734
328*/PoolPartyBof/releases/download/*.{0,1000}\/PoolPartyBof\/releases\/download\/.{0,1000}offensive_tool_keywordPoolPartyBofA beacon object file implementation of PoolParty Process Injection TechniqueT1055.011 - T1055 - T1620TA0005N/ABlack BastaPrivilege Escalationhttps://github.com/0xEr3bus/PoolPartyBof11N/AN/A104380442023-12-21T19:00:20Z2023-12-11T19:28:20Z9736
329*/PoolPartyBof/tarball/*.{0,1000}\/PoolPartyBof\/tarball\/.{0,1000}offensive_tool_keywordPoolPartyBofA beacon object file implementation of PoolParty Process Injection TechniqueT1055.011 - T1055 - T1620TA0005N/ABlack BastaPrivilege Escalationhttps://github.com/0xEr3bus/PoolPartyBof11N/AN/A104380442023-12-21T19:00:20Z2023-12-11T19:28:20Z9737
330*/PoolPartyBof/zipball/*.{0,1000}\/PoolPartyBof\/zipball\/.{0,1000}offensive_tool_keywordPoolPartyBofA beacon object file implementation of PoolParty Process Injection TechniqueT1055.011 - T1055 - T1620TA0005N/ABlack BastaPrivilege Escalationhttps://github.com/0xEr3bus/PoolPartyBof11N/AN/A104380442023-12-21T19:00:20Z2023-12-11T19:28:20Z9738
331*/Powermad.ps1*.{0,1000}\/Powermad\.ps1.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp11N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z9813
332*/PowerUp.ps1*.{0,1000}\/PowerUp\.ps1.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script11N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z9830
333*/PowerView.ps1*.{0,1000}\/PowerView\.ps1.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script11N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z9835
334*/prefetch-tool.git*.{0,1000}\/prefetch\-tool\.git.{0,1000}offensive_tool_keywordprefetch-toolWindows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitationT1564.007TA0004N/AN/APrivilege Escalationhttps://github.com/exploits-forsale/prefetch-tool11N/AN/A8190102024-04-26T05:40:32Z2024-04-26T05:00:27Z9860
335*/PrintNightmare.git*.{0,1000}\/PrintNightmare\.git.{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/outflanknl/PrintNightmare11N/AN/A104337672021-09-13T08:45:26Z2021-09-13T08:44:02Z9876
336*/PrintSpoofer.exe*.{0,1000}\/PrintSpoofer\.exe.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/11N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z9883
337*/PrintSpoofer.git*.{0,1000}\/PrintSpoofer\.git.{0,1000}offensive_tool_keywordPrintSpooferAbusing Impersonation Privileges on Windows 10 and Server 2019T1548.002 - T1055.001 - T1055.002TA0005 - TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrintSpoofer11N/AN/A101019713422020-09-10T17:49:41Z2020-04-28T08:26:29Z9884
338*/PrintSpoofer.git*.{0,1000}\/PrintSpoofer\.git.{0,1000}offensive_tool_keywordprintspooferAbusing impersonation privileges through the Printer BugT1134 - T1003 - T1055TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/PrintSpoofer11N/AN/A101019713422020-09-10T17:49:41Z2020-04-28T08:26:29Z9885
339*/PrivEditor.dll*.{0,1000}\/PrivEditor\.dll.{0,1000}offensive_tool_keywordPrivFuKernel Mode WinDbg extension for token privilege editT1055 - T1078 - T1134TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z9888
340*/Privesc.git*.{0,1000}\/Privesc\.git.{0,1000}offensive_tool_keywordPrivescWindows PowerShell script that finds misconfiguration issues which can lead to privilege escalationT1068 - T1548 - T1082 - T1078TA0004N/AN/APrivilege Escalationhttps://github.com/enjoiz/Privesc11N/AN/A106595972024-12-01T15:24:41Z2015-11-19T13:22:01Z9889
341*/privesc.ps1*.{0,1000}\/privesc\.ps1.{0,1000}offensive_tool_keywordPrivescWindows PowerShell script that finds misconfiguration issues which can lead to privilege escalationT1068 - T1548 - T1082 - T1078TA0004N/AN/APrivilege Escalationhttps://github.com/enjoiz/Privesc11N/AN/A106595972024-12-01T15:24:41Z2015-11-19T13:22:01Z9890
342*/PrivEsc.psm1*.{0,1000}\/PrivEsc\.psm1.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script11N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z9891
343*/PrivescCheck*.{0,1000}\/PrivescCheck.{0,1000}offensive_tool_keywordPrivescCheckPrivilege Escalation Enumeration Script for WindowsT1053 - T1088TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrivescCheck11N/AN/A101032304602025-03-05T14:44:17Z2020-01-16T12:28:10Z9893
344*/PrivExchange.git*.{0,1000}\/PrivExchange\.git.{0,1000}offensive_tool_keywordprivexchangeExchange your privileges for Domain Admin privs by abusing ExchangeT1053.005 - T1078 - T1069.002TA0002 - TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/dirkjanm/PrivExchange11N/AN/AN/A1010111732020-01-23T19:48:51Z2019-01-21T17:39:47Z9896
345*/PrivFu.git*.{0,1000}\/PrivFu\.git.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z9898
346*/Privileger.git*.{0,1000}\/Privileger\.git.{0,1000}offensive_tool_keywordPrivilegerPrivileger is a tool to work with Windows PrivilegesT1548.002TA0004 N/AN/APrivilege Escalationhttps://github.com/MzHmO/Privileger11N/AN/A82136322023-02-07T07:28:40Z2023-01-31T11:24:37Z9901
347*/PrivKit.git*.{0,1000}\/PrivKit\.git.{0,1000}offensive_tool_keywordPrivKitPrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.T1548.002 - T1059.003 - T1027.002TA0005N/AN/APrivilege Escalationhttps://github.com/mertdas/PrivKit11N/AN/A95405472024-06-15T16:54:32Z2023-03-20T04:19:40Z9902
348*/PrivKit/*.{0,1000}\/PrivKit\/.{0,1000}offensive_tool_keywordPrivKitPrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.T1548.002 - T1059.003 - T1027.002TA0005N/AN/APrivilege Escalationhttps://github.com/mertdas/PrivKit11N/AN/A95405472024-06-15T16:54:32Z2023-03-20T04:19:40Z9903
349*/psgetsys.ps1*.{0,1000}\/psgetsys\.ps1.{0,1000}offensive_tool_keywordpsgetsystemgetsystem via parent process using ps1 & embeded c#T1134 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/decoder-it/psgetsystem11N/AN/A105406882023-10-26T07:13:08Z2018-02-02T11:28:22Z9968
350*/psgetsystem.git*.{0,1000}\/psgetsystem\.git.{0,1000}offensive_tool_keywordpsgetsystemgetsystem via parent process using ps1 & embeded c#T1134 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/decoder-it/psgetsystem11N/AN/A105406882023-10-26T07:13:08Z2018-02-02T11:28:22Z9969
351*/PView.psm1*.{0,1000}\/PView\.psm1.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script11N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z10034
352*/PyExec.git*.{0,1000}\/PyExec\.git.{0,1000}offensive_tool_keywordPyExecThis is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses.T1134 - T1055 - T1548.002TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/OlivierLaflamme/PyExec11N/AN/A911172019-09-11T13:56:04Z2019-09-11T13:54:15Z10066
353*/raceabrt.c*.{0,1000}\/raceabrt\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z10141
354*/rasman.exe*.{0,1000}\/rasman\.exe.{0,1000}offensive_tool_keywordRasmanPotatousing RasMan service for privilege escalationT1548.002 - T1055.002 - T1055.001 TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/crisprss/RasmanPotato11N/AN/A104371532023-02-06T10:27:41Z2023-02-06T09:41:51Z10157
355*/RasmanPotato*.{0,1000}\/RasmanPotato.{0,1000}offensive_tool_keywordRasmanPotatousing RasMan service for privilege escalationT1548.002 - T1055.002 - T1055.001 TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/crisprss/RasmanPotato11N/AN/A104371532023-02-06T10:27:41Z2023-02-06T09:41:51Z10158
356*/releases/download/Binaries/DeadPotato*.{0,1000}\/releases\/download\/Binaries\/DeadPotato.{0,1000}offensive_tool_keywordDeadPotatoDeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privilegesT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011N/AN/APrivilege Escalationhttps://github.com/lypd0/DeadPotato11N/AN/A104382452024-08-17T06:08:29Z2024-07-31T01:08:30Z10340
357*/releases/latest/download/lse.sh*.{0,1000}\/releases\/latest\/download\/lse\.sh.{0,1000}offensive_tool_keywordlinux-smart-enumerationLinux enumeration tool for privilege escalation and discoveryT1087.004 - T1016 - T1548.001 - T1046TA0007 - TA0004 - TA0002N/AN/APrivilege Escalationhttps://github.com/diego-treitos/linux-smart-enumeration11#linuxN/A91035755842023-12-25T14:46:47Z2019-02-13T11:02:21Z10351
358*/RemotePotato0.git*.{0,1000}\/RemotePotato0\.git.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato011N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z10397
359*/RemotePotato0.zip*.{0,1000}\/RemotePotato0\.zip.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato011N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z10398
360*/RoguePotato.git*.{0,1000}\/RoguePotato\.git.{0,1000}offensive_tool_keywordRoguePotatoWindows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RoguePotato11N/AN/A101010811312021-01-09T20:43:07Z2020-05-10T17:38:28Z10496
361*/RogueWinRM.git*.{0,1000}\/RogueWinRM\.git.{0,1000}offensive_tool_keywordRogueWinRMRogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not runningT1548.003 - T1134.002 - T1055TA0004N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RogueWinRM11N/AN/A1087881072020-02-23T19:26:41Z2019-12-02T22:58:03Z10497
362*/RottenPotatoNG.git*.{0,1000}\/RottenPotatoNG\.git.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG11N/AN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z10527
363*/RustPotato.git*.{0,1000}\/RustPotato\.git.{0,1000}offensive_tool_keywordRustPotatoA Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privilegesT1134.001 - T1055.011TA0004N/AN/APrivilege Escalationhttps://github.com/emdnaia/RustPotato11N/AN/A101002025-01-06T18:10:17Z2025-01-06T19:44:57Z10647
364*/S4UTomato.git*.{0,1000}\/S4UTomato\.git.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato11N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z10659
365*/SeAuditPrivilegePoC.exe*.{0,1000}\/SeAuditPrivilegePoC\.exe.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z10763
366*/SeBackupPrivilegePoC.exe*.{0,1000}\/SeBackupPrivilegePoC\.exe.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z10765
367*/SecondaryLogonVariant.exe*.{0,1000}\/SecondaryLogonVariant\.exe.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z10767
368*/SeManageVolumeExploit.git*.{0,1000}\/SeManageVolumeExploit\.git.{0,1000}offensive_tool_keywordSeManageVolumeExploitThis exploit grants full permission on C:\ drive for all users on the machineT1046 - T1098 - T1222.002TA0007 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/CsEnox/SeManageVolumeExploit11N/AN/A102110172023-05-29T05:41:16Z2021-10-11T01:17:04Z10783
369*/ServiceName:TokenDriver*.{0,1000}\/ServiceName\:TokenDriver.{0,1000}offensive_tool_keywordTokenvatorA tool to elevate privilege with Windows TokensT1134 - T1078TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/0xbadjuju/Tokenvator11N/AN/AN/A1010382012023-10-06T13:17:05Z2017-12-08T01:29:11Z10801
370*/SharpEfsPotato*.{0,1000}\/SharpEfsPotato.{0,1000}offensive_tool_keywordSharpEfsPotatoLocal privilege escalation from SeImpersonatePrivilege using EfsRpc.T1548.002 - T1134.002TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/bugch3ck/SharpEfsPotato11N/AN/A104317462022-10-17T12:35:06Z2022-10-17T12:20:47Z10957
371*/SharpElevator.exe*.{0,1000}\/SharpElevator\.exe.{0,1000}offensive_tool_keywordSharpElevatorSharpElevator is a C# implementation of Elevator for UAC bypassT1548.002 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/SharpElevator11N/AN/A10151122022-08-31T18:09:10Z2022-08-29T19:52:53Z10958
372*/SharpElevator.git*.{0,1000}\/SharpElevator\.git.{0,1000}offensive_tool_keywordSharpElevatorSharpElevator is a C# implementation of Elevator for UAC bypassT1548.002 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/SharpElevator11N/AN/A10151122022-08-31T18:09:10Z2022-08-29T19:52:53Z10959
373*/SharpUp.git*.{0,1000}\/SharpUp\.git.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp11N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z11148
374*/ShimInjector.exe*.{0,1000}\/ShimInjector\.exe.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z11232
375*/ShimMe.git*.{0,1000}\/ShimMe\.git.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe11N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z11233
376*/SigmaPotato.git*.{0,1000}\/SigmaPotato\.git.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato11N/AN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z11254
377*/SigmaPotato/releases/download/*.{0,1000}\/SigmaPotato\/releases\/download\/.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato11N/AN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z11255
378*/SpoolFool.exe*.{0,1000}\/SpoolFool\.exe.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool11N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z11540
379*/SpoolFool.git*.{0,1000}\/SpoolFool\.git.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool11N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z11541
380*/SpoolFool.ps1*.{0,1000}\/SpoolFool\.ps1.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool11N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z11542
381*/Sweetpotato.exe*.{0,1000}\/Sweetpotato\.exe.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato11N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z11749
382*/SweetPotato.git*.{0,1000}\/SweetPotato\.git.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato11N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z11750
383*/SweetPotato-master.zip*.{0,1000}\/SweetPotato\-master\.zip.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato11N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z11752
384*/SwitchPriv.exe*.{0,1000}\/SwitchPriv\.exe.{0,1000}offensive_tool_keywordPrivFuenable or disable specific token privileges for a processT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/ASwitchPriv1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z11753
385*/Telemetry.git*.{0,1000}\/Telemetry\.git.{0,1000}offensive_tool_keywordTelemetryAbusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges.T1053 - T1547 - T1059TA0003 - TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/Imanfeng/Telemetry11N/AN/A92140132020-07-02T09:41:27Z2020-06-24T16:30:44Z11858
386*/test_privesc.py*.{0,1000}\/test_privesc\.py.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow11N/AN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z11864
387*/timeoutpwn64*.{0,1000}\/timeoutpwn64.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z11925
388*/tmp/beacon_x64.bin*.{0,1000}\/tmp\/beacon_x64\.bin.{0,1000}offensive_tool_keywordPoolPartyBofA beacon object file implementation of PoolParty Process Injection TechniqueT1055.011 - T1055 - T1620TA0005N/ABlack BastaPrivilege Escalationhttps://github.com/0xEr3bus/PoolPartyBof10#linuxN/A104380442023-12-21T19:00:20Z2023-12-11T19:28:20Z11954
389*/tmp/exploit*.{0,1000}\/tmp\/exploit.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z11968
390*/tmp/gtfokey.pub*.{0,1000}\/tmp\/gtfokey\.pub.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10#linuxN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z11974
391*/tmp/libpwn.c*.{0,1000}\/tmp\/libpwn\.c.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10#linuxN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z11977
392*/tmp/libpwn.so*.{0,1000}\/tmp\/libpwn\.so.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10#linuxN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z11978
393*/tmp/passwd.bak*.{0,1000}\/tmp\/passwd\.bak.{0,1000}offensive_tool_keywordPOCexploit the Linux Dirty Pipe vulnerabilityT1068 - T1078.003 - T1071.004 - T1072 - T1105TA0004 - TA0006?N/AN/APrivilege Escalationhttps://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits10#linuxN/A1065951482023-05-20T05:55:45Z2022-03-12T20:57:24Z11983
394*/tmp/r00tshell*.{0,1000}\/tmp\/r00tshell.{0,1000}offensive_tool_keywordexploit-dbprivilege escalation exploit pattern on https://www.exploit-db.com/exploits/38576T1068 - T1548 - T1055 - T1088 - T1134 - T1221 - T1543 - T1547 - T1574TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://www.exploit-db.com/exploits/3857610#linuxlinux privesc1010N/AN/AN/AN/A11989
395*/tmp/shellcode.bin*.{0,1000}\/tmp\/shellcode\.bin.{0,1000}offensive_tool_keywordPoolPartyBofA beacon object file implementation of PoolParty Process Injection TechniqueT1055.011 - T1055 - T1620TA0005N/ABlack BastaPrivilege Escalationhttps://github.com/0xEr3bus/PoolPartyBof10#linuxN/A104380442023-12-21T19:00:20Z2023-12-11T19:28:20Z11993
396*/tmp/traitor.so*.{0,1000}\/tmp\/traitor\.so.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linuxN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z12002
397*/TokenAssignor.exe*.{0,1000}\/TokenAssignor\.exe.{0,1000}offensive_tool_keywordPrivFuTool to execute token assigned processT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/ATokenAssignor1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z12010
398*/Token-Impersonation.git*.{0,1000}\/Token\-Impersonation\.git.{0,1000}offensive_tool_keywordToken-ImpersonationMake a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)T1134.001 - T1134.002TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/Leo4j/Token-Impersonation11N/AN/A81732024-03-20T17:07:13Z2023-11-02T10:46:24Z12014
399*/Token-Impersonation.ps1*.{0,1000}\/Token\-Impersonation\.ps1.{0,1000}offensive_tool_keywordToken-ImpersonationMake a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)T1134.001 - T1134.002TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/Leo4j/Token-Impersonation11N/AN/A81732024-03-20T17:07:13Z2023-11-02T10:46:24Z12015
400*/TokenPlayer.git*.{0,1000}\/TokenPlayer\.git.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer11N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z12016
401*/TokenStealing*.{0,1000}\/TokenStealing.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z12018
402*/TokenStealing.exe*.{0,1000}\/TokenStealing\.exe.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/11N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z12019
403*/Tokenvator/*.{0,1000}\/Tokenvator\/.{0,1000}offensive_tool_keywordTokenvatorA tool to elevate privilege with Windows TokensT1134 - T1078TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/0xbadjuju/Tokenvator11N/AN/AN/A1010382012023-10-06T13:17:05Z2017-12-08T01:29:11Z12027
404*/tomcat-RH-root.sh*.{0,1000}\/tomcat\-RH\-root\.sh.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester11#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z12029
405*/traitor/pkg/backdoor*.{0,1000}\/traitor\/pkg\/backdoor.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linuxN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z12073
406*/traitor/releases/download/*.{0,1000}\/traitor\/releases\/download\/.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linuxN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z12074
407*/traitor-386*.{0,1000}\/traitor\-386.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linuxN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z12075
408*/traitor-amd64*.{0,1000}\/traitor\-amd64.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linuxN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z12076
409*/traitor-arm64*.{0,1000}\/traitor\-arm64.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linuxN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z12077
410*/UAC-BOF-Bonanza.git*.{0,1000}\/UAC\-BOF\-Bonanza\.git.{0,1000}offensive_tool_keywordcobaltstrikeCollection of UAC Bypass Techniques Weaponized as BOFsT1548.002 - T1203 - T1055 - T1134.002TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/icyguider/UAC-BOF-Bonanza11N/AN/A106500652024-02-21T22:07:54Z2024-02-16T14:47:13Z12204
411*/UAC-TokenMagic.ps1*.{0,1000}\/UAC\-TokenMagic\.ps1.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer11N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z12211
412*/UserNamespaceOverlayfsSetuidWriteExec/*.{0,1000}\/UserNamespaceOverlayfsSetuidWriteExec\/.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z12258
413*/UserRightsUtil.exe*.{0,1000}\/UserRightsUtil\.exe.{0,1000}offensive_tool_keywordPrivFumanage user right without secpol.mscT1059 - T1078TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/AUserRightsUtil1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z12259
414*/VDR.git*.{0,1000}\/VDR\.git.{0,1000}offensive_tool_keywordVDRVulnerable driver research tool - result and exploit PoCsT1547.009 - T1210 - T1068 - T1055TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/TakahiroHaruyama/VDR11N/AN/A102192292023-11-01T00:06:55Z2023-10-23T08:34:44Z12425
415*/VDR-main.zip.{0,1000}\/VDR\-main\.zipoffensive_tool_keywordVDRVulnerable driver research tool - result and exploit PoCsT1547.009 - T1210 - T1068 - T1055TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/TakahiroHaruyama/VDR11N/AN/A102192292023-11-01T00:06:55Z2023-10-23T08:34:44Z12426
416*/vnik_v1.c*.{0,1000}\/vnik_v1\.c.{0,1000}offensive_tool_keywordlinux-exploit-suggesterLinux privilege escalation auditing toolT1078 - T1068 - T1055TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/The-Z-Labs/linux-exploit-suggester10#linuxN/A1010590911332024-02-17T11:44:50Z2016-10-06T21:55:51Z12474
417*/webdavshare/potato.local*.{0,1000}\/webdavshare\/potato\.local.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10N/AN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z12533
418*/WerTrigger.git*.{0,1000}\/WerTrigger\.git.{0,1000}offensive_tool_keywordWerTriggerWeaponizing for privileged file writes bugs with windows problem reportingT1059.003 - T1055.001 - T1127.001 - T1546.008TA0002 - TA0004 N/AN/APrivilege Escalationhttps://github.com/sailay1996/WerTrigger11N/AN/A93221362022-05-10T17:36:49Z2020-05-20T11:27:56Z12559
419*/WfpTokenDup.exe*.{0,1000}\/WfpTokenDup\.exe.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z12560
420*/Windows_MSKSSRV_LPE_CVE-2023-36802.git*.{0,1000}\/Windows_MSKSSRV_LPE_CVE\-2023\-36802\.git.{0,1000}offensive_tool_keywordWindows_MSKSSRV_LPE_CVE-2023-36802Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POCT1068 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-3680211N/AN/A102161382023-10-10T17:44:17Z2023-10-09T17:32:15Z12598
421*/winPEAS.exe*.{0,1000}\/winPEAS\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z12623
422*/winPEAS.ps1*.{0,1000}\/winPEAS\.ps1.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z12627
423*/winPEASany.exe*.{0,1000}\/winPEASany\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z12628
424*/winPEASany_ofs.exe*.{0,1000}\/winPEASany_ofs\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z12630
425*/winPEASany_ofs.exe*.{0,1000}\/winPEASany_ofs\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z12631
426*/winPEAS-Obfuscated.exe*.{0,1000}\/winPEAS\-Obfuscated\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z12632
427*/winPEASx64.exe*.{0,1000}\/winPEASx64\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z12633
428*/winPEASx86.exe*.{0,1000}\/winPEASx86\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng11N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z12634
429*/ZeroHVCI.exe*.{0,1000}\/ZeroHVCI\.exe.{0,1000}offensive_tool_keywordZeroHVCIAchieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229T1068 - T1564 - T1014 - T1499TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/zer0condition/ZeroHVCI11N/AN/A72198432024-10-26T17:08:38Z2024-07-20T07:29:18Z12810
430*/ZeroHVCI.git*.{0,1000}\/ZeroHVCI\.git.{0,1000}offensive_tool_keywordZeroHVCIAchieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229T1068 - T1564 - T1014 - T1499TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/zer0condition/ZeroHVCI11N/AN/A72198432024-10-26T17:08:38Z2024-07-20T07:29:18Z12811
431*:\users\public\*.bat*.{0,1000}\:\\users\\public\\.{0,1000}\.bat.{0,1000}offensive_tool_keyword_scripts in public user folderT1036 - T1055 - T1574TA0003 - TA0004 - TA0005N/AN/APrivilege EscalationN/A10N/AN/A1010N/AN/AN/AN/A12853
432*:\users\public\*.hta*.{0,1000}\:\\users\\public\\.{0,1000}\.ps1.{0,1000}offensive_tool_keyword_scripts in public user folderT1036 - T1055 - T1574TA0003 - TA0004 - TA0005N/AN/APrivilege EscalationN/A10N/AN/A1010N/AN/AN/AN/A12854
433*:\users\public\*.ps1*.{0,1000}\:\\users\\public\\.{0,1000}\.ps1.{0,1000}offensive_tool_keyword_scripts in public user folderT1036 - T1055 - T1574TA0003 - TA0004 - TA0005N/AN/APrivilege EscalationN/A10N/AN/A1010N/AN/AN/AN/A12855
434*:\users\public\*.vbs*.{0,1000}\:\\users\\public\\.{0,1000}\.vbs.{0,1000}offensive_tool_keyword_scripts in public user folderT1036 - T1055 - T1574TA0003 - TA0004 - TA0005N/AN/APrivilege EscalationN/A10N/AN/A1010N/AN/AN/AN/A12856
435*:CreateProcessFromParent((Get-Process "lsass").Id*.{0,1000}\:CreateProcessFromParent\(\(Get\-Process\s\"lsass\"\)\.Id.{0,1000}offensive_tool_keywordpsgetsystemgetsystem via parent process using ps1 & embeded c#T1134 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/decoder-it/psgetsystem10N/AN/A105406882023-10-26T07:13:08Z2018-02-02T11:28:22Z12868
436*[!] Couldn't capture the user credential hash :*.{0,1000}\[!\]\sCouldn\'t\scapture\sthe\suser\scredential\shash\s\:.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z12899
437*[!] Couldn't communicate with the fake RPC Server*.{0,1000}\[!\]\sCouldn\'t\scommunicate\swith\sthe\sfake\sRPC\sServer.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z12901
438*[!] Couldn't receive the type2 message from the fake RPC Server*.{0,1000}\[!\]\sCouldn\'t\sreceive\sthe\stype2\smessage\sfrom\sthe\sfake\sRPC\sServer.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z12902
439*[!] Elevated process spawned!*.{0,1000}\[!\]\sElevated\sprocess\sspawned!.{0,1000}offensive_tool_keywordElevatorUAC bypass by abusing RPC and debug objects.T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Kudaes/Elevator10#contentN/A107614692023-10-19T08:51:09Z2022-08-25T21:39:28Z12909
440*[!] Failed to delete Performance registry key.*.{0,1000}\[!\]\sFailed\sto\sdelete\sPerformance\sregistry\skey\..{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion10#contentN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z12915
441*[!] Found exploitable sgid binary*.{0,1000}\[!\]\sFound\sexploitable\ssgid\sbinary.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10#contentN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z12929
442*[!] Found exploitable Sudo NOPASSWD binary*.{0,1000}\[!\]\sFound\sexploitable\sSudo\sNOPASSWD\sbinary.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10#content #linuxN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z12930
443*[!] Found exploitable suid binary*.{0,1000}\[!\]\sFound\sexploitable\ssuid\sbinary.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10#contentN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z12931
444*[!] HTTP reflected DCOM authentication failed *.{0,1000}\[!\]\sHTTP\sreflected\sDCOM\sauthentication\sfailed\s.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10#contentN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z12934
445*[!] Modifialbe scheduled tasks were not evaluated due to permissions*.{0,1000}\[!\]\sModifialbe\sscheduled\stasks\swere\snot\sevaluated\sdue\sto\spermissions.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10#contentN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z12947
446*[!] Rasman service is not running!*.{0,1000}\[!\]\sRasman\sservice\sis\snot\srunning!.{0,1000}offensive_tool_keywordRasmanPotatousing RasMan service for privilege escalationT1548.002 - T1055.002 - T1055.001 TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/crisprss/RasmanPotato10#contentN/A104371532023-02-06T10:27:41Z2023-02-06T09:41:51Z12954
447*[!] SMB reflected DCOM authentication failed*.{0,1000}\[!\]\sSMB\sreflected\sDCOM\sauthentication\sfailed.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10#contentN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z12959
448*[-] Exploit failed! *.{0,1000}\[\-\]\sExploit\sfailed!\s.{0,1000}offensive_tool_keywordJuicyPotatoNGAnother Windows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AFoxKitten - APT33 - Volatile Cedar - SandwormPrivilege Escalationhttps://github.com/antonioCoco/JuicyPotatoNG10#contentN/A1098441012022-11-12T01:48:39Z2022-09-21T17:08:35Z13006
449*[-] Failed to decrypt TGT using supplied password/hash. If this TGT was requested with no preauth then the password supplied may be incorrect or the data was encrypted with a different type of encryption than expected*.{0,1000}\[\-\]\sFailed\sto\sdecrypt\sTGT\susing\ssupplied\spassword\/hash\.\sIf\sthis\sTGT\swas\srequested\swith\sno\spreauth\sthen\sthe\spassword\ssupplied\smay\sbe\sincorrect\sor\sthe\sdata\swas\sencrypted\swith\sa\sdifferent\stype\sof\sencryption\sthan\sexpected.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13008
450*[-] Failed to delete Performance DLL*.{0,1000}\[\-\]\sFailed\sto\sdelete\sPerformance\sDLL.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion10#contentN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z13009
451*[-] Failed to start reverse shell*.{0,1000}\[\-\]\sFailed\sto\sstart\sreverse\sshell.{0,1000}offensive_tool_keywordRustPotatoA Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privilegesT1134.001 - T1055.011TA0004N/AN/APrivilege Escalationhttps://github.com/emdnaia/RustPotato10#contentN/A101002025-01-06T18:10:17Z2025-01-06T19:44:57Z13013
452*[+] Arbitrary Directory Creation to SYSTEM Shell technique !*.{0,1000}\[\+\]\sArbitrary\sDirectory\sCreation\sto\sSYSTEM\sShell\stechnique\s!.{0,1000}offensive_tool_keywordDirCreate2SystemWeaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error ReportingT1068 - T1059.001 - T1070.004TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/binderlabs/DirCreate2System10#contentN/A84357382022-12-19T17:00:43Z2022-12-15T03:49:55Z13048
453*[+] AS-REQ w/o preauth successful!*.{0,1000}\[\+\]\sAS\-REQ\sw\/o\spreauth\ssuccessful!.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10#contentN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z13050
454*[+] Attempting DCOM NTLM relaying with CLSID*.{0,1000}\[\+\]\sAttempting\sDCOM\sNTLM\srelaying\swith\sCLSID.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10#contentN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z13053
455*[+] Attempting NP impersonation using method EfsRpc to launch *.{0,1000}\[\+\]\sAttempting\sNP\simpersonation\susing\smethod\sEfsRpc\sto\slaunch\s.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10#contentN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z13054
456*[+] Attempting NP impersonation using method PrintSpoofer to launch *.{0,1000}\[\+\]\sAttempting\sNP\simpersonation\susing\smethod\sPrintSpoofer\sto\slaunch\s.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10#contentN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z13055
457*[+] Building GTFOBins lists*.{0,1000}\[\+\]\sBuilding\sGTFOBins\slists.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10#contentN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z13071
458*[+] Building linux exploit suggesters*.{0,1000}\[\+\]\sBuilding\slinux\sexploit\ssuggesters.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10#content #linuxN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z13072
459*[+] Building S4U2proxy request for service: *.{0,1000}\[\+\]\sBuilding\sS4U2proxy\srequest\sfor\sservice\:\s.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13073
460*[+] Building S4U2self *.{0,1000}\[\+\]\sBuilding\sS4U2self\s.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13074
461*[+] cross realm S4U2Self success!*.{0,1000}\[\+\]\scross\srealm\sS4U2Self\ssuccess!.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10#contentN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z13094
462*[+] Downloading Fat Linpeas binaries*.{0,1000}\[\+\]\sDownloading\sFat\sLinpeas\sbinaries.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10#contentN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z13106
463*[+] dropping suid shell*.{0,1000}\[\+\]\sdropping\ssuid\sshell.{0,1000}offensive_tool_keywordPOCexploit the Linux Dirty Pipe vulnerabilityT1068 - T1078.003 - T1071.004 - T1072 - T1105TA0004 - TA0006?N/AN/APrivilege Escalationhttps://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits10#content #linuxN/A1065951482023-05-20T05:55:45Z2022-03-12T20:57:24Z13112
464*[+] Exploit Completed*.{0,1000}\[\+\]\sExploit\sCompleted.{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/calebstewart/CVE-2021-167510#contentN/A101010492302021-07-05T08:54:06Z2021-07-01T23:45:58Z13136
465*[+] Exploit completed. Got a SYSTEM token! :)*.{0,1000}\[\+\]\sExploit\scompleted\.\sGot\sa\sSYSTEM\stoken!\s\:\).{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion10#contentN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z13137
466*[+] Exploit successful! *.{0,1000}\[\+\]\sExploit\ssuccessful!\s.{0,1000}offensive_tool_keywordJuicyPotatoNGAnother Windows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AFoxKitten - APT33 - Volatile Cedar - SandwormPrivilege Escalationhttps://github.com/antonioCoco/JuicyPotatoNG10#contentN/A1098441012022-11-12T01:48:39Z2022-09-21T17:08:35Z13138
467*[+] Exploit worked* it should execute your command as SYSTEM!*.{0,1000}\[\+\]\sExploit\sworked.{0,1000}\sit\sshould\sexecute\syour\scommand\sas\sSYSTEM!.{0,1000}offensive_tool_keywordCoercedPotatoRDLLReflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilegeT1055 - T1134 - T1548TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/sokaRepo/CoercedPotatoRDLL10#contentN/A103204312023-11-23T18:58:41Z2023-11-23T13:22:38Z13139
468*[+] Finding directory to hijack*.{0,1000}\[\+\]\sFinding\sdirectory\sto\shijack.{0,1000}offensive_tool_keywordDirCreate2SystemWeaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error ReportingT1068 - T1059.001 - T1070.004TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/binderlabs/DirCreate2System10#contentN/A84357382022-12-19T17:00:43Z2022-12-15T03:49:55Z13142
469*[+] Getting credentials using U2U*.{0,1000}\[\+\]\sGetting\scredentials\susing\sU2U.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13152
470*[+] Got a S4U logon token (Handle = *.{0,1000}\[\+\]\sGot\sa\sS4U\slogon\stoken\s\(Handle\s\=\s.{0,1000}offensive_tool_keywordPrivFuexecute process as NT SERVICE\TrustedInstaller group accountT1059 - T1078TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#contentTrustExec1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z13155
471*[+] Got Krb Auth from NT/System. Relaying to ADCS now*.{0,1000}\[\+\]\sGot\sKrb\sAuth\sfrom\sNT\/System\.\sRelaying\sto\sADCS\snow.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13156
472*[+] Got Krb Auth from NT/SYSTEM. Relying to LDAP now*.{0,1000}\[\+\]\sGot\sKrb\sAuth\sfrom\sNT\/SYSTEM\.\sRelying\sto\sLDAP\snow.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13160
473*[+] hacked the exterior layer of the datacenter mainframe*.{0,1000}\[\+\]\shacked\sthe\sexterior\slayer\sof\sthe\sdatacenter\smainframe.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#content #linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z13165
474*[+] Hijackable DLL: *.{0,1000}\[\+\]\sHijackable\sDLL\:\s.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10#contentN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z13167
475*[+] hijacking suid binary*.{0,1000}\[\+\]\shijacking\ssuid\sbinary.{0,1000}offensive_tool_keywordPOCexploit the Linux Dirty Pipe vulnerabilityT1068 - T1078.003 - T1071.004 - T1072 - T1105TA0004 - TA0006?N/AN/APrivilege Escalationhttps://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits10#content #linuxN/A1065951482023-05-20T05:55:45Z2022-03-12T20:57:24Z13168
476*[+] HKLM\\SAM is saved successfully*.{0,1000}\[\+\]\sHKLM\\\\SAM\sis\ssaved\ssuccessfully.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#contentPrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z13171
477*[+] HTTP Client Auth Context swapped with SYSTEM *.{0,1000}\[\+\]\sHTTP\sClient\sAuth\sContext\sswapped\swith\sSYSTEM\s.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10#contentN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z13174
478*[+] HTTP reflected DCOM authentication succeeded!*.{0,1000}\[\+\]\sHTTP\sreflected\sDCOM\sauthentication\ssucceeded!.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10#contentN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z13175
479*[+] Impersonating user * to target SPN *.{0,1000}\[\+\]\sImpersonating\suser\s.{0,1000}\sto\starget\sSPN\s.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13178
480*[+] Impersonation as smss.exe*.{0,1000}\[\+\]\sImpersonation\sas\ssmss\.exe.{0,1000}offensive_tool_keywordPrivFuexecute process as NT SERVICE\TrustedInstaller group accountT1059 - T1078TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#contentTrustExec1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z13179
481*[+] Impersonation as winlogon.exe is successful*.{0,1000}\[\+\]\sImpersonation\sas\swinlogon\.exe\sis\ssuccessful.{0,1000}offensive_tool_keywordPrivFuSeTcbPrivilege exploitationT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10#contentPrivFu\PowerOfTcb1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z13180
482*[+] Impersonation successful using token from PID *.{0,1000}\[\+\]\sImpersonation\ssuccessful\susing\stoken\sfrom\sPID\s.{0,1000}offensive_tool_keywordToken-ImpersonationMake a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)T1134.001 - T1134.002TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/Leo4j/Token-Impersonation10#contentN/A81732024-03-20T17:07:13Z2023-11-02T10:46:24Z13181
483*[+] Invoking EfsRpcAddUsersToFile with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcAddUsersToFile\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13192
484*[+] Invoking EfsRpcAddUsersToFileEx with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcAddUsersToFileEx\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13193
485*[+] Invoking EfsRpcDecryptFileSrv with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcDecryptFileSrv\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13194
486*[+] Invoking EfsRpcDuplicateEncryptionInfoFile with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcDuplicateEncryptionInfoFile\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13195
487*[+] Invoking EfsRpcDuplicateEncryptionInfoFile with target path:*.{0,1000}\[\+\]\sInvoking\sEfsRpcDuplicateEncryptionInfoFile\swith\starget\spath\:.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13196
488*[+] Invoking EfsRpcEncryptFileSrv with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcEncryptFileSrv\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13197
489*[+] Invoking EfsRpcFileKeyInfo with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcFileKeyInfo\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13198
490*[+] Invoking EfsRpcFileKeyInfoEx with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcFileKeyInfoEx\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13199
491*[+] Invoking EfsRpcGetEncryptedFileMetadata with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcGetEncryptedFileMetadata\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13200
492*[+] Invoking EfsRpcOpenFileRaw with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcOpenFileRaw\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13201
493*[+] Invoking EfsRpcQueryRecoveryAgents with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcQueryRecoveryAgents\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13202
494*[+] Invoking EfsRpcQueryUsersOnFile with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcQueryUsersOnFile\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13203
495*[+] Invoking EfsRpcRemoveUsersFromFile with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcRemoveUsersFromFile\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13204
496*[+] Invoking EfsRpcSetEncryptedFileMetadata with target path: *.{0,1000}\[\+\]\sInvoking\sEfsRpcSetEncryptedFileMetadata\swith\starget\spath\:\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13205
497*[+] Malicious named pipe running on *.{0,1000}\[\+\]\sMalicious\snamed\spipe\srunning\son\s.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#contentN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13224
498*[+] overwriting modprobe_path with different PIDs *.{0,1000}\[\+\]\soverwriting\smodprobe_path\swith\sdifferent\sPIDs\s.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#content #linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z13245
499*[+] Poc By @404death *.{0,1000}\[\+\]\sPoc\sBy\s\@404death\s.{0,1000}offensive_tool_keywordDirCreate2SystemWeaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error ReportingT1068 - T1059.001 - T1070.004TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/binderlabs/DirCreate2System10#contentN/A84357382022-12-19T17:00:43Z2022-12-15T03:49:55Z13258
500*[+] popping root shell*.{0,1000}\[\+\]\spopping\sroot\sshell.{0,1000}offensive_tool_keywordPOCexploit the Linux Dirty Pipe vulnerabilityT1068 - T1078.003 - T1071.004 - T1072 - T1105TA0004 - TA0006?N/AN/APrivilege Escalationhttps://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits10#content #linuxN/A1065951482023-05-20T05:55:45Z2022-03-12T20:57:24Z13261
501*[+] Potenatially Hijackable DLL: *.{0,1000}\[\+\]\sPotenatially\sHijackable\sDLL\:\s.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10#contentN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z13262
502*[+] Rasman service is error*.{0,1000}\[\+\]\sRasman\sservice\sis\serror.{0,1000}offensive_tool_keywordRasmanPotatousing RasMan service for privilege escalationT1548.002 - T1055.002 - T1055.001 TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/crisprss/RasmanPotato10#contentN/A104371532023-02-06T10:27:41Z2023-02-06T09:41:51Z13276
503*[+] Rasman service is running!*.{0,1000}\[\+\]\sRasman\sservice\sis\srunning!.{0,1000}offensive_tool_keywordRasmanPotatousing RasMan service for privilege escalationT1548.002 - T1055.002 - T1055.001 TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/crisprss/RasmanPotato10#contentN/A104371532023-02-06T10:27:41Z2023-02-06T09:41:51Z13277
504*[+] Relaying seems successfull, check ntlmrelayx output!*.{0,1000}\[\+\]\sRelaying\sseems\ssuccessfull,\scheck\sntlmrelayx\soutput!.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z13283
505*[+] Run the spawn method for SYSTEM shell:*.{0,1000}\[\+\]\sRun\sthe\sspawn\smethod\sfor\sSYSTEM\sshell\:.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13290
506*[+] RUNNING ALL KNOWN EXPLOITS*.{0,1000}\[\+\]\sRUNNING\sALL\sKNOWN\sEXPLOITS.{0,1000}offensive_tool_keywordCoercedPotatoCoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.T1548.002 - T1134.002TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Prepouce/CoercedPotato10#contentN/A104366662024-08-26T08:09:00Z2023-09-11T19:04:29Z13291
507*[+] running normal privesc*.{0,1000}\[\+\]\srunning\snormal\sprivesc.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#content #linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z13292
508*[+] S4U2proxy success!*.{0,1000}\[\+\]\sS4U2proxy\ssuccess!.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13294
509*[+] S4U2proxy success!*.{0,1000}\[\+\]\sS4U2proxy\ssuccess!.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10#contentN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z13295
510*[+] S4U2self success!*.{0,1000}\[\+\]\sS4U2self\ssuccess!.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13296
511*[+] S4U2self success!*.{0,1000}\[\+\]\sS4U2self\ssuccess!.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10#contentN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z13297
512*[+] Sending S4U2proxy request to domain controller *.{0,1000}\[\+\]\sSending\sS4U2proxy\srequest\sto\sdomain\scontroller\s.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13304
513*[+] Sending S4U2proxy request via KDC proxy: *.{0,1000}\[\+\]\sSending\sS4U2proxy\srequest\svia\sKDC\sproxy\:\s.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13305
514*[+] Sending S4U2proxy request via KDC proxy:*.{0,1000}\[\+\]\sSending\sS4U2proxy\srequest\svia\sKDC\sproxy\:.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13306
515*[+] Sending S4U2self request to *.{0,1000}\[\+\]\sSending\sS4U2self\srequest\sto\s.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13307
516*[+] Sending S4U2self request via KDC proxy:*.{0,1000}\[\+\]\sSending\sS4U2self\srequest\svia\sKDC\sproxy\:.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#contentN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z13308
517*[+] Server connected to our evil RPC pipe*.{0,1000}\[\+\]\sServer\sconnected\sto\sour\sevil\sRPC\spipe.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10#contentN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z13311
518*[+] SeTcbPrivilege is enabled successfully*.{0,1000}\[\+\]\sSeTcbPrivilege\sis\senabled\ssuccessfully.{0,1000}offensive_tool_keywordPrivFuSeTcbPrivilege exploitationT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10#contentPrivFu\PowerOfTcb1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z13312
519*[+] SMB reflected DCOM authentication succeeded!*.{0,1000}\[\+\]\sSMB\sreflected\sDCOM\sauthentication\ssucceeded!.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10#contentN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z13321
520*[+] SMB reflected DCOM authentication succeeded!*.{0,1000}\[\+\]\sSMB\sreflected\sDCOM\sauthentication\ssucceeded!.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10#contentN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z13322
521*[+] Spawning root shell*.{0,1000}\[\+\]\sSpawning\sroot\sshell.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10#contentN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z13324
522*[+] Spawning SYSTEM shell*.{0,1000}\[\+\]\sSpawning\sSYSTEM\sshell.{0,1000}offensive_tool_keywordDirCreate2SystemWeaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error ReportingT1068 - T1059.001 - T1070.004TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/binderlabs/DirCreate2System10#contentN/A84357382022-12-19T17:00:43Z2022-12-15T03:49:55Z13325
523*[+] Stole token from*.{0,1000}\[\+\]\sStole\stoken\sfrom.{0,1000}offensive_tool_keywordGotatoGeneric impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.T1003.003 - T1056.002 - T1550.001 - T1090TA0005 - TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/iammaguire/Gotato10#contentN/A92112162021-06-07T21:19:58Z2021-06-05T22:32:48Z13331
524*[+] successfully breached the mainframe as real-PID *.{0,1000}\[\+\]\ssuccessfully\sbreached\sthe\smainframe\sas\sreal\-PID\s.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#content #linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z13339
525*[+] Successfully downloaded GPO from fakedc to *.{0,1000}\[\+\]\sSuccessfully\sdownloaded\sGPO\sfrom\sfakedc\sto\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10#contentN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z13342
526*[+] Successfully injected malicious scheduled task*.{0,1000}\[\+\]\sSuccessfully\sinjected\smalicious\sscheduled\stask.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10#contentN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z13346
527*[+] Successfully set the spool directory to: *.{0,1000}\[\+\]\sSuccessfully\sset\sthe\sspool\sdirectory\sto\:\s.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10#contentN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z13351
528*[+] Successfully spoofed gPLink for OU *.{0,1000}\[\+\]\sSuccessfully\sspoofed\sgPLink\sfor\sOU\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10#contentN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z13353
529*[+] Successfully updated extension names of fakedc GPO*.{0,1000}\[\+\]\sSuccessfully\supdated\sextension\snames\sof\sfakedc\sGPO.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10#contentN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z13354
530*[+] Successfully uploaded GPO to SMB server *.{0,1000}\[\+\]\sSuccessfully\suploaded\sGPO\sto\sSMB\sserver\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10#contentN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z13355
531*[+] Triggering name pipe access on evil PIPE *.{0,1000}\[\+\]\sTriggering\sname\spipe\saccess\son\sevil\sPIPE\s.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10#contentN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z13374
532*[+] User hash stolen!*.{0,1000}\[\+\]\sUser\shash\sstolen!.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z13387
533*[+] WOOT! Created elevated process *.{0,1000}\[\+\]\sWOOT!\sCreated\selevated\sprocess\s.{0,1000}offensive_tool_keywordSharpElevatorSharpElevator is a C# implementation of Elevator for UAC bypassT1548.002 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/SharpElevator10#contentN/A10151122022-08-31T18:09:10Z2022-08-29T19:52:53Z13420
534*[+]ImpersonateLoggedOnUser() succeed!*.{0,1000}\[\+\]ImpersonateLoggedOnUser\(\)\ssucceed!.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10#contentN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z13424
535*[winPEAS.Program]::Main(*.{0,1000}\[winPEAS\.Program\]\:\:Main\(.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z13521
536*\\.\pipe\coerced\pipe\spoolss*.{0,1000}\\\\\.\\pipe\\coerced\\pipe\\spoolss.{0,1000}offensive_tool_keywordCoercedPotatoRDLLReflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilegeT1055 - T1134 - T1548TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/sokaRepo/CoercedPotatoRDLL10#namedpipeN/A103204312023-11-23T18:58:41Z2023-11-23T13:22:38Z13585
537*\\.\pipe\PrivFu*.{0,1000}\\\\\.\\pipe\\PrivFu.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#namedpipeN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z13598
538*\\.\pipe\pwned/pipe/srvsvc*.{0,1000}\\\\\.\\pipe\\pwned\/pipe\/srvsvc.{0,1000}offensive_tool_keywordMultiPotatoget SYSTEM via SeImpersonate privilegesT1548.002 - T1134.002TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/S3cur3Th1sSh1t/MultiPotato10#namedpipeN/A106518922021-11-20T16:20:23Z2021-11-19T15:50:55Z13599
539*\\\\.\\pipe\\coerced\\pipe\\spoolss*.{0,1000}\\\\\\\\\.\\\\pipe\\\\coerced\\\\pipe\\\\spoolss.{0,1000}offensive_tool_keywordCoercedPotatoCoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.T1548.002 - T1134.002TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Prepouce/CoercedPotato10#namedpipeN/A104366662024-08-26T08:09:00Z2023-09-11T19:04:29Z13627
540*\\\\.\\pipe\\coerced\\pipe\\srvsvc*.{0,1000}\\\\\\\\\.\\\\pipe\\\\coerced\\\\pipe\\\\srvsvc.{0,1000}offensive_tool_keywordCoercedPotatoCoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.T1548.002 - T1134.002TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Prepouce/CoercedPotato10#namedpipeN/A104366662024-08-26T08:09:00Z2023-09-11T19:04:29Z13628
541*\\\\.\\pipe\\ElevationPipe*.{0,1000}\\\\\\\\\.\\\\pipe\\\\ElevationPipe.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10#namedpipeN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z13630
542*\\\\.\\pipe\\innocent*.{0,1000}\\\\\\\\\.\\\\pipe\\\\innocent.{0,1000}offensive_tool_keywordWindows_MSKSSRV_LPE_CVE-2023-36802Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POCT1068 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-3680210#namedpipeN/A102161382023-10-10T17:44:17Z2023-10-09T17:32:15Z13632
543*\\\\.\\pipe\\ioring_in*.{0,1000}\\\\\\\\\.\\\\pipe\\\\ioring_in.{0,1000}offensive_tool_keywordWindows_MSKSSRV_LPE_CVE-2023-36802Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POCT1068 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-3680210#namedpipeN/A102161382023-10-10T17:44:17Z2023-10-09T17:32:15Z13633
544*\\\\.\\pipe\\ioring_out*.{0,1000}\\\\\\\\\.\\\\pipe\\\\ioring_out.{0,1000}offensive_tool_keywordWindows_MSKSSRV_LPE_CVE-2023-36802Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POCT1068 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-3680210#namedpipeN/A102161382023-10-10T17:44:17Z2023-10-09T17:32:15Z13634
545*\\\\.\\pipe\\mal*.{0,1000}\\\\\\\\\.\\\\pipe\\\\mal.{0,1000}offensive_tool_keywordGotatoGeneric impersonation and privilege escalation with Golang. Like GenericPotato both named pipes and HTTP are supported.T1003.003 - T1056.002 - T1550.001 - T1090TA0005 - TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/iammaguire/Gotato10#namedpipeN/A92112162021-06-07T21:19:58Z2021-06-05T22:32:48Z13636
546*\\\\.\\pipe\\warpzone8*.{0,1000}\\\\\\\\\.\\\\pipe\\\\warpzone8.{0,1000}offensive_tool_keywordelevationstationelevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternativeT1548.002 - T1055 - T1574.002 - T1078.003TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/g3tsyst3m/elevationstation10#namedpipeN/AN/A4368452023-11-02T23:52:51Z2023-06-10T03:30:59Z13645
547*\\\\{attacker_ip}\\*.{0,1000}\\\\\\\\\{attacker_ip\}\\\\.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z13646
548*\\\\{coerce_to}\\*.{0,1000}\\\\\\\\\{coerce_to\}\\\\.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z13647
549*\\\\127.0.0.1\\pipe\\warpzone8*.{0,1000}\\\\\\\\127\.0\.0\.1\\\\pipe\\\\warpzone8.{0,1000}offensive_tool_keywordelevationstationelevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternativeT1548.002 - T1055 - T1574.002 - T1078.003TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/g3tsyst3m/elevationstation10#namedpipeN/AN/A4368452023-11-02T23:52:51Z2023-06-10T03:30:59Z13648
550*\\Debug\\Injected.dll*.{0,1000}\\\\Debug\\\\Injected\.dll.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z13654
551*\\HackSysExtremeVulnerableDriver*.{0,1000}\\\\HackSysExtremeVulnerableDriver.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z13663
552*\\localhost/pipe/petit\*.{0,1000}\\\\localhost\/pipe\/petit\\.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13664
553*\\pipe\\GodPotato*.{0,1000}\\\\pipe\\\\GodPotato.{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato10#namedpipeN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z13672
554*\\pipe\\petit\\pipe\\srvsvc*.{0,1000}\\\\pipe\\\\petit\\\\pipe\\\\srvsvc.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#namedpipeN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z13676
555*\\pipe\\RustPotato*.{0,1000}\\\\pipe\\\\RustPotato.{0,1000}offensive_tool_keywordRustPotatoA Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privilegesT1134.001 - T1055.011TA0004N/AN/APrivilege Escalationhttps://github.com/emdnaia/RustPotato10#content #namedpipeN/A101002025-01-06T18:10:17Z2025-01-06T19:44:57Z13677
556*\\pipe\\SigmaPotato*.{0,1000}\\\\pipe\\\\SigmaPotato.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato10#namedpipeN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z13678
557*\\Release\\Injected.dll*.{0,1000}\\\\Release\\\\Injected\.dll.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z13683
558*\\temp\\Injected.dll*.{0,1000}\\\\temp\\\\Injected\.dll.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z13689
559*\127.0.0.1/pipe/coerced*.{0,1000}\\127\.0\.0\.1\/pipe\/coerced.{0,1000}offensive_tool_keywordCoercedPotatoRDLLReflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilegeT1055 - T1134 - T1548TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/sokaRepo/CoercedPotatoRDLL10N/AN/A103204312023-11-23T18:58:41Z2023-11-23T13:22:38Z13715
560*\ACE_Get-KerberosTicketCache.ps1*.{0,1000}\\ACE_Get\-KerberosTicketCache\.ps1.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z13777
561*\ACEshark.log*.{0,1000}\\ACEshark\.log.{0,1000}offensive_tool_keywordACEsharkuncover potential privilege escalation vectors by analyzing windows service configurations and Access Control EntriesT1058 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/t3l3machus/ACEshark10#logfileN/A62109192025-01-15T07:01:48Z2024-12-28T10:42:29Z13779
562*\ACEshark.py*.{0,1000}\\ACEshark\.py.{0,1000}offensive_tool_keywordACEsharkuncover potential privilege escalation vectors by analyzing windows service configurations and Access Control EntriesT1058 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/t3l3machus/ACEshark10N/AN/A62109192025-01-15T07:01:48Z2024-12-28T10:42:29Z13780
563*\ADAPE.ps1*.{0,1000}\\ADAPE\.ps1.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script10N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z13791
564*\ADCSPwn*.{0,1000}\\ADCSPwn.{0,1000}offensive_tool_keywordADCSPwnA tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate serviceT1550.002 - T1078.003 - T1110.003 - T1649TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/bats3c/ADCSPwn10N/AN/A1098381272023-03-20T20:30:40Z2021-07-30T15:04:41Z13807
565*\addcomputer_LDAP_spn.py*.{0,1000}\\addcomputer_LDAP_spn\.py.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z13814
566*\addcomputer_with_spns.py*.{0,1000}\\addcomputer_with_spns\.py.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z13815
567*\AddUser.dll*.{0,1000}\\AddUser\.dll.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z13823
568*\AddUser.sln*.{0,1000}\\AddUser\.sln.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z13824
569*\adm2sys.py*.{0,1000}\\adm2sys\.py.{0,1000}offensive_tool_keywordPyExecThis is a very simple privilege escalation technique from admin to System. This is the same technique PSExec uses.T1134 - T1055 - T1548.002TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/OlivierLaflamme/PyExec10N/AN/A911172019-09-11T13:56:04Z2019-09-11T13:54:15Z13853
570*\AlwaysInstallElevated.cs*.{0,1000}\\AlwaysInstallElevated\.cs.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z13908
571*\BackgroundShell.exe*.{0,1000}\\BackgroundShell\.exe.{0,1000}offensive_tool_keywordPrivFuSeTcbPrivilege exploitationT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/APrivFu\PowerOfTcb1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z14199
572*\BackupOperatorToDA*.{0,1000}\\BackupOperatorToDA.{0,1000}offensive_tool_keywordBackupOperatorToDAFrom an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain ControllerT1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003TA0005 - TA0001 - TA0003N/AN/APrivilege Escalationhttps://github.com/mpgn/BackupOperatorToDA10N/AN/A105421532025-01-04T14:16:46Z2022-02-15T20:51:46Z14208
573*\BadPotato.csproj*.{0,1000}\\BadPotato\.csproj.{0,1000}offensive_tool_keywordBadPotatoWindows Privilege Escalation Exploit BadPotatoT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareEarth LuscaPrivilege Escalationhttps://github.com/BeichenDream/BadPotato10N/AN/A1098361362020-05-10T15:42:21Z2020-05-10T10:01:20Z14216
574*\BadPotato.exe*.{0,1000}\\BadPotato\.exe.{0,1000}offensive_tool_keywordBadPotatoWindows Privilege Escalation Exploit BadPotatoT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareEarth LuscaPrivilege Escalationhttps://github.com/BeichenDream/BadPotato10N/AN/A1098361362020-05-10T15:42:21Z2020-05-10T10:01:20Z14218
575*\BadWindowsService.cs*.{0,1000}\\BadWindowsService\.cs.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService10N/AN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z14224
576*\BadWindowsService.exe*.{0,1000}\\BadWindowsService\.exe.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService10N/AN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z14225
577*\BadWindowsService.sln*.{0,1000}\\BadWindowsService\.sln.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService10N/AN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z14226
578*\Bat-Potato.bat*.{0,1000}\\Bat\-Potato\.bat.{0,1000}signature_keywordBat-PotatoAutomating Juicy Potato Local Privilege Escalation CMD exploit for penetration testersT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/0x4xel/Bat-Potato10N/AN/A10142112022-12-13T20:19:51Z2022-12-12T20:50:22Z14276
579*\beRoot.exe*.{0,1000}\\beRoot\.exe.{0,1000}offensive_tool_keywordBeRootPrivilege Escalation Project - Windows / Linux / Mac T1068 - T1055 - T1078 - T1548 - T1003TA0004N/AN/APrivilege Escalationhttps://github.com/AlessandroZ/BeRoot10#linuxN/A101025234592024-10-04T11:54:01Z2017-04-14T12:47:31Z14287
580*\BITSInject.py*.{0,1000}\\BITSInject\.py.{0,1000}offensive_tool_keywordBITSInjectA one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM accountT1197TA0004N/AN/APrivilege Escalationhttps://github.com/SafeBreach-Labs/BITSInject10N/AN/A8199182019-08-24T22:02:12Z2017-07-03T12:39:38Z14323
581*\BITSInject-master*.{0,1000}\\BITSInject\-master.{0,1000}offensive_tool_keywordBITSInjectA one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM accountT1197TA0004N/AN/APrivilege Escalationhttps://github.com/SafeBreach-Labs/BITSInject10N/AN/A8199182019-08-24T22:02:12Z2017-07-03T12:39:38Z14324
582*\BITSJobPayloads.py*.{0,1000}\\BITSJobPayloads\.py.{0,1000}offensive_tool_keywordBITSInjectA one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM accountT1197TA0004N/AN/APrivilege Escalationhttps://github.com/SafeBreach-Labs/BITSInject10N/AN/A8199182019-08-24T22:02:12Z2017-07-03T12:39:38Z14325
583*\bypassuac.txt*.{0,1000}\\bypassuac\.txt.{0,1000}offensive_tool_keywordcobaltstrikeCollection of UAC Bypass Techniques Weaponized as BOFsT1548.002 - T1203 - T1055 - T1134.002TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/icyguider/UAC-BOF-Bonanza10N/AN/A106500652024-02-21T22:07:54Z2024-02-16T14:47:13Z14427
584*\C$\wh0nqs.txt.*.{0,1000}\\C\$\\wh0nqs\.txt\..{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z14432
585*\CachedGPPPassword.cs*.{0,1000}\\CachedGPPPassword\.cs.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z14455
586*\CoercedPotato.cpp*.{0,1000}\\CoercedPotato\.cpp.{0,1000}offensive_tool_keywordCoercedPotatoRDLLReflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilegeT1055 - T1134 - T1548TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/sokaRepo/CoercedPotatoRDLL10N/AN/A103204312023-11-23T18:58:41Z2023-11-23T13:22:38Z14573
587*\Crassus-main*.{0,1000}\\Crassus\-main.{0,1000}offensive_tool_keywordCrassusCrassus Windows privilege escalation discovery toolT1068 - T1003 - T1003.003 - T1046TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/vu-ls/Crassus10N/AN/A106571592024-11-08T14:11:39Z2023-01-12T21:01:52Z14647
588*\CreateTokenVariant.exe*.{0,1000}\\CreateTokenVariant\.exe.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z14655
589*\CurrentControlSet\Services\BadWindowsService*.{0,1000}\\CurrentControlSet\\Services\\BadWindowsService.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService10#registryN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z14711
590*\CVE-2024-49138-POC-main*.{0,1000}\\CVE\-2024\-49138\-POC\-main.{0,1000}offensive_tool_keywordPOCWindows Privilege escalation POC exploitation for CVE-2024-49138T1068 - T1058 - T1203TA0004N/AN/APrivilege Escalationhttps://github.com/emdnaia/CVE-2024-49138-POC10N/AN/A91102025-01-15T01:01:21Z2025-01-15T02:11:49Z14752
591*\DeadPotato\pipe\epmapper*.{0,1000}\\DeadPotato\\pipe\\epmapper.{0,1000}offensive_tool_keywordDeadPotatoDeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privilegesT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011N/AN/APrivilege Escalationhttps://github.com/lypd0/DeadPotato10#namedpipeN/A104382452024-08-17T06:08:29Z2024-07-31T01:08:30Z14836
592*\Debug\Injected.dll*.{0,1000}\\Debug\\Injected\.dll.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z14838
593*\DesktopShell.exe*.{0,1000}\\DesktopShell\.exe.{0,1000}offensive_tool_keywordPrivFuSeTcbPrivilege exploitationT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/APrivFu\PowerOfTcb1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z14912
594*\dircreate2system.pdb*.{0,1000}\\dircreate2system\.pdb.{0,1000}offensive_tool_keywordDirCreate2SystemWeaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error ReportingT1068 - T1059.001 - T1070.004TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/binderlabs/DirCreate2System10N/AN/A84357382022-12-19T17:00:43Z2022-12-15T03:49:55Z14936
595*\dircreate2system.sln*.{0,1000}dircreate2system\.sln.{0,1000}offensive_tool_keywordDirCreate2SystemWeaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error ReportingT1068 - T1059.001 - T1070.004TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/binderlabs/DirCreate2System10N/AN/A84357382022-12-19T17:00:43Z2022-12-15T03:49:55Z14937
596*\DirCreate2System\bin\*.{0,1000}\\DirCreate2System\\bin\\.{0,1000}offensive_tool_keywordDirCreate2SystemWeaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error ReportingT1068 - T1059.001 - T1070.004TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/binderlabs/DirCreate2System10N/AN/A84357382022-12-19T17:00:43Z2022-12-15T03:49:55Z14938
597*\DirtyCLR.sln*.{0,1000}\\DirtyCLR\.sln.{0,1000}offensive_tool_keywordDirtyCLRAn App Domain Manager Injection DLL PoCT1055.001 - T1546.016 - T1055.013TA0005 - TA0004N/ABlack BastaPrivilege Escalationhttps://github.com/ipSlav/DirtyCLR10N/AN/A72170192023-12-14T21:22:12Z2023-12-11T11:29:36Z14943
598*\DirtyCLR-main*.{0,1000}\\DirtyCLR\-main.{0,1000}offensive_tool_keywordDirtyCLRAn App Domain Manager Injection DLL PoCT1055.001 - T1546.016 - T1055.013TA0005 - TA0004N/ABlack BastaPrivilege Escalationhttps://github.com/ipSlav/DirtyCLR10N/AN/A72170192023-12-14T21:22:12Z2023-12-11T11:29:36Z14944
599*\DomainGPPPassword.cs*.{0,1000}\\DomainGPPPassword\.cs.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z15024
600*\elevateit.bat*.{0,1000}\\elevateit\.bat.{0,1000}offensive_tool_keywordelevationstationelevate to SYSTEM any way we can! Metasploit and PSEXEC getsystem alternativeT1548.002 - T1055 - T1574.002 - T1078.003TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/g3tsyst3m/elevationstation10N/AN/AN/A4368452023-11-02T23:52:51Z2023-06-10T03:30:59Z15254
601*\elevator.exe -*.{0,1000}\\elevator\.exe\s\-.{0,1000}offensive_tool_keywordElevatorUAC bypass by abusing RPC and debug objects.T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Kudaes/Elevator10N/AN/A107614692023-10-19T08:51:09Z2022-08-25T21:39:28Z15255
602*\Elevator\target\release*.{0,1000}\\Elevator\\target\\release.{0,1000}offensive_tool_keywordElevatorUAC bypass by abusing RPC and debug objects.T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Kudaes/Elevator10N/AN/A107614692023-10-19T08:51:09Z2022-08-25T21:39:28Z15256
603*\evil.dll*.{0,1000}\\evil\.dll.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10N/AN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z15335
604*\exploit.c.{0,1000}\\exploit\.coffensive_tool_keywordWindows_MSKSSRV_LPE_CVE-2023-36802Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POCT1068 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-3680210N/AN/A102161382023-10-10T17:44:17Z2023-10-09T17:32:15Z15389
605*\exploit.exe*.{0,1000}\\exploit\.exe.{0,1000}offensive_tool_keywordWindows_MSKSSRV_LPE_CVE-2023-36802Complete exploit works on vulnerable Windows 11 22H2 systems CVE-2023-36802 Local Privilege Escalation POCT1068 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/chompie1337/Windows_MSKSSRV_LPE_CVE-2023-3680210N/AN/A102161382023-10-10T17:44:17Z2023-10-09T17:32:15Z15392
606*\ExploitableSystem.txt*.{0,1000}\\ExploitableSystem\.txt.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script10N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z15394
607*\Godpotato\*.{0,1000}\\Godpotato\\.{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato10N/AN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z15661
608*\GodPotato\pipe\epmapper*.{0,1000}\\GodPotato\\pipe\\epmapper.{0,1000}offensive_tool_keywordDeadPotatoDeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privilegesT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011N/AN/APrivilege Escalationhttps://github.com/lypd0/DeadPotato10#namedpipeN/A104382452024-08-17T06:08:29Z2024-07-31T01:08:30Z15662
609*\gtfonow.py*.{0,1000}\\gtfonow\.py.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10N/AN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z15746
610*\HijackablePaths.cs*.{0,1000}\\HijackablePaths\.cs.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z15796
611*\IDiagnosticProfileUAC*.{0,1000}\\IDiagnosticProfileUAC.{0,1000}offensive_tool_keywordIDiagnosticProfileUACUAC bypass using auto-elevated COM object Virtual Factory for DiagCplT1548.002 - T1059.003 - T1027.002TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/Wh04m1001/IDiagnosticProfileUAC10N/AN/A102182322022-07-02T20:31:47Z2022-07-02T19:55:42Z15872
612*\Ikeext-Privesc*.{0,1000}\\Ikeext\-Privesc.{0,1000}offensive_tool_keywordIkeext-PrivescWindows IKEEXT DLL Hijacking Exploit ToolT1546.011 - T1574.009 - T1036.004TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/securycore/Ikeext-Privesc10N/AN/A10133522018-02-25T13:45:15Z2018-02-27T11:18:56Z15884
613*\JuicyPotato.exe*.{0,1000}\\JuicyPotato\.exe.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10N/AN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z16038
614*\JuicyPotato.pdb*.{0,1000}\\JuicyPotato\.pdb.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/jakobfriedl/precompiled-binaries10N/AN/A102138382025-03-06T13:02:11Z2023-08-08T12:21:46Z16039
615*\JuicyPotato.pdb*.{0,1000}\\JuicyPotato\.pdb.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10#contentN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z16040
616*\JuicyPotato_x32.exe*.{0,1000}\\JuicyPotato_x32\.exe.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10N/AN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z16045
617*\JuicyPotato_x64.exe*.{0,1000}\\JuicyPotato_x64\.exe.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10N/AN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z16046
618*\JuicyPotato-master*.{0,1000}\\JuicyPotato\-master.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10N/AN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z16047
619*\JuicyPotatoNG*.{0,1000}\\JuicyPotatoNG.{0,1000}offensive_tool_keywordJuicyPotatoNGAnother Windows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AFoxKitten - APT33 - Volatile Cedar - SandwormPrivilege Escalationhttps://github.com/antonioCoco/JuicyPotatoNG10N/AN/A1098441012022-11-12T01:48:39Z2022-09-21T17:08:35Z16048
620*\JuicyPotato-shellcode\*.{0,1000}\\JuicyPotato\-shellcode\\.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10N/AN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z16049
621*\Juicy-Potato-x86-master*.{0,1000}\\Juicy\-Potato\-x86\-master.{0,1000}offensive_tool_keywordBat-PotatoAutomating Juicy Potato Local Privilege Escalation CMD exploit for penetration testersT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/0x4xel/Bat-Potato10N/AN/A10142112022-12-13T20:19:51Z2022-12-12T20:50:22Z16050
622*\KernelTokens.sys*.{0,1000}\\KernelTokens\.sys.{0,1000}offensive_tool_keywordTokenvatorA tool to elevate privilege with Windows TokensT1134 - T1078TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/0xbadjuju/Tokenvator10N/AN/AN/A1010382012023-10-06T13:17:05Z2017-12-08T01:29:11Z16113
623*\KExecDD-main*.{0,1000}\\KExecDD\-main.{0,1000}offensive_tool_keywordKExecDDAdmin to Kernel code execution using the KSecDD driverT1068 - T1055.011TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/floesen/KExecDD10N/AN/A83244412024-04-19T09:58:14Z2024-04-19T08:54:49Z16114
624*\KrbRelayUp.lib*.{0,1000}\\KrbRelayUp\.lib.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z16180
625*\KrbSCM.cs*.{0,1000}\\KrbSCM\.cs.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z16181
626*\LocalAdminSharp.sln*.{0,1000}\\LocalAdminSharp\.sln.{0,1000}offensive_tool_keywordLocalAdminSharp.NET executable to use when dealing with privilege escalation on Windows to gain local administrator accessT1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004TA0004N/AN/APrivilege Escalationhttps://github.com/notdodo/LocalAdminSharp10N/AN/A102157172022-11-01T17:45:43Z2022-01-01T10:35:09Z16328
627*\LocalPotato\*.cpp*.{0,1000}\\LocalPotato\\.{0,1000}\.cpp.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10N/AN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z16332
628*\LocalPotato\*.exe*.{0,1000}\\LocalPotato\\.{0,1000}\.exe.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10N/AN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z16333
629*\MakeMeAdmin * x64 Debug.msi*.{0,1000}\\MakeMeAdmin\s.{0,1000}\sx64\sDebug\.msi.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z16436
630*\MakeMeAdmin * x64.msi*.{0,1000}\\MakeMeAdmin\s.{0,1000}\sx64\.msi.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z16437
631*\MakeMeAdmin.sln*.{0,1000}\\MakeMeAdmin\.sln.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z16438
632*\MakeMeAdmin-main*.{0,1000}\\MakeMeAdmin\-main.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z16439
633*\MakeMeEnterpriseAdmin.ps1.{0,1000}\\MakeMeEnterpriseAdmin\.ps1offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z16440
634*\MakeMeEnterpriseAdmin.ps1*.{0,1000}\\MakeMeEnterpriseAdmin\.ps1.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z16441
635*\modifiableautorun.o*.{0,1000}\\modifiableautorun\.o.{0,1000}offensive_tool_keywordPrivKitPrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.T1548.002 - T1059.003 - T1027.002TA0005N/AN/APrivilege Escalationhttps://github.com/mertdas/PrivKit10N/AN/A95405472024-06-15T16:54:32Z2023-03-20T04:19:40Z16649
636*\MSFRottenPotato.cpp*.{0,1000}\\MSFRottenPotato\.cpp.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10N/AN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z16673
637*\MSFRottenPotato.log*.{0,1000}\\MSFRottenPotato\.log.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10N/AN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z16675
638*\MSFRottenPotato.sln*.{0,1000}\\MSFRottenPotato\.sln.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10N/AN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z16676
639*\MSFRottenPotatoTestHarness.*.{0,1000}\\MSFRottenPotatoTestHarness\..{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10N/AN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z16677
640*\NamedPipeClient.exe*.{0,1000}\\NamedPipeClient\.exe.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z16719
641*\NamedPipeClient.exe*.{0,1000}\\NamedPipeClient\.exe.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z16720
642*\NoFilter.cpp*.{0,1000}\\NoFilter\.cpp.{0,1000}offensive_tool_keywordNoFilterTool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.T1548 - T1548.002 - T1055 - T1055.004TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/deepinstinct/NoFilter10N/AN/A93298482024-10-29T07:30:35Z2023-07-30T09:25:38Z16945
643*\NoFilter.exe*.{0,1000}\\NoFilter\.exe.{0,1000}offensive_tool_keywordNoFilterTool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.T1548 - T1548.002 - T1055 - T1055.004TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/deepinstinct/NoFilter10N/AN/A93298482024-10-29T07:30:35Z2023-07-30T09:25:38Z16946
644*\NoFilter.sln*.{0,1000}\\NoFilter\.sln.{0,1000}offensive_tool_keywordNoFilterTool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.T1548 - T1548.002 - T1055 - T1055.004TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/deepinstinct/NoFilter10N/AN/A93298482024-10-29T07:30:35Z2023-07-30T09:25:38Z16947
645*\NoFilter.vcxproj*.{0,1000}\\NoFilter\.vcxproj.{0,1000}offensive_tool_keywordNoFilterTool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.T1548 - T1548.002 - T1055 - T1055.004TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/deepinstinct/NoFilter10N/AN/A93298482024-10-29T07:30:35Z2023-07-30T09:25:38Z16948
646*\NTLMRelay2Self*.{0,1000}\\NTLMRelay2Self.{0,1000}offensive_tool_keywordNTLMRelay2SelfAn other No-Fix LPE - NTLMRelay2Self over HTTP (Webdav).T1078 - T1078.004 - T1557 - T1557.001 - T1068TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/med0x2e/NTLMRelay2Self10N/AN/A105400422024-01-27T08:52:03Z2022-04-30T10:05:02Z16995
647*\NtRights\*.{0,1000}\\NtRights\\.{0,1000}offensive_tool_keywordNtRightstool for adding privileges from the commandlineT1548.002 - T1059.003 - T1027.002TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/gtworek/PSBits/tree/master/NtRights10N/AN/A71033375422025-03-12T19:59:23Z2019-06-29T13:22:36Z17007
648*\OfficeInjector.exe*.{0,1000}\\OfficeInjector\.exe.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z17034
649*\ouned_smbserver.py*.{0,1000}\\ouned_smbserver\.py.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z17062
650*\PEASS-ng*.{0,1000}\\PEASS\-ng.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z17180
651*\Perfusion.cpp*.{0,1000}\\Perfusion\.cpp.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion10N/AN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z17185
652*\Perfusion.exe*.{0,1000}\\Perfusion\.exe.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion10N/AN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z17186
653*\Perfusion.sln*.{0,1000}\\Perfusion\.sln.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion10N/AN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z17187
654*\PerfusionDll.cpp*.{0,1000}\\PerfusionDll\.cpp.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion10N/AN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z17188
655*\PerfusionDll.dll*.{0,1000}\\PerfusionDll\.dll.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion10N/AN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z17189
656*\PerfusionDll.log*.{0,1000}\\PerfusionDll\.log.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion10N/AN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z17190
657*\petit\pipe\srvsvc*.{0,1000}\\petit\\pipe\\srvsvc.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10#namedpipeN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17218
658*\PetitPotato.cpp*.{0,1000}\\PetitPotato\.cpp.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17221
659*\PetitPotato.log*.{0,1000}\\PetitPotato\.log.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17222
660*\petitpotato.obj*.{0,1000}\\petitpotato\.obj.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17223
661*\petitpotato.pdb*.{0,1000}\\petitpotato\.pdb.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17224
662*\PetitPotato.sln*.{0,1000}\\PetitPotato\.sln.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17225
663*\PetitPotato.tlog*.{0,1000}\\PetitPotato\.tlog.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17226
664*\PetitPotato.vcxproj*.{0,1000}\\PetitPotato\.vcxproj.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17227
665*\petitpotato\x64\*.{0,1000}\\petitpotato\\x64\\.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17228
666*\PetitPotato-1.0.0.zip*.{0,1000}\\PetitPotato\-1\.0\.0\.zip.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17229
667*\PetitPotato-1.0.0\*.{0,1000}\\PetitPotato\-1\.0\.0\\.{0,1000}offensive_tool_keywordPetitPotatoLocal privilege escalation via PetitPotam (Abusing impersonate privileges)T1134.005 - T1548.001TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/wh0amitz/PetitPotato10N/AN/A105430522023-03-30T10:45:00Z2022-04-19T19:59:19Z17230
668*\pipe\ElevationPipe*.{0,1000}\\pipe\\ElevationPipe.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10#namedpipeN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z17270
669*\pipe\GodPotato*.{0,1000}\\pipe\\GodPotato.{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato10#namedpipeN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z17271
670*\pipe\RustPotato*.{0,1000}\\pipe\\RustPotato.{0,1000}offensive_tool_keywordRustPotatoA Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privilegesT1134.001 - T1055.011TA0004N/AN/APrivilege Escalationhttps://github.com/emdnaia/RustPotato10#content #namedpipeN/A101002025-01-06T18:10:17Z2025-01-06T19:44:57Z17279
671*\pipe\SigmaPotato*.{0,1000}\\pipe\\SigmaPotato.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato10#namedpipeN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z17280
672*\PoC\PrivilegeEscalation*.{0,1000}\\PoC\\PrivilegeEscalation.{0,1000}offensive_tool_keywordechoac-pocpoc stealing the Kernel's KPROCESS/EPROCESS block and writing it to a newly spawned shell to elevate its privileges to the highest possible - nt authority\systemT1068 - T1203 - T1059.003TA0002 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/kite03/echoac-poc10N/AN/A82138252024-01-09T16:44:00Z2023-06-28T00:52:22Z17309
673*\Potato.exe*.{0,1000}\\Potato\.exe.{0,1000}offensive_tool_keywordpotatoPotato Privilege Escalation on WindowsT1134.001 - T1068 - T1055 - T1546.015TA0004N/AN/APrivilege Escalationhttps://github.com/foxglovesec/Potato10N/AN/A787211652021-01-16T20:34:04Z2016-02-09T11:28:17Z17349
674*\Potato\obj\Release\Potato.pdb*.{0,1000}\\Potato\\obj\\Release\\Potato\.pdb.{0,1000}offensive_tool_keywordpotatoPotato Privilege Escalation on WindowsT1134.001 - T1068 - T1055 - T1546.015TA0004N/AN/APrivilege Escalationhttps://github.com/foxglovesec/Potato10#contentN/A787211652021-01-16T20:34:04Z2016-02-09T11:28:17Z17350
675*\PotatoTrigger.cpp*.{0,1000}PotatoTrigger\.cpp.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10N/AN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z17351
676*\Powermad.ps1*.{0,1000}\\Powermad\.ps1.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z17374
677*\prefetch_leak.h*.{0,1000}\\prefetch_leak\.h.{0,1000}offensive_tool_keywordprefetch-toolWindows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitationT1564.007TA0004N/AN/APrivilege Escalationhttps://github.com/exploits-forsale/prefetch-tool10N/AN/A8190102024-04-26T05:40:32Z2024-04-26T05:00:27Z17444
678*\prefetch_tool.sln*.{0,1000}\\prefetch_tool\.sln.{0,1000}offensive_tool_keywordprefetch-toolWindows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitationT1564.007TA0004N/AN/APrivilege Escalationhttps://github.com/exploits-forsale/prefetch-tool10N/AN/A8190102024-04-26T05:40:32Z2024-04-26T05:00:27Z17445
679*\prefetch_tool.vcxproj*.{0,1000}\\prefetch_tool\.vcxproj.{0,1000}offensive_tool_keywordprefetch-toolWindows KASLR bypass using prefetch side-channel CVE-2024-21345 exploitationT1564.007TA0004N/AN/APrivilege Escalationhttps://github.com/exploits-forsale/prefetch-tool10N/AN/A8190102024-04-26T05:40:32Z2024-04-26T05:00:27Z17446
680*\PrintNightmare.*.{0,1000}\\PrintNightmare\..{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/outflanknl/PrintNightmare10N/AN/A104337672021-09-13T08:45:26Z2021-09-13T08:44:02Z17456
681*\PrintSpoofer.cs*.{0,1000}\\PrintSpoofer\.cs.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z17458
682*\PrintSpoofer.exe*.{0,1000}\\PrintSpoofer\.exe.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z17465
683*\PrintSpoofer-1.0.zip*.{0,1000}\\PrintSpoofer\-1\.0\.zip.{0,1000}offensive_tool_keywordprintspooferAbusing impersonation privileges through the Printer BugT1134 - T1003 - T1055TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/PrintSpoofer10N/AN/A101019713422020-09-10T17:49:41Z2020-04-28T08:26:29Z17466
684*\PrivEditor.dll*.{0,1000}\\PrivEditor\.dll.{0,1000}offensive_tool_keywordPrivFuKernel Mode WinDbg extension for token privilege editT1055 - T1078 - T1134TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z17467
685*\PrivEditor\*.{0,1000}\\PrivEditor\\.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z17468
686*\privesc.ps1*.{0,1000}\\privesc\.ps1.{0,1000}offensive_tool_keywordPrivescWindows PowerShell script that finds misconfiguration issues which can lead to privilege escalationT1068 - T1548 - T1082 - T1078TA0004N/AN/APrivilege Escalationhttps://github.com/enjoiz/Privesc10N/AN/A106595972024-12-01T15:24:41Z2015-11-19T13:22:01Z17469
687*\PrivEsc.txt*.{0,1000}\\PrivEsc\.txt.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script10N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z17470
688*\PrivescCheck*.{0,1000}\\PrivescCheck.{0,1000}offensive_tool_keywordPrivescCheckPrivilege Escalation Enumeration Script for WindowsT1053 - T1088TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrivescCheck10N/AN/A101032304602025-03-05T14:44:17Z2020-01-16T12:28:10Z17471
689*\PrivescCheck_*.{0,1000}\\PrivescCheck_.{0,1000}offensive_tool_keywordPrivescCheckPrivilege Escalation Enumeration Script for WindowsT1053 - T1088TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrivescCheck10N/AN/A101032304602025-03-05T14:44:17Z2020-01-16T12:28:10Z17473
690*\PrivescCheck_*.{0,1000}\\PrivescCheck_.{0,1000}offensive_tool_keywordPrivescCheckPrivilege Escalation Enumeration Script for WindowsT1053 - T1088TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrivescCheck10N/AN/A101032304602025-03-05T14:44:17Z2020-01-16T12:28:10Z17474
691*\Privesc-master*.{0,1000}\\Privesc\-master.{0,1000}offensive_tool_keywordPrivescWindows PowerShell script that finds misconfiguration issues which can lead to privilege escalationT1068 - T1548 - T1082 - T1078TA0004N/AN/APrivilege Escalationhttps://github.com/enjoiz/Privesc10N/AN/A106595972024-12-01T15:24:41Z2015-11-19T13:22:01Z17475
692*\PrivFu.txt*.{0,1000}\\PrivFu\.txt.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z17477
693*\PrivKit\*.{0,1000}\\PrivKit\\.{0,1000}offensive_tool_keywordPrivKitPrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.T1548.002 - T1059.003 - T1027.002TA0005N/AN/APrivilege Escalationhttps://github.com/mertdas/PrivKit10N/AN/A95405472024-06-15T16:54:32Z2023-03-20T04:19:40Z17479
694*\ProcessDLLHijack.cs*.{0,1000}\\ProcessDLLHijack\.cs.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z17485
695*\ProcessSpoofing.h*.{0,1000}\\ProcessSpoofing\.h.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z17487
696*\Program Files\Bad Windows Service*.{0,1000}\\Program\sFiles\\Bad\sWindows\sService.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService10N/AN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z17514
697*\psgetsys.ps1*.{0,1000}\\psgetsys\.ps1.{0,1000}offensive_tool_keywordpsgetsystemgetsystem via parent process using ps1 & embeded c#T1134 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/decoder-it/psgetsystem10N/AN/A105406882023-10-26T07:13:08Z2018-02-02T11:28:22Z17608
698*\RasMan.cpp*.{0,1000}RasMan\.cpp.{0,1000}offensive_tool_keywordRasmanPotatousing RasMan service for privilege escalationT1548.002 - T1055.002 - T1055.001 TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/crisprss/RasmanPotato10N/AN/A104371532023-02-06T10:27:41Z2023-02-06T09:41:51Z17745
699*\rasman.exe*.{0,1000}\\rasman\.exe.{0,1000}offensive_tool_keywordRasmanPotatousing RasMan service for privilege escalationT1548.002 - T1055.002 - T1055.001 TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/crisprss/RasmanPotato10N/AN/A104371532023-02-06T10:27:41Z2023-02-06T09:41:51Z17746
700*\RasMan.sln*.{0,1000}RasMan\.sln.{0,1000}offensive_tool_keywordRasmanPotatousing RasMan service for privilege escalationT1548.002 - T1055.002 - T1055.001 TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/crisprss/RasmanPotato10N/AN/A104371532023-02-06T10:27:41Z2023-02-06T09:41:51Z17747
701*\RasmanPotato*.{0,1000}\\RasmanPotato.{0,1000}offensive_tool_keywordRasmanPotatousing RasMan service for privilege escalationT1548.002 - T1055.002 - T1055.001 TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/crisprss/RasmanPotato10N/AN/A104371532023-02-06T10:27:41Z2023-02-06T09:41:51Z17748
702*\Relay\Attacks\ShadowCred.cs*.{0,1000}\\Relay\\Attacks\\ShadowCred\.cs.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10N/AN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z17894
703*\Release\Injected.dll*.{0,1000}\\Release\\Injected\.dll.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z17898
704*\Release\SpoolFool.pdb*.{0,1000}\\Release\\SpoolFool\.pdb.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z17902
705*\RemotePotato0.cpp*.{0,1000}\\RemotePotato0\.cpp.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z18005
706*\RemotePotato0.sln*.{0,1000}\\RemotePotato0\.sln.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z18006
707*\RemotePotato0.zip*.{0,1000}\\RemotePotato0\.zip.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z18007
708*\RemotePotato0-main.zip*.{0,1000}\\RemotePotato0\-main\.zip.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z18008
709*\RemotePotato0-main\*.{0,1000}\\RemotePotato0\-main\\.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z18009
710*\Resources\mimikatz.exe*.{0,1000}\\Resources\\mimikatz\.exe.{0,1000}offensive_tool_keywordDeadPotatoDeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privilegesT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011N/AN/APrivilege Escalationhttps://github.com/lypd0/DeadPotato10N/AN/A104382452024-08-17T06:08:29Z2024-07-31T01:08:30Z18026
711*\RogueOxidResolver.cpp*.{0,1000}\\RogueOxidResolver\.cpp.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010N/AN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z18090
712*\RogueWinRM.sln*.{0,1000}\\RogueWinRM\.sln.{0,1000}offensive_tool_keywordRogueWinRMRogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not runningT1548.003 - T1134.002 - T1055TA0004N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RogueWinRM10N/AN/A1087881072020-02-23T19:26:41Z2019-12-02T22:58:03Z18091
713*\RogueWinRM\*.{0,1000}\\RogueWinRM\\.{0,1000}offensive_tool_keywordRogueWinRMRogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not runningT1548.003 - T1134.002 - T1055TA0004N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RogueWinRM10N/AN/A1087881072020-02-23T19:26:41Z2019-12-02T22:58:03Z18092
714*\RottenPotatoNG-main*.{0,1000}\\RottenPotatoNG\-main.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10N/AN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z18107
715*\RottenPotatoNG-master*.{0,1000}\\RottenPotatoNG\-master.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10N/AN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z18108
716*\RustPotato-main*.{0,1000}\\RustPotato\-main.{0,1000}offensive_tool_keywordRustPotatoA Rust implementation of GodPotato - abusing SeImpersonate to gain SYSTEM privilegesT1134.001 - T1055.011TA0004N/AN/APrivilege Escalationhttps://github.com/emdnaia/RustPotato10N/AN/A101002025-01-06T18:10:17Z2025-01-06T19:44:57Z18237
717*\S4U.Exe*.{0,1000}\\S4U\.Exe.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z18246
718*\S4uDelegator.*.{0,1000}\\S4uDelegator\..{0,1000}offensive_tool_keywordPrivFuperform S4U logon with SeTcbPrivilegeT1134TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AS4uDelegator1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z18247
719*\S4UTomato\*.{0,1000}\\S4UTomato\\.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z18248
720*\SeAuditPrivilegePoC.exe*.{0,1000}\\SeAuditPrivilegePoC\.exe.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z18343
721*\SeBackupPrivilegePoC.exe*.{0,1000}\\SeBackupPrivilegePoC\.exe.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z18344
722*\SecondaryLogonVariant.exe*.{0,1000}\\SecondaryLogonVariant\.exe.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z18345
723*\SeRestorePrivilegeTestFile.txt*.{0,1000}\\SeRestorePrivilegeTestFile\.txt.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z18355
724*\ShadowCredentials.cs*.{0,1000}\\ShadowCredentials\.cs.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z18402
725*\ShareFinder.txt*.{0,1000}\\ShareFinder\.txt.{0,1000}offensive_tool_keywordADAPE-ScriptActive Directory Assessment and Privilege Escalation ScriptT1178 - T1087 - T1482TA0002 - TA0004 - TA0007N/ABlack BastaPrivilege Escalationhttps://github.com/cjoan75/ADAPE-Script10N/AN/A81002020-07-11T00:53:24Z2020-08-09T16:52:35Z18421
726*\SharpEfsPotato*.{0,1000}\\SharpEfsPotato.{0,1000}offensive_tool_keywordSharpEfsPotatoLocal privilege escalation from SeImpersonatePrivilege using EfsRpc.T1548.002 - T1134.002TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/bugch3ck/SharpEfsPotato10N/AN/A104317462022-10-17T12:35:06Z2022-10-17T12:20:47Z18526
727*\SharpElevator.cs*.{0,1000}\\SharpElevator\.cs.{0,1000}offensive_tool_keywordSharpElevatorSharpElevator is a C# implementation of Elevator for UAC bypassT1548.002 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/SharpElevator10N/AN/A10151122022-08-31T18:09:10Z2022-08-29T19:52:53Z18529
728*\SharpElevator.exe*.{0,1000}\\SharpElevator\.exe.{0,1000}offensive_tool_keywordSharpElevatorSharpElevator is a C# implementation of Elevator for UAC bypassT1548.002 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/SharpElevator10N/AN/A10151122022-08-31T18:09:10Z2022-08-29T19:52:53Z18530
729*\SharpElevator.sln*.{0,1000}\\SharpElevator\.sln.{0,1000}offensive_tool_keywordSharpElevatorSharpElevator is a C# implementation of Elevator for UAC bypassT1548.002 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/SharpElevator10N/AN/A10151122022-08-31T18:09:10Z2022-08-29T19:52:53Z18531
730*\SharpUp.csproj*.{0,1000}\\SharpUp\.csproj.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z18732
731*\SharpUp.sln*.{0,1000}SharpUp.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z18739
732*\SharpUp\*.{0,1000}\\SharpUp\\.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z18740
733*\SharpUp-master*.{0,1000}\\SharpUp\-master.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z18741
734*\ShimInjector.cpp*.{0,1000}\\ShimInjector\.cpp.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z18802
735*\ShimInjector.cpp*.{0,1000}\\ShimInjector\.cpp.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z18803
736*\ShimInjector.exe*.{0,1000}\\ShimInjector\.exe.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z18804
737*\SigmaPotato.csproj*.{0,1000}\\SigmaPotato\.csproj.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato10N/AN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z18818
738*\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\TelemetryController\fun*.{0,1000}\\SOFTWARE\\Microsoft\\Windows\sNT\\CurrentVersion\\AppCompatFlags\\TelemetryController\\fun.{0,1000}offensive_tool_keywordTelemetryAbusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges.T1053 - T1547 - T1059TA0003 - TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/Imanfeng/Telemetry10#registryN/A92140132020-07-02T09:41:27Z2020-06-24T16:30:44Z18963
739*\SOFTWARE\Policies\Sinclair Community College\Make Me Admin*.{0,1000}\\SOFTWARE\\Policies\\Sinclair\sCommunity\sCollege\\Make\sMe\sAdmin.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10#registryN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z18970
740*\SOFTWARE\Sinclair Community College\Make Me Admin*.{0,1000}\\SOFTWARE\\Sinclair\sCommunity\sCollege\\Make\sMe\sAdmin.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10#registryN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z18971
741*\SpoolFool.exe*.{0,1000}\\SpoolFool\.exe.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z19053
742*\SpoolFool.ps1*.{0,1000}\\SpoolFool\.ps1.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z19054
743*\SpoolFool.sln*.{0,1000}\\SpoolFool\.sln.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z19055
744*\SpoolFool-main*.{0,1000}\\SpoolFool\-main.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z19056
745*\src\check\Credentials.ps1*.{0,1000}\\src\\check\\Credentials\.ps1.{0,1000}offensive_tool_keywordPrivescCheckPrivilege Escalation Enumeration Script for WindowsT1053 - T1088TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrivescCheck10N/AN/A101032304602025-03-05T14:44:17Z2020-01-16T12:28:10Z19079
746*\Sweetpotato.exe*.{0,1000}\\Sweetpotato\.exe.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z19189
747*\SweetPotato\Program.cs*.{0,1000}\\SweetPotato\\Program\.cs.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z19190
748*\SweetPotato-master.zip*.{0,1000}\\SweetPotato\-master\.zip.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10N/AN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z19191
749*\SwitchPriv.exe*.{0,1000}\\SwitchPriv\.exe.{0,1000}offensive_tool_keywordPrivFuenable or disable specific token privileges for a processT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/ASwitchPriv1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19192
750*\SwitchPriv.sln*.{0,1000}\\SwitchPriv\.sln.{0,1000}offensive_tool_keywordPrivFuenable or disable specific token privileges for a processT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/ASwitchPriv1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19193
751*\temp\Injected.dll*.{0,1000}\\temp\\Injected\.dll.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10N/AN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z19290
752*\TokenAssignor.exe*.{0,1000}\\TokenAssignor\.exe.{0,1000}offensive_tool_keywordPrivFuTool to execute token assigned processT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/ATokenAssignor1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19368
753*\TokenDump.exe*.{0,1000}\\TokenDump\.exe.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19371
754*\Token-Impersonation.ps1*.{0,1000}\\Token\-Impersonation\.ps1.{0,1000}offensive_tool_keywordToken-ImpersonationMake a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)T1134.001 - T1134.002TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/Leo4j/Token-Impersonation10N/AN/A81732024-03-20T17:07:13Z2023-11-02T10:46:24Z19376
755*\TokenPlayer.cpp*.{0,1000}\\TokenPlayer\.cpp.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z19377
756*\TokenPlayer.exe*.{0,1000}\\TokenPlayer\.exe.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z19378
757*\TokenPlayer\TokenPlayer\*.{0,1000}\\TokenPlayer\\TokenPlayer\\.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z19379
758*\tokenprivileges.c*.{0,1000}\\tokenprivileges\.c.{0,1000}offensive_tool_keywordPrivKitPrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.T1548.002 - T1059.003 - T1027.002TA0005N/AN/APrivilege Escalationhttps://github.com/mertdas/PrivKit10N/AN/A95405472024-06-15T16:54:32Z2023-03-20T04:19:40Z19380
759*\tokenprivileges.o*.{0,1000}\\tokenprivileges\.o.{0,1000}offensive_tool_keywordPrivKitPrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.T1548.002 - T1059.003 - T1027.002TA0005N/AN/APrivilege Escalationhttps://github.com/mertdas/PrivKit10N/AN/A95405472024-06-15T16:54:32Z2023-03-20T04:19:40Z19381
760*\TokenStealing.exe*.{0,1000}\\TokenStealing\.exe.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19382
761*\Tokenvator\*.{0,1000}\\Tokenvator\\.{0,1000}offensive_tool_keywordTokenvatorA tool to elevate privilege with Windows TokensT1134 - T1078TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/0xbadjuju/Tokenvator10N/AN/AN/A1010382012023-10-06T13:17:05Z2017-12-08T01:29:11Z19387
762*\TrustExec.exe*.{0,1000}\\TrustExec\.exe.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19430
763*\TrustExec.exe*.{0,1000}\\TrustExec\.exe.{0,1000}offensive_tool_keywordPrivFuexecute process as NT SERVICE\TrustedInstaller group accountT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/ATrustExec1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19431
764*\tStifle.exe*.{0,1000}\\tStifle\.exe.{0,1000}offensive_tool_keywordStifle.NET Post-Exploitation Utility for Abusing Explicit Certificate Mappings in ADCST1550.003 - T1552.004 - T1606.002TA0006 - TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/logangoins/Stifle10#contentN/A7214092025-02-10T04:58:46Z2025-02-08T06:13:43Z19436
765*\UACBypassedService*.{0,1000}\\UACBypassedService.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z19488
766*\UAC-TokenMagic.ps1*.{0,1000}\\UAC\-TokenMagic\.ps1.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z19493
767*\UnquotedServicePath.cs*.{0,1000}\\UnquotedServicePath\.cs.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z19523
768*\unquotedsvcpath.o*.{0,1000}\\unquotedsvcpath\.o.{0,1000}offensive_tool_keywordPrivKitPrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.T1548.002 - T1059.003 - T1027.002TA0005N/AN/APrivilege Escalationhttps://github.com/mertdas/PrivKit10N/AN/A95405472024-06-15T16:54:32Z2023-03-20T04:19:40Z19524
769*\UserRightsUtil.exe*.{0,1000}\\UserRightsUtil\.exe.{0,1000}offensive_tool_keywordPrivFumanage user right without secpol.mscT1059 - T1078TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AUserRightsUtil1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19539
770*\Users\Public\nc.exe*.{0,1000}\\Users\\Public\\nc\.exe.{0,1000}offensive_tool_keywordWindows-Privilege-EscalationWindows Privilege Escalation Techniques and ScriptsT1055 - T1548 - T1078TA0004 - TA0005 - TA0040N/AN/APrivilege Escalationhttps://github.com/frizb/Windows-Privilege-Escalation10N/AN/AN/A98611902020-03-25T22:35:02Z2017-05-12T13:09:50Z19563
771*\VDR-main.zip.{0,1000}\\VDR\-main\.zipoffensive_tool_keywordVDRVulnerable driver research tool - result and exploit PoCsT1547.009 - T1210 - T1068 - T1055TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/TakahiroHaruyama/VDR10N/AN/A102192292023-11-01T00:06:55Z2023-10-23T08:34:44Z19599
772*\WfpTokenDup.exe*.{0,1000}\\WfpTokenDup\.exe.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19695
773*\windows\temp\nc64.exe*.{0,1000}\\windows\\temp\\nc64\.exe.{0,1000}offensive_tool_keywordRogueWinRMRogueWinRM is a local privilege escalation exploit that allows to escalate from a Service account (with SeImpersonatePrivilege) to Local System account if WinRM service is not runningT1548.003 - T1134.002 - T1055TA0004N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RogueWinRM10N/AN/A1087881072020-02-23T19:26:41Z2019-12-02T22:58:03Z19748
774*\winPEAS.exe*.{0,1000}\\winPEAS\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z19782
775*\winPEAS.ps1*.{0,1000}\\winPEAS\.ps1.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z19786
776*\winPEAS.sln*.{0,1000}\\winPEAS\.sln.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z19787
777*\winPEASany.exe*.{0,1000}\\winPEASany\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z19788
778*\winPEASany_ofs.exe*.{0,1000}\\winPEASany_ofs\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z19790
779*\winPEASany_ofs.exe*.{0,1000}\\winPEASany_ofs\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z19791
780*\winPEASexe\*.{0,1000}\\winPEASexe\\.{0,1000}offensive_tool_keywordPEASSPEASS - Privilege Escalation Awesome Scripts SUITET1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/carlospolop/PEASS-ng10N/AN/AN/A101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z19792
781*\winPEAS-Obfuscated.exe*.{0,1000}\\winPEAS\-Obfuscated\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z19793
782*\winPEASx64.exe*.{0,1000}\\winPEASx64\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z19794
783*\winPEASx86.exe*.{0,1000}\\winPEASx86\.exe.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10N/AN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z19795
784*\ZeroHVCI.cpp*.{0,1000}\\ZeroHVCI\.cpp.{0,1000}offensive_tool_keywordZeroHVCIAchieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229T1068 - T1564 - T1014 - T1499TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/zer0condition/ZeroHVCI10N/AN/A72198432024-10-26T17:08:38Z2024-07-20T07:29:18Z19950
785*\ZeroHVCI.exe*.{0,1000}\\ZeroHVCI\.exe.{0,1000}offensive_tool_keywordZeroHVCIAchieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229T1068 - T1564 - T1014 - T1499TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/zer0condition/ZeroHVCI10N/AN/A72198432024-10-26T17:08:38Z2024-07-20T07:29:18Z19951
786*\ZeroHVCI.sln*.{0,1000}\\ZeroHVCI\.sln.{0,1000}offensive_tool_keywordZeroHVCIAchieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229T1068 - T1564 - T1014 - T1499TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/zer0condition/ZeroHVCI10N/AN/A72198432024-10-26T17:08:38Z2024-07-20T07:29:18Z19952
787*\ZeroHVCI-master*.{0,1000}\\ZeroHVCI\-master.{0,1000}offensive_tool_keywordZeroHVCIAchieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229T1068 - T1564 - T1014 - T1499TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/zer0condition/ZeroHVCI10N/AN/A72198432024-10-26T17:08:38Z2024-07-20T07:29:18Z19953
788*] - caution! this means that exploit is not fileless*.{0,1000}\]\s\-\scaution!\sthis\smeans\sthat\sexploit\sis\snot\sfileless.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#content #linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z19976
789*] Bruteforcing %d CLSIDs*.{0,1000}\]\sBruteforcing\s\%d\sCLSIDs.{0,1000}offensive_tool_keywordJuicyPotatoNGAnother Windows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AFoxKitten - APT33 - Volatile Cedar - SandwormPrivilege Escalationhttps://github.com/antonioCoco/JuicyPotatoNG10N/AN/A1098441012022-11-12T01:48:39Z2022-09-21T17:08:35Z19983
790*] Cloning GPO * from fakedc .{0,1000}\]\sCloning\sGPO\s.{0,1000}\sfrom\sfakedc\soffensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z20006
791*] Completed Privesc Checks in *.{0,1000}\]\sCompleted\sPrivesc\sChecks\sin\s.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z20009
792*] dumping runtime core memory of the root smart contract*.{0,1000}\]\sdumping\sruntime\score\smemory\sof\sthe\sroot\ssmart\scontract.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#content #linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z20019
793*] executing xss local file write to hijack systemd user*.{0,1000}\]\sexecuting\sxss\slocal\sfile\swrite\sto\shijack\ssystemd\suser.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#content #linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z20025
794*] going to escalate the quantum privilege of wifi driver*.{0,1000}\]\sgoing\sto\sescalate\sthe\squantum\sprivilege\sof\swifi\sdriver.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#content #linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z20030
795*] going to inject sql payload into the external mainframe smart contract interface*.{0,1000}\]\sgoing\sto\sinject\ssql\spayload\sinto\sthe\sexternal\smainframe\ssmart\scontract\sinterface.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#content #linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z20031
796*] Granting read and execute to SYSTEM on DLL: *.{0,1000}\]\sGranting\sread\sand\sexecute\sto\sSYSTEM\son\sDLL\:\s.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10N/AN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z20032
797*] Injecting malicious scheduled task into downloaded GPO*.{0,1000}\]\sInjecting\smalicious\sscheduled\stask\sinto\sdownloaded\sGPO.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z20043
798*] Modifying * attribute of GPO on fakedc to *.{0,1000}\]\sModifying\s.{0,1000}\sattribute\sof\sGPO\son\sfakedc\sto\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z20053
799*] Modifying gPCFileSysPath attribute of GPO on fakedc to *.{0,1000}\]\sModifying\sgPCFileSysPath\sattribute\sof\sGPO\son\sfakedc\sto\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z20054
800*] QueueUserAPC Inject shellcode completed, enjoy!*.{0,1000}\]\sQueueUserAPC\sInject\sshellcode\scompleted,\senjoy!.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10#contentN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z20060
801*] Received DCOM NTLM type 3 authentication from the privileged client*.{0,1000}\]\sReceived\sDCOM\sNTLM\stype\s3\sauthentication\sfrom\sthe\sprivileged\sclient.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10N/AN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z20061
802*] Retrieving the S4U2Self referral from *.{0,1000}\]\sRetrieving\sthe\sS4U2Self\sreferral\sfrom\s.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z20064
803*] Roasted hashes written to : *.{0,1000}\]\sRoasted\shashes\swritten\sto\s\:\s.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z20065
804*] sending network-based smb hypertrojan with credentials*.{0,1000}\]\ssending\snetwork\-based\ssmb\shypertrojan\swith\scredentials.{0,1000}offensive_tool_keywordPOClocal privilege escalation Proof-of-Concept exploit for CVE-2024-1086 working on most Linux kernels between v5.14 and v6.6T1068 - T1548.002TA0004N/AN/APrivilege Escalationhttps://github.com/Notselwyn/CVE-2024-108610#content #linuxCVE-2024-1086 POC101023573142024-04-17T16:09:54Z2024-03-20T21:16:41Z20069
805*] Sending S4U2proxy request *.{0,1000}\]\sSending\sS4U2proxy\srequest\s.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z20070
806*] Spoofing gPLink to *.{0,1000}\]\sSpoofing\sgPLink\sto\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z20072
807*] Starting RogueOxidResolver RPC Server listening on port*.{0,1000}\]\sStarting\sRogueOxidResolver\sRPC\sServer\slistening\son\sport.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z20078
808*] Starting the NTLM relay attack, launch ntlmrelayx on *.{0,1000}\]\sStarting\sthe\sNTLM\srelay\sattack,\slaunch\sntlmrelayx\son\s.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z20080
809*] Starting the RPC server to capture the credentials hash from the user authentication!!*.{0,1000}\]\sStarting\sthe\sRPC\sserver\sto\scapture\sthe\scredentials\shash\sfrom\sthe\suser\sauthentication!!.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#contentN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z20081
810*]Spawning Process with Spoofed Parent*.{0,1000}\]Spawning\sProcess\swith\sSpoofed\sParent.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10N/AN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z20099
811*<BadPotato.exe>*.{0,1000}\<BadPotato\.exe\>.{0,1000}offensive_tool_keywordBadPotatoWindows Privilege Escalation Exploit BadPotatoT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareEarth LuscaPrivilege Escalationhttps://github.com/BeichenDream/BadPotato10#originalfilenameN/A1098361362020-05-10T15:42:21Z2020-05-10T10:01:20Z20205
812*<title>PrivescCheck Report</title>*.{0,1000}\<title\>PrivescCheck\sReport\<\/title\>.{0,1000}offensive_tool_keywordPrivescCheckPrivilege Escalation Enumeration Script for WindowsT1053 - T1088TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/itm4n/PrivescCheck10N/AN/A101032304602025-03-05T14:44:17Z2020-01-16T12:28:10Z20260
813*=== LAUNCHING SMB SERVER AND WAITING FOR GPT REQUESTS ===*.{0,1000}\=\=\=\sLAUNCHING\sSMB\sSERVER\sAND\sWAITING\sFOR\sGPT\sREQUESTS\s\=\=\=.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z20274
814*=== SharpUp: Running Privilege Escalation Checks ===*.{0,1000}\=\=\=\sSharpUp\:\sRunning\sPrivilege\sEscalation\sChecks\s\=\=\=.{0,1000}offensive_tool_keywordSharpUpSharpUp is a C# port of various PowerUp functionality. Currently. only the most common checks have been ported. no weaponization functions have yet been implemented.T1003 - T1082 - T1057 - T1069 - T1083TA0004 - TA0007N/AN/APrivilege Escalationhttps://github.com/GhostPack/SharpUp10N/AN/AN/A1013442532024-02-14T16:38:26Z2018-07-24T17:39:33Z20276
815*=== SPOOFING THE GPLINK ATTRIBUTE OF THE TARGET OU ===*.{0,1000}\=\=\=\sSPOOFING\sTHE\sGPLINK\sATTRIBUTE\sOF\sTHE\sTARGET\sOU\s\=\=\=.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z20277
816*=== WAITING (GPT REQUESTS WILL BE FORWARDED TO SMB SERVER) ===*.{0,1000}\=\=\=\sWAITING\s\(GPT\sREQUESTS\sWILL\sBE\sFORWARDED\sTO\sSMB\sSERVER\)\s\=\=\=.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z20278
817*=== WAITING (SMB NTLM AUTHENTICATION COERCED TO *.{0,1000}\=\=\=\sWAITING\s\(SMB\sNTLM\sAUTHENTICATION\sCOERCED\sTO\s.{0,1000}offensive_tool_keywordOunedThe OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoningT1484 - T1210TA0001 - TA0004 - TA0005 - TA0009N/AN/APrivilege Escalationhttps://github.com/synacktiv/Ouned10N/AN/A102112142025-03-29T14:20:38Z2024-04-17T10:18:04Z20279
818*>ADCSPwn<*.{0,1000}\>ADCSPwn\<.{0,1000}offensive_tool_keywordADCSPwnA tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate serviceT1550.002 - T1078.003 - T1110.003 - T1649TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/bats3c/ADCSPwn10N/AN/A1098381272023-03-20T20:30:40Z2021-07-30T15:04:41Z20316
819*>BadPotato<*.{0,1000}\>BadPotato\<.{0,1000}offensive_tool_keywordBadPotatoWindows Privilege Escalation Exploit BadPotatoT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareEarth LuscaPrivilege Escalationhttps://github.com/BeichenDream/BadPotato10#productnameN/A1098361362020-05-10T15:42:21Z2020-05-10T10:01:20Z20340
820*>CreateAssignTokenVariant<*.{0,1000}\>CreateAssignTokenVariant\<.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20359
821*>CreateImpersonateTokenVariant<*.{0,1000}\>CreateImpersonateTokenVariant\<.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20360
822*>DeadPotato<*.{0,1000}\>DeadPotato\<.{0,1000}offensive_tool_keywordDeadPotatoDeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privilegesT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011N/AN/APrivilege Escalationhttps://github.com/lypd0/DeadPotato10N/AN/A104382452024-08-17T06:08:29Z2024-07-31T01:08:30Z20368
823*>DebugInjectionVariant<*.{0,1000}\>DebugInjectionVariant\<.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20369
824*>DebugUpdateProcVariant<*.{0,1000}\>DebugUpdateProcVariant\<.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20370
825*>DirtyCLR<*.{0,1000}\>DirtyCLR\<.{0,1000}offensive_tool_keywordDirtyCLRAn App Domain Manager Injection DLL PoCT1055.001 - T1546.016 - T1055.013TA0005 - TA0004N/ABlack BastaPrivilege Escalationhttps://github.com/ipSlav/DirtyCLR10N/AN/A72170192023-12-14T21:22:12Z2023-12-11T11:29:36Z20377
826*>EfsPotato<*.{0,1000}\>EfsPotato\<.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20384
827*>Enables users to elevate themselves to administrator-level rights.<*.{0,1000}\>Enables\susers\sto\selevate\sthemselves\sto\sadministrator\-level\srights\.\<.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z20387
828*>Make Me Admin<*.{0,1000}\>Make\sMe\sAdmin\<.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z20436
829*>MakeMeAdmin<*.{0,1000}\>MakeMeAdmin\<.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10N/AN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z20437
830*>NamedPipeImpersonation<*.{0,1000}\>NamedPipeImpersonation\<.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20454
831*>PrintSpoofer<*.{0,1000}\>PrintSpoofer\<.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20483
832*>RestoreServiceModificationVariant<*.{0,1000}\>RestoreServiceModificationVariant\<.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20504
833*>S4uDelegator<*.{0,1000}\>S4uDelegator\<.{0,1000}offensive_tool_keywordPrivFuperform S4U logon with SeTcbPrivilegeT1134TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu11N/AS4uDelegator1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20511
834*>S4ULogonShell<*.{0,1000}\>S4ULogonShell\<.{0,1000}offensive_tool_keywordPrivFuSeTcbPrivilege exploitationT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/APrivFu\PowerOfTcb1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20512
835*>SeAuditPrivilegePoC<*.{0,1000}\>SeAuditPrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20517
836*>SeBackupPrivilegePoC<*.{0,1000}\>SeBackupPrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20518
837*>SecondaryLogonVariant<*.{0,1000}\>SecondaryLogonVariant\<.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20519
838*>SeCreatePagefilePrivilegePoC<*.{0,1000}\>SeCreatePagefilePrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20520
839*>SeCreateTokenPrivilegePoC<*.{0,1000}\>SeCreateTokenPrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20521
840*>SeDebugPrivilegePoC<*.{0,1000}\>SeDebugPrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20522
841*>SeRestorePrivilegePoC<*.{0,1000}\>SeRestorePrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20523
842*>SeSecurityPrivilegePoC<*.{0,1000}\>SeSecurityPrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20524
843*>SeShutdownPrivilegePoC<*.{0,1000}\>SeShutdownPrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20525
844*>SeSystemEnvironmentPrivilegePoC<*.{0,1000}\>SeSystemEnvironmentPrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20526
845*>SeTakeOwnershipPrivilegePoC<*.{0,1000}\>SeTakeOwnershipPrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20529
846*>SeTcbPrivilegePoC<*.{0,1000}\>SeTcbPrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20530
847*>SeTrustedCredManAccessPrivilegePoC<*.{0,1000}\>SeTrustedCredManAccessPrivilegePoC\<.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/APrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20531
848*>TakeOwnershipServiceModificationVariant<*.{0,1000}\>TakeOwnershipServiceModificationVariant\<.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20597
849*>TcbS4uImpersonationVariant<*.{0,1000}\>TcbS4uImpersonationVariant\<.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20598
850*>TokenStealing<*.{0,1000}\>TokenStealing\<.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20604
851*>UACBypassedService<*.{0,1000}\>UACBypassedService\<.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10N/AN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z20607
852*>UserRightsUtil<*.{0,1000}\>UserRightsUtil\<.{0,1000}offensive_tool_keywordPrivFumanage user right without secpol.mscT1059 - T1078TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10N/AUserRightsUtil1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20611
853*>WfpTokenDup<*.{0,1000}\>WfpTokenDup\<.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10N/AArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20619
854*008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050*.{0,1000}008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20670
855*008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050*.{0,1000}008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20671
856*008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050*.{0,1000}008edaedd37b477a5edd2475fc4e8793b03ec4cba503049a0db2114d4eb18050.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20672
857*00a2407eb70a40f0054d83e92cc9e8e85b010bfcc75ab5bab1ced62f81622d92*.{0,1000}00a2407eb70a40f0054d83e92cc9e8e85b010bfcc75ab5bab1ced62f81622d92.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20679
858*00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a*.{0,1000}00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20688
859*00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a*.{0,1000}00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20689
860*00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a*.{0,1000}00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20690
861*00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a*.{0,1000}00c868aae54b994cb537e54cb490d665a1d408d2634876bf2cedf4900a2d9c5a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20691
862*01ccc2ba607a0aa44e7bd6690dc5d93001ad70b03ad817142f7f9abb4c911abb*.{0,1000}01ccc2ba607a0aa44e7bd6690dc5d93001ad70b03ad817142f7f9abb4c911abb.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20759
863*01cf2c956d813b4dddcde5f3349ada814764aa45d9579e8dde063c891f62d1d4*.{0,1000}01cf2c956d813b4dddcde5f3349ada814764aa45d9579e8dde063c891f62d1d4.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linux #filehashN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z20760
864*0212bde3715a349a6b684dd54548638b5899be8d62a1e25559937e494e3cce54*.{0,1000}0212bde3715a349a6b684dd54548638b5899be8d62a1e25559937e494e3cce54.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10#filehashN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z20778
865*026389a44b0e1797d97afd0c333f778fe8c066e9edf4c0b847872263a27451f0*.{0,1000}026389a44b0e1797d97afd0c333f778fe8c066e9edf4c0b847872263a27451f0.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20803
866*0266d99789720ec1a83a397127c478885b3f3ff02026a3fb06d3a10e523a9cc0*.{0,1000}0266d99789720ec1a83a397127c478885b3f3ff02026a3fb06d3a10e523a9cc0.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20804
867*0269fd0001afa23edd1206484dccce04b49e0ec0daa65234126a6f3c42f35a46*.{0,1000}0269fd0001afa23edd1206484dccce04b49e0ec0daa65234126a6f3c42f35a46.{0,1000}offensive_tool_keywordZeroHVCIAchieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers - CVE-2024-26229T1068 - T1564 - T1014 - T1499TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/zer0condition/ZeroHVCI10#filehashN/A72198432024-10-26T17:08:38Z2024-07-20T07:29:18Z20805
868*0286bd5f-1a56-4251-8758-adb0338d4e98*.{0,1000}0286bd5f\-1a56\-4251\-8758\-adb0338d4e98.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10#GUIDprojectN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z20824
869*02ac483d126c4b08d880cfab52f1904323006b4778f43f536bb83bb38c2a9f2e*.{0,1000}02ac483d126c4b08d880cfab52f1904323006b4778f43f536bb83bb38c2a9f2e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20832
870*02cbcc3c3b79a7f81165838af0605d7238e8c5ad7a6e2d59d7795c1f137fe7a4*.{0,1000}02cbcc3c3b79a7f81165838af0605d7238e8c5ad7a6e2d59d7795c1f137fe7a4.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10#filehashN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z20840
871*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20849
872*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20850
873*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20851
874*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20852
875*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20853
876*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20854
877*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20855
878*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20856
879*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20857
880*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20858
881*02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e*.{0,1000}02f6a2640616568c5b0f581b1902ebb7be15b6368a2c69ab7f3014754d88b51e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20859
882*036b5e87804f5996d8009b8d06f95a307227c6835a51ce64427cae7189cf86d2*.{0,1000}036b5e87804f5996d8009b8d06f95a307227c6835a51ce64427cae7189cf86d2.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10#filehashN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z20894
883*03b99b08166cc1f4ef733078b9756cd12d39824acd022a2aca1da5f888094538*.{0,1000}03b99b08166cc1f4ef733078b9756cd12d39824acd022a2aca1da5f888094538.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20921
884*03c1585bf3e2e6013e2f8cd34d34eedc9c4195dc72628a779db43cdd16b1a7cc*.{0,1000}03c1585bf3e2e6013e2f8cd34d34eedc9c4195dc72628a779db43cdd16b1a7cc.{0,1000}offensive_tool_keywordPrivFuperform S4U logon with SeTcbPrivilegeT1134TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#filehashS4uDelegator1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z20924
885*03e1412cfc9954592a8c8b93d151ce20083d7a1797b3eb8b15e6098179627b73*.{0,1000}03e1412cfc9954592a8c8b93d151ce20083d7a1797b3eb8b15e6098179627b73.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20934
886*03fdcd35cfb237327c0813ce931a62ffcf837302f8e0285ff1c8085ee30f2828*.{0,1000}03fdcd35cfb237327c0813ce931a62ffcf837302f8e0285ff1c8085ee30f2828.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linux #filehashN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z20942
887*046f841782518838690b1ad7916ea33c68cd32cfdd9c87aabc7d85425b0f20ed*.{0,1000}046f841782518838690b1ad7916ea33c68cd32cfdd9c87aabc7d85425b0f20ed.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z20988
888*04a57cd7fa95b8851ef4d45aa6b30b9c89dbbbe7b8a1780a15c34b9a81f9ef91*.{0,1000}04a57cd7fa95b8851ef4d45aa6b30b9c89dbbbe7b8a1780a15c34b9a81f9ef91.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10#filehashN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z21001
889*04FC654C-D89A-44F9-9E34-6D95CE152E9D*.{0,1000}04FC654C\-D89A\-44F9\-9E34\-6D95CE152E9D.{0,1000}offensive_tool_keywordPrivFuKernel mode WinDbg extension and PoCs for token privilege investigation.T1016 - T1018 - T1098 - T1134 - T1055 - T1053 - T1059 - T1035 - T1547.001 - T1547.004 - T1548.001TA0007 - TA0008 - TA0002 - TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#GUIDprojectN/A1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z21020
890*050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23*.{0,1000}050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21026
891*050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23*.{0,1000}050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21027
892*050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23*.{0,1000}050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21028
893*050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23*.{0,1000}050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21029
894*050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23*.{0,1000}050d0065e439ca1d3b1ebe97f74cc4842f40a3b3da609ff3fdc52442af4e7b23.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21030
895*050dcd051a109b6bd8804e769242ec4e1c087bdd2fb45880c2affeebb630cf77*.{0,1000}050dcd051a109b6bd8804e769242ec4e1c087bdd2fb45880c2affeebb630cf77.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10#filehashN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z21031
896*0527a14f-1591-4d94-943e-d6d784a50549*.{0,1000}0527a14f\-1591\-4d94\-943e\-d6d784a50549.{0,1000}offensive_tool_keywordBadPotatoWindows Privilege Escalation Exploit BadPotatoT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareEarth LuscaPrivilege Escalationhttps://github.com/BeichenDream/BadPotato10#GUIDprojectN/A1098361362020-05-10T15:42:21Z2020-05-10T10:01:20Z21039
897*053c976a6b035d2c3daefe986d293fcb1d92ffd0f535a649ee61218c66721555*.{0,1000}053c976a6b035d2c3daefe986d293fcb1d92ffd0f535a649ee61218c66721555.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10#filehashN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z21042
898*057432add809186a039ba449a5988101aad9f9e55119b90e34b49e9f14835b3a*.{0,1000}057432add809186a039ba449a5988101aad9f9e55119b90e34b49e9f14835b3a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21052
899*05c10f59c21e200d25112a44581eab14d4793bfdc4f4cad8a9e6b0d231f4f1aa*.{0,1000}05c10f59c21e200d25112a44581eab14d4793bfdc4f4cad8a9e6b0d231f4f1aa.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linux #filehashN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z21073
900*063bc732edb5ca68d2122d0311ddb46dd38ff05074945566d1fa067c3579d767*.{0,1000}063bc732edb5ca68d2122d0311ddb46dd38ff05074945566d1fa067c3579d767.{0,1000}offensive_tool_keywordBadPotatoWindows Privilege Escalation Exploit BadPotatoT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareEarth LuscaPrivilege Escalationhttps://github.com/BeichenDream/BadPotato10#filehashN/A1098361362020-05-10T15:42:21Z2020-05-10T10:01:20Z21099
901*06f14218e0f7b881a61c998824e6709b313b5c8baaa87a8d15986b0c5cf2b7cb*.{0,1000}06f14218e0f7b881a61c998824e6709b313b5c8baaa87a8d15986b0c5cf2b7cb.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21150
902*0705092d4c2a8e0475d1f686166b9b1ecb999c0133a0eaf8a7b8fd902dc64930*.{0,1000}0705092d4c2a8e0475d1f686166b9b1ecb999c0133a0eaf8a7b8fd902dc64930.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21156
903*07400fb1198a8326fead8180f927e62e218885a4940b9879082d2adf49064ea5*.{0,1000}07400fb1198a8326fead8180f927e62e218885a4940b9879082d2adf49064ea5.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21173
904*07628592-5A22-4C0A-9330-6C90BD7A94B6*.{0,1000}07628592\-5A22\-4C0A\-9330\-6C90BD7A94B6.{0,1000}offensive_tool_keywordLocalAdminSharp.NET executable to use when dealing with privilege escalation on Windows to gain local administrator accessT1055.011 - T1068 - T1548.002 - T1548.003 - T1548.004TA0004N/AN/APrivilege Escalationhttps://github.com/notdodo/LocalAdminSharp10#GUIDprojectN/A102157172022-11-01T17:45:43Z2022-01-01T10:35:09Z21183
905*0817eb1eeb9b25430a2666b8bd637d83e8c3c10ba14a8f6db0b0d3147ce3ab4a*.{0,1000}0817eb1eeb9b25430a2666b8bd637d83e8c3c10ba14a8f6db0b0d3147ce3ab4a.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#filehashPrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z21241
906*0971A047-A45A-43F4-B7D8-16AC1114B524*.{0,1000}0971A047\-A45A\-43F4\-B7D8\-16AC1114B524.{0,1000}offensive_tool_keywordBackupOperatorToDAFrom an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain ControllerT1078 - T1078.003 - T1021 - T1021.006 - T1112 - T1003.003TA0005 - TA0001 - TA0003N/AN/APrivilege Escalationhttps://github.com/mpgn/BackupOperatorToDA10#GUIDprojectN/A105421532025-01-04T14:16:46Z2022-02-15T20:51:46Z21341
907*0999e7ec2eaa95fded99e6b8cb3ffd5ae372a896731cef3eb5bdb0b8977e64f4*.{0,1000}0999e7ec2eaa95fded99e6b8cb3ffd5ae372a896731cef3eb5bdb0b8977e64f4.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21353
908*09d9169b42e10b354ce44c9bdb8f06c52506f14f39f6378e52b3c2eac1d27866*.{0,1000}09d9169b42e10b354ce44c9bdb8f06c52506f14f39f6378e52b3c2eac1d27866.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21371
909*09e0c32321b7bc4b6d95f4a36d9030ce2333d67ffff15e4ff51631c3c4aa319d*.{0,1000}09e0c32321b7bc4b6d95f4a36d9030ce2333d67ffff15e4ff51631c3c4aa319d.{0,1000}offensive_tool_keywordBITSInjectA one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM accountT1197TA0004N/AN/APrivilege Escalationhttps://github.com/SafeBreach-Labs/BITSInject10#filehashN/A8199182019-08-24T22:02:12Z2017-07-03T12:39:38Z21373
910*0a2dbf9faa4445dfca15c92c6048cfca1e98ad9981f3c8349e7ffa34e62f638d*.{0,1000}0a2dbf9faa4445dfca15c92c6048cfca1e98ad9981f3c8349e7ffa34e62f638d.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21394
911*0a33c2da28a068610b62a369635506fbd4a15233867c9c1e3041948006177cb6*.{0,1000}0a33c2da28a068610b62a369635506fbd4a15233867c9c1e3041948006177cb6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21395
912*0A78E156-D03F-4667-B70E-4E9B4AA1D491*.{0,1000}0A78E156\-D03F\-4667\-B70E\-4E9B4AA1D491.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#GUIDprojectPrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z21409
913*0ADFD1F0-7C15-4A22-87B4-F67E046ECD96*.{0,1000}0ADFD1F0\-7C15\-4A22\-87B4\-F67E046ECD96.{0,1000}offensive_tool_keywordTokenPlayerManipulating and Abusing Windows Access TokensT1134 - T1484 - T1055 - T1078TA0004 - TA0005 - TA0006N/AN/APrivilege Escalationhttps://github.com/S1ckB0y1337/TokenPlayer10#GUIDprojectN/A103274452021-01-15T16:07:47Z2020-08-20T23:05:49Z21433
914*0ae164e1f157f452b32b06e43b828d792daa447b535b08330f942ade8b87d70b*.{0,1000}0ae164e1f157f452b32b06e43b828d792daa447b535b08330f942ade8b87d70b.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21436
915*0b3502ac778c671bad537e6433a8f58ec4e1f9a7ab34d37a7bb1bf8c08b2dcf7*.{0,1000}0b3502ac778c671bad537e6433a8f58ec4e1f9a7ab34d37a7bb1bf8c08b2dcf7.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21455
916*0b5f0373ab8388f655fe01309ff6a58e96e969d8a94a06b5a05dce11c998f2f0*.{0,1000}0b5f0373ab8388f655fe01309ff6a58e96e969d8a94a06b5a05dce11c998f2f0.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21464
917*0b6a762812a1fbfda681951fbd60bcaa919b99e6e61df84a251f800bb4479a0e*.{0,1000}0b6a762812a1fbfda681951fbd60bcaa919b99e6e61df84a251f800bb4479a0e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21466
918*0ba663873a7926866e3dd717b970f7e651700d00e9d99f667dfd473eafa81b8a*.{0,1000}0ba663873a7926866e3dd717b970f7e651700d00e9d99f667dfd473eafa81b8a.{0,1000}offensive_tool_keywordKExecDDAdmin to Kernel code execution using the KSecDD driverT1068 - T1055.011TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/floesen/KExecDD10#filehashN/A83244412024-04-19T09:58:14Z2024-04-19T08:54:49Z21485
919*0bb4b892f67fdf903ed5e5df2c85c5ccb71669c298736cf24284412de435509a*.{0,1000}0bb4b892f67fdf903ed5e5df2c85c5ccb71669c298736cf24284412de435509a.{0,1000}offensive_tool_keywordADCSPwnA tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate serviceT1550.002 - T1078.003 - T1110.003 - T1649TA0004 - TA0006N/AN/APrivilege Escalationhttps://github.com/bats3c/ADCSPwn10#filehashN/A1098381272023-03-20T20:30:40Z2021-07-30T15:04:41Z21489
920*0c021fa1272bc222489a6a54e46a10c85d57d758071b310afc66441f72d4a482*.{0,1000}0c021fa1272bc222489a6a54e46a10c85d57d758071b310afc66441f72d4a482.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21513
921*0c2c7f0208bac76684a0e8f5960772b22014f417a81caba157b0b512e13404b2*.{0,1000}0c2c7f0208bac76684a0e8f5960772b22014f417a81caba157b0b512e13404b2.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21527
922*0ca801fdfa8a5040b2e60608fe9ff7fc987ef7d361e389ddcc8d1568b8832230*.{0,1000}0ca801fdfa8a5040b2e60608fe9ff7fc987ef7d361e389ddcc8d1568b8832230.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21565
923*0CC923FB-E1FD-456B-9FE4-9EBA5A3DC2FC*.{0,1000}0CC923FB\-E1FD\-456B\-9FE4\-9EBA5A3DC2FC.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10#GUIDprojectArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z21574
924*0CD16C7B-2A65-44E5-AB74-843BD23241D3*.{0,1000}0CD16C7B\-2A65\-44E5\-AB74\-843BD23241D3.{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/outflanknl/PrintNightmare10#GUIDprojectN/A104337672021-09-13T08:45:26Z2021-09-13T08:44:02Z21577
925*0cf16d4d70941be216c787a44a7401c9c9547016952a2c699579d4e4bb9c8110*.{0,1000}0cf16d4d70941be216c787a44a7401c9c9547016952a2c699579d4e4bb9c8110.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10#filehashN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z21585
926*0d8cac6cbe2019d99a5260f4c934d9a4c9c7022d141006cfc0f87fdc3f8ae4ab*.{0,1000}0d8cac6cbe2019d99a5260f4c934d9a4c9c7022d141006cfc0f87fdc3f8ae4ab.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linux #filehashN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z21633
927*0d8f5888bc6e02085496b4a070b39169bdea67051b1a9f7af21b29de9615842e*.{0,1000}0d8f5888bc6e02085496b4a070b39169bdea67051b1a9f7af21b29de9615842e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21637
928*0defeb7a564d2f4f237d89ae63065e78af68b0febda5927f25722696593bf42e*.{0,1000}0defeb7a564d2f4f237d89ae63065e78af68b0febda5927f25722696593bf42e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21669
929*0e9af89e0f2faa8d7f92d6e9538e19f82c701c798031d890978845e388b85ba6*.{0,1000}0e9af89e0f2faa8d7f92d6e9538e19f82c701c798031d890978845e388b85ba6.{0,1000}offensive_tool_keywordACEsharkuncover potential privilege escalation vectors by analyzing windows service configurations and Access Control EntriesT1058 - T1548TA0004N/AN/APrivilege Escalationhttps://github.com/t3l3machus/ACEshark10#filehashN/A62109192025-01-15T07:01:48Z2024-12-28T10:42:29Z21723
930*0eec76148fd7a3b1eb54d3fa71c30b5370d410e1eb81231ff0e9e66de3598aea*.{0,1000}0eec76148fd7a3b1eb54d3fa71c30b5370d410e1eb81231ff0e9e66de3598aea.{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/outflanknl/PrintNightmare10#filehashN/A104337672021-09-13T08:45:26Z2021-09-13T08:44:02Z21742
931*0f56c703e9b7ddeb90646927bac05a5c6d95308c8e13b88e5d4f4b572423e036*.{0,1000}0f56c703e9b7ddeb90646927bac05a5c6d95308c8e13b88e5d4f4b572423e036.{0,1000}offensive_tool_keywordBat-PotatoAutomating Juicy Potato Local Privilege Escalation CMD exploit for penetration testersT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/0x4xel/Bat-Potato10#filehashN/A10142112022-12-13T20:19:51Z2022-12-12T20:50:22Z21767
932*0f7b6ddc0ef44701c4ab1284610d51d36b4e79d68fb0e184d122533d77cbfb63*.{0,1000}0f7b6ddc0ef44701c4ab1284610d51d36b4e79d68fb0e184d122533d77cbfb63.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21782
933*0fb342f94f359c9f54205a979854b7a3a3910bb7e118f0fc44cead28ebd81f0d*.{0,1000}0fb342f94f359c9f54205a979854b7a3a3910bb7e118f0fc44cead28ebd81f0d.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10#filehashN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z21800
934*0x4xel/Bat-Potato*.{0,1000}0x4xel\/Bat\-Potato.{0,1000}offensive_tool_keywordBat-PotatoAutomating Juicy Potato Local Privilege Escalation CMD exploit for penetration testersT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/0x4xel/Bat-Potato11N/AN/A10142112022-12-13T20:19:51Z2022-12-12T20:50:22Z21833
935*0xbadjuju/Tokenvator*.{0,1000}0xbadjuju\/Tokenvator.{0,1000}offensive_tool_keywordTokenvatorA tool to elevate privilege with Windows TokensT1134 - T1078TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/0xbadjuju/Tokenvator11N/AN/AN/A1010382012023-10-06T13:17:05Z2017-12-08T01:29:11Z21841
936*0xEr3bus/PoolPartyBof*.{0,1000}0xEr3bus\/PoolPartyBof.{0,1000}offensive_tool_keywordPoolPartyBofA beacon object file implementation of PoolParty Process Injection TechniqueT1055.011 - T1055 - T1620TA0005N/ABlack BastaPrivilege Escalationhttps://github.com/0xEr3bus/PoolPartyBof11N/AN/A104380442023-12-21T19:00:20Z2023-12-11T19:28:20Z21848
937*105C2C6D-1C0A-4535-A231-80E355EFB112*.{0,1000}105C2C6D\-1C0A\-4535\-A231\-80E355EFB112.{0,1000}offensive_tool_keywordRoguePotatoWindows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RoguePotato10#GUIDprojectN/A101010811312021-01-09T20:43:07Z2020-05-10T17:38:28Z21888
938*10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab*.{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21922
939*10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab*.{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21923
940*10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab*.{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21924
941*10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab*.{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21925
942*10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab*.{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21926
943*10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab*.{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21927
944*10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab*.{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21928
945*10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab*.{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21929
946*10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab*.{0,1000}10f1654ada84329ad352c7a0879ca49659d8df9a1da87a19ec16d75de2661fab.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21930
947*1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57*.{0,1000}1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21938
948*1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57*.{0,1000}1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21939
949*1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57*.{0,1000}1107ec321a60c6b0a500475efd25bf81e12b743c2270cc0482adc7ced6339a57.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21940
950*1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a*.{0,1000}1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21942
951*1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a*.{0,1000}1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21943
952*1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a*.{0,1000}1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21944
953*1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a*.{0,1000}1114bbdd9da82e10229805d40ab46ce31fc7a8f57b7ee53d47fa337f5937361a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21945
954*1141183bf4a5fdb8a92a4bb9ae2278ec6391e1bc96ebee10245ad8a416372bd9*.{0,1000}1141183bf4a5fdb8a92a4bb9ae2278ec6391e1bc96ebee10245ad8a416372bd9.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10#filehashN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z21958
955*1141183bf4a5fdb8a92a4bb9ae2278ec6391e1bc96ebee10245ad8a416372bd9*.{0,1000}1141183bf4a5fdb8a92a4bb9ae2278ec6391e1bc96ebee10245ad8a416372bd9.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10#filehashN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z21959
956*1189360f7da03490a9f0f3ce283d487335a4db24232d6fabfd17bc7ec4e53392*.{0,1000}1189360f7da03490a9f0f3ce283d487335a4db24232d6fabfd17bc7ec4e53392.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linux #filehashN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z21974
957*11a92a7c6a84715416eb8a1c033a6a8db9a70494bfc08c9f09734e599be76cef*.{0,1000}11a92a7c6a84715416eb8a1c033a6a8db9a70494bfc08c9f09734e599be76cef.{0,1000}offensive_tool_keywordSpoolFoolExploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)T1068 - T1055 - T1059.003TA0004 - TA0005 - TA0003DispossessorPrivilege Escalationhttps://github.com/ly4k/SpoolFool10#filehashN/A987881602022-02-09T16:54:09Z2022-02-08T17:25:44Z21982
958*11b29c6bbbcb4bf9dc59b7b308de0da0f13e5f6116a3f10dffe76f4f927ccd8b*.{0,1000}11b29c6bbbcb4bf9dc59b7b308de0da0f13e5f6116a3f10dffe76f4f927ccd8b.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21984
959*11cb4947c8f8e84c34512070b1ead707af5e948b82937f32e15df293269e678d*.{0,1000}11cb4947c8f8e84c34512070b1ead707af5e948b82937f32e15df293269e678d.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z21991
960*12545d5c24427a6dc3e63d63472bb344ad1d67f323756f1430b48ae2acdf322d*.{0,1000}12545d5c24427a6dc3e63d63472bb344ad1d67f323756f1430b48ae2acdf322d.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22030
961*127.0.0.1/C$/Windows/System32/utilman.exe*.{0,1000}127\.0\.0\.1\/C\$\/Windows\/System32\/utilman\.exe.{0,1000}offensive_tool_keywordpotatoPotato Privilege Escalation on WindowsT1134.001 - T1068 - T1055 - T1546.015TA0004N/AN/APrivilege Escalationhttps://github.com/foxglovesec/Potato10#contentN/A787211652021-01-16T20:34:04Z2016-02-09T11:28:17Z22039
962*127.0.0.1/pipe/coerced\\C$*.{0,1000}127\.0\.0\.1\/pipe\/coerced\\\\C\$.{0,1000}offensive_tool_keywordCoercedPotatoCoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.T1548.002 - T1134.002TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Prepouce/CoercedPotato10N/AN/A104366662024-08-26T08:09:00Z2023-09-11T19:04:29Z22041
963*130af28d5a846c7f961a6a0a1188e1688501d8c0c4a3df4c1451005f1fc162fa*.{0,1000}130af28d5a846c7f961a6a0a1188e1688501d8c0c4a3df4c1451005f1fc162fa.{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato10#filehashN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z22101
964*1312202e1f36db3f8bb319c6a886ba558373b83dd9d8bd54a8fc42ae156d81cb*.{0,1000}1312202e1f36db3f8bb319c6a886ba558373b83dd9d8bd54a8fc42ae156d81cb.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linux #filehashN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z22105
965*13827593b510bd2cb72270a7bd4aecfe90043112f1a70b879a36b0eaf1efcfa2*.{0,1000}13827593b510bd2cb72270a7bd4aecfe90043112f1a70b879a36b0eaf1efcfa2.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22138
966*1460d78f92f67929b451732af1d24752026b9d91fd85faec196460f7d4cac9f9*.{0,1000}1460d78f92f67929b451732af1d24752026b9d91fd85faec196460f7d4cac9f9.{0,1000}offensive_tool_keywordPrivFuSeTcbPrivilege exploitationT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10#filehashPrivFu\PowerOfTcb1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z22193
967*146ca286f362290e96eda2a0b7cd9feb4e971763ba194731d1826e12e593439d*.{0,1000}146ca286f362290e96eda2a0b7cd9feb4e971763ba194731d1826e12e593439d.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10#filehashN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z22198
968*148b284dead436f9dbbc23f7e4861901ddc7f1d2cc03c49b8b0379ff6b5633b4*.{0,1000}148b284dead436f9dbbc23f7e4861901ddc7f1d2cc03c49b8b0379ff6b5633b4.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato10#filehashN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z22206
969*14a0ceba63b3d76d7d30653112a0b43e3a2ef1f07a8030d7a949696b5c3065f6*.{0,1000}14a0ceba63b3d76d7d30653112a0b43e3a2ef1f07a8030d7a949696b5c3065f6.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato10#filehashN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z22209
970*156e71ab72393301c2a27995c869afd9972b5fcf4f3a7e92e8335358f11e0306*.{0,1000}156e71ab72393301c2a27995c869afd9972b5fcf4f3a7e92e8335358f11e0306.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22259
971*1605d453-7d62-4198-a436-27e48ef828eb*.{0,1000}1605d453\-7d62\-4198\-a436\-27e48ef828eb.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10#GUIDprojectN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z22292
972*17914e2d97784ef7aaf52f9f8b04db77cad036308c6b3584fa0fa172ad1da077*.{0,1000}17914e2d97784ef7aaf52f9f8b04db77cad036308c6b3584fa0fa172ad1da077.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linux #filehashN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z22404
973*1812fedbe3078c546fb0b59bd0d1ef35110969a49515f3c7fd1a519469d01104*.{0,1000}1812fedbe3078c546fb0b59bd0d1ef35110969a49515f3c7fd1a519469d01104.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22432
974*182e81c156f653dea62d0aaa97c23887cf99907e16503654bc1fb55405073903*.{0,1000}182e81c156f653dea62d0aaa97c23887cf99907e16503654bc1fb55405073903.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10#filehashArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z22441
975*186789b7b7c4973d4f941582a796c3ced5ae7fbc4527cf19040e740d380c4106*.{0,1000}186789b7b7c4973d4f941582a796c3ced5ae7fbc4527cf19040e740d380c4106.{0,1000}offensive_tool_keywordStifle.NET Post-Exploitation Utility for Abusing Explicit Certificate Mappings in ADCST1550.003 - T1552.004 - T1606.002TA0006 - TA0003 - TA0004N/AN/APrivilege Escalationhttps://github.com/logangoins/Stifle10#filehashN/A7214092025-02-10T04:58:46Z2025-02-08T06:13:43Z22457
976*18841fe957995a34a5b74eb0a894cad7ee2c10d1c33f1955c1623279e81b9343*.{0,1000}18841fe957995a34a5b74eb0a894cad7ee2c10d1c33f1955c1623279e81b9343.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22465
977*18950aed7a4061673d241d5548f425779a3fa89e734a28b2b91fed786894a698*.{0,1000}18950aed7a4061673d241d5548f425779a3fa89e734a28b2b91fed786894a698.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22468
978*192f251afb217d7b5080564ef78df67235cf0e47bd78a458706a5dd958a9d093*.{0,1000}192f251afb217d7b5080564ef78df67235cf0e47bd78a458706a5dd958a9d093.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22510
979*19344cc373b3ed325dd8fcbd5ea333922495486b206c6098c7314f055e194646*.{0,1000}19344cc373b3ed325dd8fcbd5ea333922495486b206c6098c7314f055e194646.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22513
980*1990a0005ec6cd1b0cbfaa53cb51f27622f17e14df230215cb9921e1b2552a47*.{0,1000}1990a0005ec6cd1b0cbfaa53cb51f27622f17e14df230215cb9921e1b2552a47.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22540
981*1a550baec33973542f4a634762c680be12e21c3c91eb62e68558bfb5c96bbf5e*.{0,1000}1a550baec33973542f4a634762c680be12e21c3c91eb62e68558bfb5c96bbf5e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22596
982*1a88b6412bb1e6349948bc6abdc0eebb5df61cc8c0a7ec9709310a77dbc7bccb*.{0,1000}1a88b6412bb1e6349948bc6abdc0eebb5df61cc8c0a7ec9709310a77dbc7bccb.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService10#filehashN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z22610
983*1ac39556a986e4338e44ab2e94fcc34fd12cd690feeef22161d255bd1067d7e1*.{0,1000}1ac39556a986e4338e44ab2e94fcc34fd12cd690feeef22161d255bd1067d7e1.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22627
984*1ada2351bf027363a8dd71c06a73a7450f52f6b85a0bd08e0e51d83b379172d7*.{0,1000}1ada2351bf027363a8dd71c06a73a7450f52f6b85a0bd08e0e51d83b379172d7.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22636
985*1B1F64B3-B8A4-4BBB-BB66-F020E2D4F288*.{0,1000}1B1F64B3\-B8A4\-4BBB\-BB66\-F020E2D4F288.{0,1000}offensive_tool_keywordPerfusionExploit for the RpcEptMapper registry key permissions vulnerability (Windows 7 / 2088R2 / 8 / 2012)T1068 - T1055 - T1548.002TA0003 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/itm4n/Perfusion10#GUIDprojectN/A105419752021-04-22T16:20:32Z2021-02-11T18:28:22Z22659
986*1b220d5538e63244c3b81a0c7a83ebb9ac7b0cdaed9f3e84057a812d7192b9b2*.{0,1000}1b220d5538e63244c3b81a0c7a83ebb9ac7b0cdaed9f3e84057a812d7192b9b2.{0,1000}offensive_tool_keywordGTFONowAutomatic privilege escalation for misconfigured capabilities - sudo and suid binaries using GTFOBins.T1548.003 - T1548.002 - T1548.001TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Frissi0n/GTFONow10#filehashN/A66566732024-11-10T08:38:30Z2021-01-18T21:16:40Z22661
987*1B3C96A3-F698-472B-B786-6FED7A205159*.{0,1000}1B3C96A3\-F698\-472B\-B786\-6FED7A205159.{0,1000}offensive_tool_keywordlocalpotatoThe LocalPotato attack is a type of NTLM reflection attack that targets local authentication. This attack allows for arbitrary file read/write and elevation of privilege.T1550.002 - T1078.003 - T1005 - T1070.004TA0004 - TA0006 - TA0002N/AN/APrivilege Escalationhttps://github.com/decoder-it/LocalPotato10#GUIDprojectN/A107691922023-11-07T01:09:08Z2023-01-04T18:22:29Z22668
988*1ba53ac62c21cd1f829f4d4cb0ee06906cd3bfd0cf78da267c3b7d9acfb6d27b*.{0,1000}1ba53ac62c21cd1f829f4d4cb0ee06906cd3bfd0cf78da267c3b7d9acfb6d27b.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22702
989*1BF9C10F-6F89-4520-9D2E-AAF17D17BA5E*.{0,1000}1BF9C10F\-6F89\-4520\-9D2E\-AAF17D17BA5E.{0,1000}offensive_tool_keywordSweetPotatoLocal Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019T1548 - T1055TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/CCob/SweetPotato10#GUIDprojectN/A101016972282024-09-04T17:09:30Z2020-04-12T17:40:03Z22721
990*1c14d0d58efdd3244a1fd4398ef9c65e96bfe4faccc168e7ace84728da908d9e*.{0,1000}1c14d0d58efdd3244a1fd4398ef9c65e96bfe4faccc168e7ace84728da908d9e.{0,1000}offensive_tool_keywordPrivFuenable or disable specific token privileges for a processT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#filehashSwitchPriv1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z22730
991*1c291548b59d3af8b3c225cb7e019b86a3cb706eec437b275528699898bcdb3a*.{0,1000}1c291548b59d3af8b3c225cb7e019b86a3cb706eec437b275528699898bcdb3a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22734
992*1c6b60ff20f7c26a7436d966fc741ecd05dc2b3326de1ebcd7fcf6142ac24409*.{0,1000}1c6b60ff20f7c26a7436d966fc741ecd05dc2b3326de1ebcd7fcf6142ac24409.{0,1000}offensive_tool_keywordRemotePotato0Windows Privilege Escalation from User to Domain Admin.T1078.002 - T1078.003 - T1078.004TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/antonioCoco/RemotePotato010#filehashN/A101013822152022-12-18T01:52:53Z2021-02-08T22:02:19Z22749
993*1cad3b4c47e6f3d4f97c3299b8d1498bd2a4cd3c7eb26f255f693bbcd46fe516*.{0,1000}1cad3b4c47e6f3d4f97c3299b8d1498bd2a4cd3c7eb26f255f693bbcd46fe516.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#filehashKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z22768
994*1d6d4c0b001fc20d404d6e2ec3625d9fc245c31484023e2ac7a3b123eec8cce1*.{0,1000}1d6d4c0b001fc20d404d6e2ec3625d9fc245c31484023e2ac7a3b123eec8cce1.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10#filehashN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z22823
995*1e53b8773c0796d3bed82c67ced0fa96ec2565a697035826a8cec638c6454c7b*.{0,1000}1e53b8773c0796d3bed82c67ced0fa96ec2565a697035826a8cec638c6454c7b.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22891
996*1eb987e0-23a5-415e-9194-cd961314441b*.{0,1000}1eb987e0\-23a5\-415e\-9194\-cd961314441b.{0,1000}offensive_tool_keywordPrivFuSeTcbPrivilege exploitationT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10#GUIDprojectPrivFu\PowerOfTcb1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z22926
997*1f09a88ab2eca35f7e5abd4cc2f11a8f25cd7a060a5c3a943ee88e66fa241dd0*.{0,1000}1f09a88ab2eca35f7e5abd4cc2f11a8f25cd7a060a5c3a943ee88e66fa241dd0.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22954
998*1f350bc4b39f1e89f64366e08af152badfb9756d600b5e611af2433b1e0d3687*.{0,1000}1f350bc4b39f1e89f64366e08af152badfb9756d600b5e611af2433b1e0d3687.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22970
999*1f63e243a7469526eb57f6d08a8d14fbb58290eb999247a005679809fc307edb*.{0,1000}1f63e243a7469526eb57f6d08a8d14fbb58290eb999247a005679809fc307edb.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z22983
1000*205acf53b1ebc226645925788768bf52c0701d3227fedc7565cb803862cee602*.{0,1000}205acf53b1ebc226645925788768bf52c0701d3227fedc7565cb803862cee602.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23060
1001*205acf53b1ebc226645925788768bf52c0701d3227fedc7565cb803862cee602*.{0,1000}205acf53b1ebc226645925788768bf52c0701d3227fedc7565cb803862cee602.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23061
1002*20b948d35e9e730e5aaa00f8de01107af773b93313fed752ae63afcd45353073*.{0,1000}20b948d35e9e730e5aaa00f8de01107af773b93313fed752ae63afcd45353073.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linux #filehashN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z23085
1003*22048db7a9a636d9bebbce5d6e883f87942a5fe9546341bf66d234b89772df4b*.{0,1000}22048db7a9a636d9bebbce5d6e883f87942a5fe9546341bf66d234b89772df4b.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23174
1004*220dea762dec11fe8d6a5b7a24b6af9e4b72dfc084e2b1b835ab661323486ecc*.{0,1000}220dea762dec11fe8d6a5b7a24b6af9e4b72dfc084e2b1b835ab661323486ecc.{0,1000}offensive_tool_keywordShimMeInjects a DLL into a suspended process running as SYSTEM via the OfficeClickToRun service for privilege escalation - Shim Injector: Injects a DLL into a process by modifying shim data in memory without creating or registering new SDB files to evade detection.T1055 - T1053 - T1548.002 - T1078 - T1546 - T1070TA0004 - TA0005 - TA0006 - TA0009N/AN/APrivilege Escalationhttps://github.com/deepinstinct/ShimMe10#filehashN/A92140202024-10-29T07:33:38Z2024-08-04T10:03:28Z23179
1005*227c72ed-494a-4d29-9170-5e5994c12f5c*.{0,1000}227c72ed\-494a\-4d29\-9170\-5e5994c12f5c.{0,1000}offensive_tool_keywordPOCWindows Privilege escalation POC exploitation for CVE-2024-49138T1068 - T1058 - T1203TA0004N/AN/APrivilege Escalationhttps://github.com/emdnaia/CVE-2024-49138-POC10#GUIDprojectN/A91102025-01-15T01:01:21Z2025-01-15T02:11:49Z23218
1006*2297A528-E866-4056-814A-D01C1C305A38*.{0,1000}2297A528\-E866\-4056\-814A\-D01C1C305A38.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#GUIDprojectPrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z23224
1007*233c1188ee1bfe659c4403fda91ac1ce114d9f44f6478cbbe9e8fa22b1e6c600*.{0,1000}233c1188ee1bfe659c4403fda91ac1ce114d9f44f6478cbbe9e8fa22b1e6c600.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23269
1008*233d78a0eb44c9b9d7a92ee810f90dec29ab1778536c1b9f5d16c988ac0c70ab*.{0,1000}233d78a0eb44c9b9d7a92ee810f90dec29ab1778536c1b9f5d16c988ac0c70ab.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23272
1009*234cfdd1b014e769ee31cda9b6dd0a17c05f028a6e059e5bd4d01175e986dfb0*.{0,1000}234cfdd1b014e769ee31cda9b6dd0a17c05f028a6e059e5bd4d01175e986dfb0.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23274
1010*23779f962171cb3bb425ed7cc6aca741338b9340ede2eb8fa70aad40ddcfca8f*.{0,1000}23779f962171cb3bb425ed7cc6aca741338b9340ede2eb8fa70aad40ddcfca8f.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23283
1011*24d861124682031773ac0f6df9e5011b18a8d925c8c22469330826e64ccc2bab*.{0,1000}24d861124682031773ac0f6df9e5011b18a8d925c8c22469330826e64ccc2bab.{0,1000}offensive_tool_keywordlinuxprivcheckersearch for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploitsT1210.001 - T1082 - T1088 - T1547.001TA0002 - TA0004 - TA0006 - TA0007 - TA0008N/AN/APrivilege Escalationhttps://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py10#filehash #linuxN/A71016455242022-01-31T10:32:08Z2016-04-19T13:31:46Z23375
1012*24fe09ac811357d1a5ddd63652604def847cb2d4f81c01ecfe563ead611783e3*.{0,1000}24fe09ac811357d1a5ddd63652604def847cb2d4f81c01ecfe563ead611783e3.{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato10#filehashN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z23384
1013*24fe09ac811357d1a5ddd63652604def847cb2d4f81c01ecfe563ead611783e3*.{0,1000}24fe09ac811357d1a5ddd63652604def847cb2d4f81c01ecfe563ead611783e3.{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato10#filehashN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z23385
1014*2507ccefca7ad5cc4247bae065b0fefb7c3b16cf2d1190535473a05f213d5004*.{0,1000}2507ccefca7ad5cc4247bae065b0fefb7c3b16cf2d1190535473a05f213d5004.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23388
1015*26085f4768e13063e5dde27f0e313854ce91aa032a7b26d4f57ebc03a6628560*.{0,1000}26085f4768e13063e5dde27f0e313854ce91aa032a7b26d4f57ebc03a6628560.{0,1000}offensive_tool_keywordKExecDDAdmin to Kernel code execution using the KSecDD driverT1068 - T1055.011TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/floesen/KExecDD10#filehashN/A83244412024-04-19T09:58:14Z2024-04-19T08:54:49Z23459
1016*261f880e-4bee-428d-9f64-c29292002c19*.{0,1000}261f880e\-4bee\-428d\-9f64\-c29292002c19.{0,1000}offensive_tool_keywordJuicyPotatoNGAnother Windows Local Privilege Escalation from Service Account to SystemT1055.002 - T1078.003 - T1070.004TA0005 - TA0004 - TA0002N/AFoxKitten - APT33 - Volatile Cedar - SandwormPrivilege Escalationhttps://github.com/antonioCoco/JuicyPotatoNG10#GUIDprojectN/A1098441012022-11-12T01:48:39Z2022-09-21T17:08:35Z23467
1017*266fa73ded3a2a2dc421e5605dc2fa2bff53d999fe3adebc44ffa989c33061bf*.{0,1000}266fa73ded3a2a2dc421e5605dc2fa2bff53d999fe3adebc44ffa989c33061bf.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23487
1018*26de444c20c30bd7d731ff5322fca24dc5f442f43daaa5d840edfcc594e17465*.{0,1000}26de444c20c30bd7d731ff5322fca24dc5f442f43daaa5d840edfcc594e17465.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23525
1019*272dd72f9bdff7973ed8b642bf8713ece481e208a77fd03b6a24f2b520e1d49e*.{0,1000}272dd72f9bdff7973ed8b642bf8713ece481e208a77fd03b6a24f2b520e1d49e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23546
1020*27744baf01464354d336015e1051fdc6706235549f5e62e0230e139eb743b4bb*.{0,1000}27744baf01464354d336015e1051fdc6706235549f5e62e0230e139eb743b4bb.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23565
1021*27E42E24-9F76-44E2-B1D6-82F68D5C4466*.{0,1000}27E42E24\-9F76\-44E2\-B1D6\-82F68D5C4466.{0,1000}offensive_tool_keywordPOCLocal Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.T1055.011 - T1548.002TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/hakaioffsec/CVE-2024-2133810#GUIDprojectN/A93292602024-04-16T21:00:14Z2024-04-13T05:53:02Z23589
1022*288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd*.{0,1000}288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23629
1023*288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd*.{0,1000}288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23630
1024*288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd*.{0,1000}288690fbff02ab86b27552a54a1ded2743a4d819b9d3b2106ee91ee74bcda8fd.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23631
1025*28a29dffc8a5924a97a67798c91db2b75d5b2841ec3c810886fa5554fe2e899d*.{0,1000}28a29dffc8a5924a97a67798c91db2b75d5b2841ec3c810886fa5554fe2e899d.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23636
1026*290083a0a3dac6b3c05ab3e01fb5cdfb128c0175914f1fe64cdb1a5e247d43f0*.{0,1000}290083a0a3dac6b3c05ab3e01fb5cdfb128c0175914f1fe64cdb1a5e247d43f0.{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/cube0x0/CVE-2021-167510#filehashN/A101018795822021-07-20T15:28:13Z2021-06-29T17:24:14Z23659
1027*291cf10eee25d10b0ddaddfb68b643dab252c1466fa4e813bb753b19b6604ef1*.{0,1000}291cf10eee25d10b0ddaddfb68b643dab252c1466fa4e813bb753b19b6604ef1.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23669
1028*296176cf45851a6671437cced0cbfaf3aadf9c5d717ea973f911928a36a78442*.{0,1000}296176cf45851a6671437cced0cbfaf3aadf9c5d717ea973f911928a36a78442.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10#filehashN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z23691
1029*2AD3951D-DEA6-4CF7-88BE-4C73344AC9DA*.{0,1000}2AD3951D\-DEA6\-4CF7\-88BE\-4C73344AC9DA.{0,1000}offensive_tool_keywordPrivFuArtsOfGetSystem privesc toolsT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10#GUIDprojectArtsOfGetSystem1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z23775
1030*2AE886C3-3272-40BE-8D3C-EBAEDE9E61E1*.{0,1000}2AE886C3\-3272\-40BE\-8D3C\-EBAEDE9E61E1.{0,1000}offensive_tool_keywordDeadPotatoDeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privilegesT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011N/AN/APrivilege Escalationhttps://github.com/lypd0/DeadPotato10#GUIDprojectN/A104382452024-08-17T06:08:29Z2024-07-31T01:08:30Z23780
1031*2AE886C3-3272-40BE-8D3C-EBAEDE9E61E1*.{0,1000}2AE886C3\-3272\-40BE\-8D3C\-EBAEDE9E61E1.{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato10#GUIDprojectN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z23781
1032*2AE886C3-3272-40BE-8D3C-EBAEDE9E61E1*.{0,1000}2AE886C3\-3272\-40BE\-8D3C\-EBAEDE9E61E1.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato10#GUIDprojectN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z23782
1033*2b0ae5d810f64cc33f7f5df193aa56c3f39d85b0447242491da024b0a1b1a45a*.{0,1000}2b0ae5d810f64cc33f7f5df193aa56c3f39d85b0447242491da024b0a1b1a45a.{0,1000}offensive_tool_keywordPrivFuget SYSTEM integrity level by abusing arbitrary kernel write vulnerability and token privilegesT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#filehashKernelWritePoCs1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z23789
1034*2B704D89-41B9-4051-A51C-36A82ACEBE10*.{0,1000}2B704D89\-41B9\-4051\-A51C\-36A82ACEBE10.{0,1000}offensive_tool_keywordPrivFuSeTcbPrivilege exploitationT1134 - T1134.001 - T1078 - T1059 - T1075TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu/10#GUIDprojectPrivFu\PowerOfTcb1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z23816
1035*2b8c3873a05907a9f2d211fdc992666345d060c7376b6e9760fb800a4a54076c*.{0,1000}2b8c3873a05907a9f2d211fdc992666345d060c7376b6e9760fb800a4a54076c.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23817
1036*2c96a3a04b62c87a9e5179230186d006f49dca951b230c1db6a543d5ee5ef2b6*.{0,1000}2c96a3a04b62c87a9e5179230186d006f49dca951b230c1db6a543d5ee5ef2b6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23890
1037*2cc9517df6d1839ac8bd5077a34ad43f2377e0e4fc9c024f5f9e44b150b94baf*.{0,1000}2cc9517df6d1839ac8bd5077a34ad43f2377e0e4fc9c024f5f9e44b150b94baf.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23900
1038*2CFB9E9E-479D-4E23-9A8E-18C92E06B731*.{0,1000}2CFB9E9E\-479D\-4E23\-9A8E\-18C92E06B731.{0,1000}offensive_tool_keywordNoFilterTool for abusing the Windows Filtering Platform for privilege escalation. It can launch a new console as NT AUTHORITY\SYSTEM or as another user that is logged on to the machine.T1548 - T1548.002 - T1055 - T1055.004TA0004 - TA0003N/AN/APrivilege Escalationhttps://github.com/deepinstinct/NoFilter10#GUIDprojectN/A93298482024-10-29T07:30:35Z2023-07-30T09:25:38Z23912
1039*2daeb177f86c873780c59e59fa8c424e45aea199bf5fb3e935310b043d41787f*.{0,1000}2daeb177f86c873780c59e59fa8c424e45aea199bf5fb3e935310b043d41787f.{0,1000}offensive_tool_keywordPrintNightmarePrintNightmare exploitationT1210 - T1059.001 - T1548.002TA0001 - TA0002 - TA0004N/ADispossessorPrivilege Escalationhttps://github.com/cube0x0/CVE-2021-167510#filehashN/A101018795822021-07-20T15:28:13Z2021-06-29T17:24:14Z23959
1040*2e179a37f42864951b1151bba266fff17c45e6cacf0fbc8ebf8d8ad9ab45ada9*.{0,1000}2e179a37f42864951b1151bba266fff17c45e6cacf0fbc8ebf8d8ad9ab45ada9.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z23984
1041*2e67c9adb1962e9b5c9a025b2901fc01e2a214b53f5552656a07f2057307f6e5*.{0,1000}2e67c9adb1962e9b5c9a025b2901fc01e2a214b53f5552656a07f2057307f6e5.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10#filehashN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z24001
1042*2ebd756e16d30a5270d5b850eac35b51f1448536adb37e1b415669d51b67c775*.{0,1000}2ebd756e16d30a5270d5b850eac35b51f1448536adb37e1b415669d51b67c775.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24040
1043*2ebd756e16d30a5270d5b850eac35b51f1448536adb37e1b415669d51b67c775*.{0,1000}2ebd756e16d30a5270d5b850eac35b51f1448536adb37e1b415669d51b67c775.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24041
1044*2ec87edb4eba79beefc686363936786094dacb8616bdbcccbec2cefc367f080b*.{0,1000}2ec87edb4eba79beefc686363936786094dacb8616bdbcccbec2cefc367f080b.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24045
1045*2ec87edb4eba79beefc686363936786094dacb8616bdbcccbec2cefc367f080b*.{0,1000}2ec87edb4eba79beefc686363936786094dacb8616bdbcccbec2cefc367f080b.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24046
1046*2f00a05b-263d-4fcc-846b-da82bd684603*.{0,1000}2f00a05b\-263d\-4fcc\-846b\-da82bd684603.{0,1000}offensive_tool_keywordTelemetryAbusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges.T1053 - T1547 - T1059TA0003 - TA0005 - TA0004N/AN/APrivilege Escalationhttps://github.com/Imanfeng/Telemetry10#GUIDprojectN/A92140132020-07-02T09:41:27Z2020-06-24T16:30:44Z24074
1047*2fc2426035652b2ecfc952407b4d22ab78b9ae554da8f2466bccf48fa2a3870a*.{0,1000}2fc2426035652b2ecfc952407b4d22ab78b9ae554da8f2466bccf48fa2a3870a.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#filehashPrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z24125
1048*3027a212272957298bf4d32505370fa63fb162d6a6a6ec091af9d7626317a858*.{0,1000}3027a212272957298bf4d32505370fa63fb162d6a6a6ec091af9d7626317a858.{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato10#filehashN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z24165
1049*3027a212272957298bf4d32505370fa63fb162d6a6a6ec091af9d7626317a858*.{0,1000}3027a212272957298bf4d32505370fa63fb162d6a6a6ec091af9d7626317a858.{0,1000}offensive_tool_keywordgodpotatoGodPotato is an advanced privilege escalation tool that utilizes research on DCOM and builds upon years of Potato techniques. It enables privilege escalation to NT AUTHORITY\SYSTEM on Windows systems from 2012 to 2022 by leveraging the ImpersonatePrivilege permission. It addresses limitations of previous Potato versions and can run on almost any Windows OS by exploiting rpcss vulnerabilities.T1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011Ghost RansomwareN/APrivilege Escalationhttps://github.com/BeichenDream/GodPotato10#filehashN/A101019382362023-11-24T19:22:31Z2022-12-23T14:37:00Z24166
1050*3188b14bc09838bf33b57704649237b1c1d343189edaf142cfcf9608c4a41e5d*.{0,1000}3188b14bc09838bf33b57704649237b1c1d343189edaf142cfcf9608c4a41e5d.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24264
1051*31afc2becc2f46a5f993745e453b13146ca804c48eab0c5b41ba859286cad77a*.{0,1000}31afc2becc2f46a5f993745e453b13146ca804c48eab0c5b41ba859286cad77a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24279
1052*320ed251abc046f440dc0e76d00864d6cf5f65dee61988898d86c18e5513a8c9*.{0,1000}320ed251abc046f440dc0e76d00864d6cf5f65dee61988898d86c18e5513a8c9.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService10#filehashN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z24305
1053*329797f116972ec9d9ef719592d687908a2dd4bd5066900bee5452225ca8beb3*.{0,1000}329797f116972ec9d9ef719592d687908a2dd4bd5066900bee5452225ca8beb3.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24338
1054*337cd6f66f324a1e30d9bae046f10577318da2126f3981dfff99c6def8799bd4*.{0,1000}337cd6f66f324a1e30d9bae046f10577318da2126f3981dfff99c6def8799bd4.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24407
1055*337ED7BE-969A-40C4-A356-BE99561F4633*.{0,1000}337ED7BE\-969A\-40C4\-A356\-BE99561F4633.{0,1000}offensive_tool_keywordCoercedPotatoCoercedPotato From Patate (LOCAL/NETWORK SERVICE) to SYSTEM by abusing SeImpersonatePrivilege on Windows 10 Windows 11 and Server 2022.T1548.002 - T1134.002TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/Prepouce/CoercedPotato10#GUIDprojectN/A104366662024-08-26T08:09:00Z2023-09-11T19:04:29Z24409
1056*337ED7BE-969A-40C4-A356-BE99561F4633*.{0,1000}337ED7BE\-969A\-40C4\-A356\-BE99561F4633.{0,1000}offensive_tool_keywordCoercedPotatoRDLLReflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilegeT1055 - T1134 - T1548TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/sokaRepo/CoercedPotatoRDLL10#GUIDprojectN/A103204312023-11-23T18:58:41Z2023-11-23T13:22:38Z24410
1057*347e20ccd42d4346d9a1cb3255d77b493d3b1b52be12f72ccaa9085d6b5dd30f*.{0,1000}347e20ccd42d4346d9a1cb3255d77b493d3b1b52be12f72ccaa9085d6b5dd30f.{0,1000}offensive_tool_keywordBadWindowsServiceAn insecurely implemented and installed Windows service for emulating elevation of privileges vulnerabilitiesT1068 - T1211 - T1050TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/BadWindowsService10#filehashN/A10158102022-08-25T14:22:25Z2022-08-19T15:38:05Z24478
1058*348980f606af2f76e3fb4ac9e1e66f3eb42da0091e72695942a3e97ff7977c0b*.{0,1000}348980f606af2f76e3fb4ac9e1e66f3eb42da0091e72695942a3e97ff7977c0b.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linux #filehashN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z24484
1059*34b4ac22a90064a96fcea9ff8e3f5f3bd089af9672d0e5313d3b1b8f0f0a9125*.{0,1000}34b4ac22a90064a96fcea9ff8e3f5f3bd089af9672d0e5313d3b1b8f0f0a9125.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24496
1060*351268e508cccd1a0bf2c53e605a5db1df85b8c5d4095a4ef0e2d9bb997b39a2*.{0,1000}351268e508cccd1a0bf2c53e605a5db1df85b8c5d4095a4ef0e2d9bb997b39a2.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24518
1061*351b7ea09ad99959f21e0c21bef93112ec360ccef4bc0cbaaed390a16631326b*.{0,1000}351b7ea09ad99959f21e0c21bef93112ec360ccef4bc0cbaaed390a16631326b.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato10#filehashN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z24521
1062*358282c9584c5b32ce5aa55238c71fc7d4cb405e5b7f0ef5e2db4950a4a34b4f*.{0,1000}358282c9584c5b32ce5aa55238c71fc7d4cb405e5b7f0ef5e2db4950a4a34b4f.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24548
1063*363a083ee261a6b87743076d1f38062c4e23d0938817c63dea8716b694c78c7a*.{0,1000}363a083ee261a6b87743076d1f38062c4e23d0938817c63dea8716b694c78c7a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24587
1064*36a795ba9dfe58c4e8cac8b24ada8cbee9b598dc7af6ee076de0b09750aea29a*.{0,1000}36a795ba9dfe58c4e8cac8b24ada8cbee9b598dc7af6ee076de0b09750aea29a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24616
1065*36c88f1852f3c162bf64d973bb6f69ffb7e22503015e104716fc51eaddcbe875*.{0,1000}36c88f1852f3c162bf64d973bb6f69ffb7e22503015e104716fc51eaddcbe875.{0,1000}offensive_tool_keywordDirCreate2SystemWeaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error ReportingT1068 - T1059.001 - T1070.004TA0003 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/binderlabs/DirCreate2System10#filehashN/A84357382022-12-19T17:00:43Z2022-12-15T03:49:55Z24628
1066*36f45e69b0d6ce0325647dbe792399267ce73266f5cc72ca6f2bd845ba5513c9*.{0,1000}36f45e69b0d6ce0325647dbe792399267ce73266f5cc72ca6f2bd845ba5513c9.{0,1000}offensive_tool_keywordPrivFuenable or disable specific token privileges for a processT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#filehashSwitchPriv1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z24642
1067*3727823313bffb3ba255f6bd4be4239a6b6816ead83aa024cec2459e4ef2cbf1*.{0,1000}3727823313bffb3ba255f6bd4be4239a6b6816ead83aa024cec2459e4ef2cbf1.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24662
1068*37447f986ad651df8ea39416f5d5289fda6d3d48155e7ae257c086f9a2478de0*.{0,1000}37447f986ad651df8ea39416f5d5289fda6d3d48155e7ae257c086f9a2478de0.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10#filehashN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z24668
1069*378f6e87219651f96e607e40c229e5f17df4ad71836409881fe3cc77c6780ac7*.{0,1000}378f6e87219651f96e607e40c229e5f17df4ad71836409881fe3cc77c6780ac7.{0,1000}offensive_tool_keywordSharpElevatorSharpElevator is a C# implementation of Elevator for UAC bypassT1548.002 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/SharpElevator10#filehashN/A10151122022-08-31T18:09:10Z2022-08-29T19:52:53Z24686
1070*37ee54a15c44f222327a9d77243113c2b0efb07451eca2f887d314b6e0963f86*.{0,1000}37ee54a15c44f222327a9d77243113c2b0efb07451eca2f887d314b6e0963f86.{0,1000}offensive_tool_keywordSigmaPotatoSeImpersonate privilege escalation toolT1134 - T1055 - T1543TA0004 - TA0005 - TA0003N/AN/APrivilege Escalationhttps://github.com/tylerdotrar/SigmaPotato10#filehashN/A94326382024-05-16T23:46:04Z2023-09-09T01:35:42Z24709
1071*39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6*.{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24797
1072*39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6*.{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24798
1073*39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6*.{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24799
1074*39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6*.{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24800
1075*39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6*.{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24801
1076*39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6*.{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24802
1077*39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6*.{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24803
1078*39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6*.{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24804
1079*39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6*.{0,1000}39210402176e6bf813dbff36370978a66505dc7a25008841e5225603ccbcb8e6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24805
1080*3a0b118ddd6b02426aba9ead93a576f7b99997cf6f07907147dd0d3294ff8887*.{0,1000}3a0b118ddd6b02426aba9ead93a576f7b99997cf6f07907147dd0d3294ff8887.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10#filehashN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z24861
1081*3aa113440e9f684df0d0f889c69ae914a40b07c10a340d1fad4f8365286fe19d*.{0,1000}3aa113440e9f684df0d0f889c69ae914a40b07c10a340d1fad4f8365286fe19d.{0,1000}offensive_tool_keywordKrbRelayUpa universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).T1558 - T1210TA0004 - TA0003N/ADispossessor - Back BastaPrivilege Escalationhttps://github.com/Dec0ne/KrbRelayUp10#filehashN/A101015802092022-08-06T12:23:58Z2022-04-24T21:33:00Z24911
1082*3b02572ebc1fa9eb22898bc2f17f72d50775a18d4c6ff3094ea19e5b5f25c949*.{0,1000}3b02572ebc1fa9eb22898bc2f17f72d50775a18d4c6ff3094ea19e5b5f25c949.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24932
1083*3b730f6be970c1671b68792fe163427a15e0fa4426b1d635d9f7e74872f91a7d*.{0,1000}3b730f6be970c1671b68792fe163427a15e0fa4426b1d635d9f7e74872f91a7d.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z24957
1084*3c3a96d02e34589d314b230c417b122970e492282767211866c8ac042e8bd556*.{0,1000}3c3a96d02e34589d314b230c417b122970e492282767211866c8ac042e8bd556.{0,1000}offensive_tool_keywordS4UTomatoEscalate Service Account To LocalSystem via KerberosT1558 - T1558.002 - T1548.002 - T1078 - T1078.004TA0006 - TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/wh0amitz/S4UTomato10#filehashN/A104394762023-09-14T08:53:19Z2023-07-30T11:51:57Z25017
1085*3cb401fdba1a0e74389ac9998005805f1d3e8ed70018d282f5885410d48725e1*.{0,1000}3cb401fdba1a0e74389ac9998005805f1d3e8ed70018d282f5885410d48725e1.{0,1000}offensive_tool_keywordtraitorAutomatically exploit low-hanging fruit to pop a root shell. Linux privilege escalation made easyT1068 - T1548.004 - T1611 - T1203 - T1059.004TA0004 - TA0001 - TA0002 - TA0005N/AN/APrivilege Escalationhttps://github.com/liamg/traitor10#linux #filehashN/A101068536512024-03-12T21:01:14Z2021-01-24T10:50:15Z25050
1086*3cd433ed1ca4566eade23d65399ebc7399e230fcdbde56deb29891e0213aefc1*.{0,1000}3cd433ed1ca4566eade23d65399ebc7399e230fcdbde56deb29891e0213aefc1.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25057
1087*3ce51c89b8367bae6cae0ff3fa4bbe420df215568e10af5f7b29b3e19048a2e8*.{0,1000}3ce51c89b8367bae6cae0ff3fa4bbe420df215568e10af5f7b29b3e19048a2e8.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25063
1088*3e3092fdc0f518823e6cdbff46f7ad327bee6bca9477a826279c7a76bffa7bce*.{0,1000}3e3092fdc0f518823e6cdbff46f7ad327bee6bca9477a826279c7a76bffa7bce.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25136
1089*3e55d1d13465cb7e706efa6d4ddf120b35200d694c619889de3d3190236e780a*.{0,1000}3e55d1d13465cb7e706efa6d4ddf120b35200d694c619889de3d3190236e780a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25149
1090*3e667715625410352da4236f16184e38c442b2af48fd6f8899b954578c974c8b*.{0,1000}3e667715625410352da4236f16184e38c442b2af48fd6f8899b954578c974c8b.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25154
1091*3e6ea66956ca27686fdb0b1a7fa1a86ddec39e72aa892958bf9f3b4c5dbce7df*.{0,1000}3e6ea66956ca27686fdb0b1a7fa1a86ddec39e72aa892958bf9f3b4c5dbce7df.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25159
1092*3e95f084c11e971e4b30805e59d4cef87b5698ba21ce72b8a228b4e33c069754*.{0,1000}3e95f084c11e971e4b30805e59d4cef87b5698ba21ce72b8a228b4e33c069754.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25171
1093*3eca25646f5d9435a6d13eaed2781aaa5efad2a3e512e154892f7a5cde46805f*.{0,1000}3eca25646f5d9435a6d13eaed2781aaa5efad2a3e512e154892f7a5cde46805f.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25187
1094*3ef06f25d21583d9c1158704c593f3276a1056cf6d23f8c56d8dac84df5320de*.{0,1000}3ef06f25d21583d9c1158704c593f3276a1056cf6d23f8c56d8dac84df5320de.{0,1000}offensive_tool_keywordDeadPotatoDeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privilegesT1134.001 - T1068 - T1055 - T1546.015TA0004 - TA0006 - TA0011N/AN/APrivilege Escalationhttps://github.com/lypd0/DeadPotato10#filehashN/A104382452024-08-17T06:08:29Z2024-07-31T01:08:30Z25201
1095*3ef598c9422361f5ce5252d0c4261d88889b51c2c9794ca6a72c6669e77526b1*.{0,1000}3ef598c9422361f5ce5252d0c4261d88889b51c2c9794ca6a72c6669e77526b1.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25202
1096*3f4dc752db705589bdb8e487a55dbdc6891c13c557ec0383701fc5b94d8f8264*.{0,1000}3f4dc752db705589bdb8e487a55dbdc6891c13c557ec0383701fc5b94d8f8264.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25227
1097*3f7216ab8b49c48f550b68c1e5b8d55f10ff60506090ff19e8b6654186b7bf5c*.{0,1000}3f7216ab8b49c48f550b68c1e5b8d55f10ff60506090ff19e8b6654186b7bf5c.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25239
1098*40e7b75207030fb9603977b5b4fb3a8e67f73a243f004cc6eac07114f2ae061a*.{0,1000}40e7b75207030fb9603977b5b4fb3a8e67f73a243f004cc6eac07114f2ae061a.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25370
1099*410D25CC-A75E-4B65-8D24-05FA4D8AE0B9*.{0,1000}410D25CC\-A75E\-4B65\-8D24\-05FA4D8AE0B9.{0,1000}offensive_tool_keywordPrivFuTool to execute token assigned processT1055TA0004N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#GUIDprojectTokenAssignor1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z25384
1100*413be3fa27650bb8202b36a93755e57a56faf88d98f38a8c546ac6117c70575e*.{0,1000}413be3fa27650bb8202b36a93755e57a56faf88d98f38a8c546ac6117c70575e.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25394
1101*4164003E-BA47-4A95-8586-D5AAC399C050*.{0,1000}4164003E\-BA47\-4A95\-8586\-D5AAC399C050.{0,1000}offensive_tool_keywordJuicyPotatoWindows Local Privilege Escalation from Service Account to SystemT1055.012 - T1068 - T1548.002 - T1505.003TA0004 - TA0003 - TA0005N/AN/APrivilege Escalationhttps://github.com/uknowsec/JuicyPotato10#GUIDprojectN/A102190462021-07-01T05:28:41Z2021-06-10T12:06:13Z25407
1102*4164003E-BA47-4A95-8586-D5AAC399C050*.{0,1000}4164003E\-BA47\-4A95\-8586\-D5AAC399C050.{0,1000}offensive_tool_keywordRottenPotatoNGperform the RottenPotato attack and get a handle to a privileged tokenT1134.001 - T1055.012 - T1547.001TA0004N/ASandwormPrivilege Escalationhttps://github.com/breenmachine/RottenPotatoNG10#GUIDprojectN/A8109351832017-12-29T14:38:47Z2017-12-29T13:19:03Z25408
1103*416656DC-D499-498B-8ACF-6502A13EFC9E*.{0,1000}416656DC\-D499\-498B\-8ACF\-6502A13EFC9E.{0,1000}offensive_tool_keywordMakeMeAdminEnables users to elevate themselves to administrator-level rightsT1078 - T1059 - T1087TA0004N/AN/APrivilege Escalationhttps://github.com/pseymour/MakeMeAdmin10#GUIDprojectN/A95430942024-12-22T02:56:23Z2018-05-29T19:42:58Z25409
1104*42560ffa5cc3bf26dd9cf38c0bc8e2dbf853646128af8ca713e579023ff42ada*.{0,1000}42560ffa5cc3bf26dd9cf38c0bc8e2dbf853646128af8ca713e579023ff42ada.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25478
1105*4278e1122672d9c4029ec7c7f3a0e5180d7ad34a24519e80059b8fc9c5ea4df2*.{0,1000}4278e1122672d9c4029ec7c7f3a0e5180d7ad34a24519e80059b8fc9c5ea4df2.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25492
1106*42BDEFC0-0BAE-43DF-97BB-C805ABFBD078*.{0,1000}42BDEFC0\-0BAE\-43DF\-97BB\-C805ABFBD078.{0,1000}offensive_tool_keywordSharpElevatorSharpElevator is a C# implementation of Elevator for UAC bypassT1548.002 - T1548TA0004 - TA0005N/AN/APrivilege Escalationhttps://github.com/eladshamir/SharpElevator10#GUIDprojectN/A10151122022-08-31T18:09:10Z2022-08-29T19:52:53Z25516
1107*42e10ec6f9a5276060bade151ccd929325daa8ac8910ee26de5e6eebe10f77aa*.{0,1000}42e10ec6f9a5276060bade151ccd929325daa8ac8910ee26de5e6eebe10f77aa.{0,1000}offensive_tool_keywordToken-ImpersonationMake a Token (local admin rights not required) or Steal the Token of the specified Process ID (local admin rights required)T1134.001 - T1134.002TA0004 - TA0009N/AN/APrivilege Escalationhttps://github.com/Leo4j/Token-Impersonation10#filehashN/A81732024-03-20T17:07:13Z2023-11-02T10:46:24Z25524
1108*4349B8A8-F17B-44D5-AE4D-21BE9C9D1573*.{0,1000}4349B8A8\-F17B\-44D5\-AE4D\-21BE9C9D1573.{0,1000}offensive_tool_keywordPrivFuPoCs for sensitive token privileges such SeDebugPrivilegeT1068 - T1134 - T1134.001 - T1078 - T1059TA0004 - TA0009 - TA0003N/AN/APrivilege Escalationhttps://github.com/daem0nc0re/PrivFu10#GUIDprojectPrivilegedOperations1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z25549
1109*438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6*.{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25571
1110*438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6*.{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25572
1111*438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6*.{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25573
1112*438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6*.{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25574
1113*438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6*.{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25575
1114*438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6*.{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25576
1115*438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6*.{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25577
1116*438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6*.{0,1000}438257b96cb3f726b6f796f81c5d72d6c9681f3e617ce272b6250a86496fc9c6.{0,1000}offensive_tool_keywordPEASS-ngPEASS-ng - Privilege Escalation Awesome Scripts suiteT1098TA0004 - TA0005N/AScattered Spider* - PLAY - EMBER BEAR - COZY BEAR - DispossessorPrivilege Escalationhttps://github.com/peass-ng/PEASS-ng10#filehashN/A10101734732092025-04-01T04:29:00Z2019-01-13T19:58:24Z25578
The file is too large to be shown. View Raw