NetworkServiceExploit
A simple POC for NetworkService PrivEsc as described by Forshaw (https://www.tiraniddo.dev/2020/04/sharing-logon-session-little-too-much.html)
Most of the code is taken from: https://github.com/milkdevil/incognito2/
There are no reviews yet. Be the first to send feedback to the community and the maintainers!
A simple POC for NetworkService PrivEsc as described by Forshaw (https://www.tiraniddo.dev/2020/04/sharing-logon-session-little-too-much.html)
Most of the code is taken from: https://github.com/milkdevil/incognito2/
LocalPotato
psgetsystem
getsystem via parent process using ps1 & embeded c#ADCSCoercePotato
TokenStealer
powershellveryless
Constrained Language Mode + AMSI bypass all in onejuicy_2
juicypotato for win10 > 1803 & win server 2019whoami-priv-Hackinparis2019
Slides from my talk in "Hackinparis" 2019 editionpsportfwd
a simple portforwarder in ps1 with embeded c# codeRelabelAbuse
pipeserverimpersonate
named pipe server with impersonationHyper-V-admin-EOP
Small POC in powershell exploiting hardlinks during the VM deletion processTroopers24
whoami-priv
Slides from my talk "whoami /priv" at Romhack 2018BadBackupOperator
DFSCoerce-exe-2
DFSCoerce exe revisited version with custom authenticationdiaghub_exploit
Simplified version of Forshaw's Diaghub Collector Exploitbluehatil22
Slides from out talk at BH IL 2022CreateTokenExample
lonelypotato
Switch to JuicyPotato! https://github.com/decoder-it/juicy-potatohacktivity2019
Slides from my presentation at BudapestLove Open Source and this site? Check out how you can help us