p0wnedShell. PowerShell Runspace Post Exploitation Toolkit
1.6kStarFighters. A JavaScript and VBScript Based Empire Launcher, which runs within their own embedded PowerShell Host.
321MSBuildShell. MSBuildShell, a Powershell Host running within MSBuild.exe
296CScriptShell. CScriptShell, a Powershell Host running within cscript.exe
163JSMeter. JavaScript Reversed TCP Meterpreter Stager
138TpmInitUACBypass. Bypassing User Account Control (UAC) using TpmInit.exe
130VBSMeter. VBS Reversed TCP Meterpreter Stager
88SmashedPotato. C#
83p0wnedLoader. C#
78HSEVD-StackOverflowX64. HackSys Extreme Vulnerable Driver - Windows 10 x64 StackOverflow Exploit with SMEP Bypass
66p0shKiller. C++
65MacroMeter. VBA Reversed TCP Meterpreter Stager
64MS17-012. MS17-012 - COM Session Moniker EoP Exploit running within MSBuild.exe
59SharpCat. SharpCat - A Simple Reversed Command Shell which can be started using InstallUtil (Bypassing AppLocker)
47TpmInitUACAnniversaryBypass. Bypassing User Account Control (UAC) using TpmInit.exe
44EasySystem. Quick and dirty System (Power)Shell using NamedPipe impersonation.
43HSEVD-ArbitraryOverwriteGDI. HackSys Extreme Vulnerable Driver - ArbitraryOverwrite Exploit using GDI
42HSEVD-StackOverflow. HackSys Extreme Vulnerable Driver - StackOverflow Exploit
32HSEVD-ArbitraryOverwrite. HackSys Extreme Vulnerable Driver - ArbitraryOverwrite Exploit
26p0wnedReverse. PowerShell Runspace Connect-Back Shell
26HSEVD-VariousExploits. HackSys Extreme Vulnerable Driver - Various Windows 7 x86 Kernel Exploits
20HSEVD-StackCookieBypass. HackSys Extreme Vulnerable Driver - StackOverflow with Stack Cookie Bypass Exploit
20HSEVD-StackOverflowGDI. HackSys Extreme Vulnerable Driver - Windows 10 x64 StackOverflow Exploit using GDI
19HSEVD-ArbitraryOverwriteLowIL. HackSys Extreme Vulnerable Driver - ArbitraryOverwrite Exploit using GDI -> Low Integrity to System
15HackTheBox-Jail. HTB Jail Remote Exploit By Cneeliz - 2017
15HackTheBox-Smasher. Python
8FortiParse. Fortigate Configuration Parser
4Tater. Tater is a PowerShell implementation of the Hot Potato Windows Privilege Escalation exploit from @breenmachine and @foxglovesec
4Potato. Windows privilege escalation through NTLM Relay and NBNS Spoofing
3AggressorScripts-1. Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources
2Inveigh. Inveigh is a Windows PowerShell LLMNR/NBNS spoofer with challenge/response capture over HTTP/SMB
2snarf. Snarf man-in-the-middle / relay suite
2