Skip to content

Instantly share code, notes, and snippets.

b4cktr4ck2 / esc1.ps1
Created February 22, 2023 21:50
PowerShell script to exploit ESC1/retrieve your own NTLM password hash.
#Thank you @NotMedic for troubleshooting/validating stuff!
$password = Read-Host -Prompt "Enter Password"
#^^ Feel free to hardcode this for running in a beacon/not retyping it all the time!
$server = "admin" #This will just decide the name of the cert request files that are created. I didn't want to change the var name so it's server for now.
$CERTPATH = "C:\Users\lowpriv\Desktop\" #Where do you want the cert requests to be stored?
$CAFQDN = "dc01.alexlab.local" #hostname of underlying CA box.
$CASERVER = "alexlab-dc01-ca" #CA name.
BOLL7708 / twitch-bonus-auto-claimer.js
Last active July 26, 2023 17:35
BOLL's UserScripts
// ==UserScript==
// @name Twitch Bonus Auto Claimer
// @namespace
// @homepageURL
// @downloadURL
// @match *://*
// @match *://*
// @grant GM_getValue
// @grant GM_setValue
// @version 1.0
solariz / rescreen.c
Created February 3, 2021 07:56
tiny tool to move all Windows to the main Screen
/* tiny tool to move all Windows to the main Screen
using System;
using System.Diagnostics;
using System.Runtime.InteropServices;
namespace rescreen
class Program
0xdevalias /
Last active March 27, 2023 03:38
(unofficial) Guide to Viome API Endpoints, Data Export and Backup

(unofficial) Guide to Viome API Endpoints, Data Export and Backup

Since Viome doesn't appear to offer us a way to export our data aside from as a PDF, I was inspired to have a look if I could see it any other way.

The CEO says that they don't release the raw data:

TarlogicSecurity /
Created May 14, 2019 13:33
A cheatsheet with commands that can be used to perform kerberos attacks

Kerberos cheatsheet



python -domain <domain_name> -users <users_file> -passwords <passwords_file> -outputfile <output_file>

With Rubeus version with brute module:

nmap --top-ports <#ports> -v -oG - localhost

Top 100:


Top 1000:

##Custom TMUX settings
# 0 is too far from ` ;)
set -g base-index 1
#Set colors to work
set -g default-terminal "screen-256color"
#Remap Prefix to screens
set -g prefix C-a
bind C-a send-prefix
function Invoke-ExcelMacroPivot{
Matt Nelson (@enigma0x3)
Pivots to a remote host by using an Excel macro and Excel's COM object
Remote host to pivot to
.PARAMETER RemoteDocumentPath
Local path on the remote host where the payload resides
function Create-LNKPayload{
Generates a malicous LNK file
Name of the LNK file you want to create.
function Invoke-UACBypass {
Bypasses UAC on Windows 10 by abusing the SilentCleanup task to win a race condition, allowing for a DLL hijack without a privileged file copy.
Author: Matthew Graeber (@mattifestation), Matt Nelson (@enigma0x3)
License: BSD 3-Clause
Required Dependencies: None
Optional Dependencies: None