Mr-Un1k0d3r/SCShell
Fileless lateral movement tool that relies on ChangeServiceConfigA to run command observed · 2026-08-28
Health v2 · maintenance only
32/100
- Activity 0
- Release rhythm 35
- Longevity 100
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2485
- days_rel: n/a
- days_push: 1151
- n_releases_24m: 0
Adoption not part of the score
1655 stars · 259 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
SCShell is a fileless lateral movement tool that executes commands on remote Windows systems by modifying a service's binary path via ChangeServiceConfigA over DCERPC, without SMB authentication or dropping files. It includes a C utility and a Python implementation supporting pass-the-hash via Impacket.
Use cases
- perform fileless lateral movement on Windows networks
- execute remote commands without creating or registering services
- run payloads over DCERPC instead of SMB
- pass the hash to move laterally with Impacket
- red team remote command execution on Windows hosts
When to choose
- you need stealthy, fileless remote execution on Windows during authorized penetration tests
- you want to avoid SMB authentication and service creation artifacts
- you need pass-the-hash lateral movement support
When to avoid
- you need a defensive or detection tool rather than an offensive one
- you lack authorization to test the target systems
- you need a maintained tool with active development and a license
Facets
cli-tool · maturity maintenance
security penetration-testing security penetration-testing windows windows python cli lateral-movement fileless dcerpc pass-the-hash red-team offensive-security service-abuse
1 source
- readme: https://github.com/Mr-Un1k0d3r/SCShell · fetched 2026-08-28 · 6ec708384bdb
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Mr-Un1k0d3r/SCShell | main | 32 |
For agents
markdown · JSON · MCP: product_card(name="Mr-Un1k0d3r/SCShell")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem