Highlights
- Pro
-
Certipy Public
Tool for Active Directory Certificate Services enumeration and abuse
-
ldap3 Public archive
Forked from cannatag/ldap3Fork of LDAP3 supporting channel binding
-
Impacket Public
Modified version of Impacket to use dynamic NTLMv2 Challenge/Response
-
Pypykatz Public
Modified version of Pypykatz to print encrypted credentials
-
PassTheChallenge Public
Recovering NTLM hashes from Credential Guard
-
BloodHound Public archive
Fork of BloodHound with PKI nodes and edges for Certipy along with some minor personal improvements
-
PwnKit Public
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
-
SpoolFool Public
Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)
-
Pachine Public
Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)
-
CallbackHell Public
Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)
-
PrintNightmare Public
Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)
-
PetitPotam Public
Python implementation for PetitPotam
-
SMBGhost Public archive
Scanner for CVE-2020-0796 - SMBv3 RCE
-
BlueGate Public
PoC (DoS + scanner) for CVE-2020-0609 & CVE-2020-0610 - RD Gateway RCE
-
CurveBall Public
PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll)