Skip to content
View thecybermafia's full-sized avatar

Block or report thecybermafia

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
26 stars written in PowerShell
Clear filter

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

PowerShell 1,367 129 Updated Oct 29, 2025

Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in them.

PowerShell 1,108 113 Updated Aug 16, 2025

Dominate Active Directory with PowerShell.

PowerShell 1,101 116 Updated Oct 31, 2025

Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.

PowerShell 1,046 105 Updated Nov 3, 2025

PowerHuntShares is an audit script designed in inventory, analyze, and report excessive privileges configured on Active Directory domains.

PowerShell 922 105 Updated Oct 15, 2025

Active Directory Auditing and Enumeration

PowerShell 494 54 Updated Oct 14, 2025

PowerShell scripts for alternative SharpHound enumeration, including users, groups, computers, and certificates, using the ActiveDirectory module (ADWS) or System.DirectoryServices class (LDAP).

PowerShell 388 37 Updated May 16, 2025

An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.

PowerShell 336 54 Updated Nov 4, 2025

LudusHound is a tool for red and blue teams that transforms BloodHound data into a fully functional, Active Directory replica environment via Ludus for controlled testing.

PowerShell 330 23 Updated Sep 3, 2025

A companion tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory

PowerShell 282 29 Updated Oct 23, 2025

A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky assignments, and potential misconfigurations.

PowerShell 276 21 Updated Sep 28, 2025

Privacy and security baseline for personal Windows 10 and Windows 11

PowerShell 204 16 Updated Oct 2, 2023

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

PowerShell 175 19 Updated Oct 30, 2025

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

PowerShell 161 15 Updated May 13, 2024

Permanently disable EDRs as local admin

PowerShell 121 13 Updated Oct 7, 2025

Gain insights into COM/DCOM implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By following this approach, a security researcher will hopeful…

PowerShell 117 10 Updated Oct 30, 2025

Audits an AppLocker policy XML and reports weak/misconfigured/risky settings, including actual ACL checks.

PowerShell 116 10 Updated Aug 19, 2025

Simple PowerShell HTTP Server (no dependencies, single file, PowerShell 5.1/7)

PowerShell 85 6 Updated Jan 14, 2025

Persist like a Dodder

PowerShell 66 4 Updated May 19, 2025

PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.

PowerShell 63 10 Updated Oct 22, 2025

This technique leverages PowerShell's .NET interop layer and COM automation to achieve stealthy command execution by abusing implicit type coercion

PowerShell 51 4 Updated May 16, 2025

Windows Event Log Auditor

PowerShell 50 3 Updated Nov 6, 2025

Decrypt SCCM and DPAPI secrets with Powershell.

PowerShell 41 3 Updated Jun 24, 2025

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

PowerShell 38 1 Updated Oct 28, 2025

Token impersonation in PowerShell to execute under the context of another user.

PowerShell 22 1 Updated Oct 14, 2025
PowerShell 16 1 Updated Aug 12, 2025