Skip to content
View Pentest0fu's full-sized avatar

Block or report Pentest0fu

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

Python 183 11 Updated Nov 3, 2025

PoC Exploit for the NTLM reflection SMB flaw.

Python 581 123 Updated Jun 15, 2025

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Python 1,228 165 Updated Mar 19, 2025

A command-line tool to query the DeHashed API. Easily search for various parameters like usernames, emails, hashed passwords, IP addresses, and more.

Python 249 54 Updated Jul 2, 2025

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

Go 1,987 192 Updated Nov 5, 2025

E-mails, subdomains and names Harvester - OSINT

Python 14,872 2,337 Updated Nov 4, 2025

MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It ca…

PowerShell 3,143 593 Updated Aug 7, 2025

A tool for checking if MFA is enabled on multiple Microsoft Services

PowerShell 1,582 220 Updated Mar 4, 2025

TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!

Python 1,250 171 Updated Oct 7, 2025

Fast and powerful SSL/TLS scanning library.

Python 3,686 485 Updated Aug 3, 2025

Windows Exploit Suggester - Next Generation

Python 4,673 601 Updated Oct 30, 2025

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 71,422 16,178 Updated Nov 2, 2025

C2 infrastructure over Microsoft Teams.

Go 727 117 Updated Jan 15, 2025

Continuous password spraying tool

Python 195 20 Updated Oct 27, 2025

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP, IMAP, etc from a pcap file or from a live interface.

Python 2,282 429 Updated Aug 22, 2025

Threat Hunting Toolkit is a Swiss Army knife for threat hunting, log processing, and security-focused data science

Shell 145 14 Updated Nov 1, 2025

A tool for parsing breached passwords

Shell 2,048 571 Updated Mar 21, 2024

Python script that converts Grafana hash digests to PBKDF2_HMAC_SHA256 format in order to facilitate password cracking using Hashcat.

Python 25 7 Updated Oct 24, 2021

Automating situational awareness for cloud penetration tests.

Go 2,231 211 Updated Nov 3, 2025

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Python 4,963 763 Updated Jul 24, 2025

Prefetch Explorer Command Line

C# 274 43 Updated Jan 12, 2025

Tool designed to find folder exclusions using Windows Defender using command line utility MpCmdRun.exe as a low privileged user, without relying on event logs

C# 220 20 Updated Oct 6, 2024

Rapidly Search and Hunt through Windows Forensic Artefacts

Rust 3,351 293 Updated Oct 12, 2025

This is the updated script from https://teamrocketist.github.io/2017/08/29/Forensics-Hackit-2017-USB-ducker/

Python 111 30 Updated Apr 20, 2021

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

Go 14,043 2,457 Updated Oct 6, 2025

🔍 gowitness - a golang, web screenshot utility using Chrome Headless

Go 4,032 409 Updated May 27, 2025

An extremely effective subdomain enumeration wordlist of 3,000,000 lines, crafted by harvesting SSL certs from the entire IPv4 space.

710 93 Updated Apr 4, 2023

TerminatorZ is a highly sophisticated and efficient web security tool that scans for top potential vulnerabilities with known CVEs in your web applications.

Shell 283 41 Updated Sep 6, 2024

Script to generate a .pth file which will execute arbitrary commands

Python 1 Updated Jun 15, 2024

Decrypt FortiGate configuration secrets

Python 7 4 Updated Dec 21, 2021
Next