Highlights
- Pro
Stars
Self-hosted SSH and remote desktop management.
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability).
A .net OLE/COM viewer and inspector to merge functionality of OleView and Test Container
Set of tools to analyze Windows sandboxes for exposed attack surface.
A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its gRPC service no proxies or protocol reimplementa…
C# .Net Framework program that uses RunspaceFactory for Powershell command execution.
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.
Over 600 terminal color schemes/themes for iTerm/iTerm2. Includes ports to Terminal, Konsole, PuTTY, Xresources, XRDB, Remmina, Termite, XFCE, Tilda, FreeBSD VT, Terminator, Kitty, MobaXterm, LXTer…
yq is a portable command-line YAML, JSON, XML, CSV, TOML, HCL and properties processor
Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP callbacks · TLS · Auth · Share links. A powerful pyth…
AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses
Active Directory information dumper via LDAP
A collection of Azure AD/Entra tools for offensive and defensive security purposes
A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
A collaborative, multi-platform, red teaming framework
The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.
Dump Azure AD Connect credentials for Azure AD and Active Directory
Azure Security Resources and Notes
Porting of mimikatz sekurlsa::logonpasswords, sekurlsa::ekeys and lsadump::dcsync commands
A method of bypassing EDR's active projection DLL's by preventing entry point exection
FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more.