Skip to content
View Wh04m1001's full-sized avatar

Block or report Wh04m1001

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

PowerShell collector for adding MSSQL attack paths to BloodHound with OpenGraph

PowerShell 264 16 Updated Oct 16, 2025

Shows which M365 Objects have Privileged Access and what type (i.e. PIM, Direct, Currently Elevated)

PowerShell 34 4 Updated May 17, 2025

Admin to Kernel code execution using the KSecDD driver

C 259 43 Updated Apr 19, 2024

Windows NT ioctl bruteforcer and modular fuzzer

C++ 124 30 Updated Jan 15, 2019

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

Go 1,987 192 Updated Oct 30, 2025

quicmap is a simple yet quic (!) QUIC protocol scanner

Python 90 16 Updated Mar 12, 2024

Browser's XSS Filter Bypass Cheat Sheet

1,142 213 Updated May 6, 2017

Scanner for CVE-2020-0796 - SMBv3 RCE

Python 701 193 Updated Oct 1, 2020

SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers

C# 1 1 Updated Nov 10, 2023

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

C# 578 62 Updated Mar 19, 2024

linWinPwn is a bash script that streamlines the use of a number of Active Directory tools

Shell 2,106 295 Updated Nov 2, 2025

SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Directory Web Services (ADWS) protocol.

C# 827 89 Updated Feb 3, 2024

Async Python library to parse local and remote disk images.

Python 80 8 Updated Jul 11, 2025

Privilege escalation using the XAML diagnostics API (CVE-2023-36003)

C++ 94 22 Updated Jan 11, 2024

DDSpoof is a tool that enables DHCP DNS Dynamic Update attacks against Microsoft DHCP servers in AD environments.

Python 133 14 Updated Apr 12, 2024

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be r…

PowerShell 1,293 175 Updated Nov 22, 2022

To audit the security of read-only domain controllers

C# 117 8 Updated Nov 27, 2023

This repository contains various XXE labs set up for different languages and their different parsers. This may alternatively serve as a playground to teach or test with Vulnerability scanners / WAF…

PHP 112 37 Updated Mar 22, 2024

Tools for Attacking Pleasant Password Server

C# 22 4 Updated Sep 19, 2023

Python script to enumerate valid Microsoft 365 domains, retrieve tenant name, and check for an MDI instance.

Python 204 34 Updated Nov 13, 2024

Weaponized CobaltStrike BOF for CVE-2023-36874 Windows Error Reporting LPE

C++ 205 26 Updated Aug 25, 2023

PoC to coerce authentication from Windows hosts using MS-WSP

C# 295 39 Updated Sep 7, 2023

Custom Queries - Brought Up to BH4.1 syntax

263 45 Updated Sep 11, 2025

Impacket pre-compiled binaries

17 Updated Jul 31, 2023

Simple BOF to read the protection level of a process

C 119 10 Updated May 10, 2023
Next