Skip to content
View dafthack's full-sized avatar

Highlights

  • Pro

Organizations

@blackhillsinfosec

Block or report dafthack

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

MCP server that should work with n8n

Python 3 1 Updated Jan 24, 2026
1 Updated Aug 29, 2025

Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com

PowerShell 7,642 1,350 Updated Oct 16, 2025

ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.

HTML 1,913 299 Updated Jun 15, 2020

A script for generating custom passphrase lists to be used for password cracking with hashcat rules

PowerShell 81 22 Updated Jun 27, 2018

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

HTML 1,383 306 Updated May 22, 2020

Credential and Red Teaming Defense for Windows Environments

C++ 330 59 Updated Jul 17, 2024

Chameleon: A tool for evading Proxy categorisation

Python 516 75 Updated Nov 28, 2024

Official Black Hat Arsenal Security Tools Repository

4,283 1,178 Updated Aug 26, 2024

Wiki to collect Red Team infrastructure hardening resources

4,479 911 Updated Oct 1, 2025

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Python 4,155 684 Updated Apr 21, 2024

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 70,969 25,009 Updated May 17, 2026

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

Python 5,726 898 Updated Jan 5, 2026

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique present…

Python 3,912 821 Updated Jan 24, 2024

PowerSploit - A PowerShell Post-Exploitation Framework

PowerShell 12,984 4,716 Updated Aug 17, 2020

Six Degrees of Domain Admin

PowerShell 10,534 1,788 Updated Mar 2, 2026

A post-exploitation OS X/Linux agent written in Python 2.7

Python 871 201 Updated Aug 24, 2017

Empire is a PowerShell and Python post-exploitation agent.

PowerShell 7,835 2,922 Updated Jan 19, 2020

DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAR…

PowerShell 2,054 413 Updated Jul 11, 2024

MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It ca…

PowerShell 3,233 598 Updated Aug 7, 2025