Lists (3)
Sort Name ascending (A-Z)
Starred repositories
A collection of Azure AD/Entra tools for offensive and defensive security purposes
AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
Kerberos relaying and unconstrained delegation abuse toolkit
Automatic SSTI detection tool with interactive interface
Syscall Shellcode Loader (Work in Progress)
Just another Powerview alternative but on steroids
Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and comprehensive network discovery. Export results as BloodHound‑…
PoC Exploit for the NTLM reflection SMB flaw.
SHAREM is a shellcode analysis framework, capable of emulating more than 20,000 WinAPIs and virutally all Windows syscalls. It also contains its own custom disassembler, with many innovative featur…
BloodHound-MCP-AI is integration that connects BloodHound with AI through Model Context Protocol, allowing security professionals to analyze Active Directory attack paths using natural language ins…
Enhance Your Active Directory Password Spraying with User Intelligence.
gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.
SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.
🐍 TOON for Python (Token-Oriented Object Notation) Encoder/Decoder - Reduce LLM token costs by 30-60% with structured data.
Python alternative to Mimikatz lsadump::dcshadow
A tool for coercing and relaying Kerberos authentication over DCOM and RPC.
A Kerberos AP-REQ hijacking tool with DNS unsecure updates abuse.
Automated exploitation of MSSQL servers at scale
Tool to enumerate privileged Scheduled Tasks on Remote Systems
A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.