Stars
A simple, lightweight PowerShell script to remove pre-installed apps, disable telemetry, as well as perform various other changes to customize, declutter and improve your Windows experience. Win11D…
Six Degrees of Domain Admin
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
Empire is a PowerShell and Python post-exploitation agent.
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
Red Teaming Tactics and Techniques
Privilege Escalation Enumeration Script for Windows
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It ca…
PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server
Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.
netshell features all in version 2 powershell
A collection of scripts for assessing Microsoft Azure security
Remote Desktop entirely coded in PowerShell.
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAR…
PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.
PowerShell Pass The Hash Utils
Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.
PowerShell MachineAccountQuota and DNS exploit tools
SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be r…
Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment
ConPtyShell - Fully Interactive Reverse Shell for Windows
A PowerShell based utility for the creation of malicious Office macro documents.
Tool to audit and attack LAPS environments
SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket
retrieve information via O365 and AzureAD with a valid cred
GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.
Security auditing tool for Azure environments