Skip to content
View wisdark's full-sized avatar

Block or report wisdark

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
34 stars written in PowerShell
Clear filter

A simple, lightweight PowerShell script that allows you to remove pre-installed apps, disable telemetry, as well as perform various other changes to declutter and customize your Windows experience.…

PowerShell 43,240 1,722 Updated Apr 4, 2026

Force Remove Copilot, Recall and More in Windows 11

PowerShell 11,182 371 Updated Apr 2, 2026

game of active directory

PowerShell 7,662 1,052 Updated Mar 12, 2026

Privilege Escalation Enumeration Script for Windows

PowerShell 3,790 502 Updated Mar 28, 2026

Automation for internal Windows Penetrationtest / AD-Security

PowerShell 3,655 542 Updated Aug 28, 2025

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.

PowerShell 2,490 363 Updated Apr 3, 2026

A post-exploitation powershell tool for extracting juicy info from memory.

PowerShell 1,866 332 Updated Jun 28, 2024
PowerShell 1,676 309 Updated Apr 14, 2025

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

PowerShell 1,493 140 Updated Feb 18, 2026

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be r…

PowerShell 1,317 172 Updated Nov 22, 2022

A Post-exploitation Toolset for Interacting with the Microsoft Graph API

PowerShell 1,270 160 Updated Mar 27, 2026

Microsoft signed ActiveDirectory PowerShell module

PowerShell 1,013 219 Updated Oct 3, 2019

WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)

PowerShell 779 80 Updated Feb 3, 2023

Azure JWT Token Manipulation Toolset

PowerShell 724 112 Updated Dec 6, 2024

ScriptSentry finds misconfigured and dangerous logon scripts.

PowerShell 626 52 Updated Feb 16, 2026

Cover various security approaches to attack techniques and also provides new discoveries about security breaches.

PowerShell 486 82 Updated Apr 17, 2025

Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with lateral movement within Active Directory environments

PowerShell 442 67 Updated Oct 1, 2025

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

PowerShell 420 63 Updated Jan 13, 2026

PowerShell scripts for alternative SharpHound enumeration, including users, groups, computers, and certificates, using the ActiveDirectory module (ADWS) or System.DirectoryServices class (LDAP).

PowerShell 401 38 Updated Jan 14, 2026

Azure Post Exploitation Framework

PowerShell 246 22 Updated Oct 27, 2025

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

PowerShell 240 25 Updated Oct 30, 2025

Retrieve and display information about active user sessions on remote computers. No admin privileges required.

PowerShell 208 23 Updated Aug 12, 2024

Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement

PowerShell 182 26 Updated May 19, 2025

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

PowerShell 155 23 Updated Jun 10, 2024

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

PowerShell 155 11 Updated Mar 4, 2026

A pure PowerShell solution for Entra OAuth authentication, enabling easy retrieval of access and refresh tokens

PowerShell 135 16 Updated Jan 27, 2026

Inboxfuscation is an advanced offensive & defensive framework for mailbox rule obfuscation and detection in Exchange environments.

PowerShell 83 12 Updated Sep 11, 2025

Advanced In-Memory PowerShell Process Injection Framework

PowerShell 73 10 Updated Jul 16, 2025

PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.

PowerShell 72 11 Updated Oct 22, 2025

Tamper Active Directory user attributes to collect their hashes with MS-SNTP

PowerShell 65 7 Updated Jan 21, 2025
Next