Skip to content
View wisdark's full-sized avatar

Block or report wisdark

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
32 stars written in PowerShell
Clear filter

A simple, lightweight PowerShell script to remove pre-installed apps, disable telemetry, as well as perform various other changes to customize, declutter and improve your Windows experience. Win11D…

PowerShell 36,099 1,400 Updated Dec 16, 2025

game of active directory

PowerShell 7,243 1,013 Updated Jul 16, 2025

A tool which is uses to remove Windows Defender in Windows 8.x, Windows 10 (every version) and Windows 11.

PowerShell 6,749 443 Updated Jun 6, 2025

Automation for internal Windows Penetrationtest / AD-Security

PowerShell 3,616 545 Updated Aug 28, 2025

Privilege Escalation Enumeration Script for Windows

PowerShell 3,598 497 Updated Nov 19, 2025

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.

PowerShell 2,444 353 Updated Nov 8, 2025

A post-exploitation powershell tool for extracting juicy info from memory.

PowerShell 1,864 333 Updated Jun 28, 2024
PowerShell 1,651 312 Updated Apr 14, 2025

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be r…

PowerShell 1,308 175 Updated Nov 22, 2022

A Post-exploitation Toolset for Interacting with the Microsoft Graph API

PowerShell 1,236 151 Updated Jul 22, 2025

Microsoft signed ActiveDirectory PowerShell module

PowerShell 977 219 Updated Oct 3, 2019

WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)

PowerShell 778 82 Updated Feb 3, 2023

Azure JWT Token Manipulation Toolset

PowerShell 698 109 Updated Dec 6, 2024

ScriptSentry finds misconfigured and dangerous logon scripts.

PowerShell 614 55 Updated Dec 20, 2024

Cover various security approaches to attack techniques and also provides new discoveries about security breaches.

PowerShell 483 79 Updated Apr 17, 2025

Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with lateral movement within Active Directory environments

PowerShell 430 67 Updated Oct 1, 2025

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

PowerShell 408 62 Updated Sep 27, 2024

PowerShell scripts for alternative SharpHound enumeration, including users, groups, computers, and certificates, using the ActiveDirectory module (ADWS) or System.DirectoryServices class (LDAP).

PowerShell 393 39 Updated May 16, 2025

Azure Post Exploitation Framework

PowerShell 242 22 Updated Oct 27, 2025

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

PowerShell 232 24 Updated Oct 30, 2025

Retrieve and display information about active user sessions on remote computers. No admin privileges required.

PowerShell 200 23 Updated Aug 12, 2024

Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement

PowerShell 181 25 Updated May 19, 2025

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

PowerShell 154 24 Updated Jun 10, 2024

A pure PowerShell solution for Entra OAuth authentication, enabling easy retrieval of access and refresh tokens

PowerShell 120 9 Updated Dec 14, 2025

Inboxfuscation is an advanced offensive & defensive framework for mailbox rule obfuscation and detection in Exchange environments.

PowerShell 79 10 Updated Sep 11, 2025

PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.

PowerShell 72 11 Updated Oct 22, 2025

Advanced In-Memory PowerShell Process Injection Framework

PowerShell 71 10 Updated Jul 16, 2025

Fuegoshell is a powershell oneliner generator for Windows remote shell re-using TCP 445

PowerShell 53 7 Updated Apr 27, 2024

Tamper Active Directory user attributes to collect their hashes with MS-SNTP

PowerShell 41 7 Updated Jan 21, 2025

Active directory Attacks and Scripts

PowerShell 27 9 Updated Sep 8, 2023
Next