Skip to content
View wisdark's full-sized avatar

Block or report wisdark

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
34 stars written in PowerShell
Clear filter

A simple, lightweight PowerShell script that allows you to remove pre-installed apps, disable telemetry, as well as perform various other changes to declutter and customize your Windows experience.…

PowerShell 42,742 1,695 Updated Mar 23, 2026

Force Remove Copilot, Recall and More in Windows 11

PowerShell 11,079 366 Updated Mar 25, 2026

game of active directory

PowerShell 7,628 1,046 Updated Mar 12, 2026

Privilege Escalation Enumeration Script for Windows

PowerShell 3,771 504 Updated Jan 30, 2026

Automation for internal Windows Penetrationtest / AD-Security

PowerShell 3,652 544 Updated Aug 28, 2025

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.

PowerShell 2,482 366 Updated Dec 31, 2025

A post-exploitation powershell tool for extracting juicy info from memory.

PowerShell 1,865 332 Updated Jun 28, 2024
PowerShell 1,675 311 Updated Apr 14, 2025

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

PowerShell 1,490 141 Updated Feb 18, 2026

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be r…

PowerShell 1,316 174 Updated Nov 22, 2022

A Post-exploitation Toolset for Interacting with the Microsoft Graph API

PowerShell 1,265 160 Updated Jul 22, 2025

Microsoft signed ActiveDirectory PowerShell module

PowerShell 1,013 220 Updated Oct 3, 2019

WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)

PowerShell 779 81 Updated Feb 3, 2023

Azure JWT Token Manipulation Toolset

PowerShell 721 111 Updated Dec 6, 2024

ScriptSentry finds misconfigured and dangerous logon scripts.

PowerShell 625 52 Updated Feb 16, 2026

Cover various security approaches to attack techniques and also provides new discoveries about security breaches.

PowerShell 485 83 Updated Apr 17, 2025

Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with lateral movement within Active Directory environments

PowerShell 441 67 Updated Oct 1, 2025

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

PowerShell 418 63 Updated Jan 13, 2026

PowerShell scripts for alternative SharpHound enumeration, including users, groups, computers, and certificates, using the ActiveDirectory module (ADWS) or System.DirectoryServices class (LDAP).

PowerShell 401 39 Updated Jan 14, 2026

Azure Post Exploitation Framework

PowerShell 245 22 Updated Oct 27, 2025

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

PowerShell 240 24 Updated Oct 30, 2025

Retrieve and display information about active user sessions on remote computers. No admin privileges required.

PowerShell 209 23 Updated Aug 12, 2024

Interactive Shell and Command Execution over Named-Pipes (SMB) for Fileless lateral movement

PowerShell 182 26 Updated May 19, 2025

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

PowerShell 155 23 Updated Jun 10, 2024

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

PowerShell 152 11 Updated Mar 4, 2026

A pure PowerShell solution for Entra OAuth authentication, enabling easy retrieval of access and refresh tokens

PowerShell 132 15 Updated Jan 27, 2026

Inboxfuscation is an advanced offensive & defensive framework for mailbox rule obfuscation and detection in Exchange environments.

PowerShell 81 11 Updated Sep 11, 2025

Advanced In-Memory PowerShell Process Injection Framework

PowerShell 73 10 Updated Jul 16, 2025

PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.

PowerShell 72 11 Updated Oct 22, 2025

Tamper Active Directory user attributes to collect their hashes with MS-SNTP

PowerShell 65 7 Updated Jan 21, 2025
Next