Lists (32)
Sort Name ascending (A-Z)
ad
AI
antispam
api
blue
blueteam
bug bountry
c2
Cheat-Sheet,wiki
cloud
ctf
data
dfir
eva
file
iam
infra
mobile
ntlm
opsec
osint
pentest
phishing
re
recong
spray
sql
web
windows
wordlist
xss
Starred repositories
BOF to steal browser cookies & credentials
The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.
Modular Enumeration and Password Spraying Framework
Username enumeration and password spraying tool aimed at Microsoft O365.
The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷
A curated list of awesome resources related to enhancing your enterprise Email Security
A lightweight GPT model, trained to discover subdomains.
🕵️♂️ All-in-one OSINT tool for analysing any website
The purpose of this project is to demonstrate the Log4Shell exploit with Log4J vulnerabilities using PDF as delivery channel
LudusHound is a tool for red and blue teams that transforms BloodHound data into a fully functional, Active Directory replica environment via Ludus for controlled testing.
🔥 The Web Data API for AI - Turn entire websites into LLM-ready markdown or structured data
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
A library for detecting known secrets across many web frameworks
Decrypt SCCM and DPAPI secrets with Powershell.
TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and penetration tests with the tokens generated working out of t…
Privilege Escalation Enumeration Script for Windows
👻Stowaway -- Multi-hop Proxy Tool for pentesters
Simple pure PowerShell POC to bypass Entra / Intune Compliance Conditional Access Policy
Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab
Investigate malicious Windows logon by visualizing and analyzing Windows event log
linWinPwn is a bash script that streamlines the use of a number of Active Directory tools
PowerHuntShares is an audit script designed in inventory, analyze, and report excessive privileges configured on Active Directory domains.
Active Directory and Internal Pentest Cheatsheets