Stars
A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.
JF⚡can - Super fast port scanning & service discovery using Masscan and Nmap. Scan large networks with Masscan and use Nmap's scripting abilities to discover information about services. Generate re…
Mishky's AD Range & The Escalation Path from Hell, version 1.1
A Python native library containing necessary classes, functions and structures to interact with Windows Active Directory.
Active Directory and Internal Pentest Cheatsheets
Check the Domain for Local Admin Access
CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications
ConPtyShell - Fully Interactive Reverse Shell for Windows
A script to generate AV evaded(static) DLL shellcode loader with AES encryption.
SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file.
A script to test an RDP host for sticky keys and utilman backdoor.
🔍 An OSINT tool for discovering linked social accounts and associated emails across multiple platforms using a single username.
fuzzuli is a url fuzzing tool that aims to find critical backup files by creating a dynamic wordlist based on the domain.
A list of useful Powershell scripts with 100% AV bypass (At the time of publication).
An OSINT tool to search for accounts by username and email in social networks.
HackTheBox Certified Penetration Tester Specialist Cheatsheet
A repository that includes all the important wordlists used while bug hunting.
DoS tool for HTTP requests (inspired by hulk but has more functionalities)
WordPress Bruteforce List, Default paths and endpoints
Remotely Enumerate sessions using undocumented Windows Station APIs
Remote Desktop Protocol .NET Console Application for Authenticated Command Execution
AutomatedLab is a provisioning solution and framework that lets you deploy complex labs on HyperV and Azure with simple PowerShell scripts. It supports all Windows operating systems from 2008 R2 to…
BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world.…