Privilege Escalation / Looting
Python3 script to dump breach data from Dehashed
Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)
KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).
Linux enumeration tool for pentesting and CTFs with verbosity levels
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
An advanced graphical search engine for Exploit-DB
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
Scripted Local Linux Enumeration & Privilege Escalation Checks
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
linuxprivchecker.py -- a Linux Privilege Escalation Check Script
Windows Post-Exploitation tools wrapper
Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling
LPE exploit for CVE-2023-21768
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )
Matrix42 executable and DLL to decrypt password hashes
Hide your Powershell script in plain sight. Bypass all Powershell security features
Red Teaming & Pentesting checklists for various engagements
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.
Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.
OSINT Tool for Finding Passwords of Compromised Email Addresses
A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.