Skip to content
View skorov's full-sized avatar

Block or report skorov

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

This is the tool to dump the LSASS process on modern Windows 11

C++ 443 53 Updated Sep 15, 2025

Group Policy Objects manipulation and exploitation framework

Python 258 26 Updated Oct 11, 2025

Credentials recovery project

Python 10,415 2,098 Updated Sep 18, 2025

Windows remote execution multitool

Go 714 70 Updated Oct 1, 2025
PowerShell 4 1 Updated Jan 26, 2023

An even funnier way to disable windows defender. (through WSC api)

C++ 2,890 257 Updated Jul 13, 2025

A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security professionals and CTF players.

Python 1,448 136 Updated Sep 24, 2025

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

PowerShell 161 15 Updated May 13, 2024

Microsoft signed ActiveDirectory PowerShell module

PowerShell 959 217 Updated Oct 3, 2019

DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the default settings).

C# 557 81 Updated Jun 5, 2023

BadZure orchestrates the setup of Azure AD tenants, populating them with diverse entities while also introducing common security misconfigurations to create vulnerable tenants with multiple attack …

Python 468 29 Updated Oct 14, 2025

ScriptSentry finds misconfigured and dangerous logon scripts.

PowerShell 598 53 Updated Dec 20, 2024

Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post

C# 129 22 Updated Jan 14, 2023

GhostBuild is a collection of simple MSBuild launchers for various GhostPack/.NET projects

Python 249 51 Updated Sep 26, 2020

SSH based reverse shell

Go 1,260 168 Updated Sep 18, 2025

A public, open source physical security methodology

46 3 Updated Apr 2, 2024

An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

Go 3,969 387 Updated May 24, 2025

Tool for Active Directory Certificate Services enumeration and abuse

Python 2 Updated Oct 8, 2024

A (partial) Python rewriting of PowerSploit's PowerView

Python 1,049 124 Updated Oct 3, 2025

Tools for Kerberos PKINIT and relaying to AD CS

Python 832 96 Updated Jan 3, 2025

DNSChef - DNS proxy for Penetration Testers and Malware Analysts

Python 1,009 222 Updated Aug 16, 2024

Silentbridge is a toolkit for bypassing 802.1x-2010 and 802.1x-2004.

C 264 44 Updated Jun 13, 2023

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load the C# project.

Python 117 16 Updated May 2, 2024

Timeroasting scripts by Tom Tervoort

Python 363 41 Updated Jun 27, 2025

TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts

C# 1,313 146 Updated Apr 10, 2025
Python 39 3 Updated Mar 25, 2021

SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket

PowerShell 899 118 Updated Jul 26, 2021

Leak NTLM via Website tab in teams via MS Office

78 10 Updated Mar 28, 2024

scan for NTLM directories

Python 370 59 Updated Aug 13, 2025

So, you think you have MFA? AAD/ROPC/MFA bypass testing tool

Go 119 18 Updated Nov 21, 2022
Next