This is your work, valued
TaskHound. Tool to enumerate privileged Scheduled Tasks on Remote Systems
★ 312WinSSHound. Windows SSH Misconfiguration Discovery Tool - Map lateral movement paths through misconfigured SSH services in Active Directory environments
★ 91RoguePlanet. RoguePlanet Windows Defender Vulnerability
★ 1.6kHecate. A modern alternative Web-UI for the Mythic Command and Control Server
★ 81vmkit. A header-only, freestanding C++20 template for IR-bytecode VM loaders
★ 27Whisker. Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively adding "Shadow Credentials" to the target account.
★ 951OpenHound. Python
★ 17paexec-py. psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus
★ 43VPK. Vast.ai Password Kracking
★ 96Erebus. Erebus is an Initial Access wrapper for the Mythic Command & Control Server. It converts shellcode into payloads specifically used for phishing and IA operations.
★ 146fsquirt_loader. C
★ 9smbcrawler. smbcrawler is no-nonsense tool that takes credentials and a list of hosts and 'crawls' (or 'spiders') through those shares
★ 189bhcli. CLI tool to interact with the BloodHound CE API
★ 77PowerHub. A post exploitation tool based on a web application, focusing on bypassing endpoint protection and application whitelisting
★ 827DumpGuard. Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.
★ 720BloodHound. Six Degrees of Domain Admin
★ 3.3kremoteKrbRelayx. A tool for coercing and relaying Kerberos authentication over DCOM and RPC.
★ 151HoundTrainer. A tool for managing custom node types and Cypher queries in BloodHound
★ 12ludus-rangecraft. A collection of my personal Ludus configs, custom roles, and environment setups.
★ 8FEX. A fast usermode x86 and x86-64 emulator for Arm64 Linux
★ 7.8kdpapi-projects. DPAPI research and offensive tools
★ 17NetExec. The Network Execution Tool
★ 5.7kMaldevAdventures. A collection repo for my journey of learning malware development. It involves implementing PoCs, techniques and other interesting things.
★ 12printerbugnew. The DCERPC only printerbug.py version
★ 234Crystal-Kit. Evasion kit for Cobalt Strike
★ 481AdaptixC2. AdaptixC2 is a highly modular advanced redteam toolkit
★ 3.4kOperatorsKit. Collection of Beacon Object Files (BOF) for Cobalt Strike
★ 708C2-Tool-Collection. A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.
★ 1.4kShareHound. A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily
★ 310shareql. A domain specific language for matching directories and files in network shares
★ 14UnderlayCopy. PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads
★ 257Vulnacle. A deliberately misconfigured database training appliance
★ 4Extension-Kit. AdaptixFramework Extension Kit
★ 538goexec. Windows remote execution multitool
★ 807SQL-BOF. Library of BOFs to interact with SQL servers
★ 4sekken-enum. adws enumeration bof
★ 173