This is your work, valued
pywhisker. Python version of the C# tool for "Shadow Credentials" attacks
918targetedKerberoast. Kerberoast with ACL abuse capabilities
675shellerator. Simple CLI tool for the generation of bind and reverse shells in multiple languages
393smartbrute. Password spraying and bruteforcing tool for Active Directory Domain Services
388ShadowCoerce. MS-FSRVP coercion abuse PoC
302dcshadow. Python alternative to Mimikatz lsadump::dcshadow
162The-Hacker-Tools. This project is aimed at freely providing technical guides on various hacking tools.
125impacket. Impacket is a collection of Python classes for working with network protocols.
78httpmethods. HTTP verb tampering & methods enumeration
69telegram-bot-cli. This is a command line tool I use when I want to get notified, on Telegram (on my phone), that something has finished running (on my laptop).
62uberfile. Simple CLI tool for the generation of downloader oneliners for UNIX-like or Windows systems
44hashonymize. Anonymize your hashcat formatted files for online cracking
31Get-GPPPassword. Python script for extracting and decrypting Group Policy Preferences passwords
26google-colab-hashcat. Jupyter Notebook
24CVE-2020-7961. Exploit script for CVE-2020-7961
18GeoWordlists. GeoWordlists is a tool to generate wordlists of passwords containing cities at a defined distance around the client city.
11openvpn-install. OpenVPN road warrior installer for Debian, Ubuntu and CentOS
10blackhat-arsenal-tools. Official Black Hat Arsenal Security Tools Repository
7Responder. Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
6BloodHound.py. A Python based ingestor for BloodHound
6PetitPotam. C
5CrackMapExec. A swiss army knife for pentesting networks
5PKINITtools. Tools for Kerberos PKINIT and relaying to AD CS
4bloodhound-quickwin. Simple script to extract useful informations from the combo BloodHound + Neo4j
4GoldenCopy. Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket.
4Powermad. PowerShell MachineAccountQuota and DNS exploit tools
3krbrelayx. Kerberos unconstrained delegation abuse toolkit
3volatility3. Volatility 3.0 development
3ldeep. In-depth ldap enumeration utility
3badges. ToolsWatch and Black Hat Arsenal selection of badges
3username-anarchy. Username tools for penetration testing
3CrackMapExec-MachineAccountQuota. CrackMapExec module that retrieves the "MachineAccountQuota" domain-level attribute.
2BloodHound. Six Degrees of Domain Admin
2infosec-events.
2Keyboard. C++
1github-actions-nested-workflows. GHA bug showcase
1