luckystrike. A PowerShell based utility for the creation of malicious Office macro documents.
1.1kADImporter. Credit to Helge Klein - https://helgeklein.com/blog/2015/02/creating-realistic-test-user-accounts-active-directory/
69rubeus2ccache. Extracts all base64 ticket data from a rubeus /dump file and converts the tickets to ccache files for easy use with other tools.
67ansible-redelk. Ansible playbooks for instrumenting a Red Team environment with RedElk
52activedirectory. This script runs several security checks and makes modifications (with your permission) to your Active Directory domain to improve it's security posture.
45Ludus-MDE-MDI-Roles. Ludus roles to deploy ASR rules and MDI auditing settings
25ludus_badblood. Outfits your ludus AD domain with BadBlood info.
17psfire. simple demo of using C# & System.Management.Automation.dll to run powershell code (b64 encoded) without powershell.exe
14Ansible-SSH-Conf. Uses Ansible to generate a new EC2 instance then an SSH conf file for that instance.
10pssync. Powershell Synchronization Repository
9custompayload. Put output from msfvenom into custom c# project for AV evasion
9dotfiles. Shell
8slides.
5ludus_splunk. A role for installing Splunk Enterprise on a Debian host.
5ptf. The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
4autobrute. Simple http/ntlm brute forcer with some helpful options.
4ludus_splunk_universalforwarder. A role for deploying the Splunk UF to lab hosts.
4metasploit-framework. Metasploit Framework
3ansible_arch_vm. Ansible playbook to build and configure an Arch VM
3dnscat2-powershell. A Powershell port of dnscat2, a DNS covert channel tool.
1unicorn. Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.
1vcr-1. Vulnerability Compliance Report Tool used to parse Nessus files into html reports created by SynerComm, Inc.
1SCShell. Fileless lateral movement tool that relies on ChangeServiceConfigA to run command
1Powermad. PowerShell MachineAccountQuota and DNS exploit tools
1AndrewSpecial. AndrewSpecial, dumping lsass' memory stealthily and bypassing "Cilence" since 2019.
1gimme. A tool for alerting on searches for products you want. Shameless streaming project. xDD
1ROADtools. The Azure AD exploration framework.
1