Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
HuntCyberArk — CyberArk Security Audit | Kitploit
Tools/GitHubGitHub/logisek/huntcyberark
Vulnerability ScannersAPI Security TestingConfiguration AuditingWeb SecurityNetwork SecurityPenetration TestingCloud SecurityIdentity & Access Management (IAM)AuthenticationRed Teaming
GitHub
236148 months agoReviewed by Kitploit
logisek/huntcyberark

HuntCyberArk

CyberArk Security Audit

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

HuntCyberArk - CyberArk Security Audit Suite

A comprehensive PowerShell-based security assessment tool for CyberArk Privileged Access Management (PAM) platforms. Designed for offensive security professionals, red teamers, and penetration testers.

This tool is designed to run REMOTELY against CyberArk servers via network. It does NOT need to be executed on the CyberArk servers themselves. All checks are performed over the network using PVWA API, port scanning, and web testing.

This tool performs security checks including CIS Benchmark compliance, vendor best practices, blackbox testing, network security analysis, CVE-specific vulnerability checks (including 2025 CVEs), machine identity security, secrets management, zero standing privileges (ZSP) assessment, identity governance, and enhanced security checks.

Key Features

FeatureDescription
Remote AuditingAll checks performed remotely via network - no need to install on CyberArk servers
OPSEC ModeStealth scanning with configurable delays, jitter, and reduced detection footprint
Proxy SupportRoute all traffic through Burp Suite, ZAP, or other intercepting proxies
Timing AttacksDetect user enumeration and blind injection via response timing analysis
JWT SecurityTest for none algorithm bypass, key confusion, weak signing algorithms
WebSocket TestingDiscover real-time endpoints and test for Cross-Site WebSocket Hijacking
WAF EvasionTest encoding bypasses, HTTP Parameter Pollution, request smuggling
User-Agent RotationRandomized or custom User-Agent strings to evade fingerprinting
Parallel ExecutionOptional parallel execution for faster scans
Quiet ModeReduced console output for automation and scripting
Credential SecuritySecure handling with memory cleanup after use
Comprehensive ReportingHTML dashboard, 7 CSV files, and structured JSON for programmatic use
PoC EvidenceRequest/Response proof-of-concept included in HTML report for penetration testing
Selective ExecutionRun only specific check categories (portscan, CVE, blackbox, authenticated, network)
False Positive ReductionBaseline fingerprinting to eliminate SPA catch-all false positives
Identity Auth TestingStartAuthentication/ForgotUsername info disclosure and enumeration checks

Table of Contents

  • Prerequisites
  • Installation
  • Audit Phases & Authentication Requirements
  • Features
  • Usage
  • Parameters
  • Output
    • HTML Report
    • CSV Reports
    • JSON Report
    • Risk Scoring
  • Security Considerations
  • Known Vulnerable CyberArk Versions
  • Troubleshooting
  • References

Prerequisites

System Requirements

RequirementMinimumRecommended
PowerShell7.07.x (latest)
.NET Framework4.54.8+
Operating SystemWindows 10/Server 2016Windows 11/Server 2022
Memory2 GB available4 GB available

Required Access

Audit PhaseAccess Required
Phase 1 (Unauthenticated)Network access to PVWA (HTTPS/443)
Phase 2 (Authenticated)CyberArk API credentials with Vault Admin or Auditor role

Network Requirements

  • Outbound HTTPS (TCP/443) access to the PVWA server
  • For comprehensive port scanning: access to ports 1858, 1859, 3389, 5985, 5986
  • DNS resolution for the target PVWA hostname

Installation

No External Tools Required

This script is fully self-contained and uses only native PowerShell and .NET Framework capabilities. No additional tools or modules need to be installed.

The script leverages:

  • Native .NET Classes: System.Net.Sockets.TcpClient, System.Net.Security.SslStream for network and TLS analysis
  • Built-in Cmdlets: Invoke-WebRequest, Invoke-RestMethod for HTTP/API testing
  • X.509 Certificates: System.Security.Cryptography.X509Certificates for certificate analysis

Step 1: Verify PowerShell Version

Open PowerShell and run:

$PSVersionTable.PSVersion

Ensure the Major version is 7 or higher. If not, download PowerShell 7.x.

Note: This script requires PowerShell 7.0 or later. Windows PowerShell 5.1 is not supported.

Step 2: Download the Script

Option A: Clone the repository (recommended)

git clone https://github.com/Logisek/HuntCyberArk.git
cd HuntCyberArk

Option B: Download directly

# Download to current directory
Invoke-WebRequest -Uri "https://raw.githubusercontent.com/Logisek/HuntCyberArk/main/CyberArk-Security-Audit.ps1" -OutFile "CyberArk-Security-Audit.ps1"

Step 3: Set Execution Policy (if needed)

If you encounter script execution errors, temporarily allow script execution:

# Check current policy
Get-ExecutionPolicy

# Set for current session only (recommended)
Set-ExecutionPolicy -ExecutionPolicy Bypass -Scope Process

# Or unblock the downloaded script
Unblock-File -Path .\CyberArk-Security-Audit.ps1

Step 4: Verify SSL/TLS Configuration

For proper TLS testing, ensure your PowerShell session supports TLS 1.2+:

# Enable TLS 1.2 (recommended to add to your profile)
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12

Step 5: Test Connectivity

Verify you can reach the PVWA server:

# Test basic connectivity
Test-NetConnection -ComputerName pvwa.domain.com -Port 443

# Test HTTPS endpoint
Invoke-WebRequest -Uri "https://pvwa.domain.com/PasswordVault/" -UseBasicParsing -TimeoutSec 10

Optional: Install PowerShell 7 (Recommended)

PowerShell 7 provides improved performance and better TLS support:

# Windows (winget)
winget install Microsoft.PowerShell

# Windows (manual)
# Download from: https://github.com/PowerShell/PowerShell/releases

Audit Phases & Authentication Requirements

The audit runs in two phases, each with different authentication requirements:

Phase 1: Unauthenticated Checks (No credentials required)

External/blackbox testing that can be run without any credentials:

  • Network security (port scanning, vault port exposure)
  • TLS/SSL configuration and certificate analysis
  • Blackbox web security (exposed endpoints, information disclosure)
  • PVWA security headers and cookie security
  • CVE-specific vulnerability testing (including 2025 CVEs)
  • API security testing (unauthenticated endpoints)
  • Component version detection
  • Timing attack detection
  • JWT/OAuth2 security testing
  • WebSocket endpoint discovery
  • WAF evasion testing
  • CyberArk Identity/Privilege Cloud authentication endpoint testing (StartAuthentication, ForgotUsername)

Use Case: Penetration testing, external security assessments, quick reconnaissance

Download Tool