Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Awesome-RedTeam-Cheatsheet — Red Team Cheatsheet in constant expansion. | Kitploit
Tools/GitHubGitHub/ristbs/awesome-redteam-cheatsheet
Privilege EscalationPersistence MechanismsLateral MovementPenetration TestingLearning & EducationRed TeamingCurated Resources
GitHubristbs/awesome-redteam-cheatsheet

Awesome-RedTeam-Cheatsheet

Red Team Cheatsheet in constant expansion.

View Repository
1.3k167213 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

image


Red Team Techniques

  • Initial Access Techniques (soon)
  • Code Execution Techniques (soon)
  • Lateral Mouvement Techniques (soon)
  • Evasion Techniques (soon)
  • Persistence Techniques (soon)
  • Privilege Escalation Techniques (soon)
  • Credential Dumping Techniques (soon)
  • Pivoting Techniques (soon)

Windows Protocols and Terminologies

  • Windows Protocols and Terminologies Guide (soon)

Miscs

  • OPSEC Guide
  • Malware Development
  • Attacking AD Azure Cloud (soon)

Support

You can support me here 🐱 :

Active-directory-Cheat-sheet

This AD attacks CheatSheet, made by RistBS is inspired by the Active-Directory-Exploitation-Cheat-Sheet repo.

Summary

  • AD Exploitation Cheat Sheet by RistBS
    • Summary
    • Tools
    • Powershell Components
      • Powershell Tricks
      • PSWA Abusing
    • Enumeration
      • GPO enumeration
      • ACL and ACE enumeration
      • RID Cycling
    • Privilege Escalation
      • Token Impersonation
      • Kerberoasting
      • ASREPRoasting
      • DNSAdmin
    • Lateral Mouvement
      • WMIExec
    • Credentials Dumping
      • LSASS Dumping
      • NTDS Dumping
      • DPAPI Abusing
      • LSA Dumping
      • SAM Dumping
      • Dump Registry Remotely and Directly
      • Read GMSA Passwords
    • Hash Cracking
    • Bruteforce AD Password
      • Custom Username and Password wordlist
    • Pivoting
      • SMB Pipes
      • SharpSocks
      • RDP Tunneling via DVC
    • Persistence
      • SIDHistory Injection
      • AdminSDHolder and SDProp
    • ACLs and ACEs Abusing
      • GenericAll
    • Enhanced Security Bypass
      • AntiMalware Scan Interface
      • ConstrainLanguageMode
      • Just Enough Administration
      • ExecutionPolicy
      • RunAsPPL for Credentials Dumping
      • ETW Disabling
    • MS Exchange
      • OWA, EWS and EAS Password Spraying
      • GAL and OAB Extraction
      • PrivExchange
      • ProxyLogon
      • CVE-2020-0688
    • MSSQL Server
      • UNC Path Injection
      • MC-SQLR Poisoning
      • DML, DDL and Logon Triggers
    • Forest Persistence
      • DCShadow
    • Cross Forest Attacks
      • Trust Tickets
      • Using KRBTGT Hash
    • Azure Active Directory (AAD)
      • AZ User Enumeration
      • PowerZure
      • Golden SAML
      • PRT Manipulation
      • MSOL Service Account
    • Miscs
      • Domain Level Attribute
        • MachineAccountQuota (MAQ) Exploitation
        • Bad-Pwd-Count
      • Abusing IPv6 in AD
        • Rogue DHCP
        • IOXIDResolver Interface Enumeration
      • References

Tools

Powershell tools :

  • [⭐] Nishang -> https://github.com/samratashok/nishang

nishang has multiples useful scripts for windows pentesting in Powershell environement.

  • [⭐] PowerView -> https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1

powerview is a script from powersploit that allow enumeration of the AD architecture for a potential lateral mouvement.

Enumeration tools :

  • [⭐] Bloodhound -> https://github.com/BloodHoundAD/BloodHound
  • [⭐] crackmapexec -> https://github.com/byt3bl33d3r/CrackMapExe

AD exploitation toolkit :

  • [⭐] Impacket -> https://github.com/SecureAuthCorp/impacket
  • [⭐] kekeo -> https://github.com/gentilkiwi/kekeo

Dumping Tools :

  • [⭐] mimikatz -> https://github.com/gentilkiwi/mimikatz
  • [⭐] rubeus -> https://github.com/GhostPack/Rubeus

Listener Tool :

  • [⭐] responder -> https://github.com/SpiderLabs/Responder

Powershell Components

Powershell Tricks

PS-Session :

#METHOD 1
$c = New-PSSession -ComputerName 10.10.13.100 -Authentication Negociate -Credential $user
Enter-PSSession -Credential $c -ComputerName 10.10.13.100

# METHOD 2
$pass = ConvertTo-SecureString 'Ab!Q@aker1' -asplaintext -force
$cred = New-Object System.Management.Automation.PSCredential('$user, $pass')
Enter-PSSession -Credential $c -ComputerName 10.10.13.100

PSWA Abusing

allow anyone with creds to connect to any machine and any config

[ ! ] this action require credentials.

Add-PswaAuthorizationRule -UsernName * -ComputerName * -ConfigurationName *

Enumeration

Find user with SPN

using PowerView :

Get-NetUser –SPN

using AD Module :

Get-ADUser -Filter {ServicePrincipalName -ne "$null"} -Properties ServicePrincipalName

Trusts Enumeration

MapTrust :

Invoke-MapDomainTrust

Domain trusts for the current domain :

Download Tool