
Invoke-BadSuccessor.ps1
PowerShell Script to automatically abuse the BadSuccessor vulnerability (CVE-2025-53779)

PowerShell Script to automatically abuse the BadSuccessor vulnerability (CVE-2025-53779)

Powershell tool to automate Active Directory enumeration.

The ultimate WinRM shell for hacking/pentesting

A fork of the great TokenTactics with support for CAE and token endpoint v2

Dominate Active Directory with PowerShell.

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

AD CS exploitation related stuff goes here

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

PowerShell Pass The Hash Utils

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

A tool for checking if MFA is enabled on multiple Microsoft Services

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

Powershell script to create malicious SMB or WebDAV links to steal NTLM authentication

PowerShell MachineAccountQuota and DNS exploit tools


AzureRT - A Powershell module implementing various Azure Red Team tactics

Detect and abuse risky SPNs

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…