
ldap_shell
Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…


An LDAP based Active Directory user and group enumeration tool

Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.

Asynchronous RDP client for Python (headless)

Password spraying and bruteforcing tool for Active Directory Domain Services

Opens 1K+ IPs or Shodan search results and attempts to login

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

The great CrackMapExec tool compiled for Windows

A fast enumeration tool for Windows Active Directory Pentesting written in Go


**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

Tool for assessing on-premises Microsoft servers authentication such as ADFS, Skype, Exchange, and RDWeb

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

Python3 rewrite of AsOutsider features of AADInternals

LDAP Querying without the Suck

A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.