
smbclient-ng
smbclient-ng, a fast and user friendly way to interact with SMB shares.

smbclient-ng, a fast and user friendly way to interact with SMB shares.

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)


An LDAP based Active Directory user and group enumeration tool

Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.

Unveiled at DEF CON 20, NTLM Relaying to ALL THE THINGS!

Asynchronous RDP client for Python (headless)

Password spraying and bruteforcing tool for Active Directory Domain Services

Python library for auditing Microsoft Active Directory via LDAP, supporting NTLM, Kerberos, SSPI authentication, channel binding, encryption, and…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Enumerate information from NTLM authentication enabled web endpoints 🔎

Pure-Python toolkit for Kerberos-based attacks including ASREProast, SPNroast, and LDAP enumeration to identify and exploit vulnerable Active…

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

AzureRT - A Powershell module implementing various Azure Red Team tactics