
squarephish
Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

Dump NTDS with golden certificates and UnPAC the hash

Enumerate information from NTLM authentication enabled web endpoints 🔎

Check for LDAP protections regarding the relay of NTLM authentication

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Certighost POC

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.

True P2P Email on top of Yggdrasil Network for Android

Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html

Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.

SAML2 Burp Extension

AzureRT - A Powershell module implementing various Azure Red Team tactics

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

Linux kernel module implementing a zero-configuration, OTP-based firewall for IoT devices. Transparently authenticates network traffic using a…