
ADReaper
A fast enumeration tool for Windows Active Directory Pentesting written in Go

A fast enumeration tool for Windows Active Directory Pentesting written in Go

Opens 1K+ IPs or Shodan search results and attempts to login


WireBug is a toolset for Voice-over-IP penetration testing

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…


A "plugin" for Android Java to allow asking the user about SSL certificates

A tool for enumerating potential hosts that are open to GSSAPI abuse within Active Directory networks

Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).

Docker-based CVE-2018-10933 libssh authentication bypass exploit with patched client for testing SSH server vulnerabilities and unauthorized access…

Find authentication (authn) and authorization (authz) security bugs in web application routes.

KrbRoastParser is a tool for parsing Kerberos packets from pcap files to extract AS-REQ, AS-REP and TGS-REP hashes

Proof-of-concept exploit for CVE-2022-22972 that bypasses authentication in VMware Workspace ONE, vIDM, and vRealize Automation 7.6 via Host header…

Vault app for DC34 badge

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Serverless AITM Simulation Framework for Entra ID and M365

A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability