
Invoke-LinkSpray
Powershell script to create malicious SMB or WebDAV links to steal NTLM authentication

Powershell script to create malicious SMB or WebDAV links to steal NTLM authentication

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

PowerShell Script to automatically abuse the BadSuccessor vulnerability (CVE-2025-53779)

Powershell Script to build token for CVE-2019-1619

A tool for checking if MFA is enabled on multiple Microsoft Services


Abusing Azure services over C2

C# implementation of SMBExec for remote command execution on Windows targets using NTLM password hashes, enabling lateral movement and pass-the-hash…

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a…

An script to perform kerberos bruteforcing by using impacket

A script to test credentials against Active Directory Federation Services (ADFS), allowing password spraying or bruteforce attacks.

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Password Spraying Script detecting current and previous passwords of Active Directory User

Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

an impacket-dependent script exploiting CVE-2019-1040

Python script to detect FortiOS authentication bypass (CVE-2024-55591) by probing WebSocket connections to the management interface, identifying…