
PsMapExec
Dominate Active Directory with PowerShell.

Dominate Active Directory with PowerShell.

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

Powershell script to create malicious SMB or WebDAV links to steal NTLM authentication

PowerShell Pass The Hash Utils

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

Powershell tool to automate Active Directory enumeration.

PowerShell MachineAccountQuota and DNS exploit tools

Some scripts to abuse kerberos using Powershell

AzureRT - A Powershell module implementing various Azure Red Team tactics

A Powershell implementation of PrivExchange designed to run under the current user's context

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

PowerShell Script to automatically abuse the BadSuccessor vulnerability (CVE-2025-53779)

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

PoC for CVE-2021-26088 written in PowerShell

PowerShell toolkit to audit, harden, and hunt for insecure NTLM/SMB usage, addressing CVE-2025-50154 credential leak risks with event log analysis…

Powershell Script to build token for CVE-2019-1619

A tool for checking if MFA is enabled on multiple Microsoft Services