
wpCrack
wordpress hash cracker .

wordpress hash cracker .

Use ESC1 to perform a makeshift DCSync and dump hashes

KrbRoastParser is a tool for parsing Kerberos packets from pcap files to extract AS-REQ, AS-REP and TGS-REP hashes

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

Fast offline auditing of Active Directory passwords using Python.

SécurixOS is a NixOS-based secure operating system tailored for small to medium-sized teams. It provides a minimal, hardened environment with strong…

Pass the Hash to a named pipe for token Impersonation

Pass the Hash to a named pipe for token Impersonation

Tenda AC15 cookie exposure

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)

[UNSUPPORTED] A small tool to turn any entered passphrase into a strong secure password, allowing you to easily use different strong passwords for…

A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

Dump NTDS with golden certificates and UnPAC the hash

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…