
Koh
Captures Windows logon session tokens via token leakage to enable credential reuse and impersonation, with Cobalt Strike BOF integration for…

Captures Windows logon session tokens via token leakage to enable credential reuse and impersonation, with Cobalt Strike BOF integration for…

C# tool for automated password spraying attacks against Active Directory users via LDAP, with configurable delays and password lists, designed for…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Comprehensive self-paced manual on Windows identity, Kerberos, and PKI internals, covering credential dumping, ticket forgery, domain persistence,…

AzureRT - A Powershell module implementing various Azure Red Team tactics

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…

SMB Auto Relay provides the automation of SMB/NTLM Relay technique for pentesting and red teaming exercises in active directory environments.

active directory query tool using LDAP Protocol , helps red teamer / penetration testers to validate users credentials , retrieve information about…

Exploit for Red Hat / GlusterFS CVE-2018-1088 & CVE-2018-1112, featured @ DEFCON 26, Las Vegas!

Python utility that reads accessible gMSA password blobs from Active Directory and extracts plaintext passwords for use in security audits and red…

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code…

Inspect, debug, and visually test Model Context Protocol (MCP) servers from a web UI, CLI, or TUI, with tool/resource exploration, request logging,…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Proof-of-Concept tool to authenticate to an LDAP/S server with a certificate through Schannel

This skill helps Claude write secure code and prevent common vulnerabilities.

Python3 tool to perform password spraying using RDP

Proof-of-concept tool that coerces Windows authentication via MS-DFSNM NetrDfsRemoveStdRoot and NetrDfsAddStdRoot methods for credential relay…