


Perform a MitM attack and extract clear text credentials from RDP connections

A simple super fast django reusable app that blocks people from brute forcing login attempts

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.

Windows Privilege Escalation from User to Domain Admin.

Tool to remotely dump secrets from the Windows registry

Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.

SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.

Enumerate information from NTLM authentication enabled web endpoints 🔎

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

KrbRoastParser is a tool for parsing Kerberos packets from pcap files to extract AS-REQ, AS-REP and TGS-REP hashes

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

Generate a RSA PEM key pair from pure JS

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.