
DonPAPI
Automated remote credential dumper for Windows environments, extracting DPAPI secrets, browser credentials, certificates, and configuration files…

Automated remote credential dumper for Windows environments, extracting DPAPI secrets, browser credentials, certificates, and configuration files…

The great CrackMapExec tool compiled for Windows

A fast enumeration tool for Windows Active Directory Pentesting written in Go

Automated vulnerability scanner for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass) with TLS certificate enumeration, authentication…

Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.

Post-Exploitation EVTX Analyzer for BloodHound Mapping

Weaponizing DCOM for NTLM Authentication Coercions

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy

Exploits Windows IPv6 default configuration to spoof DNS via DHCPv6, redirecting victim traffic for credential relaying and man-in-the-middle attacks…

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

Proof-of-concept for CVE-2021-3130: demonstrates credential exposure via HTML obfuscation bypass in Open-AudIT up to 4.0.2, revealing SSH, SNMP, and…

⭐⭐ Join us at SNIA SDC for the SMB3 IO Lab (September 28 - October 1, 2026), see upcoming Interoperability Events

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

Decrypt GlobalProtect configuration and cookie files.

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

A tool for checking if MFA is enabled on multiple Microsoft Services

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.