
StandIn
StandIn is a small .NET35/45 AD post-exploitation toolkit

StandIn is a small .NET35/45 AD post-exploitation toolkit

A powershell script to deploy the registry mitigation key for CVE-2020-1350

This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).

C# tool for enumerating and exploiting misconfigurations in Active Directory Certificate Services (AD CS), enabling certificate template abuse,…

Tools for Kerberos PKINIT and relaying to AD CS

Enumerate AD through LDAP with a collection of helpfull scripts being bundled

Cobalt Strike BOF collection for attacking Azure AD during red team operations, covering authentication, enumeration, and post-exploitation vectors.

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

The vulnerability allowed a low-privileged user to escalate privileges to domain administrator in a default Active Directory environment with the…

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

Unauthenticated RCE at Woody Ad Snippets / CVE-2019-15858 (PoC)

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase"…