
TaskHound
Tool to enumerate privileged Scheduled Tasks on Remote Systems

Tool to enumerate privileged Scheduled Tasks on Remote Systems

ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current…

PowerShell module for administering and auditing Azure AD and Office 365, enabling token manipulation, user enumeration, and security assessments of…

Parses AD Explorer snapshots into BloodHound-compatible JSON or NDJSON for Active Directory reconnaissance and attack path mapping.

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

Tooling for assessing an Azure AD tenant state and configuration

A tool to help query AD via the LDAP protocol

Identify the attack paths in BloodHound breaking your AD tiering

Stealthy LDAP query BOF for Active Directory reconnaissance via AD WS, enabling attribute enumeration and data collection for red team operations.

Enumerate AD through LDAP with a collection of helpfull scripts being bundled

Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a single XSLX +…

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

PowerShell tool for enumerating Azure AD users, devices, applications, and domains via Microsoft Graph API, with offline data export capability.

Iterative AD discovery toolkit for offensive operations

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

Collects and analyzes AD and Azure AD authentication logs to detect lateral movement attacks using graph-based anomaly detection, visualizing…

Converts Active Directory Explorer snapshot (.dat) files into BloodHound CE JSON archives for graph-based AD attack-path analysis and reconnaissance.

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…