
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Adversary Emulation Framework

DejaVU - Open Source Deception Framework

OpSec-safe Powershell runspace from within C# (aka SharpPick) with AMSI, Constrained Language Mode and Script Block Logging disabled at startup

Kerberos relay framework for Windows environments enabling authentication relay, privilege escalation, and lateral movement via LDAP, SMB, HTTP, and…

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

Unveiled at DEF CON 20, NTLM Relaying to ALL THE THINGS!

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

OSCP field notebook: merged technique vault and numbered notes. MIT.

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Offline command line lookup utility for GTFOBins (https://github.com/GTFOBins/GTFOBins.github.io), LOLBAS (https://github.com/LOLBAS-Project/LOLBAS),…

Incriminator is an OpenSource Project with educational purposes that allows you to incriminate other devices during a cybercrime.


LSTAR - CobaltStrike Translated to EN

Exploit for CVE-2020-1472 (ZeroLogon) that resets the domain controller account password and enables DCSync for full domain compromise.

Tunnel TCP connections through a file

Windows Session Hijacking via COM

A compact guide to network pivoting for penetration testings / CTF challenges.