
WinFlesher
Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

Collects Active Directory object metadata, group memberships, sessions, ACLs, and trusts to feed BloodHound attack-path mapping for security…

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

Python implementation of OpenPsPipeJack

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Weaponizing DCOM for NTLM Authentication Coercions

Weaponizing DCOM for NTLM Authentication Coercions

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

A BloodHound collector for Microsoft Configuration Manager


A simple POC that abuses Backup Operator privileges to remote dump SAM, SYSTEM, and SECURITY

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

Penetration testing framework with AI-driven decision engine

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY,…