
cloudfox
Automating situational awareness for cloud penetration tests.

Automating situational awareness for cloud penetration tests.

Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive…

Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop

Windows-native penetration testing swiss army knife for lateral movement, credential access, data exfiltration, and vulnerability scanning across…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Dominate the domain. Relay to royalty.

Fileless Command Execution for Lateral Movement in Nim

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

Automates NTLM relay exploitation using ntlmrelayx.py for SMB share enumeration, shell execution, secrets dumping, and MSSQL command execution via…

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Deploy payloads to *Nix systems en masse

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

ProfileHound - BloodHound OpenGraph collector for user profiles stored on domain machines. Make informed decisions about looting secrets by…

Post-exploitation toolkit for Azure AD: fetch/search Microsoft Graph data, swap FOCI refresh tokens, and generate Azure CLI auth files from tokens.

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…