
Checklists
Red Teaming & Pentesting checklists for various engagements

Red Teaming & Pentesting checklists for various engagements

PowerShell Pass The Hash Utils

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

The Shadow Attack Framework

SharpSploit is a .NET post-exploitation library written in C#

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly.

Powershell C2 Server and Implants

Freedom Fighting Mode: open source hacking harness

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

PowerShell-based post-exploitation framework for lateral movement in Active Directory environments. Executes in-memory with named-pipe command…

A windows token impersonation tool

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Assist reverse tcp shells in post-exploration tasks

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation