
Maestro
Abusing Azure services over C2

Abusing Azure services over C2

Weaponizing DCOM for NTLM Authentication Coercions

The great CrackMapExec tool compiled for Windows


A BloodHound collector for Microsoft Configuration Manager

Offline command line lookup utility for GTFOBins (https://github.com/GTFOBins/GTFOBins.github.io), LOLBAS (https://github.com/LOLBAS-Project/LOLBAS),…

Tool to enumerate privileged Scheduled Tasks on Remote Systems

ProfileHound - BloodHound OpenGraph collector for user profiles stored on domain machines. Make informed decisions about looting secrets by…


Retrieve and display information about active user sessions on remote computers. No admin privileges required.


C# port of WMImplant which uses either CIM or WMI to query remote systems

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

PowerShell toolkit for Active Directory penetration testing, featuring domain/user/group enumeration, trust relationship analysis, RDP configuration,…

This C# tool sprays for admin access over the entire domain