
BloodHound-Legacy
Graph-based tool that maps hidden relationships and attack paths in Active Directory environments to identify and quantify privilege escalation…

Graph-based tool that maps hidden relationships and attack paths in Active Directory environments to identify and quantify privilege escalation…

Windows Privilege Escalation from User to Domain Admin.

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

A multithreaded tool designed to identify if credentials are valid, invalid, or local admin valid credentials within a network at-scale via SMB, plus…

Automated tool to exploit CVE-2018-8581 (PrivExchange) to escalate privileges from Exchange to Domain Admin via NTLM relay, with options for DCSync…

Windows token impersonation tool to list tokens, execute commands as impersonated users, and add domain admin users during Active Directory pentests.

Python exploit for CVE-2019-1040 that abuses Exchange and relay vulnerabilities to achieve RCE and Domain Admin, with options for credential dumping…

Retrieve and display information about active user sessions on remote computers. No admin privileges required.

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

This C# tool sprays for admin access over the entire domain

Python tool exploiting CVE-2019-1040 to perform Kerberos delegation attacks, enabling relay attacks for RCE and domain admin compromise.

Automated Active Directory privilege escalation tool using DCSync to extract krbtgt hash and forge a golden ticket for enterprise admin access.

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

Automated exploitation of CVE-2022-26923 (Certifried) for privilege escalation via AD CS abuse, RBCD, and Kerberos ticket extraction to dump NTLM…

Rust-based exploit for CVE-2021-36934 (HiveNightmare) that dumps SAM, SECURITY, and SYSTEM registry hives from shadow copies for privilege escalation…