
ntlmscout
Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

Enumerate user accounts and registered authentication methods via the Microsoft Self-Service Password Reset (SSPR) portal

Dependency-free Python PoC generator for CVE-2025-24071 that crafts a malicious .library-ms file in a ZIP to trigger Windows Explorer NTLM hash…

Research tool that scans SSH services for authentication bypasses, timing leaks, weak keys, and post-session exposures, with JSON output and analysis.

PHP-based iCloud Apple ID dictionary attack tool that bypasses account lockout and secondary authentication to brute-force credentials.

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

Offensive 802.11 auditing tool that automates WPA/WPA2 handshake and PMKID capture using deauthentication, rogue-client, and channel-switch attacks,…

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

Retrieve AD accounts description and search for password in it

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

A tool to query for the existence of pre-windows 2000 computer objects.

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

Remote operations commands implemented using Beacon Object Files

A small utility to translate NTDS.dit files to SQLite format.

A C# tool to output crackable DPAPI hashes from user MasterKeys

Rust in-memory dumper

A C# implementation of dumping credentials from Windows Credential Manager

Leak of any user's NetNTLM hash. Fixed in KB5040434