
oscp-notes-2026
OSCP field notebook by Samson Laird: merged technique vault, numbered notes (MIT)

OSCP field notebook by Samson Laird: merged technique vault, numbered notes (MIT)

Performs dictionary-based brute-force login attacks against Instagram accounts using Python, with optional Tor support for anonymized authorized…

Wordlist to crack .zip-file password

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…


A standalone DLL that exports databases in cleartext once injected in the KeePass process.

A collection of all the data i could extract from 1 billion leaked credentials from internet.

A small utility to translate NTDS.dit files to SQLite format.

A C# tool to output crackable DPAPI hashes from user MasterKeys

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

A C# implementation of dumping credentials from Windows Credential Manager

Leak of any user's NetNTLM hash. Fixed in KB5040434

Dump cookies and credentials directly from Chrome/Edge process memory

Leverage WindowsApp createdump tool to obtain an lsass dump

Smart keylogging capability to steal SSH Credentials including password & Private Key

A credential extraction BOF for Veeam Backup and Replication and Veeam One

Extract registry and NTDS secrets from local or remote disk images