
custom-oscp-tooling
OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

OSCP field notebook by Samson Laird: merged technique vault, numbered notes (MIT)

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

Hunting for passwords with deep learning

Retrieve AD accounts description and search for password in it

Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet

Cisco ASA Software and ASDM Security Research

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

A tool to query for the existence of pre-windows 2000 computer objects.

CVE-2026-27912 (ResetNightmare) — Linux/impacket port of Semperis Community's Invoke-ResetNightmare PoC

My handbook for Windows Privilege Escalation concepts. Do Check out my Playlist, link: https://www.youtube.com/playlist?list=PLlrnAg4kKF3puXLI0JyltbNJ…

Enumerate and attack Active Directory with LDAP session persistence, ACL abuse, Kerberoasting/ASREProasting, shadow credentials, RBCD, and NTLM relay.

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

Asynchronous RDP client for Python (headless)

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

Modern tactical exploitation toolkit.

Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later