
AngryOxide
Offensive 802.11 auditing tool that automates WPA/WPA2 handshake and PMKID capture using deauthentication, rogue-client, and channel-switch attacks,…

Offensive 802.11 auditing tool that automates WPA/WPA2 handshake and PMKID capture using deauthentication, rogue-client, and channel-switch attacks,…

INSTA_CYBER is a Python-powered ethical hacking tool designed for educational and research purposes. Built by Muhammad Sabir Ali (INNO_CYBER), this…

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

Retrieve AD accounts description and search for password in it

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

A tool to query for the existence of pre-windows 2000 computer objects.

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

Remote operations commands implemented using Beacon Object Files

A small utility to translate NTDS.dit files to SQLite format.

A C# tool to output crackable DPAPI hashes from user MasterKeys

Rust in-memory dumper

A C# implementation of dumping credentials from Windows Credential Manager

Leak of any user's NetNTLM hash. Fixed in KB5040434

Leverage WindowsApp createdump tool to obtain an lsass dump

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

NTLMv1 Multitool

POC tool for ResetNightmare (CVE-2026-27912)