
powerview.py
Enumerate and attack Active Directory with LDAP session persistence, ACL abuse, Kerberoasting/ASREProasting, shadow credentials, RBCD, and NTLM relay.

Enumerate and attack Active Directory with LDAP session persistence, ACL abuse, Kerberoasting/ASREProasting, shadow credentials, RBCD, and NTLM relay.

Leak of any user's NetNTLM hash. Fixed in KB5040434

COFF file (BOF) for managing Kerberos tickets.

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…

D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root…

:smiley_cat: Running Hashcat on Google Colab with session backup and restore.

C# tool to dump all cookies from Chrome/Edge browsers, including httpOnly and secure flags, for session hijacking and post-exploitation credential…