
hashcat
World's fastest and most advanced password recovery utility

World's fastest and most advanced password recovery utility

Curated collection of Hashcat password-cracking rules with benchmark data, designed to help red teams and penetration testers crack complex passwords…

A tool for automating cracking methodologies through Hashcat from the TrustedSec team.

All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+…

SMB1 server for NTLMv2 hash interception, written in C.

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

Browser-based password cracking toolkit with hash lookup, wordlist generation, rule-based attack simulation, and client-side hash cracking for…

8-14 character Hashcat masks based on analysis of 3.2 million NTLM hashes cracked while pentesting

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…


Windows绕过EDR实现DumpHash

Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB…

Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes,…

CVE-2026-63030 (wp2shell) POC.

A web front-end for password cracking and analytics

NTLMv1 Multitool