
hashcat
World's fastest and most advanced password recovery utility

World's fastest and most advanced password recovery utility

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Wifite but USB-only & cross-platform.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

A tool to query for the existence of pre-windows 2000 computer objects.

John the Ripper jumbo - advanced offline password cracker, which supports hundreds of hash and cipher types, and runs on many operating systems,…

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Embedded Device Security Assessment Framework — 700 modules, 350 CVEs, 55 vendors, APT Group Engine. Covers routers, IP cameras, GPON ONTs, ISP CPEs,…

Remote operations commands implemented using Beacon Object Files

Dependency-free Python PoC generator for CVE-2025-24071 that crafts a malicious .library-ms file in a ZIP to trigger Windows Explorer NTLM hash…

This is a multi-use bash script for Linux systems to audit wireless networks.

Local-network security auditing with EOL, CVE, device identity, and HTML reports

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

Authorized education-sector recon & triage orchestrator (nmap/dirsearch/sqlmap/hydra + CVE-2024-4577, secret/API-key leak, XSS, wp2shell) with a web…

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.