
ldapnomnom
Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)

Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)

Password spraying and bruteforcing tool for Active Directory Domain Services

Pure-Python toolkit for Kerberos-based attacks including ASREProast, SPNroast, and LDAP enumeration to identify and exploit vulnerable Active…

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Improved SMTP Checker / SMTP Cracker with proxy-support, inbox test and many more features.

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Opens 1K+ IPs or Shodan search results and attempts to login

Relational database brute force and post exploitation tool for MySQL and MSSQL

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

Scripts and utilities to help your hacking needs

The IoT security toolkit to help identify IoT related dashboards and scan them for default passwords and vulnerabilities.

A simple Python script that reads a text file with lots of e-mails and passwords, and tries to check if those credentials are valid by trying to…

Retrieve AD accounts description and search for password in it


WITCHCRAFT is a cyberdeck toolkit built for runners who dive deep into the mesh. It’s your all-in-one rig for data-ghosting, ICE-breaking, and…

This repository holds interesting bits and pieces related to research I performed on wireless presentation devices manufactured by Awindinc and…