
DonPwner
Advanced Domain Controller attack and credential analysis tool leveraging DonPAPI database

Advanced Domain Controller attack and credential analysis tool leveraging DonPAPI database

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Complete credential attack suite for authorized security testing — SSH, FTP, Web Login, Bruteforce, Dictionary attacks

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

PoC for CVE-2024-42049

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

SSH brute-force tool targeting jailbroken iPhones with default 'alpine' password, featuring network scanning, wordlist-based cracking, and file…

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Weaponizing DCOM for NTLM Authentication Coercions

Infection Monkey - An open-source adversary emulation platform

Collection of VBA macro published in our twitter / blog

Leak NTLM via Website tab in teams via MS Office

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Automated NTLM relay attack tool combining Responder poisoning with Impacket relay and secretsdump for credential capture, hash relaying, and lateral…

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…

PACK (Password Analysis and Cracking Kit)