
Minimalistic-offensive-security-tools
A repository of tools for pentesting of restricted and isolated environments.

A repository of tools for pentesting of restricted and isolated environments.

Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability

PoC exploit for CVE-2025-24071, a Windows File Explorer spoofing vulnerability that leaks NTLM hashes via malicious .library-ms files in RAR/ZIP…

VBScript tool that extracts and displays saved Wi-Fi passwords from Windows systems, outputting credentials to a text file for local access.

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

Harvests NetNTLM hashes in Windows domains via a local WebDAV server, with LNK file poisoning and Office document field code injection for lateral…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

Xenotix Python Keylogger for Windows.

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will…

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

Proof-of-concept for CVE-2022-42176: hard-coded credentials in PCSecure configuration file allow local privilege escalation to admin panel and…