
LaZagne
Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager


Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy . Brutal is…

CVE-2023-24055 PoC (KeePass 2.5x)

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

An Advanced C# .NET Rat, It’s Stable and Contains Many Features.

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment

Script to steal passwords from ssh.

A post-exploitation powershell tool for extracting juicy info from memory.

Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021-43798)

ParadoxiaRat : Native Windows Remote access Tool.

Beacon Object File for in-line LSASS credential extraction using the KslD.sys BYOVD technique. Extracts NT hashes and cleartext passwords from…