
Credential-Hunting
CredsHunter - Credential Hunting scripts for Windows and Linux OS

CredsHunter - Credential Hunting scripts for Windows and Linux OS

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted…

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…

Modern tactical exploitation toolkit.

Centralized data enrichment platform for offensive security assessments that ingests, enriches, and enables collaborative analysis of collected files…

Powershell tool to automate Active Directory enumeration.

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

Async BOF to capture KeePass master passwords by detecting and keylogging locked database windows.

fsociety Hacking Tools Pack – A Penetration Testing Framework

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

abusing windows toast notifications for fun and user manipulation