
Kestrel
Low-observability Active Directory security enumeration tool using native ADSI/COM interfaces. Enumerates ACLs, delegation, trusts, ADCS, Kerberoast…

Low-observability Active Directory security enumeration tool using native ADSI/COM interfaces. Enumerates ACLs, delegation, trusts, ADCS, Kerberoast…

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

A HTA shell to assist with breakout assessments.

Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)

Kali365 - EvilTokens Replica

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

Offline AI Security Assistant for Air-Gapped Pentesting

GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted…

WIP Post-exploitation framework tailored for hypervisors.

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

DDoor - cross platform backdoor using dns txt records

Python implementation of OpenPsPipeJack

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

Post-Exploitation EVTX Analyzer for BloodHound Mapping

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.