
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Six Degrees of Domain Admin

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to…

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

A PowerShell script for helping to find vulnerable settings in AD Group Policy. (deprecated, use Grouper2 instead!)

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

A PoC application demonstrating the power of an Android kernel arbitrary R/W.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

The world's most powerful System Activity Monitor Engine · 一款功能强大的终端行为采集防御开发套件 ~ 旨在帮助EDR、零信任、数据安全、审计管控等终端安全软件可以快速实现产品功能,…

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…