
cloudfox
Automating situational awareness for cloud penetration tests.

Automating situational awareness for cloud penetration tests.

Dominate the domain. Relay to royalty.

An information security preparedness tool to do adversarial simulation.

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

The Shadow Attack Framework

Low-observability Active Directory security enumeration tool using native ADSI/COM interfaces. Enumerates ACLs, delegation, trusts, ADCS, Kerberoast…

A windows token impersonation tool

RedSnarf is a pen-testing / red-teaming tool for Windows environments

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard,…

Source Code Management Attack Toolkit

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

Proof of Concept for CVE-2020-0665, a.k.a. SID Filter Bypass.

Exploit code for CVE-2021-1675, a Windows Print Spooler remote code execution vulnerability, demonstrating the attack and providing a…

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

Tool to discover Resource-Based Constrained Delegation attack paths in Active Directory environments

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…