
BloodHound
Six Degrees of Domain Admin

Six Degrees of Domain Admin

Automating situational awareness for cloud penetration tests.

🔍 Identify and understand the local privilege escalation vulnerability (CVE-2025-68921) in Nahimic audio software, impacting many gaming laptops.

CredsHunter - Credential Hunting scripts for Windows and Linux OS

Windows protocol library, including SMB and RPC implementations, among others.

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted…

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…


Powershell tool to automate Active Directory enumeration.

Determine privileges from cloud credentials via brute-force testing.

Identify privilege escalation paths within and across different clouds

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Active Directory information dumper via ADWS for evasion purposes.