
noPac
CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.

CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.

PowerShell MachineAccountQuota and DNS exploit tools

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

Open source C2 server created for stealth red team operations

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data

Automates local privilege escalation to SYSTEM on domain-joined Windows workstations by relaying NTLM authentication from WebDAV to LDAP, leveraging…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…


Active Directory information dumper via ADWS for evasion purposes.

Automating the MITM attack on WSUS

Tool to enumerate privileged Scheduled Tasks on Remote Systems

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

DCOM in memory and fileless lateral movement techniques through .Net deserilization

AzureRT - A Powershell module implementing various Azure Red Team tactics

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

A Post exploitation tool written in C# uses either CIM or WMI to query remote systems.