
PowerLurk
Malicious WMI Events using PowerShell

Malicious WMI Events using PowerShell


Collection of PowerShell functions a Red Teamer may use in an engagement

A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.

Interactive shell for Active Directory enumeration and ACL abuse via LDAP/LDAPS. Supports DCSync, RBCD, Shadow Credentials, password changes, and…

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

SMBeagle - Fileshare auditing tool.

iOS gamed exploit (fixed in 15.0.2)

Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.

Chat with hacker assistant

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Bash script purposed for system enumeration, vulnerability identification and privilege escalation.

.NET-based Active Directory enumeration tool inspired by PowerView. Enumerates domains, users, computers, groups, shares, and sessions. Supports LDAP…

Tool to enumerate privileged Scheduled Tasks on Remote Systems

A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build…

n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

Identify the attack paths in BloodHound breaking your AD tiering

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…