
trident
automated password spraying tool

System-wide NTLM relay tool that hooks Windows authentication APIs to relay incoming NTLM connections, downgrade Kerberos, and dump NetNTLM hashes…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

👻Impost3r -- A linux password thief

Xenotix Python Keylogger for Windows.

A password guessing tool that targets the Kerberos and LDAP services within the Windows Active Directory environment.

Automated Linux evil maid attack

Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types

Credential Guard Bypass Via Patching Wdigest Memory

COFF file (BOF) for managing Kerberos tickets.

Asynchronous Password Spraying Tool in C# for Windows Environments

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

This repository presents a proof-of-concept of CVE-2023-7028

Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging