
SAMDump
Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++,…

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++,…


Async BOF to automatically extract or renew Kerberos TGTs on a target system.

BOF-based tool to extract browser cookies and credentials from Chrome, Edge, and Firefox via handle duplication and fileless download, with offline…

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Tool to remotely dump secrets from the Windows registry

Post-Exploitation EVTX Analyzer for BloodHound Mapping

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

Extract Windows credentials directly from VM memory snapshots and virtual disks

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map,…

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

Perform a MitM attack and extract clear text credentials from RDP connections

WinRAR 0day CVE-2025-8088 PoC RAR Archive

Extract registry and NTDS secrets from local or remote disk images

Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace