
Rubeus
Trying to tame the three-headed dog.

Trying to tame the three-headed dog.

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

LSTAR - CobaltStrike 综合后渗透插件

A little tool to play with Windows security

Mimikatz implementation in pure Python

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.

Credentials gathering tool automating remote procdump and parse of lsass process.

RunPE implementation with multiple evasive techniques (2)

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

Python alternative to Mimikatz lsadump::dcshadow

Cobalt Strike BOF that creates an LSASS minidump in memory and exfiltrates it over the C2 callback for offline credential parsing with Mimikatz or…

a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

Active Directory security risk assessment tool that evaluates vulnerabilities, misconfigurations, and maturity using a streamlined methodology,…

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.