


Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been…

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

Security Manage Framwork is a security management platform for enterprise intranet, which includes asset management, vulnerability management,…

PhantomJS uses internal module: webpage, to open, close, render, and perform multiple actions on webpages, which suffers from an arbitrary file read…

automato should help with automating some of the user-focused enumeration tasks during an internal penetration test.


Microsoft Edge Elevation of Privilege Vulnerability

PeekABoo tool can be used during internal penetration testing when a user needs to enable Remote Desktop on the targeted machine. It uses PowerShell…


Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

CVE-2018-12598

CVE-2018-12597