
AutoPtT
Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. In C#, C++, Crystal, Python, Rust, Golang, Nim…

Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. In C#, C++, Crystal, Python, Rust, Golang, Nim…

Loot and decrypt Windows DPAPI secrets remotely or offline, including masterkeys, credentials, vaults, certificates, browser data, and cached Azure…

Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!

Active Directory security risk assessment tool that evaluates vulnerabilities, misconfigurations, and maturity using a streamlined methodology,…

Red teaming tool to dump LSASS memory, bypassing basic countermeasures.

A little tool to play with Windows security

Extract Windows credentials directly from VM memory snapshots and virtual disks

Mimikatz implementation in pure Python

Dominate Active Directory with PowerShell.

Trying to tame the three-headed dog.

RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.

RunPE implementation with multiple evasive techniques (2)

Python alternative to Mimikatz lsadump::dcshadow

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Cobalt Strike BOF that creates an LSASS minidump in memory and exfiltrates it over the C2 callback for offline credential parsing with Mimikatz or…

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…

SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…