
TruffleSnout
Iterative AD discovery toolkit for offensive operations

Iterative AD discovery toolkit for offensive operations

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

Collects and analyzes AD and Azure AD authentication logs to detect lateral movement attacks using graph-based anomaly detection, visualizing…

Converts Active Directory Explorer snapshot (.dat) files into BloodHound CE JSON archives for graph-based AD attack-path analysis and reconnaissance.

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

User enumeration and password spraying tool for testing Azure AD

Analyzing AD domains for security risks related to user accounts

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

Retrieve AD accounts description and search for password in it

The vulnerability allowed a low-privileged user to escalate privileges to domain administrator in a default Active Directory environment with the…

Azure AD Password Checker

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

Active Directory Forensic Toolkit : Detect & reconstruct AD attacks from Windows event logs (EVTX)

Unauthenticated RCE at Woody Ad Snippets / CVE-2019-15858 (PoC)

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

active directory query tool using LDAP Protocol , helps red teamer / penetration testers to validate users credentials , retrieve information about…