Active Directory certificate abuse
☆43Oct 9, 2022Updated 3 years ago
Alternatives and similar repositories for CertifyKit
Users that are interested in CertifyKit are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Cheatsheet for Altered Security's CESP ADCS course☆18Nov 15, 2023Updated 2 years ago
- Beacon Object File (BOF) to retrieve and decrypt the the LAPSv2 password from the Windows Active Directory and Microsoft Azure/Entra Acti…☆21Oct 24, 2025Updated 9 months ago
- Dump Teams conversations☆18Jun 9, 2021Updated 5 years ago
- TokenCert☆105Nov 15, 2024Updated last year
- UAC Bypass using RequestTrace scheduled task☆28Jul 23, 2026Updated 2 weeks ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- 用Go开发的Java字节码解析器,和“javap”命令作用一致 Java class file parser plays the same role as "javap"☆18Oct 17, 2017Updated 8 years ago
- Remote process shellcode injection with interactive output via named pipes☆50Jan 10, 2024Updated 2 years ago
- Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post☆133Jan 14, 2023Updated 3 years ago
- Purple Team Dropper generator using open source templates.☆17May 23, 2024Updated 2 years ago
- ☆45Oct 16, 2023Updated 2 years ago
- Rust implementation, creating a scheduled task programmatically with user logon trigger.☆47Jun 10, 2025Updated last year
- Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)☆745May 7, 2025Updated last year
- 🕵️ Real-time desktop surveillance over HTTP - DXGI capture, MJPEG stream, single C binary, zero dependencies. Built for red teams with n…☆22Jul 28, 2026Updated 2 weeks ago
- The program uses the Windows API functions to traverse through directories and locate DLL files with RWX section☆113Jul 15, 2023Updated 3 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- AV/EDR killer leveraging vulnerable kernel drivers☆494Nov 28, 2023Updated 2 years ago
- Bypass Credential Guard by patching WDigest.dll using only NTAPI functions☆270Apr 8, 2025Updated last year
- OPSEC safe Kerberoasting in C#☆200Jun 14, 2022Updated 4 years ago
- Installing wazuh SIEM Unified XDR and SIEM protection☆34Jun 3, 2025Updated last year
- 👻inject_und3ad -- 蚁剑(AntSword)插件☆24Aug 8, 2019Updated 7 years ago
- all random stuff that dont warrant a seperate repo☆12Sep 2, 2022Updated 3 years ago
- ☆123Oct 9, 2023Updated 2 years ago
- Tool to aid in dumping LSASS process remotely☆44Sep 23, 2025Updated 10 months ago
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆58Feb 20, 2022Updated 4 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- New exploitation tricks for hardened .NET Remoting servers☆33Aug 5, 2025Updated last year
- BurpSuite Rpc 算法转发插件☆17Jan 4, 2023Updated 3 years ago
- A Stealthy Lsass Dumper - can abuse ProcExp152.sys driver to dump PPL Lsass, no dbghelp.lib calls.☆326Jan 31, 2023Updated 3 years ago
- .NET wrapper around LogonUserA to test creds☆13Jun 2, 2022Updated 4 years ago
- ☆38Jun 5, 2023Updated 3 years ago
- early cascade injection PoC based on Outflanks blog post☆241Nov 7, 2024Updated last year
- Implant drop-in for EDR testing☆147Nov 15, 2023Updated 2 years ago
- ☆24Jul 2, 2024Updated 2 years ago
- 基于多种策略, 对已有 JAR 包中的全限定类名进行变换, 无限生成高度相似的虚假类名☆20Jul 30, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆389Dec 13, 2024Updated last year
- Performing Indirect Clean Syscalls☆620May 2, 2026Updated 3 months ago
- "Service-less" driver loading☆191Nov 28, 2024Updated last year
- Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain☆385Sep 20, 2025Updated 10 months ago
- This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone…☆221Oct 19, 2024Updated last year
- ☆133Jan 23, 2025Updated last year
- A basic exemple of the API-Hashing method used by Red Teamers but also by malwares developers in C++☆37Jan 10, 2024Updated 2 years ago