SnaffCon / Snaffler
a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )
☆2,115Updated last week
Related projects ⓘ
Alternatives and complementary repositories for Snaffler
- Tool for Active Directory Certificate Services enumeration and abuse☆2,401Updated 2 months ago
- Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure …☆2,290Updated last month
- A Python based ingestor for BloodHound☆1,934Updated 3 months ago
- Extract credentials from lsass remotely☆2,050Updated last month
- Active Directory certificate abuse.☆1,510Updated 2 months ago
- ☆1,526Updated 4 months ago
- Automation for internal Windows Penetrationtest / AD-Security☆3,334Updated 9 months ago
- Privilege Escalation Enumeration Script for Windows☆2,962Updated this week
- Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab☆2,008Updated 6 months ago
- Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.☆1,968Updated last year
- BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of…☆2,036Updated last year
- Trying to tame the three-headed dog.☆4,117Updated last month
- DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will auto…☆1,779Updated 3 months ago
- A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for secu…☆1,183Updated 3 months ago
- TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!☆1,052Updated 2 months ago
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.☆2,478Updated last year
- A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)☆993Updated 5 months ago
- A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.☆1,812Updated 3 weeks ago
- Dumping DPAPI credz remotely☆991Updated last week
- KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default…☆1,528Updated 2 years ago
- A tool to perform Kerberos pre-auth bruteforcing☆2,648Updated 2 months ago
- ScareCrow - Payload creation framework designed around EDR bypass.☆2,732Updated last year
- This repo contains some Amsi Bypass methods i found on different Blog Posts.☆1,703Updated 4 months ago
- A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.☆1,790Updated 3 weeks ago
- WADComs is an interactive cheat sheet, containing a curated list of offensive security tools and their respective commands, to be used ag…☆1,425Updated 4 months ago
- Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensi…☆3,768Updated 4 months ago
- Starkiller is a Frontend for PowerShell Empire.☆1,373Updated last month
- SharpUp is a C# port of various PowerUp functionality.☆1,256Updated 8 months ago
- Compiled Binaries for Ghostpack☆1,169Updated 2 weeks ago
- Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities☆1,554Updated 3 years ago