ZeroDayLab / PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework
☆216Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for PowerSploit
- ☆350Updated 3 years ago
- RACE is a PowerShell module for executing ACL attacks against Windows targets.☆212Updated last year
- Dumping LAPS from Python☆255Updated last year
- Invoke-ZeroLogon allows attackers to impersonate any computer, including the domain controller itself, and execute remote procedure calls…☆215Updated 4 years ago
- Kerberos Resource-Based Constrained Delegation Attack from Outside using Impacket☆496Updated 2 years ago
- PowerShell Constrained Language Mode Bypass☆232Updated 3 years ago
- Collection of some of my own tools with other great open source tools out there packaged into a powershell module☆143Updated 2 years ago
- scan for NTLM directories☆346Updated 4 months ago
- WSuspicious - A tool to abuse insecure WSUS connections for privilege escalations☆346Updated 4 years ago
- A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.☆163Updated 2 years ago
- Proof-of-concept obfuscation toolkit for C# post-exploitation tools☆413Updated 2 years ago
- Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types☆372Updated last year
- ADCS abuser☆256Updated last year
- SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket☆763Updated 3 years ago
- Lists who can read any gMSA password blobs and parses them if the current user has access.☆244Updated 9 months ago
- Collection of cyphers for bloodhound☆143Updated 4 months ago
- ☆181Updated 5 years ago
- A proof of concept on attack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)☆178Updated 3 years ago
- Inject remote template link into word document for remote template injection☆160Updated 3 years ago
- Enumerate Domain Data☆316Updated last year
- ☆349Updated 3 years ago
- Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory☆377Updated 7 months ago
- A Cobalt Strike tool to audit Active Directory user accounts for weak, well known or easy guessable passwords.☆425Updated 2 years ago
- ☆198Updated last year
- Simple script to extract useful informations from the combo BloodHound + Neo4j☆197Updated 11 months ago
- Evil SQL Client (ESC) is an interactive .NET SQL console client with enhanced SQL Server discovery, access, and data exfiltration feature…☆280Updated last year
- Password spraying tool and Bloodhound integration☆213Updated last year
- Collection of remote authentication triggers in C#☆464Updated 6 months ago
- Bypass for PowerShell Constrained Language Mode☆375Updated 2 years ago
- Automating juicy potato local privilege escalation exploit for penetration testers☆138Updated 3 years ago