BaldHead is a modular and interactive Active Directory (AD) attack framework built for red teamers and security testers. It automates enumeration and exploitation of AD misconfigurations
☆109Apr 11, 2026Updated last month
Alternatives and similar repositories for BaldHead
Users that are interested in BaldHead are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Dumping LSASS Evaded Endpoint Security Solutions☆18Feb 15, 2025Updated last year
- rust port of pspy with support for process monitoring over dbus☆37Jan 4, 2026Updated 4 months ago
- Ludus role for deploying a Cobalt Strike Teamserver onto Linux servers☆19Mar 19, 2025Updated last year
- Aliasr is a modern, feature-rich TUI launcher for pentest commands.☆112Apr 23, 2026Updated last month
- Python tool to automatically perform SPN-less RBCD attacks.☆130Jan 7, 2026Updated 4 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A comprehensive collection of study materials, practice exams, and resources that helped me successfully pass the CISSP exam.☆14Feb 7, 2025Updated last year
- NTLM HTTP relay tool with SOCKS proxy for browser session hijacking☆161Apr 6, 2026Updated last month
- A Windows tool that converts LDIF files to BloodHound CE☆32Dec 20, 2025Updated 5 months ago
- BusPwn V1.0 is a powerful Modbus hacking framework designed for testing and exploiting vulnerabilities in Modbus-based systems commonly f…☆28Apr 19, 2025Updated last year
- Охотник (Hunter) is a simple Adversary Simulation tool developed for achieves stealth through API unhooking, direct and indirect syscalls…☆95Apr 23, 2025Updated last year
- Advanced In-Memory PowerShell Process Injection Framework☆74Jul 16, 2025Updated 10 months ago
- Automating the MITM attack on WSUS☆364Apr 3, 2026Updated last month
- PowerShell-based utility for mapping byte offsets to source code using hex and ASCII context for detection research and red team tooling.☆33Dec 31, 2025Updated 4 months ago
- Pure PowerShell port of PassTheCert tool to authenticate to an LDAP/S server with a certificate through Schannel☆64Apr 13, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A Burp Extension that makes it easier to view all script code on a Response.☆17Nov 12, 2023Updated 2 years ago
- Tiny and fast port scanner (Sliver edition)☆30Feb 17, 2026Updated 3 months ago
- A practical client for ADWS in Golang.☆53Mar 3, 2026Updated 2 months ago
- This script analyzes the DCSync output file from several tools (such as Mimikatz, Secretsdump and SharpKatz...)☆70Mar 17, 2025Updated last year
- Script related in Active Directory Attacks Domain☆24Aug 19, 2023Updated 2 years ago
- ☆158Apr 4, 2025Updated last year
- Dump LSASS via physical memory read primitives in vulnerable kernel drivers☆329Feb 2, 2026Updated 3 months ago
- modified mssqlclient from impacket to extract policies from the SCCM database☆47Feb 24, 2026Updated 3 months ago
- Automated Cloud Misconfiguration Testing☆25Jun 20, 2025Updated 11 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆19Sep 1, 2025Updated 8 months ago
- KQL queries for Incident Response☆14Oct 31, 2023Updated 2 years ago
- alternative to procdump☆11May 26, 2021Updated 5 years ago
- Client-side Encrypted Upload Server Python Script☆67Jul 10, 2025Updated 10 months ago
- Golang Automation Framework for Cobalt Strike using the Rest API☆59Apr 10, 2026Updated last month
- Audiodg.exe DLL hijacking for LPE with reboot-free restart primitive. Executes code as LOCAL SERVICE, escalates to SYSTEM via Scheduled T…☆93Jan 24, 2026Updated 4 months ago
- Interract with Microsoft SQL Server (MS SQL | MSSQL) servers and their linked instances in restricted environments, without the need for …☆64May 21, 2026Updated last week
- ☆85Feb 12, 2026Updated 3 months ago
- kerberos in rust for fun and profit☆73Mar 13, 2026Updated 2 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆166Mar 4, 2025Updated last year
- Impersonate Windows tokens in Nim☆23Aug 4, 2025Updated 9 months ago
- burpsuite extension to analyze javascript files using semgrep☆12Feb 3, 2025Updated last year
- My mobile writeups repository☆33Nov 19, 2025Updated 6 months ago
- A Collection of Wordlists for Penetration Testing☆39Mar 13, 2026Updated 2 months ago
- A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Cal…☆262Jun 10, 2025Updated 11 months ago
- A scanner for the FortiNet vulnerability CVE-2025-64446☆31Nov 18, 2025Updated 6 months ago