A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.
☆168Feb 19, 2025Updated last year
Alternatives and similar repositories for ketshash
Users that are interested in ketshash are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.☆140Mar 7, 2018Updated 8 years ago
- Discover "HotSpots" - potential spots for credentials theft☆24Apr 12, 2018Updated 8 years ago
- Find accounts using common and default passwords in Active Directory.☆70Sep 19, 2019Updated 7 years ago
- Test Blue Team detections without running any attack.☆271May 2, 2024Updated 2 years ago
- A script for advanced discovery of Privileged Accounts - includes Shadow Admins☆830Sep 9, 2019Updated 7 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Perform various SMB-related attacks, particularly useful for testing large Active Directory environments.☆41Oct 15, 2022Updated 3 years ago
- ntlm relay attack to Exchange Web Services☆332Jan 15, 2018Updated 8 years ago
- Miscellaneous C-Sharp projects for red team activities☆22Aug 12, 2022Updated 4 years ago
- SMB MiTM tool with a focus on attacking clients through file content swapping, lnk swapping, as well as compromising any data passed over…☆382Aug 17, 2018Updated 8 years ago
- PowerShell Obfuscation Detection Framework☆756Dec 1, 2023Updated 2 years ago
- Various Cheat Sheets☆183Jun 24, 2021Updated 5 years ago
- CScriptShell, a Powershell Host running within cscript.exe☆163Apr 11, 2017Updated 9 years ago
- Windows log and threat hunting with powershell☆16Dec 11, 2020Updated 5 years ago
- ☆181Feb 21, 2022Updated 4 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Active Directory Assessment and Privilege Escalation Script☆1,124Dec 7, 2022Updated 3 years ago
- PowerShell oneliner to retrieve wdigest passwords from the memory☆220Dec 11, 2017Updated 8 years ago
- Dump TeamViewer ID and password from memory. Works much better than other tools.☆98Apr 13, 2018Updated 8 years ago
- Powershell script for enumerating vulnerable DCOM Applications☆264Nov 30, 2018Updated 7 years ago
- A cobaltstrike script that integrates DDEAuto Attacks☆63Oct 17, 2017Updated 8 years ago
- Exfiltrate data with ICMP☆101Jan 31, 2018Updated 8 years ago
- alternative to procdump☆11May 26, 2021Updated 5 years ago
- c# implementation of Active Directory Integrated DNS dumping (authenticated user)☆204May 25, 2021Updated 5 years ago
- beacon,aggressor-scripts,cna,cobalt-strike,email☆36Jun 18, 2019Updated 7 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆351Mar 19, 2021Updated 5 years ago
- Investigate malicious Windows logon by visualizing and analyzing Windows event log☆3,273Aug 2, 2026Updated last month
- 安全狗sql注入绕过☆28Mar 21, 2018Updated 8 years ago
- Exchange privilege escalations to Active Directory☆832Apr 23, 2023Updated 3 years ago
- A simple tool to detect NBT-NS and LLMNR spoofing (and messing with them a bit)☆36Mar 21, 2019Updated 7 years ago
- initial commit☆172Jun 11, 2018Updated 8 years ago
- Python / C# Unmanaged PowerShell based RAT☆768Mar 29, 2023Updated 3 years ago
- ☆15Feb 26, 2018Updated 8 years ago
- ☆12Oct 12, 2013Updated 12 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- PowerShell Pass The Hash Utils☆1,805Dec 9, 2018Updated 7 years ago
- goddi (go dump domain info) dumps Active Directory domain information☆424May 31, 2022Updated 4 years ago
- Windows Event Forwarding for Active Directory Security Logs☆29Jun 28, 2016Updated 10 years ago
- ☆210Jan 30, 2019Updated 7 years ago
- RedSnarf is a pen-testing / red-teaming tool for Windows environments☆1,220Sep 14, 2020Updated 6 years ago
- Check if a IP is from tor or is a malicious proxy☆56Feb 9, 2021Updated 5 years ago
- Perform a MitM attack and extract clear text credentials from RDP connections☆1,457Nov 20, 2025Updated 10 months ago