daem0nc0re / Abusing_Weak_ACL_on_Certificate_Templates
Investigation about ACL abusing for Active Directory Certificate Services (AD CS)
☆119Updated 3 years ago
Alternatives and similar repositories for Abusing_Weak_ACL_on_Certificate_Templates:
Users that are interested in Abusing_Weak_ACL_on_Certificate_Templates are comparing it to the libraries listed below
- Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket.☆83Updated 9 months ago
- Determine if the WebClient Service (WebDAV) is running on a remote system☆125Updated 11 months ago
- ☆157Updated 3 months ago
- ☆144Updated last week
- ☆99Updated 9 months ago
- ☆39Updated 3 weeks ago
- Grab NetNTLMv2 hashes using ETW with administrative rights on Windows 8.1 / Windows Server 2016 and later☆91Updated last year
- Get Fine Grained Password Policy☆67Updated 9 months ago
- Tooling related to the WAM Bam - Recovering Web Tokens From Office blog post☆120Updated 2 years ago
- ☆74Updated 6 months ago
- Tool for issuing manual LDAP queries which offers bofhound compatible output☆52Updated 8 months ago
- ☆113Updated last year
- ☆85Updated 2 years ago
- ☆139Updated 2 years ago
- A Python POC for CRED1 over SOCKS5☆139Updated 4 months ago
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆53Updated 2 years ago
- A python port of @dafthack's MFAsweep with some added OPSEC functionality. MFAde can be used to find single-factor authentication failure…☆37Updated 2 years ago
- The BackupOperatorToolkit contains different techniques allowing you to escalate from Backup Operator to Domain Admin☆168Updated 2 years ago
- A C# tool to output crackable DPAPI hashes from user MasterKeys☆132Updated 5 months ago
- A module for CME that spiders across a domain.☆35Updated 2 years ago
- ADCS cert template modification and ACL enumeration☆132Updated last year
- Simple BOF to read the protection level of a process☆114Updated last year
- ☆83Updated 3 years ago
- Abuse Azure API permissions for red teaming☆61Updated 2 years ago
- ☆190Updated 10 months ago
- C# version of NTLMRawUnHide☆72Updated 2 years ago
- GolenGMSA tool for working with GMSA passwords☆139Updated 10 months ago
- Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules, actions, and exclusion locations☆146Updated 11 months ago
- C# POC to extract NetNTLMv1/v2 hashes from ETW provider☆252Updated last year
- ☆70Updated last year