Investigation about ACL abusing for Active Directory Certificate Services (AD CS)
☆134Oct 10, 2021Updated 5 years ago
Alternatives and similar repositories for Abusing_Weak_ACL_on_Certificate_Templates
Users that are interested in Abusing_Weak_ACL_on_Certificate_Templates are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ADCS cert template modification and ACL enumeration☆144Jun 26, 2023Updated 3 years ago
- ADCS abuser☆324Feb 6, 2023Updated 3 years ago
- WhoAmI by asking the LDAP service on a domain controller.☆67Feb 8, 2022Updated 4 years ago
- Collection of remote authentication triggers in C#☆540May 15, 2024Updated 2 years ago
- MS-FSRVP coercion abuse PoC☆303Dec 30, 2021Updated 4 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- C# version of Powermad☆172Dec 5, 2023Updated 2 years ago
- NTLM relaying for Windows made easy☆586Apr 25, 2023Updated 3 years ago
- Cobalt Strike BOF to list Windows Pipes & return their Owners & DACL Permissions☆96Mar 8, 2023Updated 3 years ago
- A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.☆141Sep 24, 2021Updated 5 years ago
- Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) via Syswhispers2☆186Jul 21, 2022Updated 4 years ago
- DirSync is a simple proof of concept PowerShell module to demonstrate the impact of delegating DS-Replication-Get-Changes and DS-Replicat…☆30Apr 26, 2023Updated 3 years ago
- Convert ldapdomaindump to Bloodhound☆80Dec 19, 2023Updated 2 years ago
- Check for LDAP protections regarding the relay of NTLM authentication☆531Nov 19, 2024Updated last year
- Module Stomping, No New Thread, HellsGate syscaller, UUID Shellcode Runner for x64 Windows 10!☆449Mar 8, 2023Updated 3 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Local SYSTEM auth trigger for relaying☆173Jul 22, 2025Updated last year
- LiquidSnake is a tool that allows operators to perform fileless lateral movement using WMI Event Subscriptions and GadgetToJScript☆351Sep 1, 2021Updated 5 years ago
- .NET 4.0 WinRM API Command Execution☆164Sep 11, 2020Updated 6 years ago
- Buggy script to play with GPOs☆136Jul 14, 2026Updated 2 months ago
- C# tool for installing a shared network printer abusing the PrinterNightmare bug to allow other network machines easy privesc!☆181Aug 4, 2021Updated 5 years ago
- SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket☆981Jul 26, 2021Updated 5 years ago
- Spray a hash via smb to check for local administrator access☆143Feb 7, 2021Updated 5 years ago
- An other No-Fix LPE, NTLMRelay2Self over HTTP (Webdav).☆420Jan 27, 2024Updated 2 years ago
- official repo for the AdHuntTool (part of the old RedTeamCSharpScripts repo)☆235Jun 10, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Click Once + App Domain☆69Feb 23, 2026Updated 7 months ago
- A .NET tool for exporting and importing certificates without touching disk.☆500Oct 8, 2021Updated 5 years ago
- A repository that maps commonly used attacks using MSRPC protocols to ATT&CK☆348May 30, 2023Updated 3 years ago
- Federated Office365 user enumeration based on correlated response trend analysis☆49May 3, 2022Updated 4 years ago
- ☆504Nov 20, 2022Updated 3 years ago
- A Combination LSASS Dumper and LSASS Parser. All Credit goes to @slyd0g and @cube0x0.☆147Nov 21, 2021Updated 4 years ago
- ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound via BOFHound, and also supports full-ob…☆1,100Jul 10, 2026Updated 3 months ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆193May 31, 2026Updated 4 months ago
- Strstr with user-supplied needle and filename as a BOF.☆32Sep 27, 2021Updated 5 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A .NET implementation to dump SAM, SYSTEM, SECURITY registry hives from a remote host☆42Dec 8, 2023Updated 2 years ago
- Framework for Kerberos relaying☆956May 29, 2022Updated 4 years ago
- PoC to coerce authentication from Windows hosts using MS-WSP☆304Sep 7, 2023Updated 3 years ago
- Dumping DPAPI credz remotely☆1,429Sep 9, 2026Updated last month
- UnhookMe is an universal Windows API resolver & unhooker addressing problem of invoking unmonitored system calls from within of your Red …☆347Jul 3, 2022Updated 4 years ago
- Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that b…☆219Jul 14, 2021Updated 5 years ago
- Tools for Kerberos PKINIT and relaying to AD CS☆933Jan 3, 2025Updated last year