Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys.
☆45Jul 21, 2026Updated this week
Alternatives and similar repositories for credshound
Users that are interested in credshound are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Tailscale/Headscale C2 profile and agent for Mythic☆25Mar 14, 2026Updated 4 months ago
- Living Off the Land Credentials. Public credential defaults, locations, and exposure patterns for real products, SaaS/cloud services, app…☆42Updated this week
- CVE-2025-59501 POC code☆25Nov 20, 2025Updated 8 months ago
- ☆52Jul 12, 2026Updated last week
- In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit☆19Apr 14, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- One PsExec client to rule them all☆15Mar 25, 2026Updated 3 months ago
- PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping☆30May 12, 2026Updated 2 months ago
- A modern alternative Web-UI for the Mythic Command and Control Server☆79Jul 3, 2026Updated 2 weeks ago
- Dump TGTs remotely and convert Windows' klist binary output to ccache.☆85Jun 30, 2026Updated 3 weeks ago
- A Windows rootkit that turns user-land processes into Protected Processes☆30Nov 16, 2024Updated last year
- ☆86Apr 8, 2026Updated 3 months ago
- L0phtCrack 7 macOS fork — Apple Silicon port with hashcat engine (M1/M2/M3/M4)☆26Mar 31, 2026Updated 3 months ago
- DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.☆210Jun 25, 2026Updated 3 weeks ago
- ☆44Jul 1, 2026Updated 2 weeks ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Active Directory information dumper via ADWS for evasion purposes.☆274Jul 9, 2026Updated last week
- The Azure Execution Tool☆159Feb 6, 2026Updated 5 months ago
- dcsync bof☆54Feb 13, 2026Updated 5 months ago
- Notion C2 Profile for Mythic☆47Apr 30, 2026Updated 2 months ago
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 2 months ago
- open source implementation of the UDC2 spec used in Cobalt Strike☆55Jul 4, 2026Updated 2 weeks ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆26May 10, 2026Updated 2 months ago
- Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).☆115Jun 22, 2026Updated 3 weeks ago
- Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.☆65May 4, 2026Updated 2 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Modular User-Defined Reflective Loader (UDRL) built on Crystal Palace for controlled DLL execution and evasion research.☆33Apr 14, 2026Updated 3 months ago
- Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !☆43Mar 24, 2026Updated 3 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆41May 27, 2026Updated last month
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆273Jun 22, 2026Updated 3 weeks ago
- PowerShell tool to deploy deceptive Active Directory objects, and audit them☆16Jan 7, 2026Updated 6 months ago
- A harmless Netcat-lookalike for detection testing. Simulates NC-style command-line flags and listener behavior without exposing a real ba…☆37Nov 27, 2025Updated 7 months ago
- PowerShell implementation for AD CS☆157Mar 2, 2026Updated 4 months ago
- CopyReadProcessMemory expoits the miss-configuration/vulnerability present on the API Windows method ReadProcessMemory.☆33Nov 27, 2025Updated 7 months ago
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆83Apr 11, 2026Updated 3 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- ☆30Mar 26, 2026Updated 3 months ago
- Printer exploitation framework for penetration testing. Discovers printers via PJL scanning, checks for default credentials, and extracts…☆21Mar 10, 2026Updated 4 months ago
- A collection of useful API endpoints for security operators and administrators☆16Jan 8, 2026Updated 6 months ago
- A personal RAG system for offensive security knowledge☆154Jul 13, 2026Updated last week
- open source port/reimplementation of the Cobalt Strike BOF Loader as is☆73Mar 8, 2026Updated 4 months ago
- SOAPy is a Proof of Concept (PoC) tool for conducting offensive interaction with Active Directory Web Services (ADWS) through a SOCKS5 pr…☆211Jun 6, 2026Updated last month
- ☆93Updated this week