Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, and AI keys.
☆59Jul 21, 2026Updated 2 weeks ago
Alternatives and similar repositories for credshound
Users that are interested in credshound are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Tailscale/Headscale C2 profile and agent for Mythic☆25Mar 14, 2026Updated 4 months ago
- Living Off the Land Credentials. Public credential defaults, locations, and exposure patterns for real products, SaaS/cloud services, app…☆49Jul 19, 2026Updated 3 weeks ago
- GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumera…☆42Jul 23, 2026Updated 2 weeks ago
- CVE-2025-59501 POC code☆25Nov 20, 2025Updated 8 months ago
- ☆59Jul 12, 2026Updated 3 weeks ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- In-memory BOF implementation of Silent Process Exit LSASS dump via RtlReportSilentProcessExit☆19Apr 14, 2026Updated 3 months ago
- One PsExec client to rule them all☆15Mar 25, 2026Updated 4 months ago
- PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping☆36May 12, 2026Updated 2 months ago
- A modern alternative Web-UI for the Mythic Command and Control Server☆81Jul 3, 2026Updated last month
- Dump TGTs remotely and convert Windows' klist binary output to ccache.☆94Updated this week
- A Windows rootkit that turns user-land processes into Protected Processes☆30Nov 16, 2024Updated last year
- L0phtCrack 7 macOS fork — Apple Silicon port with hashcat engine (M1/M2/M3/M4)☆26Mar 31, 2026Updated 4 months ago
- ☆88Apr 8, 2026Updated 4 months ago
- DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.☆210Jun 25, 2026Updated last month
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆44Jul 1, 2026Updated last month
- Active Directory information dumper via ADWS for evasion purposes.☆316Jul 9, 2026Updated last month
- The Azure Execution Tool☆159Feb 6, 2026Updated 6 months ago
- dcsync bof☆54Feb 13, 2026Updated 5 months ago
- Notion C2 Profile for Mythic☆48Apr 30, 2026Updated 3 months ago
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- open source implementation of the UDC2 spec used in Cobalt Strike☆58Jul 4, 2026Updated last month
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 3 months ago
- Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).☆118Jun 22, 2026Updated last month
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.☆66May 4, 2026Updated 3 months ago
- Modular User-Defined Reflective Loader (UDRL) built on Crystal Palace for controlled DLL execution and evasion research.☆33Apr 14, 2026Updated 3 months ago
- Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !☆43Mar 24, 2026Updated 4 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆41May 27, 2026Updated 2 months ago
- DCOM in memory and fileless lateral movement techniques through .Net deserilization☆283Jun 22, 2026Updated last month
- PowerShell tool to deploy deceptive Active Directory objects, and audit them☆16Jan 7, 2026Updated 7 months ago
- A harmless Netcat-lookalike for detection testing. Simulates NC-style command-line flags and listener behavior without exposing a real ba…☆37Nov 27, 2025Updated 8 months ago
- PowerShell implementation for AD CS☆159Jul 30, 2026Updated last week
- CopyReadProcessMemory expoits the miss-configuration/vulnerability present on the API Windows method ReadProcessMemory.☆33Nov 27, 2025Updated 8 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆83Apr 11, 2026Updated 4 months ago
- ☆31Mar 26, 2026Updated 4 months ago
- Printer exploitation framework for penetration testing. Discovers printers via PJL scanning, checks for default credentials, and extracts…☆21Mar 10, 2026Updated 5 months ago
- A collection of useful API endpoints for security operators and administrators☆16Jan 8, 2026Updated 7 months ago
- A personal RAG system for offensive security knowledge☆170Jul 13, 2026Updated 3 weeks ago
- open source port/reimplementation of the Cobalt Strike BOF Loader as is☆74Mar 8, 2026Updated 5 months ago
- SOAPy is a Proof of Concept (PoC) tool for conducting offensive interaction with Active Directory Web Services (ADWS) through a SOCKS5 pr…☆213Jun 6, 2026Updated 2 months ago