KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes, BloodHound, NTDS and DCSync).
☆268Jul 7, 2026Updated 2 weeks ago
Alternatives and similar repositories for knowsmore
Users that are interested in knowsmore are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆92Aug 5, 2023Updated 2 years ago
- SCCMHunter is a post-ex tool built to streamline identifying, profiling, and attacking SCCM related assets in an Active Directory domain.…☆933Jun 25, 2026Updated last month
- Enumerate Domain Users Without Authentication☆305Apr 22, 2025Updated last year
- A tool to generate a wordlist from the information present in LDAP, in order to crack passwords of domain accounts.☆379Mar 24, 2026Updated 4 months ago
- ☆28Aug 18, 2023Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Various one-off pentesting projects written in Nim. Updates happen on a whim.☆159May 25, 2026Updated 2 months ago
- An x64 position-independent shellcode stager that verifies the stage it retrieves prior to execution☆195Nov 27, 2024Updated last year
- ☆570Mar 28, 2024Updated 2 years ago
- Retrieve and display information about active user sessions on remote computers. No admin privileges required.☆211Aug 12, 2024Updated last year
- A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage Power…☆823Mar 28, 2025Updated last year
- Proof of Concept (PoC) .NET tool for remotely killing EDR with WDAC☆437Sep 29, 2025Updated 9 months ago
- ☆59Nov 13, 2024Updated last year
- Demonized Shell is an Advanced Tool for persistence in linux.☆455Jan 5, 2025Updated last year
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆609Jan 20, 2026Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Some scripts to abuse kerberos using Powershell☆364Apr 10, 2026Updated 3 months ago
- SprayShark is a modular G-Suite password sprayer with threading!☆60May 17, 2025Updated last year
- Offensive MSSQL toolkit written in Python, based off SQLRecon☆212May 8, 2026Updated 2 months ago
- Azure DevOps Services Attack Toolkit☆155Apr 29, 2026Updated 2 months ago
- WPXStrike is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's criticals…☆76Dec 28, 2023Updated 2 years ago
- Shellcode encryptor & obfuscator tool☆1,033Updated this week
- PrestaXSRF is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's critical…☆32Dec 26, 2023Updated 2 years ago
- .NET post-exploitation toolkit for Active Directory reconnaissance and exploitation☆401Jul 23, 2025Updated last year
- Associated-Threat-Analyzer detects malicious IPv4 addresses and domain names associated with your web application using local malicious d…☆41Aug 31, 2023Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Active Directory data ingestor for BloodHound Legacy written in Rust. 🦀☆1,164Oct 21, 2024Updated last year
- Generate password spraying lists based on the pwdLastSet-attribute of users.☆56Dec 6, 2023Updated 2 years ago
- Dump Kerberos tickets from the KCM database of SSSD☆59Dec 31, 2025Updated 6 months ago
- Use ESC1 to perform a makeshift DCSync and dump hashes☆212Nov 2, 2023Updated 2 years ago
- Leak of any user's NetNTLM hash. Fixed in KB5040434☆262Aug 13, 2024Updated last year
- A command-line utility designed to recursively spider webpages for URLs. It works by actively traversing websites - following links embed…☆111Dec 8, 2025Updated 7 months ago
- HookChain: A new perspective for Bypassing EDR Solutions☆609Jan 5, 2025Updated last year
- A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.☆400Jan 20, 2026Updated 6 months ago
- A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other ob…☆490Oct 14, 2022Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Ask a TGS on behalf of another user without password☆481Mar 30, 2025Updated last year
- C# DInvoke Shellcode Runner☆31Feb 10, 2025Updated last year
- The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).☆370Dec 13, 2025Updated 7 months ago
- CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability☆146Jan 13, 2025Updated last year
- A Rust implementation of Internal-Monologue — retrieving NetNTLM hashes without touching LSASS, leveraging SSPI for NTLM negotiation and …☆193Apr 26, 2025Updated last year
- Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (c…☆1,124Nov 9, 2024Updated last year
- LSASS memory dumper using only NTAPIs, creating a minimal minidump. It can be compiled as shellcode (PIC), supports XOR encryption, and r…☆387Apr 26, 2025Updated last year