This C# tool sprays for admin access over the entire domain
☆90Dec 7, 2025Updated 9 months ago
Alternatives and similar repositories for Find-AdminAccess
Users that are interested in Find-AdminAccess are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A portable C# utility for enumerating local and remote windows sessions☆56Jan 1, 2026Updated 8 months ago
- Modified version of PEAS client for offensive operations☆51May 18, 2026Updated 4 months ago
- Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. In C#, C++, Cryst…☆386Aug 31, 2026Updated 3 weeks ago
- Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11☆86Jan 26, 2026Updated 7 months ago
- Windows Access token manipulation tool made in C#☆25Aug 24, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A C# utility for interacting with SCOM☆97Dec 2, 2025Updated 9 months ago
- A Windows tool that converts LDIF files to BloodHound CE☆31Dec 20, 2025Updated 9 months ago
- Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. In C#, C++, Crystal, Python, Rust,…☆155Aug 31, 2026Updated 3 weeks ago
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆117Apr 16, 2026Updated 5 months ago
- Windows Session Hijacking via COM☆350Dec 13, 2025Updated 9 months ago
- A tool that helps change the recovery configuration of a Windows service to make lateral movement more stealthy☆44Feb 8, 2026Updated 7 months ago
- BOF to terminate a process via PID as argument☆27Sep 7, 2025Updated last year
- A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA …☆168Nov 2, 2025Updated 10 months ago
- Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall☆150Dec 17, 2025Updated 9 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆176Jun 19, 2026Updated 3 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆118Dec 21, 2025Updated 9 months ago
- Enumerate Domain Users Without Authentication☆311Apr 22, 2025Updated last year
- ProfileHound - BloodHound OpenGraph collector for user profiles stored on domain machines. Make informed decisions about looting secrets …☆164Jul 8, 2026Updated 2 months ago
- Using Chromium-based browsers as a proxy for C2 traffic.☆155Dec 6, 2025Updated 9 months ago
- Tool to enumerate privileged Scheduled Tasks on Remote Systems☆311Aug 29, 2026Updated 3 weeks ago
- TCP Port Forwarding Utility on C☆41Jun 18, 2026Updated 3 months ago
- PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via …☆191Jan 25, 2026Updated 7 months ago
- Okta Data Collector for BloodHound Community☆17Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.☆75Oct 22, 2025Updated 10 months ago
- Python tool to automatically perform SPN-less RBCD attacks.☆132Jan 7, 2026Updated 8 months ago
- A C# tool for extracting information from SCCM PXE boot media.☆56May 21, 2026Updated 4 months ago
- Remote service-staging tool built on Impacket, designed for BOF-style lateral movement workflows that lets you upload custom service load…☆128Dec 7, 2025Updated 9 months ago
- Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.☆747May 9, 2026Updated 4 months ago
- Golang Automation Framework for Cobalt Strike using the Rest API☆59Apr 10, 2026Updated 5 months ago
- Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!☆601Aug 17, 2026Updated last month
- adws enumeration bof☆175Sep 1, 2026Updated 2 weeks ago
- Updated version of a long known self deletion technique to work with 24H2.☆61Jun 9, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.☆222Jan 6, 2026Updated 8 months ago
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆193May 23, 2026Updated 3 months ago
- Fast context enumeration for newly obtained Active Directory credentials.☆88Apr 17, 2026Updated 5 months ago
- Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and co…☆837May 16, 2026Updated 4 months ago
- psexecsvc - a python implementation of PSExec's native service implementation☆314Mar 24, 2026Updated 5 months ago
- PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads☆256Oct 30, 2025Updated 10 months ago
- The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencie…☆183Sep 3, 2025Updated last year