A fast enumeration tool for Windows Active Directory Pentesting written in Go
☆287Jan 14, 2023Updated 3 years ago
Alternatives and similar repositories for ADReaper
Users that are interested in ADReaper are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- linWinPwn is a bash script that streamlines the use of a number of Active Directory tools☆2,219Updated this week
- OPSEC safe Kerberoasting in C#☆200Jun 14, 2022Updated 4 years ago
- Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.☆489Jul 9, 2024Updated 2 years ago
- BloodyAD is an Active Directory Privilege Escalation Framework☆2,303Sep 15, 2026Updated last week
- Quietly enumerate an Active Directory Domain via LDAP parsing users, admins, groups, etc.☆502Jan 23, 2023Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other ob…☆494Oct 14, 2022Updated 3 years ago
- WMEye is a post exploitation tool that uses WMI Event Filter and MSBuild Execution for lateral movement☆372Dec 24, 2021Updated 4 years ago
- Framework for Kerberos relaying☆955May 29, 2022Updated 4 years ago
- AD Enum is a pentesting tool that allows to find misconfiguration through the the protocol LDAP and exploit some of those weaknesses with…☆319Jul 4, 2023Updated 3 years ago
- Dump NTDS with golden certificates and UnPAC the hash☆650Mar 20, 2024Updated 2 years ago
- KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default…☆1,689Aug 6, 2022Updated 4 years ago
- An Office365 User Attack Tool☆650Mar 19, 2024Updated 2 years ago
- ☆504Nov 20, 2022Updated 3 years ago
- DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the …☆576Jun 5, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- An ADCS Exploitation Automation Tool Weaponizing Certipy and Coercer☆749May 19, 2023Updated 3 years ago
- Retrieve AD accounts description and search for password in it☆81Jul 21, 2022Updated 4 years ago
- AD ACL abuse☆411Sep 15, 2026Updated last week
- Active Directory password spraying tool. Auto fetches user list and avoids potential lockouts.☆132Nov 25, 2021Updated 4 years ago
- A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.☆635Oct 18, 2025Updated 11 months ago
- Convert shellcode into different formats!☆355Jan 24, 2023Updated 3 years ago
- Proof of Concept Utilities Developed to Research NTLM Relaying Attacks Targeting ADFS☆191Jun 22, 2022Updated 4 years ago
- PIC lsass dumper using cloned handles☆597Oct 18, 2022Updated 3 years ago
- evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)☆1,510Dec 21, 2023Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Active Directory data ingestor for BloodHound Legacy written in Rust. 🦀☆1,171Oct 21, 2024Updated last year
- CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.☆1,414Dec 16, 2021Updated 4 years ago
- A User Impersonation tool - via Token or Shellcode injection☆419May 21, 2022Updated 4 years ago
- Hide your payload in DNS☆622May 3, 2023Updated 3 years ago
- Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by …☆743Aug 18, 2023Updated 3 years ago
- ☆411Dec 14, 2023Updated 2 years ago
- ☆535Nov 20, 2021Updated 4 years ago
- The swiss army knife of LSASS dumping☆2,139Sep 17, 2024Updated 2 years ago
- A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.☆399Jan 10, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A quick handy script to harvest credentials off of a user during a Red Team and get execution of a file from the user☆254Mar 7, 2022Updated 4 years ago
- Dumping LSASS with a duplicated handle from custom LSA plugin☆206Feb 23, 2022Updated 4 years ago
- Automation for internal Windows Penetrationtest / AD-Security☆3,695Aug 28, 2025Updated last year
- Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-softw…☆275Apr 4, 2023Updated 3 years ago
- A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.☆814Jun 16, 2026Updated 3 months ago
- Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts wa…☆1,100Oct 14, 2025Updated 11 months ago
- Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory☆405Aug 15, 2025Updated last year