mandiant / ADFSpoof
☆386Updated 7 months ago
Alternatives and similar repositories for ADFSpoof:
Users that are interested in ADFSpoof are comparing it to the libraries listed below
- ☆340Updated last year
- ☆364Updated 3 years ago
- SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket☆814Updated 3 years ago
- ☆445Updated 2 years ago
- AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Co…☆215Updated 4 years ago
- A proof of concept on attack vectors against Active Directory by abusing Active Directory Certificate Services (ADCS)☆182Updated 3 years ago
- Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types☆378Updated 2 years ago
- Check for LDAP protections regarding the relay of NTLM authentication☆482Updated 3 months ago
- Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain☆341Updated 3 years ago
- Recon-AD, an AD recon tool based on ADSI and reflective DLL’s☆322Updated 5 years ago
- Enumerate Domain Data☆325Updated last year
- A centralized resource for previously documented WDAC bypass techniques☆508Updated 10 months ago
- PowerShell Constrained Language Mode Bypass☆258Updated 4 years ago
- AzureRT - A Powershell module implementing various Azure Red Team tactics☆230Updated 2 years ago
- Kerberos Resource-Based Constrained Delegation Attack from Outside using Impacket☆524Updated 2 years ago
- A Cobalt Strike tool to audit Active Directory user accounts for weak, well known or easy guessable passwords.☆432Updated 2 years ago
- scan for NTLM directories☆354Updated 8 months ago
- Checks running processes, process metadata, Dlls loaded into your current process and the each DLLs metadata, common install directories,…☆257Updated last year
- Partial python implementation of SharpGPOAbuse☆403Updated last year
- A collection of proof-of-concept source code and scripts for executing remote commands over WinRM using the WSMan.Automation COM object☆233Updated 4 years ago
- Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory☆384Updated 11 months ago
- Invoke-ZeroLogon allows attackers to impersonate any computer, including the domain controller itself, and execute remote procedure calls…☆215Updated 4 years ago
- Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel☆320Updated last year
- Amplify network visibility from multiple POV of other hosts☆300Updated 11 months ago
- Bypass for PowerShell Constrained Language Mode☆381Updated 3 years ago
- A C# utility for interacting with SCCM☆610Updated 5 months ago
- WSuspicious - A tool to abuse insecure WSUS connections for privilege escalations☆352Updated 4 years ago
- Run Powershell without software restrictions.☆285Updated 3 years ago
- StandIn is a small .NET35/45 AD post-exploitation toolkit☆254Updated 3 years ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆222Updated 3 years ago