DCSync Attack from Outside using Impacket
☆115May 2, 2022Updated 3 years ago
Alternatives and similar repositories for DCSync
Users that are interested in DCSync are comparing it to the libraries listed below
Sorting:
- MS-FSRVP coercion abuse PoC☆302Dec 30, 2021Updated 4 years ago
- ADCS cert template modification and ACL enumeration☆143Jun 26, 2023Updated 2 years ago
- An other No-Fix LPE, NTLMRelay2Self over HTTP (Webdav).☆418Jan 27, 2024Updated 2 years ago
- Dump NTDS with golden certificates and UnPAC the hash☆647Mar 20, 2024Updated 2 years ago
- Pass the Hash to a named pipe for token Impersonation☆311Nov 29, 2023Updated 2 years ago
- Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel☆390Feb 23, 2024Updated 2 years ago
- ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound via BOFHound, and also supports full-ob…☆1,063Jan 22, 2026Updated last month
- Check for LDAP protections regarding the relay of NTLM authentication☆530Nov 19, 2024Updated last year
- Tool for issuing manual LDAP queries which offers bofhound compatible output☆45Jan 14, 2026Updated 2 months ago
- From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller☆440Jan 4, 2025Updated last year
- An ADCS Exploitation Automation Tool Weaponizing Certipy and Coercer☆741May 19, 2023Updated 2 years ago
- DPAPI looting remotely and locally in Python☆542Mar 13, 2026Updated last week
- ☆832Sep 9, 2022Updated 3 years ago
- ☆199Aug 28, 2025Updated 6 months ago
- Framework for Kerberos relaying☆938May 29, 2022Updated 3 years ago
- Some Service DCOM Object and SeImpersonatePrivilege abuse.☆372Dec 9, 2022Updated 3 years ago
- Modified version of PEAS client for offensive operations☆42Jan 16, 2023Updated 3 years ago
- My implementation of the GIUDA project in C++☆189Jul 25, 2023Updated 2 years ago
- Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin pr…☆237Sep 3, 2023Updated 2 years ago
- Proxylogon & Proxyshell & Proxyoracle & Proxytoken & All exchange server history vulns summarization :)☆562Dec 7, 2023Updated 2 years ago
- A C# utility for interacting with SCCM☆683Aug 20, 2025Updated 7 months ago
- ☆46Jun 25, 2024Updated last year
- Tool for issuing manual LDAP queries which offers bofhound compatible output☆57Jun 2, 2024Updated last year
- Tool for viewing NTDS.dit☆197Mar 14, 2025Updated last year
- Get Fine Grained Password Policy☆78Mar 13, 2026Updated last week
- A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.☆301Oct 26, 2022Updated 3 years ago
- A User Impersonation tool - via Token or Shellcode injection☆422May 21, 2022Updated 3 years ago
- Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-softw…☆277Apr 4, 2023Updated 2 years ago
- Collection of remote authentication triggers in C#☆524May 15, 2024Updated last year
- ADCS abuser☆317Feb 6, 2023Updated 3 years ago
- Dumping LAPS from Python☆283Dec 7, 2022Updated 3 years ago
- TCP Port Redirection Utility☆765Jan 31, 2023Updated 3 years ago
- More examples using the Impacket library designed for learning purposes.☆264Nov 4, 2022Updated 3 years ago
- A password guessing tool that targets the Kerberos and LDAP services within the Windows Active Directory environment.☆444Aug 18, 2023Updated 2 years ago
- A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certifica…☆867Mar 20, 2023Updated 3 years ago
- New generation of wmiexec.py☆1,269Jan 5, 2026Updated 2 months ago
- The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).☆361Dec 13, 2025Updated 3 months ago
- PortBender修改为exe版本☆29Jul 24, 2023Updated 2 years ago
- ☆538Nov 20, 2021Updated 4 years ago