nccgroup / SteppingStones
A Red Team Activity Hub
☆175Updated this week
Related projects ⓘ
Alternatives and complementary repositories for SteppingStones
- Slides and Codes used for the workshop Red Team Infrastructure Automation☆174Updated 7 months ago
- A tool leveraging Kerberos tickets to get Microsoft 365 access tokens using Seamless SSO☆129Updated 2 months ago
- The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).☆265Updated last week
- Modular cross-platform Microsoft Graph API (Entra, o365, and Intune) enumeration and exploitation toolkit☆133Updated 3 months ago
- ☆180Updated last month
- ☆170Updated last month
- Make everyone in your VLAN ASRep roastable☆137Updated 5 months ago
- Lord Of Active Directory - automatic vulnerable active directory on AWS☆131Updated last year
- Everything and anything related to password spraying☆126Updated 6 months ago
- Azure mindmap for penetration tests☆161Updated last year
- ☆143Updated 8 months ago
- Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel☆143Updated 3 weeks ago
- RedInfraCraft automates the deployment of powerful red team infrastructures! It streamlines the setup of C2s, makes it easy to create adv…☆89Updated this week
- A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances.☆246Updated last year
- Impacket is a collection of Python classes for working with network protocols.☆268Updated 3 weeks ago
- SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.☆156Updated 3 weeks ago
- An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails c…☆133Updated last month
- ☆279Updated 3 weeks ago
- Proof of concept: using a Cloudflare worker for AITM attacks☆91Updated 8 months ago
- Timeroasting scripts by Tom Tervoort☆182Updated last year
- Custom Queries - Brought Up to BH4.1 syntax☆230Updated 3 weeks ago
- A Slack bot phishing framework for Red Teaming exercises☆159Updated 6 months ago
- C2 Infrastructure Automation☆86Updated last week
- Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)☆163Updated last month
- A Python POC for CRED1 over SOCKS5☆134Updated last month
- Low and slow password spraying tool, designed to spray on an interval over a long period of time☆188Updated last month
- linikatz is a tool to attack AD on UNIX☆138Updated last year
- Python implementation of GhostPack's Seatbelt situational awareness tool☆196Updated last week
- ☆95Updated 2 years ago
- Continuous password spraying tool☆117Updated this week