A tool for collecting RDP, web and VNC screenshots all in one place
☆475Apr 3, 2023Updated 3 years ago
Alternatives and similar repositories for scrying
Users that are interested in scrying are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Standalone utility for service discovery on open ports!☆755Jan 13, 2026Updated 8 months ago
- .NET Project for Attacking vCenter☆558Nov 11, 2021Updated 4 years ago
- Reuse open handles to dynamically dump LSASS.☆245Apr 4, 2024Updated 2 years ago
- An interactive command prompt for red teaming and pentesting. Automatically pushes commands through SOCKS4/5 proxies via proxychains. Opt…☆227Aug 23, 2022Updated 4 years ago
- Find Microsoft Exchange instance for a given domain and identify the exact version☆190Jan 30, 2023Updated 3 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Various Cobalt Strike BOFs☆790Oct 16, 2022Updated 3 years ago
- NTLM relaying for Windows made easy☆586Apr 25, 2023Updated 3 years ago
- Cobalt Strike Beacon Object Files (BOFs) written in rust with rust core and alloc.☆283Feb 8, 2024Updated 2 years ago
- Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.☆1,326Jul 3, 2026Updated 3 months ago
- Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to …☆759Sep 23, 2024Updated 2 years ago
- Maximizing BloodHound. Max is a good boy.☆533Apr 25, 2025Updated last year
- Cobalt Strike kit for Lateral Movement☆677Feb 21, 2020Updated 6 years ago
- Tool for interacting with outlook interop during red team engagements☆145Jun 29, 2021Updated 5 years ago
- Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop☆1,318Nov 2, 2022Updated 3 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )☆2,957Feb 27, 2026Updated 7 months ago
- My collection of battle-tested Aggressor Scripts for Cobalt Strike 4.0+☆1,107Apr 19, 2023Updated 3 years ago
- Automation for internal Windows Penetrationtest / AD-Security☆3,699Aug 28, 2025Updated last year
- User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin☆493Sep 24, 2025Updated last year
- Windows Privilege Escalation from User to Domain Admin.☆1,471Dec 18, 2022Updated 3 years ago
- A C2 post-exploitation framework☆485Jan 24, 2024Updated 2 years ago
- Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that b…☆219Jul 14, 2021Updated 5 years ago
- Utility to craft HTML or SVG smuggled files for Red Team engagements☆245Mar 19, 2024Updated 2 years ago
- Extracting Clear Text Passwords from mstsc.exe using API Hooking.☆1,469Jul 20, 2024Updated 2 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A VSCode plugin to assist with BOF development.☆36Aug 14, 2024Updated 2 years ago
- Extract credentials from lsass remotely☆2,214Sep 9, 2026Updated last month
- ☆667Nov 17, 2021Updated 4 years ago
- Check for LDAP protections regarding the relay of NTLM authentication☆531Nov 19, 2024Updated last year
- ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound via BOFHound, and also supports full-ob…☆1,100Jul 10, 2026Updated 3 months ago
- Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.☆608Aug 5, 2022Updated 4 years ago
- UAC bypass by abusing RPC and debug objects.☆628Oct 19, 2023Updated 2 years ago
- LSASS memory dumper using direct system calls and API unhooking.☆1,596Jan 5, 2021Updated 5 years ago
- Fileless lateral movement tool that relies on ChangeServiceConfigA to run command☆1,668Jul 10, 2023Updated 3 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Coerce Windows machines auth via MS-EVEN☆173Jan 17, 2024Updated 2 years ago
- Proof of Concept Utilities Developed to Research NTLM Relaying Attacks Targeting ADFS☆191Jun 22, 2022Updated 4 years ago
- Self-developed tools for Lateral Movement/Code Execution☆721Aug 17, 2021Updated 5 years ago
- A tool to make socks connections through HTTP agents☆726Mar 30, 2021Updated 5 years ago
- Python interpreter for Cobalt Strike Malleable C2 Profiles. Allows you to parse, build and modify them programmatically.☆290Jun 8, 2026Updated 4 months ago
- Dump the memory of a PPL with a userland exploit☆888Jul 24, 2022Updated 4 years ago
- Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory☆404Aug 15, 2025Updated last year