secureworks / squarephish
☆275Updated last year
Related projects ⓘ
Alternatives and complementary repositories for squarephish
- Evilginx Phishing Engagement Infrastructure Setup Guide☆301Updated last month
- Weaponized Browser-in-the-Middle (BitM) for Penetration Testers☆402Updated 3 months ago
- Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound☆426Updated last week
- ☆280Updated 11 months ago
- An ADCS Exploitation Automation Tool Weaponizing Certipy and Coercer☆702Updated last year
- Malicious shortcut generator for collecting NTLM hashes from insecure file shares.☆307Updated 3 weeks ago
- Amsi Bypass payload that works on Windwos 11☆370Updated last year
- Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework☆516Updated 4 months ago
- KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes, BloodHound, NTDS and DCSync).☆209Updated 3 months ago
- Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types☆372Updated last year
- Kill AV/EDR leveraging BYOVD attack☆309Updated last year
- Automated Active Directory Enumeration☆414Updated last week
- Reverse engineered to remove IOCs, added Exchange Online Protection IP blacklist and bing-bot user-agent blocking, DNS configuration and …☆85Updated 4 months ago
- Hiding GoPhish from the boys in blue☆173Updated last year
- The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).☆265Updated last week
- A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other ob…☆452Updated 2 years ago
- Password spraying tool and Bloodhound integration☆213Updated last year
- Everything and anything related to password spraying☆126Updated 6 months ago
- Dump NTDS with golden certificates and UnPAC the hash☆623Updated 8 months ago
- A Slack bot phishing framework for Red Teaming exercises☆159Updated 6 months ago
- Materials for the workshop "Red Team Ops: Havoc 101"☆351Updated last month
- Tool to remotely dump secrets from the Windows registry☆401Updated 3 months ago
- Bounces when a fish bites - Evilginx database monitoring with exfiltration automation☆158Updated 5 months ago
- Spray365 makes spraying Microsoft accounts (Office 365 / Azure AD) easy through its customizable two-step password spraying approach. The…☆343Updated 2 years ago
- Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic lo…☆254Updated last year
- A tool to generate a wordlist from the information present in LDAP, in order to crack passwords of domain accounts.☆332Updated 3 weeks ago
- Lord Of Active Directory - automatic vulnerable active directory on AWS☆131Updated last year
- Retrieve and display information about active user sessions on remote computers. No admin privileges required.☆164Updated 3 months ago
- Useful C2 techniques and cheatsheets learned from engagements☆425Updated last month