A cheatsheet for NetExec
☆197Jun 9, 2025Updated 9 months ago
Alternatives and similar repositories for cme-nxc-cheat-sheet
Users that are interested in cme-nxc-cheat-sheet are comparing it to the libraries listed below
Sorting:
- Generate AES128 and AES256 Kerberos keys from a given username, password, and realm☆18Sep 18, 2024Updated last year
- Lab used for workshop and CTF☆500Feb 3, 2026Updated last month
- SANS Workshop: Active Directory Privilege Escalation with Empire!☆36Nov 12, 2025Updated 3 months ago
- Dominate Active Directory with PowerShell.☆1,166Nov 28, 2025Updated 3 months ago
- ☆48Oct 15, 2025Updated 4 months ago
- Shadow Dumper is a powerful tool used to dump LSASS memory, often needed in penetration testing and red teaming. It uses multiple advance…☆570May 22, 2025Updated 9 months ago
- LSASS memory dumper using only NTAPIs, creating a minimal minidump. It can be compiled as shellcode (PIC), supports XOR encryption, and r…☆384Apr 26, 2025Updated 10 months ago
- Powershell tool to automate Active Directory enumeration.☆1,286Sep 9, 2025Updated 6 months ago
- Active Directory pentesting mind map☆512May 26, 2023Updated 2 years ago
- Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!☆539May 9, 2025Updated 10 months ago
- BloodyAD is an Active Directory Privilege Escalation Framework☆2,102Feb 27, 2026Updated last week
- Powerview on steroids☆890Updated this week
- Exploit AD CS misconfiguration allowing privilege escalation and persistence from any child domain to full forest compromise☆129Dec 2, 2023Updated 2 years ago
- Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound☆672Oct 23, 2025Updated 4 months ago
- 🛡️ Assign AD permissions via PowerShell templates — Simplify and standardize AD delegation with reusable PowerShell templates.☆23Feb 28, 2026Updated last week
- HTML Smuggling with Web Assembly☆66Feb 20, 2024Updated 2 years ago
- The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).☆360Dec 13, 2025Updated 2 months ago
- ☆215Mar 26, 2024Updated last year
- DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely☆382Dec 13, 2024Updated last year
- Active Directory Auditing and Enumeration☆521Dec 3, 2025Updated 3 months ago
- Proof-of-Concept tool to authenticate to an LDAP/S server with a certificate through Schannel☆731Sep 3, 2025Updated 6 months ago
- ☆53Sep 23, 2025Updated 5 months ago
- smbclient-ng, a fast and user friendly way to interact with SMB shares.☆1,019Feb 1, 2026Updated last month
- The Network Execution Tool☆5,315Updated this week
- List of some AD tools I frequently use☆56Nov 2, 2025Updated 4 months ago
- ☆252Jul 31, 2024Updated last year
- Study materials for the Certified Red Team Expert (CRTE) exam, covering essential concepts in red teaming and penetration testing.☆166Jul 16, 2023Updated 2 years ago
- Introductory guide on the configuration and subsequent exploitation of Active Directory Certificate Services with Certipy. Based on the w…☆141Sep 4, 2023Updated 2 years ago
- Kerberoast with ACL abuse capabilities☆619Dec 16, 2024Updated last year
- Tool to bypass LSA Protection (aka Protected Process Light)☆64Jan 2, 2025Updated last year
- A cross-platform tool to parse and describe the contents of a raw ntSecurityDescriptor structure☆48Oct 4, 2025Updated 5 months ago
- A BloodHound collector for Microsoft Configuration Manager☆392Jul 7, 2025Updated 8 months ago
- This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone…☆215Oct 19, 2024Updated last year
- ☆381Oct 17, 2025Updated 4 months ago
- Make everyone in your VLAN ASRep roastable☆248Oct 7, 2025Updated 5 months ago
- OSCP Cheatsheet☆16Jun 14, 2023Updated 2 years ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆79Aug 5, 2024Updated last year
- linWinPwn is a bash script that streamlines the use of a number of Active Directory tools☆2,158Updated this week
- Retrieve LAPS passwords from a domain. The tools is inspired in pyLAPS.☆87Mar 6, 2025Updated last year