☆97Jul 28, 2026Updated this week
Alternatives and similar repositories for Kestrel
Users that are interested in Kestrel are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin res…☆87Jun 20, 2026Updated last month
- ☆58Jul 12, 2026Updated 3 weeks ago
- Dump TGTs remotely and convert Windows' klist binary output to ccache.☆92Jun 30, 2026Updated last month
- An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed a…☆27May 21, 2026Updated 2 months ago
- Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advance…☆114Jun 30, 2026Updated last month
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but fo…☆175Jun 19, 2026Updated last month
- Automatically deploying Mythic C2 in Azure using Terraform☆25Jul 3, 2026Updated last month
- open source port/reimplementation of the Cobalt Strike BOF Loader as is☆74Mar 8, 2026Updated 4 months ago
- Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.☆96Jul 22, 2026Updated last week
- PowerShell implementation for AD CS☆159Updated this week
- The Azure Execution Tool☆159Feb 6, 2026Updated 5 months ago
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆133Mar 27, 2026Updated 4 months ago
- goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current…☆66Jun 28, 2026Updated last month
- Tailscale/Headscale C2 profile and agent for Mythic☆25Mar 14, 2026Updated 4 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Lateral Movement Bof with MSI ODBC Driver Install☆173Sep 30, 2025Updated 10 months ago
- A newer iteration of TitanLdr with some newer hooks, and design. A generic user defined reflective DLL I built to prove a point to Mudge …☆34Mar 20, 2023Updated 3 years ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 2 months ago
- C# to read WIM files over the network without transferring the whole file☆40Jan 22, 2026Updated 6 months ago
- InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution☆162Jul 15, 2026Updated 2 weeks ago
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆83Apr 11, 2026Updated 3 months ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆183May 31, 2026Updated 2 months ago
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆134Jul 23, 2026Updated last week
- Opengraph-Compatible JSON Generator for BloodHound☆29Mar 30, 2026Updated 4 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Automatically scan the file system to identify Electron applications vulnerable to ASAR tampering.☆162Nov 28, 2025Updated 8 months ago
- Python3 rewrite of AsOutsider features of AADInternals☆62Jul 23, 2025Updated last year
- Crystal Palace Evasion kit for Sliver☆108Jun 13, 2026Updated last month
- GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumera…☆40Jul 23, 2026Updated last week
- A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.☆134Mar 30, 2026Updated 4 months ago
- psexec-like remote execution using the paexec wire protocol that supports paexec and remoteexecm2 from manageengine adselfservice plus☆43Mar 24, 2026Updated 4 months ago
- A collection of DPAPI hunting and parsing BOFs☆38Mar 3, 2026Updated 5 months ago
- Cobalt Strike Aggressor Script for identifying security products on Windows hosts — six enumeration methods rated by noise level, from si…☆92Feb 6, 2026Updated 5 months ago
- Transform LDAP filters, BaseDNs, attribute lists, and attribute entries using composable middleware chains. Zero dependencies. Works as a…☆44Apr 13, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Open Source Implementation of Cobalt Strike's Malleable C2☆106Jun 27, 2026Updated last month
- Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants☆200Jun 6, 2026Updated last month
- A BOF designed to inspect processes memory and addresses☆40Apr 19, 2026Updated 3 months ago
- NTLM HTTP relay tool with SOCKS proxy for browser session hijacking☆183Apr 6, 2026Updated 3 months ago
- A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single depe…☆702Jul 21, 2026Updated last week
- open source implementation of the UDC2 spec used in Cobalt Strike☆57Jul 4, 2026Updated 3 weeks ago
- DynLoader A modular Windows loader focused on EDR evasion Built with indirect syscall (Tartarus Gate / Hell’s Gate), Manual PE parsing …☆81Jul 10, 2026Updated 3 weeks ago