tokyoneon / CredPhish
CredPhish is a PowerShell script designed to invoke legitimate credential prompts and exfiltrate passwords over DNS.
☆290Updated 3 years ago
Alternatives and similar repositories for CredPhish:
Users that are interested in CredPhish are comparing it to the libraries listed below
- AD Enum is a pentesting tool that allows to find misconfiguration through the the protocol LDAP and exploit some of those weaknesses with…☆295Updated last year
- Basic C2 Server☆187Updated 3 years ago
- VPN Overall Reconnaissance, Testing, Enumeration and eXploitation Toolkit☆429Updated last year
- Malicious shortcut generator for collecting NTLM hashes from insecure file shares.☆315Updated 3 months ago
- Proof-of-concept obfuscation toolkit for C# post-exploitation tools☆416Updated 2 years ago
- Hiding GoPhish from the boys in blue☆174Updated 2 years ago
- A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies☆311Updated last year
- A password guessing tool that targets the Kerberos and LDAP services within the Windows Active Directory environment.☆436Updated last year
- Tricks the target into enabling content (macros) with fake messages. Once enabled, uses macros to reduce the risk of suspision from targe…☆166Updated 3 years ago
- Script collection to bypass Network Access Control (NAC, 802.1x)☆279Updated 3 months ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆220Updated 3 years ago
- Invoke-ZeroLogon allows attackers to impersonate any computer, including the domain controller itself, and execute remote procedure calls…☆215Updated 4 years ago
- Automated Tool That Generates The Perfect Meterpreter Powershell Payload☆224Updated 3 years ago
- ☆404Updated last year
- Password spraying tool and Bloodhound integration☆219Updated 3 weeks ago
- A better version of Xencrypt.Xencrypt it self is a Powershell runtime crypter designed to evade AVs.☆212Updated 3 years ago
- Assist reverse tcp shells in post-exploration tasks☆215Updated 10 months ago
- ☆189Updated 5 years ago
- Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory☆383Updated 10 months ago
- Enumerate valid usernames from Office 365 using ActiveSync, Autodiscover v1, or office.com login page.☆251Updated 8 months ago
- msImpersonate - User account impersonation written in pure Python3☆107Updated 2 years ago
- Open-Source Collection of Social Engineering Pretexts☆133Updated last year
- Ansible playbook to deploy a phishing engagement in the cloud.☆217Updated 2 years ago
- scan for NTLM directories☆351Updated 7 months ago
- A script to test credentials against Active Directory Federation Services (ADFS), allowing password spraying or bruteforce attacks.☆168Updated 3 years ago
- Maximizing BloodHound. Max is a good boy.☆503Updated 2 weeks ago
- Password Hunter in Active Directory☆197Updated 2 years ago
- Kerberoast attack -pure python-☆423Updated last year
- Checks running processes, process metadata, Dlls loaded into your current process and the each DLLs metadata, common install directories,…☆250Updated last year
- WSuspicious - A tool to abuse insecure WSUS connections for privilege escalations☆353Updated 4 years ago