zblurx / BloodHoundCustomQueries
My BloodHound custom queries
☆23Updated last year
Related projects ⓘ
Alternatives and complementary repositories for BloodHoundCustomQueries
- HelpSystems Nanodump, but wrapped in powershell via Invoke-ReflectivePEInjection☆53Updated 2 years ago
- SuperSharpShares is a tool designed to automate enumerating domain shares, allowing for quick verification of accessible shares by your a…☆63Updated 6 months ago
- A script that greps composite key-like strings from a KeePassXC process dump, then uses a customized version of pykeepass library to unlo…☆30Updated 2 years ago
- Quick and dirty PowerShell script to abuse the overly permissive capabilities of the SYSTEM user in a child domain on the Public Key Serv…☆25Updated last year
- Extract registry and NTDS secrets from local or remote disk images☆32Updated 2 months ago
- Programmatically start WebClient from an unprivileged session to enable that juicy privesc.☆66Updated last year
- ☆68Updated last year
- Python3 rewrite of AsOutsider features of AADInternals☆35Updated 2 months ago
- Federated Office365 user enumeration based on correlated response trend analysis☆47Updated 2 years ago
- Tool for issuing manual LDAP queries which offers bofhound compatible output☆15Updated 2 months ago
- Standalone Cobalt Strike operation logging Aggressor script for Ghostwriter 2.0+☆25Updated 3 months ago
- Modified version of PEAS client for offensive operations☆38Updated last year
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆33Updated 5 months ago
- Convert an LDIF file to JSON files ingestible by BloodHound☆40Updated 2 months ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆41Updated last month
- Scripts to interact with Microsoft Graph APIs☆31Updated 2 weeks ago
- Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged p…☆49Updated 2 years ago
- ☆43Updated 4 months ago
- Get Fine Grained Password Policy☆65Updated 6 months ago
- Leveraging AWS Lambda Function URLs for C2 Redirection☆22Updated last year
- Proof of Concept code and samples presenting emerging threat of MSI installer files.☆77Updated last year
- A module for CME that spiders across a domain.☆35Updated 2 years ago
- Secretsdump C# version only supporting local (live) operation☆47Updated last year
- A VSCode devcontainer for development of COFF files with batteries included.☆47Updated last year
- ☆35Updated 2 years ago
- A BOF port of the research of @thefLinkk and @codewhitesec☆94Updated 3 years ago
- ☆36Updated last month
- ☆51Updated 3 years ago
- Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry☆25Updated 3 years ago