zblurx / dploot
DPAPI looting remotely and locally in Python
☆423Updated last week
Related projects ⓘ
Alternatives and complementary repositories for dploot
- DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the …☆523Updated last year
- Impacket is a collection of Python classes for working with network protocols.☆268Updated 3 weeks ago
- Dump NTDS with golden certificates and UnPAC the hash☆623Updated 8 months ago
- Python library with CLI allowing to remotely dump domain user credentials via an ADCS without dumping the LSASS process memory☆377Updated 7 months ago
- Partial python implementation of SharpGPOAbuse☆363Updated 9 months ago
- Dump lsass using only Native APIs by hand-crafting Minidump files (without MiniDumpWriteDump!!!)☆466Updated last month
- A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) wit…☆493Updated 8 months ago
- A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other ob…☆452Updated 2 years ago
- ☆191Updated last month
- Recovering NTLM hashes from Credential Guard☆327Updated last year
- BOF for Kerberos abuse (an implementation of some important features of the Rubeus).☆396Updated 2 weeks ago
- Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound☆426Updated last week
- Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types☆372Updated last year
- FindUncommonShares is a Python script allowing to quickly find uncommon shares in vast Windows Domains, and filter by READ or WRITE acces…☆389Updated 3 weeks ago
- Tool to remotely dump secrets from the Windows registry☆401Updated 3 months ago
- AD ACL abuse☆260Updated 4 months ago
- ☆279Updated 3 weeks ago
- An other No-Fix LPE, NTLMRelay2Self over HTTP (Webdav).☆394Updated 9 months ago
- Some scripts to abuse kerberos using Powershell☆313Updated last year
- Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel☆301Updated 8 months ago
- Amsi Bypass payload that works on Windwos 11☆370Updated last year
- Lifetime AMSI bypass by @ZeroMemoryEx ported to .NET Framework 4.8☆349Updated 2 months ago
- Kill AV/EDR leveraging BYOVD attack☆309Updated last year
- ☆294Updated 3 weeks ago
- The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).☆265Updated last week
- .net config loader☆308Updated last year
- Materials for the workshop "Red Team Ops: Havoc 101"☆351Updated last month
- Ask a TGS on behalf of another user without password☆465Updated 3 months ago
- Python tool to Check running WebClient services on multiple targets based on @leechristensen☆252Updated 3 years ago
- Proof-of-Concept tool to authenticate to an LDAP/S server with a certificate through Schannel☆572Updated 4 months ago