![](/assets/headers/header-logo.png)

![](https://img.shields.io/badge/Tools%20%26%20Resources%20Available-34-757575?style=for-the-badge)

### Active Directory

* [Aced](https://github.com/garrettfoster13/aced) - A tool to parse and resolve a single targeted Active Directory principal's DACL) ![last-commit](https://img.shields.io/github/last-commit/garrettfoster13/aced?style=flat)
* [BadBlood](https://github.com/davidprowe/BadBlood) - Fills a Microsoft Active Directory Domain with a structure and thousands of objects. ![last-commit](https://img.shields.io/github/last-commit/davidprowe/BadBlood?style=flat)
* [BloodHound](https://github.com/BloodHoundAD/BloodHound) - Six Degrees of Domain Admin. ![last-commit](https://img.shields.io/github/last-commit/BloodHoundAD/BloodHound?style=flat)
* [Certify](https://github.com/GhostPack/Certify) - Active Directory certificate abuse. ![last-commit](https://img.shields.io/github/last-commit/GhostPack/Certify?style=flat)
* [CrackMapExec](https://github.com/byt3bl33d3r/CrackMapExec) - A swiss army knife for pentesting networks. ![last-commit](https://img.shields.io/github/last-commit/byt3bl33d3r/CrackMapExec?style=flat)
* [SCCMHunter](https://github.com/garrettfoster13/sccmhunter) - tool built to streamline identifying, profiling, and attacking SCCM related assets in an Active Directory domain. ![last-commit](https://img.shields.io/github/last-commit/garrettfoster13/sccmhunter?style=flat)
* [WinPwn](https://github.com/S3cur3Th1sSh1t/WinPwn) - Automation for internal Windows Penetrationtest / AD-Security. ![last-commit](https://img.shields.io/github/last-commit/S3cur3Th1sSh1t/WinPwn?style=flat)

### Bitlocker

* [Bitleaker](https://github.com/kkamagui/bitleaker) - This tool can decrypt a BitLocker-locked partition with the TPM vulnerability. ![last-commit](https://img.shields.io/github/last-commit/kkamagui/bitleaker?style=flat)

### Cheatsheets

* [LOLBAS](https://lolbas-project.github.io) - Living Off The Land Binaries and Scripts. ![last-commit](https://img.shields.io/github/last-commit/sqlmapproject/sqlmap?style=flat)

### Credentials

* [LaZagne](https://github.com/AlessandroZ/LaZagne) - Credentials recovery project ![last-commit](https://img.shields.io/github/last-commit/AlessandroZ/LaZagne?style=flat)
* [Redsnarf](https://github.com/nccgroup/redsnarf) - Tool for retrieving hashes and credentials from Windows workstations, servers and domain controllers using OpSec Safe Techniques. ![last-commit](https://img.shields.io/github/last-commit/nccgroup/redsnarf?style=flat)
* [SCOMDecrypt](https://github.com/nccgroup/SCOMDecrypt) - Tool to decrypt stored RunAs credentials from SCOM servers. ![last-commit](https://img.shields.io/github/last-commit/nccgroup/SCOMDecrypt?style=flat)

### Exchange

* [MailSniper](https://github.com/dafthack/MailSniper) - A penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms ![last-commit](https://img.shields.io/github/last-commit/dafthack/MailSniper?style=flat)
* [Ruler](https://github.com/sensepost/ruler) - A tool to abuse Exchange services. ![last-commit](https://img.shields.io/github/last-commit/sensepost/ruler?style=flat)

### Interprocess Communication

* [pipe-intercept](https://github.com/gabriel-sztejnworcel/pipe-intercept) - Intercept Windows Named Pipes communication. ![last-commit](https://img.shields.io/github/last-commit/gabriel-sztejnworcel/pipe-intercept?style=flat)

### Kerberos

* [Kerberoast](https://github.com/nidem/kerberoast) - A series of tools for attacking MS Kerberos implementations. ![last-commit](https://img.shields.io/github/last-commit/nidem/kerberoast?style=flat)
* [Pykek](https://github.com/mubix/pykek) - A python library to manipulate KRB5-related data. ![last-commit](https://img.shields.io/github/last-commit/mubix/pykek?style=flat)
* [Rubeus](https://github.com/GhostPack/Rubeus) - A C\# toolset for raw Kerberos interaction and abuses. ![last-commit](https://img.shields.io/github/last-commit/GhostPack/Rubeus?style=flat)

### Kernel

* [Fibratus](https://github.com/rabbitstack/fibratus) - A modern tool for Windows kernel exploration and tracing with a focus on security. ![last-commit](https://img.shields.io/github/last-commit/nidem/kerberoast?style=flat)
* [Vergilius](https://www.vergiliusproject.com/) - Take a look into the depths of
Windows kernels and reveal more than 60000+ undocumented structures. The descent into Hell is easy!

### Memory

* [Blackbone](https://github.com/DarthTon/Blackbone) - DLL scatter manual mapper. ![last-commit](https://img.shields.io/github/last-commit/DarthTon/Blackbone?style=flat)
* [PPLdump](https://github.com/itm4n/PPLdump) -  Dump the memory of a PPL with a userland exploit. ![last-commit](https://img.shields.io/github/last-commit/itm4n/PPLdump?style=flat)

### Post Exploitation

* [CredNinja](https://github.com/Raikia/CredNinja) - A multithreaded tool designed to identify if credentials are valid, invalid, or local admin valid credentials within a network at-scale via SMB. ![last-commit](https://img.shields.io/github/last-commit/Raikia/CredNinja?style=flat)
* [Mimikatz](https://github.com/gentilkiwi/mimikatz) - Experiments with Windows security. ![last-commit](https://img.shields.io/github/last-commit/gentilkiwi/mimikatz?style=flat)

### Powershell

* [iBombshell](https://github.com/Telefonica/ibombshell) - Tool to deploy a post-exploitation prompt at any time. ![last-commit](https://img.shields.io/github/last-commit/Telefonica/ibombshell?style=flat)
* [Pentestly](https://github.com/praetorian-inc/pentestly) - Python and Powershell internal penetration testing framework. ![last-commit](https://img.shields.io/github/last-commit/praetorian-inc/pentestly?style=flat)
* [Powershell Suite](https://github.com/FuzzySecurity/PowerShell-Suite) - A collection of PowerShell utilities. ![last-commit](https://img.shields.io/github/last-commit/FuzzySecurity/PowerShell-Suite?style=flat)
* [Stracciatella](https://github.com/mgeeky/Stracciatella) - OpSec-safe Powershell runspace from within C# with AMSI, Constrained Language Mode and Script Block Logging disabled at startup. ![last-commit](https://img.shields.io/github/last-commit/mgeeky/Stracciatella?style=flat)

### RDP

* [PowerRemoteDesktop](https://github.com/DarkCoderSc/PowerRemoteDesktop) - Remote Desktop entirely coded in PowerShell. ![last-commit](https://img.shields.io/github/last-commit/DarkCoderSc/PowerRemoteDesktop?style=flat)
* [SharpRDP](https://github.com/0xthirteen/SharpRDP) - Remote Desktop Protocol .NET Console Application for Authenticated Command Execution. ![last-commit](https://img.shields.io/github/last-commit/0xthirteen/SharpRDP?style=flat)

### RPC

* [rpcenum](https://github.com/s4vitar/rpcenum) - Bash tool to extract info from a domain via RPCClient. ![last-commit](https://img.shields.io/github/last-commit/s4vitar/rpcenum?style=flat)

### Scripts

* [LOLBAS](https://lolbas-project.github.io/#) - Living Off The Land Binaries and Scripts. ![last-commit](https://img.shields.io/github/last-commit/LOLBAS-Project/LOLBAS?style=flat)
* [Macshift](https://github.com/nayuki/Macshift) - Windows command-line application changes the MAC address of a given network adapter on the current machine to a random or given value. ![last-commit](https://img.shields.io/github/last-commit/nayuki/Macshift?style=flat)
* [Windows-Pentest](https://github.com/ankh2054/windows-pentest) - Windows Pentest Scripts. ![last-commit](https://img.shields.io/github/last-commit/ankh2054/windows-pentest?style=flat)
