source
addcomputer.py

Adds a computer account to domain.

AdGuardHome

Network-wide ads & trackers blocking DNS server.

ASNmap

Go CLI and Library for quickly mapping organization network ranges using ASN information.

Cache

Cache mode.

Coerce

Exploit Remote Procedure Calls (RPC).

FTP

Own stuff using FTP.

FTP

Own stuff using FTP.

getnthash.py

Use Kerberos U2U to submit a TGS request for yourself.

LinPEAS

Linux Privilege Escalation Awesome Script.

Report

Work with gowitness reports.

AdGuardHome Sync

Synchronize config from one AdGuardHome instance to another.

dnsx

dnsx is a fast and multi-purpose DNS toolkit allow to run multiple probes using retryabledns library.

FindDelegation.py

Queries target domain for delegation relationships.

Fuzz

For research purposes - fuzz Remote Procedure Calls (RPC).

gets4uticket.py

Gets an S4U2self ticket impersonating given user.

LDAP

Own stuff using LDAP

LDAP

LDAP mode.

LDAP

Own stuff using LDAP.

Scan

Perform various scans using sources such as a file, Nmap XMLs, Nessus exports, or by scanning network CIDR ranges.

WinPEAS

Windows local Privilege Escalation Awesome Script.

ADRecon

ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment..

GetNPUsers.py

Queries target domain for users with 'Do not require Kerberos preauthentication' set and export their TGTs for cracking. (ASREPRoasting)

gettgtpkinit.py

Requests a TGT using Kerberos PKINIT and either a PEM or PFX based certificate+key.

httpx

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

MSSQL

Own stuff using MSSQL

MSSQL

Owning stuff using MSSQL.

Scan

Assess the Remote Procedure Calls (RPC) listening.

Arsenal

Arsenal is just a quick inventory, reminder and launcher for pentest commands.

Framework

Frameworks.

GetST.py

Given a password, hash or aesKey, it will request a Service Ticket and save it as ccache.

NFS

Own stuff using NFS.

RDP

Own stuff using RDP.

GetUserSPNs.py

Queries target domain for SPNs that are running under a user account (kerberoasting).

RDP

Own stuff using RDP.

SMB

Own stuff using SMB.

BloodHound

Uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment.

ntlmrelayx.py

For every connection received, this module will try to relay that connection to specified target(s) system or the original client.

SMB

Own stuff using SMB.

SSH

Own stuff using SSH.

Subfinder

Subfinder is a subdomain discovery tool that discovers subdomains for websites by using passive online sources.

BloodHound.py

Python based ingestor for BloodHound.

psexec.py

PSEXEC like functionality example using RemComSvc.

SSH

Own stuff using SSH.

WinRM

Own stuff using WinRM.

bloodyAD

Active Directory Privilege Escalation Framework.

cmedb

Database containing credentials captured.

rdp_check.py

Test whether an account is valid on the target host using the RDP protocol.

VNC

Own stuff using VNC.

CDK

CDK is an open-sourced container penetration toolkit, designed for offering stable exploitation in different slimmed containers without any OS dependency.

samrdump.py

This script downloads the list of users for the target system.

WinRM

Own stuff using WinRM.

Ciphey

Fully automated decryption/decoding/cracking tool using natural language processing & artificial intelligence, along with some common sense.

secretsdump.py

Performs various techniques to dump secrets from the remote machine without executing any agent there.

WMI

Own stuff using WMI.

Coercer

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 9 methods.

nxcdb

Database containing credentials captured.

smbclient.py

SMB client implementation.

CrackMapExec

A swiss army knife for pentesting networks.

smbexec.py

PSEXEC over SMB.

CyberChef

The Cyber Swiss Army Knife.

DonPAPI

Dumping revelant information on compromised targets without AV detection.

smbrelayx.py

Relay SMB traffic.

Evil-WinRM

This shell is the ultimate WinRM shell for hacking/pentesting.

smbserver.py

This script will launch a SMB Server and add a share specified as an argument. You need to be root in order to bind to port 445. For optional authentication, it is possible to specify username and password or the NTLM hash.

GoodHound

GoodHound operationalises Bloodhound by determining the busiest paths to high value targets and creating actionable output to prioritise remediation of attack paths.

ticketer.py

Creates a Kerberos golden/silver tickets based on user options.

GoWitness

A website screenshot utility written in Golang, that uses Chrome Headless to generate screenshots of web interfaces using the command line.

wmiexec.py

Executes a semi-interactive shell using Windows Management Instrumentation.

Hugo

The world's fastest framework for building websites.

Impacket

Is a collection of Python classes for working with network protocols.

LDEEP

In-depth ldap enumeration utility.

linWinPwn

Swiss-Army knife for Active Directory Pentesting using Linux.

Lsassy

Python library to remotely extract credentials on a set of hosts.

Metasploit

The world's most used penetration testing framework.

Mimikatz

Is a tool I've made to learn C and make somes experiments with Windows security.

Mitm6

mitm6 is a pentesting tool that exploits the default configuration of Windows to take over the default DNS server.

MSFvenom

MSFvenom is a combination of Msfpayload and Msfencode, putting both of these tools into a single Framework instance. msfvenom replaced both msfpayload and msfencode as of June 8th, 2015.

Navi

An interactive cheatsheet tool for the command-line and application launchers.

NetExec

The Network Execution Tool.

PEASS-ng

Privilege Escalation Awesome Scripts SUITE new generation.

Pi-Hole

A black hole for Internet advertisements. Network-wide (DNS-based) Ad Blocking.

PingCastle

PingCastle - Get Active Directory Security at 80% in 20% of the time.

PKINITtools

Tools for Kerberos PKINIT and relaying to AD CS.

Pretender

Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.

ProjectDiscovery

Security Through Intelligent Automation.

Pypykatz

Mimikatz implementation in pure Python. At least a part of it :)

ScoutSuite

Multi-Cloud Security Auditing Tool.

SearchSploit

SearchSploit gives you the power to perform detailed off-line searches through your locally checked-out copy of the repository.

Seth

RDP credential sniffer - Man in the Middle RDP

Subdomain Visualizer

Script that visualizes subdomains for the domain you want.

WEF

Wi-Fi Exploitation Framework.

Wifite2

Rewrite of the popular wireless network auditor, 'wifite' - automated wireless auditor.

Search knowledge base