#Framework
Knowledge base entries tagged Framework.
Adds a computer account to domain.
AdGuardHomeNetwork-wide ads & trackers blocking DNS server.
ASNmapGo CLI and Library for quickly mapping organization network ranges using ASN information.
CacheCache mode.
CoerceExploit Remote Procedure Calls (RPC).
FTPOwn stuff using FTP.
FTPOwn stuff using FTP.
getnthash.pyUse Kerberos U2U to submit a TGS request for yourself.
LinPEASLinux Privilege Escalation Awesome Script.
ReportWork with gowitness reports.
AdGuardHome SyncSynchronize config from one AdGuardHome instance to another.
dnsxdnsx is a fast and multi-purpose DNS toolkit allow to run multiple probes using retryabledns library.
FindDelegation.pyQueries target domain for delegation relationships.
FuzzFor research purposes - fuzz Remote Procedure Calls (RPC).
gets4uticket.pyGets an S4U2self ticket impersonating given user.
LDAPOwn stuff using LDAP
LDAPLDAP mode.
LDAPOwn stuff using LDAP.
ScanPerform various scans using sources such as a file, Nmap XMLs, Nessus exports, or by scanning network CIDR ranges.
WinPEASWindows local Privilege Escalation Awesome Script.
ADReconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment..
GetNPUsers.pyQueries target domain for users with 'Do not require Kerberos preauthentication' set and export their TGTs for cracking. (ASREPRoasting)
gettgtpkinit.pyRequests a TGT using Kerberos PKINIT and either a PEM or PFX based certificate+key.
httpxhttpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
MSSQLOwn stuff using MSSQL
MSSQLOwning stuff using MSSQL.
ScanAssess the Remote Procedure Calls (RPC) listening.
ArsenalArsenal is just a quick inventory, reminder and launcher for pentest commands.
FrameworkFrameworks.
GetST.pyGiven a password, hash or aesKey, it will request a Service Ticket and save it as ccache.
NFSOwn stuff using NFS.
RDPOwn stuff using RDP.
GetUserSPNs.pyQueries target domain for SPNs that are running under a user account (kerberoasting).
RDPOwn stuff using RDP.
SMBOwn stuff using SMB.
BloodHoundUses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment.
ntlmrelayx.pyFor every connection received, this module will try to relay that connection to specified target(s) system or the original client.
SMBOwn stuff using SMB.
SSHOwn stuff using SSH.
SubfinderSubfinder is a subdomain discovery tool that discovers subdomains for websites by using passive online sources.
BloodHound.pyPython based ingestor for BloodHound.
psexec.pyPSEXEC like functionality example using RemComSvc.
SSHOwn stuff using SSH.
WinRMOwn stuff using WinRM.
bloodyADActive Directory Privilege Escalation Framework.
cmedbDatabase containing credentials captured.
rdp_check.pyTest whether an account is valid on the target host using the RDP protocol.
VNCOwn stuff using VNC.
CDKCDK is an open-sourced container penetration toolkit, designed for offering stable exploitation in different slimmed containers without any OS dependency.
samrdump.pyThis script downloads the list of users for the target system.
WinRMOwn stuff using WinRM.
CipheyFully automated decryption/decoding/cracking tool using natural language processing & artificial intelligence, along with some common sense.
secretsdump.pyPerforms various techniques to dump secrets from the remote machine without executing any agent there.
WMIOwn stuff using WMI.
CoercerA python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 9 methods.
nxcdbDatabase containing credentials captured.
smbclient.pySMB client implementation.
CrackMapExecA swiss army knife for pentesting networks.
smbexec.pyPSEXEC over SMB.
CyberChefThe Cyber Swiss Army Knife.
DonPAPIDumping revelant information on compromised targets without AV detection.
smbrelayx.pyRelay SMB traffic.
Evil-WinRMThis shell is the ultimate WinRM shell for hacking/pentesting.
smbserver.pyThis script will launch a SMB Server and add a share specified as an argument. You need to be root in order to bind to port 445. For optional authentication, it is possible to specify username and password or the NTLM hash.
GoodHoundGoodHound operationalises Bloodhound by determining the busiest paths to high value targets and creating actionable output to prioritise remediation of attack paths.
ticketer.pyCreates a Kerberos golden/silver tickets based on user options.
GoWitnessA website screenshot utility written in Golang, that uses Chrome Headless to generate screenshots of web interfaces using the command line.
wmiexec.pyExecutes a semi-interactive shell using Windows Management Instrumentation.
HugoThe world's fastest framework for building websites.
ImpacketIs a collection of Python classes for working with network protocols.
LDEEPIn-depth ldap enumeration utility.
linWinPwnSwiss-Army knife for Active Directory Pentesting using Linux.
LsassyPython library to remotely extract credentials on a set of hosts.
MetasploitThe world's most used penetration testing framework.
MimikatzIs a tool I've made to learn C and make somes experiments with Windows security.
Mitm6mitm6 is a pentesting tool that exploits the default configuration of Windows to take over the default DNS server.
MSFvenomMSFvenom is a combination of Msfpayload and Msfencode, putting both of these tools into a single Framework instance. msfvenom replaced both msfpayload and msfencode as of June 8th, 2015.
NaviAn interactive cheatsheet tool for the command-line and application launchers.
NetExecThe Network Execution Tool.
PEASS-ngPrivilege Escalation Awesome Scripts SUITE new generation.
Pi-HoleA black hole for Internet advertisements. Network-wide (DNS-based) Ad Blocking.
PingCastlePingCastle - Get Active Directory Security at 80% in 20% of the time.
PKINITtoolsTools for Kerberos PKINIT and relaying to AD CS.
PretenderYour MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.
ProjectDiscoverySecurity Through Intelligent Automation.
PypykatzMimikatz implementation in pure Python. At least a part of it :)
ScoutSuiteMulti-Cloud Security Auditing Tool.
SearchSploitSearchSploit gives you the power to perform detailed off-line searches through your locally checked-out copy of the repository.
SethRDP credential sniffer - Man in the Middle RDP
Subdomain VisualizerScript that visualizes subdomains for the domain you want.
WEFWi-Fi Exploitation Framework.
Wifite2Rewrite of the popular wireless network auditor, 'wifite' - automated wireless auditor.