Stars
Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI
Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It ca…
PingCastle - Get Active Directory Security at 80% in 20% of the time
LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)
SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.
A PowerShell-based toolkit and framework consisting of a collection of techniques and tradecraft for use in red team, post-exploitation, adversary simulation, or other offensive security tasks.
Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS
A C# implementation of PrivExchange by @_dirkjan.
Active Directory Assessment and Privilege Escalation Script
Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities
Various PowerShell scripts that may be useful during red team exercise
A collection of Red Team focused tools, scripts, and notes
SharpGen is a .NET Core console application that utilizes the Rosyln C# compiler to quickly cross-compile .NET Framework console applications or libraries.
SharpSploit is a .NET post-exploitation library written in C#
Covenant is a collaborative .NET C2 framework for red teamers.
TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution.
The Offensive Manual Web Application Penetration Testing Framework.
A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and re…
A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
Tools to compare list of packages against known vulnerabilities and exploits
Set of information and examples about ARM assembly language programming
securipy / pentesting-core
Forked from 4dminserver/adminserverCore para herramientas de seguridad
The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.