Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tools: ad (133)

Pentesting tools tagged ad. See all tools or the category key.

Team (best effort)

abuseACL

A python script to automatically list vulnerable Windows ACEs/ACLs.

ad

adwsdomaindump

A tool for dumping domain data via ADWS for evasion purposes.

ad

aliasr

Aliasr is a modern and feature-rich TUI launcher for penetration testing commands inspired by Arsenal but with significantly improved functionality.

ad osint web Red Team

anew

A simple tool for filtering and manipulating text data / such as log files and other outputs.

ad web

asciinema

Terminal session recorder

ad light osint web Red Team

asdf

Extendable version manager with support for ruby python go etc

ad light osint web Red Team

asrepcatcher

Make your VLAN ASREProastable.

ad

autobloody

Automatically exploit Active Directory privilege escalation paths shown by BloodHound.

ad

bloodbash

BloodBash is a powerful standalone BloodHound / SharpHound + AzureHound JSON analyzer written in Python

ad

BloodHound-CE

Active Directory security tool for reconnaissance and attacking AD environments (Community Edition)

ad

bloodhound-ce.py

BloodHound-CE ingestor in Python.

ad

bloodhound-import

Import data into BloodHound for analyzing active directory trust relationships

ad

bloodhound.py

BloodHound ingestor in Python.

ad light

bloodhound-quickwin

A tool for BloodHounding on Windows machines without .NET or Powershell installed

ad

bolt

Bolt crawls the target website to the specified depth and stores all the HTML forms found in a database for further processing.

ad web

byp4xx

A Swiss Army knife for bypassing web application firewalls and filters.

ad web

cewler

CeWL alternative in Python

ad web

chaos

A Go client to communicate with Chaos dataset API from ProjectDiscovery.

ad web

cmloot

cmloot.py is built to aid penetration testers to search and find sensitive files in Configuration Manager's complex file share structure.

ad

crackhound

A fast WPA/WPA2/WPA3 WiFi Handshake capture / password recovery and analysis tool

ad

curlie

Curlie is a frontend to curl that adds the ease of use of httpie without compromising on features and performance

ad web

cyperoth

Automated extensible toolset that runs cypher queries against Bloodhound's Neo4j backend and saves output to spreadsheets.

ad

daclsearch

Exhaustive search and flexible filtering of Active Directory ACEs

ad

dfscoerce

DFS-R target coercion tool

ad

divideandscan

Advanced subdomain scanner

ad

dtrx

Do The Right eXtraction - don't remember what set of tar flags or where to pipe the output to extract it? no worries!

ad osint web Red Team

enyx

Framework for building offensive security tools.

ad

EVENmonitor

Monitor the Windows Event Log with grep-like features or filtering for specific Event IDs

ad

evilwinrm

Tool to connect to a remote Windows system with WinRM.

ad light

exegol-history

Credentials management for Exegol

ad light osint web Red Team

freeipscanner

A simple bash script to enumerate stale ADIDNS entries

ad

freerdp2-x11

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP) released under the Apache license.

ad

fzf

🌸 A command-line fuzzy finder

ad light osint web Red Team

genusernames

GenUsername is a Python tool for generating a list of usernames based on a name or email address.

ad web

geowordlists

tool to generate wordlists of passwords containing cities at a defined distance around the client city.

ad web

glow

glow is a tool to render Markdown inside the terminal.

ad osint web Red Team

godap

A complete TUI for LDAP.

ad

GoExec

GoExec is a new take on some of the methods used to gain remote execution on Windows devices. GoExec implements a number of largely unrealized…

ad

goldencopy

Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket

ad

gosecretsdump

Implements NTLMSSP network authentication protocol in Go

ad

GPOddity

Aiming at automating GPO attack vectors through NTLM relaying (and more)

ad

gpoParser

Tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

ad

hashonymize

This small tool is aimed at anonymizing hashes files for offline but online cracking like Google Collab for instance (see…

ad

Hob0Rules rules

Password cracking rules for Hashcat based on statistics and industry patterns

ad web

httpmethods

Tool for exploiting HTTP methods (e.g. PUT / DELETE / etc.)

ad web

iptables

Userspace command line tool for configuring kernel firewall

ad

jdwp

This exploitation script is meant to be used by pentesters against active JDWP service / in order to gain Remote Code Execution.

ad web

jsluice

Extract URLs / paths / secrets and other interesting data from JavaScript source code.

ad web

jwt

a command-line tool for working with JSON Web Tokens (JWTs)

ad light web

keepassxc

Cross-platform password manager

ad osint web Red Team

KeePwn

KeePwn is a tool that extracts passwords from KeePass 1.x and 2.x databases.

ad

keytabextract

KeyTabExtract is a tool to extract valuable information from keytab files.

ad

ldaprelayscan

Check Domain Controllers for LDAP server protections regarding the relay of NTLM authentication.

ad

ldapsearch

Search for and display entries (ldap)

ad

ldapsearch-ad

LDAP search utility with AD support

ad

libmspack

C library for Microsoft compression formats.

ad

lnkup

This tool will allow you to generate LNK payloads. Upon rendering or being run they will exfiltrate data.

ad

lsassy

Windows secrets and passwords extraction tool.

ad

mariadb-client

MariaDB is a community-developed fork of the MySQL relational database management system. The mariadb-client package includes command-line utilities…

ad

masky

Masky is a python library providing an alternative way to remotely dump domain users' credentials thanks to an ADCS. A command line tool has been…

ad

mdcat

Fancy cat for Markdown

ad light osint web Red Team

metasploit

A popular penetration testing framework that includes many exploits and payloads

ad light

moodlescan

Scan Moodle sites for information and vulnerabilities.

ad web

msprobe

msprobe is a tool to identify Microsoft Windows hosts and servers that are running certain services.

ad

neo4j

Database.

ad light

neovim

hyperextensible Vim-based text editor

ad light osint web Red Team

nmap-parse-ouptut

Converts/manipulates/extracts data from a Nmap scan output.

ad

noPac

Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user.

ad

NSAKEY rules

Password cracking rules and masks for hashcat

ad web

oaburl

Find Open redirects and other vulnerabilities.

ad

objectwalker

A python module to explore the object tree to extract paths to interesting objects in memory.

ad osint web Red Team

oneforall

a powerful subdomain collection tool.

ad web

onelistforall

Rockyou for web fuzzing

ad web

OneRuleToRuleThemStill rules

One rule to crack all passwords. A revamped - optimised and updated version of the original OneRuleToRuleThemAll hashcat rule

ad web

Pantagrule rules

large hashcat rulesets generated from real-world compromised passwords

ad web

pass

TODO

ad web

PassTheCert

PassTheCert is a tool to extract Active Directory user password hashes from a domain controller's local certificate store.

ad

petitpotam

Windows machine account manipulation

ad

PHP filter chain generator

A CLI to generate PHP filters chain / get your RCE without uploading a file if you control entirely the parameter passed to a require or an include…

ad web

postman

API platform for testing APIs

ad web

Powerview.py

PowerView.py is an alternative for the awesome original PowerView.ps1 script.

ad

pretender

an mitm tool for helping with relay attacks.

ad

prips

A utility for quickly generating IP ranges or enumerating hosts within a specified range.

ad web

privexchange

a tool to perform attacks against Microsoft Exchange server using NTLM relay techniques

ad

proxychains

Proxy chains - redirect connections through proxy servers.

ad light

pth-tools

A toolkit to perform pass-the-hash attacks

ad

pwncat-vl

Maintained fork of pwncat-cs with recent fixes and enhancements.

ad

PXEThief

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

ad

pyFindUncommonShares

Script that can help identify shares that are not commonly found on a Windows system.

ad

pyftpdlib

Extremely fast and scalable Python FTP server library

ad light osint web Red Team

pygoldengmsa

Cross-platform Python implementation of the GoldenGMSA attack for exploiting Group Managed Service Accounts (gMSA) in Active Directory.

ad

pylaps

Utility for enumerating and querying LDAP servers.

ad

pypykatz

a Python library for mimikatz-like functionality

ad

pysnaffler

Snaffler. But in python.

ad

pywerview

A (partial) Python rewriting of PowerSploit's PowerView.

ad

pywhisker

PyWhisker is a Python equivalent of the original Whisker made by Elad Shamir and written in C#. This tool allows users to manipulate the…

ad

pywsus

Python implementation of a WSUS client

ad

redis-tools

redis-tools is a collection of Redis client utilities including redis-cli and redis-benchmark.

ad

remmina

Remote desktop client.

ad

RemoteMonologue

A tool to coerce NTLM authentications via DCOM

ad

rlwrap

rlwrap is a small utility that wraps input and output streams of executables / making it possible to edit and re-run input history

ad osint web Red Team

roastinthemiddle

RoastInTheMiddle is a tool to intercept and relay NTLM authentication requests.

ad

robotstester

Utility for testing whether a website's robots.txt file is correctly configured.

ad web

rsync

File synchronization tool for efficiently copying and updating data between local or remote locations

ad osint web Red Team

rusthound

BloodHound ingestor in Rust.

ad

sccmsecrets

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting and initial access and lateral movement.

ad

sccmwtf

This code is designed for exploring SCCM in a lab.

ad

searchsploit

A command line search tool for Exploit-DB

ad osint web Red Team

shadowcoerce

Utility for bypassing the Windows Defender antivirus by hiding a process within a legitimate process.

ad

sharker

A fast and reliable network capture analyzer

ad

smartbrute

The smart password spraying and bruteforcing tool for Active Directory Domain Services.

ad

smbclient

SMBclient is a command-line utility that allows you to access Windows shared resources

ad light

ssh-audit

ssh-audit is a tool to test SSH server configuration for best practices.

ad

symfony-exploits

Collection of Symfony exploits and PoCs.

ad web

tdo_dump

Proof-of-Concept tool to dump trusted domain objects and extract trust credentials for lateral movement across domain boundaries

ad

TeamsPhisher

TeamsPhisher is a Python3 program that facilitates the delivery of phishing messages and attachments to Microsoft Teams users whose organizations…

ad

testssl

a tool for testing SSL/TLS encryption on servers

ad light web

thr

THR (The Hacker Recipes) is aimed at providing technical guides on various hacking topics.

ad osint web Red Team

tig

Tig is an ncurses-based text-mode interface for git.

ad osint web Red Team

timing

Tool to generate a timing profile for a given command.

ad web

token-exploiter

Token Exploiter is a tool designed to analyze GitHub Personal Access Tokens.

ad web

TriliumNext

Personal knowledge management system (successor to Trilium).

ad osint web Red Team

udpx

Fast and lightweight - UDPX is a single-packet UDP scanner written in Go that supports the discovery of over 45 services with the ability to add…

ad

updog

Simple replacement for Python's SimpleHTTPServer.

ad web

uploader

Tool for quickly downloading files to a remote machine based on the target operating system

ad osint web Red Team

urldedupe

urldedupe is a c++ tool to quickly pass in a list of URLs and get back a list of deduplicated (unique) URL and query string combination.

ad web

webclientservicescanner

Scans for web service endpoints

ad

windapsearch-go

Active Directory enumeration tool.

ad

wireguard

WireGuard is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography

ad light osint web Red Team

xtightvncviewer

xtightvncviewer is an open source VNC client software.

ad

yarn

Yarn is a package manager that doubles down as project manager.

ad light osint web Red Team

yt-dlp

A youtube-dl fork with additional features and fixes

ad osint web Red Team

zerologon

Exploit for the Zerologon vulnerability (CVE-2020-1472).

ad