Tools: ad (133)
Pentesting tools tagged ad. See all tools or the category key.
abuseACL
A python script to automatically list vulnerable Windows ACEs/ACLs.
adwsdomaindump
A tool for dumping domain data via ADWS for evasion purposes.
aliasr
Aliasr is a modern and feature-rich TUI launcher for penetration testing commands inspired by Arsenal but with significantly improved functionality.
anew
A simple tool for filtering and manipulating text data / such as log files and other outputs.
asciinema
Terminal session recorder
asdf
Extendable version manager with support for ruby python go etc
asrepcatcher
Make your VLAN ASREProastable.
autobloody
Automatically exploit Active Directory privilege escalation paths shown by BloodHound.
bloodbash
BloodBash is a powerful standalone BloodHound / SharpHound + AzureHound JSON analyzer written in Python
BloodHound-CE
Active Directory security tool for reconnaissance and attacking AD environments (Community Edition)
bloodhound-ce.py
BloodHound-CE ingestor in Python.
bloodhound-import
Import data into BloodHound for analyzing active directory trust relationships
bloodhound.py
BloodHound ingestor in Python.
bloodhound-quickwin
A tool for BloodHounding on Windows machines without .NET or Powershell installed
bolt
Bolt crawls the target website to the specified depth and stores all the HTML forms found in a database for further processing.
byp4xx
A Swiss Army knife for bypassing web application firewalls and filters.
cewler
CeWL alternative in Python
chaos
A Go client to communicate with Chaos dataset API from ProjectDiscovery.
cmloot
cmloot.py is built to aid penetration testers to search and find sensitive files in Configuration Manager's complex file share structure.
crackhound
A fast WPA/WPA2/WPA3 WiFi Handshake capture / password recovery and analysis tool
curlie
Curlie is a frontend to curl that adds the ease of use of httpie without compromising on features and performance
cyperoth
Automated extensible toolset that runs cypher queries against Bloodhound's Neo4j backend and saves output to spreadsheets.
daclsearch
Exhaustive search and flexible filtering of Active Directory ACEs
dfscoerce
DFS-R target coercion tool
divideandscan
Advanced subdomain scanner
dtrx
Do The Right eXtraction - don't remember what set of tar flags or where to pipe the output to extract it? no worries!
enyx
Framework for building offensive security tools.
EVENmonitor
Monitor the Windows Event Log with grep-like features or filtering for specific Event IDs
evilwinrm
Tool to connect to a remote Windows system with WinRM.
exegol-history
Credentials management for Exegol
freeipscanner
A simple bash script to enumerate stale ADIDNS entries
freerdp2-x11
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP) released under the Apache license.
fzf
🌸 A command-line fuzzy finder
genusernames
GenUsername is a Python tool for generating a list of usernames based on a name or email address.
geowordlists
tool to generate wordlists of passwords containing cities at a defined distance around the client city.
glow
glow is a tool to render Markdown inside the terminal.
godap
A complete TUI for LDAP.
GoExec
GoExec is a new take on some of the methods used to gain remote execution on Windows devices. GoExec implements a number of largely unrealized…
goldencopy
Copy the properties and groups of a user from neo4j (bloodhound) to create an identical golden ticket
gosecretsdump
Implements NTLMSSP network authentication protocol in Go
GPOddity
Aiming at automating GPO attack vectors through NTLM relaying (and more)
gpoParser
Tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.
hashonymize
This small tool is aimed at anonymizing hashes files for offline but online cracking like Google Collab for instance (see…
Hob0Rules rules
Password cracking rules for Hashcat based on statistics and industry patterns
httpmethods
Tool for exploiting HTTP methods (e.g. PUT / DELETE / etc.)
iptables
Userspace command line tool for configuring kernel firewall
jdwp
This exploitation script is meant to be used by pentesters against active JDWP service / in order to gain Remote Code Execution.
jsluice
Extract URLs / paths / secrets and other interesting data from JavaScript source code.
jwt
a command-line tool for working with JSON Web Tokens (JWTs)
keepassxc
Cross-platform password manager
KeePwn
KeePwn is a tool that extracts passwords from KeePass 1.x and 2.x databases.
keytabextract
KeyTabExtract is a tool to extract valuable information from keytab files.
ldaprelayscan
Check Domain Controllers for LDAP server protections regarding the relay of NTLM authentication.
ldapsearch
Search for and display entries (ldap)
ldapsearch-ad
LDAP search utility with AD support
libmspack
C library for Microsoft compression formats.
lnkup
This tool will allow you to generate LNK payloads. Upon rendering or being run they will exfiltrate data.
lsassy
Windows secrets and passwords extraction tool.
mariadb-client
MariaDB is a community-developed fork of the MySQL relational database management system. The mariadb-client package includes command-line utilities…
masky
Masky is a python library providing an alternative way to remotely dump domain users' credentials thanks to an ADCS. A command line tool has been…
mdcat
Fancy cat for Markdown
metasploit
A popular penetration testing framework that includes many exploits and payloads
moodlescan
Scan Moodle sites for information and vulnerabilities.
msprobe
msprobe is a tool to identify Microsoft Windows hosts and servers that are running certain services.
neo4j
Database.
neovim
hyperextensible Vim-based text editor
nmap-parse-ouptut
Converts/manipulates/extracts data from a Nmap scan output.
noPac
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user.
NSAKEY rules
Password cracking rules and masks for hashcat
oaburl
Find Open redirects and other vulnerabilities.
objectwalker
A python module to explore the object tree to extract paths to interesting objects in memory.
oneforall
a powerful subdomain collection tool.
onelistforall
Rockyou for web fuzzing
OneRuleToRuleThemStill rules
One rule to crack all passwords. A revamped - optimised and updated version of the original OneRuleToRuleThemAll hashcat rule
Pantagrule rules
large hashcat rulesets generated from real-world compromised passwords
pass
TODO
PassTheCert
PassTheCert is a tool to extract Active Directory user password hashes from a domain controller's local certificate store.
petitpotam
Windows machine account manipulation
PHP filter chain generator
A CLI to generate PHP filters chain / get your RCE without uploading a file if you control entirely the parameter passed to a require or an include…
postman
API platform for testing APIs
Powerview.py
PowerView.py is an alternative for the awesome original PowerView.ps1 script.
pretender
an mitm tool for helping with relay attacks.
prips
A utility for quickly generating IP ranges or enumerating hosts within a specified range.
privexchange
a tool to perform attacks against Microsoft Exchange server using NTLM relay techniques
proxychains
Proxy chains - redirect connections through proxy servers.
pth-tools
A toolkit to perform pass-the-hash attacks
pwncat-vl
Maintained fork of pwncat-cs with recent fixes and enhancements.
PXEThief
PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager
pyFindUncommonShares
Script that can help identify shares that are not commonly found on a Windows system.
pyftpdlib
Extremely fast and scalable Python FTP server library
pygoldengmsa
Cross-platform Python implementation of the GoldenGMSA attack for exploiting Group Managed Service Accounts (gMSA) in Active Directory.
pylaps
Utility for enumerating and querying LDAP servers.
pypykatz
a Python library for mimikatz-like functionality
pysnaffler
Snaffler. But in python.
pywerview
A (partial) Python rewriting of PowerSploit's PowerView.
pywhisker
PyWhisker is a Python equivalent of the original Whisker made by Elad Shamir and written in C#. This tool allows users to manipulate the…
pywsus
Python implementation of a WSUS client
redis-tools
redis-tools is a collection of Redis client utilities including redis-cli and redis-benchmark.
remmina
Remote desktop client.
RemoteMonologue
A tool to coerce NTLM authentications via DCOM
rlwrap
rlwrap is a small utility that wraps input and output streams of executables / making it possible to edit and re-run input history
roastinthemiddle
RoastInTheMiddle is a tool to intercept and relay NTLM authentication requests.
robotstester
Utility for testing whether a website's robots.txt file is correctly configured.
rsync
File synchronization tool for efficiently copying and updating data between local or remote locations
rusthound
BloodHound ingestor in Rust.
sccmsecrets
SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting and initial access and lateral movement.
sccmwtf
This code is designed for exploring SCCM in a lab.
searchsploit
A command line search tool for Exploit-DB
shadowcoerce
Utility for bypassing the Windows Defender antivirus by hiding a process within a legitimate process.
sharker
A fast and reliable network capture analyzer
smartbrute
The smart password spraying and bruteforcing tool for Active Directory Domain Services.
smbclient
SMBclient is a command-line utility that allows you to access Windows shared resources
ssh-audit
ssh-audit is a tool to test SSH server configuration for best practices.
symfony-exploits
Collection of Symfony exploits and PoCs.
tdo_dump
Proof-of-Concept tool to dump trusted domain objects and extract trust credentials for lateral movement across domain boundaries
TeamsPhisher
TeamsPhisher is a Python3 program that facilitates the delivery of phishing messages and attachments to Microsoft Teams users whose organizations…
testssl
a tool for testing SSL/TLS encryption on servers
thr
THR (The Hacker Recipes) is aimed at providing technical guides on various hacking topics.
tig
Tig is an ncurses-based text-mode interface for git.
timing
Tool to generate a timing profile for a given command.
token-exploiter
Token Exploiter is a tool designed to analyze GitHub Personal Access Tokens.
TriliumNext
Personal knowledge management system (successor to Trilium).
udpx
Fast and lightweight - UDPX is a single-packet UDP scanner written in Go that supports the discovery of over 45 services with the ability to add…
updog
Simple replacement for Python's SimpleHTTPServer.
uploader
Tool for quickly downloading files to a remote machine based on the target operating system
urldedupe
urldedupe is a c++ tool to quickly pass in a list of URLs and get back a list of deduplicated (unique) URL and query string combination.
webclientservicescanner
Scans for web service endpoints
windapsearch-go
Active Directory enumeration tool.
wireguard
WireGuard is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography
xtightvncviewer
xtightvncviewer is an open source VNC client software.
yarn
Yarn is a package manager that doubles down as project manager.
yt-dlp
A youtube-dl fork with additional features and fixes
zerologon
Exploit for the Zerologon vulnerability (CVE-2020-1472).