Tools: windows (148)
Pentesting tools tagged windows. See all tools or the category key.
3proxy-win32
Tiny free proxy server.
adape-script
Active Directory Assessment and Privilege Escalation Script.
adpeas
winPEAS, but for Active Directory.
agafi
A gadget finder and a ROP-Chainer tool for x86 platforms.
analyzepesig
Analyze digital signature of PE file.
antiransom
A tool capable of detect and stop attacks of Ransomware using honeypots.
atstaketools
This is an archive of various @Stake tools that help perform vulnerability scanning and analysis, information gathering,
backorifice
A remote administration system which allows a user to control a computer across a tcpip connection using a simple consol
browselist
Retrieves the browse list ; the output list contains computer names, and the roles they play in the network.
brute12
A tool designed for auditing the cryptography container security in PKCS12 format.
brutus
One of the fastest, most flexible remote password crackers you can get your hands on.
cachedump
A tool that demonstrates how to recover cache entry information: username and hashed password (called MSCASH).
certipy
Active Directory Certificate Services enumeration and abuse.
chrome-decode
Chrome web browser decoder tool that demonstrates recovering passwords.
chromensics
A Google chrome forensics tool.
conpass
Password spraying in AD environment avoing account locking.
crackmapexec-pingcastle
NetExec & CrackMapExec module that execute PingCastle on a remote machine.
dark-dork-searcher
Dark-Dork Searcher.
darkarmour
Store and execute an encrypted windows binary from inside memory, without a single bit touching disk.
de4dot
.NET deobfuscator and unpacker.
de4dotex
.NET deobfuscator and unpacker.
directorytraversalscan
Detect directory traversal vulnerabilities in HTTP servers and web applications.
dnspy
.NET debugger and assembly editor.
donpapi
Dumping revelant information on compromised targets without AV detection with DPAPI.
dotpeek
Free .NET Decompiler and Assembly Browser.
dumpacl
Dumps NTs ACLs and audit settings.
dumpusers
Dumps account names and information even though RestrictAnonymous has been set to 1.
eraser
Windows tool which allows you to completely remove sensitive data from your hard drive by overwriting it several times w
etherchange
Can change the Ethernet address of the network adapters in Windows.
etherflood
Floods a switched network with Ethernet frames with random hardware addresses.
extractbitlockerkeys
Script to automatically extract the bitlocker recovery keys from a domain.
filefuzz
A binary file fuzzer for Windows with several options.
finduncommonshares
Python script allowing to quickly find uncommon shares in vast Windows Domains.
fport
Identify unknown open ports and their associated applications.
fred
Cross-platform M$ registry hive editor.
fuzztalk
An XML driven fuzz testing framework that emphasizes easy extensibility and reusability.
gene
Signature Engine for Windows Event Logs.
ghostpack
Compiled Binaries for Ghostpack (.NET v4.8.1).
gplist
Lists information about the applied Group Policies.
gpowned
GPOs manipulation tool.
grabitall
Performs traffic redirection by sending spoofed ARP replies.
gsd
Gives you the Discretionary Access Control List of any Windows NT service you specify as a command line option.
gtalk-decode
Google Talk decoder tool that demonstrates recovering passwords from accounts.
handle
An small application designed to analyze your system searching for global objects related to running process and display
hexodus
Python framework project designed to enumerate and help in Active Directory attacks through Windows protocols like SMB,
hollows-hunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, sh
hookanalyser
A hook tool which can be potentially helpful in reversing applications and analyzing malware. It can hook to an API in a
httpbog
A slow HTTP denial-of-service tool that works similarly to other attacks, but rather than leveraging request headers or
httprecon
Tool for web server fingerprinting, also known as http fingerprinting.
httprint-win32
A web server fingerprinting tool (Windows binaries).
hyperion-crypter
A runtime encrypter for 32-bit and 64-bit portable executables.
ikeprobe
Determine vulnerabilities in the PSK implementation of the VPN server.
intercepter-ng
A next generation sniffer including a lot of features: capturing passwords/hashes, sniffing chat messages, performing ma
inzider
This is a tool that lists processes in your Windows system and the ports each one listen on.
juicy-potato
A sugared version of RottenPotatoNG, with a bit of juice.
justdecompile
The decompilation engine of JustDecompile.
kekeo
A little toolbox to play with Microsoft Kerberos in C.
kerbcrack
Kerberos sniffer and cracker for Windows.
klogger
A keystroke logger for the NT-series of Windows.
ldapmonitor
Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!
lethalhta
Lateral Movement technique using DCOM and HTA.
lolbas
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts).
malwareanalyser
A freeware tool to perform static and dynamic analysis on malware.
mbenum
Queries the master browser for whatever information it has registered.
memimager
Performs a memory dump using NtSystemDebugControl.
mingsweeper
A network reconnaissance tool designed to facilitate large address space,high speed node discovery and identification.
modifycerttemplate
Aid operators in modifying ADCS certificate templates so that a created vulnerable state can be leveraged for privilege
mrkaplan
Help red teamers to stay hidden by clearing evidence of execution.
mssqlrelay
Microsoft SQL Relay is an offensive tool for auditing and abusing Microsoft SQL (MSSQL) services.
msvpwn
Bypass Windows' authentication via binary patching.
nbname
Decodes and displays all NetBIOS name packets it receives on UDP port 137 and more!
nbtenum
A utility for Windows that can be used to enumerate NetBIOS information from one host or a range of hosts.
netbus
NetBus remote administration tool
netexec-pingcastle
NetExec & CrackMapExec module that execute PingCastle on a remote machine.
netripper
Smart traffic sniffing for penetration testers.
netstumbler
Well-known wireless AP scanner and sniffer.
nimrm
Native WinRM shell client with NTLM, Kerberos, file transfers, in-memory operations, and multi-session support.
nirsoft
Unique collection of small and useful freeware utilities.
ntds-decode
This application dumps LM and NTLM hashes from active accounts stored in an Active Directory database.
orakelcrackert
This tool can crack passwords which are encrypted using Oracle's latest SHA1 based password protection algorithm.
osslsigncode
A small tool that implements part of the functionality of the Microsoft tool signtool.exe.
pafish
A demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as ma
pe-bear
A freeware reversing tool for PE files.
pe-sieve
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcod
periscope
A PE file inspection tool.
petools
Portable executable (PE) manipulation toolkit.
pextractor
A forensics tool that can extract all files from an executable file created by a joiner or similar.
php-vulnerability-hunter
An whitebox fuzz testing tool capable of detected several classes of vulnerabilities in PHP web applications.
pingcastle
Active Directory scanning tool.
pmap
Passively discover, scan, and fingerprint link-local peers by the background noise they generate (i.e. their broadcast a
pmdump
A tool that lets you dump the memory contents of a process to a file without stopping the process.
powercloud
Deliver powershell payloads via DNS TXT via CloudFlare using PowerShell.
powerlessshell
Run PowerShell command without invoking powershell.exe.
powerops
PowerShell Runspace Portable Post Exploitation Tool aimed at making Penetration Testing with PowerShell "easier".
powershdll
Run PowerShell with rundll32. Bypass software restrictions.
ppee
A Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in
pre2k
Query for existence of pre-windows 2000 computer objects which can be leveraged to gain a foothold in a target domain.
promiscdetect
Checks if your network adapter(s) is running in promiscuous mode, which may be a sign that you have a sniffer running on
pstoreview
Lists the contents of the Protected Storage.
pwdump
Extracts the binary SAM and SYSTEM file from the filesystem and then the hashes.
pyadrecon
Gathers information about the Active Directory and generates a report which can provide a holistic picture of the curren
pygpoabuse
RCE via GPO scheduled tasks.
python2-minidump
Python library to parse and read Microsoft minidump file format.
python2-minikerberos
Kerberos manipulation library in pure Python.
radiography
A forensic tool which grabs as much information as possible from a Windows system.
rasenum
A small program which lists the information for all of the entries in any phonebook file (.pbk).
regreport
Windows registry forensic analysis tool.
regview
Open raw Windows NT 5 Registry files (Windows 2000 or higher).
resourcehacker
Resource compiler and decompiler for Windows® applications.
roadlib
Azure AD and O365 exploration framework.
roadoidc
Azure AD and O365 exploration framework.
roadrecon
Azure AD and O365 exploration framework.
roadtx
Azure AD and O365 exploration framework.
rpak
A collection of tools that can be useful for doing attacks on routing protocols.
rpcsniffer
Sniffs WINDOWS RPC messages in a given RPC server process.
rpctools
Contains three separate tools for obtaining information from a system that is running RPC services
sccmhunter
Identifying, profiling, and attacking SCCM related assets in an Active Directory domain.
setowner
Allows you to set file ownership to any account, as long as you have the "Restore files and directories" user right.
shad0w
A modular C2 framework designed to successfully operate on mature environments.
sigspotter
A tool that search in your HD to find which publishers has been signed binaries in your PC.
sipscan
A sip scanner.
skype-dump
This is a tool that demonstrates dumping MD5 password hashes from the configuration file in Skype.
smbrelay
SMB / HTTP to SMB replay attack toolkit.
snitch
Turn back the asterisks in password fields to plaintext passwords.
snowman
A native code to C/C++ decompiler, see the examples of generated code.
snscan
A Windows based SNMP detection utility that can quickly and accurately identify SNMP enabled devices on a network.
spade
A general-purpose Internet utility package, with some extra features to help in tracing the source of spam and other for
sqlping
SQL Server scanning tool that also checks for weak passwords using wordlists.
sqlpowerinjector
Application created in .Net 1.1 that helps the penetration tester to find and exploit SQL injections on a web page.
streamfinder
Searches for Alternate Data Streams (ADS).
sub7
A remote administration tool. No further comments ;-)
superscan
Powerful TCP port scanner, pinger, resolver.
sysinternals-suite
Sysinternals tools suite.
targetedkerberoast
Kerberoast with ACL abuse capabilities.
uacme
Defeating Windows User Account Control.
unsecure
Bruteforces network login masks.
upnp-pentest-toolkit
UPnP Pentest Toolkit for Windows.
wifichannelmonitor
A utility for Windows that captures wifi traffic on the channel you choose, using Microsoft Network Monitor capture driv
windivert
A user-mode packet capture-and-divert package for Windows.
windowsspyblocker
Block spying and tracking on Windows.
winfo
Uses null sessions to remotely try to retrieve lists of and information about user accounts, workstation/interdomain/ser
winhex
Hex Editor and Disk Editor.
winpwn
Automation for internal Windows Penetrationtest / AD-Security.
winrelay
A TCP/UDP forwarder/redirector that works with both IPv4 and IPv6.
wpsweep
A simple ping sweeper, that is, it pings a range of IP addresses and lists the ones that reply.
wups
An UDP port scanner for Windows.
x-scan
A general network vulnerabilities scanner for scanning network vulnerabilities for specific IP address scope or stand-al
x64dbg
An open-source x64/x32 debugger for windows.