Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

Tools: windows (148)

Pentesting tools tagged windows. See all tools or the category key.

Team (best effort)

3proxy-win32

Tiny free proxy server.

windows Red Team

adape-script

Active Directory Assessment and Privilege Escalation Script.

windows Red Team

adpeas

winPEAS, but for Active Directory.

windows Red Team

agafi

A gadget finder and a ROP-Chainer tool for x86 platforms.

windows Red Team

analyzepesig

Analyze digital signature of PE file.

windows Red Team

antiransom

A tool capable of detect and stop attacks of Ransomware using honeypots.

windows Red Team

atstaketools

This is an archive of various @Stake tools that help perform vulnerability scanning and analysis, information gathering,

windows Red Team

backorifice

A remote administration system which allows a user to control a computer across a tcpip connection using a simple consol

windows Red Team

browselist

Retrieves the browse list ; the output list contains computer names, and the roles they play in the network.

windows Red Team

brute12

A tool designed for auditing the cryptography container security in PKCS12 format.

windows Red Team

brutus

One of the fastest, most flexible remote password crackers you can get your hands on.

windows Red Team

cachedump

A tool that demonstrates how to recover cache entry information: username and hashed password (called MSCASH).

windows Red Team

certipy

Active Directory Certificate Services enumeration and abuse.

windows Red Team

chrome-decode

Chrome web browser decoder tool that demonstrates recovering passwords.

windows Red Team

chromensics

A Google chrome forensics tool.

windows Red Team

conpass

Password spraying in AD environment avoing account locking.

windows Red Team

crackmapexec-pingcastle

NetExec & CrackMapExec module that execute PingCastle on a remote machine.

windows Red Team

dark-dork-searcher

Dark-Dork Searcher.

windows Red Team

darkarmour

Store and execute an encrypted windows binary from inside memory, without a single bit touching disk.

windows Red Team

de4dot

.NET deobfuscator and unpacker.

windows Red Team

de4dotex

.NET deobfuscator and unpacker.

windows Red Team

directorytraversalscan

Detect directory traversal vulnerabilities in HTTP servers and web applications.

windows Red Team

dnspy

.NET debugger and assembly editor.

windows Red Team

donpapi

Dumping revelant information on compromised targets without AV detection with DPAPI.

windows Red Team

dotpeek

Free .NET Decompiler and Assembly Browser.

windows Red Team

dumpacl

Dumps NTs ACLs and audit settings.

windows Red Team

dumpusers

Dumps account names and information even though RestrictAnonymous has been set to 1.

windows Red Team

eraser

Windows tool which allows you to completely remove sensitive data from your hard drive by overwriting it several times w

windows Red Team

etherchange

Can change the Ethernet address of the network adapters in Windows.

windows Red Team

etherflood

Floods a switched network with Ethernet frames with random hardware addresses.

windows Red Team

extractbitlockerkeys

Script to automatically extract the bitlocker recovery keys from a domain.

windows Red Team

filefuzz

A binary file fuzzer for Windows with several options.

windows Red Team

finduncommonshares

Python script allowing to quickly find uncommon shares in vast Windows Domains.

windows Red Team

fport

Identify unknown open ports and their associated applications.

windows Red Team

fred

Cross-platform M$ registry hive editor.

windows Red Team

fuzztalk

An XML driven fuzz testing framework that emphasizes easy extensibility and reusability.

windows Red Team

gene

Signature Engine for Windows Event Logs.

windows Red Team

ghostpack

Compiled Binaries for Ghostpack (.NET v4.8.1).

windows Red Team

gplist

Lists information about the applied Group Policies.

windows Red Team

gpowned

GPOs manipulation tool.

windows Red Team

grabitall

Performs traffic redirection by sending spoofed ARP replies.

windows Red Team

gsd

Gives you the Discretionary Access Control List of any Windows NT service you specify as a command line option.

windows Red Team

gtalk-decode

Google Talk decoder tool that demonstrates recovering passwords from accounts.

windows Red Team

handle

An small application designed to analyze your system searching for global objects related to running process and display

windows Red Team

hexodus

Python framework project designed to enumerate and help in Active Directory attacks through Windows protocols like SMB,

windows Red Team

hollows-hunter

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, sh

windows Red Team

hookanalyser

A hook tool which can be potentially helpful in reversing applications and analyzing malware. It can hook to an API in a

windows Red Team

httpbog

A slow HTTP denial-of-service tool that works similarly to other attacks, but rather than leveraging request headers or

windows Red Team

httprecon

Tool for web server fingerprinting, also known as http fingerprinting.

windows Red Team

httprint-win32

A web server fingerprinting tool (Windows binaries).

windows Red Team

hyperion-crypter

A runtime encrypter for 32-bit and 64-bit portable executables.

windows Red Team

ikeprobe

Determine vulnerabilities in the PSK implementation of the VPN server.

windows Red Team

intercepter-ng

A next generation sniffer including a lot of features: capturing passwords/hashes, sniffing chat messages, performing ma

windows Red Team

inzider

This is a tool that lists processes in your Windows system and the ports each one listen on.

windows Red Team

juicy-potato

A sugared version of RottenPotatoNG, with a bit of juice.

windows Red Team

justdecompile

The decompilation engine of JustDecompile.

windows Red Team

kekeo

A little toolbox to play with Microsoft Kerberos in C.

windows Red Team

kerbcrack

Kerberos sniffer and cracker for Windows.

windows Red Team

klogger

A keystroke logger for the NT-series of Windows.

windows Red Team

ldapmonitor

Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration!

windows Red Team

lethalhta

Lateral Movement technique using DCOM and HTA.

windows Red Team

lolbas

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts).

windows Red Team

malwareanalyser

A freeware tool to perform static and dynamic analysis on malware.

windows Red Team

mbenum

Queries the master browser for whatever information it has registered.

windows Red Team

memimager

Performs a memory dump using NtSystemDebugControl.

windows Red Team

mingsweeper

A network reconnaissance tool designed to facilitate large address space,high speed node discovery and identification.

windows Red Team

modifycerttemplate

Aid operators in modifying ADCS certificate templates so that a created vulnerable state can be leveraged for privilege

windows Red Team

mrkaplan

Help red teamers to stay hidden by clearing evidence of execution.

windows Red Team

mssqlrelay

Microsoft SQL Relay is an offensive tool for auditing and abusing Microsoft SQL (MSSQL) services.

windows Red Team

msvpwn

Bypass Windows' authentication via binary patching.

windows Red Team

nbname

Decodes and displays all NetBIOS name packets it receives on UDP port 137 and more!

windows Red Team

nbtenum

A utility for Windows that can be used to enumerate NetBIOS information from one host or a range of hosts.

windows Red Team

netbus

NetBus remote administration tool

windows Red Team

netexec-pingcastle

NetExec & CrackMapExec module that execute PingCastle on a remote machine.

windows Red Team

netripper

Smart traffic sniffing for penetration testers.

windows Red Team

netstumbler

Well-known wireless AP scanner and sniffer.

windows Red Team

nimrm

Native WinRM shell client with NTLM, Kerberos, file transfers, in-memory operations, and multi-session support.

windows Red Team

nirsoft

Unique collection of small and useful freeware utilities.

windows Red Team

ntds-decode

This application dumps LM and NTLM hashes from active accounts stored in an Active Directory database.

windows Red Team

orakelcrackert

This tool can crack passwords which are encrypted using Oracle's latest SHA1 based password protection algorithm.

windows Red Team

osslsigncode

A small tool that implements part of the functionality of the Microsoft tool signtool.exe.

windows Red Team

pafish

A demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as ma

windows Red Team

pe-bear

A freeware reversing tool for PE files.

windows Red Team

pe-sieve

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcod

windows Red Team

periscope

A PE file inspection tool.

windows Red Team

petools

Portable executable (PE) manipulation toolkit.

windows Red Team

pextractor

A forensics tool that can extract all files from an executable file created by a joiner or similar.

windows Red Team

php-vulnerability-hunter

An whitebox fuzz testing tool capable of detected several classes of vulnerabilities in PHP web applications.

windows Red Team

pingcastle

Active Directory scanning tool.

windows Red Team

pmap

Passively discover, scan, and fingerprint link-local peers by the background noise they generate (i.e. their broadcast a

windows Red Team

pmdump

A tool that lets you dump the memory contents of a process to a file without stopping the process.

windows Red Team

powercloud

Deliver powershell payloads via DNS TXT via CloudFlare using PowerShell.

windows Red Team

powerlessshell

Run PowerShell command without invoking powershell.exe.

windows Red Team

powerops

PowerShell Runspace Portable Post Exploitation Tool aimed at making Penetration Testing with PowerShell "easier".

windows Red Team

powershdll

Run PowerShell with rundll32. Bypass software restrictions.

windows Red Team

ppee

A Professional PE file Explorer for reversers, malware researchers and those who want to statically inspect PE files in

windows Red Team

pre2k

Query for existence of pre-windows 2000 computer objects which can be leveraged to gain a foothold in a target domain.

windows Red Team

promiscdetect

Checks if your network adapter(s) is running in promiscuous mode, which may be a sign that you have a sniffer running on

windows Red Team

pstoreview

Lists the contents of the Protected Storage.

windows Red Team

pwdump

Extracts the binary SAM and SYSTEM file from the filesystem and then the hashes.

windows Red Team

pyadrecon

Gathers information about the Active Directory and generates a report which can provide a holistic picture of the curren

windows Red Team

pygpoabuse

RCE via GPO scheduled tasks.

windows Red Team

python2-minidump

Python library to parse and read Microsoft minidump file format.

windows Red Team

python2-minikerberos

Kerberos manipulation library in pure Python.

windows Red Team

radiography

A forensic tool which grabs as much information as possible from a Windows system.

windows Red Team

rasenum

A small program which lists the information for all of the entries in any phonebook file (.pbk).

windows Red Team

regreport

Windows registry forensic analysis tool.

windows Red Team

regview

Open raw Windows NT 5 Registry files (Windows 2000 or higher).

windows Red Team

resourcehacker

Resource compiler and decompiler for Windows® applications.

windows Red Team

roadlib

Azure AD and O365 exploration framework.

windows Red Team

roadoidc

Azure AD and O365 exploration framework.

windows Red Team

roadrecon

Azure AD and O365 exploration framework.

windows Red Team

roadtx

Azure AD and O365 exploration framework.

windows Red Team

rpak

A collection of tools that can be useful for doing attacks on routing protocols.

windows Red Team

rpcsniffer

Sniffs WINDOWS RPC messages in a given RPC server process.

windows Red Team

rpctools

Contains three separate tools for obtaining information from a system that is running RPC services

windows Red Team

sccmhunter

Identifying, profiling, and attacking SCCM related assets in an Active Directory domain.

windows Red Team

setowner

Allows you to set file ownership to any account, as long as you have the "Restore files and directories" user right.

windows Red Team

shad0w

A modular C2 framework designed to successfully operate on mature environments.

windows Red Team

sigspotter

A tool that search in your HD to find which publishers has been signed binaries in your PC.

windows Red Team

sipscan

A sip scanner.

windows Red Team

skype-dump

This is a tool that demonstrates dumping MD5 password hashes from the configuration file in Skype.

windows Red Team

smbrelay

SMB / HTTP to SMB replay attack toolkit.

windows Red Team

snitch

Turn back the asterisks in password fields to plaintext passwords.

windows Red Team

snowman

A native code to C/C++ decompiler, see the examples of generated code.

windows Red Team

snscan

A Windows based SNMP detection utility that can quickly and accurately identify SNMP enabled devices on a network.

windows Red Team

spade

A general-purpose Internet utility package, with some extra features to help in tracing the source of spam and other for

windows Red Team

sqlping

SQL Server scanning tool that also checks for weak passwords using wordlists.

windows Red Team

sqlpowerinjector

Application created in .Net 1.1 that helps the penetration tester to find and exploit SQL injections on a web page.

windows Red Team

streamfinder

Searches for Alternate Data Streams (ADS).

windows Red Team

sub7

A remote administration tool. No further comments ;-)

windows Red Team

superscan

Powerful TCP port scanner, pinger, resolver.

windows Red Team

sysinternals-suite

Sysinternals tools suite.

windows Red Team

targetedkerberoast

Kerberoast with ACL abuse capabilities.

windows Red Team

uacme

Defeating Windows User Account Control.

windows Red Team

unsecure

Bruteforces network login masks.

windows Red Team

upnp-pentest-toolkit

UPnP Pentest Toolkit for Windows.

windows Red Team

wifichannelmonitor

A utility for Windows that captures wifi traffic on the channel you choose, using Microsoft Network Monitor capture driv

windows Red Team

windivert

A user-mode packet capture-and-divert package for Windows.

windows Red Team

windowsspyblocker

Block spying and tracking on Windows.

windows Red Team

winfo

Uses null sessions to remotely try to retrieve lists of and information about user accounts, workstation/interdomain/ser

windows Red Team

winhex

Hex Editor and Disk Editor.

windows Red Team

winpwn

Automation for internal Windows Penetrationtest / AD-Security.

windows Red Team

winrelay

A TCP/UDP forwarder/redirector that works with both IPv4 and IPv6.

windows Red Team

wpsweep

A simple ping sweeper, that is, it pings a range of IP addresses and lists the ones that reply.

windows Red Team

wups

An UDP port scanner for Windows.

windows Red Team

x-scan

A general network vulnerabilities scanner for scanning network vulnerabilities for specific IP address scope or stand-al

windows Red Team

x64dbg

An open-source x64/x32 debugger for windows.

windows Red Team