Pinned Repositories
Certify
Active Directory certificate abuse.
KeeThief
Methods for attacking KeePass 2.X databases, including extracting of encryption key material from memory.
PSPKIAudit
PowerShell toolkit for AD CS auditing based on the PSPKI toolkit.
Rubeus
Trying to tame the three-headed dog.
SafetyKatz
SafetyKatz is a combination of slightly modified version of @gentilkiwi's Mimikatz project and @subtee's .NET PE Loader
Seatbelt
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
SharpDPAPI
SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.
SharpDump
SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.
SharpUp
SharpUp is a C# port of various PowerUp functionality.
SharpWMI
SharpWMI is a C# implementation of various WMI functionality.
GhostPack's Repositories
GhostPack/Rubeus
Trying to tame the three-headed dog.
GhostPack/Seatbelt
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
GhostPack/Certify
Active Directory certificate abuse.
GhostPack/SharpUp
SharpUp is a C# port of various PowerUp functionality.
GhostPack/SafetyKatz
SafetyKatz is a combination of slightly modified version of @gentilkiwi's Mimikatz project and @subtee's .NET PE Loader
GhostPack/SharpDPAPI
SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.
GhostPack/KeeThief
Methods for attacking KeePass 2.X databases, including extracting of encryption key material from memory.
GhostPack/PSPKIAudit
PowerShell toolkit for AD CS auditing based on the PSPKI toolkit.
GhostPack/SharpWMI
SharpWMI is a C# implementation of various WMI functionality.
GhostPack/ForgeCert
"Golden" certificates
GhostPack/SharpDump
SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.
GhostPack/Koh
The Token Stealer
GhostPack/SharpRoast
DEPRECATED SharpRoast is a C# port of various PowerView's Kerberoasting functionality.
GhostPack/Lockless
Lockless allows for the copying of locked files.
GhostPack/DeepPass
Hunting for passwords with deep learning
GhostPack/RestrictedAdmin
Remotely enables Restricted Admin Mode
GhostPack/Invoke-Evasion
PowerShell Obfuscation and Data Science
GhostPack/RAGnarok
A Nemesis powered Retrieval-Augmented Generation (RAG) chatbot proof-of-concept.