XSGEG9's Stars
ElliotKillick/LdrLockLiberator
For when DLLMain is the only way
lanjelot/patator
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
0xmitsurugi/gimmecredz
You're a #pentester and you totally pwn that linux box, congrats! Now what? You can launch gimmecredz.sh which will try to extract all passwords from known locations.
SecWiki/windows-kernel-exploits
windows-kernel-exploits Windows平台提权漏洞集合
NullArray/RootHelper
A Bash script that downloads and unzips scripts that will aid with privilege escalation on a Linux system.
Bo0oM/fuzz.txt
Potentially dangerous files
qazbnm456/awesome-web-security
🐶 A curated list of Web Security materials and resources.
s0md3v/Breacher
An advanced multithreaded admin panel finder written in python.
trimstray/the-book-of-secret-knowledge
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
mubix/post-exploitation
Post Exploitation Collection
dirkjanm/PrivExchange
Exchange your privileges for Domain Admin privs by abusing Exchange
BastilleResearch/mousejack
MouseJack device discovery and research tools
ambionics/phpggc
PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.
insecurityofthings/jackit
JackIt - Exploit Code for Mousejack
dirkjanm/krbrelayx
Kerberos unconstrained delegation abuse toolkit
dionach/PassHunt
Search drives for documents containing passwords
NetSPI/MicroBurst
A collection of scripts for assessing Microsoft Azure security
quickbreach/ExchangeRelayX
An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.
initstring/dirty_sock
Linux privilege escalation exploit via snapd (CVE-2019-7304)
ANSSI-FR/ADTimeline
Timeline of Active Directory changes with replication metadata
Ridter/Exchange2domain
CVE-2018-8581
ryhanson/phishery
An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector
S3cur3Th1sSh1t/audit_scripts
Scripts to gather system configuration information for offline/remote auditing
S3cur3Th1sSh1t/AD-Attack-Defense
Active Directory Security For Red & Blue Team
S3cur3Th1sSh1t/Creds
Some usefull Scripts and Executables for Pentest & Forensics
S3cur3Th1sSh1t/WinPwn
Automation for internal Windows Penetrationtest / AD-Security
dafthack/MailSniper
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
enaqx/awesome-pentest
A collection of awesome penetration testing resources, tools and other shiny things
orlyjamie/mimikittenz
A post-exploitation powershell tool for extracting juicy info from memory.
SpiderLabs/Responder
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.