-
Bulletproof
- https://viperone.gitbook.io/pentest-everything
Stars
The Kerberoasting / AD password-audit wordlist I use on engagements: priority-merged HashMob large list + The-Viper-One's kerberoast_pws, order-preserving dedup via rling, paired with OneRuleToRule…
Info on how to use Kerberos KDC on a non-domain joined host
This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library
A Linux Privilege Escalation cheat sheet I made prepping for the OSCP that has mophored into the most comprehensive, specific Linux PrivEsc reference online : )
A cheatsheet for the Titanis library and reference for using the command line tools from Titanis for Active Directory Penatration Testing
Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay, delegation), with …
Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI + web UI.
Standalone PowerShell scripts that generate interactive, self-contained HTML reports for Active Directory health and security.
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
One-pass anonymous Active Directory enumeration over SAMR and LSARPC — null session, no credentials, with structured reusable output.
Ask the Web Account Manager (WAM) for Entra ID tokens
Active Directory snapshots from Linux and macOS in the AD Explorer .dat format. Opens in AD Explorer, works with ADExplorerSnapshot.py and BOFHound.
Here is a Hashcat rule to generate a list of quick-win passwords. These are the formats I’ve most commonly seen in companies.
Tool to enumerate Windows sessions across one or more hosts via three native RPC interfaces, correlate every observation into a BloodHound HasSession-like JSON report written in Rust. 🦀
Tool to authenticate to an LDAP/S server with a certificate through Schannel written in Rust. 🦀
Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.
Recover NT hashes from NetNTLMv1 responses using local WebGPU computation and local/remote table lookup
SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.
A SeImpersonate potato primitive that exploits squatting the IAiddService endpoint
SpicyAD is a C# Active Directory penetration testing tool designed for authorized security assessments. It combines multiple AD attack techniques into a single, easy-to-use tool with both interacti…
x64dbg-MCP Server is a native MCP (Model Context Protocol) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Connect any MCP-compatible AI assistant and control x64dbg pro…
The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber risk through the elimination of attack paths.
