Skip to content
View chibd2000's full-sized avatar
🤒
🤒

Block or report chibd2000

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

Active Directory Attack

active directory attack
66 repositories

pyForgeCert is a Python equivalent of the ForgeCert.

Python 64 3 Updated Aug 15, 2023

A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.

C# 456 79 Updated Oct 14, 2022

Python version of the C# tool for "Shadow Credentials" attacks

Python 680 85 Updated Feb 25, 2025

A .NET tool for exporting and importing certificates without touching disk.

C# 482 68 Updated Oct 8, 2021
Python 312 34 Updated Mar 4, 2025

"Golden" certificates

C# 658 110 Updated Aug 17, 2024

Active Directory certificate abuse.

C# 1,607 222 Updated Aug 12, 2024

Tools for Kerberos PKINIT and relaying to AD CS

Python 701 83 Updated Jan 3, 2025

Extracts Key Values from .keytab files

Python 247 46 Updated Aug 26, 2020

Framework for Kerberos relaying

C# 892 126 Updated May 29, 2022

Custom Query list for the Bloodhound GUI based off my cheatsheet

765 126 Updated Jan 17, 2023

Standalone implementation of a part of the WSUS spec. Built for offensive security purposes.

Python 303 44 Updated Nov 11, 2022

The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).

Python 280 22 Updated Nov 8, 2024

Active Directory Integrated DNS dumping by any authenticated user

Python 979 115 Updated Nov 29, 2024

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

C# 623 81 Updated Jul 30, 2022

PoC for Zerologon - all research credits go to Tom Tervoort of Secura

Python 1,217 283 Updated Nov 3, 2020

A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE

Python 792 123 Updated May 19, 2024

PoC to coerce authentication from Windows hosts using MS-WSP

C# 230 31 Updated Sep 7, 2023

A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.

C# 830 127 Updated Mar 20, 2023

MS-FSRVP coercion abuse PoC

Python 285 37 Updated Dec 30, 2021

PowerShell toolkit for AD CS auditing based on the PSPKI toolkit.

PowerShell 846 116 Updated Feb 28, 2024

pwning IPv4 via IPv6

Python 1,763 256 Updated Feb 20, 2024

CVE-2018-8581

Python 371 76 Updated Oct 21, 2022

GolenGMSA tool for working with GMSA passwords

C# 139 21 Updated Apr 11, 2024

Escalate Service Account To LocalSystem via Kerberos

C# 393 75 Updated Sep 14, 2023

Active Directory information dumper via LDAP

Python 1,224 197 Updated Aug 20, 2024

Python script that takes new output from Get-DomainTrustMapping .csvs and outputs graphml. Based on DomainTrustExplorer.

Python 95 17 Updated Dec 7, 2023

C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527

C# 1,868 585 Updated Jul 20, 2021

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

Python 1,912 192 Updated Mar 6, 2025

Dump NTDS with golden certificates and UnPAC the hash

Python 633 68 Updated Mar 20, 2024