"keyword","metadata_keyword_regex","metadata_keyword_type","metadata_tool","metadata_description","metadata_tool_techniques","metadata_tool_tactics","metadata_malwares_name","metadata_groups_name","metadata_category","metadata_link","metadata_enable_endpoint_detection","metadata_enable_proxy_detection","metadata_tags","metadata_comment","metadata_severity_score","metadata_popularity_score","metadata_github_stars","metadata_github_forks","metadata_github_updated_at","metadata_github_created_at","metadata_entry_id"
"* - Dump LSASS memory bypassing countermeasures*",".{0,1000}\s\-\sDump\sLSASS\smemory\sbypassing\scountermeasures.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","0","#content","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","6"
"* - Remote lsass dump reader*",".{0,1000}\s\-\sRemote\slsass\sdump\sreader.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#content","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","10"
"* /altservice:ldap *",".{0,1000}\s\/altservice\:ldap\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","36"
"* /asrepkey*",".{0,1000}\s\/asrepkey.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","37"
"* /changentlm* /user:* /oldhash:*",".{0,1000}\s\/changentlm.{0,1000}\s\/user\:.{0,1000}\s\/oldhash\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","46"
"* /changentlm* /user:* /oldpwd:*",".{0,1000}\s\/changentlm.{0,1000}\s\/user\:.{0,1000}\s\/oldpwd\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","47"
"* /changentlm* /user:* /oldpwd:*",".{0,1000}\s\/changentlm.{0,1000}\s\/user\:.{0,1000}\s\/oldpwd\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","48"
"* /createnetonly:*cmd.exe*",".{0,1000}\s\/createnetonly\:.{0,1000}cmd\.exe.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57"
"* /createnetonly:*cmd.exe*",".{0,1000}\s\/createnetonly\:.{0,1000}cmd\.exe.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","58"
"* /credpassword*",".{0,1000}\s\/credpassword.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","59"
"* /creduser:* /credpassword:*",".{0,1000}\s\/creduser\:.{0,1000}\s\/credpassword\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","60"
"* /decodemk /binary:* /password:*",".{0,1000}\s\/decodemk\s\/binary\:.{0,1000}\s\/password\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","61"
"* /domain:* /dc:* /getcredentials /nowrap*",".{0,1000}\s\/domain\:.{0,1000}\s\/dc\:.{0,1000}\s\/getcredentials\s\/nowrap.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","62"
"* /dumpsecret /input:* /system*",".{0,1000}\s\/dumpsecret\s\/input\:.{0,1000}\s\/system.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","63"
"* /dumpsecret /input:defaultpassword*",".{0,1000}\s\/dumpsecret\s\/input\:defaultpassword.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","64"
"* /dumpsecret /input:dpapi_system /offline*",".{0,1000}\s\/dumpsecret\s\/input\:dpapi_system\s\/offline.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","65"
"* /gethmac /mode:hashid /input:* /key:*",".{0,1000}\s\/gethmac\s\/mode\:hashid\s\/input\:.{0,1000}\s\/key\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","69"
"* /GetKeys WirelessKeyView*",".{0,1000}\s\/GetKeys\sWirelessKeyView.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","0","N/A","N/A","7","10","N/A","N/A","N/A","N/A","70"
"* /getlsasecret /input:*",".{0,1000}\s\/getlsasecret\s\/input\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","71"
"* /getntlmhash /password:*",".{0,1000}\s\/getntlmhash\s\/password\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","72"
"* /getntlmhash | wtee *.ntlm*",".{0,1000}\s\/getntlmhash\s\|\swtee\s.{0,1000}\.ntlm.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","73"
"* /getsamkey /offline*",".{0,1000}\s\/getsamkey\s\/offline.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","74"
"* /impersonateuser:* /msdsspn:* /ptt*",".{0,1000}\s\/impersonateuser\:.{0,1000}\s\/msdsspn\:.{0,1000}\s\/ptt.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","75"
"* /ldap * /printcmd*",".{0,1000}\s\/ldap\s.{0,1000}\s\/printcmd.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","76"
"* /ldapfilter:'admincount=1'*",".{0,1000}\s\/ldapfilter\:\'admincount\=1\'.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","77"
"* /nofullpacsig *",".{0,1000}\s\/nofullpacsig\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","83"
"* /outfile:* /spn:*",".{0,1000}\s\/outfile\:.{0,1000}\s\/spn\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","84"
"* /outfile:* /spns:*",".{0,1000}\s\/outfile\:.{0,1000}\s\/spns\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","85"
"* /ptt /binary:*.kirbi*",".{0,1000}\s\/ptt\s\/binary\:.{0,1000}\.kirbi.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","89"
"* /pwdsetafter:*",".{0,1000}\s\/pwdsetafter\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","90"
"* /pwdsetbefore:*",".{0,1000}\s\/pwdsetbefore\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","91"
"* /rc4opsec *",".{0,1000}\s\/rc4opsec\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","94"
"* /s4uproxytarget*",".{0,1000}\s\/s4uproxytarget.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","96"
"* /s4utransitedservices*",".{0,1000}\s\/s4utransitedservices.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","98"
"* /service:krbtgt *",".{0,1000}\s\/service\:krbtgt\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","99"
"* /setntlm * /user:* /newhash:*",".{0,1000}\s\/setntlm\s.{0,1000}\s\/user\:.{0,1000}\s\/newhash\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","100"
"* /setntlm * /user:* /newpwd:*",".{0,1000}\s\/setntlm\s.{0,1000}\s\/user\:.{0,1000}\s\/newpwd\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","101"
"* /simple * /spn*",".{0,1000}\s\/simple\s.{0,1000}\s\/spn.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","102"
"* /ticket *.kirbi*",".{0,1000}\s\/ticket\s.{0,1000}\.kirbi.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","104"
"* /ticket:* /autoenterprise *",".{0,1000}\s\/ticket\:.{0,1000}\s\/autoenterprise\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","105"
"* /ticket:*.kirbi*",".{0,1000}\s\/ticket\:.{0,1000}\.kirbi.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","107"
"* /usetgtdeleg *",".{0,1000}\s\/usetgtdeleg\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","113"
"* | NTLMParse*",".{0,1000}\s\|\sNTLMParse.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","0","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","136"
"* > Wi-Fi-PASS*",".{0,1000}\s\>\sWi\-Fi\-PASS.{0,1000}","offensive_tool_keyword","wifigrabber","grab wifi password and exfiltrate to a given site","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","149"
"* 1$a$$.exe*",".{0,1000}\s1\$a\$\$\.exe.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","153"
"* 29ABE9Hy.log*",".{0,1000}\s29ABE9Hy\.log.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","0","N/A","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","159"
"* --action SPRAY_USERS *",".{0,1000}\s\-\-action\sSPRAY_USERS\s.{0,1000}","offensive_tool_keyword","SharpHose","Asynchronous Password Spraying Tool in C# for Windows Environments","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/ustayready/SharpHose","1","0","N/A","N/A","10","4","312","62","2023-12-19T21:06:47Z","2020-05-01T22:10:49Z","186"
"* adcsync.py*",".{0,1000}\sadcsync\.py.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","0","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","207"
"* add /target:* /altsecid:X509:*",".{0,1000}\sadd\s\/target\:.{0,1000}\s\/altsecid\:X509\:.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","209"
"* adfsbrute.py*",".{0,1000}\sadfsbrute\.py.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","0","N/A","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","225"
"* --adfs-host * --krb-key * --krb-ticket *",".{0,1000}\s\-\-adfs\-host\s.{0,1000}\s\-\-krb\-key\s.{0,1000}\s\-\-krb\-ticket\s.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","0","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","226"
"* adfs-spray.py*",".{0,1000}\sadfs\-spray\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","228"
"* ADPassHunt.GetGPPPassword*",".{0,1000}\sADPassHunt\.GetGPPPassword.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","234"
"* Any passwords that were successfully sprayed have been output to*",".{0,1000}\sAny\spasswords\sthat\swere\ssuccessfully\ssprayed\shave\sbeen\soutput\sto.{0,1000}","offensive_tool_keyword","Invoke-Pre2kSpray","Enumerate domain machine accounts and perform pre2k password spraying.","T1087.002 - T1110.003","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/eversinc33/Invoke-Pre2kSpray","1","0","#content","N/A","8","1","69","11","2023-07-14T06:50:22Z","2023-07-05T10:07:38Z","268"
"* App-Bound Encryption Decryption process*",".{0,1000}\sApp\-Bound\sEncryption\sDecryption\sprocess.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","#content","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","271"
"* Ask4Creds.ps1*",".{0,1000}\sAsk4Creds\.ps1.{0,1000}","offensive_tool_keyword","Ask4Creds","Prompt User for credentials","T1056 - T1071","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Leo4j/Ask4Creds","1","0","N/A","N/A","8","1","1","0","2024-03-20T17:09:21Z","2023-11-12T15:21:40Z","280"
"* asktgs * /ticket:*",".{0,1000}\sasktgs\s.{0,1000}\s\/ticket\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","281"
"* asktgs *.kirbi*",".{0,1000}\sasktgs\s.{0,1000}\.kirbi.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","282"
"* asktgs /ticket:*",".{0,1000}\sasktgs\s\/ticket\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","283"
"* asktgt * /service:*",".{0,1000}\sasktgt\s.{0,1000}\s\/service\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","284"
"* asktgt /user *",".{0,1000}\sasktgt\s\/user\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","285"
"* asktht /user:*",".{0,1000}\sasktht\s\/user\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","288"
"* asreproast *",".{0,1000}\sasreproast\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","292"
"* atomizer.py *",".{0,1000}\satomizer\.py\s.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","9","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","306"
"* autoNTDS.py*",".{0,1000}\sautoNTDS\.py.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","0","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","342"
"* BabelStrike.py*",".{0,1000}\sBabelStrike\.py.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","0","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","351"
"* backupcreds.exe*",".{0,1000}\sbackupcreds\.exe.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","364"
"* backupkey* /server:* /file*.pvk*",".{0,1000}\sbackupkey.{0,1000}\s\/server\:.{0,1000}\s\/file.{0,1000}\.pvk.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","365"
"* --bf-hashes-file *",".{0,1000}\s\-\-bf\-hashes\-file\s.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","386"
"* --bf-passwords-file *",".{0,1000}\s\-\-bf\-passwords\-file\s.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","387"
"* BlankOBF.py*",".{0,1000}\sBlankOBF\.py.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","403"
"* bleeding-jumbo john*",".{0,1000}\sbleeding\-jumbo\sjohn.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","405"
"* blob /target:*.bin* /pvk:*",".{0,1000}\sblob\s\/target\:.{0,1000}\.bin.{0,1000}\s\/pvk\:.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","407"
"* blob /target:*.bin* /unprotect*",".{0,1000}\sblob\s\/target\:.{0,1000}\.bin.{0,1000}\s\/unprotect.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","408"
"* --bloodhound --import-data *",".{0,1000}\s\-\-bloodhound\s\-\-import\-data\s.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","411"
"* --bloodhound --mark-owned *",".{0,1000}\s\-\-bloodhound\s\-\-mark\-owned\s.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","412"
"* --bloodhound --sync *",".{0,1000}\s\-\-bloodhound\s\-\-sync\s.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","414"
"* bloodhoundsync.py*",".{0,1000}\sbloodhoundsync\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","416"
"* brute * /password*",".{0,1000}\sbrute\s.{0,1000}\s\/password.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","464"
"* --bruteforce *.kdbx*",".{0,1000}\s\-\-bruteforce\s.{0,1000}\.kdbx.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","465"
"* bruteuser *",".{0,1000}\sbruteuser\s.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","472"
"* bruteuser -d *",".{0,1000}\sbruteuser\s\-d\s.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","473"
"* by @citronneur (v*",".{0,1000}\sby\s\@citronneur\s\(v.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","479"
"* by erwan2212@gmail.com*",".{0,1000}\sby\serwan2212\@gmail\.com.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","482"
"* BypassCredGuard.exe*",".{0,1000}\sBypassCredGuard\.exe.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","485"
"* -c ""!mimikatz"" *",".{0,1000}\s\-c\s\""!mimikatz\""\s.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","490"
"* cachedump.py*",".{0,1000}\scachedump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","533"
"* --ccache-ticket *",".{0,1000}\s\-\-ccache\-ticket\s.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","551"
"* changepw * /ticket:*",".{0,1000}\schangepw\s.{0,1000}\s\/ticket\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","557"
"* chrome_decrypt.cpp *",".{0,1000}\schrome_decrypt\.cpp\s.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","573"
"* chrome_decrypt.cpp*",".{0,1000}\schrome_decrypt\.cpp.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","574"
"* chrome_decrypt.exe*",".{0,1000}\schrome_decrypt\.exe.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","575"
"* chromium_based_browsers.py*",".{0,1000}\schromium_based_browsers\.py.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","579"
"* cmedb",".{0,1000}\scmedb","offensive_tool_keyword","crackmapexec","windows default compiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","617"
"* comsvcs_stealth.py*",".{0,1000}\scomsvcs_stealth\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","667"
"* --config *.json --debug --exfil --onedrive*",".{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-debug\s\-\-exfil\s\-\-onedrive.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","670"
"* --config *.json --enum --validate-msol --usernames *",".{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-enum\s\-\-validate\-msol\s\-\-usernames\s.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","671"
"* --config *.json --enum --validate-teams*",".{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-enum\s\-\-validate\-teams.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","672"
"* --config *.json --exfil --aad*",".{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-exfil\s\-\-aad.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","673"
"* --crack * --ntds*",".{0,1000}\s\-\-crack\s.{0,1000}\s\-\-ntds.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","0","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","706"
"* --crack-status*",".{0,1000}\s\-\-crack\-status.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","711"
"* credentials /pvk:*",".{0,1000}\scredentials\s\/pvk\:.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","733"
"* credmaster.py*",".{0,1000}\scredmaster\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","734"
"* credmaster-success.txt*",".{0,1000}\scredmaster\-success\.txt.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","735"
"* credmaster-validusers.txt*",".{0,1000}\scredmaster\-validusers\.txt.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","736"
"* cstealer.py*",".{0,1000}\scstealer\.py.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","747"
"* --custom_user_agent*",".{0,1000}\s\-\-custom_user_agent.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","0","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","753"
"* darkcodersc *",".{0,1000}\sdarkcodersc\s.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","0","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","778"
"* --dc-ip * -request * -format hashcat*",".{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-request\s.{0,1000}\s\-format\shashcat.{0,1000}","offensive_tool_keyword","hashcat","Worlds fastest and most advanced password recovery utility.","T1110.001 - T1003.001 - T1021.001","TA0006 - TA0009 - TA0010","N/A","Black Basta","Credential Access","https://github.com/hashcat/hashcat","1","0","#linux","N/A","10","10","22481","3046","2024-08-16T23:50:35Z","2015-12-04T14:46:51Z","791"
"* --debug --exfil --onedrive*",".{0,1000}\s\-\-debug\s\-\-exfil\s\-\-onedrive.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","805"
"* Decrypt-RDCMan.ps1*",".{0,1000}\sDecrypt\-RDCMan\.ps1.{0,1000}","offensive_tool_keyword","Decrypt-RDCMan","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1","1","0","N/A","N/A","9","1","1","1","2016-12-01T14:06:24Z","2017-11-22T23:18:39Z","807"
"* default_logins.txt*",".{0,1000}\sdefault_logins\.txt.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","809"
"* DEL {}SQLDmpr*.mdmp & for /f *",".{0,1000}\sDEL\s\{\}SQLDmpr.{0,1000}\.mdmp\s\&\sfor\s\/f\s.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","813"
"* dementor.py*",".{0,1000}\sdementor\.py.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","820"
"* diamond * /certificate:*",".{0,1000}\sdiamond\s.{0,1000}\s\s\/certificate\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","834"
"* diamond /tgtdeleg *",".{0,1000}\sdiamond\s\/tgtdeleg\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","835"
"* diamond /user:*",".{0,1000}\sdiamond\s\/user\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","836"
"* Disable_defender.py*",".{0,1000}\sDisable_defender\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","853"
"* dllinject.py*",".{0,1000}\sdllinject\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","870"
"* domcachedump.py*",".{0,1000}\sdomcachedump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","915"
"* -Downgrade False -Restore False -Impersonate True * -challange *",".{0,1000}\s\-Downgrade\sFalse\s\-Restore\sFalse\s\-Impersonate\sTrue\s.{0,1000}\s\-challange\s.{0,1000}","offensive_tool_keyword","Internal-Monologue","Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS","T1003 - T1051 - T1574 - T1110 - T1547","TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/eladshamir/Internal-Monologue","1","0","N/A","N/A","N/A","10","1512","240","2018-10-11T12:13:08Z","2017-12-09T05:59:01Z","940"
"* dpapi blob *.json *.dat*",".{0,1000}\sdpapi\sblob\s.{0,1000}\.json\s.{0,1000}\.dat.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","948"
"* dpapi credential *.json cred*",".{0,1000}\sdpapi\scredential\s.{0,1000}\.json\scred.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","949"
"* dpapi masterkey /root/*",".{0,1000}\sdpapi\smasterkey\s\/root\/.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","950"
"* dpapi minidump *.dmp*",".{0,1000}\sdpapi\sminidump\s.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","951"
"* dpapi prekey nt *S-1-5-21*",".{0,1000}\sdpapi\sprekey\snt\s.{0,1000}S\-1\-5\-21.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","952"
"* dpapi prekey password *",".{0,1000}\sdpapi\sprekey\spassword\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","953"
"* dpapi prekey registry *.reg*",".{0,1000}\sdpapi\sprekey\sregistry\s.{0,1000}\.reg.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","954"
"* dpapi securestring *.dat*",".{0,1000}\sdpapi\ssecurestring\s.{0,1000}\.dat.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","955"
"* dragoncastle.py*",".{0,1000}\sdragoncastle\.py.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","961"
"* dump * /service:*",".{0,1000}\sdump\s.{0,1000}\s\/service\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","969"
"* dump --usermode --kernelmode --driver *",".{0,1000}\sdump\s\-\-usermode\s\-\-kernelmode\s\-\-driver\s.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","971"
"* --dump_file Keepass.exe.dmp*",".{0,1000}\s\-\-dump_file\sKeepass\.exe\.dmp.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","973"
"* --dump_lsa*",".{0,1000}\s\-\-dump_lsa.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","974"
"* --dump_usedhashes*",".{0,1000}\s\-\-dump_usedhashes.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","976"
"* --dump_wireless*",".{0,1000}\s\-\-dump_wireless.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","977"
"* --dump-bitlocker *",".{0,1000}\s\-\-dump\-bitlocker\s.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","979"
"* --dump-bitlocker*",".{0,1000}\s\-\-dump\-bitlocker.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","980"
"* -DumpCred -ComputerName @*",".{0,1000}\s\-DumpCred\s\-ComputerName\s\@.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","0","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","982"
"* -DumpCreds -ComputerName @*",".{0,1000}\s\-DumpCreds\s\-ComputerName\s\@.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","0","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","985"
"* dumpert.py*",".{0,1000}\sdumpert\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","989"
"* --dump-hash-domain --with-history*",".{0,1000}\s\-\-dump\-hash\-domain\s\-\-with\-history.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","992"
"* --dump-hash-domain*",".{0,1000}\s\-\-dump\-hash\-domain.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","993"
"* --dump-hash-domain-cached*",".{0,1000}\s\-\-dump\-hash\-domain\-cached.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","994"
"* --dump-hash-domain-cached*",".{0,1000}\s\-\-dump\-hash\-domain\-cached.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","995"
"* --dump-hash-local*",".{0,1000}\s\-\-dump\-hash\-local.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","996"
"* dump-lsass.py*",".{0,1000}\sdump\-lsass\.py.{0,1000}","offensive_tool_keyword","impacket","Dump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems.","T1021 - T1047 - T1055.011 - T1003","TA0002 - TA0005 - TA0006","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Credential Access","https://github.com/kaluche/Dump-Lsass","1","0","N/A","N/A","10","1","1","0","2019-11-14T18:15:26Z","2019-11-20T20:26:27Z","999"
"* --dumpmode network --network raw --ip * --port *",".{0,1000}\s\-\-dumpmode\snetwork\s\-\-network\sraw\s\-\-ip\s.{0,1000}\s\-\-port\s.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","1000"
"* --dumpmode network --network smb *",".{0,1000}\s\-\-dumpmode\snetwork\s\-\-network\ssmb\s.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","1001"
"* --dump-name *lsass*",".{0,1000}\s\-\-dump\-name\s.{0,1000}lsass.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","1002"
"* --dumpname lsass.dmp*",".{0,1000}\s\-\-dumpname\slsass\.dmp.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","1003"
"* DumpS1.ps1*",".{0,1000}\sDumpS1\.ps1.{0,1000}","greyware_tool_keyword","SentinelAgent","dump a process with SentinelAgent.exe","T1003 - T1055","TA0006 - TA0005","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e","1","0","N/A","N/A","8","7","N/A","N/A","N/A","N/A","1004"
"* DumpSvc.exe*",".{0,1000}\sDumpSvc\.exe.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","1005"
"* EASSniper.ps1*",".{0,1000}\sEASSniper\.ps1.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","1014"
"* EASSniper.ps1*",".{0,1000}\sEASSniper\.ps1.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","1015"
"* eas-valid-users.txt*",".{0,1000}\seas\-valid\-users\.txt.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","1016"
"* empire_exec*",".{0,1000}\sempire_exec.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1036"
"* empireadmin*",".{0,1000}\sempireadmin.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1037"
"* --enum --validate-msol *",".{0,1000}\s\-\-enum\s\-\-validate\-msol\s.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","1056"
"* --enum --validate-teams*",".{0,1000}\s\-\-enum\s\-\-validate\-teams.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","1057"
"* enum_avproducts*",".{0,1000}\senum_avproducts.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1058"
"* enum_chrome*",".{0,1000}\senum_chrome.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1059"
"* enum_dns*",".{0,1000}\senum_dns.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1060"
"* EtwHash*",".{0,1000}\sEtwHash.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","0","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","1075"
"* EvilTwinServer *",".{0,1000}\sEvilTwinServer\s.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","1094"
"* -ExchHostname * -Password *",".{0,1000}\s\-ExchHostname\s.{0,1000}\s\-Password\s.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","N/A","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","0","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","1095"
"* --exfil --cookie-dump * --all*",".{0,1000}\s\-\-exfil\s\-\-cookie\-dump\s\s.{0,1000}\s\-\-all.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","1122"
"* --exfil --cookie-dump *",".{0,1000}\s\-\-exfil\s\-\-cookie\-dump\s.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","1123"
"* --exfil --teams --owa --owa-limit*",".{0,1000}\s\-\-exfil\s\-\-teams\s\-\-owa\s\-\-owa\-limit.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","1124"
"* --exfil --teams --owa*",".{0,1000}\s\-\-exfil\s\-\-teams\s\-\-owa.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","1125"
"* --exfil --tokens * --onedrive --owa*",".{0,1000}\s\-\-exfil\s\-\-tokens\s.{0,1000}\s\-\-onedrive\s\-\-owa.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","1126"
"* --exfil --tokens * --onedrive*",".{0,1000}\s\-\-exfil\s\-\-tokens\s.{0,1000}\s\-\-onedrive.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","1127"
"* extract --secrets --zsh*",".{0,1000}\sextract\s\-\-secrets\s\-\-zsh.{0,1000}","offensive_tool_keyword","PassDetective","PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets","T1059 - T1059.004 - T1552 - T1552.001","TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/aydinnyunus/PassDetective","1","0","N/A","N/A","7","2","129","8","2024-06-19T10:39:39Z","2023-07-22T12:31:57Z","1141"
"* -f nessus.nessus *",".{0,1000}\s\-f\snessus\.nessus\s.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","1172"
"* --force-ps32",".{0,1000}\s\-\-force\-ps32","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1211"
"* Forensike.ps1*",".{0,1000}\sForensike\.ps1.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","1215"
"* --fork --write *.dmp*",".{0,1000}\s\-\-fork\s\-\-write\s.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","1217"
"* --format=netntlmv2 *.txt*",".{0,1000}\s\-\-format\=netntlmv2\s.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1228"
"* --format=NT -w=*_password.txt*",".{0,1000}\s\-\-format\=NT\s\-w\=.{0,1000}_password\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper is a fast password cracker.","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/magnumripper/JohnTheRipper","1","0","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1229"
"* -fullmemdmp -snap & ping 127.0.0.1 -n *",".{0,1000}\s\-fullmemdmp\s\-snap\s\&\sping\s127\.0\.0\.1\s\-n\s.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","1258"
"* generate audit -ep *--passwords_in_userfile*",".{0,1000}\sgenerate\saudit\s\-ep\s.{0,1000}\-\-passwords_in_userfile.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","0","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","1291"
"* generate normal -ep * -d * -u * -pf *",".{0,1000}\sgenerate\snormal\s\-ep\s.{0,1000}\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-pf\s.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","0","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","1292"
"* generate normal -ep ex-plan.s365 *",".{0,1000}\sgenerate\snormal\s\-ep\sex\-plan\.s365\s.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","0","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","1293"
"* --gen-relay-list *",".{0,1000}\s\-\-gen\-relay\-list\s.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1300"
"* get_keystrokes*",".{0,1000}\sget_keystrokes.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1308"
"* get_netdomaincontroller*",".{0,1000}\sget_netdomaincontroller.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1309"
"* get_netrdpsession*",".{0,1000}\sget_netrdpsession.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1310"
"* get_timedscreenshot*",".{0,1000}\sget_timedscreenshot.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1312"
"* Get-NetNTLM.ps1*",".{0,1000}\sGet\-NetNTLM\.ps1.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","0","N/A","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","1323"
"* Get-SpoolStatus.ps1*",".{0,1000}\sGet\-SpoolStatus\.ps1.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","1332"
"* github repos list --org*",".{0,1000}\sgithub\srepos\slist\s\-\-org.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","0","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","1342"
"* github repos list --user *",".{0,1000}\sgithub\srepos\slist\s\-\-user\s.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","0","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","1343"
"* golden * /badpwdcount*",".{0,1000}\sgolden\s.{0,1000}\s\/badpwdcount.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","1351"
"* golden * /ldap *",".{0,1000}\sgolden\s.{0,1000}\s\/ldap\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","1352"
"* golden * /user:*",".{0,1000}\sgolden\s.{0,1000}\s\/user\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","1353"
"* gosecretsdump_linux*",".{0,1000}\sgosecretsdump_linux.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#linux","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","1360"
"* gosecretsdump_mac*",".{0,1000}\sgosecretsdump_mac.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","1361"
"* gosecretsdump_win*",".{0,1000}\sgosecretsdump_win.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","1362"
"* gpp_autologin*",".{0,1000}\sgpp_autologin.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1375"
"* gpp_password*",".{0,1000}\sgpp_password.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1376"
"* hack.py*",".{0,1000}\shack\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1399"
"* harvest * /monitorinterval:*",".{0,1000}\sharvest\s.{0,1000}\s\/monitorinterval\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","1410"
"* hashview.py*",".{0,1000}\shashview\.py.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","0","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","1415"
"* hashview-agent *",".{0,1000}\shashview\-agent\s.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","0","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","1416"
"* httprelayserver.py*",".{0,1000}\shttprelayserver\.py.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","0","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","1528"
"* icebreaker.py*",".{0,1000}\sicebreaker\.py.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","1607"
"* -Identity * -Set @{serviceprincipalname='*'}*",".{0,1000}\s\-Identity\s.{0,1000}\s\-Set\s\@\{serviceprincipalname\=\'.{0,1000}\'\}.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Targeted kerberoasting by setting SPN","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","1613"
"* -Identity * -XOR @{useraccountcontrol=4194304*",".{0,1000}\s\-Identity\s.{0,1000}\s\-XOR\s\@\{useraccountcontrol\=4194304.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Targeted kerberoasting we need ACL write permissions to set UserAccountControl flags for the target user. Using PowerView","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","1614"
"* impacketfile.py*",".{0,1000}\simpacketfile\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","1634"
"* -inc -u=0 *.pwd*",".{0,1000}\s\-inc\s\-u\=0\s.{0,1000}\.pwd.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1650"
"* -inc=digits *",".{0,1000}\s\-inc\=digits\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1651"
"* -InFile Wi-Fi-PASS*",".{0,1000}\s\-InFile\sWi\-Fi\-PASS.{0,1000}","offensive_tool_keyword","wifigrabber","grab wifi password and exfiltrate to a given site","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","1657"
"* instabf.py*",".{0,1000}\sinstabf\.py.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","0","N/A","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","1670"
"* instainsane.sh*",".{0,1000}\sinstainsane\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/umeshshinde19/instainsane","1","0","N/A","N/A","7","7","655","371","2024-02-11T10:29:05Z","2018-12-02T22:48:11Z","1671"
"* install chntpw*",".{0,1000}\sinstall\schntpw.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","1682"
"* install creddump7*",".{0,1000}\sinstall\screddump7.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","1684"
"* install hekatomb*",".{0,1000}\sinstall\shekatomb.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","0","N/A","N/A","10","6","N/A","N/A","N/A","N/A","1690"
"* install requests_ntlm*",".{0,1000}\sinstall\srequests_ntlm.{0,1000}","greyware_tool_keyword","requests-ntlm","HTTP NTLM Authentication for Requests Library","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://pypi.org/project/requests-ntlm/","1","0","N/A","N/A","8","9","N/A","N/A","N/A","N/A","1699"
"* install samdump2*",".{0,1000}\sinstall\ssamdump2.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","1700"
"* install spraycharles*",".{0,1000}\sinstall\sspraycharles.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","1703"
"* install wordlists*",".{0,1000}\sinstall\swordlists.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","1714"
"* install-sb.sh*",".{0,1000}\sinstall\-sb\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","0","N/A","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","1717"
"* insTof.py*",".{0,1000}\sinsTof\.py.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","0","N/A","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","1718"
"* invoke_sessiongopher*",".{0,1000}\sinvoke_sessiongopher.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1735"
"* invoke_vnc*",".{0,1000}\sinvoke_vnc.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1736"
"* john_done*",".{0,1000}\sjohn_done.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1806"
"* john_fork*",".{0,1000}\sjohn_fork.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1807"
"* john_load*",".{0,1000}\sjohn_load.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1808"
"* john_load_conf*",".{0,1000}\sjohn_load_conf.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1809"
"* john_load_conf_db*",".{0,1000}\sjohn_load_conf_db.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1810"
"* john_log_format*",".{0,1000}\sjohn_log_format.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1811"
"* john_log_format2*",".{0,1000}\sjohn_log_format2.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1812"
"* john_mpi_wait*",".{0,1000}\sjohn_mpi_wait.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1813"
"* john_omp_fallback*",".{0,1000}\sjohn_omp_fallback.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1814"
"* john_omp_init*",".{0,1000}\sjohn_omp_init.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1815"
"* john_omp_maybe_adjust_or_fallback*",".{0,1000}\sjohn_omp_maybe_adjust_or_fallback.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1816"
"* john_omp_show_info*",".{0,1000}\sjohn_omp_show_info.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1817"
"* john_register_all*",".{0,1000}\sjohn_register_all.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1818"
"* john_register_one*",".{0,1000}\sjohn_register_one.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1819"
"* john_run*",".{0,1000}\sjohn_run.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1820"
"* john_set_mpi*",".{0,1000}\sjohn_set_mpi.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1821"
"* john_set_tristates*",".{0,1000}\sjohn_set_tristates.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1822"
"* john_wait*",".{0,1000}\sjohn_wait.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1824"
"* JohnTheRipper/*",".{0,1000}\sJohnTheRipper\/.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1825"
"* -just-dc-ntlm *",".{0,1000}\s\-just\-dc\-ntlm\s.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","1833"
"* -just-dc-user *",".{0,1000}\s\-just\-dc\-user\s.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","1836"
"* keepass /unprotect*",".{0,1000}\skeepass\s\/unprotect.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","1848"
"* KeePwn.py*",".{0,1000}\sKeePwn\.py.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","1851"
"* KeeTheft.exe*",".{0,1000}\sKeeTheft\.exe.{0,1000}","offensive_tool_keyword","KeeThiefSyscalls","Patch GhostPack/KeeThief for it to use DInvoke and syscalls","T1003.001 - T1558.002","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/Metro-Holografix/KeeThiefSyscalls","1","0","N/A","private github repo","10","1","N/A","N/A","N/A","N/A","1852"
"* KeeThief.ps1*",".{0,1000}\sKeeThief\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","1853"
"* kerberoast *",".{0,1000}\skerberoast\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","1855"
"* kerberoast *",".{0,1000}\skerberoast\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","1856"
"* kerberos asreproast *",".{0,1000}\skerberos\sasreproast\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1863"
"* kerberos brute * -d *",".{0,1000}\skerberos\sbrute\s.{0,1000}\s\-d\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1864"
"* kerberos brute *.txt*",".{0,1000}\skerberos\sbrute\s.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1865"
"* kerberos ccache del *.ccache*",".{0,1000}\skerberos\sccache\sdel\s.{0,1000}\.ccache.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1866"
"* kerberos ccache exportkirbi *",".{0,1000}\skerberos\sccache\sexportkirbi\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1867"
"* kerberos ccache list *.ccache*",".{0,1000}\skerberos\sccache\slist\s.{0,1000}\.ccache.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1868"
"* kerberos ccache loadkirbi *",".{0,1000}\skerberos\sccache\sloadkirbi\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1869"
"* kerberos ccache roast *",".{0,1000}\skerberos\sccache\sroast\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1870"
"* kerberos keytab *.keytab*",".{0,1000}\skerberos\skeytab\s.{0,1000}\.keytab.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1871"
"* kerberos kirbi parse *",".{0,1000}\skerberos\skirbi\sparse\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1872"
"* kerberos spnroast *",".{0,1000}\skerberos\sspnroast\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1873"
"* kerberos.py*",".{0,1000}\skerberos\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","1875"
"* kerbrute.py*",".{0,1000}\skerbrute\.py.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","1876"
"* --key PPLBlade*",".{0,1000}\s\-\-key\sPPLBlade.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","1878"
"* KeyCredentialLink.ps1*",".{0,1000}\sKeyCredentialLink\.ps1.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","1879"
"* klist * /service:*",".{0,1000}\sklist\s.{0,1000}\s\/service\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","1892"
"* knowsmore.cmd.wordlist*",".{0,1000}\sknowsmore\.cmd\.wordlist.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1893"
"* knowsmore.cmdbase*",".{0,1000}\sknowsmore\.cmdbase.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1894"
"* knowsmore.config*",".{0,1000}\sknowsmore\.config.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1895"
"* knowsmore.knowsmore*",".{0,1000}\sknowsmore\.knowsmore.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1896"
"* knowsmore.libs.bloodhoundsync*",".{0,1000}\sknowsmore\.libs\.bloodhoundsync.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1897"
"* knowsmore.libs.exporterbase*",".{0,1000}\sknowsmore\.libs\.exporterbase.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1898"
"* knowsmore.libs.ntdsuseraccount*",".{0,1000}\sknowsmore\.libs\.ntdsuseraccount.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1899"
"* knowsmore.module*",".{0,1000}\sknowsmore\.module.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1900"
"* knowsmore.password*",".{0,1000}\sknowsmore\.password.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1901"
"* knowsmore.py*",".{0,1000}\sknowsmore\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1902"
"* knowsmore.util.color*",".{0,1000}\sknowsmore\.util\.color.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1903"
"* knowsmore.util.database*",".{0,1000}\sknowsmore\.util\.database.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1904"
"* knowsmore.util.knowsmoredb*",".{0,1000}\sknowsmore\.util\.knowsmoredb.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1905"
"* knowsmore.util.logger*",".{0,1000}\sknowsmore\.util\.logger.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1906"
"* knowsmore.util.process*",".{0,1000}\sknowsmore\.util\.process.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1907"
"* knowsmore.util.tools*",".{0,1000}\sknowsmore\.util\.tools.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","1908"
"* l$a$$Pid *",".{0,1000}\sl\$a\$\$Pid\s.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","1919"
"* laps.py *--ldapserver*",".{0,1000}\slaps\.py\s.{0,1000}\-\-ldapserver.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","0","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","1924"
"* laps.py *-u * -p *",".{0,1000}\slaps\.py\s.{0,1000}\-u\s.{0,1000}\s\-p\s.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","0","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","1925"
"* laZagne.py*",".{0,1000}\slaZagne\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","1930"
"* --list=hidden-options*",".{0,1000}\s\-\-list\=hidden\-options.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1959"
"* live dpapi blobfile *.blob*",".{0,1000}\slive\sdpapi\sblobfile\s.{0,1000}\.blob.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1964"
"* live dpapi cred *",".{0,1000}\slive\sdpapi\scred\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1965"
"* live dpapi keys -o *",".{0,1000}\slive\sdpapi\skeys\s\-o\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1966"
"* live dpapi securestring *",".{0,1000}\slive\sdpapi\ssecurestring\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1967"
"* live dpapi vcred *",".{0,1000}\slive\sdpapi\svcred\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1968"
"* live dpapi vpol *",".{0,1000}\slive\sdpapi\svpol\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1969"
"* live dpapi wifi*",".{0,1000}\slive\sdpapi\swifi.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1970"
"* live kerberos apreq *",".{0,1000}\slive\skerberos\sapreq\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1971"
"* live kerberos dump*",".{0,1000}\slive\skerberos\sdump.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1972"
"* live kerberos purge*",".{0,1000}\slive\skerberos\spurge.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1973"
"* live kerberos roast*",".{0,1000}\slive\skerberos\sroast.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1974"
"* live kerberos sessions*",".{0,1000}\slive\skerberos\ssessions.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1975"
"* live kerberos tgt*",".{0,1000}\slive\skerberos\stgt.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1976"
"* live kerberos triage*",".{0,1000}\slive\skerberos\striage.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1977"
"* live lsa -o *",".{0,1000}\slive\slsa\s\-o\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1978"
"* live lsa -o *",".{0,1000}\slive\slsa\s\-o\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1979"
"* live process create -c regedit*",".{0,1000}\slive\sprocess\screate\s\-c\sregedit.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1980"
"* live smb client *",".{0,1000}\slive\ssmb\sclient\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1981"
"* live smb dcsync *",".{0,1000}\slive\ssmb\sdcsync\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1982"
"* live smb lsassdump *",".{0,1000}\slive\ssmb\slsassdump\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1983"
"* live smb regdump *",".{0,1000}\slive\ssmb\sregdump\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1984"
"* live smb secretsdump *",".{0,1000}\slive\ssmb\ssecretsdump\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1985"
"* live smbapi localgroup enum -t*",".{0,1000}\slive\ssmbapi\slocalgroup\senum\s\-t.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1986"
"* live smbapi session enum *",".{0,1000}\slive\ssmbapi\ssession\senum\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1987"
"* live smbapi share enum*",".{0,1000}\slive\ssmbapi\sshare\senum.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1988"
"* live users whoami*",".{0,1000}\slive\susers\swhoami.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","1989"
"* lnkbomb.py*",".{0,1000}\slnkbomb\.py.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","0","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","1996"
"* load_extra_pots*",".{0,1000}\sload_extra_pots.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","1998"
"* --load-dll *ssp.dll*",".{0,1000}\s\-\-load\-dll\s.{0,1000}ssp\.dll.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","2000"
"* Local:DPAPIDecrypt*",".{0,1000}\sLocal\:DPAPIDecrypt.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","2010"
"* Local:LoadEncryptionDll*",".{0,1000}\sLocal\:LoadEncryptionDll.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","2011"
"* --local-auth --shares*",".{0,1000}\s\-\-local\-auth\s\-\-shares.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2017"
"* --loggedon-users*",".{0,1000}\s\-\-loggedon\-users.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2035"
"* loginAAD.ps1*",".{0,1000}\sloginAAD\.ps1.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","2037"
"* lsa minidump * -o *",".{0,1000}\slsa\sminidump\s.{0,1000}\s\-o\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","2042"
"* lsa minidump *.dmp*",".{0,1000}\slsa\sminidump\s.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","2044"
"* lsa minidump /*",".{0,1000}\slsa\sminidump\s\/.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","2045"
"* lsadump.py*",".{0,1000}\slsadump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","2046"
"* lsasecrets.py*",".{0,1000}\slsasecrets\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","2047"
"* lsass.dmp*",".{0,1000}\slsass\.dmp.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Dump LSASS memory through a process snapshot (-r) avoiding interacting with it directly","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","2048"
"* Lsassx.ps1*",".{0,1000}\sLsassx\.ps1.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","2050"
"* Lsassx-OBF.ps1*",".{0,1000}\sLsassx\-OBF\.ps1.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","2051"
"* lsassy*",".{0,1000}\slsassy.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","2053"
"* Luna Grabber Builder*",".{0,1000}\sLuna\sGrabber\sBuilder.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","2056"
"* LyncSniper.ps1*",".{0,1000}\/LyncSniper\.ps1.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","2057"
"* -M multirdp*",".{0,1000}\s\-M\smultirdp.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2076"
"* -M pe_inject*",".{0,1000}\s\-M\spe_inject.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2079"
"* -m rdrleakdiag -M masterkeys*",".{0,1000}\s\-m\srdrleakdiag\s\-M\smasterkeys.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","2085"
"* -M scuffy*",".{0,1000}\s\-M\sscuffy.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2089"
"* -M shellcode_inject*",".{0,1000}\s\-M\sshellcode_inject.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2092"
"* -M slinky",".{0,1000}\s\-M\sslinky","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2094"
"* -M tokens*",".{0,1000}\s\-M\stokens.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2100"
"* -M uac",".{0,1000}\s\-M\suac","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2101"
"* -M web_delivery*",".{0,1000}\s\-M\sweb_delivery.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2105"
"* m365-fatigue.py *",".{0,1000}\sm365\-fatigue\.py\s.{0,1000}","offensive_tool_keyword","m365-fatigue","automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.","T1110.001 - T1078.001 - T1556.004","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/0xB455/m365-fatigue","1","0","N/A","N/A","10","1","77","7","2024-04-08T14:53:44Z","2023-11-30T13:33:03Z","2107"
"* -ma lssas.exe*",".{0,1000}\s\-ma\slssas\.exe.{0,1000}","greyware_tool_keyword","Procdump","dump lsass process with procdump","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","2109"
"* mask?a?a?a?a?*",".{0,1000}\smask\?a\?a\?a\?a\?.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","2118"
"* --mask=?1?1?1* --min-len*",".{0,1000}\s\-\-mask\=\?1\?1\?1.{0,1000}\s\-\-min\-len.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","2119"
"* memorydump.py*",".{0,1000}\smemorydump\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","2136"
"* met_inject*",".{0,1000}\smet_inject.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2142"
"* mimikittenz*",".{0,1000}\smimikittenz.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2159"
"* mimipenguin.sh*",".{0,1000}\smimipenguin\.sh.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","0","N/A","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","2160"
"* mimipy.py *",".{0,1000}\smimipy\.py\s.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","0","N/A","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","2161"
"* MirrorDump.exe*",".{0,1000}\sMirrorDump\.exe.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","2164"
"* --mobaxterm-poison-hkcr*",".{0,1000}\s\-\-mobaxterm\-poison\-hkcr.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","2169"
"* --mode decrypt --dumpname *.dmp --key *",".{0,1000}\s\-\-mode\sdecrypt\s\-\-dumpname\s.{0,1000}\.dmp\s\-\-key\s.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","2171"
"* --mode dump --name *.exe --handle procexp --obfuscate*",".{0,1000}\s\-\-mode\sdump\s\-\-name\s.{0,1000}\.exe\s\-\-handle\sprocexp\s\-\-obfuscate.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","2172"
"* --mode dump --name lsass.exe*",".{0,1000}\s\-\-mode\sdump\s\-\-name\slsass\.exe.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","2173"
"* --module o365_spray_activesync*",".{0,1000}\s\-\-module\so365_spray_activesync.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2178"
"* monitor /interval:* /filteruser:*",".{0,1000}\smonitor\s\/interval\:.{0,1000}\s\/filteruser\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","2182"
"* mssprinkler.ps1*",".{0,1000}\smssprinkler\.ps1.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","0","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","2203"
"* --mstsc-poison-hkcr*",".{0,1000}\s\-\-mstsc\-poison\-hkcr.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","2218"
"* MultiDump.exe*",".{0,1000}\sMultiDump\.exe.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","2220"
"* nanodump*",".{0,1000}\snanodump.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","2253"
"* nanodump/*",".{0,1000}\snanodump\/.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","2254"
"* NativeDump.exe*",".{0,1000}\sNativeDump\.exe.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","2255"
"* nc_srv.bat*",".{0,1000}\snc_srv\.bat.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","2268"
"* needs High Integrity Privileges to dump the relevant process!*",".{0,1000}\sneeds\sHigh\sIntegrity\sPrivileges\sto\sdump\sthe\srelevant\sprocess!.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","#content","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","2274"
"* --neo4j-host *",".{0,1000}\s\-\-neo4j\-host\s.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","2279"
"* --neo4j-host *--neo4j-port*",".{0,1000}\s\-\-neo4j\-host\s.{0,1000}\-\-neo4j\-port.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","0","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","2280"
"* -neo4j-password *",".{0,1000}\s\-neo4j\-password\s.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","2281"
"* --neo4j-port *",".{0,1000}\s\-\-neo4j\-port\s.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","2282"
"* --neo4j-user *",".{0,1000}\s\-\-neo4j\-user\s.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","2283"
"* netripper*",".{0,1000}\snetripper.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2299"
"* NiceRAT.py*",".{0,1000}\sNiceRAT\.py.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","2312"
"* --ntds * -crack *",".{0,1000}\s\-\-ntds\s.{0,1000}\s\-crack\s.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","0","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","2381"
"* -ntds NTDS.dit -filters*",".{0,1000}\s\-ntds\sNTDS\.dit\s\s\-filters.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","0","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","2383"
"* -ntds ntds.dit -system SYSTEM *",".{0,1000}\s\-ntds\sntds\.dit\s\-system\sSYSTEM\s.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","2384"
"* -ntds NTDS.dit -system SYSTEM -outputdir /*",".{0,1000}\s\-ntds\sNTDS\.dit\s\-system\sSYSTEM\s\-outputdir\s\/.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","0","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","2385"
"* --ntds-file *",".{0,1000}\s\-\-ntds\-file\s.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","2387"
"* --ntds-history*",".{0,1000}\s\-\-ntds\-history.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2388"
"* --ntds-pwdLastSet*",".{0,1000}\s\-\-ntds\-pwdLastSet.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2389"
"* ntdsuseraccount.py*",".{0,1000}\sntdsuseraccount\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","2390"
"* ntlm.wordlist *--hex-wordlist*",".{0,1000}\sntlm\.wordlist\s.{0,1000}\-\-hex\-wordlist.{0,1000}","offensive_tool_keyword","hashcat","Worlds fastest and most advanced password recovery utility.","T1110.001 - T1003.001 - T1021.001","TA0006 - TA0009 - TA0010","N/A","Black Basta","Credential Access","https://github.com/hashcat/hashcat","1","0","#linux","N/A","10","10","22481","3046","2024-08-16T23:50:35Z","2015-12-04T14:46:51Z","2395"
"* ntlmdecoder.py*",".{0,1000}\sntlmdecoder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","2396"
"* ntlmdecoder.py*",".{0,1000}\sntlmdecoder\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","2397"
"* --ntlm-hash --company * --import-cracked *",".{0,1000}\s\-\-ntlm\-hash\s\-\-company\s.{0,1000}\s\-\-import\-cracked\s.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","2398"
"* --ntlm-hash --export-hashes *",".{0,1000}\s\-\-ntlm\-hash\s\-\-export\-hashes\s.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","2399"
"* --ntlm-hash --import-ntds *.ntds*",".{0,1000}\s\-\-ntlm\-hash\s\-\-import\-ntds\s.{0,1000}\.ntds.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","2400"
"* -o sprayed.txt*",".{0,1000}\s\-o\ssprayed\.txt.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","2419"
"* o365_enum_activesync.py*",".{0,1000}\so365_enum_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2421"
"* o365_enum_office.py*",".{0,1000}\so365_enum_office\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2422"
"* o365_enum_onedrive.py*",".{0,1000}\so365_enum_onedrive\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2423"
"* o365_spray_activesync.py*",".{0,1000}\so365_spray_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2424"
"* o365_spray_adfs.py*",".{0,1000}\so365_spray_adfs\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2425"
"* o365_spray_msol.py*",".{0,1000}\so365_spray_msol\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2426"
"* o365spray.py*",".{0,1000}\so365spray\.py.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","2427"
"* -oA icebreaker-scan*",".{0,1000}\s\-oA\sicebreaker\-scan.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","2428"
"* OfflineSamTool.h*",".{0,1000}\sOfflineSamTool\.h.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","2436"
"* oh365userfinder.py*",".{0,1000}\soh365userfinder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","2437"
"* omnispray.py*",".{0,1000}\somnispray\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2440"
"* --outpath * --config *.json --backdoor*",".{0,1000}\s\-\-outpath\s.{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-backdoor.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","2468"
"* --outpath *.json --backdoor*",".{0,1000}\s\-\-outpath\s.{0,1000}\.json\s\-\-backdoor.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","2469"
"* owa * --user-as-pass *",".{0,1000}\sowa\s.{0,1000}\s\-\-user\-as\-pass\s.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","2473"
"* owa_enum_activesync.py*",".{0,1000}\sowa_enum_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2474"
"* owa_spray_activesync.py*",".{0,1000}\sowa_spray_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2475"
"* owa-sprayed-creds.txt*",".{0,1000}\sowa\-sprayed\-creds\.txt.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","2476"
"* -p pwd1.list pwd2.list *",".{0,1000}\s\-p\spwd1\.list\spwd2\.list\s.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","2492"
"* paloalto_enum_globalprotectportal.py*",".{0,1000}\spaloalto_enum_globalprotectportal\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2508"
"* paloalto_spray_globalprotectportal.py*",".{0,1000}\spaloalto_spray_globalprotectportal\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","2509"
"* pamspy_event.h*",".{0,1000}\spamspy_event\.h.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","2510"
"* PassSpray.ps1*",".{0,1000}\sPassSpray\.ps1.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","0","N/A","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","2526"
"* --password wordlists/*.txt*",".{0,1000}\s\-\-password\swordlists\/.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","2528"
"* password.lst*",".{0,1000}\spassword\.lst.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","2529"
"* --password-list *",".{0,1000}\s\-\-password\-list\s.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","2532"
"* --passwordsperdelay *",".{0,1000}\s\-\-passwordsperdelay\s.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","2535"
"* passwordspray -d *",".{0,1000}\spasswordspray\s\-d\s.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","2537"
"* --passwords-to-users *hash*",".{0,1000}\s\-\-passwords\-to\-users\s.{0,1000}hash.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","0","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","2538"
"* -PathToDMP *.dmp*",".{0,1000}\s\-PathToDMP\s.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","0","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","2546"
"* physmem2minidump.py*",".{0,1000}\sphysmem2minidump\.py.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","2603"
"* Pictures\Screenshots\loot.zip*",".{0,1000}\sPictures\\Screenshots\\loot\.zip.{0,1000}","offensive_tool_keyword","Harvester_OF_SORROW","The payload opens firefox about:logins and tabs and arrows its way through options. It then takes a screen shot with the first set of log in credentials made visible. Finally it sends the screenshot to an email of your choosing.","T1056.001 - T1113 - T1512 - T1566.001 - T1059.006","TA0004 - TA0009 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/blob/master/payloads/library/credentials/Harvester_OF_SORROW/payload.txt","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","2605"
"* --plugin gmailenum*",".{0,1000}\s\-\-plugin\sgmailenum.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","2616"
"* --plugin httpbrute --url *",".{0,1000}\s\-\-plugin\shttpbrute\s\-\-url\s.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","2617"
"* --plugin httpbrute*",".{0,1000}\s\-\-plugin\shttpbrute.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","2618"
"* --plugin KeeFarceRebornPlugin.dll*",".{0,1000}\s\-\-plugin\sKeeFarceRebornPlugin\.dll.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","2620"
"* --plugin o365enum*",".{0,1000}\s\-\-plugin\so365enum.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","2621"
"* PostDump.exe*",".{0,1000}\sPostDump\.exe.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","2645"
"* PPLmedic.exe*",".{0,1000}\sPPLmedic\.exe.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","2658"
"* Pre2kSpray.ps1*",".{0,1000}\sPre2kSpray\.ps1.{0,1000}","offensive_tool_keyword","Invoke-Pre2kSpray","Enumerate domain machine accounts and perform pre2k password spraying.","T1087.002 - T1110.003","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/eversinc33/Invoke-Pre2kSpray","1","0","N/A","N/A","8","1","69","11","2023-07-14T06:50:22Z","2023-07-05T10:07:38Z","2660"
"* preauthscan /users:*",".{0,1000}\spreauthscan\s\/users\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","2661"
"* PrintCreds.py*",".{0,1000}\sPrintCreds\.py.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","2667"
"* ps /target:*.xml /unprotect*",".{0,1000}\sps\s\/target\:.{0,1000}\.xml\s\/unprotect.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","2685"
"* ptt /ticket:*",".{0,1000}\sptt\s\/ticket\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","2698"
"* pwcrack.sh*",".{0,1000}\spwcrack\.sh.{0,1000}","offensive_tool_keyword","nsa-rules","Password cracking rules and masks for hashcat that I generated from cracked passwords.","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/NSAKEY/nsa-rules","1","0","N/A","N/A","10","6","547","125","2017-01-03T11:53:25Z","2016-02-15T20:49:32Z","2723"
"* pwcrack-framework*",".{0,1000}\spwcrack\-framework.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","2724"
"* pwdump.py*",".{0,1000}\spwdump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","2725"
"* PWDumpX process *",".{0,1000}\sPWDumpX\sprocess\s.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","2728"
"* PWDumpX service *",".{0,1000}\sPWDumpX\sservice\s.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","2729"
"* Pwn3d!*",".{0,1000}\sPwn3d!.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2733"
"* pyLAPS.py*",".{0,1000}\spyLAPS\.py.{0,1000}","offensive_tool_keyword","pyLAPS","A simple way to read and write LAPS passwords from linux.","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/p0dalirius/pyLAPS","1","0","#linux","N/A","9","2","105","16","2024-10-28T08:36:38Z","2021-10-05T18:35:21Z","2739"
"* -r airolib-db /root/wpa.cap*",".{0,1000}\s\-r\sairolib\-db\s\/root\/wpa\.cap.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","2754"
"* RagingRotator.go*",".{0,1000}\sRagingRotator\.go.{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","0","N/A","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","2761"
"* --random_user_agent*",".{0,1000}\s\-\-random_user_agent.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","0","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","2764"
"* rawrpc_embedded.py*",".{0,1000}\srawrpc_embedded\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","2776"
"* --rdcman-poison-hkcr*",".{0,1000}\s\-\-rdcman\-poison\-hkcr.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","2781"
"* RDPHook.dll*",".{0,1000}\sRDPHook\.dll.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","0","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","2789"
"* RdpThief.dll*",".{0,1000}\sRdpThief\.dll.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","0","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","2791"
"* rdpv.exe*",".{0,1000}\srdpv\.exe.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","0","N/A","N/A","8","10","N/A","N/A","N/A","N/A","2792"
"* -Remote -ExchHostname *",".{0,1000}\s\-Remote\s\-ExchHostname\s.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","0","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","2829"
"* renew *.kirbi*",".{0,1000}\srenew\s.{0,1000}\.kirbi.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","2858"
"* renew */ticket:*",".{0,1000}\srenew\s.{0,1000}\/ticket\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","2859"
"* --RestoreShadowCred*",".{0,1000}\s\-\-RestoreShadowCred.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","N/A","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","2872"
"* restoresig.py*",".{0,1000}\srestoresig\.py.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","2873"
"* revshell32.bin*",".{0,1000}\srevshell32\.bin.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","2889"
"* revshell64.bin*",".{0,1000}\srevshell64\.bin.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","2890"
"* --rid-brute*",".{0,1000}\s\-\-rid\-brute.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","2902"
"* rockyou.txt *",".{0,1000}\srockyou\.txt\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","2913"
"* rpcdump.py*",".{0,1000}\srpcdump\.py.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","2924"
"* Rubeus.dll*",".{0,1000}\sRubeus\.dll.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","2942"
"* Rubeus.ps1*",".{0,1000}\sRubeus\.ps1.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","2943"
"* --rules:Jumbo *",".{0,1000}\s\-\-rules\:Jumbo\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","2945"
"* run donpapi*",".{0,1000}\srun\sdonpapi.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","2946"
"* s4u * /bronzebit*",".{0,1000}\ss4u\s.{0,1000}\s\/bronzebit.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","2971"
"* s4u * /nopac*",".{0,1000}\ss4u\s.{0,1000}\s\/nopac.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","2972"
"* s4u * /ticket:*",".{0,1000}\ss4u\s.{0,1000}\s\/ticket\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","2973"
"* s4u *.kirbi*",".{0,1000}\ss4u\s.{0,1000}\.kirbi.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","2974"
"* s4u */rc4:* ",".{0,1000}\ss4u\s.{0,1000}\/rc4\:.{0,1000}\s","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","2975"
"* sam_reset_all_pw(*",".{0,1000}\ssam_reset_all_pw\(.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","2978"
"* scan --github-org*",".{0,1000}\sscan\s\-\-github\-org.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","0","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","2989"
"* scan --github-user*",".{0,1000}\sscan\s\-\-github\-user.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","0","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","2990"
"* --script smb-security-mode*smb-enum-shares *",".{0,1000}\s\-\-script\ssmb\-security\-mode.{0,1000}smb\-enum\-shares\s.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","3009"
"* --seclogon-duplicate*",".{0,1000}\s\-\-seclogon\-duplicate.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","3028"
"* --secrets-dump -target *",".{0,1000}\s\-\-secrets\-dump\s\-target\s.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","3030"
"* secretsdump.py*",".{0,1000}\ssecretsdump\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","3031"
"* SecretStealer.ps1*",".{0,1000}\sSecretStealer\.ps1.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","3034"
"* --session=allrules --wordlist*",".{0,1000}\s\-\-session\=allrules\s\-\-wordlist.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","3054"
"* SessionGopher.ps1*",".{0,1000}\sSessionGopher\.ps1.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","3056"
"* SharpHose.exe*",".{0,1000}\sSharpHose\.exe.{0,1000}","offensive_tool_keyword","SharpHose","Asynchronous Password Spraying Tool in C# for Windows Environments","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/ustayready/SharpHose","1","0","N/A","N/A","10","4","312","62","2023-12-19T21:06:47Z","2020-05-01T22:10:49Z","3089"
"* sharpspray.exe*",".{0,1000}\ssharpspray\.exe.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","3099"
"* --show passwd*",".{0,1000}\s\-\-show\spasswd.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","3120"
"* --show_invalid_creds*",".{0,1000}\s\-\-show_invalid_creds.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","0","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","3121"
"* --shtinkering*",".{0,1000}\s\-\-shtinkering.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","3122"
"* --shuffle-users* --spray*",".{0,1000}\s\-\-shuffle\-users.{0,1000}\s\-\-spray.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","3123"
"* sigthief.py*",".{0,1000}\ssigthief\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","3133"
"* --silent-process-exit *",".{0,1000}\s\-\-silent\-process\-exit\s.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","3136"
"* silver * /domain*",".{0,1000}\ssilver\s.{0,1000}\s\/domain.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","3138"
"* silver * /ldap *",".{0,1000}\ssilver\s.{0,1000}\s\/ldap\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","3139"
"* silver * /passlastset *",".{0,1000}\ssilver\s.{0,1000}\s\/passlastset\s.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","3140"
"* silver * /service:*",".{0,1000}\ssilver\s.{0,1000}\s\/service\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","3141"
"* --single shadow.hashes*",".{0,1000}\s\-\-single\sshadow\.hashes.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","3143"
"* smb client * shares *use c$*",".{0,1000}\ssmb\sclient\s.{0,1000}\sshares\s.{0,1000}use\sc\$.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","3199"
"* smb -M mimikatz --options*",".{0,1000}\ssmb\s\-M\smimikatz\s\-\-options.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3200"
"* smb shareenum *smb2+ntlm-password*",".{0,1000}\ssmb\sshareenum\s.{0,1000}smb2\+ntlm\-password.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","3201"
"* smb* -u '' -p ''*",".{0,1000}\ssmb.{0,1000}\s\-u\s\'\'\s\-p\s\'\'.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3203"
"* smb-cmds.txt*",".{0,1000}\ssmb\-cmds\.txt.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","3212"
"* smbexec.py*",".{0,1000}\ssmbexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3221"
"* smbrelayserver.py*",".{0,1000}\ssmbrelayserver\.py.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","0","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","3233"
"* Snake.sh *",".{0,1000}\/Snake\.sh.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#linux","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","3272"
"* Snake.sh*",".{0,1000}\sSnake\.sh.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","3273"
"* SocialBox.sh*",".{0,1000}\sSocialBox\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","0","N/A","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","3291"
"* --spray *--shuffle-users*",".{0,1000}\s\-\-spray\s.{0,1000}\-\-shuffle\-users.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","3320"
"* spray -ep ex-plan.s365*",".{0,1000}\sspray\s\-ep\sex\-plan\.s365.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","0","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","3321"
"* --spray --passwords *",".{0,1000}\s\-\-spray\s\-\-passwords\s.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","3322"
"* --spray --push-locked --months-only --exclude *",".{0,1000}\s\-\-spray\s\-\-push\-locked\s\-\-months\-only\s\-\-exclude\s.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","3323"
"* --spray --push-locked --months-only*",".{0,1000}\s\-\-spray\s\-\-push\-locked\s\-\-months\-only.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","3324"
"* spray -u * -H * -p * -m owa*",".{0,1000}\sspray\s\-u\s.{0,1000}\s\-H\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sowa.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","3325"
"* spray -u * -p * -m Office365*",".{0,1000}\sspray\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sOffice365.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","3326"
"* spray -u * -p * -m Smb -H *",".{0,1000}\sspray\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sSmb\s\-H\s.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","3327"
"* spraycharles.py*",".{0,1000}\sspraycharles\.py.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","3328"
"* SprayLove.py*",".{0,1000}\sSprayLove\.py.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","3329"
"* --spraypassword *",".{0,1000}\s\-\-spraypassword\s.{0,1000}","offensive_tool_keyword","SharpHose","Asynchronous Password Spraying Tool in C# for Windows Environments","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/ustayready/SharpHose","1","0","N/A","N/A","10","4","312","62","2023-12-19T21:06:47Z","2020-05-01T22:10:49Z","3330"
"* SQLDmpr0001.mdmp*",".{0,1000}\sSQLDmpr0001\.mdmp.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","3335"
"* Starting pre2k spray against *",".{0,1000}\sStarting\spre2k\sspray\sagainst\s.{0,1000}","offensive_tool_keyword","Invoke-Pre2kSpray","Enumerate domain machine accounts and perform pre2k password spraying.","T1087.002 - T1110.003","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/eversinc33/Invoke-Pre2kSpray","1","0","#content","N/A","8","1","69","11","2023-07-14T06:50:22Z","2023-07-05T10:07:38Z","3398"
"* Successfully hijacked KeePassXC.exe*",".{0,1000}\sSuccessfully\shijacked\sKeePassXC\.exe.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","3428"
"* SW2_HashSyscall*",".{0,1000}\sSW2_HashSyscall.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","3435"
"* -system * -ntds *ntds.dit*",".{0,1000}\s\-system\s.{0,1000}\s\-ntds\s.{0,1000}ntds\.dit.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","3441"
"* -t *https://autodiscover.*/autodiscover/autodiscover.xml*autodiscover*",".{0,1000}\s\-t\s.{0,1000}https\:\/\/autodiscover\..{0,1000}\/autodiscover\/autodiscover\.xml.{0,1000}autodiscover.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","0","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","3447"
"* -target-ip * -remote-dll *.dll* -local-dll *",".{0,1000}\s\-target\-ip\s.{0,1000}\s\-remote\-dll\s.{0,1000}\.dll.{0,1000}\s\-local\-dll\s.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","3468"
"* --target-user * --dc-ip * -command *",".{0,1000}\s\-\-target\-user\s.{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-command\s.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","0","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","3483"
"* TeamFiltration.dll*",".{0,1000}\sTeamFiltration\.dll.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","3490"
"* TeamFiltration.exe*",".{0,1000}\sTeamFiltration\.exe.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","3491"
"* teams_dump.py*",".{0,1000}\steams_dump\.py.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","3492"
"* teams_dump.py*",".{0,1000}\steams_dump\.py.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","3493"
"* tgssub * /ticket:*",".{0,1000}\stgssub\s.{0,1000}\s\/ticket\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","3506"
"* tgtdeleg /nowrap*",".{0,1000}\stgtdeleg\s\/nowrap.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","3508"
"* tgtdeleg /target:*",".{0,1000}\stgtdeleg\s\/target\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","3510"
"* thc-hidra*",".{0,1000}\sthc\-hidra.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","3511"
"* ThievingFox.py*",".{0,1000}\sThievingFox\.py.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","3517"
"* ticket_converter.py*",".{0,1000}\sticket_converter\.py.{0,1000}","offensive_tool_keyword","ticket_converter","A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.","T1558.003 - T1110.004","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/zer1t0/ticket_converter","1","0","N/A","N/A","10","2","167","31","2022-06-16T19:38:05Z","2019-05-14T04:48:19Z","3519"
"* ticketsplease.*",".{0,1000}\sticketsplease\..{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","0","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","3521"
"* TokenFinder.py*",".{0,1000}\sTokenFinder\.py.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","0","N/A","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","3533"
"* TokenUniverse.zip*",".{0,1000}\sTokenUniverse\.zip.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","0","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","3537"
"* --tor_password *",".{0,1000}\s\-\-tor_password\s.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","0","N/A","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","3543"
"* tweetshell.sh*",".{0,1000}\stweetshell\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","0","N/A","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","3575"
"* --type enum -uf * --module o365_enum_office*",".{0,1000}\s\-\-type\senum\s\-uf\s.{0,1000}\s\-\-module\so365_enum_office.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","3577"
"* --type spray -uf * -pf *",".{0,1000}\s\-\-type\sspray\s\-uf\s.{0,1000}\s\-pf\s.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","3582"
"* -u * -d * --dc-ip * -k --no-pass --target * --action ""list""*",".{0,1000}\s\-u\s.{0,1000}\s\-d\s.{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-k\s\-\-no\-pass\s\-\-target\s.{0,1000}\s\-\-action\s\""list\"".{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","3586"
"* -u * --local-auth*",".{0,1000}\s\-u\s.{0,1000}\s\-\-local\-auth.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3587"
"* -u * -p * --lusers*",".{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-lusers.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3588"
"* -u * -p * --sam",".{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-sam","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3592"
"* -u * -p * --shares*",".{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-shares.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3593"
"* -u * -p *--pass-pol*",".{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\-\-pass\-pol.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3594"
"* -u wordlist * wordlist_uniq_sorted*",".{0,1000}\s\-u\swordlist\s.{0,1000}\swordlist_uniq_sorted.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","0","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","3602"
"* -user * --passwordlist *",".{0,1000}\s\-user\s.{0,1000}\s\-\-passwordlist\s.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","0","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","3636"
"* -user userlist.txt -pass passwordlist.txt *",".{0,1000}\s\-user\suserlist\.txt\s\-pass\spasswordlist\.txt\s.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","0","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","3639"
"* --user-as-pass*",".{0,1000}\s\-\-user\-as\-pass.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","3641"
"* userenum -d * *.txt*",".{0,1000}\suserenum\s\-d\s.{0,1000}\s.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","3643"
"* -UserList * -Domain * -PasswordList * -OutFile *",".{0,1000}\s\-UserList\s.{0,1000}\s\-Domain\s.{0,1000}\s\-PasswordList\s.{0,1000}\s\-OutFile\s.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","3645"
"* -userpassfile ./userpass_file.txt*",".{0,1000}\s\-userpassfile\s\.\/userpass_file\.txt.{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","0","#linux","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","3651"
"* --userpassword_list *",".{0,1000}\s\-\-userpassword_list\s.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","0","N/A","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","3652"
"* utils.ntlmdecode *",".{0,1000}\sutils\.ntlmdecode\s.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","3656"
"* vaporizer.py *",".{0,1000}\svaporizer\.py\s.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","3658"
"* vaults /target:* /pvk:*",".{0,1000}\svaults\s\/target\:.{0,1000}\s\/pvk\:.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","3661"
"* wcreddump (windows credentials dump)*",".{0,1000}\swcreddump\s\(windows\scredentials\sdump\).{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#linux #windows #content","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","3691"
"* wcreddump.py*",".{0,1000}\swcreddump\.py.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","3692"
"* --wdigest disable*",".{0,1000}\s\-\-wdigest\sdisable.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3694"
"* --wdigest enable*",".{0,1000}\s\-\-wdigest\senable.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3695"
"* -WebRoot C:\inetpub\wwwroot\SecretServer*",".{0,1000}\s\-WebRoot\sC\:\\inetpub\\wwwroot\\SecretServer.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","3699"
"* --weekday-warrior -*",".{0,1000}\s\-\-weekday\-warrior\s\-.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","3701"
"* --werfault *\temp\*",".{0,1000}\s\-\-werfault\s.{0,1000}\\temp\\.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","3702"
"* Windows-Passwords.ps1*",".{0,1000}\sWindows\-Passwords\.ps1.{0,1000}","offensive_tool_keyword","WLAN-Windows-Passwords","Opens PowerShell hidden - grabs wlan passwords - saves as a cleartext in a variable and exfiltrates info via Discord Webhook.","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/WLAN-Windows-Passwords","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","3723"
"* WINHELLO2hashcat.py*",".{0,1000}\sWINHELLO2hashcat\.py.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","3725"
"* winrm.py*",".{0,1000}\swinrm\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3734"
"* --wmi *SELECT *",".{0,1000}\s\-\-wmi\s.{0,1000}SELECT\s.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3740"
"* wmiexec.py*",".{0,1000}\swmiexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3743"
"* --wmi-namespace 'root\cimv2'*",".{0,1000}\s\-\-wmi\-namespace\s\'root\\cimv2\'.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3747"
"* --wordlist=*.lst*",".{0,1000}\s\-\-wordlist\=.{0,1000}\.lst.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","3750"
"* -X '$PSVersionTable' *",".{0,1000}\s\-X\s\'\$PSVersionTable\'\s.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3769"
"* -X '[System.Environment]::Is64BitProcess'*",".{0,1000}\s\-X\s\'\[System\.Environment\]\:\:Is64BitProcess\'.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3771"
"* -x -z --get-users-list*",".{0,1000}\s\-x\s\-z\s\-\-get\-users\-list.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","3774"
"* -x -z -s 3 -j 1 -u *.txt*",".{0,1000}\s\-x\s\-z\s\-s\s3\s\-j\s1\s\-u\s.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","3775"
"*!!! Are you sure you are running as the AD FS service account?*",".{0,1000}!!!\sAre\syou\ssure\syou\sare\srunning\sas\sthe\sAD\sFS\sservice\saccount\?.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","0","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","3796"
"*!process 0 0 lsass.exe*",".{0,1000}!process\s0\s0\slsass\.exe.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","3805"
"*""A La Vie, A L'Amour"" - Windows build *",".{0,1000}\""A\sLa\sVie,\sA\sL\'Amour\""\s\-\sWindows\sbuild\s.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","3816"
"*""author"": ""@_EthicalChaos_""*",".{0,1000}\""author\""\:\s\""\@_EthicalChaos_\"".{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","3821"
"*""MSGraph token is CAE capable""*",".{0,1000}\""MSGraph\stoken\sis\sCAE\scapable\"".{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","3854"
"*""RdpStrike.cna""*",".{0,1000}\""RdpStrike\.cna\"".{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","0","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","3862"
"*""sacrificialO365Passwords"": *",".{0,1000}\""sacrificialO365Passwords\""\:\s.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","3864"
"*""sacrificialO365Username"": *",".{0,1000}\""sacrificialO365Username\""\:\s.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","3865"
"*""Saved in session, but master password prevents plaintext recovery""*",".{0,1000}\""Saved\sin\ssession,\sbut\smaster\spassword\sprevents\splaintext\srecovery\"".{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","#content","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","3867"
"*""The LaZagne project""*",".{0,1000}\""The\sLaZagne\sproject\"".{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#content","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","3876"
"*""User32LogonProcesss""*",".{0,1000}User32LogonProcesss.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://x.com/_RastaMouse/status/1747636529613197757","1","0","N/A","typo in the process name used when calling LsaRegisterLogonProcess","10","10","N/A","N/A","N/A","N/A","3879"
"*""VeeamBackupCreds""*",".{0,1000}\""VeeamBackupCreds\"".{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","3881"
"*# Minimalistic AD login bruteforcer *",".{0,1000}\#\sMinimalistic\sAD\slogin\sbruteforcer\s.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Credential Access","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","0","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","3899"
"*# Minimalistic SMB login bruteforcer *",".{0,1000}\#\sMinimalistic\sSMB\slogin\sbruteforcer\s.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Credential Access","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","0","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","3900"
"*# Using reflection to dump LSASS in-memory with stealth*",".{0,1000}\#\sUsing\sreflection\sto\sdump\sLSASS\sin\-memory\swith\sstealth.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#content","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","3910"
"*## Extracting Private Key from Active Directory Store*",".{0,1000}\#\#\sExtracting\sPrivate\sKey\sfrom\sActive\sDirectory\sStore.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","0","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","3914"
"*$AllCurrentPwdDiscovered*",".{0,1000}\$AllCurrentPwdDiscovered.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","0","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","3941"
"*$DummyServiceName*",".{0,1000}\$DummyServiceName.{0,1000}","offensive_tool_keyword","crackmapexec","Variable name from script RestartKeePass.ps1 from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks ","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3956"
"*$dumpDir\lsass.txt*",".{0,1000}\$dumpDir\\lsass\.txt.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","3957"
"*$fct = Get-Content -Encoding byte -Path *",".{0,1000}\$fct\s\=\sGet\-Content\s\-Encoding\sbyte\s\-Path\s.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","#content","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","3974"
"*$ForensikeFolder*",".{0,1000}\$ForensikeFolder.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","3976"
"*$KeePassBinaryPath*",".{0,1000}\$KeePassBinaryPath.{0,1000}","offensive_tool_keyword","crackmapexec","Variable name from script RestartKeePass.ps1 from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks ","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3991"
"*$KeePassUser*",".{0,1000}\$KeePassUser.{0,1000}","offensive_tool_keyword","crackmapexec","Variable name from script RestartKeePass.ps1 from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks ","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","3992"
"*$KeePassXMLPath backdoored*",".{0,1000}\$KeePassXMLPath\sbackdoored.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","3993"
"*$KeePassXMLPath triggers removed*",".{0,1000}\$KeePassXMLPath\striggers\sremoved.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","3994"
"*$ThisIsNotTheStringYouAreLookingFor*",".{0,1000}\$ThisIsNotTheStringYouAreLookingFor.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","0","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","4022"
"*$TotalNbCurrentPwdDiscovered*",".{0,1000}\$TotalNbCurrentPwdDiscovered.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","0","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","4023"
"*$VeaamRegPath*SqlDatabaseName*",".{0,1000}\$VeaamRegPath.{0,1000}SqlDatabaseName.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","0","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","4025"
"*$VeaamRegPath*SqlInstanceName*",".{0,1000}\$VeaamRegPath.{0,1000}SqlInstanceName.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","0","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","4026"
"*$VeaamRegPath*SqlServerName*",".{0,1000}\$VeaamRegPath.{0,1000}SqlServerName.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","0","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","4027"
"*%appdaedx765ta%/Binaedx765nce*",".{0,1000}\%appdaedx765ta\%\/Binaedx765nce.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","4030"
"*%appdedx765ata%/Eledx765ectrum*",".{0,1000}\%appdedx765ata\%\/Eledx765ectrum.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","4034"
"*%appdedx765ata%/Etheedx765reum*",".{0,1000}\%appdedx765ata\%\/Etheedx765reum.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","4035"
"*%localaedx765ppdata%*",".{0,1000}\%localaedx765ppdata\%.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","4037"
"*%loedx765calappedx765data*",".{0,1000}\%loedx765calappedx765data.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","4039"
"*%userproedx765file%*",".{0,1000}\%userproedx765file\%.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","4045"
"*&passwd=Winter2020&ok=Log+In*",".{0,1000}\&passwd\=Winter2020\&ok\=Log\+In.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#linux","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","4050"
"*(msds-supportedencryptiontypes=0)(msds-supportedencryptiontypes:1.2.840.113556.1.4.803:=4)))*",".{0,1000}\(msds\-supportedencryptiontypes\=0\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.803\:\=4\)\)\).{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","4082"
"*(Program.MiniDump minidump*",".{0,1000}\(Program\.MiniDump\sminidump.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","#content","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","4088"
"*(SHADOW DUMPER v1.0)*",".{0,1000}\(SHADOW\sDUMPER\sv1\.0\).{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","4089"
"*./GoAWSConsoleSpray*",".{0,1000}\.\/GoAWSConsoleSpray.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","0","#linux","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","4144"
"*./go-secdump*",".{0,1000}\.\/go\-secdump.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","0","#linux","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","4145"
"*./hashcat -*",".{0,1000}\.\/hashcat\s\-.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","#linux","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","4147"
"*./hashview/*",".{0,1000}\.\/hashview\/.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","0","#linux","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","4148"
"*./hydra *",".{0,1000}\.\/hydra\s.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","4153"
"*./kerbrute *",".{0,1000}\.\/kerbrute\s.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","#linux","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","4159"
"*./ntdissector*",".{0,1000}\.\/ntdissector.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","0","#linux","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","4175"
"*./Obfuscated_*.py*",".{0,1000}\.\/Obfuscated_.{0,1000}\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#linux","N/A","10","","N/A","","","","4177"
"*./Passdetective*",".{0,1000}\.\/Passdetective.{0,1000}","offensive_tool_keyword","PassDetective","PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets","T1059 - T1059.004 - T1552 - T1552.001","TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/aydinnyunus/PassDetective","1","0","#linux","N/A","7","2","129","8","2024-06-19T10:39:39Z","2023-07-22T12:31:57Z","4180"
"*./Pcredz *",".{0,1000}\.\/Pcredz\s.{0,1000}","offensive_tool_keyword","Pcredz","This tool extracts Credit card numbers. NTLM(DCE-RPC. HTTP. SQL. LDAP. etc). Kerberos (AS-REQ Pre-Auth etype 23). HTTP Basic. SNMP. POP. SMTP. FTP. IMAP. etc from a pcap file or from a live interface.","T1116 - T1003 - T1002 - T1001 - T1005 - T1552","TA0003 - TA0002 - TA0011","N/A","N/A","Credential Access","https://github.com/lgandx/Pcredz","1","0","#linux","N/A","N/A","10","2100","413","2025-01-27T10:34:00Z","2014-04-07T02:03:33Z","4181"
"*./snake",".{0,1000}\.\/snake","offensive_tool_keyword","3snake","Tool for extracting information from newly spawned processes","T1003 - T1110 - T1552 - T1505","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/blendin/3snake","1","0","#linux","N/A","7","8","752","109","2022-02-14T17:42:10Z","2018-02-07T21:03:15Z","4208"
"*./t14m4t *",".{0,1000}\.\/t14m4t\s.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","0","#linux","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","4213"
"*./xhydra*",".{0,1000}\.\/xhydra.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","4222"
"*.asp --adcs --template Machine -smb2support*",".{0,1000}\.asp\s\-\-adcs\s\-\-template\sMachine\s\-smb2support.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","0","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","4247"
"*.dmp 1> \\127.0.0.1\C$\*",".{0,1000}\.dmp\s1\>\s\\\\127\.0\.0\.1\\C\$\\.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","4287"
"*.edx765txt*",".{0,1000}\.edx765txt.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","4308"
"*.exe /logonpasswords /symbol*",".{0,1000}\.exe\s\s\/logonpasswords\s\/symbol.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","4318"
"*.exe certificates /pvk:*.pvk*",".{0,1000}\.exe\s\scertificates\s\/pvk\:.{0,1000}\.pvk.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4321"
"*.exe keepass /unprotect*",".{0,1000}\.exe\s\skeepass\s\/unprotect.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4323"
"*.exe .\chrome.DMP*",".{0,1000}\.exe\s\.\\chrome\.DMP.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","4330"
"*.exe .\msedge.DMP*",".{0,1000}\.exe\s\.\\msedge\.DMP.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","4331"
"*.exe /gethmac /mode:SHA1 /key:*",".{0,1000}\.exe\s\/gethmac\s\/mode\:SHA1\s\/key\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","4333"
"*.exe asktgt /user:* /aes256:* /opsec /ptt*",".{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/aes256\:.{0,1000}\s\/opsec\s\/ptt.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Lateral Movement with Rubeus More stealthy variant but requires the AES256 key (see 'Dumping OS credentials with Mimikatz' section)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","4380"
"*.exe asktgt /user:* /certificate:* /password:*",".{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/certificate\:.{0,1000}\s\/password\:.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","4381"
"*.exe asktgt /user:* /rc4:* /createnetonly:*cmd.exe*",".{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/rc4\:.{0,1000}\s\/createnetonly\:.{0,1000}cmd\.exe.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Lateral Movement with Rubeus Pass the ticket to a sacrificial hidden process. allowing you to e.g. steal the token from this process (requires elevation)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","4382"
"*.exe asktgt /user:* /rc4:* /ptt*",".{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/rc4\:.{0,1000}\s\/ptt.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Lateral Movement with Rubeus Request a TGT as the target user and pass it into the current session","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","4383"
"*.exe -b chromium -p *\AppData\Local\Google\Chrome\*",".{0,1000}\.exe\s\-b\schromium\s\-p\s.{0,1000}\\AppData\\Local\\Google\\Chrome\\.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","4392"
"*.exe backupkey /nowrap *.pvk*",".{0,1000}\.exe\sbackupkey\s\/nowrap\s.{0,1000}\.pvk.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4393"
"*.exe backupkey /server:*",".{0,1000}\.exe\sbackupkey\s\/server\:.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4394"
"*.exe blob /target:C:\Temp\*",".{0,1000}\.exe\sblob\s\/target\:C\:\\Temp\\.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4395"
"*.exe BOOKMARKS*",".{0,1000}\.exe\sBOOKMARKS.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","4397"
"*.exe certificates /mkfile:*.txt*",".{0,1000}\.exe\scertificates\s\/mkfile\:.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4400"
"*.exe certificates /unprotect*",".{0,1000}\.exe\scertificates\s\/unprotect.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4401"
"*.exe compute --sid * --kdskey *",".{0,1000}\.exe\scompute\s\-\-sid\s.{0,1000}\s\-\-kdskey\s.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","0","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","4407"
"*.exe COOKIES*",".{0,1000}\.exe\sCOOKIES.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","4414"
"*.exe credentials /pvk:*.pvk*",".{0,1000}\.exe\scredentials\s\/pvk\:.{0,1000}\.pvk.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4417"
"*.exe CREDIT_CARDS*",".{0,1000}\.exe\sCREDIT_CARDS.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","4418"
"*.exe --dll * --dump * --pid *",".{0,1000}\.exe\s\-\-dll\s.{0,1000}\s\-\-dump\s.{0,1000}\s\-\-pid\s.{0,1000}","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","0","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","4425"
"*.exe dump /luid:* /service:krbtgt*",".{0,1000}\.exe\sdump\s\/luid\:.{0,1000}\s\/service\:krbtgt.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","4429"
"*.exe --dump -k * -u http*",".{0,1000}\.exe\s\-\-dump\s\-k\s.{0,1000}\s\-u\shttp.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","0","N/A","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","4431"
"*.exe dump --key-name *",".{0,1000}\.exe\sdump\s\-\-key\-name\s.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","4432"
"*.exe exec * cmd interactive*",".{0,1000}\.exe\sexec\s.{0,1000}\scmd\sinteractive.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","0","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","4439"
"*.exe --get-users-list > *",".{0,1000}\.exe\s\-\-get\-users\-list\s\>\s.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","4456"
"*.exe gmsainfo --sid *",".{0,1000}\.exe\sgmsainfo\s\-\-sid\s.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","0","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","4457"
"*.exe hash /password:*",".{0,1000}\.exe\shash\s\/password\:.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","4466"
"*.exe kdsinfo --guid *",".{0,1000}\.exe\skdsinfo\s\-\-guid\s.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","0","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","4488"
"*.exe machinemasterkeys*",".{0,1000}\.exe\smachinemasterkeys.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4529"
"*.exe machinetriage*",".{0,1000}\.exe\smachinetriage.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4530"
"*.exe machinevaults*",".{0,1000}\.exe\smachinevaults.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4531"
"*.exe masterkeys /hashes*",".{0,1000}\.exe\smasterkeys\s\/hashes.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4532"
"*.exe masterkeys /hashes*",".{0,1000}\.exe\smasterkeys\s\/hashes.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4533"
"*.exe masterkeys /pvk:*",".{0,1000}\.exe\smasterkeys\s\/pvk\:.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4534"
"*.exe --procdump -p *",".{0,1000}\.exe\s\-\-procdump\s\-p\s.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","4572"
"*.exe ps /target:C:\Temp\* /unprotect*",".{0,1000}\.exe\sps\s\/target\:C\:\\Temp\\.{0,1000}\s\/unprotect.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4574"
"*.exe ptt /ticket:*.kirbi",".{0,1000}\.exe\sptt\s\/ticket\:.{0,1000}\.kirbi","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","4576"
"*.exe rdg /unprotect*",".{0,1000}\.exe\srdg\s\/unprotect.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4584"
"*.exe --signature --driver*",".{0,1000}\.exe\s\-\-signature\s\-\-driver.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","4611"
"*.exe spy --pid *",".{0,1000}\.exe\sspy\s\-\-pid\s.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","0","N/A","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","4620"
"*.exe spy --window *",".{0,1000}\.exe\sspy\s\-\-window\s.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","0","N/A","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","4621"
"*.exe triage /password:*",".{0,1000}\.exe\striage\s\/password\:.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","4632"
"*.exe -u * -s 2 -c cmd.exe*",".{0,1000}\.exe\s\-u\s.{0,1000}\s\-s\s2\s\-c\scmd\.exe.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","0","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","4633"
"*.exe -v -u * -w 10k-most-common.txt*",".{0,1000}\.exe\s\-v\s\-u\s.{0,1000}\s\-w\s10k\-most\-common\.txt.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","0","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","4639"
"*.exe Xmanager /user:* /sid:* /path:**",".{0,1000}\.exe\sXmanager\s\/user\:.{0,1000}\s\/sid\:.{0,1000}\s\/path\:.{0,1000}.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","4645"
"*.exe -Xmangager -p *",".{0,1000}\.exe\s\-Xmangager\s\-p\s.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","4646"
"*.exe* -d localhost * -u * -p */24*",".{0,1000}\.exe.{0,1000}\s\-d\slocalhost\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\/24.{0,1000}","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","4647"
"*.exe* -u administrator -H :*--shares*",".{0,1000}\.exe.{0,1000}\s\-u\sadministrator\s\-H\s\:.{0,1000}\-\-shares.{0,1000}","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","4657"
"*.local.kirbi*",".{0,1000}\.local\.kirbi.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","4695"
"*.ps1 -dcip * -Username * -Password* -ExportToCSV *.csv -ExportToJSON *.json*",".{0,1000}\.ps1\s\-dcip\s.{0,1000}\s\-Username\s.{0,1000}\s\-Password.{0,1000}\s\-ExportToCSV\s.{0,1000}\.csv\s\-ExportToJSON\s.{0,1000}\.json.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","0","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","4760"
"*.py -credz *.txt * ",".{0,1000}\.py\s\s\-credz\s.{0,1000}\.txt\s.{0,1000}\s","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","4773"
"*.py rekall *.dmp* -t 0",".{0,1000}\.py\s\srekall\s.{0,1000}\.dmp.{0,1000}\s\-t\s0","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","4788"
"*.py * --burp *",".{0,1000}\.py\s.{0,1000}\s\-\-burp\s.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","0","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","4793"
"*.py * -debug -dnstcp*",".{0,1000}\.py\s.{0,1000}\s\-debug\s\-dnstcp.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","0","N/A","N/A","10","","N/A","","","","4796"
"*.py -d ""test.local"" -u ""john"" -p ""password123"" --target ""user2"" --action ""list"" --dc-ip ""10.10.10.1""*",".{0,1000}\.py\s\-d\s\""test\.local\""\s\-u\s\""john\""\s\-p\s\""password123\""\s\-\-target\s\""user2\""\s\-\-action\s\""list\""\s\-\-dc\-ip\s\""10\.10\.10\.1\"".{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","4822"
"*.py -d * -u * -p * --target * --action * --export PEM*",".{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\s.{0,1000}\s\-\-export\sPEM.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","4823"
"*.py -d * -u * -p * --target * --action ""add"" --filename * ",".{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\""add\""\s\-\-filename\s.{0,1000}\s","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","4824"
"*.py -d * -u * -p * --target * --action ""clear""* ",".{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\""clear\"".{0,1000}\s","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","4825"
"*.py -d * -u * -p * --target * --action ""info"" --device-id *",".{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\""info\""\s\-\-device\-id\s.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","4826"
"*.py -d * -u * -p * --target * --action ""list"" *",".{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\""list\""\s.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","4827"
"*.py -d * -u * -p * --target * --action ""remove"" --device-id *",".{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\""remove\""\s\-\-device\-id\s.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","4828"
"*.py discover -H domain_list.txt*",".{0,1000}\.py\sdiscover\s\-H\sdomain_list\.txt.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","0","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","4829"
"*.py enum -H * -U *.txt -P *.txt -*.txt*",".{0,1000}\.py\senum\s\-H\s.{0,1000}\s\-U\s.{0,1000}\.txt\s\-P\s.{0,1000}\.txt\s\-.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","0","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","4831"
"*.py lock -H * -u administrator -d *",".{0,1000}\.py\slock\s\-H\s.{0,1000}\s\-u\sadministrator\s\-d\s.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","0","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","4836"
"*.py spray -ep *",".{0,1000}\.py\sspray\s\-ep\s.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","0","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","4842"
"*.py teams --get*",".{0,1000}\.py\steams\s\-\-get.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","4845"
"*.py teams --list*",".{0,1000}\.py\steams\s\-\-list.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","4846"
"*.py*.ccache *.kirbi *",".{0,1000}\.py.{0,1000}\.ccache\s.{0,1000}\.kirbi\s.{0,1000}","offensive_tool_keyword","ticket_converter","A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.","T1558.003 - T1110.004","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/zer1t0/ticket_converter","1","0","N/A","N/A","10","2","167","31","2022-06-16T19:38:05Z","2019-05-14T04:48:19Z","4855"
"*.py*.kirbi *.ccache*",".{0,1000}\.py.{0,1000}\.kirbi\s.{0,1000}\.ccache.{0,1000}","offensive_tool_keyword","ticket_converter","A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.","T1558.003 - T1110.004","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/zer1t0/ticket_converter","1","0","N/A","N/A","10","2","167","31","2022-06-16T19:38:05Z","2019-05-14T04:48:19Z","4856"
"*.py*found-users.txt*",".{0,1000}\.py.{0,1000}found\-users\.txt.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","4857"
"*/.config/lsassy*",".{0,1000}\/\.config\/lsassy.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#linux","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","5011"
"*/.ntdissector*",".{0,1000}\/\.ntdissector.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","0","#linux","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","5027"
"*/.spraycharles/logs*",".{0,1000}\/\.spraycharles\/logs.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","#linux","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","5035"
"*/.spraycharles/out*",".{0,1000}\/\.spraycharles\/out.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","#linux","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","5036"
"*/.spraycharles:/root/.spraycharles*",".{0,1000}\/\.spraycharles\:\/root\/\.spraycharles.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","#linux","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","5037"
"*//shuck.sh*",".{0,1000}\/\/shuck\.sh.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","5060"
"*/1$a$$.exe*",".{0,1000}\/1\$a\$\$\.exe.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","1","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","5075"
"*/1/all_in_one.7z.torrent*",".{0,1000}\/1\/all_in_one\.7z\.torrent.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","5077"
"*/1/all_in_one_p.7z*",".{0,1000}\/1\/all_in_one_p\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","5078"
"*/1/all_in_one_w.7z*",".{0,1000}\/1\/all_in_one_w\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","5079"
"*/3snake.git*",".{0,1000}\/3snake\.git.{0,1000}","offensive_tool_keyword","3snake","Tool for extracting information from newly spawned processes","T1003 - T1110 - T1552 - T1505","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/blendin/3snake","1","1","N/A","N/A","7","8","752","109","2022-02-14T17:42:10Z","2018-02-07T21:03:15Z","5094"
"*/Adamantium-Thief.git*",".{0,1000}\/Adamantium\-Thief\.git.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","1","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","5131"
"*/adconnectdump.git*",".{0,1000}\/adconnectdump\.git.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","5148"
"*/ADCSCoercePotato.git*",".{0,1000}\/ADCSCoercePotato\.git.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","5156"
"*/ADCSCoercePotato/*",".{0,1000}\/ADCSCoercePotato\/.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","5157"
"*/adcsync.git*",".{0,1000}\/adcsync\.git.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","1","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","5164"
"*/adcsync.py*",".{0,1000}\/adcsync\.py.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","1","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","5165"
"*/adfsbrute.git*",".{0,1000}\/adfsbrute\.git.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","1","N/A","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","5187"
"*/adfsbrute.py*",".{0,1000}\/adfsbrute\.py.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","1","N/A","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","5188"
"*/ADFSDump.git*",".{0,1000}\/ADFSDump\.git.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","1","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","5191"
"*/ADFSDump-PS.git*",".{0,1000}\/ADFSDump\-PS\.git.{0,1000}","offensive_tool_keyword","ADFSDump-PS","ADFSDump to assist with GoldenSAML","T1078 - T1552.004 - T1558.004","TA0006 ","N/A","N/A","Credential Access","https://github.com/ZephrFish/ADFSDump-PS","1","1","N/A","N/A","10","1","31","8","2024-05-20T00:00:19Z","2024-05-19T00:46:28Z","5192"
"*/ADFSpray*",".{0,1000}\/ADFSpray.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","1","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","5194"
"*/ADFSRelay.git*",".{0,1000}\/ADFSRelay\.git.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","5195"
"*/ADFSRelay.go*",".{0,1000}\/ADFSRelay\.go.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","5196"
"*/adfs-spray.py*",".{0,1000}\/adfs\-spray\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","5197"
"*/aerosol.py*",".{0,1000}\/aerosol\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","#linux","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","5220"
"*/amass/wordlists*",".{0,1000}\/amass\/wordlists.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5286"
"*/amsiwala.exe*",".{0,1000}\/amsiwala\.exe.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","1","N/A","N/A","10","1","N/A","N/A","N/A","N/A","5306"
"*/AndrewSpecial.git*",".{0,1000}\/AndrewSpecial\.git.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","1","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","5308"
"*/apps/zxtm/wizard.fcgi?error=1§ion=Access+Management%3ALocalUsers*",".{0,1000}\/apps\/zxtm\/wizard\.fcgi\?error\=1\§ion\=Access\+Management\%3ALocalUsers.{0,1000}","offensive_tool_keyword","POC","Ivanti Authent Bypass CVE-2024-7593 - Successful exploitation could lead to authentication bypass and creation of an administrator user","T1078 - T1136 - T1078.001","TA0006 - TA0004 - TA0005","N/A","N/A","Credential Access","https://x.com/mthcht/status/1823463842459848906","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","5388"
"*/Ask4Creds.git*",".{0,1000}\/Ask4Creds\.git.{0,1000}","offensive_tool_keyword","Ask4Creds","Prompt User for credentials","T1056 - T1071","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Leo4j/Ask4Creds","1","1","N/A","N/A","8","1","1","0","2024-03-20T17:09:21Z","2023-11-12T15:21:40Z","5409"
"*/Ask4Creds.ps1*",".{0,1000}\/Ask4Creds\.ps1.{0,1000}","offensive_tool_keyword","Ask4Creds","Prompt User for credentials","T1056 - T1071","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Leo4j/Ask4Creds","1","1","N/A","N/A","8","1","1","0","2024-03-20T17:09:21Z","2023-11-12T15:21:40Z","5411"
"*/ASREPRoast*",".{0,1000}\/ASREPRoast.{0,1000}","offensive_tool_keyword","ASREPRoast","Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. ","T1558.003","TA0006","N/A","N/A","Credential Access","https://github.com/HarmJ0y/ASREPRoast","1","1","N/A","N/A","N/A","3","202","58","2018-09-25T03:26:00Z","2017-01-14T21:07:57Z","5423"
"*/atomizer.py*",".{0,1000}\/atomizer\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","#linux","N/A","9","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","5456"
"*/ATPMiniDump.git*",".{0,1000}\/ATPMiniDump\.git.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","1","N/A","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","5460"
"*/autoNTDS.git*",".{0,1000}\/autoNTDS\.git.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","1","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","5486"
"*/autoNTDS.py*",".{0,1000}\/autoNTDS\.py.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","1","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","5487"
"*/BabelStrike.git*",".{0,1000}\/BabelStrike\.git.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","1","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","5518"
"*/BabelStrike.py*",".{0,1000}\/BabelStrike\.py.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","1","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","5519"
"*/backupcreds.exe*",".{0,1000}\/backupcreds\.exe.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","1","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","5542"
"*/BackupCreds.git*",".{0,1000}\/BackupCreds\.git.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","1","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","5543"
"*/badcert.pem*",".{0,1000}\/badcert\.pem.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#linux","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","5548"
"*/badkey.pem*",".{0,1000}\/badkey\.pem.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#linux","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","5549"
"*/BesoToken.cpp*",".{0,1000}\/BesoToken\.cpp.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","1","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","5606"
"*/BesoToken.exe*",".{0,1000}\/BesoToken\.exe.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","1","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","5607"
"*/BesoToken.git*",".{0,1000}\/BesoToken\.git.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","1","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","5608"
"*/big_shell_pwd.7z*",".{0,1000}\/big_shell_pwd\.7z.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","1","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","5618"
"*/Blank%20Grabber/Extras/hash*",".{0,1000}\/Blank\%20Grabber\/Extras\/hash.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","5692"
"*/Blank.Grabber.zip*",".{0,1000}\/Blank\.Grabber\.zip.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","5693"
"*/Blank-Grabber#download*",".{0,1000}\/Blank\-Grabber\#download.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","5694"
"*/Blank-Grabber.git*",".{0,1000}\/Blank\-Grabber\.git.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","5695"
"*/BlankOBF.py*",".{0,1000}\/BlankOBF\.py.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","5697"
"*/blindsight.exe*",".{0,1000}\/blindsight\.exe.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","1","N/A","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","5700"
"*/blindsight.git*",".{0,1000}\/blindsight\.git.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","1","N/A","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","5701"
"*/bloodhound.py*",".{0,1000}\/bloodhound\.py.{0,1000}","offensive_tool_keyword","crackmapexec","bloodhound integration with crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks ","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","5715"
"*/bloodhoundsync.py*",".{0,1000}\/bloodhoundsync\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","5725"
"*/BrowserDataGrabber.git*",".{0,1000}\/BrowserDataGrabber\.git.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","1","N/A","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","5817"
"*/BrowserGhost.git*",".{0,1000}\/BrowserGhost\.git.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","5819"
"*/BrowserGhost/releases/download/*",".{0,1000}\/BrowserGhost\/releases\/download\/.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","5820"
"*/BrowserGhost/tarball/*",".{0,1000}\/BrowserGhost\/tarball\/.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","5821"
"*/BrowserGhost/zipball/*",".{0,1000}\/BrowserGhost\/zipball\/.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","5822"
"*/Bruteforcer.*",".{0,1000}\/Bruteforcer\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","5833"
"*/brutespray.git*",".{0,1000}\/brutespray\.git.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","5842"
"*/brutespray/*",".{0,1000}\/brutespray\/.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","5843"
"*/brutespray/*",".{0,1000}\/brutespray\/.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","5844"
"*/brutespray_*",".{0,1000}\/brutespray_.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","5845"
"*/BypassCredGuard.cpp*",".{0,1000}\/BypassCredGuard\.cpp.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","5880"
"*/BypassCredGuard.exe*",".{0,1000}\/BypassCredGuard\.exe.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","5881"
"*/BypassCredGuard.git*",".{0,1000}\/BypassCredGuard\.git.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","5882"
"*/c ping 127.0.0.1 && del \\*",".{0,1000}\/c\sping\s127\.0\.0\.1\s\&\&\sdel\s\\\\.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","5890"
"*/cached-domain-credentials.html*",".{0,1000}\/cached\-domain\-credentials\.html.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","5936"
"*/cachedump.py*",".{0,1000}\/cachedump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","5937"
"*/cain.html*",".{0,1000}\/cain\.html.{0,1000}","offensive_tool_keyword","Cain&Abel","Cain & Able exploitation tool file ","T1075 - T1110 - T1071 - T1003 - T1555","TA0003 - TA0008","N/A","FIN7 - Night Dragon","Credential Access","https://github.com/undergroundwires/CEH-in-bullet-points/blob/master/chapters/08-sniffing/sniffing-tools.md","1","1","N/A","N/A","N/A","10","1067","310","2024-08-13T04:35:50Z","2021-05-11T12:38:17Z","5940"
"*/CapBypass.ps1*",".{0,1000}\/CapBypass\.ps1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","0","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","5952"
"*/cerbrutus*",".{0,1000}\/cerbrutus.{0,1000}","offensive_tool_keyword","cerbrutus","Network brute force tool. written in Python. Faster than other existing solutions (including the main leader in the network brute force market).","T1110 - T1040 - T1496","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/Cerbrutus-BruteForcer/cerbrutus","1","1","N/A","N/A","N/A","4","385","57","2021-08-22T19:05:45Z","2021-07-07T19:11:40Z","5972"
"*/certsync.git*",".{0,1000}\/certsync\.git.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","1","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","5982"
"*/cheetah.git*",".{0,1000}\/cheetah\.git.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","1","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","6004"
"*/cheetah.py*",".{0,1000}\/cheetah\.py.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","#linux","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","6005"
"*/chntpw -*",".{0,1000}\/chntpw\s\-.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#linux","N/A","10","10","N/A","N/A","N/A","N/A","6021"
"*/chntpw-140201*",".{0,1000}\/chntpw\-140201.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6022"
"*/chrome_creditcard.csv*",".{0,1000}\/chrome_creditcard\.csv.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","6023"
"*/chrome_creditcard.json*",".{0,1000}\/chrome_creditcard\.json.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","6024"
"*/chrome_decrypt.exe*",".{0,1000}\/chrome_decrypt\.exe.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","1","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","6025"
"*/chrome_decrypt.py*",".{0,1000}\/chrome_decrypt\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","6026"
"*/chrome_password.csv*",".{0,1000}\/chrome_password\.csv.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","6027"
"*/chrome_password.json*",".{0,1000}\/chrome_password\.json.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","6028"
"*/Chrome-App-Bound-Encryption-Decryption.git*",".{0,1000}\/Chrome\-App\-Bound\-Encryption\-Decryption\.git.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","1","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","6029"
"*/ChromeDump/*",".{0,1000}\/ChromeDump\/.{0,1000}","offensive_tool_keyword","chromedump","ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser","T1059.007 - T1114.001 - T1518.001 - T1552.002","TA0005 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/g4l4drim/ChromeDump","1","1","N/A","N/A","N/A","1","55","1","2024-10-12T14:07:36Z","2023-01-26T20:44:06Z","6031"
"*/ChromeKatz.git*",".{0,1000}\/ChromeKatz\.git.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","6032"
"*/ChromeStealer.git*",".{0,1000}\/ChromeStealer\.git.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","1","N/A","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","6035"
"*/chromium_based_browsers.py*",".{0,1000}\/chromium_based_browsers\.py.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","1","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","6036"
"*/cme smb *",".{0,1000}\/cme\ssmb\s.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","#linux","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","6112"
"*/cme winrm *",".{0,1000}\/cme\swinrm\s.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","#linux","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","6113"
"*/cmedb",".{0,1000}\/cmedb","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral move","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","6117"
"*/comsvcs_stealth.py*",".{0,1000}\/comsvcs_stealth\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","6177"
"*/crack.sh/get-cracking/*",".{0,1000}\/\/crack\.sh\/get\-cracking\/.{0,1000}","offensive_tool_keyword","crack.sh","crack.sh THE WORLD???S FASTEST DES CRACKER. Used by attackers to submit passwords to crack","T1110.002 - T1021.002","TA0006 - TA0008","N/A","N/A","Credential Access","https://crack.sh/get-cracking/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6212"
"*/cracked-users.txt*",".{0,1000}\/cracked\-users\.txt.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","0","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","6219"
"*/cracklord.git*",".{0,1000}\/cracklord\.git.{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","6220"
"*/cracklord/cmd/*",".{0,1000}\/cracklord\/cmd\/.{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","6221"
"*/creddump7*.py*",".{0,1000}\/creddump7.{0,1000}\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","6239"
"*/creddump7.git*",".{0,1000}\/creddump7\.git.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","6240"
"*/creddump7.git*",".{0,1000}\/creddump7\.git.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","6241"
"*/creddump7/*",".{0,1000}\/creddump7\/.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","6242"
"*/creddump7/releases/*",".{0,1000}\/creddump7\/releases\/.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","6244"
"*/credentials/SudoSnatch*",".{0,1000}\/credentials\/SudoSnatch.{0,1000}","offensive_tool_keyword","sudoSnatch","sudoSnatch payload grabs sudo password in plain text and imediately after target uses sudo command and sends it back to attacker remotely/locally.","T1552.001 - T1056.001 - T1071.001","TA0006 - TA0004 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SudoSnatch","1","1","#linux","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","6251"
"*/credentials/wifigrabber*",".{0,1000}\/credentials\/wifigrabber.{0,1000}","offensive_tool_keyword","wifigrabber","grab wifi password and exfiltrate to a given site","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","6252"
"*/CredMaster.git*",".{0,1000}\/CredMaster\.git.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","6257"
"*/credmaster.py*",".{0,1000}\/credmaster\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","6258"
"*/credmaster.txt*",".{0,1000}\/credmaster\.txt.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#linux","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","6259"
"*/CredMaster-master.zip*",".{0,1000}\/CredMaster\-master\.zip.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","6260"
"*/credmaster-success.txt*",".{0,1000}\/credmaster\-success\.txt.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#linux","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","6261"
"*/credmaster-validusers.txt*",".{0,1000}\/credmaster\-validusers\.txt.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#linux","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","6262"
"*/CredPhisher.exe*",".{0,1000}\/CredPhisher\.exe.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","1","N/A","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","6264"
"*/creds-*/creds.zip*",".{0,1000}\/creds\-.{0,1000}\/creds\.zip.{0,1000}","offensive_tool_keyword","DefaultCreds-cheat-sheet","One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password","T1110.001 - T1110.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/ihebski/DefaultCreds-cheat-sheet","1","1","N/A","N/A","N/A","10","6048","726","2025-04-15T13:13:19Z","2021-01-01T19:02:36Z","6268"
"*/crunch-wordlist/*",".{0,1000}\/crunch\-wordlist\/.{0,1000}","offensive_tool_keyword","crunch","Generate a dictionary file containing words with a minimum and maximum length","T1596 - T1596.001","TA0043","N/A","N/A","Credential Access","https://sourceforge.net/projects/crunch-wordlist/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6298"
"*/cstealer.git*",".{0,1000}\/cstealer\.git.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","1","N/A","N/A","10","","N/A","","","","6322"
"*/cstealer.py*",".{0,1000}\/cstealer\.py.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","1","N/A","N/A","10","","N/A","","","","6323"
"*/dafthack/MSOLSpray*",".{0,1000}\/dafthack\/MSOLSpray.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","6396"
"*/DanMcInerney/ridenum*",".{0,1000}\/DanMcInerney\/ridenum.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","6400"
"*/DarkCoderSc/*",".{0,1000}\/DarkCoderSc\/.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","6406"
"*/DCSyncer.git*",".{0,1000}\/DCSyncer\.git.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","6472"
"*/DCSyncer/releases/download/*",".{0,1000}\/DCSyncer\/releases\/download\/.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","6473"
"*/DCSyncer/tarball/*",".{0,1000}\/DCSyncer\/tarball\/.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","6474"
"*/DCSyncer/zipball/*",".{0,1000}\/DCSyncer\/zipball\/.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","6475"
"*/DeathStar/DeathStar.py*",".{0,1000}\/DeathStar\/DeathStar\.py.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","6484"
"*/decipher_mremoteng.iml*",".{0,1000}\/decipher_mremoteng\.iml.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","6488"
"*/DecryptAutoLogon.exe*",".{0,1000}\/DecryptAutoLogon\.exe.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","1","N/A","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","6490"
"*/DecryptAutoLogon.git*",".{0,1000}\/DecryptAutoLogon\.git.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","1","N/A","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","6491"
"*/decrypt-chrome-passwords*",".{0,1000}\/decrypt\-chrome\-passwords.{0,1000}","offensive_tool_keyword","decrypt-chrome-passwords","A simple program to decrypt chrome password saved on your machine.","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/ohyicong/decrypt-chrome-passwords","1","1","N/A","N/A","10","10","966","211","2024-07-31T14:08:55Z","2020-12-28T15:11:12Z","6492"
"*/decrypted.dmp*",".{0,1000}\/decrypted\.dmp.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","6493"
"*/decrypting-lsa-secrets.html*",".{0,1000}\/decrypting\-lsa\-secrets\.html.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","6494"
"*/decrypting-lsa-secrets.html*",".{0,1000}\/decrypting\-lsa\-secrets\.html.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","6496"
"*/Decrypt-RDCMan.ps1*",".{0,1000}\/Decrypt\-RDCMan\.ps1.{0,1000}","offensive_tool_keyword","Decrypt-RDCMan","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1","1","1","N/A","N/A","9","1","1","1","2016-12-01T14:06:24Z","2017-11-22T23:18:39Z","6497"
"*/DecryptRDCManager.git*",".{0,1000}\/DecryptRDCManager\.git.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","1","N/A","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","6498"
"*/DecryptTeamViewer.exe*",".{0,1000}\/DecryptTeamViewer\.exe.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","1","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","6500"
"*/DecryptTeamViewer.git*",".{0,1000}\/DecryptTeamViewer\.git.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","1","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","6501"
"*/DefaultCreds_db.json*",".{0,1000}\/DefaultCreds_db\.json.{0,1000}","offensive_tool_keyword","DefaultCreds-cheat-sheet","One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password","T1110.001 - T1110.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/ihebski/DefaultCreds-cheat-sheet","1","1","N/A","N/A","N/A","10","6048","726","2025-04-15T13:13:19Z","2021-01-01T19:02:36Z","6508"
"*/DelegationBOF/*",".{0,1000}\/DelegationBOF\/.{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","1","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","6521"
"*/dementor.py*",".{0,1000}\/dementor\.py.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","1","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","6525"
"*/dicassassin.7z*",".{0,1000}\/dicassassin\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","6571"
"*/dirbuster/*",".{0,1000}\/dirbuster\/.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","6583"
"*/Disable_defender.py*",".{0,1000}\/Disable_defender\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","6603"
"*/DitExplorer.git*",".{0,1000}\/DitExplorer\.git.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","6619"
"*/DitExplorer/releases/download/*",".{0,1000}\/DitExplorer\/releases\/download\/.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","6620"
"*/DitExplorer/releases/tag/v*",".{0,1000}\/DitExplorer\/releases\/tag\/v.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","6621"
"*/DitExplorer/tarball/*",".{0,1000}\/DitExplorer\/tarball\/.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","6622"
"*/DitExplorer/zipball/*",".{0,1000}\/DitExplorer\/zipball\/.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","6623"
"*/dllinject.py*",".{0,1000}\/dllinject\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","6640"
"*/dnsspoof.c*",".{0,1000}\/dnsspoof\.c.{0,1000}","offensive_tool_keyword","dsniff","password sniffer. handles FTP. Telnet. SMTP. HTTP. POP. poppass. NNTP. IMAP. SNMP. LDAP. Rlogin. RIP. OSPF. PPTP MS-CHAP. NFS. VRRP. YP/NIS. SOCKS. X11. CVS. IRC. AIM. ICQ. Napster. PostgreSQL. Meeting Maker. Citrix ICA. Symantec pcAnywhere. NAI Sniffer. Microsoft SMB. Oracle SQL*Net. Sybase and Microsoft SQL auth info. dsniff automatically detects and minimally parses each application protocol. only saving the interesting bits. and uses Berkeley DB as its output file format. only logging unique authentication attempts. full TCP/IP reassembly is provided by libnids(3) (likewise for the following tools as well).","T1110 - T1040 - T1074.001 - T1555.002 - T1555.003","TA0001 - TA0002 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/tecknicaltom/dsniff","1","0","#linux","N/A","N/A","3","208","47","2010-06-29T05:53:39Z","2010-06-23T13:11:11Z","6696"
"*/DomainPasswordSpray.git*",".{0,1000}\/DomainPasswordSpray\.git.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","6724"
"*/domcachedump.py*",".{0,1000}\/domcachedump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","6727"
"*/DonPAPI.git*",".{0,1000}\/DonPAPI\.git.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","6734"
"*/DonPAPI.py*",".{0,1000}\/DonPAPI\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","6735"
"*/download/LsassDumping/*",".{0,1000}\/download\/LsassDumping\/.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","1","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","6753"
"*/download/pcunlocker*",".{0,1000}\/download\/pcunlocker.{0,1000}","greyware_tool_keyword","pcunlocker","Reset and unlock forgotten Windows login password","T1078","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://www.pcunlocker.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","6754"
"*/dpat.py*",".{0,1000}\/dpat\.py.{0,1000}","offensive_tool_keyword","DPAT","Domain Password Audit Tool for Pentesters","T1003 - T1087 - T1110 - T1555","TA0006 - TA0004 - TA0002 - TA0005","N/A","N/A","Credential Access","https://github.com/clr2of8/DPAT","1","0","N/A","N/A","10","10","954","156","2022-06-24T21:41:43Z","2016-11-22T22:00:21Z","6779"
"*/dploot.git*",".{0,1000}\/dploot\.git.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","6782"
"*/DragonCastle.git*",".{0,1000}\/DragonCastle\.git.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","1","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","6783"
"*/DragonCastle.pdb*",".{0,1000}\/DragonCastle\.pdb.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","1","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","6784"
"*/dragoncastle.py*",".{0,1000}\/dragoncastle\.py.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","1","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","6785"
"*/DriverDump.exe*",".{0,1000}\/DriverDump\.exe.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","6790"
"*/dsniff.c*",".{0,1000}\/dsniff\.c.{0,1000}","offensive_tool_keyword","dsniff","password sniffer. handles FTP. Telnet. SMTP. HTTP. POP. poppass. NNTP. IMAP. SNMP. LDAP. Rlogin. RIP. OSPF. PPTP MS-CHAP. NFS. VRRP. YP/NIS. SOCKS. X11. CVS. IRC. AIM. ICQ. Napster. PostgreSQL. Meeting Maker. Citrix ICA. SymantecpcAnywhere. NAI Sniffer. Microsoft SMB. Oracle SQL*Net. Sybase and Microsoft SQL auth info. dsniff automatically detects and minimally parses each application protocol. only saving the interesting bits. and uses Berkeley DB as its output file format. only logging unique authentication attempts. full TCP/IP reassembly is provided by libnids(3) (likewise for the following tools as well).","T1110 - T1040 - T1074.001 - T1555.002 - T1555.003","TA0001 - TA0002 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/tecknicaltom/dsniff","1","0","#linux","N/A","N/A","3","208","47","2010-06-29T05:53:39Z","2010-06-23T13:11:11Z","6806"
"*/dsniff.services*",".{0,1000}\/dsniff\.services.{0,1000}","offensive_tool_keyword","dsniff","password sniffer. handles FTP. Telnet. SMTP. HTTP. POP. poppass. NNTP. IMAP. SNMP. LDAP. Rlogin. RIP. OSPF. PPTP MS-CHAP. NFS. VRRP. YP/NIS. SOCKS. X11. CVS. IRC. AIM. ICQ. Napster. PostgreSQL. Meeting Maker. Citrix ICA. Symantec pcAnywhere. NAI Sniffer. Microsoft SMB. Oracle SQL*Net. Sybase and Microsoft SQL auth info. dsniff automatically detects and minimally parses each application protocol. only saving the interesting bits. and uses Berkeley DB as its output file format. only logging unique authentication attempts. full TCP/IP reassembly is provided by libnids(3) (likewise for the following tools as well).","T1110 - T1040 - T1074.001 - T1555.002 - T1555.003","TA0001 - TA0002 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/tecknicaltom/dsniff","1","0","#linux","N/A","N/A","3","208","47","2010-06-29T05:53:39Z","2010-06-23T13:11:11Z","6807"
"*/DUBrute.git*",".{0,1000}\/DUBrute\.git.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","1","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","6808"
"*/DumpAADSyncCreds.git*",".{0,1000}\/DumpAADSyncCreds\.git.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","1","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","6822"
"*/dumper2020.git*",".{0,1000}\/dumper2020\.git.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","1","N/A","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","6827"
"*/dumper2020_exe*",".{0,1000}\/dumper2020_exe.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","1","N/A","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","6828"
"*/dumpert.py*",".{0,1000}\/dumpert\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","6830"
"*/DumpIt.exe*",".{0,1000}\/DumpIt\.exe.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","1","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","6832"
"*/DumpLSASS.git*",".{0,1000}\/DumpLSASS\.git.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","1","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","6833"
"*/Dump-Lsass.git*",".{0,1000}\/Dump\-Lsass\.git.{0,1000}","offensive_tool_keyword","impacket","Dump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems.","T1021 - T1047 - T1055.011 - T1003","TA0002 - TA0005 - TA0006","N/A","Dispossessor - Black Basta","Credential Access","https://github.com/kaluche/Dump-Lsass","1","1","N/A","N/A","10","1","1","0","2019-11-14T18:15:26Z","2019-11-20T20:26:27Z","6834"
"*/dump-lsass.py*",".{0,1000}\/dump\-lsass\.py.{0,1000}","offensive_tool_keyword","impacket","Dump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems.","T1021 - T1047 - T1055.011 - T1003","TA0002 - TA0005 - TA0006","N/A","Dispossessor - Black Basta","Credential Access","https://github.com/kaluche/Dump-Lsass","1","1","N/A","N/A","10","1","1","0","2019-11-14T18:15:26Z","2019-11-20T20:26:27Z","6836"
"*/dumpmethod/*.py",".{0,1000}\/dumpmethod\/.{0,1000}\.py","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","6837"
"*/DumpNParse.exe*",".{0,1000}\/DumpNParse\.exe.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","1","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","6838"
"*/DumpNParse.git*",".{0,1000}\/DumpNParse\.git.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","1","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","6839"
"*/DumpS1.ps1*",".{0,1000}\/DumpS1\.ps1.{0,1000}","greyware_tool_keyword","SentinelAgent","dump a process with SentinelAgent.exe","T1003 - T1055","TA0006 - TA0005","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e","1","0","N/A","N/A","8","7","N/A","N/A","N/A","N/A","6841"
"*/dumpSecrets.go*",".{0,1000}\/dumpSecrets\.go.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","6842"
"*/dumpsecrets_test.go*",".{0,1000}\/dumpsecrets_test\.go.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","6843"
"*/DumpShellcode/*",".{0,1000}\/DumpShellcode\/.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","6844"
"*/DumpSvc.exe*",".{0,1000}\/DumpSvc\.exe.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","6846"
"*/DumpThatLSASS.*",".{0,1000}\/DumpThatLSASS\..{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","1","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","6847"
"*/DumpThatLSASS.git*",".{0,1000}\/DumpThatLSASS\.git.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","1","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","6848"
"*/DumpThatLSASS/*",".{0,1000}\/DumpThatLSASS\/.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","1","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","6849"
"*/dumpweb.log*",".{0,1000}\/dumpweb\.log.{0,1000}","offensive_tool_keyword","chromedump","ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser","T1059.007 - T1114.001 - T1518.001 - T1552.002","TA0005 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/g4l4drim/ChromeDump","1","1","#logfile #linux","N/A","N/A","1","55","1","2024-10-12T14:07:36Z","2023-01-26T20:44:06Z","6850"
"*/dumpy.exe*",".{0,1000}\/dumpy\.exe.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","1","N/A","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","6853"
"*/Dumpy.git*",".{0,1000}\/Dumpy\.git.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","1","N/A","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","6854"
"*/EASSniper.git*",".{0,1000}\/EASSniper\.git.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","1","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","6871"
"*/EASSniper.ps1*",".{0,1000}\/EASSniper\.ps1.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","1","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","6872"
"*/EASSniper.ps1*",".{0,1000}\/EASSniper\.ps1.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","6873"
"*/eas-valid-users.txt*",".{0,1000}\/eas\-valid\-users\.txt.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","#linux","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","6874"
"*/enum_av.py*",".{0,1000}\/enum_av\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","6955"
"*/ETWHash/*",".{0,1000}\/ETWHash\/.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","1","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","7046"
"*/EvilLsassTwin*",".{0,1000}\/EvilLsassTwin.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","7080"
"*/EvilLsassTwin/*",".{0,1000}\/EvilLsassTwin\/.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","7081"
"*/EvilTwinServer*",".{0,1000}\/EvilTwinServer.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","7094"
"*/exported_credentials.csv*",".{0,1000}\/exported_credentials\.csv.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","#linux","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","7149"
"*/extpassword.zip*",".{0,1000}\/extpassword\.zip.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","7159"
"*/ExtractBitlockerKeys.git*",".{0,1000}\/ExtractBitlockerKeys\.git.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","1","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","7161"
"*/fakelogonscreen.exe*",".{0,1000}\/fakelogonscreen.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","7169"
"*/fakelogonscreen.git*",".{0,1000}\/fakelogonscreen\.git.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","7170"
"*/fakelogonscreen/releases/download/*",".{0,1000}\/fakelogonscreen\/releases\/download\/.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","7171"
"*/fakelogonscreen/tarball/*",".{0,1000}\/fakelogonscreen\/tarball\/.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","7172"
"*/fakelogonscreen/zipball/*",".{0,1000}\/fakelogonscreen\/zipball\/.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","7173"
"*/Farmer.git*",".{0,1000}\/Farmer\.git.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","1","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","7176"
"*/fb_firstlast.7z*",".{0,1000}\/fb_firstlast\.7z.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","7179"
"*/fb-brute.pl*",".{0,1000}\/fb\-brute\.pl.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://raw.githubusercontent.com/Sup3r-Us3r/scripts/master/fb-brute.pl","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","7180"
"*/fern-wifi-cracker/*",".{0,1000}\/fern\-wifi\-cracker\/.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","7184"
"*/fgdump.git*",".{0,1000}\/fgdump\.git.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","1","N/A","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","7189"
"*/find_domain.sh*",".{0,1000}\/find_domain\.sh.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","7202"
"*/firefox_decrypt.git*",".{0,1000}\/firefox_decrypt\.git.{0,1000}","offensive_tool_keyword","firefox_decrypt","Firefox Decrypt is a tool to extract passwords from Mozilla","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/unode/firefox_decrypt","1","1","N/A","N/A","10","10","2172","317","2024-11-08T13:52:34Z","2014-01-17T13:25:02Z","7210"
"*/firefox_decrypt.py*",".{0,1000}\/firefox_decrypt\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","7211"
"*/Forensike.git*",".{0,1000}\/Forensike\.git.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","1","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","7228"
"*/Forensike.ps1*",".{0,1000}\/Forensike\.ps1.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","1","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","7229"
"*/forkatz.filters*",".{0,1000}\/forkatz\.filters.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","7235"
"*/forkatz.git*",".{0,1000}\/forkatz\.git.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","7236"
"*/format:hashcat*",".{0,1000}\/format\:hashcat.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","7240"
"*/FormThief.git*",".{0,1000}\/FormThief\.git.{0,1000}","offensive_tool_keyword","FormThief","Spoofing desktop login applications with WinForms and WPF","T1204.002 - T1056.004 - T1071.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/mlcsec/FormThief","1","1","N/A","N/A","8","2","173","31","2024-02-19T22:40:09Z","2024-02-19T22:34:07Z","7241"
"*/Gemail-Hack.git*",".{0,1000}\/Gemail\-Hack\.git.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/Ha3MrX/Gemail-Hack","1","1","N/A","N/A","7","10","1062","400","2024-01-17T15:12:44Z","2018-04-19T13:48:41Z","7346"
"*/getlsasrvaddr.exe*",".{0,1000}\/getlsasrvaddr\.exe.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","1","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","7372"
"*/Get-NetNTLM.git*",".{0,1000}\/Get\-NetNTLM\.git.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","1","N/A","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","7373"
"*/Get-NetNTLM.ps1*",".{0,1000}\/Get\-NetNTLM\.ps1.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","1","N/A","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","7374"
"*/get-shucking.php*",".{0,1000}\/get\-shucking\.php.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","7384"
"*/GlobalUnProtect.git*",".{0,1000}\/GlobalUnProtect\.git.{0,1000}","offensive_tool_keyword","GlobalUnProtect","Decrypt GlobalProtect configuration and cookie files.","T1552 - T1003 - T1555","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rotarydrone/GlobalUnProtect","1","1","N/A","N/A","9","2","147","19","2024-09-10T20:19:24Z","2024-09-04T15:31:52Z","7526"
"*/gMSADumper*",".{0,1000}\/gMSADumper.{0,1000}","offensive_tool_keyword","gMSADumper","Lists who can read any gMSA password blobs and parses them if the current user has access.","T1552.001 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/micahvandeusen/gMSADumper","1","1","N/A","N/A","N/A","3","274","51","2024-02-12T02:15:32Z","2021-04-10T00:15:24Z","7532"
"*/GMSAPasswordReader.git*",".{0,1000}\/GMSAPasswordReader\.git.{0,1000}","offensive_tool_keyword","GMSAPasswordReader","Reads the password blob from a GMSA account using LDAP and parses the values into hashes for re-use.","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/rvazarkar/GMSAPasswordReader","1","1","N/A","N/A","7","3","219","34","2023-02-17T14:37:40Z","2020-01-19T19:06:20Z","7537"
"*/GoAWSConsoleSpray.git*",".{0,1000}\/GoAWSConsoleSpray\.git.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","1","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","7538"
"*/gocrack.git*",".{0,1000}\/gocrack\.git.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","1","N/A","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","7544"
"*/gocrack/.hashcat*",".{0,1000}\/gocrack\/\.hashcat.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","7545"
"*/gocrack/server*",".{0,1000}\/gocrack\/server.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","7546"
"*/gocrack_server*",".{0,1000}\/gocrack_server.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","7547"
"*/gocrack_worker*",".{0,1000}\/gocrack_worker.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","7548"
"*/gocrack-1.0.zip*",".{0,1000}\/gocrack\-1\.0\.zip.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","7549"
"*/GoldenGMSA.git*",".{0,1000}\/GoldenGMSA\.git.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","1","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","7567"
"*/go-lsass.exe*",".{0,1000}\/go\-lsass\.exe.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","1","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","7571"
"*/go-lsass.git*",".{0,1000}\/go\-lsass\.git.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","1","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","7572"
"*/go-lsass/releases*",".{0,1000}\/go\-lsass\/releases.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","1","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","7573"
"*/go-lsass-master.zip*",".{0,1000}\/go\-lsass\-master\.zip.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","1","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","7574"
"*/go-secdump.git*",".{0,1000}\/go\-secdump\.git.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","1","N/A","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","7590"
"*/gosecretsdump.*",".{0,1000}\/gosecretsdump\..{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","7592"
"*/gosecretsdump/*",".{0,1000}\/gosecretsdump\/.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","7593"
"*/gosecretsdump_linux*",".{0,1000}\/gosecretsdump_linux.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","#linux","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","7594"
"*/gosecretsdump_mac*",".{0,1000}\/gosecretsdump_mac.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","7595"
"*/gosecretsdump_win*",".{0,1000}\/gosecretsdump_win.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","7596"
"*/gpp-decrypt*",".{0,1000}\/gpp\-decrypt.{0,1000}","offensive_tool_keyword","gpp-decrypt","Decrypt the given Group Policy Preferences","T1552.002 - T1212","TA0009 - TA0006","N/A","N/A","Credential Access","https://gitlab.com/kalilinux/packages/gpp-decrypt","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","7614"
"*/grabchrome.exe*",".{0,1000}\/grabchrome\.exe.{0,1000}","offensive_tool_keyword","GrabChrome","HelloKitty Grabber used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","7616"
"*/gsecdump-*.exe*",".{0,1000}\/gsecdump\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","7641"
"*/gsecdump.exe*",".{0,1000}\/gsecdump\.exe.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","7642"
"*/HackBrowserData.git*",".{0,1000}\/HackBrowserData\.git.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7692"
"*/hack-browser-data-linux-386.zip*",".{0,1000}\/hack\-browser\-data\-linux\-386\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7693"
"*/hack-browser-data-linux-amd64.zip*",".{0,1000}\/hack\-browser\-data\-linux\-amd64\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7694"
"*/hack-browser-data-linux-arm.zip*",".{0,1000}\/hack\-browser\-data\-linux\-arm\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7695"
"*/hack-browser-data-linux-arm64.zip*",".{0,1000}\/hack\-browser\-data\-linux\-arm64\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","#linux","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7696"
"*/hack-browser-data-osx-64bit.zip*",".{0,1000}\/hack\-browser\-data\-osx\-64bit\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7697"
"*/hack-browser-data-windows-32bit.zip*",".{0,1000}\/hack\-browser\-data\-windows\-32bit\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7698"
"*/hack-browser-data-windows-64bit.zip*",".{0,1000}\/hack\-browser\-data\-windows\-64bit\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","7699"
"*/hashcat-rule.git*",".{0,1000}\/hashcat\-rule\.git.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","7727"
"*/hashcrack_com.rb*",".{0,1000}\/hashcrack_com\.rb.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","7728"
"*/hashcracking.rb*",".{0,1000}\/hashcracking\.rb.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","7729"
"*/hashesorg2019.gz*",".{0,1000}\/hashesorg2019\.gz.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","7731"
"*/hashview.py*",".{0,1000}\/hashview\.py.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","7733"
"*/httprelayserver.py*",".{0,1000}\/httprelayserver\.py.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","7917"
"*/hydra -*",".{0,1000}hydra\s\-.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","7990"
"*/icebreaker.git*",".{0,1000}\/icebreaker\.git.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","8005"
"*/icebreaker.py*",".{0,1000}\/icebreaker\.py.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","8006"
"*/iepv.exe*",".{0,1000}\/iepv\.exe.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","8015"
"*/ike-crack.*",".{0,1000}\/ike\-crack\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","8023"
"*/impacketfile.py*",".{0,1000}\/impacketfile\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","8038"
"*/insta-bf.git*",".{0,1000}\/insta\-bf\.git.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","1","N/A","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","8094"
"*/instabf.py*",".{0,1000}\/instabf\.py.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","1","N/A","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","8095"
"*/instainsane.git*",".{0,1000}\/instainsane\.git.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/umeshshinde19/instainsane","1","1","N/A","N/A","7","7","655","371","2024-02-11T10:29:05Z","2018-12-02T22:48:11Z","8097"
"*/instainsane.sh*",".{0,1000}\/instainsane\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/umeshshinde19/instainsane","1","1","N/A","N/A","7","7","655","371","2024-02-11T10:29:05Z","2018-12-02T22:48:11Z","8098"
"*/install-sb.sh*",".{0,1000}\/install\-sb\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","1","N/A","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","8102"
"*/insTof.py*",".{0,1000}\/insTof\.py.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","1","N/A","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","8104"
"*/Invoke-CleverSpray.git*",".{0,1000}\/Invoke\-CleverSpray\.git.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","1","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","8145"
"*/Invoke-RDPThief.git*",".{0,1000}\/Invoke\-RDPThief\.git.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","1","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","8160"
"*/john -*",".{0,1000}\/john\s\-.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","8241"
"*/john/run/*.pl*",".{0,1000}\/john\/run\/.{0,1000}\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","8243"
"*/john/run/*.py*",".{0,1000}\/john\/run\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","8244"
"*/JohnTheRipper*",".{0,1000}\/JohnTheRipper.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","8246"
"*/KeeFarce.exe*",".{0,1000}\/KeeFarce\.exe.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","1","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","8297"
"*/KeeFarce.git*",".{0,1000}\/KeeFarce\.git.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","1","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","8298"
"*/KeeFarceDLL.dll*",".{0,1000}\/KeeFarceDLL\.dll.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","1","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","8299"
"*/keepwn.core.*",".{0,1000}\/keepwn\.core.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8303"
"*/KeePwn.git*",".{0,1000}\/KeePwn\.git.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8304"
"*/KeePwn.py*",".{0,1000}\/KeePwn\.py.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8305"
"*/keepwn.utils.*",".{0,1000}\/keepwn\.utils.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8306"
"*/KeePwn/keepwn/*",".{0,1000}\/KeePwn\/keepwn\/.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8307"
"*/KeePwn/tarball/*",".{0,1000}\/KeePwn\/tarball\/.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8308"
"*/KeePwn/zipball/*",".{0,1000}\/KeePwn\/zipball\/.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8309"
"*/KeePwn-0.3/*",".{0,1000}\/KeePwn\-0\.3\/.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","8310"
"*/KeeTheft.exe*",".{0,1000}\/KeeTheft\.exe.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","8312"
"*/KeeThief.git*",".{0,1000}\/KeeThief\.git.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","8314"
"*/KeeThief.git*",".{0,1000}\/KeeThief\.git.{0,1000}","offensive_tool_keyword","KeeThiefSyscalls","Patch GhostPack/KeeThief for it to use DInvoke and syscalls","T1003.001 - T1558.002","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/Metro-Holografix/KeeThiefSyscalls","1","1","N/A","private github repo","10","","N/A","","","","8315"
"*/KeeThief.ps1*",".{0,1000}\/KeeThief\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","8316"
"*/KerberOPSEC.git*",".{0,1000}\/KerberOPSEC\.git.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","8327"
"*/kerberos.py*",".{0,1000}\/kerberos\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","8328"
"*/kerberosticket.py*",".{0,1000}\/kerberosticket\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","8330"
"*/kerbrute.git*",".{0,1000}\/kerbrute\.git.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","8333"
"*/kerbrute.go*",".{0,1000}\/kerbrute\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","8334"
"*/kerbrute.py*",".{0,1000}\/kerbrute\.py.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","8335"
"*/kerbrute/*",".{0,1000}\/kerbrute\/.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","8336"
"*/KeyCredentialLink.git*",".{0,1000}\/KeyCredentialLink\.git.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","1","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","8339"
"*/KeyCredentialLink.ps1*",".{0,1000}\/KeyCredentialLink\.ps1.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","1","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","8340"
"*/Kill_protector.py*",".{0,1000}\/Kill_protector\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8357"
"*/knowsmore.cmd*",".{0,1000}\/knowsmore\.cmd.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","8382"
"*/knowsmore.db*",".{0,1000}\/knowsmore\.db.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","8383"
"*/knowsmore.git*",".{0,1000}\/knowsmore\.git.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","8384"
"*/knowsmore.py*",".{0,1000}\/knowsmore\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","8385"
"*/label-date-lsass.dmp*",".{0,1000}\/label\-date\-lsass\.dmp.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","#content","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","8419"
"*/laps.py *--ldapserver*",".{0,1000}\/laps\.py\s.{0,1000}\-\-ldapserver.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","0","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","8437"
"*/laps.py *-u * -p *",".{0,1000}\/laps\.py\s.{0,1000}\-u\s.{0,1000}\s\-p\s.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","0","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","8438"
"*/LAPSDumper.git*",".{0,1000}\/LAPSDumper\.git.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","1","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","8441"
"*/lastpass.py*",".{0,1000}\/lastpass\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","8447"
"*/LaZagne.git*",".{0,1000}\/LaZagne\.git.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","8458"
"*/laZagne.py*",".{0,1000}\/laZagne\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","8459"
"*/LDAPWordlistHarvester.git*",".{0,1000}\/LDAPWordlistHarvester\.git.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","1","N/A","N/A","5","4","N/A","N/A","N/A","N/A","8483"
"*/legba.git*",".{0,1000}\/legba\.git.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","1","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","8487"
"*/legba/target/release/legba*",".{0,1000}\/legba\/target\/release\/legba.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","#linux","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","8488"
"*/LetMeowIn.git*",".{0,1000}\/LetMeowIn\.git.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","1","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","8491"
"*/lgandx/Responder*",".{0,1000}\/lgandx\/Responder.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","8496"
"*/lnkbomb.git*",".{0,1000}\/lnkbomb\.git.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","1","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","8562"
"*/lnkbomb.py*",".{0,1000}\/lnkbomb\.py.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","1","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","8563"
"*/load_ssp.x64.exe*",".{0,1000}\/load_ssp\.x64\.exe.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","8566"
"*/localbrute-extra-mini.ps1*",".{0,1000}\/localbrute\-extra\-mini\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Credential Access","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","1","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","8583"
"*/loginAAD.ps1*",".{0,1000}\/loginAAD\.ps1.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","8613"
"*/login-securite/DonPAPI*",".{0,1000}\/login\-securite\/DonPAPI.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","8614"
"*/logonuifox.dll*",".{0,1000}\/logonuifox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","8616"
"*/lsadump.py*",".{0,1000}\/lsadump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","8638"
"*/lsarelayx.git*",".{0,1000}\/lsarelayx\.git.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","1","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","8639"
"*/lsasecrets.py*",".{0,1000}\/lsasecrets\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","8640"
"*/lsass.DMP*",".{0,1000}\/lsass\.DMP.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","8641"
"*/lsass.rar*",".{0,1000}\/lsass\.rar.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","1","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","8642"
"*/lsass.zip*",".{0,1000}\/lsass\.zip.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","1","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","8643"
"*/Lsass_Shtinkering.cpp*",".{0,1000}\/Lsass_Shtinkering\.cpp.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","8645"
"*/Lsass_Shtinkering.exe*",".{0,1000}\/Lsass_Shtinkering\.exe.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","8646"
"*/lsass64.exe*",".{0,1000}\/lsass64\.exe.{0,1000}","offensive_tool_keyword","lslsass","dump active logon session password hashes from the lsass process (old tool for vista and older)","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","8647"
"*/LsassReflectDumping.git*",".{0,1000}\/LsassReflectDumping\.git.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","1","N/A","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","8649"
"*/Lsass-Shtinkering.git*",".{0,1000}\/Lsass\-Shtinkering\.git.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","8650"
"*/LsassSilentProcessExit.git*",".{0,1000}\/LsassSilentProcessExit\.git.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","8651"
"*/Lsassx.git*",".{0,1000}\/Lsassx\.git.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","1","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","8652"
"*/Lsassx.ps1*",".{0,1000}\/Lsassx\.ps1.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","1","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","8653"
"*/Lsassx-OBF.ps1*",".{0,1000}\/Lsassx\-OBF\.ps1.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","1","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","8654"
"*/lsassy*",".{0,1000}\/lsassy.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","8655"
"*/lsassy/releases/download/*",".{0,1000}\/lsassy\/releases\/download\/.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","8656"
"*/lsa-whisperer-*.zip*",".{0,1000}\/lsa\-whisperer\-.{0,1000}\.zip.{0,1000}","greyware_tool_keyword","lsa-whisperer","Tools for interacting with authentication packages using their individual message protocols","T1556.002 - T1003.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/EvanMcBroom/lsa-whisperer","1","1","N/A","N/A","6","4","316","29","2025-04-01T13:54:17Z","2022-08-04T14:35:45Z","8658"
"*/lsa-whisperer.git*",".{0,1000}\/lsa\-whisperer\.git.{0,1000}","greyware_tool_keyword","lsa-whisperer","Tools for interacting with authentication packages using their individual message protocols","T1556.002 - T1003.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/EvanMcBroom/lsa-whisperer","1","1","N/A","N/A","6","4","316","29","2025-04-01T13:54:17Z","2022-08-04T14:35:45Z","8659"
"*/luna.log*",".{0,1000}\/luna\.log.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#linux","N/A","10","","N/A","","","","8664"
"*/Luna-Grabber.git*",".{0,1000}\/Luna\-Grabber\.git.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8665"
"*/Luna-Grabber/releases/download/*",".{0,1000}\/Luna\-Grabber\/releases\/download\/.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8666"
"*/Luna-Grabber/tarball/*",".{0,1000}\/Luna\-Grabber\/tarball\/.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8667"
"*/Luna-Grabber/zipball*",".{0,1000}\/Luna\-Grabber\/zipball.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8668"
"*/Luna-Grabber-Injection/main*",".{0,1000}\/Luna\-Grabber\-Injection\/main.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","8669"
"*/lyncsmash/*",".{0,1000}\/lyncsmash\/.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","8671"
"*/LyncSniper.ps1*",".{0,1000}\/LyncSniper\.ps1.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","8672"
"*/m365-fatigue.git*",".{0,1000}\/m365\-fatigue\.git.{0,1000}","offensive_tool_keyword","m365-fatigue","automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.","T1110.001 - T1078.001 - T1556.004","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/0xB455/m365-fatigue","1","1","N/A","N/A","10","1","77","7","2024-04-08T14:53:44Z","2023-11-30T13:33:03Z","8674"
"*/m365-fatigue.py*",".{0,1000}\/m365\-fatigue\.py.{0,1000}","offensive_tool_keyword","m365-fatigue","automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.","T1110.001 - T1078.001 - T1556.004","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/0xB455/m365-fatigue","1","1","N/A","N/A","10","1","77","7","2024-04-08T14:53:44Z","2023-11-30T13:33:03Z","8675"
"*/mailpv.exe*",".{0,1000}\/mailpv\.exe.{0,1000}","offensive_tool_keyword","MailPassView","Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","8691"
"*/MailSniper/*",".{0,1000}\/MailSniper\/.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","8694"
"*/malDll.dll*",".{0,1000}\/malDll\.dll.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","8707"
"*/malseclogon.*",".{0,1000}\/malseclogon\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","8712"
"*/md5cracker.rb*",".{0,1000}\/md5cracker\.rb.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","8731"
"*/memorydump.py*",".{0,1000}\/memorydump\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","8755"
"*/mimidogz.git*",".{0,1000}\/mimidogz\.git.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","8818"
"*/mimikatz.git*",".{0,1000}\/mimikatz\.git.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz github link","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8825"
"*/mimikatz/archive/master.zip*",".{0,1000}\/mimikatz\/archive\/master\.zip.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archive link","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8829"
"*/mimikatz/releases/*",".{0,1000}\/mimikatz\/releases\/.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archive link","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8830"
"*/mimikatz/zipball/*",".{0,1000}\/mimikatz\/zipball\/.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archive link","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","8831"
"*/mimilib.dll*",".{0,1000}\/mimilib\.dll.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","1","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","8838"
"*/mimipenguin.sh*",".{0,1000}\/mimipenguin\.sh.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","1","N/A","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","8845"
"*/mimipenguin/releases/download/*",".{0,1000}\/mimipenguin\/releases\/download\/.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","1","#linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","8848"
"*/mimipy.git*",".{0,1000}\/mimipy\.git.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","1","N/A","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","8849"
"*/MiniDump.git*",".{0,1000}\/MiniDump\.git.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","8852"
"*/MiniDump-main.zip*",".{0,1000}\/MiniDump\-main\.zip.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","8855"
"*/MirrorDump.exe*",".{0,1000}\/MirrorDump\.exe.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","1","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","8860"
"*/MirrorDump.git*",".{0,1000}\/MirrorDump\.git.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","1","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","8861"
"*/mobaxterm.rb*",".{0,1000}\/mobaxterm\.rb.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#linux","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","8872"
"*/mRemoteNG-Decrypt*",".{0,1000}\/mRemoteNG\-Decrypt.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/haseebT/mRemoteNG-Decrypt","1","1","N/A","N/A","8","2","146","42","2023-07-06T16:15:20Z","2019-05-27T05:25:57Z","8909"
"*/mremoteng-decrypt.git*",".{0,1000}\/mremoteng\-decrypt\.git.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","8910"
"*/mremoteng-decrypt/releases/download/*",".{0,1000}\/mremoteng\-decrypt\/releases\/download\/.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","8911"
"*/mremoteng-decrypt/tarball/*",".{0,1000}\/mremoteng\-decrypt\/tarball\/.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","8912"
"*/mremoteng-decrypt/zipball/*",".{0,1000}\/mremoteng\-decrypt\/zipball\/.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","8913"
"*/MSOLSpray*",".{0,1000}\/MSOLSpray.{0,1000}","offensive_tool_keyword","MSOLSpray","This module will perform password spraying against Microsoft Online accounts (Azure/O365)","T1110.003 - T1553.003 - T1621","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/MSOLSpray","1","1","N/A","network exploitation tool","10","10","964","174","2024-03-19T11:03:06Z","2020-03-16T13:38:22Z","8941"
"*/MSSprinkler.git*",".{0,1000}\/MSSprinkler\.git.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","1","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","8943"
"*/mssprinkler.ps1*",".{0,1000}\/mssprinkler\.ps1.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","1","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","8944"
"*/mssqlexec.py*",".{0,1000}\/mssqlexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","8952"
"*/mstscfox.dll*",".{0,1000}\/mstscfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","8961"
"*/MultiDump.exe*",".{0,1000}\/MultiDump\.exe.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","1","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","8964"
"*/MultiDump.exe*",".{0,1000}\/MultiDump\.exe.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","1","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","8965"
"*/MultiDump.git*",".{0,1000}\/MultiDump\.git.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","1","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","8966"
"*/mzcv.exe*",".{0,1000}\/mzcv\.exe.{0,1000}","greyware_tool_keyword","MozillaCookiesView","nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors","T1070 - T1552.001 - T1125 - T1005","TA0009 - TA0005","N/A","MuddyWater","Credential Access","https://www.nirsoft.net/utils/mzcv.html","1","0","N/A","N/A","7","10","N/A","N/A","N/A","N/A","8993"
"*/mzcv-x64.zip*",".{0,1000}\/mzcv\-x64\.zip.{0,1000}","greyware_tool_keyword","MozillaCookiesView","nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors","T1070 - T1552.001 - T1125 - T1005","TA0009 - TA0005","N/A","MuddyWater","Credential Access","https://www.nirsoft.net/utils/mzcv.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","8994"
"*/nanodump*",".{0,1000}\/nanodump.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","9008"
"*/NativeDump.exe*",".{0,1000}\/NativeDump\.exe.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","9015"
"*/NativeDump.git*",".{0,1000}\/NativeDump\.git.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","9016"
"*/nc_srv.bat",".{0,1000}\/nc_srv\.bat","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","9026"
"*/ncrack-*",".{0,1000}\/ncrack\-.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","0","#linux","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","9034"
"*/ncrack.git*",".{0,1000}\/ncrack\.git.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","9035"
"*/Necro-Stealer.git*",".{0,1000}\/Necro\-Stealer\.git.{0,1000}","offensive_tool_keyword","Necro-Stealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/Necro-Stealer","1","1","N/A","N/A","8","1","6","1","2022-12-06T16:06:55Z","2022-12-06T15:52:17Z","9040"
"*/nessus.py*",".{0,1000}\/nessus\.py.{0,1000}","offensive_tool_keyword","crackmapexec","parser nessus.py from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9052"
"*/Net-GPPPassword.git*",".{0,1000}\/Net\-GPPPassword\.git.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","9094"
"*/netntlm.pl*",".{0,1000}\/netntlm\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","9100"
"*/NetNTLMtoSilverTicket*",".{0,1000}\/NetNTLMtoSilverTicket.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","1","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","9101"
"*/NiceRAT.git*",".{0,1000}\/NiceRAT\.git.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","9144"
"*/NiceRAT.py*",".{0,1000}\/NiceRAT\.py.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","9145"
"*/NiceRAT-1.0.0.zip*",".{0,1000}\/NiceRAT\-1\.0\.0\.zip.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","9146"
"*/nidem/kerberoast*",".{0,1000}\/nidem\/kerberoast.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","9147"
"*/Nimperiments.git*",".{0,1000}\/Nimperiments\.git.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","9169"
"*/NLBrute*.rar*",".{0,1000}\/NLBrute.{0,1000}\.rar.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","1","N/A","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","9194"
"*/NLBrute*.zip*",".{0,1000}\/NLBrute.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","1","N/A","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","9195"
"*/NLBrute.exe*",".{0,1000}\/NLBrute\.exe.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","1","N/A","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","9196"
"*/nmap.py*",".{0,1000}\/nmap\.py.{0,1000}","offensive_tool_keyword","crackmapexec","parser nmap.py from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9197"
"*/Nofault.exe*",".{0,1000}\/Nofault\.exe.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","9225"
"*/noseyparker.git*",".{0,1000}\/noseyparker\.git.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","9242"
"*/NPPSPY.dll*",".{0,1000}\/NPPSPY\.dll.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","1","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","9252"
"*/NPPSpy.exe*",".{0,1000}\/NPPSpy\.exe.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","1","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","9253"
"*/nsa-rules.git*",".{0,1000}\/nsa\-rules\.git.{0,1000}","offensive_tool_keyword","nsa-rules","Password cracking rules and masks for hashcat that I generated from cracked passwords.","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/NSAKEY/nsa-rules","1","1","N/A","N/A","10","6","547","125","2017-01-03T11:53:25Z","2016-02-15T20:49:32Z","9258"
"*/ntdissector.git*",".{0,1000}\/ntdissector\.git.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","1","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","9271"
"*/ntdissector/*",".{0,1000}\/ntdissector\/.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","0","#linux","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","9272"
"*/ntdsuseraccount.py*",".{0,1000}\/ntdsuseraccount\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","9279"
"*/NTHASH-FPC.git*",".{0,1000}\/NTHASH\-FPC\.git.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","9282"
"*/ntlmdecoder.py*",".{0,1000}\/ntlmdecoder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","9284"
"*/ntlmdecoder.py*",".{0,1000}\/ntlmdecoder\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","9285"
"*/NTLMInjector.git*",".{0,1000}\/NTLMInjector\.git.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","1","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","9286"
"*/NTLMParse.go*",".{0,1000}\/NTLMParse\.go.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","9287"
"*/NtlmRelayToEWS.git*",".{0,1000}\/NtlmRelayToEWS\.git.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","9293"
"*/NtlmRelayToEWS/*",".{0,1000}\/NtlmRelayToEWS\/.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","9294"
"*/NTLMSleuth.git*",".{0,1000}\/NTLMSleuth\.git.{0,1000}","offensive_tool_keyword","NTLMSleuth","verify NTLM hash integrity against the robust database of ntlm.pw.","T1003 - T1555","TA0006","N/A","Black Basta","Credential Access","https://github.com/jmarr73/NTLMSleuth","1","1","N/A","N/A","8","1","8","0","2024-08-28T15:21:10Z","2023-12-12T16:41:35Z","9303"
"*/NtlmThief.git*",".{0,1000}\/NtlmThief\.git.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","9304"
"*/ntlmUserPasswords.ntlm*",".{0,1000}\/ntlmUserPasswords\.ntlm.{0,1000}","offensive_tool_keyword","DPAT","Domain Password Audit Tool for Pentesters","T1003 - T1087 - T1110 - T1555","TA0006 - TA0004 - TA0002 - TA0005","N/A","N/A","Credential Access","https://github.com/clr2of8/DPAT","1","0","N/A","N/A","10","10","954","156","2022-06-24T21:41:43Z","2016-11-22T22:00:21Z","9306"
"*/o365_enum_activesync.py*",".{0,1000}\/o365_enum_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9334"
"*/o365_enum_office.py*",".{0,1000}\/o365_enum_office\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9335"
"*/o365_enum_onedrive.py*",".{0,1000}\/o365_enum_onedrive\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9336"
"*/o365_spray_activesync.py*",".{0,1000}\/o365_spray_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9337"
"*/o365_spray_adfs.py*",".{0,1000}\/o365_spray_adfs\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9338"
"*/o365_spray_msol.py*",".{0,1000}\/o365_spray_msol\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9339"
"*/o365spray.git*",".{0,1000}\/o365spray\.git.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","1","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","9341"
"*/o365spray.py*",".{0,1000}\/o365spray\.py.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","1","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","9342"
"*/obfuscated_scripts/*",".{0,1000}\/obfuscated_scripts\/.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9346"
"*/OfflineSamTool.exe*",".{0,1000}\/OfflineSamTool\.exe.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9370"
"*/oh365userfinder.py*",".{0,1000}\/oh365userfinder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","9373"
"*/Omnispray.git*",".{0,1000}\/Omnispray\.git.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9376"
"*/omnispray.py*",".{0,1000}\/omnispray\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9377"
"*/onedrive_user_enum*",".{0,1000}\/onedrive_user_enum.{0,1000}","offensive_tool_keyword","onedrive_user_enum","enumerate valid onedrive users","T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/onedrive_user_enum","1","1","N/A","network exploitation tool","N/A","7","663","83","2025-04-17T00:13:11Z","2019-03-05T08:54:38Z","9382"
"*/operapassview.zip",".{0,1000}\/operapassview\.zip","offensive_tool_keyword","OperaPassView","OperaPassView is a small password recovery tool that decrypts the content of the Opera Web browser password file (wand.dat) and displays the list of all Web site passwords stored in this file","T1003 - T1555 - T1145","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/opera_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9398"
"*/opt/gocrack/files/engine*",".{0,1000}\/opt\/gocrack\/files\/engine.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","9410"
"*/opt/gocrack/files/task*",".{0,1000}\/opt\/gocrack\/files\/task.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","9411"
"*/opt/icebreaker*",".{0,1000}\/opt\/icebreaker.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","9414"
"*/oset.exe*",".{0,1000}\/oset\.exe.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9447"
"*/oset.zip*",".{0,1000}\/oset\.zip.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9448"
"*/oSpray.py*",".{0,1000}\/oSpray\.py.{0,1000}","offensive_tool_keyword","Okta-Password-Sprayer","This script is a multi-threaded Okta password sprayer.","T1110 - T1110.003 - T1621","TA0006","N/A","N/A","Credential Access","https://github.com/Rhynorater/Okta-Password-Sprayer","1","0","#linux","N/A","10","1","70","16","2024-01-05T16:24:38Z","2018-09-24T23:39:16Z","9452"
"*/owa_enum_activesync.py*",".{0,1000}\/owa_enum_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9465"
"*/owa_spray_activesync.py*",".{0,1000}\/owa_spray_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9466"
"*/owa-sprayed-creds.txt*",".{0,1000}\/owa\-sprayed\-creds\.txt.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","#linux","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","9468"
"*/paloalto_enum_globalprotectportal.py*",".{0,1000}\/paloalto_enum_globalprotectportal\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9493"
"*/paloalto_spray_globalprotectportal.py*",".{0,1000}\/paloalto_spray_globalprotectportal\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","9494"
"*/pamspy -p *",".{0,1000}\/pamspy\s\-p\s.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","9495"
"*/pamspy.git*",".{0,1000}\/pamspy\.git.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","1","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","9496"
"*/pass_gen.pl*",".{0,1000}\/pass_gen\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","9512"
"*/PassDetective.git*",".{0,1000}\/PassDetective\.git.{0,1000}","offensive_tool_keyword","PassDetective","PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets","T1059 - T1059.004 - T1552 - T1552.001","TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/aydinnyunus/PassDetective","1","1","N/A","N/A","7","2","129","8","2024-06-19T10:39:39Z","2023-07-22T12:31:57Z","9513"
"*/PassSpray.git*",".{0,1000}\/PassSpray\.git.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","1","N/A","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","9516"
"*/PassSpray.ps1*",".{0,1000}\/PassSpray\.ps1.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","1","N/A","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","9518"
"*/passwd_tracer.c*",".{0,1000}\/passwd_tracer\.c.{0,1000}","offensive_tool_keyword","3snake","Tool for extracting information from newly spawned processes","T1003 - T1110 - T1552 - T1505","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/blendin/3snake","1","0","#linux","N/A","7","8","752","109","2022-02-14T17:42:10Z","2018-02-07T21:03:15Z","9529"
"*/password.lst*",".{0,1000}\/password\.lst.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","9530"
"*/password_ruled.txt*",".{0,1000}\/password_ruled\.txt.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","9534"
"*/password_sniffer.html*",".{0,1000}\/password_sniffer\.html.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9535"
"*/Passwords/Common-Credentials/10k-most-common.txt*",".{0,1000}\/Passwords\/Common\-Credentials\/10k\-most\-common\.txt.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","1","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","9539"
"*/pcunlocker.iso*",".{0,1000}\/pcunlocker\.iso.{0,1000}","greyware_tool_keyword","pcunlocker","Reset and unlock forgotten Windows login password","T1078","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://www.pcunlocker.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9577"
"*/pcunlocker_trial.zip*",".{0,1000}\/pcunlocker_trial\.zip.{0,1000}","greyware_tool_keyword","pcunlocker","Reset and unlock forgotten Windows login password","T1078","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://www.pcunlocker.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9578"
"*/physmem2minidump.py*",".{0,1000}\/physmem2minidump\.py.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","1","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","9687"
"*/physmem2profit.git*",".{0,1000}\/physmem2profit\.git.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","1","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","9688"
"*/pixiewps --*",".{0,1000}\/pixiewps\s\-\-.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#linux","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","9707"
"*/pixiewps/archive/master.zip*",".{0,1000}\/pixiewps\/archive\/master\.zip.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","9708"
"*/POC/driverdump/*",".{0,1000}\/POC\/driverdump\/.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","1","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","9719"
"*/PostDump.exe*",".{0,1000}\/PostDump\.exe.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","9791"
"*/POSTDump.git*",".{0,1000}\/POSTDump\.git.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","9792"
"*/PowerBruteLogon*",".{0,1000}\/PowerBruteLogon.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","9797"
"*/PowerExtract.git*",".{0,1000}\/PowerExtract\.git.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","9801"
"*/PowerExtract.git*",".{0,1000}\/PowerExtract\.git.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","9802"
"*/ppl/ppl.c*",".{0,1000}\/ppl\/ppl\.c.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","9843"
"*/ppl_dump.*",".{0,1000}\/ppl_dump\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","9844"
"*/PPLBlade.git*",".{0,1000}\/PPLBlade\.git.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","1","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","9845"
"*/PPLFault/*",".{0,1000}\/PPLFault\/.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","9848"
"*/PPLmedic.exe*",".{0,1000}\/PPLmedic\.exe.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","1","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","9851"
"*/PPLmedic.git*",".{0,1000}\/PPLmedic\.git.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","1","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","9852"
"*/pplsystem.exe*",".{0,1000}\/pplsystem\.exe.{0,1000}","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","1","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","9853"
"*/PPLSystem.git*","\/PPLSystem\.git","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","1","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","9854"
"*/Pre2kSpray.ps1*",".{0,1000}\/Pre2kSpray\.ps1.{0,1000}","offensive_tool_keyword","Invoke-Pre2kSpray","Enumerate domain machine accounts and perform pre2k password spraying.","T1087.002 - T1110.003","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/eversinc33/Invoke-Pre2kSpray","1","1","N/A","N/A","8","1","69","11","2023-07-14T06:50:22Z","2023-07-05T10:07:38Z","9857"
"*/PredatorTheStealer.git*",".{0,1000}\/PredatorTheStealer\.git.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","1","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","9859"
"*/PrintCreds.py*",".{0,1000}\/PrintCreds\.py.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","1","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","9870"
"*/Procdump.zip*",".{0,1000}\/Procdump\.zip.{0,1000}","greyware_tool_keyword","Procdump","dump lsass process with procdump","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","9907"
"*/ProduKey.exe*",".{0,1000}\/ProduKey\.exe.{0,1000}","greyware_tool_keyword","produkey","ProduKey is a small utility that displays the ProductID and the CD-Key of Microsoft Office (Microsoft Office 2003. Microsoft Office 2007). Windows (Including Windows 8/7/Vista). Exchange Server. and SQL Server installed on your computer. You can view this information for your current running operating system. or for another operating system/computer - by using command-line options. This utility can be useful if you lost the product key of your Windows/Office. and you want to reinstall it on your computer.","T1003.001 - T1003.002 - T1012 - T1057 - T1518","TA0006 - TA0007 - TA0009","N/A","Evilnum","Credential Access","https://www.nirsoft.net/utils/product_cd_key_viewer.html","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","9915"
"*/protocols/ftp.py*",".{0,1000}\/protocols\/ftp\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9921"
"*/protocols/ldap.py*",".{0,1000}\/protocols\/ldap\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9922"
"*/protocols/mssql.py*",".{0,1000}\/protocols\/mssql\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9923"
"*/protocols/rdp.py*",".{0,1000}\/protocols\/rdp\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9924"
"*/protocols/rdp.py*",".{0,1000}\/protocols\/rdp\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted ","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9925"
"*/protocols/smb.py*",".{0,1000}\/protocols\/smb\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9926"
"*/protocols/ssh.py*",".{0,1000}\/protocols\/ssh\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","9927"
"*/PSPY.dll*",".{0,1000}\/PSPY\.dll.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","1","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","9985"
"*/pswRecovery4Moz.txt*",".{0,1000}\/pswRecovery4Moz\.txt.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","9998"
"*/pwcrack banner*",".{0,1000}\/pwcrack\sbanner.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#linux","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","10036"
"*/pwcrack.sh*",".{0,1000}\/pwcrack\.sh.{0,1000}","offensive_tool_keyword","nsa-rules","Password cracking rules and masks for hashcat that I generated from cracked passwords.","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/NSAKEY/nsa-rules","1","1","N/A","N/A","10","6","547","125","2017-01-03T11:53:25Z","2016-02-15T20:49:32Z","10037"
"*/pwcrack-framework.git*",".{0,1000}\/pwcrack\-framework\.git.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","10038"
"*/pwcrack-framework/*",".{0,1000}\/pwcrack\-framework\/.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","10039"
"*/pwdump.py*",".{0,1000}\/pwdump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","10040"
"*/pwdump7.zip*",".{0,1000}\/pwdump7\.zip.{0,1000}","offensive_tool_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","10042"
"*/pwdump8.*",".{0,1000}\/pwdump8\..{0,1000}","offensive_tool_keyword","PwDump8","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://download.openwall.net/pub/projects/john/contrib/pwdump/pwdump8-8.2.zip","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","10043"
"*/PXEThief*",".{0,1000}\/PXEThief.{0,1000}","offensive_tool_keyword","pxethief","PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager","T1555.004 - T1555.002","TA0006","N/A","N/A","Credential Access","https://github.com/MWR-CyberSec/PXEThief","1","1","N/A","N/A","N/A","4","368","57","2024-05-29T15:07:15Z","2022-08-12T22:16:46Z","10058"
"*/pyLAPS.git*",".{0,1000}\/pyLAPS\.git.{0,1000}","offensive_tool_keyword","pyLAPS","A simple way to read and write LAPS passwords from linux.","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/p0dalirius/pyLAPS","1","1","#linux","N/A","9","2","105","16","2024-10-28T08:36:38Z","2021-10-05T18:35:21Z","10072"
"*/pyLAPS.py*",".{0,1000}\/pyLAPS\.py.{0,1000}","offensive_tool_keyword","pyLAPS","A simple way to read and write LAPS passwords from linux.","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/p0dalirius/pyLAPS","1","1","#linux","N/A","9","2","105","16","2024-10-28T08:36:38Z","2021-10-05T18:35:21Z","10073"
"*/pypykatz*",".{0,1000}\/pypykatz.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","10087"
"*/pysecdump.git*",".{0,1000}\/pysecdump\.git.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","10095"
"*/pywhisker.git*",".{0,1000}\/pywhisker\.git.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","1","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","10109"
"*/quarkspwdump.git*",".{0,1000}\/quarkspwdump\.git.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","1","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","10122"
"*/quarkspwdump.git*",".{0,1000}\/quarkspwdump\.git.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","1","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","10123"
"*/RagingRotator.git*",".{0,1000}\/RagingRotator\.git.{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","1","N/A","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","10146"
"*/RagingRotator.go*",".{0,1000}\/RagingRotator\.go.{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","1","N/A","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","10147"
"*/rawrpc.py*",".{0,1000}\/rawrpc\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","10190"
"*/rawrpc_embedded.py*",".{0,1000}\/rawrpc_embedded\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","10191"
"*/rdcmanfox.dll*",".{0,1000}\/rdcmanfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","10206"
"*/RDP Recognizer.exe*",".{0,1000}\/RDP\sRecognizer\.exe.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","10209"
"*/RDPCredentialStealer.git*",".{0,1000}\/RDPCredentialStealer\.git.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","10214"
"*/RDPCredentialStealer/releases/download/*",".{0,1000}\/RDPCredentialStealer\/releases\/download\/.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","10215"
"*/RDPCredentialStealer/tarball/latest*",".{0,1000}\/RDPCredentialStealer\/tarball\/latest.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","10216"
"*/RDPHook.dll*",".{0,1000}\/RDPHook\.dll.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","1","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","10218"
"*/RdpStrike.git*",".{0,1000}\/RdpStrike\.git.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","1","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","10227"
"*/RdpThief*",".{0,1000}RdpThief.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","1","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","10228"
"*/RdpThief.dll*",".{0,1000}\/RdpThief\.dll.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","1","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","10230"
"*/RdpThief.git*",".{0,1000}\/RdpThief\.git.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","1","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","10231"
"*/rdpv.exe*",".{0,1000}\/rdpv\.exe.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","1","N/A","N/A","8","10","N/A","N/A","N/A","N/A","10233"
"*/ReflectDump.exe*",".{0,1000}\/ReflectDump\.exe.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","1","N/A","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","10306"
"*/releases/download/*/abc.exe*",".{0,1000}\/releases\/download\/.{0,1000}\/abc\.exe.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","1","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","10338"
"*/releases/download/v0.1/pamspy*",".{0,1000}\/releases\/download\/v0\.1\/pamspy.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","1","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","10345"
"*/releases/download/v0.2/pamspy*",".{0,1000}\/releases\/download\/v0\.2\/pamspy.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","1","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","10346"
"*/releases/download/v1.0/ADFSRelay*",".{0,1000}\/releases\/download\/v1\.0\/ADFSRelay.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","10347"
"*/releases/download/v1.0/NTLMParse*",".{0,1000}\/releases\/download\/v1\.0\/NTLMParse.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","10348"
"*/Responder/Responder.conf*",".{0,1000}\/Responder\/Responder\.conf.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","10419"
"*/restoresig.py*",".{0,1000}\/restoresig\.py.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","1","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","10429"
"*/returnvar/wce/*",".{0,1000}\/returnvar\/wce\/.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","10430"
"*/revshell32.bin*",".{0,1000}\/revshell32\.bin.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","10462"
"*/revshell64.bin*",".{0,1000}\/revshell64\.bin.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","10463"
"*/ridenum/ridenum.py*",".{0,1000}\/ridenum\/ridenum\.py.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","10479"
"*/ROADToken.exe*",".{0,1000}\/ROADToken\.exe.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","1","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","10489"
"*/ROADtoken.git*",".{0,1000}\/ROADtoken\.git.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","1","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","10490"
"*/rockyou.txt*",".{0,1000}\/rockyou\.txt.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Crack the hash with Hashcat","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10493"
"*/rockyou.txt*",".{0,1000}\/rockyou\.txt.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","10495"
"*/root/.local/bin/spraycharles*",".{0,1000}\/root\/\.local\/bin\/spraycharles.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","#linux","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","10501"
"*/root/lsarelayx*",".{0,1000}\/root\/lsarelayx.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","0","#linux","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","10505"
"*/Routerscan.7z*",".{0,1000}\/Routerscan\.7z.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","10529"
"*/RouterScan.exe*",".{0,1000}\/RouterScan\.exe.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","10530"
"*/router-scan.git*",".{0,1000}\/router\-scan\.git.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","10531"
"*/RouterScan.log*",".{0,1000}\/RouterScan\.log.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#linux","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","10532"
"*/rpcdump.py*",".{0,1000}\/rpcdump\.py.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","1","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","10544"
"*/Rubeus*",".{0,1000}\/Rubeus.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","10590"
"*/Rubeus.dll*",".{0,1000}\/Rubeus\.dll.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","1","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","10591"
"*/Rubeus.git*",".{0,1000}\/Rubeus\.git.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","10598"
"*/Rubeus.ps1*",".{0,1000}\/Rubeus\.ps1.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","1","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","10599"
"*/Rubeus/*",".{0,1000}\/Rubeus\/.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","10600"
"*/Rubeus-Rundll32.git*",".{0,1000}\/Rubeus\-Rundll32\.git.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","1","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","10601"
"*/Rubeus-Rundll32/*",".{0,1000}\/Rubeus\-Rundll32\/.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","1","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","10602"
"*/run/leet.pl*",".{0,1000}\/run\/leet\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","10610"
"*/RustiveDump.exe*",".{0,1000}\/RustiveDump\.exe.{0,1000}","offensive_tool_keyword","RustiveDump","LSASS memory dumper using only NTAPIs","T1003.001 - T1055 - T1106","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/safedv/RustiveDump","1","1","N/A","N/A","10","4","332","43","2025-03-08T12:10:35Z","2024-10-06T16:01:49Z","10645"
"*/RustiveDump.git*",".{0,1000}\/RustiveDump\.git.{0,1000}","offensive_tool_keyword","RustiveDump","LSASS memory dumper using only NTAPIs","T1003.001 - T1055 - T1106","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/safedv/RustiveDump","1","1","N/A","N/A","10","4","332","43","2025-03-08T12:10:35Z","2024-10-06T16:01:49Z","10646"
"*/rvrsh3ll/*",".{0,1000}\/rvrsh3ll\/.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","10652"
"*/SafetyDump.exe*",".{0,1000}\/SafetyDump\.exe.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","1","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","10664"
"*/SafetyDump.git*",".{0,1000}\/SafetyDump\.git.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","1","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","10665"
"*/SafetyKatz.git*",".{0,1000}\/SafetyKatz\.git.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","10671"
"*/samdump2*",".{0,1000}\/samdump2.{0,1000}","offensive_tool_keyword","samdump2","Retrieves syskey and extract hashes from Windows 2k/NT/XP/Vista SAM.","T1003.002 - T1564.001","TA0006 - TA0010","N/A","Black Basta","Credential Access","https://salsa.debian.org/pkg-security-team/samdump2","1","0","N/A","N/A","10","6","N/A","N/A","N/A","N/A","10679"
"*/sampasswd*",".{0,1000}\/sampasswd.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#linux","N/A","10","10","N/A","N/A","N/A","N/A","10680"
"*/samruser.py*",".{0,1000}\/samruser\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","10683"
"*/samusrgrp.*",".{0,1000}\/samusrgrp\..{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#linux","N/A","10","10","N/A","N/A","N/A","N/A","10684"
"*/sbin/chntpw*",".{0,1000}\/sbin\/chntpw.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#linux","N/A","10","10","N/A","N/A","N/A","N/A","10695"
"*/sbin/sampasswd*",".{0,1000}\/sbin\/sampasswd.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#linux","N/A","10","10","N/A","N/A","N/A","N/A","10697"
"*/sbin/samunlock*",".{0,1000}\/sbin\/samunlock.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#linux","N/A","10","10","N/A","N/A","N/A","N/A","10698"
"*/sbin/samusrgrp*",".{0,1000}\/sbin\/samusrgrp.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#linux","N/A","10","10","N/A","N/A","N/A","N/A","10699"
"*/SCOMDecrypt.git*",".{0,1000}\/SCOMDecrypt\.git.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","10733"
"*/ScriptSentry.git*",".{0,1000}\/ScriptSentry\.git.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","10738"
"*/ScriptSentry.ps1*",".{0,1000}\/ScriptSentry\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","10739"
"*/ScriptSentry.psd1*",".{0,1000}\/ScriptSentry\.psd1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","10740"
"*/ScriptSentry.psm1*",".{0,1000}\/ScriptSentry\.psm1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","10741"
"*/SecretFinder.git*",".{0,1000}\/SecretFinder\.git.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","1","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","10768"
"*/secretsdump.py*",".{0,1000}\/secretsdump\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","10771"
"*/SecretServerSecretStealer.git*",".{0,1000}\/SecretServerSecretStealer\.git.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","10774"
"*/SecretServerSecretStealer-master.zip*",".{0,1000}\/SecretServerSecretStealer\-master\.zip.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","10775"
"*/SecretStealer.ps1*",".{0,1000}\/SecretStealer\.ps1.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","1","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","10777"
"*/SessionGopher.git*",".{0,1000}\/SessionGopher\.git.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","1","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","10805"
"*/SessionGopher.ps1*",".{0,1000}\/SessionGopher\.ps1.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","1","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","10807"
"*/SessionSearcher.exe*",".{0,1000}\/SessionSearcher\.exe.{0,1000}","offensive_tool_keyword","SessionSearcher","Searches all connected drives for PuTTY private keys and RDP connection files and parses them for relevant details","T1552.004 - T1083 - T1114.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/matterpreter/OffensiveCSharp/tree/master/SessionSearcher","1","1","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","10809"
"*/SetNTLM.ps1*",".{0,1000}\/SetNTLM\.ps1.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","1","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","10812"
"*/ShadowDumper.git*",".{0,1000}\/ShadowDumper\.git.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","1","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","10835"
"*/ShadowDumper/releases/download/*",".{0,1000}\/ShadowDumper\/releases\/download\/.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","1","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","10836"
"*/ShadowSpray.git*",".{0,1000}\/ShadowSpray\.git.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","1","N/A","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","10851"
"*/ShadowStealer.git*",".{0,1000}\/ShadowStealer\.git.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","1","N/A","N/A","10","","N/A","","","","10853"
"*/share/windows-resources/wce*",".{0,1000}\/share\/windows\-resources\/wce.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","0","#linux","N/A","8","4","N/A","N/A","N/A","N/A","10856"
"*/shares-with-SCF.txt*",".{0,1000}\/shares\-with\-SCF\.txt.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","10863"
"*/SharpAltSecIds.exe*",".{0,1000}\/SharpAltSecIds\.exe.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","1","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","10869"
"*/SharpAltSecIds.git*",".{0,1000}\/SharpAltSecIds\.git.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","1","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","10870"
"*/SharpBruteForceSSH.git*","\/SharpBruteForceSSH\.git","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","1","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","10880"
"*/SharpChromium.git*",".{0,1000}\/SharpChromium\.git.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","10900"
"*/SharpClipboard.git*",".{0,1000}\/SharpClipboard\.git.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","1","N/A","N/A","8","1","N/A","N/A","N/A","N/A","10901"
"*/SharpCloud.git*",".{0,1000}\/SharpCloud\.git.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","10906"
"*/SharpDecryptPwd.git*",".{0,1000}\/SharpDecryptPwd\.git.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","1","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","10922"
"*/SharpDomainSpray.git*",".{0,1000}\/SharpDomainSpray\.git.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","1","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","10929"
"*/SharpDPAPI.git*",".{0,1000}\/SharpDPAPI\.git.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","10942"
"*/SharpDump.exe*",".{0,1000}\/SharpDump\.exe.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","1","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","10947"
"*/SharpDump.git*",".{0,1000}\/SharpDump\.git.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","1","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","10948"
"*/SharpEdge.exe*",".{0,1000}\/SharpEdge\.exe.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","1","N/A","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","10949"
"*/SharpEdge.git*",".{0,1000}\/SharpEdge\.git.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","1","N/A","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","10950"
"*/SharpHose.exe*",".{0,1000}\/SharpHose\.exe.{0,1000}","offensive_tool_keyword","SharpHose","Asynchronous Password Spraying Tool in C# for Windows Environments","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/ustayready/SharpHose","1","1","N/A","N/A","10","4","312","62","2023-12-19T21:06:47Z","2020-05-01T22:10:49Z","10999"
"*/SharpLocker.exe*",".{0,1000}\/SharpLocker\.exe.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","1","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","11022"
"*/SharpLocker.git*",".{0,1000}\/SharpLocker\.git.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","1","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","11023"
"*/SharpLocker/releases/*",".{0,1000}\/SharpLocker\/releases\/.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","1","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","11024"
"*/SharpLocker/zipball/*",".{0,1000}\/SharpLocker\/zipball\/.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","1","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","11025"
"*/SharpMiniDump.git*",".{0,1000}\/SharpMiniDump\.git.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","1","N/A","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","11035"
"*/SharpRDPThief.git*",".{0,1000}\/SharpRDPThief\.git.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","1","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","11064"
"*/SharpSAMDump.git*",".{0,1000}\/SharpSAMDump\.git.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","1","N/A","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","11069"
"*/SharpSecDump.git*",".{0,1000}\/SharpSecDump\.git.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","11083"
"*/SharpSpray.exe*",".{0,1000}\/SharpSpray\.exe.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","1","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","11111"
"*/sharpspray.exe*",".{0,1000}\/sharpspray\.exe.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","1","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","11112"
"*/SharpSpray.git*",".{0,1000}\/SharpSpray\.git.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","1","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","11113"
"*/SharpSpray-1.1.zip*",".{0,1000}\/SharpSpray\-1\.1\.zip.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","1","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","11114"
"*/SharpVeeamDecryptor.*",".{0,1000}\/SharpVeeamDecryptor\..{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","1","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","11149"
"*/SharpWeb.exe*",".{0,1000}\/SharpWeb\.exe.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","1","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","11157"
"*/SharpWeb.git*",".{0,1000}\/SharpWeb\.git.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","1","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","11158"
"*/shocknawe/*",".{0,1000}\/shocknawe\/.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","11236"
"*/ShuckNT.git*",".{0,1000}\/ShuckNT\.git.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","11242"
"*/Shwmae.exe*",".{0,1000}\/Shwmae\.exe.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","1","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","11243"
"*/Shwmae.git*",".{0,1000}\/Shwmae\.git.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","1","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","11244"
"*/shwmae/keys*",".{0,1000}\/shwmae\/keys.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","1","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","11245"
"*/sigthief.py*",".{0,1000}\/sigthief\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","11260"
"*/silentprocessexit.py*",".{0,1000}\/silentprocessexit\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","11268"
"*/smartbrute.git*",".{0,1000}\/smartbrute\.git.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","1","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","11348"
"*/smartbrute-main*",".{0,1000}\/smartbrute\-main.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","#linux","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","11349"
"*/smb-cmds.txt*",".{0,1000}\/smb\-cmds\.txt.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","11361"
"*/smbexec.py*",".{0,1000}\/smbexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","11372"
"*/smbldap.py*",".{0,1000}\/smbldap\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","11381"
"*/smbrelayserver.py*",".{0,1000}\/smbrelayserver\.py.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","11394"
"*/smb-signing-disabled-hosts.txt*",".{0,1000}\/smb\-signing\-disabled\-hosts\.txt.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","11406"
"*/smtp-user-enum*",".{0,1000}\/smtp\-user\-enum.{0,1000}","offensive_tool_keyword","smtp-user-enum","Username guessing tool primarily for use against the default Solaris SMTP service. Can use either EXPN - VRFY or RCPT TO.","T1133 - T1110.001","TA0007 - TA0006","N/A","N/A","Credential Access","https://pentestmonkey.net/tools/user-enumeration/smtp-user-enum","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","11443"
"*/Snake.nocomments.sh*",".{0,1000}\/Snake\.nocomments\.sh.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","11457"
"*/Snake.sh*",".{0,1000}\/Snake\.sh.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","11458"
"*/sniffpass-x64*",".{0,1000}\/sniffpass\-x64.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","11466"
"*/SocialBox.sh*",".{0,1000}\/SocialBox\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","1","N/A","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","11486"
"*/SocialBox-Termux*",".{0,1000}\/SocialBox\-Termux.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","1","N/A","N/A","10","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","11487"
"*/spray/spray.py*",".{0,1000}\/spray\/spray\.py.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","11546"
"*/Spray365*",".{0,1000}\/Spray365.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","11547"
"*/spraycharles.git*",".{0,1000}\/spraycharles\.git.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","1","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","11551"
"*/spraycharles.py*",".{0,1000}\/spraycharles\.py.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","1","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","11552"
"*/sprayers/owa.py*",".{0,1000}\/sprayers\/owa\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","11554"
"*/sprayhound.git*",".{0,1000}\/sprayhound\.git.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","1","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","11555"
"*/sprayhound/*.py*",".{0,1000}\/sprayhound\/.{0,1000}\.py.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","1","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","11556"
"*/SprayingToolkit*",".{0,1000}\/SprayingToolkit.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","11558"
"*/SprayingToolkit.git*",".{0,1000}\/SprayingToolkit\.git.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","#linux","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","11559"
"*/SprayLove.py*",".{0,1000}\/SprayLove\.py.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","1","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","11560"
"*/Spyndicapped.exe*",".{0,1000}\/Spyndicapped\.exe.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","1","N/A","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","11569"
"*/Spyndicapped.git*",".{0,1000}\/Spyndicapped\.git.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","1","N/A","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","11570"
"*/src/john.com*",".{0,1000}\/src\/john\.com.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","11590"
"*/src/jumbo.c*",".{0,1000}\/src\/jumbo\.c.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","11591"
"*/src/jumbo.h*",".{0,1000}\/src\/jumbo\.h.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","11592"
"*/sshamble.git*",".{0,1000}\/sshamble\.git.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","11605"
"*/sshame*",".{0,1000}\/sshame.{0,1000}","offensive_tool_keyword","sshame","tool to brute force SSH public-key authentication","T1110 - T1114 - T1112 - T1056","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/HynekPetrak/sshame","1","0","#linux","N/A","N/A","1","75","16","2024-03-24T11:07:35Z","2019-08-25T16:50:56Z","11606"
"*/SSH-Snake.git*",".{0,1000}\/SSH\-Snake\.git.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","11614"
"*/SSH-Snake/*",".{0,1000}\/SSH\-Snake\/.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","11615"
"*/ssp/decryptor.py",".{0,1000}\/ssp\/decryptor\.py","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","11638"
"*/Stealer.exe*",".{0,1000}\/Stealer\.exe.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","1","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","11668"
"*/Stealer.exe*",".{0,1000}\/Stealer\.exe.{0,1000}","offensive_tool_keyword","Rust-Malware-Samples","open source informations stealer in rust","T1003 - T1083 - T1114 - T1074","TA0006 - TA0009 - TA0005","N/A","N/A","Credential Access","https://github.com/Whitecat18/Rust-for-Malware-Development/tree/main/Malware-Samples","1","1","N/A","N/A","10","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","11669"
"*/Stealer.sln*",".{0,1000}\/Stealer\.sln.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","1","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","11670"
"*/sudo_tracer.c*",".{0,1000}\/sudo_tracer\.c.{0,1000}","offensive_tool_keyword","3snake","Tool for extracting information from newly spawned processes","T1003 - T1110 - T1552 - T1505","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/blendin/3snake","1","0","#linux","N/A","7","8","752","109","2022-02-14T17:42:10Z","2018-02-07T21:03:15Z","11711"
"*/Sup3r-Us3r/scripts/*",".{0,1000}\/Sup3r\-Us3r\/scripts\/.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://raw.githubusercontent.com/Sup3r-Us3r/scripts/master/fb-brute.pl","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","11728"
"*/syskey-and-sam.html*",".{0,1000}\/syskey\-and\-sam\.html.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","11763"
"*/t.me/NicestRAT*",".{0,1000}\/t\.me\/NicestRAT.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","11775"
"*/TeamFiltration.dll*",".{0,1000}\/TeamFiltration\.dll.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","11830"
"*/TeamFiltration.exe*",".{0,1000}\/TeamFiltration\.exe.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","11831"
"*/TeamFiltration/releases/latest*",".{0,1000}\/TeamFiltration\/releases\/latest.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","11832"
"*/teams_cookies_output.json*",".{0,1000}\/teams_cookies_output\.json.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","11835"
"*/teams_dump.git*",".{0,1000}\/teams_dump\.git.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","11836"
"*/teams_dump.git*",".{0,1000}\/teams_dump\.git.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","11837"
"*/teams_dump.py*",".{0,1000}\/teams_dump\.py.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","11838"
"*/teams_dump.py*",".{0,1000}\/teams_dump\.py.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","11839"
"*/tests/NIST_CAVS/*.rsp*",".{0,1000}\/tests\/NIST_CAVS\/.{0,1000}\.rsp.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","11869"
"*/TGSThief.git*",".{0,1000}\/TGSThief\.git.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","1","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","11874"
"*/TGSThief/*",".{0,1000}\/TGSThief\/.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","1","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","11875"
"*/thc-hydra/*",".{0,1000}\/thc\-hydra\/.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","11886"
"*/theHarvester.py*",".{0,1000}\/theHarvester\.py.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","11891"
"*/ThievingFox.git*",".{0,1000}\/ThievingFox\.git.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","11895"
"*/ThievingFox.py*",".{0,1000}\/ThievingFox\.py.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","11896"
"*/thycotic_secretserver_dump.rb*",".{0,1000}\/thycotic_secretserver_dump\.rb.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","1","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","11908"
"*/ticket_converter.py*",".{0,1000}\/ticket_converter\.py.{0,1000}","offensive_tool_keyword","ticket_converter","A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.","T1558.003 - T1110.004","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/zer1t0/ticket_converter","1","1","N/A","N/A","10","2","167","31","2022-06-16T19:38:05Z","2019-05-14T04:48:19Z","11909"
"*/ticketer.py -*",".{0,1000}\/ticketer\.py\s\-.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","#linux","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","11914"
"*/ticketer.py*",".{0,1000}\/ticketer\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","11917"
"*/ticketsplease.py*",".{0,1000}\/ticketsplease\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","11918"
"*/tmmmp *",".{0,1000}\/tmmmp\s.{0,1000}","offensive_tool_keyword","OMGLogger","Key logger which sends each and every key stroke of target remotely/locally.","T1056.001 - T1562.001","TA0004 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/OMGLogger","1","0","#linux","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","11939"
"*/tmp/*-passwords.txt*",".{0,1000}\/tmp\/.{0,1000}\-passwords\.txt.{0,1000}","offensive_tool_keyword","DefaultCreds-cheat-sheet","One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password","T1110.001 - T1110.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/ihebski/DefaultCreds-cheat-sheet","1","0","#linux","N/A","N/A","10","6048","726","2025-04-15T13:13:19Z","2021-01-01T19:02:36Z","11944"
"*/tmp/*-usernames.txt*",".{0,1000}\/tmp\/.{0,1000}\-usernames\.txt.{0,1000}","offensive_tool_keyword","DefaultCreds-cheat-sheet","One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password","T1110.001 - T1110.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/ihebski/DefaultCreds-cheat-sheet","1","0","#linux","N/A","N/A","10","6048","726","2025-04-15T13:13:19Z","2021-01-01T19:02:36Z","11945"
"*/tmp/credentials.txt*",".{0,1000}\/tmp\/credentials\.txt.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#linux","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","11962"
"*/tmp/kerberos_tickets*",".{0,1000}\/tmp\/kerberos_tickets.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#linux","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","11976"
"*/tmp/passwords.txt*",".{0,1000}\/tmp\/passwords\.txt.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","#linux","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","11984"
"*/TokenFinder.git*",".{0,1000}\/TokenFinder\.git.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","1","N/A","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","12012"
"*/TokenFinder.py*",".{0,1000}\/TokenFinder\.py.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","1","N/A","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","12013"
"*/TokenStealer.git*",".{0,1000}\/TokenStealer\.git.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","12017"
"*/TokenTactics.git*",".{0,1000}\/TokenTactics\.git.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","12023"
"*/TokenTacticsV2.git*",".{0,1000}\/TokenTacticsV2\.git.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","1","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","12024"
"*/TokenUniverse.git*",".{0,1000}\/TokenUniverse\.git.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","12025"
"*/TokenUniverse.zip*",".{0,1000}\/TokenUniverse\.zip.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","12026"
"*/tools/obfuscation.py -i *",".{0,1000}\/tools\/obfuscation\.py\s\-i\s.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#linux","N/A","10","","N/A","","","","12033"
"*/toolsdownload/iepv.zip*",".{0,1000}\/toolsdownload\/iepv\.zip.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12038"
"*/toolsdownload/rdpv.zip*",".{0,1000}\/toolsdownload\/rdpv\.zip.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","1","N/A","N/A","8","10","N/A","N/A","N/A","N/A","12039"
"*/top_mots_combo.7z*",".{0,1000}\/top_mots_combo\.7z.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","12041"
"*/tracers_fuzzer.cc*",".{0,1000}\/tracers_fuzzer\.cc.{0,1000}","offensive_tool_keyword","3snake","Tool for extracting information from newly spawned processes","T1003 - T1110 - T1552 - T1505","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/blendin/3snake","1","0","N/A","N/A","7","8","752","109","2022-02-14T17:42:10Z","2018-02-07T21:03:15Z","12070"
"*/TREVORspray.git*",".{0,1000}\/TREVORspray\.git.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","12081"
"*/trevorspray.log*",".{0,1000}\/trevorspray\.log.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","#logfile","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","12082"
"*/TrickDump.git*",".{0,1000}\/TrickDump\.git.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","1","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","12086"
"*/tried_logins.txt*",".{0,1000}\/tried_logins\.txt.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","#linux","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","12091"
"*/tweetshell.sh*",".{0,1000}\/tweetshell\.sh.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","1","N/A","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","12180"
"*/udmp-parser.git*",".{0,1000}\/udmp\-parser\.git.{0,1000}","offensive_tool_keyword","udmp-parser","A Cross-Platform C++ parser library for Windows user minidumps.","T1005 - T1059.003 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/0vercl0k/udmp-parser","1","1","N/A","N/A","6","3","202","23","2024-11-20T15:58:21Z","2022-01-30T18:56:21Z","12214"
"*/umeshshinde19/instainsane*",".{0,1000}\/umeshshinde19\/instainsane.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/umeshshinde19/instainsane","1","1","N/A","N/A","7","7","655","371","2024-02-11T10:29:05Z","2018-12-02T22:48:11Z","12216"
"*/unused/locktest.sh*",".{0,1000}\/unused\/locktest\.sh.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","12239"
"*/unused/Yosemite.patch*",".{0,1000}\/unused\/Yosemite\.patch.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","12240"
"*/usb140201.zip*",".{0,1000}\/usb140201\.zip.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12251"
"*/userenum.go*",".{0,1000}\/userenum\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","12254"
"*/userenum.go*",".{0,1000}\/userenum\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","12255"
"*/username-anarchy*",".{0,1000}\/username\-anarchy.{0,1000}","offensive_tool_keyword","username-anarchy","Tools for generating usernames when penetration testing. Usernames are half the password brute force problem.","T1110 - T1134 - T1078","TA0006","N/A","Black Basta","Credential Access","https://github.com/urbanadventurer/username-anarchy","1","1","N/A","N/A","N/A","10","1000","140","2024-09-20T01:57:59Z","2012-11-07T05:35:10Z","12257"
"*/usr/bin/legba*",".{0,1000}\/usr\/bin\/legba.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","#linux","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","12273"
"*/usr/local/bin/sshamble*",".{0,1000}\/usr\/local\/bin\/sshamble.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","0","#linux","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","12357"
"*/usr/share/brutespray*",".{0,1000}\/usr\/share\/brutespray.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#linux","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","12367"
"*/usr/share/doc/chntpw*",".{0,1000}\/usr\/share\/doc\/chntpw.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#linux","N/A","10","10","N/A","N/A","N/A","N/A","12370"
"*/usr/share/wordlists/*.txt*",".{0,1000}\/usr\/share\/wordlists\/.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","fcrackzip","a Free/Fast Zip Password Cracker","T1473 - T1021.002","TA0005 - TA0008","N/A","N/A","Credential Access","https://manpages.ubuntu.com/manpages/trusty/man1/fcrackzip.1.html","1","0","#linux","N/A","N/A","N/A","N/A","N/A","N/A","N/A","12378"
"*/utils/external_drive_password_recovery.html*",".{0,1000}\/utils\/external_drive_password_recovery\.html.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12381"
"*/utils/mailpv.html*",".{0,1000}\/utils\/mailpv\.html.{0,1000}","offensive_tool_keyword","MailPassView","Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12382"
"*/utils/network_password_recovery.html*",".{0,1000}\/utils\/network_password_recovery\.html.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12383"
"*/utils/passwordfox.html*",".{0,1000}\/utils\/passwordfox\.html.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12386"
"*/utils/vnc_password.html*",".{0,1000}\/utils\/vnc_password\.html.{0,1000}","offensive_tool_keyword","VNCPassView","recover the passwords stored by the VNC tool","T1003 - T1555 - T1081","TA0006 - TA0007","N/A","GoGoogle - 8BASE","Credential Access","https://www.nirsoft.net/utils/vnc_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12387"
"*/veeam-creds.git*",".{0,1000}\/veeam\-creds\.git.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","12429"
"*/virtualenvs/icebreaker*",".{0,1000}\/virtualenvs\/icebreaker.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","12455"
"*/wce.exe*",".{0,1000}\/wce\.exe.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","1","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","12504"
"*/wce32.exe*",".{0,1000}\/wce32\.exe.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","12505"
"*/wce64.exe*",".{0,1000}\/wce64\.exe.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","12506"
"*/wce-beta.zip*",".{0,1000}\/wce\-beta\.zip.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","12507"
"*/wcreddump.git*",".{0,1000}\/wcreddump\.git.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","1","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","12508"
"*/wcreddump.py*",".{0,1000}\/wcreddump\.py.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","1","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","12509"
"*/weakpass.git*",".{0,1000}\/weakpass\.git.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","12520"
"*/weakpass_2a.gz*",".{0,1000}\/weakpass_2a\.gz.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","12521"
"*/weakpass_3a.7z*",".{0,1000}\/weakpass_3a\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","12522"
"*/Web/decouverte.txt*",".{0,1000}\/Web\/decouverte\.txt.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","12523"
"*/Web/discovery.txt*",".{0,1000}\/Web\/discovery\.txt.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","12524"
"*/web_browser_password.html*",".{0,1000}\/web_browser_password\.html.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","12526"
"*/webauthn-inject.js*",".{0,1000}\/webauthn\-inject\.js.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","1","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","12529"
"*/WiFiBroot*",".{0,1000}\/WiFiBroot.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","12574"
"*/wifite -c *",".{0,1000}\/wifite\s\-c\s.{0,1000}","offensive_tool_keyword","wifite2","This repo is a complete re-write of wifite. a Python script for auditing wireless networks.Run wifite. select your targets. and Wifite will automatically start trying to capture or crack the password.","T1590 - T1170 - T1595","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/derv82/wifite2","1","0","N/A","network exploitation tool","N/A","10","6838","1403","2024-08-20T12:34:38Z","2015-05-30T06:09:52Z","12579"
"*/wifite2*",".{0,1000}\/wifite2.{0,1000}","offensive_tool_keyword","wifite2","This repo is a complete re-write of wifite. a Python script for auditing wireless networks.Run wifite. select your targets. and Wifite will automatically start trying to capture or crack the password.","T1590 - T1170 - T1595","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/derv82/wifite2","1","1","N/A","network exploitation tool","N/A","10","6838","1403","2024-08-20T12:34:38Z","2015-05-30T06:09:52Z","12580"
"*/wikipedia_fr.7z*",".{0,1000}\/wikipedia_fr\.7z.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","12581"
"*/WinBruteLogon*",".{0,1000}\/WinBruteLogon.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","12586"
"*/win-brute-logon*",".{0,1000}\/win\-brute\-logon.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","12587"
"*/win-brute-logon.git*",".{0,1000}\/win\-brute\-logon\.git.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","1","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","12588"
"*/Windows-Passwords.ps1*",".{0,1000}\/Windows\-Passwords\.ps1.{0,1000}","offensive_tool_keyword","WLAN-Windows-Passwords","Opens PowerShell hidden - grabs wlan passwords - saves as a cleartext in a variable and exfiltrates info via Discord Webhook.","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/WLAN-Windows-Passwords","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","12610"
"*/WINHELLO2hashcat.py*",".{0,1000}\/WINHELLO2hashcat\.py.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","1","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","12620"
"*/winrm.py*",".{0,1000}\/winrm\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","12646"
"*/wlanpass.txt*",".{0,1000}\/wlanpass\.txt.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#linux","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","12689"
"*/wmiexec.py*",".{0,1000}\/wmiexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","12696"
"*/wmiexec.py*",".{0,1000}\/wmiexec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","12697"
"*/word_list.c",".{0,1000}\/word_list\.c","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","12713"
"*/word_list.h",".{0,1000}\/word_list\.h","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","12714"
"*/wordlists/owa_directories.txt*",".{0,1000}\/wordlists\/owa_directories\.txt.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","12720"
"*/wordlists/skype-directories.txt*",".{0,1000}\/wordlists\/skype\-directories\.txt.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","12721"
"*/xan7r/kerberoast*",".{0,1000}\/xan7r\/kerberoast.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","12759"
"*:\Users\Public\Music\*.dll*",".{0,1000}\:\\Users\\Public\\Music\\.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","12857"
"*[!] Could not extract useful token from specified Teams database!*",".{0,1000}\[!\]\sCould\snot\sextract\suseful\stoken\sfrom\sspecified\sTeams\sdatabase!.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#content","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","12898"
"*[!] Couldn't communicate with the fake RPC Server*",".{0,1000}\[!\]\sCouldn\'t\scommunicate\swith\sthe\sfake\sRPC\sServer.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","0","#content","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","12900"
"*[!] CredBackupCredentials(*",".{0,1000}\[!\]\sCredBackupCredentials\(.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","#content","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","12903"
"*[!] Dumping LSASS Requires Elevated Priviledges!*",".{0,1000}\[!\]\sDumping\sLSASS\sRequires\sElevated\sPriviledges!.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","#content","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","12905"
"*[!] Dumping LSASS Requires Elevated Priviledges!*",".{0,1000}\[!\]\sDumping\sLSASS\sRequires\sElevated\sPriviledges!.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#content","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","12906"
"*[!] ESTSAUTHPERSISTENT cookie was empty!*",".{0,1000}\[!\]\sESTSAUTHPERSISTENT\scookie\swas\sempty!.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#content","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","12910"
"*[!] Failed to create minidump*",".{0,1000}\[!\]\sFailed\sto\screate\sminidump.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","0","#content","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","12913"
"*[!] Failed to Create Process to Dump SAM*",".{0,1000}\[!\]\sFailed\sto\sCreate\sProcess\sto\sDump\sSAM.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#content","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","12914"
"*[!] Failed to exfiltrate using RoadTools auth file*",".{0,1000}\[!\]\sFailed\sto\sexfiltrate\susing\sRoadTools\sauth\sfile.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#content","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","12918"
"*[!] Failed to fake NtOpenProcess on LSASS PID*",".{0,1000}\[!\]\sFailed\sto\sfake\sNtOpenProcess\son\sLSASS\sPID.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","#content","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","12919"
"*[!] Failed to get LSASS handle, bailing!*",".{0,1000}\[!\]\sFailed\sto\sget\sLSASS\shandle,\sbailing!.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","#content","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","12920"
"*[!] Failed to get privileges when trying to gain SYSTEM*",".{0,1000}\[!\]\sFailed\sto\sget\sprivileges\swhen\strying\sto\sgain\sSYSTEM.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","#content","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","12921"
"*[!] Failed to Locate LSASS Dump File!*",".{0,1000}\[!\]\sFailed\sto\sLocate\sLSASS\sDump\sFile!.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","#content","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","12924"
"*[!] Failed to parse RoadTools auth JSON file*",".{0,1000}\[!\]\sFailed\sto\sparse\sRoadTools\sauth\sJSON\sfile.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#content","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","12925"
"*[!] Failed to Transfer LSASS Dump*",".{0,1000}\[!\]\sFailed\sto\sTransfer\sLSASS\sDump.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#content","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","12926"
"*[!] In-memory LSASS dump method failed: *",".{0,1000}\[!\]\sIn\-memory\sLSASS\sdump\smethod\sfailed\:\s.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#content","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","12937"
"*[!] Invalid Exfil Method Chosen! Data Will Not Be Sent!*",".{0,1000}\[!\]\sInvalid\sExfil\sMethod\sChosen!\sData\sWill\sNot\sBe\sSent!.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","#content","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","12940"
"*[!] Invalid sandbox evasion technique provided!*",".{0,1000}\[!\]\sInvalid\ssandbox\sevasion\stechnique\sprovided!.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","12942"
"*[!] Lsass dump created!*",".{0,1000}\[!\]\sLsass\sdump\screated!.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","0","#content","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","12945"
"*[!] LSASS dump failed *",".{0,1000}\[!\]\sLSASS\sdump\sfailed\s.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#content","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","12946"
"*[!] Password spraying will be conducted*",".{0,1000}\[!\]\sPassword\sspraying\swill\sbe\sconducted.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","0","#content","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","12949"
"*[!] The exfiltration modules does not use FireProx*",".{0,1000}\[!\]\sThe\sexfiltration\smodules\sdoes\snot\suse\sFireProx.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#content","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","12964"
"*[!] The password * will be sprayed on targeted user accounts having*",".{0,1000}\[!\]\sThe\spassword\s.{0,1000}\swill\sbe\ssprayed\son\stargeted\suser\saccounts\shaving.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","0","#content","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","12965"
"*[!] Unhandled ShadowSpray.Kerb exception:*",".{0,1000}\[!\]\sUnhandled\sShadowSpray\.Kerb\sexception\:.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#content","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","12971"
"*[!] Valid login* expired password: *",".{0,1000}\[!\]\sValid\slogin.{0,1000}\sexpired\spassword\:\s.{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","0","#content","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","12973"
"*[!] You are running TeamFiltration without a config*",".{0,1000}\[!\]\sYou\sare\srunning\sTeamFiltration\swithout\sa\sconfig.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#content","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","12975"
"*[*] Overall compromised accounts: *",".{0,1000}\[.{0,1000}\]\sOverall\scompromised\saccounts\:\s.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","0","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","12991"
"*[-] Domain switch not provided. Enumerating the Domain Name*",".{0,1000}\[\-\]\sDomain\sswitch\snot\sprovided\.\sEnumerating\sthe\sDomain\sName.{0,1000}","offensive_tool_keyword","Invoke-GrabTheHash","Get the NTLM Hash for the User or Machine Account TGT held in your current session","T1558.004 - T1003.004","TA0006","N/A","N/A","Credential Access","https://github.com/Leo4j/Invoke-GrabTheHash","1","0","#content","N/A","8","1","6","1","2023-10-26T10:52:51Z","2023-08-22T12:14:53Z","13002"
"*[-] Failed to ReadProcessMemory for g_fParameter_UseLogonCredential*",".{0,1000}\[\-\]\sFailed\sto\sReadProcessMemory\sfor\sg_fParameter_UseLogonCredential.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","#content","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","13010"
"*[-] Failed to ReadProcessMemory for g_IsCredGuardEnabled*",".{0,1000}\[\-\]\sFailed\sto\sReadProcessMemory\sfor\sg_IsCredGuardEnabled.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","#content","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","13011"
"*[-] Failed to WriteProcessMemory for g_fParameter_UseLogonCredential*",".{0,1000}\[\-\]\sFailed\sto\sWriteProcessMemory\sfor\sg_fParameter_UseLogonCredential.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","#content","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","13014"
"*[-] Failed to WriteProcessMemory for g_IsCredGuardEnabled.*",".{0,1000}\[\-\]\sFailed\sto\sWriteProcessMemory\sfor\sg_IsCredGuardEnabled\..{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","#content","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","13015"
"*[-] Stopping here, before grabbing the Hash*",".{0,1000}\[\-\]\sStopping\shere,\sbefore\sgrabbing\sthe\sHash.{0,1000}","offensive_tool_keyword","Invoke-GrabTheHash","Get the NTLM Hash for the User or Machine Account TGT held in your current session","T1558.004 - T1003.004","TA0006","N/A","N/A","Credential Access","https://github.com/Leo4j/Invoke-GrabTheHash","1","0","#content","N/A","8","1","6","1","2023-10-26T10:52:51Z","2023-08-22T12:14:53Z","13029"
"*[-] Unable to Read LSASS Dump*",".{0,1000}\[\-\]\sUnable\sto\sRead\sLSASS\sDump.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#content","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","13030"
"*[+] Added {altsecid} to {target}*",".{0,1000}\[\+\]\sAdded\s\{altsecid\}\sto\s\{target\}.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","#content","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","13044"
"*[+] Captured snapshot of LSASS process*",".{0,1000}\[\+\]\sCaptured\ssnapshot\sof\sLSASS\sprocess.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","#content","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","13077"
"*[+] Connnecting to all computers and try to get dpapi blobs and master key files*",".{0,1000}\[\+\]\sConnnecting\sto\sall\scomputers\sand\stry\sto\sget\sdpapi\sblobs\sand\smaster\skey\sfiles.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","#content","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","13082"
"*[+] Could not find TeamFiltration config*",".{0,1000}\[\+\]\sCould\snot\sfind\sTeamFiltration\sconfig.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#content","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","13084"
"*[+] Decrypted SYSTEM vault policy*",".{0,1000}\[\+\]\sDecrypted\sSYSTEM\svault\spolicy.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","#content","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","13096"
"*[+] Deobfuscated dump saved in file decrypted.dmp*",".{0,1000}\[\+\]\sDeobfuscated\sdump\ssaved\sin\sfile\sdecrypted\.dmp.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","#content","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","13099"
"*[+] Direct syscalls have been disabled, getting API funcs from ntdll in memory!*",".{0,1000}\[\+\]\sDirect\ssyscalls\shave\sbeen\sdisabled,\sgetting\sAPI\sfuncs\sfrom\sntdll\sin\smemory!.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13102"
"*[+] Dump %wZ memory to: %wZ*",".{0,1000}\[\+\]\sDump\s\%wZ\smemory\sto\:\s\%wZ.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#content","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","13113"
"*[+] Dump sent successfully to remote host!*",".{0,1000}\[\+\]\sDump\ssent\ssuccessfully\sto\sremote\shost!.{0,1000}","offensive_tool_keyword","RustiveDump","LSASS memory dumper using only NTAPIs","T1003.001 - T1055 - T1106","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/safedv/RustiveDump","1","0","#content","N/A","10","4","332","43","2025-03-08T12:10:35Z","2024-10-06T16:01:49Z","13114"
"*[+] Extracting LAPS password from LDAP*",".{0,1000}\[\+\]\sExtracting\sLAPS\spassword\sfrom\sLDAP.{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","0","#content","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","13141"
"*[+] Found {LSASS} pid: {pid}*",".{0,1000}\[\+\]\sFound\s\{LSASS\}\spid\:\s\{pid\}.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","0","#content","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","13145"
"*[+] Getting credentials using U2U*",".{0,1000}\[\+\]\sGetting\scredentials\susing\sU2U.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#content","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","13153"
"*[+] Got NTLM type 3 AUTH message from * with hostname *",".{0,1000}\[\+\]\sGot\sNTLM\stype\s3\sAUTH\smessage\sfrom\s.{0,1000}\s\swith\shostname\s.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","0","#content","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","13163"
"*[+] Importing ticket into a sacrificial process using CreateNetOnly*",".{0,1000}\[\+\]\sImporting\sticket\sinto\sa\ssacrificial\sprocess\susing\sCreateNetOnly.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#content","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","13182"
"*[+] Injecting into existing process*",".{0,1000}\[\+\]\sInjecting\sinto\sexisting\sprocess.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13188"
"*[+] LSAKEY(s) retrieving*",".{0,1000}\[\+\]\sLSAKEY\(s\)\sretrieving.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","#content","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","13219"
"*[+] LSASS dump created successfully.*",".{0,1000}\[\+\]\sLSASS\sdump\screated\ssuccessfully\..{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#content","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","13220"
"*[+] LSASS dump done!*",".{0,1000}\[\+\]\sLSASS\sdump\sdone!.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#content","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","13221"
"*[+] LSASS Dump Read: *",".{0,1000}\[\+\]\sLSASS\sDump\sRead\:\s.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","#content","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","13222"
"*[+] LSASS Dump Read: *",".{0,1000}\[\+\]\sLSASS\sDump\sRead\:\s.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#content","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","13223"
"*[+] Minidump successfully saved to memory*",".{0,1000}\[\+\]\sMinidump\ssuccessfully\ssaved\sto\smemory.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","#content","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","13227"
"*[+] My personal simple and stupid Token Stealer... *",".{0,1000}\[\+\]\sMy\spersonal\ssimple\sand\sstupid\s\sToken\sStealer\.\.\.\s.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","0","#content","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","13229"
"*[+] NTDLL unhooking enabled*",".{0,1000}\[\+\]\sNTDLL\sunhooking\senabled.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13237"
"*[+] Obtained ADSync service account token from miiserver process*",".{0,1000}\[\+\]\sObtained\sADSync\sservice\saccount\stoken\sfrom\smiiserver\sprocess.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","0","#content","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","13242"
"*[+] Opened Process Token Sucessufully!*",".{0,1000}\[\+\]\sOpened\sProcess\sToken\sSucessufully!.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","0","#content","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","13244"
"*[+] Parsing SAM registry hive*",".{0,1000}\[\+\]\sParsing\sSAM\sregistry\shive.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","#content","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","13247"
"*[+] Parsing SAM registry hive*",".{0,1000}\[\+\]\sParsing\sSAM\sregistry\shive.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","#content","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","13248"
"*[+] Parsing SECURITY registry hive*",".{0,1000}\[\+\]\sParsing\sSECURITY\sregistry\shive.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","#content","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","13249"
"*[+] Parsing SECURITY registry hive*",".{0,1000}\[\+\]\sParsing\sSECURITY\sregistry\shive.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","#content","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","13250"
"*[+] Payload DLL successfully loaded after*",".{0,1000}\[\+\]\sPayload\sDLL\ssuccessfully\sloaded\safter.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","#content","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","13251"
"*[+] Performing recursive ShadowSpray attack. This might take a while*",".{0,1000}\[\+\]\sPerforming\srecursive\sShadowSpray\sattack\.\sThis\smight\stake\sa\swhile.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#content","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","13255"
"*[+] PPID Spoofing has been disabled*",".{0,1000}\[\+\]\sPPID\sSpoofing\shas\sbeen\sdisabled.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13268"
"*[+] Proxy blanket set successfully*",".{0,1000}\[\+\]\sProxy\sblanket\sset\ssuccessfully.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","#content","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","13271"
"*[+] Remote COM secret : *",".{0,1000}\[\+\]\sRemote\sCOM\ssecret\s\:\s.{0,1000}","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","0","#content","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","13285"
"*[+] Scanning computers list on SMB port *",".{0,1000}\[\+\]\sScanning\scomputers\slist\son\sSMB\sport\s.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","#content","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","13300"
"*[+] Seems like the creds are valid: * :: * on *",".{0,1000}\[\+\]\sSeems\slike\sthe\screds\sare\svalid\:\s.{0,1000}\s\:\:\s.{0,1000}\son\s.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","0","#content","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","13302"
"*[+] ShadowSpray recovered *",".{0,1000}\[\+\]\sShadowSpray\srecovered\s.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#content","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","13313"
"*[+] Successfully decrypted minidump file*",".{0,1000}\[\+\]\sSuccessfully\sdecrypted\sminidump\sfile.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","0","#content","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","13340"
"*[+] Successfully decrypted NGC key set from protector type *",".{0,1000}\[\+\]\sSuccessfully\sdecrypted\sNGC\skey\sset\sfrom\sprotector\stype\s.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","#content","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","13341"
"*[+] Successfully injected into process *",".{0,1000}\[\+\]\sSuccessfully\sinjected\sinto\sprocess\s.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","0","#content","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","13344"
"*[+] Successfully opened {LSASS} handle*",".{0,1000}\[\+\]\sSuccessfully\sopened\s\{LSASS\}\shandle.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","0","#content","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","13347"
"*[+] Successfully opened LSASS, PID: *",".{0,1000}\[\+\]\sSuccessfully\sopened\sLSASS,\sPID\:\s.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","#content","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","13348"
"*[+] Successfully retrieved an access token for User:*",".{0,1000}\[\+\]\sSuccessfully\sretrieved\san\saccess\stoken\sfor\sUser\:.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#content","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","13349"
"*[+] Sucessfully Dumped Process!*",".{0,1000}\[\+\]\sSucessfully\sDumped\sProcess!.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","#content","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","13356"
"*[+] Suitable Handle to LSASS Found from PID: *",".{0,1000}\[\+\]\sSuitable\sHandle\sto\sLSASS\sFound\sfrom\sPID\:\s.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","#content","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","13358"
"*[+] SYSKEY restrieving*",".{0,1000}\[\+\]\sSYSKEY\srestrieving.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","#content","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","13359"
"*[+] SYSKEY restrieving*",".{0,1000}\[\+\]\sSYSKEY\srestrieving.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","#content","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","13360"
"*[+] SysWhispers is not compatible with Obfuscator-LLVM; switching to GetSyscallStub*",".{0,1000}\[\+\]\sSysWhispers\sis\snot\scompatible\swith\sObfuscator\-LLVM\;\sswitching\sto\sGetSyscallStub.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13363"
"*[+] The 1$a$$.exe*",".{0,1000}\[\+\]\sThe\s1\$a\$\$\.exe.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","#content","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","13365"
"*[+] Using DLL enumeration for sandbox evasion*",".{0,1000}\[\+\]\sUsing\sDLL\senumeration\sfor\ssandbox\sevasion.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13391"
"*[+] Using domain enumeration for sandbox evasion*",".{0,1000}\[\+\]\sUsing\sdomain\senumeration\sfor\ssandbox\sevasion.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13395"
"*[+] Using hostname enumeration for sandbox evasion*",".{0,1000}\[\+\]\sUsing\shostname\senumeration\sfor\ssandbox\sevasion.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13398"
"*[+] Using Obfuscator-LLVM to compile stub...*",".{0,1000}\[\+\]\sUsing\sObfuscator\-LLVM\sto\scompile\sstub\.\.\..{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13401"
"*[+] Using sleep technique for sandbox evasion*",".{0,1000}\[\+\]\sUsing\ssleep\stechnique\sfor\ssandbox\sevasion.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13405"
"*[+] Using SysWhispers2 for syscalls*",".{0,1000}\[\+\]\sUsing\sSysWhispers2\sfor\ssyscalls.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13408"
"*[+] Using SysWhispers3 for syscalls*",".{0,1000}\[\+\]\sUsing\sSysWhispers3\sfor\ssyscalls.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13411"
"*[+] Using username enumeration for sandbox evasion*",".{0,1000}\[\+\]\sUsing\susername\senumeration\sfor\ssandbox\sevasion.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13412"
"*[+] v1.0 @decoder_it 2023*",".{0,1000}\[\+\]\sv1\.0\s\@decoder_it\s2023.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","0","#content","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","13414"
"*[+] Valid login* user must enroll in MFA.*",".{0,1000}\[\+\]\sValid\slogin.{0,1000}\suser\smust\senroll\sin\sMFA\..{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","0","#content","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","13415"
"*[+] Valid shellcode execution methods are: PoolPartyModuleStomping*",".{0,1000}\[\+\]\sValid\sshellcode\sexecution\smethods\sare\:\sPoolPartyModuleStomping.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","#content","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","13416"
"*[=] Dumping LSASS memory*",".{0,1000}\[\=\]\sDumping\sLSASS\smemory.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","13425"
"*[ADA] Searching for accounts with msSFU30Password attribute*",".{0,1000}\[ADA\]\sSearching\sfor\saccounts\swith\smsSFU30Password\sattribute.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","13427"
"*[ADA] Searching for accounts with userpassword attribute*",".{0,1000}\[ADA\]\sSearching\sfor\saccounts\swith\suserpassword\sattribute.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","13428"
"*[bruteforce_mode]*",".{0,1000}\[bruteforce_mode\].{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","#content","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","13446"
"*[E] Unable to read LSA secrets. Perhaps you are not SYTEM?*",".{0,1000}\[E\]\sUnable\sto\sread\sLSA\ssecrets\.\s\sPerhaps\syou\sare\snot\sSYTEM\?.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#content","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","13451"
"*[experimental] Extract keys from CAPI RSA/AES provider*",".{0,1000}\[experimental\]\sExtract\skeys\sfrom\sCAPI\sRSA\/AES\sprovider.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","13452"
"*[experimental] Patch CNG service for easy export*",".{0,1000}\[experimental\]\sPatch\sCNG\sservice\sfor\seasy\sexport.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","13453"
"*[experimental] Patch CryptoAPI layer for easy export*",".{0,1000}\[experimental\]\sPatch\sCryptoAPI\slayer\sfor\seasy\sexport.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","13454"
"*[experimental] patch Events service to avoid new events*",".{0,1000}\[experimental\]\spatch\sEvents\sservice\sto\savoid\snew\sevents.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","13455"
"*[experimental] patch Terminal Server service to allow multiples users*",".{0,1000}\[experimental\]\spatch\sTerminal\sServer\sservice\sto\sallow\smultiples\susers.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","13456"
"*[experimental] Try to enumerate all modules with Detours-like hooks*",".{0,1000}\[experimental\]\sTry\sto\senumerate\sall\smodules\swith\sDetours\-like\shooks.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","13457"
"*[experimental] try to get passwords from mstsc process*",".{0,1000}\[experimental\]\stry\sto\sget\spasswords\sfrom\smstsc\sprocess.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","13458"
"*[experimental] try to get passwords from running sessions*",".{0,1000}\[experimental\]\stry\sto\sget\spasswords\sfrom\srunning\ssessions.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","13459"
"*[GPP] Searching for passwords now*",".{0,1000}\[GPP\]\sSearching\sfor\spasswords\snow.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","13466"
"*[i] Dumping LSASS Using *",".{0,1000}\[i\]\sDumping\sLSASS\sUsing\s.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","#content","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","13472"
"*[i] Dumping LSASS Using comsvcs.dll*",".{0,1000}\[i\]\sDumping\sLSASS\sUsing\scomsvcs\.dll.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","13473"
"*[i] Dumping LSASS Using ProcDump*",".{0,1000}\[i\]\sDumping\sLSASS\sUsing\sProcDump.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","13474"
"*[i] Sending Encrypted SAM Save*",".{0,1000}\[i\]\sSending\sEncrypted\sSAM\sSave.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","13478"
"*[KeeFarceDLL]*",".{0,1000}\[KeeFarceDLL\].{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","13486"
"*[o365spray]*",".{0,1000}\[o365spray\].{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","13493"
"*[Reflection.Assembly]::Load(*[Char](*)+[Char](*)+*+[Char](*)*",".{0,1000}\[Reflection\.Assembly\]\:\:Load\(.{0,1000}\[Char\]\(.{0,1000}\)\+\[Char\]\(.{0,1000}\)\+.{0,1000}\+\[Char\]\(.{0,1000}\).{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","0","N/A","powershell scriptblock","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","13501"
"*[SharpDPAPI.Program]::Main(""machinemasterkeys"")*",".{0,1000}\[SharpDPAPI\.Program\]\:\:Main\(\""machinemasterkeys\""\).{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","#content","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","13503"
"*[Text.Encoding]::Unicode.GetString([Convert]::FromBase64String('bABzAGEAcwBzAA==*",".{0,1000}\[Text\.Encoding\]\:\:Unicode\.GetString\(\[Convert\]\:\:FromBase64String\(\'bABzAGEAcwBzAA\=\=.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#content","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","13517"
"*[warn] You either fat fingered this or something else. Either way*",".{0,1000}\[warn\]\sYou\seither\sfat\sfingered\sthis\sor\ssomething\selse\.\sEither\sway.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","0","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","13518"
"*[X] Must be elevated to triage SYSTEM credentials!*",".{0,1000}\[X\]\sMust\sbe\selevated\sto\striage\sSYSTEM\scredentials!.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","#content","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","13525"
"*[X] Must be elevated to triage SYSTEM masterkeys!*",".{0,1000}\[X\]\sMust\sbe\selevated\sto\striage\sSYSTEM\smasterkeys!.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","#content","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","13526"
"*[X] Must be elevated to triage SYSTEM vaults!*",".{0,1000}\[X\]\sMust\sbe\selevated\sto\striage\sSYSTEM\svaults!.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","#content","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","13527"
"*[X] Not in high integrity, unable to MiniDump!*",".{0,1000}\[X\]\sNot\sin\shigh\sintegrity,\sunable\sto\sMiniDump!.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#content","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","13529"
"*\\.\\pipe\\lsarelayx*",".{0,1000}\\\\\.\\\\pipe\\\\lsarelayx.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","0","#namedpipe","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","13579"
"*\\.\mimidrv*",".{0,1000}\\\\\.\\mimidrv.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","13582"
"*\\c$\Windows\Temp\*.dmp*",".{0,1000}\\\\c\$\\Windows\\Temp\\.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","13651"
"*\\Edge\\Usedx765er Data*",".{0,1000}\\\\Edge\\\\Usedx765er\sData.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","13661"
"*\\Locedx765al Staedx765te*",".{0,1000}\\\\Locedx765al\sStaedx765te.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","13665"
"*\\MiniDump\\Decryptor\\Credman*",".{0,1000}\\\\MiniDump\\\\Decryptor\\\\Credman.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","#content","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","13667"
"*\\MiniDump\\Decryptor\\KerberosSessions*",".{0,1000}\\\\MiniDump\\\\Decryptor\\\\KerberosSessions.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","#content","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","13668"
"*\\MiniDump\\Decryptor\\LogonSessions*",".{0,1000}\\\\MiniDump\\\\Decryptor\\\\LogonSessions.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","#content","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","13669"
"*\\PPLmedic\\ntstuff*",".{0,1000}\\\\PPLmedic\\\\ntstuff.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","13679"
"*\\Public\\panda.raw*",".{0,1000}\\\\Public\\\\panda\.raw.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","13680"
"*\\Public\\simpleMDWD.raw*",".{0,1000}\\\\Public\\\\simpleMDWD\.raw.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","13681"
"*\\Public\\sysMDWD.file*",".{0,1000}\\\\Public\\\\sysMDWD\.file.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","13682"
"*\\windows\\temp\\lsass.dmp*",".{0,1000}\\\\windows\\\\temp\\\\lsass\.dmp.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","0","#content","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","13693"
"*\\windows\\temp\\lsass.dmp*",".{0,1000}\\\\windows\\\\temp\\\\lsass\.dmp.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","#content","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","13694"
"*\1$a$$.exe*",".{0,1000}\\1\$a\$\$\.exe.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","13707"
"*\1password\app\FindsecondPID1password.h*",".{0,1000}\\1password\\app\\FindsecondPID1password\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","13718"
"*\1password\app\getCreds1passwordappEntries1.h*",".{0,1000}\\1password\\app\\getCreds1passwordappEntries1\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","13719"
"*\1password\app\getCreds1passwordappEntries2.h*",".{0,1000}\\1password\\app\\getCreds1passwordappEntries2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","13720"
"*\1password\app\getCreds1passwordappMaster.h*",".{0,1000}\\1password\\app\\getCreds1passwordappMaster\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","13721"
"*\1password\app\getProcUAC1password.h*",".{0,1000}\\1password\\app\\getProcUAC1password\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","13722"
"*\1password\plugin\getCreds1passwordplugin.h*",".{0,1000}\\1password\\plugin\\getCreds1passwordplugin\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","13723"
"*\1password\plugin\getCreds1passwordplugin2.h*",".{0,1000}\\1password\\plugin\\getCreds1passwordplugin2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","13724"
"*\a\1\s\x64\Release\ProcDump64.pdb*",".{0,1000}\\a\\1\\s\\x64\\Release\\ProcDump64\.pdb.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","#content","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","13766"
"*\ADCSCoercePotato\*",".{0,1000}\\ADCSCoercePotato\\.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","0","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","13806"
"*\adcsync.py*",".{0,1000}\\adcsync\.py.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","0","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","13810"
"*\adfsbrute.py*",".{0,1000}\\adfsbrute\.py.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","0","N/A","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","13835"
"*\ADFSDump.*",".{0,1000}\\ADFSDump\..{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","0","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","13836"
"*\ADFSDump\*",".{0,1000}\\ADFSDump\\.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","0","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","13839"
"*\ADFSDump-master*",".{0,1000}\\ADFSDump\-master.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","0","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","13842"
"*\ADFSDump-PS-main*",".{0,1000}\\ADFSDump\-PS\-main.{0,1000}","offensive_tool_keyword","ADFSDump-PS","ADFSDump to assist with GoldenSAML","T1078 - T1552.004 - T1558.004","TA0006 ","N/A","N/A","Credential Access","https://github.com/ZephrFish/ADFSDump-PS","1","0","N/A","N/A","10","1","31","8","2024-05-20T00:00:19Z","2024-05-19T00:46:28Z","13843"
"*\ADFSpray*",".{0,1000}\\ADFSpray.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","0","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","13845"
"*\ADFSRelay\*",".{0,1000}\\ADFSRelay\\.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","0","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","13846"
"*\adfs-spray.py*",".{0,1000}\\adfs\-spray\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","13847"
"*\adlogin.ps1*",".{0,1000}\\adlogin\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Credential Access","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","0","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","13851"
"*\ADPassHunt.pdb*",".{0,1000}\\ADPassHunt\.pdb.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","13856"
"*\ADPassHunt\*",".{0,1000}\\ADPassHunt\\.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","13857"
"*\amsi\dll.zip*",".{0,1000}\\amsi\\dll\.zip.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","13919"
"*\amsi\hook-win32.dll*",".{0,1000}\\amsi\\hook\-win32\.dll.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","13920"
"*\amsi\hook-win64.dll*",".{0,1000}\\amsi\\hook\-win64\.dll.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","13921"
"*\amsiwala.exe*",".{0,1000}\\amsiwala\.exe.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","N/A","10","","N/A","","","","13934"
"*\Andrew.dmp*",".{0,1000}\\Andrew\.dmp.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","0","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","13935"
"*\AppData\Local\Temp\*\RDP\Result\Pass1.txt*",".{0,1000}\\AppData\\Local\\Temp\\.{0,1000}\\RDP\\Result\\Pass1\.txt.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","14005"
"*\AppData\Local\Temp\*\RDP\Result\Pass2.txt*",".{0,1000}\\AppData\\Local\\Temp\\.{0,1000}\\RDP\\Result\\Pass2\.txt.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","14006"
"*\AppData\Local\Temp\*\RDP\Result\Pass3.txt*",".{0,1000}\\AppData\\Local\\Temp\\.{0,1000}\\RDP\\Result\\Pass3\.txt.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","14007"
"*\AppData\Local\Temp\tempfile.zip*",".{0,1000}\\AppData\\Local\\Temp\\tempfile\.zip.{0,1000}","offensive_tool_keyword","Rust-Malware-Samples","open source informations stealer in rust","T1003 - T1083 - T1114 - T1074","TA0006 - TA0009 - TA0005","N/A","N/A","Credential Access","https://github.com/Whitecat18/Rust-for-Malware-Development/tree/main/Malware-Samples","1","0","N/A","N/A","10","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","14053"
"*\Ask4Creds.ps1*",".{0,1000}\\Ask4Creds\.ps1.{0,1000}","offensive_tool_keyword","Ask4Creds","Prompt User for credentials","T1056 - T1071","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Leo4j/Ask4Creds","1","0","N/A","N/A","8","1","1","0","2024-03-20T17:09:21Z","2023-11-12T15:21:40Z","14111"
"*\autoNTDS.py*",".{0,1000}\\autoNTDS\.py.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","0","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","14162"
"*\AvDump.exe --pid * --exception_ptr 0*",".{0,1000}\\AvDump\.exe\s\-\-pid\s.{0,1000}\s\-\-exception_ptr\s0.{0,1000}","greyware_tool_keyword","AVDump","Avast AV to dump LSASS (C:\Program Files\Avast Software\Avast)","T1003.001 - T1059.001 - T1106","TA0006","N/A","Dispossessor","Credential Access","https://rosesecurity.gitbook.io/red-teaming-ttps/windows#av-lsass-dump","1","0","N/A","lolbin","8","9","N/A","N/A","N/A","N/A","14167"
"*\avira\getCredsavira.h*",".{0,1000}\\avira\\getCredsavira\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","14169"
"*\avira\getCredsavira2.h*",".{0,1000}\\avira\\getCredsavira2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","14170"
"*\BabelStrike.py*",".{0,1000}\\BabelStrike\.py.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","0","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","14186"
"*\BackupCreds.csproj*",".{0,1000}\\BackupCreds\.csproj.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","14203"
"*\backupcreds.exe*",".{0,1000}\\backupcreds\.exe.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","14204"
"*\backupcreds.sln*",".{0,1000}\\backupcreds\.sln.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","14205"
"*\backupcreds\Program.cs*",".{0,1000}\\backupcreds\\Program\.cs.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","14206"
"*\BackupCreds-main*",".{0,1000}\\BackupCreds\-main.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","14207"
"*\Barrel.exe debugproc*",".{0,1000}\\Barrel\.exe\sdebugproc.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","14229"
"*\BesoToken.cpp*",".{0,1000}\\BesoToken\.cpp.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","0","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","14290"
"*\BesoToken.exe*",".{0,1000}\\BesoToken\.exe.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","0","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","14291"
"*\BesoToken.vcxproj*",".{0,1000}\\BesoToken\.vcxproj.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","0","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","14292"
"*\big_shell_pwd.7z*",".{0,1000}\\big_shell_pwd\.7z.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","14301"
"*\bin\cme.exe*",".{0,1000}\\bin\\cme\.exe.{0,1000}","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","14304"
"*\bin\HostX64\x64\c2.dll*",".{0,1000}\\bin\\HostX64\\x64\\c2\.dll.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#content","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","14305"
"*\bitdefender\getCredsbitdefender.h*",".{0,1000}\\bitdefender\\getCredsbitdefender\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","14317"
"*\bitdefender\getCredsbitdefender2.h*",".{0,1000}\\bitdefender\\getCredsbitdefender2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","14318"
"*\bitwarden\plugin\getCredsbitwardenPluginChrome.h*",".{0,1000}\\bitwarden\\plugin\\getCredsbitwardenPluginChrome\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","14327"
"*\bitwarden\plugin\getCredsbitwardenPluginChrome2.h*",".{0,1000}\\bitwarden\\plugin\\getCredsbitwardenPluginChrome2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","14328"
"*\Blank.Grabber.zip*",".{0,1000}\\Blank\.Grabber\.zip.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","14341"
"*\BlankOBF.py*",".{0,1000}\\BlankOBF\.py.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","14342"
"*\blindsight.exe*",".{0,1000}\\blindsight\.exe.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","0","N/A","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","14345"
"*\bloodhoundsync.py*",".{0,1000}\\bloodhoundsync\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","14360"
"*\BOF-Template\x64\*",".{0,1000}\\BOF\-Template\\x64\\.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","14364"
"*\BrowserDataGrabber.pdb*",".{0,1000}\\BrowserDataGrabber\.pdb.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","0","N/A","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","14384"
"*\BrowserDataGrabber\*",".{0,1000}\\BrowserDataGrabber\\.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","0","N/A","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","14385"
"*\BrowserGhost.csproj*",".{0,1000}\\BrowserGhost\.csproj.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","0","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","14389"
"*\BrowserGhost.sln*",".{0,1000}\\BrowserGhost\.sln.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","0","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","14392"
"*\BrowserGhost-master*",".{0,1000}\\BrowserGhost\-master.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","0","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","14393"
"*\Brute RDP.rar*",".{0,1000}\\Brute\sRDP\.rar.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","14400"
"*\Bruteforcer.*",".{0,1000}\\Bruteforcer\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","14403"
"*\BypassCredGuard.cpp*",".{0,1000}\\BypassCredGuard\.cpp.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","14420"
"*\BypassCredGuard.exe*",".{0,1000}\\BypassCredGuard\.exe.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","14421"
"*\BypassCredGuard.log*",".{0,1000}\\BypassCredGuard\.log.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","14423"
"*\bypasscredguard.pdb*",".{0,1000}\\bypasscredguard\.pdb.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","14424"
"*\cachedump.py*",".{0,1000}\\cachedump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","14456"
"*\certipy.pfx*",".{0,1000}\\certipy\.pfx.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","0","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","14479"
"*\cheetah.py*",".{0,1000}\\cheetah\.py.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","14498"
"*\cheetah-master.zip*",".{0,1000}\\cheetah\-master\.zip.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","14499"
"*\chntpw.c*",".{0,1000}\\chntpw\.c.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","14509"
"*\chntpw-140201*",".{0,1000}\\chntpw\-140201.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","14510"
"*\chrome_creditcard.csv*",".{0,1000}\\chrome_creditcard\.csv.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","14512"
"*\chrome_creditcard.json*",".{0,1000}\\chrome_creditcard\.json.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","14513"
"*\chrome_decrypt.cpp*",".{0,1000}\\chrome_decrypt\.cpp.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","14514"
"*\chrome_decrypt.exe*",".{0,1000}\\chrome_decrypt\.exe.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","14515"
"*\chrome_password.csv*",".{0,1000}\\chrome_password\.csv.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","14517"
"*\chrome_password.json*",".{0,1000}\\chrome_password\.json.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","14518"
"*\ChromeCookiesView.cfg*",".{0,1000}\\ChromeCookiesView\.cfg.{0,1000}","greyware_tool_keyword","ChromeCookiesView","displays the list of all cookies stored by Google Chrome Web browser - abused by attackers","T1539 - T1005 - T1070.004 - T1552.001","TA0006 - TA0008 - TA0009","N/A","Evilnum - MuddyWater","Credential Access","https://www.nirsoft.net/utils/chrome_cookies_view.html","1","0","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","8","10","N/A","N/A","N/A","N/A","14519"
"*\ChromeKatz.sln*",".{0,1000}\\ChromeKatz\.sln.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","14521"
"*\ChromeStealer.cpp*",".{0,1000}\\ChromeStealer\.cpp.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","0","N/A","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","14524"
"*\ChromeStealer.sln*",".{0,1000}\\ChromeStealer\.sln.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","0","N/A","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","14525"
"*\ChromeStealer-main*",".{0,1000}\\ChromeStealer\-main.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","0","N/A","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","14526"
"*\chromium\getCredschromium.h*",".{0,1000}\\chromium\\getCredschromium\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","14527"
"*\chromium_based_browsers.py*",".{0,1000}\\chromium_based_browsers\.py.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","14528"
"*\cme.exe* -d * -u * -H *",".{0,1000}\\cme\.exe.{0,1000}\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-H\s.{0,1000}","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","14565"
"*\cme.exe* -d * -u * -p *",".{0,1000}\\cme\.exe.{0,1000}\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","14566"
"*\cme.exe* --shares*",".{0,1000}\\cme\.exe.{0,1000}\s\-\-shares.{0,1000}","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","14567"
"*\Commands\Machinecredentials.cs*",".{0,1000}\\Commands\\Machinecredentials\.cs.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","14594"
"*\comsvcs_stealth.py*",".{0,1000}\\comsvcs_stealth\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","14599"
"*\consentfox.dll*",".{0,1000}\\consentfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","14615"
"*\ConvertFrom-JWTtoken.ps1*",".{0,1000}\\ConvertFrom\-JWTtoken\.ps1.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","14627"
"*\CookieData.txt --all*",".{0,1000}\\CookieData\.txt\s\-\-all.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","14630"
"*\CookieKatz.vcxproj*",".{0,1000}\\CookieKatz\.vcxproj.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","14632"
"*\CookieKatz-BOF\*",".{0,1000}\\CookieKatz\-BOF\\.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","14633"
"*\CookieKatzMinidump\*",".{0,1000}\\CookieKatzMinidump\\.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","14634"
"*\crackmapexecwin*",".{0,1000}\\crackmapexecwin.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","14644"
"*\creddump7-master*",".{0,1000}\\creddump7\-master.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","14657"
"*\CredHistView.cfg*",".{0,1000}\\CredHistView\.cfg.{0,1000}","offensive_tool_keyword","credhistview","This tool allows you to decrypt the CREDHIST file and view the SHA1 and NTLM hashes of all previous passwords you used on your system","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/credhist_view.html","1","0","N/A","N/A","9","9","N/A","N/A","N/A","N/A","14661"
"*\credhistview.lnk*",".{0,1000}\\credhistview\.lnk.{0,1000}","offensive_tool_keyword","credhistview","This tool allows you to decrypt the CREDHIST file and view the SHA1 and NTLM hashes of all previous passwords you used on your system","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/credhist_view.html","1","0","N/A","N/A","9","9","N/A","N/A","N/A","N/A","14662"
"*\credhistview\*",".{0,1000}\\credhistview\\.{0,1000}","offensive_tool_keyword","credhistview","This tool allows you to decrypt the CREDHIST file and view the SHA1 and NTLM hashes of all previous passwords you used on your system","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/credhist_view.html","1","0","N/A","N/A","9","9","N/A","N/A","N/A","N/A","14663"
"*\credmaster.py*",".{0,1000}\\credmaster\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","14665"
"*\credmaster.txt*",".{0,1000}\\credmaster\.txt.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","14666"
"*\CredMaster-master.zip*",".{0,1000}\\CredMaster\-master\.zip.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","14667"
"*\credmaster-success.txt*",".{0,1000}\\credmaster\-success\.txt.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","14668"
"*\credmaster-validusers.txt*",".{0,1000}\\credmaster\-validusers\.txt.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","14669"
"*\CredPhisher.exe*",".{0,1000}\\CredPhisher\.exe.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","0","N/A","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","14671"
"*\CredPhisher.pdb*",".{0,1000}\\CredPhisher\.pdb.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","0","#content","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","14673"
"*\cstealer.py*",".{0,1000}\\cstealer\.py.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","0","N/A","N/A","10","","N/A","","","","14698"
"*\dafthack\MSOLSpray*",".{0,1000}\\dafthack\\MSOLSpray.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","14767"
"*\dashlane\getCredsdashlaneEntries.h*",".{0,1000}\\dashlane\\getCredsdashlaneEntries\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","14804"
"*\dashlane\getCredsdashlaneMaster.h*",".{0,1000}\\dashlane\\getCredsdashlaneMaster\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","14805"
"*\DCSyncer.sln*",".{0,1000}\\DCSyncer\.sln.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","0","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","14829"
"*\DCSyncer-master*",".{0,1000}\\DCSyncer\-master.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","0","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","14830"
"*\DecryptAutoLogon.exe*",".{0,1000}\\DecryptAutoLogon\.exe.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","N/A","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","14843"
"*\DecryptAutoLogon.sln*",".{0,1000}\\DecryptAutoLogon\.sln.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","N/A","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","14845"
"*\DecryptAutoLogon.sln*",".{0,1000}\\DecryptAutoLogon\.sln.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","N/A","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","14846"
"*\DecryptAutoLogon-main*",".{0,1000}\\DecryptAutoLogon\-main.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","N/A","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","14847"
"*\decrypted.dmp*",".{0,1000}\\decrypted\.dmp.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","14848"
"*\Decrypt-RDCMan.ps1*",".{0,1000}\\Decrypt\-RDCMan\.ps1.{0,1000}","offensive_tool_keyword","Decrypt-RDCMan","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1","1","0","N/A","N/A","9","1","1","1","2016-12-01T14:06:24Z","2017-11-22T23:18:39Z","14851"
"*\DecryptRDCManager.sln*",".{0,1000}\\DecryptRDCManager\.sln.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","0","N/A","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","14852"
"*\DecryptTeamViewer.exe*",".{0,1000}\\DecryptTeamViewer\.exe.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","0","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","14854"
"*\DecryptTeamViewer.sln*",".{0,1000}\\DecryptTeamViewer\.sln.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","0","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","14856"
"*\DecryptTeamViewer-master*",".{0,1000}\\DecryptTeamViewer\-master.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","0","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","14857"
"*\DelegationBOF.*",".{0,1000}\\DelegationBOF\..{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","0","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","14869"
"*\dementor.py*",".{0,1000}\\dementor\.py.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","14891"
"*\Device\mimidrv*",".{0,1000}\\Device\\mimidrv.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","14914"
"*\Dialupass.cfg*",".{0,1000}\\Dialupass\.cfg.{0,1000}","offensive_tool_keyword","dialupass","This utility enumerates all dialup/VPN entries on your computers. and displays their logon details: User Name. Password. and Domain. You can use it to recover a lost password of your Internet connection or VPN.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/dialupass.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","14926"
"*\Disable_defender.py*",".{0,1000}\\Disable_defender\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","14949"
"*\DitExplorer.sln*",".{0,1000}\\DitExplorer\.sln.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","14963"
"*\dllinject.py*",".{0,1000}\\dllinject\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","14980"
"*\DomainPasswordSpray\*",".{0,1000}\\DomainPasswordSpray\\.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","15025"
"*\DomainPasswordSpray-master*",".{0,1000}\\DomainPasswordSpray\-master.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","15026"
"*\domcachedump.py*",".{0,1000}\\domcachedump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","15029"
"*\DosDevices\mimidrv*",".{0,1000}\\DosDevices\\mimidrv.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","15041"
"*\dpat.py*",".{0,1000}\\dpat\.py.{0,1000}","offensive_tool_keyword","DPAT","Domain Password Audit Tool for Pentesters","T1003 - T1087 - T1110 - T1555","TA0006 - TA0004 - TA0002 - TA0005","N/A","N/A","Credential Access","https://github.com/clr2of8/DPAT","1","0","N/A","N/A","10","10","954","156","2022-06-24T21:41:43Z","2016-11-22T22:00:21Z","15060"
"*\DragonCastle.dll*",".{0,1000}\\DragonCastle\.dll.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","15061"
"*\DragonCastle.pdb*",".{0,1000}\\DragonCastle\.pdb.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","15062"
"*\DragonCastle-master\*",".{0,1000}\\DragonCastle\-master\\.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","15063"
"*\DriverDump.c*",".{0,1000}\\DriverDump\.c.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","15069"
"*\DriverDump.exe*",".{0,1000}\\DriverDump\.exe.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","15070"
"*\DriverDump.sln*",".{0,1000}\\DriverDump\.sln.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","15071"
"*\DriverDump.vcxproj*",".{0,1000}\\DriverDump\.vcxproj.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","15072"
"*\dumper2020_exe*",".{0,1000}\\dumper2020_exe.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","N/A","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","15101"
"*\dumper2020_exe.cpp*",".{0,1000}\\dumper2020_exe\.cpp.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","N/A","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","15102"
"*\dumper2020-master*",".{0,1000}\\dumper2020\-master.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","N/A","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","15103"
"*\dumpert.dmp*",".{0,1000}\\dumpert\.dmp.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","0","N/A","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","15105"
"*\dumpert.py*",".{0,1000}\\dumpert\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","15106"
"*\DumpExt.dll*",".{0,1000}\\DumpExt\.dll.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","15108"
"*\DumpIt.exe*",".{0,1000}\\DumpIt\.exe.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","15109"
"*\dump-lsass.py*",".{0,1000}\\dump\-lsass\.py.{0,1000}","offensive_tool_keyword","impacket","Dump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems.","T1021 - T1047 - T1055.011 - T1003","TA0002 - TA0005 - TA0006","N/A","Dispossessor - Black Basta","Credential Access","https://github.com/kaluche/Dump-Lsass","1","0","N/A","N/A","10","1","1","0","2019-11-14T18:15:26Z","2019-11-20T20:26:27Z","15111"
"*\DumpLSASS-main*",".{0,1000}\\DumpLSASS\-main.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","15112"
"*\DumpNParse.exe*",".{0,1000}\\DumpNParse\.exe.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","0","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","15113"
"*\DumpNParse-main*",".{0,1000}\\DumpNParse\-main.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","0","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","15115"
"*\DumpS1.ps1*",".{0,1000}\\DumpS1\.ps1.{0,1000}","greyware_tool_keyword","SentinelAgent","dump a process with SentinelAgent.exe","T1003 - T1055","TA0006 - TA0005","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e","1","0","N/A","N/A","8","7","N/A","N/A","N/A","N/A","15119"
"*\dumpSecrets.go*",".{0,1000}\\dumpSecrets\.go.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","15120"
"*\dumpsecrets_test.go*",".{0,1000}\\dumpsecrets_test\.go.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","15121"
"*\DumpShellcode*",".{0,1000}\\DumpShellcode.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","0","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","15122"
"*\DumpSomeHashesAuto.py*",".{0,1000}\\DumpSomeHashesAuto\.py.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","15123"
"*\DumpSvc.exe*",".{0,1000}\\DumpSvc\.exe.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","15124"
"*\DumpThatLSASS.*",".{0,1000}\\DumpThatLSASS\..{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","15125"
"*\DumpThatLSASS\*",".{0,1000}\\DumpThatLSASS\\.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","15126"
"*\dumpy.exe*",".{0,1000}\\dumpy\.exe.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","0","N/A","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","15129"
"*\EASSniper.ps1*",".{0,1000}\\EASSniper\.ps1.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","15209"
"*\EASSniper.ps1*",".{0,1000}\\EASSniper\.ps1.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","15210"
"*\eas-valid-users.txt*",".{0,1000}\\eas\-valid\-users\.txt.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","15211"
"*\ETWHash.*",".{0,1000}\\ETWHash\..{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","0","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","15314"
"*\EvilLsassTwin\*",".{0,1000}\\EvilLsassTwin\\.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","15347"
"*\ExploitElevate.cpp*",".{0,1000}\\ExploitElevate\.cpp.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","15395"
"*\exported_credentials.csv*",".{0,1000}\\exported_credentials\.csv.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","N/A","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","15398"
"*\ExtPassword.chm*",".{0,1000}\\ExtPassword\.chm.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15404"
"*\ExtPassword.html*",".{0,1000}\\ExtPassword\.html.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15405"
"*\extpassword.zip*",".{0,1000}\\extpassword\.zip.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15406"
"*\ExtPassword_lng.ini*",".{0,1000}\\ExtPassword_lng\.ini.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15407"
"*\FakeLogonScreen.exe*",".{0,1000}fakelogonscreen\.exe.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","15415"
"*\FakeLogonScreen.sln*",".{0,1000}\\FakeLogonScreen\.sln.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","15417"
"*\fakelogonscreen-master*",".{0,1000}\\fakelogonscreen\-master.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","15418"
"*\Fertliser.exe*",".{0,1000}\\Fertliser\.exe.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","0","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","15423"
"*\Fertliser.pdb*",".{0,1000}\\Fertliser\.pdb.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","0","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","15424"
"*\firefox\getCredsfirefox.h*",".{0,1000}\\firefox\\getCredsfirefox\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","15449"
"*\firefox\getCredsfirefox2.h*",".{0,1000}\\firefox\\getCredsfirefox2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","15450"
"*\Forensike.dmp*",".{0,1000}\\Forensike\.dmp.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","15456"
"*\Forensike.ps1*",".{0,1000}\\Forensike\.ps1.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","15457"
"*\forensike_results.txt*",".{0,1000}\\forensike_results\.txt.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","15458"
"*\FormThief-main*",".{0,1000}\\FormThief\-main.{0,1000}","offensive_tool_keyword","FormThief","Spoofing desktop login applications with WinForms and WPF","T1204.002 - T1056.004 - T1071.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/mlcsec/FormThief","1","0","N/A","N/A","8","2","173","31","2024-02-19T22:40:09Z","2024-02-19T22:34:07Z","15473"
"*\FoxmailDump.cpp*",".{0,1000}\\FoxmailDump\.cpp.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","15474"
"*\Get-FunctionHash.ps1*",".{0,1000}\\Get\-FunctionHash\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","15566"
"*\getlsasrvaddr.exe*",".{0,1000}\\getlsasrvaddr\.exe.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","15580"
"*\Get-NetNTLM.ps1*",".{0,1000}\\Get\-NetNTLM\.ps1.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","0","N/A","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","15584"
"*\Get-PEHeader.ps1*",".{0,1000}\\Get\-PEHeader\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","15596"
"*\Get-SpoolStatus.ps1*",".{0,1000}\\Get\-SpoolStatus\.ps1.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","15605"
"*\GoAWSConsoleSpray-master*",".{0,1000}\\GoAWSConsoleSpray\-master.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","0","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","15650"
"*\gocrack-1.0.zip*",".{0,1000}\\gocrack\-1\.0\.zip.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","N/A","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","15651"
"*\gocrack-master.*",".{0,1000}\\gocrack\-master\..{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","N/A","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","15652"
"*\GodFault.*",".{0,1000}\\GodFault\..{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","15653"
"*\Golden.ps1*",".{0,1000}\\Golden\.ps1.{0,1000}","offensive_tool_keyword","ADFSDump-PS","ADFSDump to assist with GoldenSAML","T1078 - T1552.004 - T1558.004","TA0006 ","N/A","N/A","Credential Access","https://github.com/ZephrFish/ADFSDump-PS","1","0","N/A","N/A","10","1","31","8","2024-05-20T00:00:19Z","2024-05-19T00:46:28Z","15668"
"*\go-lsass.exe*",".{0,1000}\\go\-lsass\.exe.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","0","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","15672"
"*\go-lsass-master.zip*",".{0,1000}\\go\-lsass\-master\.zip.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","0","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","15673"
"*\go-lsass-master\*",".{0,1000}\\go\-lsass\-master\\.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","0","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","15674"
"*\go-secdump*",".{0,1000}\\go\-secdump.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","0","N/A","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","15683"
"*\gosecretsdump.*",".{0,1000}\\gosecretsdump\..{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","15685"
"*\gosecretsdump\*",".{0,1000}\\gosecretsdump\\.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","15686"
"*\gosecretsdump_linux*",".{0,1000}\\gosecretsdump_linux.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","15687"
"*\gosecretsdump_mac*",".{0,1000}\\gosecretsdump_mac.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","15688"
"*\gosecretsdump_win*",".{0,1000}\\gosecretsdump_win.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","15689"
"*\GPUnprotect.zip*",".{0,1000}\\GPUnprotect\.zip.{0,1000}","offensive_tool_keyword","GlobalUnProtect","Decrypt GlobalProtect configuration and cookie files.","T1552 - T1003 - T1555","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rotarydrone/GlobalUnProtect","1","0","N/A","N/A","9","2","147","19","2024-09-10T20:19:24Z","2024-09-04T15:31:52Z","15715"
"*\grabchrome.exe*",".{0,1000}\\grabchrome\.exe.{0,1000}","offensive_tool_keyword","GrabChrome","HelloKitty Grabber used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15716"
"*\grbachrome.exe*",".{0,1000}\\grbachrome\.exe.{0,1000}","offensive_tool_keyword","GrabChrome","HelloKitty Grabber used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15725"
"*\gsecdump-*.exe*",".{0,1000}\\gsecdump\-.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15737"
"*\gsecdump.exe*",".{0,1000}\\gsecdump\.exe.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15738"
"*\hack-browser-data-linux-386.zip*",".{0,1000}\\hack\-browser\-data\-linux\-386\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","15757"
"*\hack-browser-data-linux-amd64.zip*",".{0,1000}\\hack\-browser\-data\-linux\-amd64\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","15758"
"*\hack-browser-data-linux-arm.zip*",".{0,1000}\\hack\-browser\-data\-linux\-arm\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","15759"
"*\hack-browser-data-linux-arm64.zip*",".{0,1000}\\hack\-browser\-data\-linux\-arm64\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","15760"
"*\hack-browser-data-osx-64bit.zip*",".{0,1000}\\hack\-browser\-data\-osx\-64bit\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","15761"
"*\hack-browser-data-windows-32bit.zip*",".{0,1000}\\hack\-browser\-data\-windows\-32bit\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","15762"
"*\hack-browser-data-windows-64bit.zip*",".{0,1000}\\hack\-browser\-data\-windows\-64bit\.zip.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","15763"
"*\hashview.py*",".{0,1000}\\hashview\.py.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","0","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","15778"
"*\httprelayserver.py*",".{0,1000}\\httprelayserver\.py.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","0","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","15843"
"*\icebreaker.py*",".{0,1000}\\icebreaker\.py.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","15865"
"*\iepv.cfg*",".{0,1000}\\iepv\.cfg.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15873"
"*\iepv.exe*",".{0,1000}\\iepv\.exe.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15874"
"*\IEPV.EXE-*.pf*",".{0,1000}\\IEPV\.EXE\-.{0,1000}\.pf.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15875"
"*\iepv.zip.lnk*",".{0,1000}\\iepv\.zip\.lnk.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","15876"
"*\impacketfile.py*",".{0,1000}\\impacketfile\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","15890"
"*\impacket-out\*",".{0,1000}\\impacket\-out\\.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","15891"
"*\Invoke-Shellcode.ps1*",".{0,1000}\\Invoke\-Shellcode\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","15986"
"*\ironvest\getCredsironvest.h*",".{0,1000}\\ironvest\\getCredsironvest\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","16010"
"*\kaspersky\getCredsKasperskyEntries.h*",".{0,1000}\\kaspersky\\getCredsKasperskyEntries\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","16064"
"*\katz.ps1*",".{0,1000}\\katz\.ps1.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz powershell alternative name","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","16066"
"*\kcredentialprovider.log*",".{0,1000}\\kcredentialprovider\.log.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz log files","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","16074"
"*\KeeFarce.exe*",".{0,1000}\\KeeFarce\.exe.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","16076"
"*\KeeFarceDLL.dll*",".{0,1000}\\KeeFarceDLL\.dll.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","16077"
"*\KeePass.sln*",".{0,1000}\\KeePass\.sln.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","16078"
"*\keepass_export.csv*",".{0,1000}\\keepass_export\.csv.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","16080"
"*\KeePassFox.csproj*",".{0,1000}\\KeePassFox\.csproj.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","16082"
"*\KeePassFox.sln*",".{0,1000}\\KeePassFox\.sln.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","16083"
"*\keeper\getCredskeeper1.h*",".{0,1000}\\keeper\\getCredskeeper1\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","16084"
"*\keeper\getCredskeeper2.h*",".{0,1000}\\keeper\\getCredskeeper2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","16085"
"*\keeper\getCredskeeper3.h*",".{0,1000}\\keeper\\getCredskeeper3\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","16086"
"*\KeePwn.py*",".{0,1000}\\KeePwn\.py.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","16087"
"*\KeePwn\keepwn\*",".{0,1000}\\KeePwn\\keepwn\\.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","16088"
"*\KeePwn-0.3\*",".{0,1000}\\KeePwn\-0\.3\\.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","16089"
"*\KeePwn-main\*",".{0,1000}\\KeePwn\-main\\.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","16090"
"*\KeeTheft.config*",".{0,1000}\\KeeTheft\.config.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","16091"
"*\KeeTheft.exe*",".{0,1000}\\KeeTheft\.exe.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","16093"
"*\KeeTheft.exe*",".{0,1000}\\KeeTheft\.exe.{0,1000}","offensive_tool_keyword","KeeThiefSyscalls","Patch GhostPack/KeeThief for it to use DInvoke and syscalls","T1003.001 - T1558.002","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/Metro-Holografix/KeeThiefSyscalls","1","0","N/A","private github repo","10","","N/A","","","","16094"
"*\KeeTheft.INI*",".{0,1000}\\KeeTheft\.INI.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","16096"
"*\KeeThief.ps1*",".{0,1000}\\KeeThief\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","16097"
"*\KerberOPSEC.cs*",".{0,1000}\\KerberOPSEC\.cs.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","16109"
"*\KerberOPSEC.sln*",".{0,1000}\\KerberOPSEC\.sln.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","16110"
"*\kerbrute.py*",".{0,1000}\\kerbrute\.py.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","16112"
"*\KeyCredentialLink.ps1*",".{0,1000}\\KeyCredentialLink\.ps1.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","16116"
"*\Kill_protector.py*",".{0,1000}\\Kill_protector\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","16136"
"*\killmsas.exe*",".{0,1000}\\killmsas\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","N/A","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","16145"
"*\kiwidns.log*",".{0,1000}\\kiwidns\.log.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz log files","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","16154"
"*\kiwifilter.log*",".{0,1000}\\kiwifilter\.log.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz log files","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","16155"
"*\kiwinp.log*",".{0,1000}\\kiwinp\.log.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz log files","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","16156"
"*\kiwissp.log*",".{0,1000}\\kiwissp\.log.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz log files","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","16157"
"*\kiwisub.log*",".{0,1000}\\kiwisub\.log.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz log files","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","16158"
"*\knowsmore.py*",".{0,1000}\\knowsmore\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","16160"
"*\kuhl_m_sekurlsa.c*",".{0,1000}\\kuhl_m_sekurlsa\.c.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","16186"
"*\LAPSDumper\*",".{0,1000}\\LAPSDumper\\.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","0","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","16203"
"*\lastpass\getCredslastpassEntries.h*",".{0,1000}\\lastpass\\getCredslastpassEntries\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","16207"
"*\lastpass\getCredslastpassMasterPass.h*",".{0,1000}\\lastpass\\getCredslastpassMasterPass\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","16208"
"*\lastpass\getCredslastpassMasterUsername.h*",".{0,1000}\\lastpass\\getCredslastpassMasterUsername\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","16209"
"*\liblsarelay.dll*",".{0,1000}\\liblsarelay\.dll.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","0","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","16236"
"*\liblsarelayx.dll*",".{0,1000}\\liblsarelayx\.dll.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","0","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","16237"
"*\lnkbomb.py*",".{0,1000}\\lnkbomb\.py.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","0","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","16307"
"*\lnkbomb-1.0\*",".{0,1000}\\lnkbomb\-1\.0\\.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","0","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","16308"
"*\load_ssp.x64.exe*",".{0,1000}\\load_ssp\.x64\.exe.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","16312"
"*\localbrute.ps1*",".{0,1000}\\localbrute\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Credential Access","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","0","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","16329"
"*\localbrute-extra-mini.ps1*",".{0,1000}\\localbrute\-extra\-mini\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Credential Access","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","0","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","16331"
"*\Lock.exe disk*",".{0,1000}\\Lock\.exe\sdisk.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","16340"
"*\loginAAD.ps1*",".{0,1000}\\loginAAD\.ps1.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","16351"
"*\logonuifox.dll*",".{0,1000}\\logonuifox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","16365"
"*\LostMyPassword.cfg*",".{0,1000}\\LostMyPassword\.cfg.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","16384"
"*\LostMyPassword_lng.ini",".{0,1000}\\LostMyPassword_lng\.ini","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","16385"
"*\LostMyPassword32bit*",".{0,1000}\\LostMyPassword32bit.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","16386"
"*\lsadump.py*",".{0,1000}\\lsadump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","16388"
"*\lsarelayx.cpp*",".{0,1000}\\lsarelayx\.cpp.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","0","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","16390"
"*\lsarelayx.csproj*",".{0,1000}\\lsarelayx\.csproj.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","0","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","16391"
"*\lsarelayx.sln*",".{0,1000}\\lsarelayx\.sln.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","0","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","16392"
"*\lsasecrets.py*",".{0,1000}\\lsasecrets\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","16393"
"*\LSASecrets.txt*",".{0,1000}\\LSASecrets\.txt.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","16394"
"*\lsass.DMP",".{0,1000}\\lsass\.DMP","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","16395"
"*\lsass.dmp*",".{0,1000}\\lsass\.dmp.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","0","N/A","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","16396"
"*\lsass.dmp*",".{0,1000}\\lsass\.dmp.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","16398"
"*\lsass.dmp*",".{0,1000}\\lsass\.dmp.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","16400"
"*\lsass.dmp*",".{0,1000}\\lsass\.dmp.{0,1000}","greyware_tool_keyword","Procdump","dump lsass process with procdump","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","16401"
"*\lsass.rar*",".{0,1000}\\lsass\.rar.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","16402"
"*\lsass.zip*",".{0,1000}\\lsass\.zip.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","16403"
"*\Lsass_Shtinkering.cpp*",".{0,1000}\\Lsass_Shtinkering\.cpp.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","16404"
"*\LSASS_Shtinkering.sln*",".{0,1000}\\LSASS_Shtinkering\.sln.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","16405"
"*\LSASS_Shtinkering\*",".{0,1000}\\LSASS_Shtinkering\\.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","16406"
"*\lsass64.exe*",".{0,1000}\\lsass64\.exe.{0,1000}","offensive_tool_keyword","lslsass","dump active logon session password hashes from the lsass process (old tool for vista and older)","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","16407"
"*\Lsass-Shtinkering-main*",".{0,1000}\\Lsass\-Shtinkering\-main.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","16409"
"*\LsassSilentProcessExit*",".{0,1000}\\LsassSilentProcessExit.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","0","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","16410"
"*\Lsassx.ps1*",".{0,1000}\\Lsassx\.ps1.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","16411"
"*\Lsassx-main*",".{0,1000}\\Lsassx\-main.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","16412"
"*\Lsassx-OBF.ps1*",".{0,1000}\\Lsassx\-OBF\.ps1.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","16413"
"*\lsa-whisperer-*",".{0,1000}\\lsa\-whisperer\-.{0,1000}","greyware_tool_keyword","lsa-whisperer","Tools for interacting with authentication packages using their individual message protocols","T1556.002 - T1003.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/EvanMcBroom/lsa-whisperer","1","0","N/A","N/A","6","4","316","29","2025-04-01T13:54:17Z","2022-08-04T14:35:45Z","16415"
"*\lslsass.exe*",".{0,1000}\\lsass\.exe.{0,1000}","offensive_tool_keyword","lslsass","dump active logon session password hashes from the lsass process (old tool for vista and older)","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","16416"
"*\luna.log*",".{0,1000}\\luna\.log.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","16419"
"*\Luna-Logged-*.zip*",".{0,1000}\\Luna\-Logged\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","16420"
"*\LyncSniper.ps1*",".{0,1000}\/LyncSniper\.ps1.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","16421"
"*\m365-fatigue.py*",".{0,1000}\\m365\-fatigue\.py.{0,1000}","offensive_tool_keyword","m365-fatigue","automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.","T1110.001 - T1078.001 - T1556.004","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/0xB455/m365-fatigue","1","0","N/A","N/A","10","1","77","7","2024-04-08T14:53:44Z","2023-11-30T13:33:03Z","16423"
"*\mailpv.exe*",".{0,1000}\\mailpv\.exe.{0,1000}","offensive_tool_keyword","MailPassView","Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","16435"
"*\malDll.dll*",".{0,1000}\\malDll\.dll.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","16442"
"*\malseclogon.*",".{0,1000}\\malseclogon\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","16443"
"*\mimidogz-master*",".{0,1000}\\mimidogz\-master.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","0","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","16584"
"*\mimilib.dll*",".{0,1000}\\mimilib\.dll.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","16591"
"*\Minidump.exe c:\*",".{0,1000}\\Minidump\.exe\sc\:\\.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","16628"
"*\Minidump.exe"" c:\*",".{0,1000}\\Minidump\.exe\""\sc\:\\.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","16629"
"*\MiniDump-main*",".{0,1000}\\MiniDump\-main.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","16631"
"*\MiniDumpToMem.cs*",".{0,1000}\\MiniDumpToMem\.cs.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","16633"
"*\MirrorDump.csproj*",".{0,1000}\\MirrorDump\.csproj.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","16635"
"*\MirrorDump.exe*",".{0,1000}\\MirrorDump\.exe.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","16636"
"*\MirrorDump.sln*",".{0,1000}\\MirrorDump\.sln.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","16637"
"*\MirrorDump\MinHook*",".{0,1000}\\MirrorDump\\MinHook.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","16638"
"*\MirrorDump\MiniDump\*",".{0,1000}\\MirrorDump\\MiniDump\\.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","16639"
"*\MirrorDump-master*",".{0,1000}\\MirrorDump\-master.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","16640"
"*\Modules\Backdoor.cs*",".{0,1000}\\Modules\\Backdoor\.cs.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","16651"
"*\MostPopularPasswords.txt*",".{0,1000}\\MostPopularPasswords\.txt.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","16660"
"*\mremoteng-decrypt\*",".{0,1000}\\mremoteng\-decrypt\\.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","0","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","16668"
"*\MSFRottenPotato.h*",".{0,1000}\\MSFRottenPotato\.h.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","0","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","16674"
"*\mssprinkler.ps1*",".{0,1000}\\mssprinkler\.ps1.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","0","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","16696"
"*\mstscfox.dll*",".{0,1000}\\mstscfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","16703"
"*\MultiDump.c*",".{0,1000}\\MultiDump\.c.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","16704"
"*\MultiDump.exe*",".{0,1000}\\MultiDump\.exe.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","16705"
"*\MultiDump.exe*",".{0,1000}\\MultiDump\.exe.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","16706"
"*\MultiDump.sln*",".{0,1000}\\MultiDump\.sln.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","16707"
"*\MultiDump.vcxproj*",".{0,1000}\\MultiDump\.vcxproj.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","16708"
"*\mzcv.exe*",".{0,1000}\\mzcv\.exe.{0,1000}","greyware_tool_keyword","MozillaCookiesView","nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors","T1070 - T1552.001 - T1125 - T1005","TA0009 - TA0005","N/A","MuddyWater","Credential Access","https://www.nirsoft.net/utils/mzcv.html","1","0","N/A","N/A","7","10","N/A","N/A","N/A","N/A","16717"
"*\mzcv-x64.zip*",".{0,1000}\\mzcv\-x64\.zip.{0,1000}","greyware_tool_keyword","MozillaCookiesView","nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors","T1070 - T1552.001 - T1125 - T1005","TA0009 - TA0005","N/A","MuddyWater","Credential Access","https://www.nirsoft.net/utils/mzcv.html","1","0","N/A","N/A","7","10","N/A","N/A","N/A","N/A","16718"
"*\nanodump*",".{0,1000}\\nanodump.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","16727"
"*\nanodump.c*",".{0,1000}\\nanodump\.c.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","16728"
"*\NativeDump.csproj*",".{0,1000}\\NativeDump\.csproj.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","16734"
"*\NativeDump.exe*",".{0,1000}\\NativeDump\.exe.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","16735"
"*\NativeDump.sln*",".{0,1000}\\NativeDump\.sln.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","16736"
"*\NativeDump\Program.cs*",".{0,1000}\\NativeDump\\Program\.cs.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","16737"
"*\nc_srv.bat",".{0,1000}\\nc_srv\.bat","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","16744"
"*\Necro-Stealer-*.zip*",".{0,1000}\\Necro\-Stealer\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","Necro-Stealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/Necro-Stealer","1","0","N/A","N/A","8","1","6","1","2022-12-06T16:06:55Z","2022-12-06T15:52:17Z","16754"
"*\netsh.exe"" wlan show profiles*",".{0,1000}netsh\.exe\swlan\sshow\sprofiles\skey\=clear.{0,1000}","greyware_tool_keyword","netsh","display saved Wi-Fi profiles on a Windows system","T1003 - T1552.001","TA0006 - TA0009","N/A","Volt Typhoon - Naikon - APT32 - Magic Hound - Lazarus Group - Carbanak - Dragonfly","Credential Access","N/A","1","0","N/A","N/A","7","7","N/A","N/A","N/A","N/A","16822"
"*\NiceRAT.py*",".{0,1000}\\NiceRAT\.py.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","16854"
"*\NiceRAT-1.0.0.zip*",".{0,1000}\\NiceRAT\-1\.0\.0\.zip.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","16855"
"*\NiceRAT-main\*",".{0,1000}\\NiceRAT\-main\\.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","16856"
"*\Nimperiments-main*",".{0,1000}\\Nimperiments\-main.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","16867"
"*\NLBrute*.rar*",".{0,1000}\\NLBrute.{0,1000}\.rar.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","0","N/A","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","16884"
"*\NLBrute*.zip*",".{0,1000}\\NLBrute.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","0","N/A","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","16885"
"*\NLBrute.exe*",".{0,1000}\\NLBrute\.exe.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","0","N/A","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","16886"
"*\Nofault.exe*",".{0,1000}\\Nofault\.exe.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","16944"
"*\norton\getCredsnorton.h*",".{0,1000}\\norton\\getCredsnorton\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","16959"
"*\norton\getCredsnorton2.h*",".{0,1000}\\norton\\getCredsnorton2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","16960"
"*\NPPSpy.c*",".{0,1000}\\NPPSpy\.c.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","0","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","16967"
"*\NPPSPY.dll*",".{0,1000}\\NPPSPY\.dll.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","0","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","16968"
"*\NPPSpy.exe*",".{0,1000}\\NPPSpy\.exe.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","0","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","16969"
"*\NPPSpy.txt*",".{0,1000}\\NPPSpy\.txt.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","0","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","16970"
"*\ntdsuseraccount.py*",".{0,1000}\\ntdsuseraccount\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","16988"
"*\NTHASH-FPC\*",".{0,1000}\\NTHASH\-FPC\\.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","16991"
"*\ntlmdecoder.py*",".{0,1000}\\ntlmdecoder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","16993"
"*\ntlmdecoder.py*",".{0,1000}\\ntlmdecoder\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","16994"
"*\NtlmRelayToEWS\*",".{0,1000}\\NtlmRelayToEWS\\.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","0","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","16996"
"*\NtlmThief\*",".{0,1000}\\NtlmThief\\.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","0","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","17001"
"*\o365_enum_activesync.py*",".{0,1000}\\o365_enum_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17012"
"*\o365_enum_office.py*",".{0,1000}\\o365_enum_office\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17013"
"*\o365_enum_onedrive.py*",".{0,1000}\\o365_enum_onedrive\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17014"
"*\o365_spray_activesync.py*",".{0,1000}\\o365_spray_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17015"
"*\o365_spray_adfs.py*",".{0,1000}\\o365_spray_adfs\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17016"
"*\o365_spray_msol.py*",".{0,1000}\\o365_spray_msol\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17017"
"*\o365spray.py*",".{0,1000}\\o365spray\.py.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","17018"
"*\OfflineSamTool.exe*",".{0,1000}\\OfflineSamTool\.exe.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17037"
"*\OfflineSamTool.h*",".{0,1000}\\OfflineSamTool\.h.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17038"
"*\oh365userfinder.py*",".{0,1000}\\oh365userfinder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","17039"
"*\omnispray.py*",".{0,1000}\\omnispray\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17040"
"*\Omnispray-main*",".{0,1000}\\Omnispray\-main.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17041"
"*\online_brute.gz*",".{0,1000}\\online_brute\.gz.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","0","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","17043"
"*\openchromedumps.exe*",".{0,1000}\\openchromedumps\.exe.{0,1000}","offensive_tool_keyword","OpenChromeDumps","OpenChrome Dump used with GrabChrome for credential access","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Yanluowang - Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17045"
"*\openChromeDumps.pdb*",".{0,1000}\\openChromeDumps\.pdb.{0,1000}","offensive_tool_keyword","OpenChromeDumps","OpenChrome Dump used with GrabChrome for credential access","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Yanluowang - Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17046"
"*\OperaPassView.chm*",".{0,1000}\\OperaPassView\.chm.{0,1000}","offensive_tool_keyword","OperaPassView","OperaPassView is a small password recovery tool that decrypts the content of the Opera Web browser password file (wand.dat) and displays the list of all Web site passwords stored in this file","T1003 - T1555 - T1145","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/opera_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17049"
"*\operapassview.zip",".{0,1000}\\operapassview\.zip","offensive_tool_keyword","OperaPassView","OperaPassView is a small password recovery tool that decrypts the content of the Opera Web browser password file (wand.dat) and displays the list of all Web site passwords stored in this file","T1003 - T1555 - T1145","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/opera_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17050"
"*\OperaPassView_lng.ini*",".{0,1000}\\OperaPassView_lng\.ini.{0,1000}","offensive_tool_keyword","OperaPassView","OperaPassView is a small password recovery tool that decrypts the content of the Opera Web browser password file (wand.dat) and displays the list of all Web site passwords stored in this file","T1003 - T1555 - T1145","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/opera_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17051"
"*\oset.exe*",".{0,1000}\\oset\.exe.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17059"
"*\oset.zip*",".{0,1000}\\oset\.zip.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17060"
"*\oSpray.py*",".{0,1000}\\oSpray\.py.{0,1000}","offensive_tool_keyword","Okta-Password-Sprayer","This script is a multi-threaded Okta password sprayer.","T1110 - T1110.003 - T1621","TA0006","N/A","N/A","Credential Access","https://github.com/Rhynorater/Okta-Password-Sprayer","1","0","N/A","N/A","10","1","70","16","2024-01-05T16:24:38Z","2018-09-24T23:39:16Z","17061"
"*\Out-Minidump.ps1*",".{0,1000}\\Out\-Minidump\.ps1.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","17069"
"*\owa_enum_activesync.py*",".{0,1000}\\owa_enum_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17070"
"*\owa_spray_activesync.py*",".{0,1000}\\owa_spray_activesync\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17071"
"*\owa-sprayed-creds.txt*",".{0,1000}\\owa\-sprayed\-creds\.txt.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","17072"
"*\paloalto_enum_globalprotectportal.py*",".{0,1000}\\paloalto_enum_globalprotectportal\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17096"
"*\paloalto_spray_globalprotectportal.py*",".{0,1000}\\paloalto_spray_globalprotectportal\.py.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","17097"
"*\pamspy.bpf.c*",".{0,1000}\\pamspy\.bpf\.c.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","17098"
"*\pamspy_event.h*",".{0,1000}\\pamspy_event\.h.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","17099"
"*\pandora.cpp*",".{0,1000}\\pandora\.cpp.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","17101"
"*\pandora.sln*",".{0,1000}\\pandora\.sln.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","17102"
"*\PassSpray.ps1*",".{0,1000}\\PassSpray\.ps1.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","0","N/A","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","17114"
"*\passwarden\app\getCredspasswarden.h*",".{0,1000}\\passwarden\\app\\getCredspasswarden\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","17124"
"*\passwarden\app\getCredspasswarden2.h*",".{0,1000}\\passwarden\\app\\getCredspasswarden2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","17125"
"*\password.lst*",".{0,1000}\\password\.lst.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","17126"
"*\passwordboss\app\getCredspasswordbossapp1.h*",".{0,1000}\\passwordboss\\app\\getCredspasswordbossapp1\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","17127"
"*\passwordboss\app\getCredspasswordbossapp2.h*",".{0,1000}\\passwordboss\\app\\getCredspasswordbossapp2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","17128"
"*\pcunlocker.iso*",".{0,1000}\\pcunlocker\.iso.{0,1000}","greyware_tool_keyword","pcunlocker","Reset and unlock forgotten Windows login password","T1078","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://www.pcunlocker.com/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17177"
"*\pcunlocker_trial.zip*",".{0,1000}\\pcunlocker_trial\.zip.{0,1000}","greyware_tool_keyword","pcunlocker","Reset and unlock forgotten Windows login password","T1078","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://www.pcunlocker.com/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17178"
"*\physmem2minidump.py*",".{0,1000}\\physmem2minidump\.py.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","17254"
"*\physmem2profit-master*",".{0,1000}\\physmem2profit\-master.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","17255"
"*\pipe\\cachedumppipe*",".{0,1000}\\pipe\\\\cachedumppipe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#namedpipe","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","17266"
"*\pipe\cachedumppipe*",".{0,1000}\\pipe\\cachedumppipe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#namedpipe","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","17268"
"*\pipe\gsecdump_*",".{0,1000}\\pipe\\gsecdump_.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#namedpipe","N/A","10","10","N/A","N/A","N/A","N/A","17272"
"*\pipe\WCEServicePipe*",".{0,1000}\\pipe\\WCEServicePipe.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#namedpipe","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","17281"
"*\POSTDump.csproj*",".{0,1000}\\POSTDump\.csproj.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","17343"
"*\PostDump.exe*",".{0,1000}\\PostDump\.exe.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","17344"
"*\POSTDump.sln*",".{0,1000}\\POSTDump\.sln.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","17345"
"*\POSTDump\POSTDump\*",".{0,1000}\\POSTDump\\POSTDump\\.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","17346"
"*\POSTMiniDump\*",".{0,1000}\\POSTMiniDump\\.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","17348"
"*\PowerBruteLogon*",".{0,1000}\\PowerBruteLogon.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","0","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","17354"
"*\ppl_dump.*",".{0,1000}\\ppl_dump\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","17415"
"*\PPLBlade-main*",".{0,1000}\\PPLBlade\-main.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","17416"
"*\PPLFault*",".{0,1000}\\PPLFault.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","17417"
"*\PPLmedic.cpp*",".{0,1000}\\PPLmedic\.cpp.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","17419"
"*\PPLmedic.exe*",".{0,1000}\\PPLmedic\.exe.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","17420"
"*\PPLmedic\PPLmedic*",".{0,1000}\\PPLmedic\\PPLmedic.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","17421"
"*\pplsystem.exe*",".{0,1000}\\pplsystem\.exe.{0,1000}","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","0","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","17422"
"*\PPLSystem-main*",".{0,1000}\\PPLSystem\-main.{0,1000}","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","0","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","17423"
"*\Pre2kSpray.ps1*",".{0,1000}\\Pre2kSpray\.ps1.{0,1000}","offensive_tool_keyword","Invoke-Pre2kSpray","Enumerate domain machine accounts and perform pre2k password spraying.","T1087.002 - T1110.003","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/eversinc33/Invoke-Pre2kSpray","1","0","N/A","N/A","8","1","69","11","2023-07-14T06:50:22Z","2023-07-05T10:07:38Z","17425"
"*\PredatorTheStealer Dll.*",".{0,1000}\\PredatorTheStealer\sDll\..{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","17426"
"*\PredatorTheStealer.*",".{0,1000}\\PredatorTheStealer\..{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","17427"
"*\PrintCreds.py*",".{0,1000}\\PrintCreds\.py.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","17452"
"*\Procdump.zip*",".{0,1000}\\Procdump\.zip.{0,1000}","greyware_tool_keyword","Procdump","dump lsass process with procdump","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17482"
"*\ProduKey.exe*",".{0,1000}\\ProduKey\.exe.{0,1000}","greyware_tool_keyword","produkey","ProduKey is a small utility that displays the ProductID and the CD-Key of Microsoft Office (Microsoft Office 2003. Microsoft Office 2007). Windows (Including Windows 8/7/Vista). Exchange Server. and SQL Server installed on your computer. You can view this information for your current running operating system. or for another operating system/computer - by using command-line options. This utility can be useful if you lost the product key of your Windows/Office. and you want to reinstall it on your computer.","T1003.001 - T1003.002 - T1012 - T1057 - T1518","TA0006 - TA0007 - TA0009","N/A","Evilnum","Credential Access","https://www.nirsoft.net/utils/product_cd_key_viewer.html","1","0","N/A","N/A","6","10","N/A","N/A","N/A","N/A","17489"
"*\ProgramData\found_shares.txt*",".{0,1000}\\ProgramData\\found_shares\.txt.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","17550"
"*\PSPY.dll*",".{0,1000}\\PSPY\.dll.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","0","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","17621"
"*\PSPY.exe*",".{0,1000}\\PSPY\.exe.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","0","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","17622"
"*\Public\Documents\DSInternals*",".{0,1000}\\Public\\Documents\\DSInternals.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","17638"
"*\Public\Music\RDPCreds.txt*",".{0,1000}\\Public\\Music\\RDPCreds\.txt.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","17640"
"*\Public\panda.raw*",".{0,1000}\\Public\\panda\.raw.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","17641"
"*\Public\simpleMDWD.raw*",".{0,1000}\\Public\\simpleMDWD\.raw.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","17642"
"*\Public\sysMDWD.file*",".{0,1000}\\Public\\sysMDWD\.file.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","17643"
"*\PuTTY ppk Files.csv*",".{0,1000}\\PuTTY\sppk\sFiles\.csv.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","17660"
"*\pwdump.py*",".{0,1000}\\pwdump\.py.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","17662"
"*\pwdump7*",".{0,1000}\\pwdump7.{0,1000}","offensive_tool_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","17665"
"*\pwdump7.zip*",".{0,1000}\\pwdump7\.zip.{0,1000}","offensive_tool_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","17666"
"*\pwdump8*",".{0,1000}\\pwdump8.{0,1000}","offensive_tool_keyword","PwDump8","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://download.openwall.net/pub/projects/john/contrib/pwdump/pwdump8-8.2.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","17667"
"*\PWDumpX.c*",".{0,1000}\\PWDumpX\.c.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","17668"
"*\PWHashes.txt*",".{0,1000}\\PWHashes\.txt.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","17669"
"*\pwned.txt*",".{0,1000}\\pwned\.txt.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","17671"
"*\pysecdump-master*",".{0,1000}\\pysecdump\-master.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","17692"
"*\QuarksADDumper.*",".{0,1000}\\QuarksADDumper\..{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","17699"
"*\QuarksPwDump*",".{0,1000}\\QuarksPwDump.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","17700"
"*\QUARKS-SAM*",".{0,1000}\\QUARKS\-SAM.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","#registry","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","17701"
"*\RagingRotator.go*",".{0,1000}\\RagingRotator\.go.{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","0","N/A","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","17733"
"*\rarreg.key*",".{0,1000}\\rarreg\.key.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","17744"
"*\rawrpc_embedded.py*",".{0,1000}\\rawrpc_embedded\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","17769"
"*\rdcmanfox.dll*",".{0,1000}\\rdcmanfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","17780"
"*\RDP Recognizer.exe*",".{0,1000}\\RDP\sRecognizer\.exe.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","17781"
"*\RDP Recognizer.pdb*",".{0,1000}\\RDP\sRecognizer\.pdb.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","17782"
"*\RDP Recognizer1.exe*",".{0,1000}\\RDP\sRecognizer1\.exe.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","17783"
"*\RDP Recognizer3.exe*",".{0,1000}\\RDP\sRecognizer3\.exe.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","17784"
"*\RDPCreds.txt*",".{0,1000}\\RDPCreds\.txt.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","17789"
"*\RDPCredsStealerDLL*",".{0,1000}\\RDPCredsStealerDLL.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","17790"
"*\RDPHook.dll*",".{0,1000}\\RDPHook\.dll.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","0","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","17791"
"*\RdpStrike.asm*",".{0,1000}\\RdpStrike\.asm.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","0","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","17794"
"*\RdpStrike.cna*",".{0,1000}\\RdpStrike\.cna.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","0","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","17795"
"*\RdpStrike\*",".{0,1000}\\RdpStrike\\.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","0","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","17796"
"*\RdpThief.*",".{0,1000}\\RdpThief\..{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","17797"
"*\RdpThief.dll*",".{0,1000}\\RdpThief\.dll.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","0","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","17799"
"*\RdpThief_x64.*",".{0,1000}\\RdpThief_x64\..{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","17800"
"*\rdpv.exe*",".{0,1000}\\rdpv\.exe.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","0","N/A","N/A","8","10","N/A","N/A","N/A","N/A","17802"
"*\ReflectDump.exe*",".{0,1000}\\ReflectDump\.exe.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","0","N/A","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","17873"
"*\ReflectDump.vcxproj*",".{0,1000}\\ReflectDump\.vcxproj.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","0","N/A","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","17874"
"*\restoresig.py*",".{0,1000}\\restoresig\.py.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","18038"
"*\revshell32.bin*",".{0,1000}\\revshell32\.bin.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","18055"
"*\revshell64.bin*",".{0,1000}\\revshell64\.bin.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","18056"
"*\ROADToken.csproj*",".{0,1000}\\ROADToken\.csproj.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","0","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","18078"
"*\ROADToken.exe*",".{0,1000}\\ROADToken\.exe.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","0","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","18079"
"*\ROADToken.sln*",".{0,1000}\\ROADToken\.sln.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","0","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","18080"
"*\roblox cookies.txt*",".{0,1000}\\roblox\scookies\.txt.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","18085"
"*\roboform\app\getCredsroboformapp.h*",".{0,1000}\\roboform\\app\\getCredsroboformapp\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","18086"
"*\roboform\app\getCredsroboformapp2.h*",".{0,1000}\\roboform\\app\\getCredsroboformapp2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","18087"
"*\roboform\app\getCredsroboformapp3.h*",".{0,1000}\\roboform\\app\\getCredsroboformapp3\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","18088"
"*\roboform\plugin\getCredsroboformplugin.h*",".{0,1000}\\roboform\\plugin\\getCredsroboformplugin\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","18089"
"*\Root\InventoryApplicationFile\offlinesamtool*",".{0,1000}\\Root\\InventoryApplicationFile\\offlinesamtool.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#registry","N/A","10","10","N/A","N/A","N/A","N/A","18095"
"*\Routerscan.7z*",".{0,1000}\\Routerscan\.7z.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","18111"
"*\RouterScan.exe*",".{0,1000}\\RouterScan\.exe.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","18112"
"*\RouterScan.log*",".{0,1000}\\RouterScan\.log.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","18113"
"*\rpcdump.py*",".{0,1000}\\rpcdump\.py.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","18137"
"*\Rubeus.*",".{0,1000}\\Rubeus\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","18187"
"*\Rubeus.dll*",".{0,1000}\\Rubeus\.dll.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","18188"
"*\Rubeus.ps1*",".{0,1000}\\Rubeus\.ps1.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","18195"
"*\Rubeus\*",".{0,1000}\\Rubeus\\.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","18197"
"*\RubeusRoast.cs*",".{0,1000}\\RubeusRoast\.cs.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","18198"
"*\Rubeus-Rundll32\*",".{0,1000}\\Rubeus\-Rundll32\\.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","18199"
"*\run\john *",".{0,1000}\\run\\john\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","18201"
"*\run\john\*.*",".{0,1000}\\run\\john\\.{0,1000}\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","18202"
"*\run\john\*.com*",".{0,1000}\\run\\john\\.{0,1000}\.com.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","18203"
"*\run\john\*.pl*",".{0,1000}\\run\\john\\.{0,1000}\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","18204"
"*\run\john\*.py*",".{0,1000}\\run\\john\\.{0,1000}\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","18205"
"*\rustive.dmp*",".{0,1000}\\rustive\.dmp.{0,1000}","offensive_tool_keyword","RustiveDump","LSASS memory dumper using only NTAPIs","T1003.001 - T1055 - T1106","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/safedv/RustiveDump","1","0","N/A","N/A","10","4","332","43","2025-03-08T12:10:35Z","2024-10-06T16:01:49Z","18234"
"*\RustiveDump.bin*",".{0,1000}\\RustiveDump\.bin.{0,1000}","offensive_tool_keyword","RustiveDump","LSASS memory dumper using only NTAPIs","T1003.001 - T1055 - T1106","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/safedv/RustiveDump","1","0","N/A","N/A","10","4","332","43","2025-03-08T12:10:35Z","2024-10-06T16:01:49Z","18235"
"*\RustiveDump.exe*",".{0,1000}\\RustiveDump\.exe.{0,1000}","offensive_tool_keyword","RustiveDump","LSASS memory dumper using only NTAPIs","T1003.001 - T1055 - T1106","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/safedv/RustiveDump","1","0","N/A","N/A","10","4","332","43","2025-03-08T12:10:35Z","2024-10-06T16:01:49Z","18236"
"*\SafetyDump.csproj*",".{0,1000}\\SafetyDump\.csproj.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","0","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","18255"
"*\SafetyDump.exe*",".{0,1000}\\SafetyDump\.exe.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","0","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","18256"
"*\SafetyDump.sln*",".{0,1000}\\SafetyDump\.sln.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","0","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","18257"
"*\SafetyKatz*",".{0,1000}\\SafetyKatz.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","0","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","18258"
"*\SAM-*.dmp*",".{0,1000}\\SAM\-.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","18266"
"*\SAM-*.dmp.LOG*",".{0,1000}\\SAM\-.{0,1000}\.dmp\.LOG.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","18267"
"*\sampasswd.*",".{0,1000}\\sampasswd\..{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","18271"
"*\ScriptSentry.ps1*",".{0,1000}\\ScriptSentry\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","0","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","18319"
"*\ScriptSentry.psd1*",".{0,1000}\\ScriptSentry\.psd1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","0","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","18320"
"*\ScriptSentry.psm1*",".{0,1000}\\ScriptSentry\.psm1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","0","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","18321"
"*\ScriptSentry.txt*",".{0,1000}\\ScriptSentry\.txt.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","0","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","18322"
"*\secretsdump.py*",".{0,1000}\\secretsdump\.py.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","18348"
"*\SecretStealer.ps1*",".{0,1000}\\SecretStealer\.ps1.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","18350"
"*\services\PWDumpX\*",".{0,1000}\\services\\PWDumpX\\.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#registry","N/A","10","8","N/A","N/A","N/A","N/A","18371"
"*\SessionGopher.ps1*",".{0,1000}\\SessionGopher\.ps1.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","18377"
"*\SessionSearcher.csproj*",".{0,1000}\\SessionSearcher\.csproj.{0,1000}","offensive_tool_keyword","SessionSearcher","Searches all connected drives for PuTTY private keys and RDP connection files and parses them for relevant details","T1552.004 - T1083 - T1114.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/matterpreter/OffensiveCSharp/tree/master/SessionSearcher","1","0","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","18379"
"*\SessionSearcher.exe*",".{0,1000}\\SessionSearcher\.exe.{0,1000}","offensive_tool_keyword","SessionSearcher","Searches all connected drives for PuTTY private keys and RDP connection files and parses them for relevant details","T1552.004 - T1083 - T1114.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/matterpreter/OffensiveCSharp/tree/master/SessionSearcher","1","0","N/A","N/A","10","10","1416","250","2023-02-06T14:56:26Z","2019-02-06T00:32:29Z","18381"
"*\SetNTLM.ps1*",".{0,1000}\\SetNTLM\.ps1.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","0","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","18388"
"*\ShadowDumper.*",".{0,1000}\\ShadowDumper\..{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","18403"
"*\ShadowSpray.cs*",".{0,1000}\\ShadowSpray\.cs.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","N/A","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","18409"
"*\ShadowSpray.sln*",".{0,1000}\\ShadowSpray\.sln.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","N/A","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","18411"
"*\ShadowStealer.csproj*",".{0,1000}\\ShadowStealer\.csproj.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","N/A","10","","N/A","","","","18413"
"*\ShadowStealer.csproj*",".{0,1000}\\ShadowStealer\.csproj.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","N/A","10","","N/A","","","","18414"
"*\ShadowStealer.sln*",".{0,1000}\\ShadowStealer\.sln.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","N/A","10","","N/A","","","","18415"
"*\ShadowStealer\*",".{0,1000}\\ShadowStealer\\.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","N/A","10","","N/A","","","","18416"
"*\SharpAltSecIds.exe*",".{0,1000}\\SharpAltSecIds\.exe.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","18432"
"*\SharpAltSecIds.sln*",".{0,1000}\\SharpAltSecIds\.sln.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","18433"
"*\SharpAltSecIds-master*",".{0,1000}\\SharpAltSecIds\-master.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","18434"
"*\SharpBruteForceSSH-main*","\\SharpBruteForceSSH\-main","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","0","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","18446"
"*\SharpChromium\*",".{0,1000}\\SharpChromium\\.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","0","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","18470"
"*\SharpClipboard.csproj*",".{0,1000}\\SharpClipboard\.csproj.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","N/A","N/A","8","1","N/A","N/A","N/A","N/A","18471"
"*\SharpClipboard.sln*",".{0,1000}\\SharpClipboard\.sln.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","N/A","N/A","8","1","N/A","N/A","N/A","N/A","18472"
"*\SharpClipboard\*",".{0,1000}\\SharpClipboard\\.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","N/A","N/A","8","1","N/A","N/A","N/A","N/A","18473"
"*\SharpDecryptPwd.sln*",".{0,1000}\\SharpDecryptPwd\.sln.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","18489"
"*\SharpDecryptPwd\*",".{0,1000}\\SharpDecryptPwd\\.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","18490"
"*\SharpDecryptPwd-main*",".{0,1000}\\SharpDecryptPwd\-main.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","18492"
"*\SharpDomainSpraty\*",".{0,1000}\\SharpDomainSpraty\\.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","0","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","18497"
"*\SharpDPAPI\*",".{0,1000}\\SharpDPAPI\\.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","18509"
"*\SharpDump.csproj*",".{0,1000}\\SharpDump\.csproj.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","18510"
"*\SharpDump.exe*",".{0,1000}\\SharpDump\.exe.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","18514"
"*\SharpEdge.csproj*",".{0,1000}\\SharpEdge\.csproj.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","0","N/A","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","18515"
"*\SharpEdge.exe*",".{0,1000}\\SharpEdge\.exe.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","0","N/A","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","18516"
"*\SharpEdge.sln*",".{0,1000}\\SharpEdge\.sln.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","0","N/A","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","18517"
"*\SharpEdge-master*",".{0,1000}\\SharpEdge\-master.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","0","N/A","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","18518"
"*\SharpHose.exe*",".{0,1000}\\SharpHose\.exe.{0,1000}","offensive_tool_keyword","SharpHose","Asynchronous Password Spraying Tool in C# for Windows Environments","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/ustayready/SharpHose","1","0","N/A","N/A","10","4","312","62","2023-12-19T21:06:47Z","2020-05-01T22:10:49Z","18571"
"*\SharpHose\Program.cs*",".{0,1000}\\SharpHose\\Program\.cs.{0,1000}","offensive_tool_keyword","SharpHose","Asynchronous Password Spraying Tool in C# for Windows Environments","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/ustayready/SharpHose","1","0","N/A","N/A","10","4","312","62","2023-12-19T21:06:47Z","2020-05-01T22:10:49Z","18572"
"*\SharpLocker.csproj*",".{0,1000}\\SharpLocker\.csproj.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","18603"
"*\SharpLocker.exe*",".{0,1000}\\SharpLocker\.exe.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","18605"
"*\SharpLocker-master*",".{0,1000}\\SharpLocker\-master.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","18606"
"*\SharpMiniDump-master*",".{0,1000}\\SharpMiniDump\-master.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","0","N/A","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","18619"
"*\SharpRDPThief\*",".{0,1000}\\SharpRDPThief\\.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","0","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","18652"
"*\SharpSAMDump-main*",".{0,1000}\\SharpSAMDump\-main.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","0","N/A","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","18659"
"*\SharpSpray.csproj*",".{0,1000}\\SharpSpray\.csproj.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","18698"
"*\SharpSpray.exe*",".{0,1000}\\SharpSpray\.exe.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","0","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","18702"
"*\sharpspray.exe*",".{0,1000}\\sharpspray\.exe.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","18703"
"*\SharpSpray.sln*",".{0,1000}\\SharpSpray\.sln.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","18704"
"*\SharpSpray\*",".{0,1000}\\SharpSpray\\.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","18705"
"*\SharpSpray-1.1.zip*",".{0,1000}\\SharpSpray\-1\.1\.zip.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","18706"
"*\SharpVeeamDecryptor-*",".{0,1000}\\SharpVeeamDecryptor\-.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059 - T1070.004","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","18742"
"*\SharpVeeamDecryptor.*",".{0,1000}\\SharpVeeamDecryptor\..{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","18743"
"*\SharpWeb.exe*",".{0,1000}\\SharpWeb\.exe.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","18752"
"*\SharpWeb.sln*",".{0,1000}\\SharpWeb\.sln.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","18753"
"*\Shock.exe knowndlls*",".{0,1000}\\Shock\.exe\sknowndlls.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","18806"
"*\Shwmae.exe*",".{0,1000}\\Shwmae\.exe.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","18814"
"*\sigthief.py*",".{0,1000}\\sigthief\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","18824"
"*\SilentProcessExit.sln*",".{0,1000}\\SilentProcessExit\.sln.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","0","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","18828"
"*\smartbrute\*",".{0,1000}\\smartbrute\\.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","18879"
"*\smartbrute-main*",".{0,1000}\\smartbrute\-main.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","18880"
"*\smblogin-extra-mini.ps1*",".{0,1000}\\smblogin\-extra\-mini\.ps1.{0,1000}","offensive_tool_keyword","Minimalistic-offensive","A repository of tools for pentesting of restricted and isolated environments.","T1110 - T1046 - T1021 - T1203 - T1485","TA0006 - TA0007 - TA0008","N/A","Dispossessor","Credential Access","https://github.com/InfosecMatter/Minimalistic-offensive-security-tools","1","0","N/A","N/A","7","6","562","121","2021-10-26T11:04:46Z","2020-05-10T17:40:31Z","18894"
"*\smbrelayserver.py*",".{0,1000}\\smbrelayserver\.py.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","0","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","18899"
"*\SniffPass.chm*",".{0,1000}\\SniffPass\.chm.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","18928"
"*\SniffPass.pdb*",".{0,1000}\\SniffPass\.pdb.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","18929"
"*\sniffpass-x64*",".{0,1000}\\sniffpass\-x64.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","18930"
"*\SOFTWARE\Sysinternals\ProcDump\*",".{0,1000}\\SOFTWARE\\Sysinternals\\ProcDump\\.{0,1000}","greyware_tool_keyword","Procdump","dump lsass process with procdump","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","#registry","N/A","10","10","N/A","N/A","N/A","N/A","18975"
"*\spraycharles.py*",".{0,1000}\\spraycharles\.py.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","19062"
"*\sprayed-creds.txt*",".{0,1000}\\sprayed\-creds\.txt.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","19063"
"*\SprayLove.py",".{0,1000}\\SprayLove\.py","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","19065"
"*\Spyndicapped.exe*",".{0,1000}\\Spyndicapped\.exe.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","0","N/A","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","19068"
"*\Spyndicapped_dev\*",".{0,1000}\\Spyndicapped_dev\\.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","0","#content","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","19069"
"*\Spyndicapped-main*",".{0,1000}\\Spyndicapped\-main.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","0","N/A","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","19070"
"*\Stealer.exe*",".{0,1000}\\Stealer\.exe.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","19128"
"*\Stealer.exe*",".{0,1000}\\Stealer\.exe.{0,1000}","offensive_tool_keyword","Rust-Malware-Samples","open source informations stealer in rust","T1003 - T1083 - T1114 - T1074","TA0006 - TA0009 - TA0005","N/A","N/A","Credential Access","https://github.com/Whitecat18/Rust-for-Malware-Development/tree/main/Malware-Samples","1","0","N/A","N/A","10","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","19129"
"*\Stealer.sln*",".{0,1000}\\Stealer\.sln.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","19130"
"*\Stealer\modules\Passwords.cs*",".{0,1000}\\Stealer\\modules\\Passwords\.cs.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","19131"
"*\Stealer\Stealer\modules\*",".{0,1000}\\Stealer\\Stealer\\modules\\.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","19132"
"*\Stealing.cpp*",".{0,1000}\\Stealing\.cpp.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","19133"
"*\stolen_cookies.txt*",".{0,1000}\\stolen_cookies\.txt.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","N/A","10","","N/A","","","","19142"
"*\StolenPasswords.txt*",".{0,1000}\\StolenPasswords\.txt.{0,1000}","offensive_tool_keyword","NPPSpy","Simple code for NPLogonNotify(). The function obtains logon data including cleartext password","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/blob/master/PasswordStealing/NPPSpy","1","0","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","19143"
"*\SuperPuTTY.csv*",".{0,1000}\\SuperPuTTY\.csv.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","19168"
"*\sysDb-dmp*",".{0,1000}\\sysDb\-dmp.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","19196"
"*\system32.zip*",".{0,1000}\\system32\.zip.{0,1000}","greyware_tool_keyword","ntdsutil","creating a full backup of the Active Directory database and saving it to the \temp directory","T1003.001 - T1070.004 - T1059","TA0005 - TA0003 - TA0002","N/A","N/A","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","19200"
"*\TeamFiltration.dll*",".{0,1000}\\TeamFiltration\.dll.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","19250"
"*\TeamFiltration.exe*",".{0,1000}\\TeamFiltration\.exe.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","19251"
"*\TeamFiltration\OneDriveAPI*",".{0,1000}\\TeamFiltration\\OneDriveAPI.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","19252"
"*\TeamFiltration\TeamFiltration\*",".{0,1000}\\TeamFiltration\\TeamFiltration\\.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","19253"
"*\TeamFiltrationConfig_Example.json*",".{0,1000}\\TeamFiltrationConfig_Example\.json.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","19254"
"*\teams_dump.py*",".{0,1000}\\teams_dump\.py.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","19255"
"*\teams_dump.py*",".{0,1000}\\teams_dump\.py.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","19256"
"*\Temp\*\ntds.dit*",".{0,1000}\\Temp\\.{0,1000}\\ntds\.dit.{0,1000}","greyware_tool_keyword","wmic","The NTDS.dit file is the heart of Active Directory including user accounts If it's found in the Temp directory it could indicate that an attacker has copied the file here in an attempt to extract sensitive information.","T1047 - T1005 - T1567.001","TA0002 - TA0003 - TA0007","N/A","MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR","Credential Access","https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","19269"
"*\Temp\*\ntds.jfm*",".{0,1000}\\Temp\\.{0,1000}\\ntds\.jfm.{0,1000}","greyware_tool_keyword","wmic","Like the ntds.dit file it should not normally be found in the Temp directory.","T1047 - T1005 - T1567.001","TA0002 - TA0003 - TA0007","N/A","MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR","Credential Access","https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","19270"
"*\temp\__SentinelAgentKernel.dmp*",".{0,1000}\\temp\\__SentinelAgentKernel\.dmp.{0,1000}","greyware_tool_keyword","SentinelAgent","dump a process with SentinelAgent.exe","T1003 - T1055","TA0006 - TA0005","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e","1","0","N/A","N/A","8","7","N/A","N/A","N/A","N/A","19271"
"*\temp\__SentinelAgentUser.dmp*",".{0,1000}\\temp\\__SentinelAgentUser\.dmp.{0,1000}","greyware_tool_keyword","SentinelAgent","dump a process with SentinelAgent.exe","T1003 - T1055","TA0006 - TA0005","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e","1","0","N/A","N/A","8","7","N/A","N/A","N/A","N/A","19272"
"*\Temp\csrss.dmp*",".{0,1000}\\Temp\\csrss\.dmp.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","19281"
"*\Temp\dumpert*",".{0,1000}\\Temp\\dumpert.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","19284"
"*\Temp\dumpert.dmp*",".{0,1000}\\Temp\\dumpert\.dmp.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","0","N/A","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","19285"
"*\Temp\lsass.dmp*",".{0,1000}\\Temp\\lsass\.dmp.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","19292"
"*\temp\lsass.exe*",".{0,1000}\\temp\\lsass\.exe.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","19293"
"*\temp\trick.zip*.json*",".{0,1000}\\temp\\trick\.zip.{0,1000}\.json.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","19304"
"*\TGSThief\*",".{0,1000}\\TGSThief\\.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","0","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","19322"
"*\ThievingFox.py*",".{0,1000}\\ThievingFox\.py.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","19332"
"*\Thycotic.ihawu.EncryptionProtection_x64.dll*",".{0,1000}\\Thycotic\.ihawu\.EncryptionProtection_x64\.dll.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","19339"
"*\Thycotic.ihawu.EncryptionProtection_x86.dll*",".{0,1000}\\Thycotic\.ihawu\.EncryptionProtection_x86\.dll.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","19340"
"*\thycotic_secretserver_dump.rb*",".{0,1000}\\thycotic_secretserver_dump\.rb.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","19341"
"*\ticket_converter.py*",".{0,1000}\\ticket_converter\.py.{0,1000}","offensive_tool_keyword","ticket_converter","A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.","T1558.003 - T1110.004","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/zer1t0/ticket_converter","1","0","N/A","N/A","10","2","167","31","2022-06-16T19:38:05Z","2019-05-14T04:48:19Z","19342"
"*\TokenFinder.py*",".{0,1000}\\TokenFinder\.py.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","0","N/A","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","19374"
"*\TokenUniverse.zip*",".{0,1000}\\TokenUniverse\.zip.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","0","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","19385"
"*\TokenUniverse\TokenUniverse.*",".{0,1000}\\TokenUniverse\\TokenUniverse\..{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","0","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","19386"
"*\tor\hidden_service.*",".{0,1000}\\tor\\hidden_service\..{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","19393"
"*\tor\onion_router.*",".{0,1000}\\tor\\onion_router\..{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","19394"
"*\TrickDump.sln*",".{0,1000}\\TrickDump\.sln.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","19416"
"*\TrickDump-main*",".{0,1000}\\TrickDump\-main.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","19417"
"*\Users\Public\*.dmp*",".{0,1000}\\Users\\Public\\.{0,1000}\.dmp.{0,1000}","greyware_tool_keyword","Procdump","Dump files might contain sensitive data and are often created as part of debugging processes or by attackers exfiltrating data. Users\Public should not be used","T1047 - T1005 - T1567.001","TA0002 - TA0003 - TA0007","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF","1","0","N/A","false positive risks","10","10","N/A","N/A","N/A","N/A","19545"
"*\Users\Public\*ntds.dit*",".{0,1000}\\Users\\Public\\.{0,1000}ntds\.dit.{0,1000}","greyware_tool_keyword","wmic","this file shouldn't be found in the Users\Public directory. Its presence could be a sign of an ongoing or past attack.","T1047 - T1005 - T1567.001","TA0002 - TA0003 - TA0007","N/A","MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR","Credential Access","https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","19546"
"*\Users\Public\*ntds.jfm*",".{0,1000}\\Users\\Public\\.{0,1000}ntds\.jfm.{0,1000}","greyware_tool_keyword","wmic","Like the ntds.dit file it should not normally be found in this directory.","T1047 - T1005 - T1567.001","TA0002 - TA0003 - TA0007","N/A","MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR","Credential Access","https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","19547"
"*\Users\Public\lsass.dmp*",".{0,1000}\\Users\\Public\\lsass\.dmp.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","19562"
"*\valid-creds.txt*",".{0,1000}\\valid\-creds\.txt.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","19587"
"*\veeam-creds\*",".{0,1000}\\veeam\-creds\\.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","0","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","19601"
"*\vncdump-*",".{0,1000}\\vncdump\-.{0,1000}","offensive_tool_keyword","vncpwdump","vnc password sniffer","T1003.003 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.codebus.net/d-2v0u.html","1","0","#namedpipe","N/A","10","10","N/A","N/A","N/A","N/A","19623"
"*\wce -c *",".{0,1000}\\wce\s\-c\s.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","19653"
"*\wce -d *",".{0,1000}\\wce\s\-d\s.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","19654"
"*\wce -e*",".{0,1000}\\wce\s\-e.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","19655"
"*\wce -l*",".{0,1000}\\wce\s\-l.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","19656"
"*\wce -r*",".{0,1000}\\wce\s\-r.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","19657"
"*\wce -s *",".{0,1000}\\wce\s\-s\s.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","19658"
"*\wce.exe *",".{0,1000}\\wce\.exe\s.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","19659"
"*\wce_ccache*",".{0,1000}\\wce_ccache.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","19660"
"*\wce_krbtkts*",".{0,1000}\\wce_krbtkts.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","19661"
"*\wce32.exe*",".{0,1000}\\wce32\.exe.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","0","N/A","N/A","8","4","N/A","N/A","N/A","N/A","19662"
"*\wce64.exe*",".{0,1000}\\wce64\.exe.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","0","N/A","N/A","8","4","N/A","N/A","N/A","N/A","19663"
"*\wce-beta.zip*",".{0,1000}\\wce\-beta\.zip.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","0","N/A","N/A","8","4","N/A","N/A","N/A","N/A","19664"
"*\wcreddump.py*",".{0,1000}\\wcreddump\.py.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","19665"
"*\webauthn-inject.js*",".{0,1000}\\webauthn\-inject\.js.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","19676"
"*\WebBrowserPassView.cfg*",".{0,1000}\\WebBrowserPassView\.cfg.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","19677"
"*\WebBrowserPassView.chm*",".{0,1000}\\WebBrowserPassView\.chm.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","19678"
"*\WebBrowserPassView_lng.ini*",".{0,1000}\\WebBrowserPassView_lng\.ini.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","19679"
"*\Windows\Tasks\Certipy*",".{0,1000}\\Windows\\Tasks\\Certipy.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","0","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","19738"
"*\Windows\Temp\Forensike*",".{0,1000}\\Windows\\Temp\\Forensike.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","19746"
"*\Windows\Temp\info_gather.txt*",".{0,1000}\\Windows\\Temp\\info_gather\.txt.{0,1000}","offensive_tool_keyword","Rust-Malware-Samples","open source informations stealer in rust","T1003 - T1083 - T1114 - T1074","TA0006 - TA0009 - TA0005","N/A","N/A","Credential Access","https://github.com/Whitecat18/Rust-for-Malware-Development/tree/main/Malware-Samples","1","0","N/A","N/A","10","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","19747"
"*\Windows-Passwords.ps1*",".{0,1000}\\Windows\-Passwords\.ps1.{0,1000}","offensive_tool_keyword","WLAN-Windows-Passwords","Opens PowerShell hidden - grabs wlan passwords - saves as a cleartext in a variable and exfiltrates info via Discord Webhook.","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/WLAN-Windows-Passwords","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","19775"
"*\WINHELLO2hashcat.py*",".{0,1000}\\WINHELLO2hashcat\.py.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","19778"
"*\wlanpass.txt*",".{0,1000}\\wlanpass\.txt.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","19829"
"*\wmievasions.ps1*",".{0,1000}\\wmievasions\.ps1.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","19841"
"*\wmiexec.zip*",".{0,1000}\\wmiexec\.zip.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","19843"
"*\x44\x8b\x01\x44\x39\x42*",".{0,1000}\\x44\\x8b\\x01\\x44\\x39\\x42.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","19885"
"*\x83\x64\x24\x30\x00\x48\x8d\x45\xe0\x44\x8b\x4d\xd8\x48\x8d\x15*",".{0,1000}\\x83\\x64\\x24\\x30\\x00\\x48\\x8d\\x45\\xe0\\x44\\x8b\\x4d\\xd8\\x48\\x8d\\x15.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","19891"
"*\x8b\x31\x39\x72\x10\x75*",".{0,1000}\\x8b\\x31\\x39\\x72\\x10\\x75.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","19893"
"*] Any passwords that were successfully sprayed have been output to *",".{0,1000}\]\sAny\spasswords\sthat\swere\ssuccessfully\ssprayed\shave\sbeen\soutput\sto\s.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","19980"
"*] Attempting stealthy LSASS dump*",".{0,1000}\]\sAttempting\sstealthy\sLSASS\sdump.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#content","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","19981"
"*] Dumping secrets for: *Username: *",".{0,1000}\]\sDumping\ssecrets\sfor\:\s.{0,1000}Username\:\s.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","20020"
"*] Enjoy your creds! Reverting to self*",".{0,1000}\]\sEnjoy\syour\screds!\sReverting\sto\sself.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","20022"
"*] Executing loaded Mimikatz PE*",".{0,1000}\]\sExecuting\sloaded\sMimikatz\sPE.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","0","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","20024"
"*] Now spraying EAS portal at https://*/Microsoft-Server-ActiveSync*",".{0,1000}\]\sNow\sspraying\sEAS\sportal\sat\shttps\:\/\/.{0,1000}\/Microsoft\-Server\-ActiveSync.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","20055"
"*] Number of available credentials: %zu*",".{0,1000}\]\sNumber\sof\savailable\scredentials\:\s\%zu.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#content","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","20056"
"*] Password spraying has begun with *",".{0,1000}\]\sPassword\sspraying\shas\sbegun\swith\s.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","20057"
"*] Password spraying is complete*",".{0,1000}\]\sPassword\sspraying\sis\scomplete.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","20058"
"*] TeamFiltration V3.5.3 PUBLIC*",".{0,1000}\]\sTeamFiltration\sV3\.5\.3\sPUBLIC.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","20085"
"*] Token does NOT have SE_ASSIGN_PRIMARY_NAME* using CreateProcessAsWithToken() for launching:*",".{0,1000}\]\sToken\sdoes\sNOT\shave\sSE_ASSIGN_PRIMARY_NAME.{0,1000}\susing\sCreateProcessAsWithToken\(\)\sfor\slaunching\:.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","0","#content","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","20087"
"*] Triage SCCM Secrets*",".{0,1000}\]\sTriage\sSCCM\sSecrets.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","20088"
"*] Will decrypt user masterkeys with NTLM hash: *",".{0,1000}\]\sWill\sdecrypt\suser\smasterkeys\swith\sNTLM\shash\:\s.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","20095"
"*_dcsync.txt*",".{0,1000}_dcsync\.txt.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","20114"
"*_DomainPasswordAuditReport.html*",".{0,1000}_DomainPasswordAuditReport\.html.{0,1000}","offensive_tool_keyword","DPAT","Domain Password Audit Tool for Pentesters","T1003 - T1087 - T1110 - T1555","TA0006 - TA0004 - TA0002 - TA0005","N/A","N/A","Credential Access","https://github.com/clr2of8/DPAT","1","0","N/A","N/A","10","10","954","156","2022-06-24T21:41:43Z","2016-11-22T22:00:21Z","20119"
"*_DumpLSASecrets*",".{0,1000}_DumpLSASecrets.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","20121"
"*_enum_vault_creds*",".{0,1000}_enum_vault_creds.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","20122"
"*_iepv.zip.*",".{0,1000}_iepv\.zip\..{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","20130"
"*_KIWI_BCRYPT_HANDLE_KEY*",".{0,1000}_KIWI_BCRYPT_HANDLE_KEY.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","20132"
"*_KIWI_BCRYPT_KEY*",".{0,1000}_KIWI_BCRYPT_KEY.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","20133"
"*_KIWI_BCRYPT_KEY81*",".{0,1000}_KIWI_BCRYPT_KEY81.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","20134"
"*_KIWI_MASTERKEY_CACHE_ENTRY*",".{0,1000}_KIWI_MASTERKEY_CACHE_ENTRY.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","20135"
"*_lsass.txt*",".{0,1000}_lsass\.txt.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","20137"
"*_lsassdecrypt.py*",".{0,1000}_lsassdecrypt\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","20138"
"*_NT6_CLEAR_SECRET*",".{0,1000}_NT6_CLEAR_SECRET.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","20146"
"*_ppl_dump.x64*",".{0,1000}_ppl_dump\.x64.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","20149"
"*_ppl_dump.x64.*",".{0,1000}_ppl_dump\.x64\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","20150"
"*_ppl_dump_dll.x64*",".{0,1000}_ppl_dump_dll\.x64.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","20151"
"*_ppl_dump_dll.x86*",".{0,1000}_ppl_dump_dll\.x86.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","20152"
"*_ppl_medic.x64.dll*",".{0,1000}_ppl_medic\.x64\.dll.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","20153"
"*_ppl_medic.x64.exe*",".{0,1000}_ppl_medic\.x64\.exe.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","20154"
"*_ppl_medic_dll.x64.*",".{0,1000}_ppl_medic_dll\.x64\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","20155"
"*\lsass*procdump**",".{0,1000}\\\lsass\<\/Data\>\.{0,1000}procdump.{0,1000}\<\/Data\>.{0,1000}","greyware_tool_keyword","Procdump","dump lsass process with procdump","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","pipe connect ED 18 sysmon","10","10","N/A","N/A","N/A","N/A","20210"
"*\lsass*ProcessHacker**",".{0,1000}\\\lsass\<\/Data\>\.{0,1000}ProcessHacker.{0,1000}\<\/Data\>.{0,1000}","offensive_tool_keyword","processhacker","dump lsass process with processhacker","T1003.001","TA0006","N/A","LockBit - Conti - Quantum - PYSA - NetWalker - 8BASE","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","pipe connect ED 18 sysmon","10","10","N/A","N/A","N/A","N/A","20211"
"*\lsassC:\Windows\System32\Taskmgr.exe*",".{0,1000}\\\lsass\<\/Data\>\C\:\\Windows\\System32\\Taskmgr\.exe\<\/Data\>.{0,1000}","greyware_tool_keyword","Taskmgr","dump lsass process with Taskmgr","T1003.001","TA0006","N/A","N/A","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","pipe connect ED 18 sysmon","10","10","N/A","N/A","N/A","N/A","20212"
"*: list/steal token from specific session*",".{0,1000}\\:\slist\/steal\stoken\sfrom\sspecific\ssession.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","0","#content","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","20256"
"*> chntpw Main Interactive Menu <*",".{0,1000}\>\schntpw\sMain\sInteractive\sMenu\s\<.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","20300"
"*---------------------> SYSKEY CHECK <-----------------------*",".{0,1000}\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\>\sSYSKEY\sCHECK\s\<\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","20302"
"*>[ STARTING CRASH DUMP ACQUISITION ]<*",".{0,1000}\>\[\sSTARTING\sCRASH\sDUMP\sACQUISITION\s\]\<.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","20304"
"*>[ STARTING NT HASHES EXTRACTION ]<*",".{0,1000}\>\[\sSTARTING\sNT\sHASHES\sEXTRACTION\s\]\<.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","20305"
"*>\gsecdump_*",".{0,1000}\>\\gsecdump_.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#namedpipe","N/A","10","10","N/A","N/A","N/A","N/A","20310"
"*>1047@exploit.im<*",".{0,1000}\>1047\@exploit\.im\<.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","#productname","N/A","9","10","N/A","N/A","N/A","N/A","20312"
"*>ADPassHunt<*",".{0,1000}\>ADPassHunt\<.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","#productname","N/A","10","10","N/A","N/A","N/A","N/A","20322"
"*>BrowserDataGrabber<*",".{0,1000}\>BrowserDataGrabber\<.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","0","#productname","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","20351"
"*>BulletsPassView<*",".{0,1000}\>BulletsPassView\<.{0,1000}","offensive_tool_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","20354"
"*>ChromePass<*",".{0,1000}\>ChromePass\<.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","20357"
"*>DecryptAutoLogon<*",".{0,1000}\>DecryptAutoLogon\<.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","#productname","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","20372"
"*>DIT Explorer<*",".{0,1000}\>DIT\sExplorer\<.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#productname","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","20380"
"*>Don HO don.h@free.fr<*",".{0,1000}\>Don\sHO\sdon\.h\@free\.fr\<.{0,1000}","offensive_tool_keyword","credhistview","This tool allows you to decrypt the CREDHIST file and view the SHA1 and NTLM hashes of all previous passwords you used on your system","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/credhist_view.html","1","0","#companyname","N/A","9","9","N/A","N/A","N/A","N/A","20381"
"*>Extracts wireless keys stored by Windows<*",".{0,1000}\>Extracts\swireless\skeys\sstored\sby\sWindows\<.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","0","#Description","N/A","7","10","N/A","N/A","N/A","N/A","20391"
"*>grabff<*",".{0,1000}\>grabff\<.{0,1000}","offensive_tool_keyword","GrabChrome","HelloKitty Grabber used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#productname","N/A","10","10","N/A","N/A","N/A","N/A","20406"
"*>IE Pass View<*",".{0,1000}\>IE\sPass\sView\<.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","20412"
"*>IE Passwords Viewer<*",".{0,1000}\>IE\sPasswords\sViewer\<.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","20413"
"*>KeeFarceDLL<*",".{0,1000}\>KeeFarceDLL\<.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","20422"
"*>KeeTheft<*",".{0,1000}\>KeeTheft\<.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","20424"
"*>KerberOPSEC*",".{0,1000}\>KerberOPSEC\<\/.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","20426"
"*>LostMyPassword<*",".{0,1000}\>LostMyPassword\<.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","0","#productname","N/A","10","10","N/A","N/A","N/A","N/A","20434"
"*>MZCookiesView<*",".{0,1000}\>MZCookiesView\<.{0,1000}","greyware_tool_keyword","MozillaCookiesView","nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors","T1070 - T1552.001 - T1125 - T1005","TA0009 - TA0005","N/A","MuddyWater","Credential Access","https://www.nirsoft.net/utils/mzcv.html","1","0","#productname","N/A","7","10","N/A","N/A","N/A","N/A","20453"
"*>Open Source Developer, Grzegorz Tworek<*",".{0,1000}\>Open\sSource\sDeveloper,\sGrzegorz\sTworek\<.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#signature","N/A","10","10","N/A","N/A","N/A","N/A","20467"
"*>OperaPassView<*",".{0,1000}\>OperaPassView\<.{0,1000}","offensive_tool_keyword","OperaPassView","OperaPassView is a small password recovery tool that decrypts the content of the Opera Web browser password file (wand.dat) and displays the list of all Web site passwords stored in this file","T1003 - T1555 - T1145","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/opera_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","20468"
"*>Password Recovery for Remote Desktop<*",".{0,1000}\>Password\sRecovery\sfor\sRemote\sDesktop\<.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","0","N/A","N/A","8","10","N/A","N/A","N/A","N/A","20471"
"*>Password Sniffer<*",".{0,1000}\>Password\sSniffer\<.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","0","#description","N/A","10","10","N/A","N/A","N/A","N/A","20472"
"*>PasswordFox<*",".{0,1000}\>PasswordFox\<.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","0","#productname","N/A","10","10","N/A","N/A","N/A","N/A","20473"
"*>PasswordHashesView<*",".{0,1000}\>PasswordHashesView\<.{0,1000}","offensive_tool_keyword","PasswordHashesView","displays the SHA1 hash and the NTLM hash of the login password for users currently logged into your system","T1003 - T1081","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/alpha/passwordhashesview-x64.zip","1","0","#productname","N/A","10","9","N/A","N/A","N/A","N/A","20474"
"*>Password-Recovery For Firefox<*",".{0,1000}\>Password\-Recovery\sFor\sFirefox\<.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","0","#Description","N/A","10","10","N/A","N/A","N/A","N/A","20475"
"*>Penetration test tool<*",".{0,1000}\>Penetration\stest\stool\<.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","#productname","N/A","9","10","N/A","N/A","N/A","N/A","20478"
"*>physmem2profit<*",".{0,1000}\>physmem2profit\<.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","#servicename","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","20479"
"*>ProcDump<*",".{0,1000}\>ProcDump\<.{0,1000}","greyware_tool_keyword","Procdump","dump lsass process with procdump","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","#productname","N/A","10","10","N/A","N/A","N/A","N/A","20484"
"*>PWDumpX Service<*",".{0,1000}\>PWDumpX\sService\<.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#servicename","N/A","10","8","N/A","N/A","N/A","N/A","20488"
"*>RDP Recognizer<*",".{0,1000}\>RDP\sRecognizer\<.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","#productname","N/A","9","10","N/A","N/A","N/A","N/A","20493"
"*>Remote Desktop PassView<*",".{0,1000}\>Remote\sDesktop\sPassView\<.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","0","#productname","N/A","8","10","N/A","N/A","N/A","N/A","20497"
"*>ROADToken.exe<*",".{0,1000}\>ROADToken\.exe\<.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","0","#originalfilename","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","20506"
"*>ROADToken<*",".{0,1000}\>ROADToken\<.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","0","#productname","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","20507"
"*>Router Scan by Stas'M<*",".{0,1000}\>Router\sScan\sby\sStas\'M\<.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","20508"
"*>RouterPassView<*",".{0,1000}\>RouterPassView\<.{0,1000}","offensive_tool_keyword","RouterPassView","help you to recover your lost password from your router file","T1002 - T1552 - T1027","TA0006 - TA0007","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/router_password_recovery.html","1","0","#productname","N/A","10","10","N/A","N/A","N/A","N/A","20509"
"*>SharpAltSecIds<*",".{0,1000}\>SharpAltSecIds\<.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","#productname","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","20533"
"*>SharpClipboard<*",".{0,1000}\>SharpClipboard\<.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","#productname","N/A","8","1","N/A","N/A","N/A","N/A","20537"
"*>SharpDecryptPwd<*",".{0,1000}\>SharpDecryptPwd\<.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","20539"
"*>SharpDump<*",".{0,1000}\>SharpDump\<.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#companyname","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","20542"
"*>SharpLocker<*",".{0,1000}\>SharpLocker\<.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","#productname","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","20559"
"*>SharpMiniDump<*",".{0,1000}\>SharpMiniDump\<.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","0","#productname","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","20563"
"*>SharpSAMDump<*",".{0,1000}\>SharpSAMDump\<.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","0","#productname","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","20568"
"*>SharpWeb<*",".{0,1000}\>SharpWeb\<.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","#productname","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","20583"
"*>Shock.exe<*",".{0,1000}\>Shock\.exe\<.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#originalfilename","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","20586"
"*>SniffPass<*",".{0,1000}\>SniffPass\<.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","0","#productname","N/A","10","10","N/A","N/A","N/A","N/A","20588"
"*>TeamFiltration.dll<*",".{0,1000}\>TeamFiltration\.dll\<.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","20601"
"*>Trick.exe<*",".{0,1000}\>Trick\.exe\<.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#originalfilename","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","20606"
"*>User32LogonProcesss<*",".{0,1000}User32LogonProcesss.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://x.com/_RastaMouse/status/1747636529613197757","1","0","N/A","typo in the process name used when calling LsaRegisterLogonProcess","10","10","N/A","N/A","N/A","N/A","20610"
"*>VeeamBackupCreds<*",".{0,1000}\>VeeamBackupCreds\<.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","20612"
"*>VNCPassView<*",".{0,1000}\>VNCPassView\<.{0,1000}","offensive_tool_keyword","VNCPassView","recover the passwords stored by the VNC tool","T1003 - T1555 - T1081","TA0006 - TA0007","N/A","GoGoogle - 8BASE","Credential Access","https://www.nirsoft.net/utils/vnc_password.html","1","0","#productname","N/A","10","10","N/A","N/A","N/A","N/A","20613"
"*>Web Browser Password Viewer<*",".{0,1000}\>Web\sBrowser\sPassword\sViewer\<.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","#Description","N/A","10","10","N/A","N/A","N/A","N/A","20614"
"*>WebBrowserPassView<*",".{0,1000}\>WebBrowserPassView\<.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","20615"
"*>Wireless Key View<*",".{0,1000}\>Wireless\sKey\sView\<.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","0","#productname","N/A","7","10","N/A","N/A","N/A","N/A","20625"
"*002cb66d300bfb43557d4a2857db4aa75260a07feee6ec53375d0cfb6161e2bd*",".{0,1000}002cb66d300bfb43557d4a2857db4aa75260a07feee6ec53375d0cfb6161e2bd.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","20645"
"*002fa7c3b308536f94ff10852afcfbb0285608d259a43277e69751ab7db48e04*",".{0,1000}002fa7c3b308536f94ff10852afcfbb0285608d259a43277e69751ab7db48e04.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","#filehash","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","20646"
"*0033346a10079dc04814e00f7717d40f104b309c5b8a0a8956fd871e305b8ae4*",".{0,1000}0033346a10079dc04814e00f7717d40f104b309c5b8a0a8956fd871e305b8ae4.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","20648"
"*015A37FC-53D0-499B-BFFE-AB88C5086040*",".{0,1000}015A37FC\-53D0\-499B\-BFFE\-AB88C5086040.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","#GUIDproject","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","20722"
"*0164dc11b05124166f83da841b2cefbf91a8a1ee105820b416d9493263ebd222*",".{0,1000}0164dc11b05124166f83da841b2cefbf91a8a1ee105820b416d9493263ebd222.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#filehash","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","20725"
"*017c2b90e43274da40ed0346587b5a2d02af576b305b882eb31806eb7509655c*",".{0,1000}017c2b90e43274da40ed0346587b5a2d02af576b305b882eb31806eb7509655c.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","20730"
"*018BD6D4-9019-42FD-8D3A-831B23B47CB2*",".{0,1000}018BD6D4\-9019\-42FD\-8D3A\-831B23B47CB2.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","0","#GUIDproject","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","20740"
"*01ae8b32692998eefc9b050e189672ebbc6e356355fc5777957830fd8a067028*",".{0,1000}01ae8b32692998eefc9b050e189672ebbc6e356355fc5777957830fd8a067028.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","0","#filehash","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","20748"
"*02024fe8246f659fb6dd07eaf93379e8a8011420d10b83e6bb422b66e53c4292*",".{0,1000}02024fe8246f659fb6dd07eaf93379e8a8011420d10b83e6bb422b66e53c4292.{0,1000}","offensive_tool_keyword","Okta-Password-Sprayer","This script is a multi-threaded Okta password sprayer.","T1110 - T1110.003 - T1621","TA0006","N/A","N/A","Credential Access","https://github.com/Rhynorater/Okta-Password-Sprayer","1","0","#filehash","N/A","10","1","70","16","2024-01-05T16:24:38Z","2018-09-24T23:39:16Z","20771"
"*02bb96ce1e3948500c9bfc51d925ca2f59a32a1ae9e4d871c6913988bdba35f6*",".{0,1000}02bb96ce1e3948500c9bfc51d925ca2f59a32a1ae9e4d871c6913988bdba35f6.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","20836"
"*02bb96ce1e3948500c9bfc51d925ca2f59a32a1ae9e4d871c6913988bdba35f6*",".{0,1000}02bb96ce1e3948500c9bfc51d925ca2f59a32a1ae9e4d871c6913988bdba35f6.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","20837"
"*032df02a828c74567c4659feb4fd6644726265e0f26456c467f46434923399ca*",".{0,1000}032df02a828c74567c4659feb4fd6644726265e0f26456c467f46434923399ca.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","20880"
"*032df02a828c74567c4659feb4fd6644726265e0f26456c467f46434923399ca*",".{0,1000}032df02a828c74567c4659feb4fd6644726265e0f26456c467f46434923399ca.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","20881"
"*036f633201389badc16397101c718b3b6dea0ef726171e0448157129faa389b9*",".{0,1000}036f633201389badc16397101c718b3b6dea0ef726171e0448157129faa389b9.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","20895"
"*03a3b39dd1b9bfb7421e4ba555ca9669b0e3ca7d993ce921d249493aee23b484*",".{0,1000}03a3b39dd1b9bfb7421e4ba555ca9669b0e3ca7d993ce921d249493aee23b484.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","20913"
"*03a544b51ade8258a377800fda3237ce6f36ebae34e6787380c0a2f341b591e9*",".{0,1000}03a544b51ade8258a377800fda3237ce6f36ebae34e6787380c0a2f341b591e9.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","20914"
"*04318d1196862e1078e431e6d59dfeafba540d0369346dcfc6432a30d9c37e54*",".{0,1000}04318d1196862e1078e431e6d59dfeafba540d0369346dcfc6432a30d9c37e54.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","20970"
"*049ab1e5eef6dbfb0cfe81f8eac287d82db549369edf2992916d9c8109528159*",".{0,1000}049ab1e5eef6dbfb0cfe81f8eac287d82db549369edf2992916d9c8109528159.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","21000"
"*04c8a0077ac2c4db41e2bba0b7052fb1d0b492a6e301853b3e189223a989e1c7*",".{0,1000}04c8a0077ac2c4db41e2bba0b7052fb1d0b492a6e301853b3e189223a989e1c7.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","21006"
"*0538b3096657777e14c5ac6296037b936df7fb375d32199b0ae1b7fe33b3d63b*",".{0,1000}0538b3096657777e14c5ac6296037b936df7fb375d32199b0ae1b7fe33b3d63b.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","0","#filehash","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","21041"
"*0556d3a1e4719382613891895582f8a392ccacfab6814bc9deafa9c99c86e553*",".{0,1000}0556d3a1e4719382613891895582f8a392ccacfab6814bc9deafa9c99c86e553.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","#filehash","N/A","8","1","N/A","N/A","N/A","N/A","21047"
"*05842de51ede327c0f55df963f6de4e32ab88f43a73b9e0e1d827bc70199eff0*",".{0,1000}05842de51ede327c0f55df963f6de4e32ab88f43a73b9e0e1d827bc70199eff0.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21058"
"*05842de51ede327c0f55df963f6de4e32ab88f43a73b9e0e1d827bc70199eff0*",".{0,1000}05842de51ede327c0f55df963f6de4e32ab88f43a73b9e0e1d827bc70199eff0.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21059"
"*0592164ed8c8e6330431ba1f8a3eeee650af93d11b4320cfcfda75483b699c32*",".{0,1000}0592164ed8c8e6330431ba1f8a3eeee650af93d11b4320cfcfda75483b699c32.{0,1000}","offensive_tool_keyword","Invoke-GrabTheHash","Get the NTLM Hash for the User or Machine Account TGT held in your current session","T1558.004 - T1003.004","TA0006","N/A","N/A","Credential Access","https://github.com/Leo4j/Invoke-GrabTheHash","1","0","#filehash","N/A","8","1","6","1","2023-10-26T10:52:51Z","2023-08-22T12:14:53Z","21063"
"*05f4184029b94e304fcef2f2c6875c1fb2a226f0d94fce013643727b10b169a5*",".{0,1000}05f4184029b94e304fcef2f2c6875c1fb2a226f0d94fce013643727b10b169a5.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#filehash","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","21083"
"*0796f9b079afb6b3a36ab11ae96bcad44364429fd9bceee074225736507bb14e*",".{0,1000}0796f9b079afb6b3a36ab11ae96bcad44364429fd9bceee074225736507bb14e.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","21195"
"*07a00b5f4f4d8fd3328b5454dc101d4e76126d9e2600ca2d6fd677452bf624d7*",".{0,1000}07a00b5f4f4d8fd3328b5454dc101d4e76126d9e2600ca2d6fd677452bf624d7.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","21198"
"*07a00b5f4f4d8fd3328b5454dc101d4e76126d9e2600ca2d6fd677452bf624d7*",".{0,1000}07a00b5f4f4d8fd3328b5454dc101d4e76126d9e2600ca2d6fd677452bf624d7.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","#filehash","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","21199"
"*07d8d02d79b1653fdb0f1c91a56d62f7f1a418564874605e07755a1f9f010b61*",".{0,1000}07d8d02d79b1653fdb0f1c91a56d62f7f1a418564874605e07755a1f9f010b61.{0,1000}","offensive_tool_keyword","Dispossessor","Bruteforce tools used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","21215"
"*087c26613e0a27bccb09de333278fb55c2b9cf3cf7600e36615353e67c1baaf9*",".{0,1000}087c26613e0a27bccb09de333278fb55c2b9cf3cf7600e36615353e67c1baaf9.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","21273"
"*08f0007bf2c941bb9372682e9cdcc21e59369b6038c70a7a20a7d3507abaa86d*",".{0,1000}08f0007bf2c941bb9372682e9cdcc21e59369b6038c70a7a20a7d3507abaa86d.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","21307"
"*0971aee212257aba1a537747e492b76aff0020623edb68defd378e8ed069f6a8*",".{0,1000}0971aee212257aba1a537747e492b76aff0020623edb68defd378e8ed069f6a8.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","#filehash","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","21342"
"*0a0f2a82d5f3dbd8d9f8c6031b2ebb8c1820cf370e6b4fae2b1396cf2107dddd*",".{0,1000}0a0f2a82d5f3dbd8d9f8c6031b2ebb8c1820cf370e6b4fae2b1396cf2107dddd.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","#filehash","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","21384"
"*0a7cf0b0d8f68eec8829dde1d90183087d641547a6c97de021db9a631da99857*",".{0,1000}0a7cf0b0d8f68eec8829dde1d90183087d641547a6c97de021db9a631da99857.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#filehash","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","21411"
"*0af6b417e2069876a8530e9ca0056ddc12b24f348e1d4a531add0760b8d11236*",".{0,1000}0af6b417e2069876a8530e9ca0056ddc12b24f348e1d4a531add0760b8d11236.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","21444"
"*0b0acd531970ccc941de33b65aed8a93a93374fa9d2791fb210e38828098db85*",".{0,1000}0b0acd531970ccc941de33b65aed8a93a93374fa9d2791fb210e38828098db85.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","0","#filehash","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","21446"
"*0b6c277ada6299603f6af3a2ec7bf7134df0c71d8f45438eeb65a2455d351e27*",".{0,1000}0b6c277ada6299603f6af3a2ec7bf7134df0c71d8f45438eeb65a2455d351e27.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","21467"
"*0b9219328ebf065db9b26c9a189d72c7d0d9c39eb35e9fd2a5fefa54a7f853e4*",".{0,1000}0b9219328ebf065db9b26c9a189d72c7d0d9c39eb35e9fd2a5fefa54a7f853e4.{0,1000}","offensive_tool_keyword","OpenChromeDumps","OpenChrome Dump used with GrabChrome for credential access","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Yanluowang - Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","21482"
"*0bb60287c127bcef5b7018b3b692eb7a91dab1a034fa65780b5e14333a63f62b*",".{0,1000}0bb60287c127bcef5b7018b3b692eb7a91dab1a034fa65780b5e14333a63f62b.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","21490"
"*0BD5DE6B-8DA5-4CF1-AE53-A265010F52AA*",".{0,1000}0BD5DE6B\-8DA5\-4CF1\-AE53\-A265010F52AA.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz GUID project","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#GUIDproject","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21500"
"*0bed6254a9818d22f531a9433f9b20d31eefe0550ece4ba12f4e05e8db5c2cfb*",".{0,1000}0bed6254a9818d22f531a9433f9b20d31eefe0550ece4ba12f4e05e8db5c2cfb.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","21507"
"*0bef08167ba7fbe62a07368279b1b6d8450cdb04696eb9abf18b02be519abd99*",".{0,1000}0bef08167ba7fbe62a07368279b1b6d8450cdb04696eb9abf18b02be519abd99.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","21508"
"*0c28929dbbc6cfe733ed93670025f18f03642a4b323d7fd123ae63c9366afc31*",".{0,1000}0c28929dbbc6cfe733ed93670025f18f03642a4b323d7fd123ae63c9366afc31.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","21524"
"*0C3EB2F7-92BA-4895-99FC-7098A16FFE8C*",".{0,1000}0C3EB2F7\-92BA\-4895\-99FC\-7098A16FFE8C.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","#GUIDproject","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","21532"
"*0c79c5147e4ff87b8b655873c328b10976a68e7226089c1a7ab09a6b74038b13*",".{0,1000}0c79c5147e4ff87b8b655873c328b10976a68e7226089c1a7ab09a6b74038b13.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21546"
"*0c79c5147e4ff87b8b655873c328b10976a68e7226089c1a7ab09a6b74038b13*",".{0,1000}0c79c5147e4ff87b8b655873c328b10976a68e7226089c1a7ab09a6b74038b13.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21547"
"*0C81C7D4-736A-4876-A36E-15E5B2EF5117*",".{0,1000}0C81C7D4\-736A\-4876\-A36E\-15E5B2EF5117.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#GUIDproject","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","21552"
"*0cb85b94cf22a5eb8c6a391c9546aeeb1d86b7e7ae482b512de0f45c3ed90f26*",".{0,1000}0cb85b94cf22a5eb8c6a391c9546aeeb1d86b7e7ae482b512de0f45c3ed90f26.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","21569"
"*0cf8787b1bfb746c629b92dc5a471a436105e176d306a2808a636adab4df1508*",".{0,1000}0cf8787b1bfb746c629b92dc5a471a436105e176d306a2808a636adab4df1508.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","21588"
"*0cf9297dc4511e2957e45524ec12f8b6e9c4873cec625daf20d27aedc0bdf5e9*",".{0,1000}0cf9297dc4511e2957e45524ec12f8b6e9c4873cec625daf20d27aedc0bdf5e9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21589"
"*0cf9297dc4511e2957e45524ec12f8b6e9c4873cec625daf20d27aedc0bdf5e9*",".{0,1000}0cf9297dc4511e2957e45524ec12f8b6e9c4873cec625daf20d27aedc0bdf5e9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21590"
"*0d21ae4c38549782f8b066155b671b2a356721209a5ecaa64bba6edcc6e2f97e*",".{0,1000}0d21ae4c38549782f8b066155b671b2a356721209a5ecaa64bba6edcc6e2f97e.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","0","#filehash","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","21608"
"*0d31a6d35d6b320f815c6ba327ccb8946d4d7f771e0dcdbf5aa8af775576f2d1*",".{0,1000}0d31a6d35d6b320f815c6ba327ccb8946d4d7f771e0dcdbf5aa8af775576f2d1.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21613"
"*0d31a6d35d6b320f815c6ba327ccb8946d4d7f771e0dcdbf5aa8af775576f2d1*",".{0,1000}0d31a6d35d6b320f815c6ba327ccb8946d4d7f771e0dcdbf5aa8af775576f2d1.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21614"
"*0d33356f9addc458bf9fc3861d9cafef954a51b66412b1cfc435eede351733f1*",".{0,1000}0d33356f9addc458bf9fc3861d9cafef954a51b66412b1cfc435eede351733f1.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#filehash #linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","21616"
"*0db7123a79bba0227e8f91d34847ccee8be3edac266c38e804344b957486fdb9*",".{0,1000}0db7123a79bba0227e8f91d34847ccee8be3edac266c38e804344b957486fdb9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21647"
"*0db7123a79bba0227e8f91d34847ccee8be3edac266c38e804344b957486fdb9*",".{0,1000}0db7123a79bba0227e8f91d34847ccee8be3edac266c38e804344b957486fdb9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21648"
"*0db7123a79bba0227e8f91d34847ccee8be3edac266c38e804344b957486fdb9*",".{0,1000}0db7123a79bba0227e8f91d34847ccee8be3edac266c38e804344b957486fdb9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21649"
"*0db7123a79bba0227e8f91d34847ccee8be3edac266c38e804344b957486fdb9*",".{0,1000}0db7123a79bba0227e8f91d34847ccee8be3edac266c38e804344b957486fdb9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21650"
"*0DF612AE-47D8-422C-B0C5-0727EA60784F*",".{0,1000}0DF612AE\-47D8\-422C\-B0C5\-0727EA60784F.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","#GUIDproject","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","21673"
"*0e2e76930ff8d2bea66b82db863243f3895d39e761893eb6de025325747774b6*",".{0,1000}0e2e76930ff8d2bea66b82db863243f3895d39e761893eb6de025325747774b6.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","21689"
"*0e3c7a01a06f011d9bb7e184d4713f88bbb3def0118e70e2f58ca79966b7c067*",".{0,1000}0e3c7a01a06f011d9bb7e184d4713f88bbb3def0118e70e2f58ca79966b7c067.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","21693"
"*0ed9e5a905e2ec8e15e331561cc665ad5b5c5fe3ec34ffacea54b6ee51244b5c*",".{0,1000}0ed9e5a905e2ec8e15e331561cc665ad5b5c5fe3ec34ffacea54b6ee51244b5c.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","0","#filehash","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","21739"
"*0f340b471ef34c69f5413540acd3095c829ffc4df38764e703345eb5e5020301*",".{0,1000}0f340b471ef34c69f5413540acd3095c829ffc4df38764e703345eb5e5020301.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#filehash","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","21760"
"*0f638c5cbc07c8c0f3f2343f5459af22e80e6a4abaeef14740454486903fcbb8*",".{0,1000}0f638c5cbc07c8c0f3f2343f5459af22e80e6a4abaeef14740454486903fcbb8.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","21775"
"*0fbcaa65ada37326741259d2ebc96d52e61d38cd6c28823194f2ffb4bf906ebe*",".{0,1000}0fbcaa65ada37326741259d2ebc96d52e61d38cd6c28823194f2ffb4bf906ebe.{0,1000}","greyware_tool_keyword","MozillaCookiesView","nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors","T1070 - T1552.001 - T1125 - T1005","TA0009 - TA0005","N/A","MuddyWater","Credential Access","https://www.nirsoft.net/utils/mzcv.html","1","0","#filehash","N/A","7","10","N/A","N/A","N/A","N/A","21802"
"*0vercl0k/udmp-parser*",".{0,1000}0vercl0k\/udmp\-parser.{0,1000}","offensive_tool_keyword","udmp-parser","A Cross-Platform C++ parser library for Windows user minidumps.","T1005 - T1059.003 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/0vercl0k/udmp-parser","1","1","N/A","N/A","6","3","202","23","2024-11-20T15:58:21Z","2022-01-30T18:56:21Z","21826"
"*0x00G/NiceRAT*",".{0,1000}0x00G\/NiceRAT.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","21827"
"*0x09AL/RdpThief*",".{0,1000}0x09AL\/RdpThief.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","1","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","21830"
"*0x4d, 0x44, 0x4d, 0x50, 0x93, 0xa7, 0x00, 0x00*",".{0,1000}0x4d,\s0x44,\s0x4d,\s0x50,\s0x93,\s0xa7,\s0x00,\s0x00.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","21831"
"*0x4d, 0x44, 0x4d, 0x50, 0x93, 0xa7, 0x00, 0x00*",".{0,1000}0x4d,\s0x44,\s0x4d,\s0x50,\s0x93,\s0xa7,\s0x00,\s0x00.{0,1000}","offensive_tool_keyword","nanodump","nanodump string minidump","T1003 - T1055.011 - T1148","TA0006","N/A","Dispossessor","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","21832"
"*0xB455/m365-fatigue*",".{0,1000}0xB455\/m365\-fatigue.{0,1000}","offensive_tool_keyword","m365-fatigue","automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.","T1110.001 - T1078.001 - T1556.004","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/0xB455/m365-fatigue","1","1","N/A","N/A","10","1","77","7","2024-04-08T14:53:44Z","2023-11-30T13:33:03Z","21840"
"*0xdea/blindsight*",".{0,1000}0xdea\/blindsight.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","1","N/A","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","21845"
"*0xEr3bus/RdpStrike*",".{0,1000}0xEr3bus\/RdpStrike.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","1","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","21849"
"*0xZDH/o365spray*",".{0,1000}0xZDH\/o365spray.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","1","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","21864"
"*0xZDH/Omnispray*",".{0,1000}0xZDH\/Omnispray.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","21865"
"*0xZDH\Omnispray*",".{0,1000}0xZDH\\Omnispray.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","21866"
"*1$a$$ Dl_lmp in *",".{0,1000}1\$a\$\$\sDl_lmp\sin\s.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","21867"
"*1_FindDomain.sh*",".{0,1000}1_FindDomain\.sh.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","21869"
"*1027943da338f85a1aff09bb1825e4d4fe2579256cec951becbb5cebd5c60b72*",".{0,1000}1027943da338f85a1aff09bb1825e4d4fe2579256cec951becbb5cebd5c60b72.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21880"
"*1027943da338f85a1aff09bb1825e4d4fe2579256cec951becbb5cebd5c60b72*",".{0,1000}1027943da338f85a1aff09bb1825e4d4fe2579256cec951becbb5cebd5c60b72.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","21881"
"*10755f01684f2dfa48f5f096748c00ee21c272a8f1a558b021dc9a8298f3cc25*",".{0,1000}10755f01684f2dfa48f5f096748c00ee21c272a8f1a558b021dc9a8298f3cc25.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","#filehash","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","21894"
"*1083596da1857862551870eb6fd06c26bdd2cac7698b27034f6cc8d773a3664b*",".{0,1000}1083596da1857862551870eb6fd06c26bdd2cac7698b27034f6cc8d773a3664b.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","21901"
"*10CC4D5B-DC87-4AEB-887B-E47367BF656B*",".{0,1000}10CC4D5B\-DC87\-4AEB\-887B\-E47367BF656B.{0,1000}","offensive_tool_keyword","FormThief","Spoofing desktop login applications with WinForms and WPF","T1204.002 - T1056.004 - T1071.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/mlcsec/FormThief","1","0","#GUIDproject","N/A","8","2","173","31","2024-02-19T22:40:09Z","2024-02-19T22:34:07Z","21915"
"*10k-worst-pass.txt*",".{0,1000}10k\-worst\-pass\.txt.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Crack with TGSRepCrack","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","21934"
"*1119pepesneakyevil*",".{0,1000}1119pepesneakyevil.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","21946"
"*118c2a7d06f9ac1aabdec653f236e04f3a697f59bef6f4e9c9ca1ea8acdc33db*",".{0,1000}118c2a7d06f9ac1aabdec653f236e04f3a697f59bef6f4e9c9ca1ea8acdc33db.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","21975"
"*118c2a7d06f9ac1aabdec653f236e04f3a697f59bef6f4e9c9ca1ea8acdc33db*",".{0,1000}118c2a7d06f9ac1aabdec653f236e04f3a697f59bef6f4e9c9ca1ea8acdc33db.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","21976"
"*118e93d0a030df314b4e592e9470c9ae9d6c40de1417714172a95891248a2365*",".{0,1000}118e93d0a030df314b4e592e9470c9ae9d6c40de1417714172a95891248a2365.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","21977"
"*11ddcce3f411ffc78725cd4487998eb819324a19a502cd86852c9d8e2cc9659d*",".{0,1000}11ddcce3f411ffc78725cd4487998eb819324a19a502cd86852c9d8e2cc9659d.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","21996"
"*1257077a68f9725d863947e0931a44727fceaad6565b73b9f8d873cc3d028e00*",".{0,1000}1257077a68f9725d863947e0931a44727fceaad6565b73b9f8d873cc3d028e00.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","#filehash","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","22032"
"*12949a43a532f0a6ed86b7a877df767050ffa81e3afa47241fbf61cbec5e58f9*",".{0,1000}12949a43a532f0a6ed86b7a877df767050ffa81e3afa47241fbf61cbec5e58f9.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","22068"
"*12bc134420da64f0ff3a93d3a1ca6376677ae9c0494b545173bf20e45787e873*",".{0,1000}12bc134420da64f0ff3a93d3a1ca6376677ae9c0494b545173bf20e45787e873.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#filehash","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","22077"
"*12d55d1fbe1ca3c7889434234adfda1abfbd5a8aacb076026b4a94e81d696bd5*",".{0,1000}12d55d1fbe1ca3c7889434234adfda1abfbd5a8aacb076026b4a94e81d696bd5.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","0","#filehash","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","22083"
"*12debc3c0e9c84b1d7d5ddaf3fc907d2fc2c4f0e6d340875eb4bf468250d9625*",".{0,1000}12debc3c0e9c84b1d7d5ddaf3fc907d2fc2c4f0e6d340875eb4bf468250d9625.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22088"
"*12debc3c0e9c84b1d7d5ddaf3fc907d2fc2c4f0e6d340875eb4bf468250d9625*",".{0,1000}12debc3c0e9c84b1d7d5ddaf3fc907d2fc2c4f0e6d340875eb4bf468250d9625.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22089"
"*12e55226b801ebdfcc9334ca438a57db1da463de48e2893009a7bb3e5e5e0dbc*",".{0,1000}12e55226b801ebdfcc9334ca438a57db1da463de48e2893009a7bb3e5e5e0dbc.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","22092"
"*1302e8b96f9a4f7230cd751f740305bb98231e4b9cb5ebeb68ba0d4fd71231b6*",".{0,1000}1302e8b96f9a4f7230cd751f740305bb98231e4b9cb5ebeb68ba0d4fd71231b6.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","22097"
"*130a517af6464f5a3d5e390b5fb90711029720b59cdeaab3c0300b4cf57227f9*",".{0,1000}130a517af6464f5a3d5e390b5fb90711029720b59cdeaab3c0300b4cf57227f9.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","22100"
"*1337OMGsam*",".{0,1000}1337OMGsam.{0,1000}","offensive_tool_keyword","SamDumpCable","Dump users sam and system hive and exfiltrate them","T1003.002 - T1564.001","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SamDumpCable","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","22118"
"*1337OMGsys*",".{0,1000}1337OMGsys.{0,1000}","offensive_tool_keyword","SamDumpCable","Dump users sam and system hive and exfiltrate them","T1003.002 - T1564.001","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SamDumpCable","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","22119"
"*13d035ab6eb82b5527186ca674d8e17a018fd7389320d0df32c8fa2551df45d8*",".{0,1000}13d035ab6eb82b5527186ca674d8e17a018fd7389320d0df32c8fa2551df45d8.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","22158"
"*14268f4b4154d80f6c8a20bd79cca08e829cfef4d5f5c244d968c3652da7a336*",".{0,1000}14268f4b4154d80f6c8a20bd79cca08e829cfef4d5f5c244d968c3652da7a336.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","22180"
"*15079a1ec5eff9da11edafb3c59984d2ab9ce7b02fabfd07cc398ee31e7e1dc8*",".{0,1000}15079a1ec5eff9da11edafb3c59984d2ab9ce7b02fabfd07cc398ee31e7e1dc8.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","22241"
"*1526febbe627085a24dd59eefa206fddd88326d78beb00b6630989cc13526733*",".{0,1000}1526febbe627085a24dd59eefa206fddd88326d78beb00b6630989cc13526733.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#filehash","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","22247"
"*158c0b33376d319848cffd69f20dc6e2dc93aa66ed71dffd6f0ee3803da70dd2*",".{0,1000}158c0b33376d319848cffd69f20dc6e2dc93aa66ed71dffd6f0ee3803da70dd2.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","0","#filehash","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","22266"
"*161451349be662c5c649be01c670f86b233fb08a1c77c9b720ea08b622d04964*",".{0,1000}161451349be662c5c649be01c670f86b233fb08a1c77c9b720ea08b622d04964.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","#filehash","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","22297"
"*162bc32dbc28b62c3a6bcaa33b83f4a99ca60453b229d35d0ae5bc1e80b98673*",".{0,1000}162bc32dbc28b62c3a6bcaa33b83f4a99ca60453b229d35d0ae5bc1e80b98673.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","22306"
"*1637c5d66df6ce383aee2ab51e305ae9b654cfb4ceb21cf09d5123a54d7d7b7d*",".{0,1000}1637c5d66df6ce383aee2ab51e305ae9b654cfb4ceb21cf09d5123a54d7d7b7d.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","0","#filehash","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","22315"
"*16386980a156fc6e9219ba230c5fd2759e4b43dff9261487598e7d0ecfe78ae0*",".{0,1000}16386980a156fc6e9219ba230c5fd2759e4b43dff9261487598e7d0ecfe78ae0.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","0","#filehash","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","22316"
"*164425759daa52e1a44001421120e2f616f08614239f5231be763061c6e56892*",".{0,1000}164425759daa52e1a44001421120e2f616f08614239f5231be763061c6e56892.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","22321"
"*16a6b0fa183e54c07a78cdcea63df1d177aaafe8cf5737df9073e63fb03388a4*",".{0,1000}16a6b0fa183e54c07a78cdcea63df1d177aaafe8cf5737df9073e63fb03388a4.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","22345"
"*16df73e36a53fb2a7c2a022c36d999a853c3e616ae4de7c3633a8d7769e81ec5*",".{0,1000}16df73e36a53fb2a7c2a022c36d999a853c3e616ae4de7c3633a8d7769e81ec5.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","22358"
"*17589EA6-FCC9-44BB-92AD-D5B3EEA6AF03*",".{0,1000}17589EA6\-FCC9\-44BB\-92AD\-D5B3EEA6AF03.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","#GUIDproject","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","22390"
"*175c1d2aab217c0aba91cdc0366e8a81ed44e4fb8c9aa9109912ce488f364178*",".{0,1000}175c1d2aab217c0aba91cdc0366e8a81ed44e4fb8c9aa9109912ce488f364178.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22391"
"*175c1d2aab217c0aba91cdc0366e8a81ed44e4fb8c9aa9109912ce488f364178*",".{0,1000}175c1d2aab217c0aba91cdc0366e8a81ed44e4fb8c9aa9109912ce488f364178.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22392"
"*176528ecba1bee91a831b36e3829803526e329f755af06e6ab14b57ac51df58c*",".{0,1000}176528ecba1bee91a831b36e3829803526e329f755af06e6ab14b57ac51df58c.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22394"
"*17723167fed5ac513f66d4540006dc989d6cf341d43464d241f84daccf889f47*",".{0,1000}17723167fed5ac513f66d4540006dc989d6cf341d43464d241f84daccf889f47.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","#filehash","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","22399"
"*17a1d963e1565ecff5794a685188f34adc40bc12b4f31aa32db53b6956369827*",".{0,1000}17a1d963e1565ecff5794a685188f34adc40bc12b4f31aa32db53b6956369827.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","22410"
"*17a1d963e1565ecff5794a685188f34adc40bc12b4f31aa32db53b6956369827*",".{0,1000}17a1d963e1565ecff5794a685188f34adc40bc12b4f31aa32db53b6956369827.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","22411"
"*17d97bd15502bc16353e7e06822578069c1e653b031fb4ac982d8cea9d31026f*",".{0,1000}17d97bd15502bc16353e7e06822578069c1e653b031fb4ac982d8cea9d31026f.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","22420"
"*17fb52476016677db5a93505c4a1c356984bc1f6a4456870f920ac90a7846180*",".{0,1000}17fb52476016677db5a93505c4a1c356984bc1f6a4456870f920ac90a7846180.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","22426"
"*17fb52476016677db5a93505c4a1c356984bc1f6a4456870f920ac90a7846180*",".{0,1000}17fb52476016677db5a93505c4a1c356984bc1f6a4456870f920ac90a7846180.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","22427"
"*17FC11E9-C258-4B8D-8D07-2F4125156244*",".{0,1000}17FC11E9\-C258\-4B8D\-8D07\-2F4125156244.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz UUID","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#GUIDproject","uuid","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22428"
"*18229920a45130f00539405fecab500d8010ef93856e1c5bcabf5aa5532b3311*",".{0,1000}18229920a45130f00539405fecab500d8010ef93856e1c5bcabf5aa5532b3311.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#filehash","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","22435"
"*1824ED63-BE4D-4306-919D-9C749C1AE271*",".{0,1000}1824ED63\-BE4D\-4306\-919D\-9C749C1AE271.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","#GUIDproject","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","22436"
"*1830c05bde7c4d7b795968d4e3c25ecb3dd98763662b1d85fd4abfbbf8e5b660*",".{0,1000}1830c05bde7c4d7b795968d4e3c25ecb3dd98763662b1d85fd4abfbbf8e5b660.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","0","#filehash","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","22442"
"*189f1c8815a6add9af140e74c2a8ed875e1d2187c42de7180aa99030d2002482*",".{0,1000}189f1c8815a6add9af140e74c2a8ed875e1d2187c42de7180aa99030d2002482.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","22471"
"*18e9b39ab7c27ea80c6b76fc04881a5348de491ab22abe65a6bdb7254e23d5d1*",".{0,1000}18e9b39ab7c27ea80c6b76fc04881a5348de491ab22abe65a6bdb7254e23d5d1.{0,1000}","offensive_tool_keyword","MailPassView","Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","22492"
"*190DFAEB-0288-4043-BE0E-3273FA653B52*",".{0,1000}190DFAEB\-0288\-4043\-BE0E\-3273FA653B52.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","#GUIDproject","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","22499"
"*197f8806b3b467c66ad64b187f831f10ddd71695d61a42344ae617ee62e62faa*",".{0,1000}197f8806b3b467c66ad64b187f831f10ddd71695d61a42344ae617ee62e62faa.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","0","#filehash","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","22534"
"*198dc4828f294ed26c63eaf2c0d38e2d7a21db41fe31ce988d9139ea2245f0ea*",".{0,1000}198dc4828f294ed26c63eaf2c0d38e2d7a21db41fe31ce988d9139ea2245f0ea.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","22539"
"*19bab15a34d5ad838ccf4d187eb40379c335fa56446d0f9621865b2767d4ac7d*",".{0,1000}19bab15a34d5ad838ccf4d187eb40379c335fa56446d0f9621865b2767d4ac7d.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","0","#filehash","N/A","7","10","N/A","N/A","N/A","N/A","22547"
"*19d22a57efb66f96f7c8aa0650cc42a93bda9074d263f37ad120f51061e6bbf1*",".{0,1000}19d22a57efb66f96f7c8aa0650cc42a93bda9074d263f37ad120f51061e6bbf1.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22556"
"*1a3c4069-8c11-4336-bef8-9a43c0ba60e2*",".{0,1000}1a3c4069\-8c11\-4336\-bef8\-9a43c0ba60e2.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","#GUIDproject","module id","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","22585"
"*1aebc75f4a66ba1711c288235dad6ac01c59e8801e8a1c2151cbb7dfd4c2c098*",".{0,1000}1aebc75f4a66ba1711c288235dad6ac01c59e8801e8a1c2151cbb7dfd4c2c098.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","0","#filehash","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","22641"
"*1af1c92c7a9a60a740d6351d935cb24d5c8ba7bde5a54bff8931a40bb6a2aa28*",".{0,1000}1af1c92c7a9a60a740d6351d935cb24d5c8ba7bde5a54bff8931a40bb6a2aa28.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","22645"
"*1aff544e58c3eda489ae9b59f32a10175d95e1aac12a4fbf25a40c40a1cc6c74*",".{0,1000}1aff544e58c3eda489ae9b59f32a10175d95e1aac12a4fbf25a40c40a1cc6c74.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","22652"
"*1b2b249d1cc2d53c4d21bfbd0a1ab7548e2ac369b13bdba538c76ba7813ce595*",".{0,1000}1b2b249d1cc2d53c4d21bfbd0a1ab7548e2ac369b13bdba538c76ba7813ce595.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","22662"
"*1b46ed14bbd4feb50be61fb1f3535adbca65d4927a3f14eaa19202deebe29041*",".{0,1000}1b46ed14bbd4feb50be61fb1f3535adbca65d4927a3f14eaa19202deebe29041.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","22673"
"*1b578e26adc91f95143cb5c8dcfa9c0baf76923ea2295cc45e2e7a99bd4a763c*",".{0,1000}1b578e26adc91f95143cb5c8dcfa9c0baf76923ea2295cc45e2e7a99bd4a763c.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","0","#filehash","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","22679"
"*1b591c180e6c5221a81921e42b0256b62cec1f1af872624f5fd178d1ed7bd7c6*",".{0,1000}1b591c180e6c5221a81921e42b0256b62cec1f1af872624f5fd178d1ed7bd7c6.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","#filehash","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","22680"
"*1b609698b6ff63a7b10bc9b656a698ce57b1995ee1f8894673d4e58e16e2a93c*",".{0,1000}1b609698b6ff63a7b10bc9b656a698ce57b1995ee1f8894673d4e58e16e2a93c.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","22682"
"*1b6d6a1a116e8ddaeb7e3dde5dfc285e50004be80e977aa612447275c5930281*",".{0,1000}1b6d6a1a116e8ddaeb7e3dde5dfc285e50004be80e977aa612447275c5930281.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#filehash","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","22687"
"*1ba38ae7e6c55fd66b21d40178341d18c195991c23044e030c3096746a2e1266*",".{0,1000}1ba38ae7e6c55fd66b21d40178341d18c195991c23044e030c3096746a2e1266.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","22700"
"*1bb41d5d6d3c883be23682ec1d94ee3317c0ab8d5fa2bee3712a5f33c0d6960b*",".{0,1000}1bb41d5d6d3c883be23682ec1d94ee3317c0ab8d5fa2bee3712a5f33c0d6960b.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","#filehash","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","22707"
"*1c309b473a4221fa7bbb5566935f888a7d8cf523ea33c6f7b568c7342f81419a*",".{0,1000}1c309b473a4221fa7bbb5566935f888a7d8cf523ea33c6f7b568c7342f81419a.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","#filehash","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","22736"
"*1c50edff472ca0901cc9f483e21487dc2c8734e91a10f9426fac07bfea048277*",".{0,1000}1c50edff472ca0901cc9f483e21487dc2c8734e91a10f9426fac07bfea048277.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","22743"
"*1c543ea5c50ef8b0b42f835970fa5f553c2ae5c308d2692b51fb476173653cb3*",".{0,1000}1c543ea5c50ef8b0b42f835970fa5f553c2ae5c308d2692b51fb476173653cb3.{0,1000}","offensive_tool_keyword","OpenChromeDumps","OpenChrome Dump used with GrabChrome for credential access","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Yanluowang - Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","22744"
"*1c8101652c99416535282e92882538ba9daee459abeb16c1fa1e3f6578a20367*",".{0,1000}1c8101652c99416535282e92882538ba9daee459abeb16c1fa1e3f6578a20367.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22757"
"*1c8101652c99416535282e92882538ba9daee459abeb16c1fa1e3f6578a20367*",".{0,1000}1c8101652c99416535282e92882538ba9daee459abeb16c1fa1e3f6578a20367.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22758"
"*1cb076b6d5b6cb781a5af9b1211d2309840a6b47c4998b802fb8667771548e17*",".{0,1000}1cb076b6d5b6cb781a5af9b1211d2309840a6b47c4998b802fb8667771548e17.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","22770"
"*1cdbbd933f2f3b766efcabbe97d13cd5275165a3d67b9dfb0aa6d34fd7a89bfd*",".{0,1000}1cdbbd933f2f3b766efcabbe97d13cd5275165a3d67b9dfb0aa6d34fd7a89bfd.{0,1000}","offensive_tool_keyword","Dispossessor","Bruteforce tools used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","22788"
"*1ce610dbd4ac4eaf18555046ad6001ecac4245c8d69eb4f3cc9affa10d37bacb*",".{0,1000}1ce610dbd4ac4eaf18555046ad6001ecac4245c8d69eb4f3cc9affa10d37bacb.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","22791"
"*1d389e53c658a3919dfcd0d1e3dd08c34a2e875eb1520ec0b9648e43e25eaabc*",".{0,1000}1d389e53c658a3919dfcd0d1e3dd08c34a2e875eb1520ec0b9648e43e25eaabc.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","0","#filehash","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","22809"
"*1df8e073ca89d026578464b0da9748194ef62c826dea4af9848ef23b3ddf1785*",".{0,1000}1df8e073ca89d026578464b0da9748194ef62c826dea4af9848ef23b3ddf1785.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","22865"
"*1e05c9543989d8f9034dcd87f662ef8319c624a1988b800ad77676f55a2bc538*",".{0,1000}1e05c9543989d8f9034dcd87f662ef8319c624a1988b800ad77676f55a2bc538.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","#filehash","N/A","9","10","N/A","N/A","N/A","N/A","22869"
"*1E0986B4-4BF3-4CEA-A885-347B6D232D46*",".{0,1000}1E0986B4\-4BF3\-4CEA\-A885\-347B6D232D46.{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","0","#GUIDproject","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","22872"
"*1e0d1441d6cc702501cd4fa67abc59887a1afedb25dc0b2aeda80cf168469883*",".{0,1000}1e0d1441d6cc702501cd4fa67abc59887a1afedb25dc0b2aeda80cf168469883.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","22873"
"*1e2744c89803f6afc884b214ba4a8f47dfc1725a4180d767630205feeead064b*",".{0,1000}1e2744c89803f6afc884b214ba4a8f47dfc1725a4180d767630205feeead064b.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","#filehash","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","22880"
"*1e3ec12fbe9825c1eb044994d27c6fb97e5b2cee352d114b0ae6f8862e2a2dd5*",".{0,1000}1e3ec12fbe9825c1eb044994d27c6fb97e5b2cee352d114b0ae6f8862e2a2dd5.{0,1000}","offensive_tool_keyword","dialupass","This utility enumerates all dialup/VPN entries on your computers. and displays their logon details: User Name. Password. and Domain. You can use it to recover a lost password of your Internet connection or VPN.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/dialupass.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","22883"
"*1e83e7eb564b39cd4d600a3b9a906a2b59bbae26320b15b5065638ad267cc3cb*",".{0,1000}1e83e7eb564b39cd4d600a3b9a906a2b59bbae26320b15b5065638ad267cc3cb.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","#filehash","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","22907"
"*1e8efe80176f832df2a27862795208571fae916c29e755447305178528bcd437*",".{0,1000}1e8efe80176f832df2a27862795208571fae916c29e755447305178528bcd437.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22913"
"*1e8efe80176f832df2a27862795208571fae916c29e755447305178528bcd437*",".{0,1000}1e8efe80176f832df2a27862795208571fae916c29e755447305178528bcd437.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22914"
"*1ebee3f2cc0a98db23a6bf0af4e5dd14bd8d21a4de9cbba58d43521b0bbe1294*",".{0,1000}1ebee3f2cc0a98db23a6bf0af4e5dd14bd8d21a4de9cbba58d43521b0bbe1294.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","#filehash","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","22927"
"*1ec6f023ad651375efd66ae2a21f7609ed29b9fdfe725304bbaf219f5876350d*",".{0,1000}1ec6f023ad651375efd66ae2a21f7609ed29b9fdfe725304bbaf219f5876350d.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","22929"
"*1f17ea5b2d547497145f092cc3b7f0ed8acbb821946a5d3265423b7262f2aa4f*",".{0,1000}1f17ea5b2d547497145f092cc3b7f0ed8acbb821946a5d3265423b7262f2aa4f.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","#filehash","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","22959"
"*1f2338d7b628374139d373af383a1bdec1a16b43ced015849c6be4e4d90cc2c3*",".{0,1000}1f2338d7b628374139d373af383a1bdec1a16b43ced015849c6be4e4d90cc2c3.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22963"
"*1f28b88a26c282842ad06aa962b62120f44bbecece84394c2498e784ceafa526*",".{0,1000}1f28b88a26c282842ad06aa962b62120f44bbecece84394c2498e784ceafa526.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","22965"
"*1f385acf11f8ea6673d7295be6492ea9913b525da25dcc037ea49ef4f86a9d58*",".{0,1000}1f385acf11f8ea6673d7295be6492ea9913b525da25dcc037ea49ef4f86a9d58.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","#filehash","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","22971"
"*1f7c4485debf950cfd5b7442d391d71de3bdc1b041993be5238847e7d6f50ba4*",".{0,1000}1f7c4485debf950cfd5b7442d391d71de3bdc1b041993be5238847e7d6f50ba4.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22988"
"*1f7c4485debf950cfd5b7442d391d71de3bdc1b041993be5238847e7d6f50ba4*",".{0,1000}1f7c4485debf950cfd5b7442d391d71de3bdc1b041993be5238847e7d6f50ba4.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","22989"
"*1ff4136cc59aec4f76d776abce00a592679490763f669a44eeead8f88c4a3c07*",".{0,1000}1ff4136cc59aec4f76d776abce00a592679490763f669a44eeead8f88c4a3c07.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","#filehash","N/A","8","1","N/A","N/A","N/A","N/A","23016"
"*1mil-AD-passwords.txt*",".{0,1000}1mil\-AD\-passwords\.txt.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","23024"
"*1password2john.py*",".{0,1000}1password2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","23028"
"*2_lyncbrute.sh*",".{0,1000}2_lyncbrute\.sh.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","23032"
"*2010807d09f45f949a2e24615d58a15d8914e09f9988aa8fd7c863c7e5434aa8*",".{0,1000}2010807d09f45f949a2e24615d58a15d8914e09f9988aa8fd7c863c7e5434aa8.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#filehash","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","23035"
"*20144d177f7af4b900fddf4466327737bb72bf30c450a4e6a577f0efc6449647*",".{0,1000}20144d177f7af4b900fddf4466327737bb72bf30c450a4e6a577f0efc6449647.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","0","#filehash","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","23038"
"*203a17d5f5b9b71578a530294b19056d7fefa2660883c1389fce89d536e93950*",".{0,1000}203a17d5f5b9b71578a530294b19056d7fefa2660883c1389fce89d536e93950.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23048"
"*205818e10c13d2e51b4c0196ca30111276ca1107fc8e25a0992fe67879eab964*",".{0,1000}205818e10c13d2e51b4c0196ca30111276ca1107fc8e25a0992fe67879eab964.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","0","#filehash","N/A","8","10","N/A","N/A","N/A","N/A","23057"
"*20641907ff43e97a5b708e9a2a18db7673cd5583c507b84a4b506dae757e21ea*",".{0,1000}20641907ff43e97a5b708e9a2a18db7673cd5583c507b84a4b506dae757e21ea.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#filehash","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","23066"
"*20B3AA84-9CA7-43E5-B0CD-8DBA5091DF92*",".{0,1000}20B3AA84\-9CA7\-43E5\-B0CD\-8DBA5091DF92.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","0","#GUIDproject","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","23084"
"*211446645fa7a934da99f218cc049cd1c59c68ac2a5da2033eaceff80b1d1c0e*",".{0,1000}211446645fa7a934da99f218cc049cd1c59c68ac2a5da2033eaceff80b1d1c0e.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#filehash","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","23106"
"*2145f05e4090b6b0ef64720547ca85d7c4960b6fd91202a524f99ed832c0b54b*",".{0,1000}2145f05e4090b6b0ef64720547ca85d7c4960b6fd91202a524f99ed832c0b54b.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","23117"
"*216767025356ffaa54815bf698254810253efcd10feddfab82e7f6ed991d553c*",".{0,1000}216767025356ffaa54815bf698254810253efcd10feddfab82e7f6ed991d553c.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","23135"
"*21870c033ee041fa83e39818f3f23a51c1f994344f15f1f2b95912c013ad77ff*",".{0,1000}21870c033ee041fa83e39818f3f23a51c1f994344f15f1f2b95912c013ad77ff.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","23139"
"*21c6e03b7a1e354d984e88080e3843f7fbd71df02fc91df92f99d4f8a11c5ea0*",".{0,1000}21c6e03b7a1e354d984e88080e3843f7fbd71df02fc91df92f99d4f8a11c5ea0.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","23152"
"*21db0a4b79dc31e1a31251fd69d793e6dd4839e3a869093f8abd8bc10aa4b7fb*",".{0,1000}21db0a4b79dc31e1a31251fd69d793e6dd4839e3a869093f8abd8bc10aa4b7fb.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","23158"
"*2202732c2585283f93fca9bee4c3f3709530fa450a1bea8bfb925768f38b2bb9*",".{0,1000}2202732c2585283f93fca9bee4c3f3709530fa450a1bea8bfb925768f38b2bb9.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","23173"
"*22101aecc2195c323fdd0d949014c993790c425693f60c2bbc2138b4a830a519*",".{0,1000}22101aecc2195c323fdd0d949014c993790c425693f60c2bbc2138b4a830a519.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23182"
"*22101aecc2195c323fdd0d949014c993790c425693f60c2bbc2138b4a830a519*",".{0,1000}22101aecc2195c323fdd0d949014c993790c425693f60c2bbc2138b4a830a519.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23183"
"*221986c87ed18ec810267b11b919766d2d556127d9a4f2b16f544b39a32c8573*",".{0,1000}221986c87ed18ec810267b11b919766d2d556127d9a4f2b16f544b39a32c8573.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","23185"
"*221ac33db7069624a6840a57b5adb7ed34ee49f911b200aa4c5d15cea7ebaf69*",".{0,1000}221ac33db7069624a6840a57b5adb7ed34ee49f911b200aa4c5d15cea7ebaf69.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","23186"
"*2242362e7144103ecd965687227503de0483d4e7636218b1dd28cc01752bdb0f*",".{0,1000}2242362e7144103ecd965687227503de0483d4e7636218b1dd28cc01752bdb0f.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","23202"
"*2273f47d253c1974f82b9b7f9018228080e8ac41b75bba4e779fe9f918d72aa1*",".{0,1000}2273f47d253c1974f82b9b7f9018228080e8ac41b75bba4e779fe9f918d72aa1.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","#filehash","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","23217"
"*227cc3d2c07ef203c39afe00c81943cf245d626c1efa1b32024d7229604635e5*",".{0,1000}227cc3d2c07ef203c39afe00c81943cf245d626c1efa1b32024d7229604635e5.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","0","#filehash","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","23219"
"*228e75216d4b2482e113e36823f9367ed46eae2d63a083c915bc282b709e758f*",".{0,1000}228e75216d4b2482e113e36823f9367ed46eae2d63a083c915bc282b709e758f.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","0","#filehash","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","23222"
"*228eb663a1c8bfc0f6a05ba522038844c762319961b07e5b623dcfa8e30ce5fa*",".{0,1000}228eb663a1c8bfc0f6a05ba522038844c762319961b07e5b623dcfa8e30ce5fa.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","#filehash","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","23223"
"*22c75c356f7e3a118f3fb98fe16c5c9232e3834e631ea1bb2af6a923f57b7b0b*",".{0,1000}22c75c356f7e3a118f3fb98fe16c5c9232e3834e631ea1bb2af6a923f57b7b0b.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","23236"
"*22df0e3fcbba509c1e28a0df720e8a36b62f731ee3bf6066dbd2d6ed09592052*",".{0,1000}22df0e3fcbba509c1e28a0df720e8a36b62f731ee3bf6066dbd2d6ed09592052.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","23243"
"*22f3cfc7bd97c20e7a313b9710a41426f42fcbf4bb6dbe108a36c92c328737a4*",".{0,1000}22f3cfc7bd97c20e7a313b9710a41426f42fcbf4bb6dbe108a36c92c328737a4.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","23249"
"*230184a9e6df447df04c22c92e6cb0d494d210fb6ec4b3350d16712d1e85d6b9*",".{0,1000}230184a9e6df447df04c22c92e6cb0d494d210fb6ec4b3350d16712d1e85d6b9.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","0","#filehash","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","23256"
"*2305237cb1b9b2320b7e62741e4a8835777462f59c9584dbcfd0672e6f2c8150*",".{0,1000}2305237cb1b9b2320b7e62741e4a8835777462f59c9584dbcfd0672e6f2c8150.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","23258"
"*2388c7f7f1073b922d235f675e32e1b6b8809dcef1cce1113bf712402cbad1cd*",".{0,1000}2388c7f7f1073b922d235f675e32e1b6b8809dcef1cce1113bf712402cbad1cd.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","0","#filehash","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","23290"
"*23ecca2af6db4c425ab534b9a738f7ec152c7fcf3c250f3ce9d7f57e6259eac9*",".{0,1000}23ecca2af6db4c425ab534b9a738f7ec152c7fcf3c250f3ce9d7f57e6259eac9.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","#filehash","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","23318"
"*23ef7c9571eb00b307253eafdd5821d52ccfa9a4a7225e328c450d9f6657be16*",".{0,1000}23ef7c9571eb00b307253eafdd5821d52ccfa9a4a7225e328c450d9f6657be16.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","23320"
"*24d7bda466850d93fc1883a3937e1317fbb3f9e631ab0d2a4fa0b45c2c21c24f*",".{0,1000}24d7bda466850d93fc1883a3937e1317fbb3f9e631ab0d2a4fa0b45c2c21c24f.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","0","#filehash","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","23373"
"*253e716a-ab96-4f87-88c7-052231ec2a12*",".{0,1000}253e716a\-ab96\-4f87\-88c7\-052231ec2a12.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","0","#GUIDproject","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","23402"
"*254389e27339fd66920dd72f3ad07fe2e220f6b0cbea8032cf0b1d8285a7b098*",".{0,1000}254389e27339fd66920dd72f3ad07fe2e220f6b0cbea8032cf0b1d8285a7b098.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","#filehash","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","23406"
"*25a3a725cec379cb70766bcc8ba6a87dba12de35f73c5e0439e2673e6840dc9a*",".{0,1000}25a3a725cec379cb70766bcc8ba6a87dba12de35f73c5e0439e2673e6840dc9a.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","23437"
"*2611455f4d60bc80f43cb13f480c6bee70497fffea48ed5c0b7d67e7fce33a52*",".{0,1000}2611455f4d60bc80f43cb13f480c6bee70497fffea48ed5c0b7d67e7fce33a52.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","23462"
"*261a0287a47dd71f44a4494a5d563bd5aa673687f60744ecf559ecb817a7ac82*",".{0,1000}261a0287a47dd71f44a4494a5d563bd5aa673687f60744ecf559ecb817a7ac82.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","0","#filehash","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","23464"
"*2633f67803a9cdd6ba381d1ff7e334a1e0472dc86d6f81513e57003644e80780*",".{0,1000}2633f67803a9cdd6ba381d1ff7e334a1e0472dc86d6f81513e57003644e80780.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23473"
"*2633f67803a9cdd6ba381d1ff7e334a1e0472dc86d6f81513e57003644e80780*",".{0,1000}2633f67803a9cdd6ba381d1ff7e334a1e0472dc86d6f81513e57003644e80780.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23474"
"*2659c2d40606e2b088c3bbd6fd6a293692ac7f219221844071abf434a638e1da*",".{0,1000}2659c2d40606e2b088c3bbd6fd6a293692ac7f219221844071abf434a638e1da.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#filehash","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","23478"
"*2677e9423aa9c338fa85cc819fa88b20262f6838f7323da6513c80a0c9c05803*",".{0,1000}2677e9423aa9c338fa85cc819fa88b20262f6838f7323da6513c80a0c9c05803.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","0","#filehash","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","23491"
"*267c2cc1712018393f79e00ee869f86e8be7522569e18ec76ab2c8deb36ba9d1*",".{0,1000}267c2cc1712018393f79e00ee869f86e8be7522569e18ec76ab2c8deb36ba9d1.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059 - T1070.004","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","#filehash","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","23493"
"*26e18c8672146105fd4aed794f8d2305c635117eaea1de3e30b8f91473449b86*",".{0,1000}26e18c8672146105fd4aed794f8d2305c635117eaea1de3e30b8f91473449b86.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","23526"
"*26f5c3b1de7bc524883c2f5620ac07e5bed58bc8149a9d1ecafa47d586a5693a*",".{0,1000}26f5c3b1de7bc524883c2f5620ac07e5bed58bc8149a9d1ecafa47d586a5693a.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","23534"
"*26fcb5597cb7d3eddd3bb24440de6555b3d34af4c9a3874b71fa27aff18ea3d5*",".{0,1000}26fcb5597cb7d3eddd3bb24440de6555b3d34af4c9a3874b71fa27aff18ea3d5.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","23535"
"*274ca13168b38590c230bddc2d606bbe8c26de8a6d79156a6c7d07265efe0fdf*",".{0,1000}274ca13168b38590c230bddc2d606bbe8c26de8a6d79156a6c7d07265efe0fdf.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23552"
"*274ca13168b38590c230bddc2d606bbe8c26de8a6d79156a6c7d07265efe0fdf*",".{0,1000}274ca13168b38590c230bddc2d606bbe8c26de8a6d79156a6c7d07265efe0fdf.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23553"
"*274ca13168b38590c230bddc2d606bbe8c26de8a6d79156a6c7d07265efe0fdf*",".{0,1000}274ca13168b38590c230bddc2d606bbe8c26de8a6d79156a6c7d07265efe0fdf.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23554"
"*274ca13168b38590c230bddc2d606bbe8c26de8a6d79156a6c7d07265efe0fdf*",".{0,1000}274ca13168b38590c230bddc2d606bbe8c26de8a6d79156a6c7d07265efe0fdf.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23555"
"*274F19EC-7CBA-4FC7-80E6-BB41C1FE6728*",".{0,1000}274F19EC\-7CBA\-4FC7\-80E6\-BB41C1FE6728.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","#GUIDproject","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","23556"
"*27cc5348dd41818e79d5d87ee9d78e0f6ddc331f31c72ef0d4073f38d4fe4637*",".{0,1000}27cc5348dd41818e79d5d87ee9d78e0f6ddc331f31c72ef0d4073f38d4fe4637.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23582"
"*28a2e9e1ab772d0017aa994feae882eeea526fcbcb2f929ec410eabcf2912c14*",".{0,1000}28a2e9e1ab772d0017aa994feae882eeea526fcbcb2f929ec410eabcf2912c14.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","#filehash","N/A","10","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","23637"
"*28b5a291efc22edff0f84eec3720d1513151a2a551b09896a7fff354cba5aaff*",".{0,1000}28b5a291efc22edff0f84eec3720d1513151a2a551b09896a7fff354cba5aaff.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","23640"
"*28e899105aafa4f17c8a0d81d2f6664926afe59ff8c35e076ba2976291521300*",".{0,1000}28e899105aafa4f17c8a0d81d2f6664926afe59ff8c35e076ba2976291521300.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23652"
"*28e899105aafa4f17c8a0d81d2f6664926afe59ff8c35e076ba2976291521300*",".{0,1000}28e899105aafa4f17c8a0d81d2f6664926afe59ff8c35e076ba2976291521300.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23653"
"*28e90498456b5e0866fde4371f560e5673f75e761855b73b063eadaef39834d2*",".{0,1000}28e90498456b5e0866fde4371f560e5673f75e761855b73b063eadaef39834d2.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","#filehash","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","23654"
"*29021B28-61F9-492D-BB51-7CA8889087E5*",".{0,1000}29021B28\-61F9\-492D\-BB51\-7CA8889087E5.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#GUIDProject","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","23660"
"*29CBBC24-363F-42D7-B018-5EF068BA8777*",".{0,1000}29CBBC24\-363F\-42D7\-B018\-5EF068BA8777.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","#GUIDproject","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","23717"
"*29cf4b68c34663281bebc94f62c92282ca351839032140fcb2b0266d44a8bc84*",".{0,1000}29cf4b68c34663281bebc94f62c92282ca351839032140fcb2b0266d44a8bc84.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","#filehash","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","23718"
"*29CFAA16-9277-4EFB-9E91-A7D11225160B*",".{0,1000}29CFAA16\-9277\-4EFB\-9E91\-A7D11225160B.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","#GUIDproject","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","23719"
"*29d30b556932d0657f14a0b290ec79d23f88d8454ca27151c8348ab7e4be9657*",".{0,1000}29d30b556932d0657f14a0b290ec79d23f88d8454ca27151c8348ab7e4be9657.{0,1000}","offensive_tool_keyword","SharpHose","Asynchronous Password Spraying Tool in C# for Windows Environments","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/ustayready/SharpHose","1","0","#filehash","N/A","10","4","312","62","2023-12-19T21:06:47Z","2020-05-01T22:10:49Z","23720"
"*2a46df8322062f52a20c78eb93d7b068b61037db2ce48edcb9f8beda43dd8ede*",".{0,1000}2a46df8322062f52a20c78eb93d7b068b61037db2ce48edcb9f8beda43dd8ede.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","#filehash","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","23742"
"*2a74704d6eb53e9a97c063f182021c51b5f687882227902e020ac82f45ab1e4c*",".{0,1000}2a74704d6eb53e9a97c063f182021c51b5f687882227902e020ac82f45ab1e4c.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23746"
"*2a74704d6eb53e9a97c063f182021c51b5f687882227902e020ac82f45ab1e4c*",".{0,1000}2a74704d6eb53e9a97c063f182021c51b5f687882227902e020ac82f45ab1e4c.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23747"
"*2a9cd5021cf8f43304a9ecc91759b534aad0efff59d9da57ca666c8b5f8ce819*",".{0,1000}2a9cd5021cf8f43304a9ecc91759b534aad0efff59d9da57ca666c8b5f8ce819.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","23757"
"*2ac9118877d2f38cfb75a17e0c0cb4ac845398e55588925fa775fc3fea93b319*",".{0,1000}2ac9118877d2f38cfb75a17e0c0cb4ac845398e55588925fa775fc3fea93b319.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23767"
"*2ac9118877d2f38cfb75a17e0c0cb4ac845398e55588925fa775fc3fea93b319*",".{0,1000}2ac9118877d2f38cfb75a17e0c0cb4ac845398e55588925fa775fc3fea93b319.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23768"
"*2acfc293585568970aa8ea676822e0c905d4eec4c0f8c743f58ce1b099dbe29d*",".{0,1000}2acfc293585568970aa8ea676822e0c905d4eec4c0f8c743f58ce1b099dbe29d.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","23772"
"*2b2b84ccdf5351dab81dbd87860fcfbf61bf44a88fb547a7f4a3cc71667c7362*",".{0,1000}2b2b84ccdf5351dab81dbd87860fcfbf61bf44a88fb547a7f4a3cc71667c7362.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","#filehash","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","23793"
"*2b6e6ca400190f98d1bf00cc5d50c728364c75db258043fe26b5f014c19c7188*",".{0,1000}2b6e6ca400190f98d1bf00cc5d50c728364c75db258043fe26b5f014c19c7188.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","23813"
"*2c1873b4fdd1abde90702784cb5870a06c8fe662cfc428c018d9052c89421351*",".{0,1000}2c1873b4fdd1abde90702784cb5870a06c8fe662cfc428c018d9052c89421351.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23858"
"*2c1873b4fdd1abde90702784cb5870a06c8fe662cfc428c018d9052c89421351*",".{0,1000}2c1873b4fdd1abde90702784cb5870a06c8fe662cfc428c018d9052c89421351.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","23859"
"*2C6D323A-B51F-47CB-AD37-972FD051D475*",".{0,1000}2C6D323A\-B51F\-47CB\-AD37\-972FD051D475.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#GUIDproject","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","23880"
"*2c71dd5b47601d4b105d8da7007511045dd58f5d71b997290209d55f20dce887*",".{0,1000}2c71dd5b47601d4b105d8da7007511045dd58f5d71b997290209d55f20dce887.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","#filehash","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","23882"
"*2d0029543e5781ba1136a85707546c7b3acafbaa56cf71e917c63cc2f7fea794*",".{0,1000}2d0029543e5781ba1136a85707546c7b3acafbaa56cf71e917c63cc2f7fea794.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","23913"
"*2dc0932b1ec1f7be50038ddcfc69790ff8b8db824d0121a02aad709a9a92119f*",".{0,1000}2dc0932b1ec1f7be50038ddcfc69790ff8b8db824d0121a02aad709a9a92119f.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","23963"
"*2e3bc20ce205875bea72dc1aceafc75307c0ed033d7e11846d97ca30ab3852ee*",".{0,1000}2e3bc20ce205875bea72dc1aceafc75307c0ed033d7e11846d97ca30ab3852ee.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","23991"
"*2e7451bba0392fb9d687c8cf6d7b99a7983742542ac0217d11f899d2d7bad07b*",".{0,1000}2e7451bba0392fb9d687c8cf6d7b99a7983742542ac0217d11f899d2d7bad07b.{0,1000}","offensive_tool_keyword","Decrypt-RDCMan","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1","1","0","#filehash","N/A","9","1","1","1","2016-12-01T14:06:24Z","2017-11-22T23:18:39Z","24005"
"*2e8ab836111066fba6cfbf4572786b071bbaea1139c2eab5a7155b635e48318d*",".{0,1000}2e8ab836111066fba6cfbf4572786b071bbaea1139c2eab5a7155b635e48318d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24021"
"*2e8ab836111066fba6cfbf4572786b071bbaea1139c2eab5a7155b635e48318d*",".{0,1000}2e8ab836111066fba6cfbf4572786b071bbaea1139c2eab5a7155b635e48318d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24022"
"*2eeba6742b716b69144db95b0240d6d7a50d48f28f2dec83b003e74ff4958ad1*",".{0,1000}2eeba6742b716b69144db95b0240d6d7a50d48f28f2dec83b003e74ff4958ad1.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","24060"
"*2F00A05B-263D-4FCC-846B-DA82BD684603*",".{0,1000}2F00A05B\-263D\-4FCC\-846B\-DA82BD684603.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","#GUIDproject","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","24072"
"*2f3c1b3378d19418aa4c99685f3ab9d6730c132a920946b64c0e4edc9efd5ed6*",".{0,1000}2f3c1b3378d19418aa4c99685f3ab9d6730c132a920946b64c0e4edc9efd5ed6.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","0","#filehash","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","24085"
"*2f40452382f378c481ce9622ea6f10cfb0275cad138c6a45fe16144111fdfa77*",".{0,1000}2f40452382f378c481ce9622ea6f10cfb0275cad138c6a45fe16144111fdfa77.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","0","#filehash","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","24087"
"*2fbc59378c66069942a5b99d32551d080f7f8a984e568c7b408e6c7b67bdebff*",".{0,1000}2fbc59378c66069942a5b99d32551d080f7f8a984e568c7b408e6c7b67bdebff.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","#filehash","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","24119"
"*2fbf1231cc622fd4b910a7fc7b474af1dcd1acbdc13b8233b852416009b9bb20*",".{0,1000}2fbf1231cc622fd4b910a7fc7b474af1dcd1acbdc13b8233b852416009b9bb20.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24121"
"*2fbf1231cc622fd4b910a7fc7b474af1dcd1acbdc13b8233b852416009b9bb20*",".{0,1000}2fbf1231cc622fd4b910a7fc7b474af1dcd1acbdc13b8233b852416009b9bb20.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24122"
"*2fd04964c571de856492e42f27043367c4b8e452a7f4719a1bdb0470b2b6576c*",".{0,1000}2fd04964c571de856492e42f27043367c4b8e452a7f4719a1bdb0470b2b6576c.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#filehash","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","24129"
"*2fe32ea10b81598147f6d39cc0ae54a03a5384c73d1fba22fc3f9ae6589ec266*",".{0,1000}2fe32ea10b81598147f6d39cc0ae54a03a5384c73d1fba22fc3f9ae6589ec266.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","#filehash","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","24135"
"*2fe5dc013f99c83e5c353ab5a064ad0ce2f197debb7b03f430934004923f6071*",".{0,1000}2fe5dc013f99c83e5c353ab5a064ad0ce2f197debb7b03f430934004923f6071.{0,1000}","offensive_tool_keyword","DPAT","Domain Password Audit Tool for Pentesters","T1003 - T1087 - T1110 - T1555","TA0006 - TA0004 - TA0002 - TA0005","N/A","N/A","Credential Access","https://github.com/clr2of8/DPAT","1","0","#filehash","N/A","10","10","954","156","2022-06-24T21:41:43Z","2016-11-22T22:00:21Z","24137"
"*2FE6C1D0-0538-48DB-B4FA-55F0296A5150*",".{0,1000}2FE6C1D0\-0538\-48DB\-B4FA\-55F0296A5150.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","0","#GUIDproject","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","24138"
"*2ff4c6949bab3ffb8c95b21f9c5eb597b93af66e3bfb635ba2bf92fd534e995b*",".{0,1000}2ff4c6949bab3ffb8c95b21f9c5eb597b93af66e3bfb635ba2bf92fd534e995b.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24146"
"*2ff4c6949bab3ffb8c95b21f9c5eb597b93af66e3bfb635ba2bf92fd534e995b*",".{0,1000}2ff4c6949bab3ffb8c95b21f9c5eb597b93af66e3bfb635ba2bf92fd534e995b.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24147"
"*2john.c",".{0,1000}2john\.c","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","24152"
"*2john.lua*",".{0,1000}2john\.lua.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","24153"
"*2john.pl*",".{0,1000}2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","24154"
"*2john.py*",".{0,1000}2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","24155"
"*30444d3f4f3bedc5d6aac36ad4deb9ce32d2ac91eb0b30e590f702b06825f372*",".{0,1000}30444d3f4f3bedc5d6aac36ad4deb9ce32d2ac91eb0b30e590f702b06825f372.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","#filehash","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","24172"
"*307088B9-2992-4DE7-A57D-9E657B1CE546*",".{0,1000}307088B9\-2992\-4DE7\-A57D\-9E657B1CE546.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#GUIDproject","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","24182"
"*3130a3c87196583390827cf55f5e5e4ef008251885f1c9a07866df3699faab3d*",".{0,1000}3130a3c87196583390827cf55f5e5e4ef008251885f1c9a07866df3699faab3d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24236"
"*3130a3c87196583390827cf55f5e5e4ef008251885f1c9a07866df3699faab3d*",".{0,1000}3130a3c87196583390827cf55f5e5e4ef008251885f1c9a07866df3699faab3d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24237"
"*318c7820d295ab78772ec8424dfc4e0a9619d81ea56ab4df81236f1a42707c97*",".{0,1000}318c7820d295ab78772ec8424dfc4e0a9619d81ea56ab4df81236f1a42707c97.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","24265"
"*31a97e6377d69a3ae7974a441d52657d200210087bfcac7f0c4f79dddf9f488b*",".{0,1000}31a97e6377d69a3ae7974a441d52657d200210087bfcac7f0c4f79dddf9f488b.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","24275"
"*31ee7ee1add800239003806829b825cadc5b95797c11e33cf6b691571c1e2069*",".{0,1000}31ee7ee1add800239003806829b825cadc5b95797c11e33cf6b691571c1e2069.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","0","#filehash","N/A","7","10","N/A","N/A","N/A","N/A","24296"
"*31f63c6923ddd1a842839f7ef1d54fec535f94760d89f0a90ad83a19dc906a8c*",".{0,1000}31f63c6923ddd1a842839f7ef1d54fec535f94760d89f0a90ad83a19dc906a8c.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","24297"
"*32ae965a0b8ea94499ffb0368ae4d5a349f84c5b37ba3cba1874d0bd73dc650c*",".{0,1000}32ae965a0b8ea94499ffb0368ae4d5a349f84c5b37ba3cba1874d0bd73dc650c.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","24346"
"*32db0ad0f6cdbdd9481c02062ed78535bd65185331a7ae6b198e3e5eb6b5a59a*",".{0,1000}32db0ad0f6cdbdd9481c02062ed78535bd65185331a7ae6b198e3e5eb6b5a59a.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","24359"
"*3342b13f536e40d34e2a0155667854ddd3904c193db870c7c759365530b2ae82*",".{0,1000}3342b13f536e40d34e2a0155667854ddd3904c193db870c7c759365530b2ae82.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","24386"
"*335f1dcefb6d0e3e4a2e97d68d54d87cb53f6ba029a428a048752b19ecca71ad*",".{0,1000}335f1dcefb6d0e3e4a2e97d68d54d87cb53f6ba029a428a048752b19ecca71ad.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","#filehash","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","24398"
"*33ccc2fca462fcf743513e4f01ebe3b7302e0158a44b8dfa1f3e56b78b3ff0be*",".{0,1000}33ccc2fca462fcf743513e4f01ebe3b7302e0158a44b8dfa1f3e56b78b3ff0be.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","24437"
"*33ccc2fca462fcf743513e4f01ebe3b7302e0158a44b8dfa1f3e56b78b3ff0be*",".{0,1000}33ccc2fca462fcf743513e4f01ebe3b7302e0158a44b8dfa1f3e56b78b3ff0be.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","24438"
"*33d0f399-f79a-44a2-a487-21fce657be35*",".{0,1000}33d0f399\-f79a\-44a2\-a487\-21fce657be35.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#GUIDProject","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","24439"
"*3422b5b6a7d4b662727baf8a4615c884a4295b71b8d0412130415b737a4cd216*",".{0,1000}3422b5b6a7d4b662727baf8a4615c884a4295b71b8d0412130415b737a4cd216.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","#filehash","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","24457"
"*342d4b1d90f163fdbce23c4bffe2fdeecb420df0472cb44a272c2a4f604f8758*",".{0,1000}342d4b1d90f163fdbce23c4bffe2fdeecb420df0472cb44a272c2a4f604f8758.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#filehash","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","24461"
"*34a3dda90725d2179dbb2bbead3e076cf7f2f6f5d7f93ec81c371f7640b034c4*",".{0,1000}34a3dda90725d2179dbb2bbead3e076cf7f2f6f5d7f93ec81c371f7640b034c4.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#filehash","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","24491"
"*34b1b9b6a69e55a9a8ee08e26eb932ea6e8823c4a93c2d95e0e7b33376492827*",".{0,1000}34b1b9b6a69e55a9a8ee08e26eb932ea6e8823c4a93c2d95e0e7b33376492827.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","24495"
"*34cfee78a17d917fabf8d9a2b48fb55f8231c0b24a5f4197615d140d18eb9b2d*",".{0,1000}34cfee78a17d917fabf8d9a2b48fb55f8231c0b24a5f4197615d140d18eb9b2d.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","0","#filehash","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","24505"
"*34db2170c5e68bb656c1bc57c0932f4b89c10133d478e9459b36641da5a47c4e*",".{0,1000}34db2170c5e68bb656c1bc57c0932f4b89c10133d478e9459b36641da5a47c4e.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","24507"
"*34fbf688da05fa13e0b3f8d18ae5aab81ce3865eb98908b236b8c593007adb5b*",".{0,1000}34fbf688da05fa13e0b3f8d18ae5aab81ce3865eb98908b236b8c593007adb5b.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24511"
"*34fbf688da05fa13e0b3f8d18ae5aab81ce3865eb98908b236b8c593007adb5b*",".{0,1000}34fbf688da05fa13e0b3f8d18ae5aab81ce3865eb98908b236b8c593007adb5b.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24512"
"*350cfd6e53c72d9c3d2fa109cc73e69171d8f1bed85ced979483592908925aff*",".{0,1000}350cfd6e53c72d9c3d2fa109cc73e69171d8f1bed85ced979483592908925aff.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","#filehash","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","24516"
"*3532e7da204a5242b3ee2a3081cc68f7cd3728d45bbcbc582c077472bba4a7f5*",".{0,1000}3532e7da204a5242b3ee2a3081cc68f7cd3728d45bbcbc582c077472bba4a7f5.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","24524"
"*361ec6983d4a8683b685dc4f9b7280e4faebf3a4006cc44c7aab3ea94fe9d2d4*",".{0,1000}361ec6983d4a8683b685dc4f9b7280e4faebf3a4006cc44c7aab3ea94fe9d2d4.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#filehash","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","24577"
"*362a1076dc1f77532a07c12db0b3ce368eac2b15d1cfc8afa1a1a735ac25e430*",".{0,1000}362a1076dc1f77532a07c12db0b3ce368eac2b15d1cfc8afa1a1a735ac25e430.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","24581"
"*36922dd433801687ef428a64f1db8195d4efa8112cd7629b283476bce58e1d30*",".{0,1000}36922dd433801687ef428a64f1db8195d4efa8112cd7629b283476bce58e1d30.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","24605"
"*36a659bab7eec62733d13b9e7f8a6ae891cfaf7cd2ec36824bf41f7e6b706944*",".{0,1000}36a659bab7eec62733d13b9e7f8a6ae891cfaf7cd2ec36824bf41f7e6b706944.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","24614"
"*374a98a083fc04f30b86718a9fe7a5a61d1afc22b93222a89d2b752b5da1df7e*",".{0,1000}374a98a083fc04f30b86718a9fe7a5a61d1afc22b93222a89d2b752b5da1df7e.{0,1000}","offensive_tool_keyword","GrabChrome","HelloKitty Grabber used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","24669"
"*375f1c3e957ea3eea4956ae449e652962a57473ff55f193b8eabec033eeea187*",".{0,1000}375f1c3e957ea3eea4956ae449e652962a57473ff55f193b8eabec033eeea187.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","0","#filehash","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","24673"
"*376890088b7c004896fa764dc8148944e9dcee1017c481e246b892520f96aa6e*",".{0,1000}376890088b7c004896fa764dc8148944e9dcee1017c481e246b892520f96aa6e.{0,1000}","offensive_tool_keyword","GlobalUnProtect","Decrypt GlobalProtect configuration and cookie files.","T1552 - T1003 - T1555","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rotarydrone/GlobalUnProtect","1","0","#filehash","N/A","9","2","147","19","2024-09-10T20:19:24Z","2024-09-04T15:31:52Z","24676"
"*37754362c1524cbecc907a1cde4a3c4e1c747235a140c2275e482724fca9955d*",".{0,1000}37754362c1524cbecc907a1cde4a3c4e1c747235a140c2275e482724fca9955d.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","24681"
"*37aaa060ddae57e5457ffc47f65362682d64da54775c2211705b8a7becc9e657*",".{0,1000}37aaa060ddae57e5457ffc47f65362682d64da54775c2211705b8a7becc9e657.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","0","#filehash #linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","24692"
"*37c719615f3d72d457564a3f2af7669fbea6d651b92de213699419a4e8ac27e9*",".{0,1000}37c719615f3d72d457564a3f2af7669fbea6d651b92de213699419a4e8ac27e9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24698"
"*37c719615f3d72d457564a3f2af7669fbea6d651b92de213699419a4e8ac27e9*",".{0,1000}37c719615f3d72d457564a3f2af7669fbea6d651b92de213699419a4e8ac27e9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24699"
"*383b8dcb968b6bd0633658d9bb55c4acaf4c85a075aa456904a42d4e4efd5561*",".{0,1000}383b8dcb968b6bd0633658d9bb55c4acaf4c85a075aa456904a42d4e4efd5561.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","0","#filehash","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","24731"
"*387416cccea393e9e9eb2c069edabbf7297226037cc374d9a358ce1020696a5d*",".{0,1000}387416cccea393e9e9eb2c069edabbf7297226037cc374d9a358ce1020696a5d.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","24744"
"*387930bab7650291baada3b39dc55167c1e6f1fd2154de61f77e07bd14c8b9bc*",".{0,1000}387930bab7650291baada3b39dc55167c1e6f1fd2154de61f77e07bd14c8b9bc.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","0","#filehash","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","24750"
"*38bbfb8a6e3de5fb329505605290d408b8d99be65f351daf4b015773525a20e3*",".{0,1000}38bbfb8a6e3de5fb329505605290d408b8d99be65f351daf4b015773525a20e3.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","24776"
"*391d4825efd725d2deed4dd7d2addc62f38c3c8f15e84ada070aabc2303b4ab4*",".{0,1000}391d4825efd725d2deed4dd7d2addc62f38c3c8f15e84ada070aabc2303b4ab4.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","24795"
"*395cb1f243d7c705459a5c7c931b48617a39ca9e89b04f4c9759f25364cfe371*",".{0,1000}395cb1f243d7c705459a5c7c931b48617a39ca9e89b04f4c9759f25364cfe371.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","24823"
"*399399f17d32ec67656ef826a7efc16e48fb10f5b59da6b2d57feca3676a8190*",".{0,1000}399399f17d32ec67656ef826a7efc16e48fb10f5b59da6b2d57feca3676a8190.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","#filehash","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","24837"
"*39a9f25d64ef416e4be4fadf6fae1b2169bfeb02501be443e8af1fec17412f60*",".{0,1000}39a9f25d64ef416e4be4fadf6fae1b2169bfeb02501be443e8af1fec17412f60.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","#filehash","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","24842"
"*39f0a8aa528f48997f9d2b81845eb9f7fbdf6151f34f883ee30da4649cc151ae*",".{0,1000}39f0a8aa528f48997f9d2b81845eb9f7fbdf6151f34f883ee30da4649cc151ae.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","24851"
"*3a14a252eb81351a4b9b204b416e17ced7f2af340e2b635c149cf53bf1be2732*",".{0,1000}3a14a252eb81351a4b9b204b416e17ced7f2af340e2b635c149cf53bf1be2732.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","24868"
"*3a1737f6fde0316cbc7552b8452384174908d9d124dd65016554a087455dd94e*",".{0,1000}3a1737f6fde0316cbc7552b8452384174908d9d124dd65016554a087455dd94e.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","24869"
"*3a7f12e2da6e68b00f1a0aff9b515e7c623da2304f729ed756e01582ddfb62aa*",".{0,1000}3a7f12e2da6e68b00f1a0aff9b515e7c623da2304f729ed756e01582ddfb62aa.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","24902"
"*3aaa5fde51d080a80e911b350db316669db2ca264b1b6f55cdac91d1ad5267bf*",".{0,1000}3aaa5fde51d080a80e911b350db316669db2ca264b1b6f55cdac91d1ad5267bf.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","24913"
"*3ac89800bd6dc53207c19d3d35161342cc19bc09a212710393ec9ab79fb55ba1*",".{0,1000}3ac89800bd6dc53207c19d3d35161342cc19bc09a212710393ec9ab79fb55ba1.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","24919"
"*3ae0b0ec554f725076ca89389d9a3523e503a24248ee8a9b342f68c156e77b12*",".{0,1000}3ae0b0ec554f725076ca89389d9a3523e503a24248ee8a9b342f68c156e77b12.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","#filehash","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","24927"
"*3b45f3db658c4628a97d2d8efa567415cb2e4cfc8a397570f0d33cc97c1aa78c*",".{0,1000}3b45f3db658c4628a97d2d8efa567415cb2e4cfc8a397570f0d33cc97c1aa78c.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","24947"
"*3c1785d7fa372507bd98842717b7bc12744b15f7a7a97856790f664561c959c2*",".{0,1000}3c1785d7fa372507bd98842717b7bc12744b15f7a7a97856790f664561c959c2.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","25007"
"*3c39207a61a348efa7dd2db2d85c1e562beedfa8c4593d1d29b7751bc84aad85*",".{0,1000}3c39207a61a348efa7dd2db2d85c1e562beedfa8c4593d1d29b7751bc84aad85.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#filehash","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","25016"
"*3c40fcf023afe126e8cc67593d21bc3ee9af7c56e3f1b8e9614cfd58030c29af*",".{0,1000}3c40fcf023afe126e8cc67593d21bc3ee9af7c56e3f1b8e9614cfd58030c29af.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","25018"
"*3cc5ee93a9ba1fc57389705283b760c8bd61f35e9398bbfa3210e2becf6d4b05*",".{0,1000}3cc5ee93a9ba1fc57389705283b760c8bd61f35e9398bbfa3210e2becf6d4b05.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","25053"
"*3d00518d63ef9b656fdef85621d8a4f3137569ea71b07d431da6b39704f54dee*",".{0,1000}3d00518d63ef9b656fdef85621d8a4f3137569ea71b07d431da6b39704f54dee.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#filehash","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","25069"
"*3d0e06086768500a2bf680ffbed0409d24b355887169b821d55233529ad2c62a*",".{0,1000}3d0e06086768500a2bf680ffbed0409d24b355887169b821d55233529ad2c62a.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","25073"
"*3d0e06086768500a2bf680ffbed0409d24b355887169b821d55233529ad2c62a*",".{0,1000}3d0e06086768500a2bf680ffbed0409d24b355887169b821d55233529ad2c62a.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","25074"
"*3D111394-E7F7-40B7-91CB-D24374DB739A*",".{0,1000}3D111394\-E7F7\-40B7\-91CB\-D24374DB739A.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","#GUIDproject","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","25075"
"*3d2b4aa76b770b3421f0867aa68b42a1a17f723df251d81af9459f3a872a6fc4*",".{0,1000}3d2b4aa76b770b3421f0867aa68b42a1a17f723df251d81af9459f3a872a6fc4.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","25081"
"*3d686ba6d6985ff3febf3cd3d45cb5eb18eff45bfec74142865ded01f9c00503*",".{0,1000}3d686ba6d6985ff3febf3cd3d45cb5eb18eff45bfec74142865ded01f9c00503.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","0","#filehash","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","25097"
"*3d9e27be3e47c7e35f0a8b3cc989ec9fe4915f323518fc380a64c080a752a7a7*",".{0,1000}3d9e27be3e47c7e35f0a8b3cc989ec9fe4915f323518fc380a64c080a752a7a7.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","25107"
"*3db93e0b8f7b39335bfa3f1712a38b8f0e21210772eec85524941e420e9e58ff*",".{0,1000}3db93e0b8f7b39335bfa3f1712a38b8f0e21210772eec85524941e420e9e58ff.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","25117"
"*3e3956052088b12e9fca1e9a209c00e8e60f5bba79bc09881316c83758a93c1d*",".{0,1000}3e3956052088b12e9fca1e9a209c00e8e60f5bba79bc09881316c83758a93c1d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","25137"
"*3e3956052088b12e9fca1e9a209c00e8e60f5bba79bc09881316c83758a93c1d*",".{0,1000}3e3956052088b12e9fca1e9a209c00e8e60f5bba79bc09881316c83758a93c1d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","25138"
"*3e43822dce57d12ca13a1888e2b5d653dfbf9815dd5cda87e1fc1ce29a423170*",".{0,1000}3e43822dce57d12ca13a1888e2b5d653dfbf9815dd5cda87e1fc1ce29a423170.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","0","#filehash","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","25146"
"*3e9a7fc50639f2077028d5cfd6ffeba037d03608f30af50cafc12a43d0a4a5e2*",".{0,1000}3e9a7fc50639f2077028d5cfd6ffeba037d03608f30af50cafc12a43d0a4a5e2.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","25172"
"*3e9a7fc50639f2077028d5cfd6ffeba037d03608f30af50cafc12a43d0a4a5e2*",".{0,1000}3e9a7fc50639f2077028d5cfd6ffeba037d03608f30af50cafc12a43d0a4a5e2.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","25173"
"*3ec41c041f4c5b1c1c781ddcd9d0286a0a920253783edb27a8fc8085d9ecb6f8*",".{0,1000}3ec41c041f4c5b1c1c781ddcd9d0286a0a920253783edb27a8fc8085d9ecb6f8.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","0","#filehash","N/A","10","","N/A","","","","25183"
"*3ee00a42a65d2df9ee571875a11f53b56c8494e90e1e8e60e128aabdb56399c8*",".{0,1000}3ee00a42a65d2df9ee571875a11f53b56c8494e90e1e8e60e128aabdb56399c8.{0,1000}","offensive_tool_keyword","RouterPassView","help you to recover your lost password from your router file","T1002 - T1552 - T1027","TA0006 - TA0007","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/router_password_recovery.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","25192"
"*3ee00a42a65d2df9ee571875a11f53b56c8494e90e1e8e60e128aabdb56399c8*",".{0,1000}3ee00a42a65d2df9ee571875a11f53b56c8494e90e1e8e60e128aabdb56399c8.{0,1000}","offensive_tool_keyword","RouterPassView","help you to recover your lost password from your router file","T1002 - T1552 - T1027","TA0006 - TA0007","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/router_password_recovery.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","25193"
"*3f0aaab9ed83635ff24bf9664603d16e9130183bdb15f55dd02b92d760a97833*",".{0,1000}3f0aaab9ed83635ff24bf9664603d16e9130183bdb15f55dd02b92d760a97833.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","25207"
"*3f511ce7fdc81166c2e8811560fb1a2b30b5568ccd184d915f23fd5494cd969e*",".{0,1000}3f511ce7fdc81166c2e8811560fb1a2b30b5568ccd184d915f23fd5494cd969e.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","25229"
"*3f5ea2764696b07fdb61c7b34736eae26518ed2e36a624df09fb37025659201f*",".{0,1000}3f5ea2764696b07fdb61c7b34736eae26518ed2e36a624df09fb37025659201f.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","25232"
"*3f5ea2764696b07fdb61c7b34736eae26518ed2e36a624df09fb37025659201f*",".{0,1000}3f5ea2764696b07fdb61c7b34736eae26518ed2e36a624df09fb37025659201f.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","25233"
"*3f731e2fb08a9113084dcbffa31890d2b42c817f8ae6da445502130b7e5f512b*",".{0,1000}3f731e2fb08a9113084dcbffa31890d2b42c817f8ae6da445502130b7e5f512b.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","25240"
"*3FCA8012-3BAD-41E4-91F4-534AA9A44F96*",".{0,1000}3FCA8012\-3BAD\-41E4\-91F4\-534AA9A44F96.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#GUIDproject","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","25263"
"*3snake-master*",".{0,1000}3snake\-master.{0,1000}","offensive_tool_keyword","3snake","Tool for extracting information from newly spawned processes","T1003 - T1110 - T1552 - T1505","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/blendin/3snake","1","1","N/A","N/A","7","8","752","109","2022-02-14T17:42:10Z","2018-02-07T21:03:15Z","25296"
"*40408670ce1d814a3283a625566334fa191580622adbd23effa6e3cdaaafc5d5*",".{0,1000}40408670ce1d814a3283a625566334fa191580622adbd23effa6e3cdaaafc5d5.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","#filehash","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","25317"
"*405cd1547ee19c39e0afa83ba8ac7a53a4f88c95447df355540d82a5aa74e484*",".{0,1000}405cd1547ee19c39e0afa83ba8ac7a53a4f88c95447df355540d82a5aa74e484.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","0","#filehash","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","25324"
"*40a2c9d397f398d5faa631d6c6070174807e39962a22be143e35b7497b5c6bd7*",".{0,1000}40a2c9d397f398d5faa631d6c6070174807e39962a22be143e35b7497b5c6bd7.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","0","#filehash","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","25340"
"*4164003E-BA47-4A95-8586-D5AAC399C050*",".{0,1000}4164003E\-BA47\-4A95\-8586\-D5AAC399C050.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","0","#GUIDproject","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","25406"
"*417a79ca577c7a337999b7e23372257421360569bf5708d0adc0f356161f35c3*",".{0,1000}417a79ca577c7a337999b7e23372257421360569bf5708d0adc0f356161f35c3.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","0","#filehash","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","25414"
"*417a79ca577c7a337999b7e23372257421360569bf5708d0adc0f356161f35c3*",".{0,1000}417a79ca577c7a337999b7e23372257421360569bf5708d0adc0f356161f35c3.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","0","#filehash","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","25415"
"*417f4c1ad7f0f15d3c01d4930cc583330eb93cf71593c8d872b65a2a50cbb6fc*",".{0,1000}417f4c1ad7f0f15d3c01d4930cc583330eb93cf71593c8d872b65a2a50cbb6fc.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","25416"
"*423091502099d1c9adba971a42db7801b2e856c1fd5bed6f1ca70d0e39ca1a94*",".{0,1000}423091502099d1c9adba971a42db7801b2e856c1fd5bed6f1ca70d0e39ca1a94.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","#filehash","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","25469"
"*4243bea295573ba62e1bf4b685804539bab0286331a11e390f7e46abdc8ee785*",".{0,1000}4243bea295573ba62e1bf4b685804539bab0286331a11e390f7e46abdc8ee785.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","25473"
"*42528d08f25fcba2cb6088f4a1d810a1c1783ee3af573204094f81c2a4c0765c*",".{0,1000}42528d08f25fcba2cb6088f4a1d810a1c1783ee3af573204094f81c2a4c0765c.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","25475"
"*4280a088866261d65bcfb3409133327b35626000c4c5b838d50c0d650baa8a62*",".{0,1000}4280a088866261d65bcfb3409133327b35626000c4c5b838d50c0d650baa8a62.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","25498"
"*42914217da8d5f50f1eb540af6b49433fbfbe42f598bb4ecd162ef2c88d07f1f*",".{0,1000}42914217da8d5f50f1eb540af6b49433fbfbe42f598bb4ecd162ef2c88d07f1f.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","#filehash","N/A","10","","N/A","","","","25500"
"*42a1be47225d778ad55b6acccfe487239ddc6ee0cc5b5471038568dd2910811f*",".{0,1000}42a1be47225d778ad55b6acccfe487239ddc6ee0cc5b5471038568dd2910811f.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","25508"
"*4334cdefe34ccba3224c79ed27d7feb1980e8f138a6dd0f993f6f830caa2476b*",".{0,1000}4334cdefe34ccba3224c79ed27d7feb1980e8f138a6dd0f993f6f830caa2476b.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","25542"
"*433d59580b95a3e3b82364729aac65643385eb4500c46eae2aab1c0567df03e6*",".{0,1000}433d59580b95a3e3b82364729aac65643385eb4500c46eae2aab1c0567df03e6.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","#filehash","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","25545"
"*4347d68bd769cf25fa1046b8c9c3f5f4c1c83ae6b96ac1d3ed4b8dce7647c22c*",".{0,1000}4347d68bd769cf25fa1046b8c9c3f5f4c1c83ae6b96ac1d3ed4b8dce7647c22c.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","25547"
"*4358d271e8e3db49fc9ba98ab0709727f9043a129b5978ebaa23881f60b26b64*",".{0,1000}4358d271e8e3db49fc9ba98ab0709727f9043a129b5978ebaa23881f60b26b64.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","25557"
"*43d7e47e21d334bb7130c5709c16f02e2cf7e4a808382aed3c0ba12cc84b9ea9*",".{0,1000}43d7e47e21d334bb7130c5709c16f02e2cf7e4a808382aed3c0ba12cc84b9ea9.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","#filehash","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","25604"
"*4459ea3ad77b52ee723e8e8db6cf46ac565fefef5126717f7fc64d596cd4eb67*",".{0,1000}4459ea3ad77b52ee723e8e8db6cf46ac565fefef5126717f7fc64d596cd4eb67.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","25634"
"*447b74994f6fec7bf3118b9c2056feca43667b899889c2a4f561303a18c82ce9*",".{0,1000}447b74994f6fec7bf3118b9c2056feca43667b899889c2a4f561303a18c82ce9.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","#filehash","N/A","10","","N/A","","","","25646"
"*44acd66093e5cc54cdd68c183815d7c16b48b82aadd03c03bb01f3e03adf17c1*",".{0,1000}44acd66093e5cc54cdd68c183815d7c16b48b82aadd03c03bb01f3e03adf17c1.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","25661"
"*44fad118e1e7776c04d4a8fa8174ff5316ab5fa23b0e58e5c8a15c50f04ed365*",".{0,1000}44fad118e1e7776c04d4a8fa8174ff5316ab5fa23b0e58e5c8a15c50f04ed365.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","25681"
"*454711d2a1a5526d75e2df5ba08bd0a1a1e5833efc59bbe6b41e31b7c32e8e76*",".{0,1000}454711d2a1a5526d75e2df5ba08bd0a1a1e5833efc59bbe6b41e31b7c32e8e76.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","25706"
"*455a614b6dd52b17b4af639045bd0c3c3ddad152334607978ec9e915553246e9*",".{0,1000}455a614b6dd52b17b4af639045bd0c3c3ddad152334607978ec9e915553246e9.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","0","#filehash","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","25715"
"*456a99ccb18c638425add933b1ae1fcef59cb064aa97dc0be231d16c35bddff0*",".{0,1000}456a99ccb18c638425add933b1ae1fcef59cb064aa97dc0be231d16c35bddff0.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","25718"
"*457cd41fbb528812aa51bc4b31fce042cdf736281b162181d91c47733d0e9e4b*",".{0,1000}457cd41fbb528812aa51bc4b31fce042cdf736281b162181d91c47733d0e9e4b.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#filehash","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","25725"
"*4595ba305652431a89d142e09e6e5a9e67515bec0864017e8331082d3004611f*",".{0,1000}4595ba305652431a89d142e09e6e5a9e67515bec0864017e8331082d3004611f.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","#filehash","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","25732"
"*461356f9bd764b57b3b9a1457aa60494ae73a7935133f5b6122edcb286b7ef0a*",".{0,1000}461356f9bd764b57b3b9a1457aa60494ae73a7935133f5b6122edcb286b7ef0a.{0,1000}","offensive_tool_keyword","blindsight","Red teaming tool to dump LSASS memory, bypassing basic countermeasures","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/0xdea/blindsight","1","0","#filehash","N/A","10","3","225","26","2024-12-31T15:28:15Z","2024-07-18T07:35:43Z","25758"
"*4665bf3f84b00ec83f005ea4feb3617acf032a69826013656a04683865c204f6*",".{0,1000}4665bf3f84b00ec83f005ea4feb3617acf032a69826013656a04683865c204f6.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#filehash","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","25779"
"*46aee0547844dab640a8f982d4fb71207da42c0e00e214f2012680d3822adb85*",".{0,1000}46aee0547844dab640a8f982d4fb71207da42c0e00e214f2012680d3822adb85.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","25805"
"*46d1f15077f064a99b06bb115ba498581828ff8b712b2c41f6eb602538077035*",".{0,1000}46d1f15077f064a99b06bb115ba498581828ff8b712b2c41f6eb602538077035.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","0","#filehash","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","25815"
"*46D3E566-0EBA-4BD9-925E-84F4CB9EE7BC*",".{0,1000}46D3E566\-0EBA\-4BD9\-925E\-84F4CB9EE7BC.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#GUIDproject","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","25817"
"*46f31a5656b5592c4b37514bf7726bb1d51140b7eab918643a931cd269289b19*",".{0,1000}46f31a5656b5592c4b37514bf7726bb1d51140b7eab918643a931cd269289b19.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","25826"
"*47042a24b908274eec6f075245339e4f6058834220e3c2469e235c881d8aa5eb*",".{0,1000}47042a24b908274eec6f075245339e4f6058834220e3c2469e235c881d8aa5eb.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","0","#filehash","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","25830"
"*4747b86b7a8d2ba61f377e2526d6f2764cb8146be5dd8d6ad42af745dd705c8b*",".{0,1000}4747b86b7a8d2ba61f377e2526d6f2764cb8146be5dd8d6ad42af745dd705c8b.{0,1000}","offensive_tool_keyword","pwdump","a tool used within a command-line interface on 64bit Windows computers to extract the NTLM (LanMan) hashes from LSASS.exe in memory. This tool may be used in conjunction with malware or other penetration testing tools to obtain credentials for use in Windows authentication systems","T1003 - T1110.001 - T1555.003 - T1003.002","TA0006","N/A","menuPass - APT41 - Threat Group-3390 - APT1 - Turla - APT39 - FIN5","Credential Access","https://ftp.samba.org/pub/samba/pwdump/","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","25840"
"*476FC126-239F-4D58-8389-E1C0E93C2C5E*",".{0,1000}476FC126\-239F\-4D58\-8389\-E1C0E93C2C5E.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","#GUIDproject","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","25850"
"*4775208998622726a1b1a5f156e6e88b2ba4e568416795c19358d7380c35b0b8*",".{0,1000}4775208998622726a1b1a5f156e6e88b2ba4e568416795c19358d7380c35b0b8.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","0","#filehash","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","25855"
"*4781b10d0dae27a772518c9167b3a654c46017897bc73ce4540f4bfca33e9b58*",".{0,1000}4781b10d0dae27a772518c9167b3a654c46017897bc73ce4540f4bfca33e9b58.{0,1000}","offensive_tool_keyword","NLBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/amazond/NLBrute-1.2","1","0","#filehash","N/A","10","1","1","2","2023-12-21T12:25:54Z","2023-12-21T12:22:27Z","25858"
"*4802db51ec51c17bea27c97d871a840211f6d74b88eb9494b00b99a28957142a*",".{0,1000}4802db51ec51c17bea27c97d871a840211f6d74b88eb9494b00b99a28957142a.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","25894"
"*48213dd6196f88e665f7ca5d9e139f56f9c54921ae9703a329f76b08ec364d3d*",".{0,1000}48213dd6196f88e665f7ca5d9e139f56f9c54921ae9703a329f76b08ec364d3d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","25904"
"*48213dd6196f88e665f7ca5d9e139f56f9c54921ae9703a329f76b08ec364d3d*",".{0,1000}48213dd6196f88e665f7ca5d9e139f56f9c54921ae9703a329f76b08ec364d3d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","25905"
"*4841539dd633e3c38767c9098481406113d80aba6c23e5326f30e5328ac30234*",".{0,1000}4841539dd633e3c38767c9098481406113d80aba6c23e5326f30e5328ac30234.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","25914"
"*484f12b93ca5f088c3a0db9f31106c2fc855642292fc867a512df8f6a8826d09*",".{0,1000}484f12b93ca5f088c3a0db9f31106c2fc855642292fc867a512df8f6a8826d09.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","0","#filehash","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","25919"
"*4860280fe3039b1f65dad29dbcbb674c6f41004c34e99d382b824b4004aacdd0*",".{0,1000}4860280fe3039b1f65dad29dbcbb674c6f41004c34e99d382b824b4004aacdd0.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","#filehash","N/A","10","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","25922"
"*48a7ca531d14b205dfcaaa59b86e78f3f092a2c1c6ccf8c827ee87ba30d3108c*",".{0,1000}48a7ca531d14b205dfcaaa59b86e78f3f092a2c1c6ccf8c827ee87ba30d3108c.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#filehash #linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","25943"
"*48dd94df199f63a06b571290ca42e17488f7053605449341eb9747807a26aa10*",".{0,1000}48dd94df199f63a06b571290ca42e17488f7053605449341eb9747807a26aa10.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#filehash","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","25958"
"*48fcb3ac5d2ca4147cb46d18b662bc25262988a105fd8c93212297a07af3d615*",".{0,1000}48fcb3ac5d2ca4147cb46d18b662bc25262988a105fd8c93212297a07af3d615.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","25968"
"*490139a7800992202ca46d3a69882b476014126fc3ed4143c184bcd7f76a5761*",".{0,1000}490139a7800992202ca46d3a69882b476014126fc3ed4143c184bcd7f76a5761.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","25970"
"*491919ffbf3bf3ba309a98d7dce8c3b04e4f269faedd59f57ec1943efe668254*",".{0,1000}491919ffbf3bf3ba309a98d7dce8c3b04e4f269faedd59f57ec1943efe668254.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","#filehash","N/A","9","10","N/A","N/A","N/A","N/A","25974"
"*4957a3e8d46d84698c5987e2c45bc2705865ac8cf742218c574de4cee69da080*",".{0,1000}4957a3e8d46d84698c5987e2c45bc2705865ac8cf742218c574de4cee69da080.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#filehash","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","25985"
"*4969b09ab7cae1ba1f02a509b9b7099195fab22321b73039fcce92e9974d7b93*",".{0,1000}4969b09ab7cae1ba1f02a509b9b7099195fab22321b73039fcce92e9974d7b93.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#filehash","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","25989"
"*49966f985d0d509cebebda87d56da72e6a94253adfb3252000dfff73fb207ff0*",".{0,1000}49966f985d0d509cebebda87d56da72e6a94253adfb3252000dfff73fb207ff0.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#filehash","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","25999"
"*4a25a09ed816e1c629945dbd33779ab714d82bebf661557864aa61562ed4298c*",".{0,1000}4a25a09ed816e1c629945dbd33779ab714d82bebf661557864aa61562ed4298c.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","26027"
"*4aa1f8595b2334131d7349d8e60ed3d0bfe9c72abd053d42b6e74111b4e010eb*",".{0,1000}4aa1f8595b2334131d7349d8e60ed3d0bfe9c72abd053d42b6e74111b4e010eb.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#filehash","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","26058"
"*4aa99dcaf5030b1c4c7c57edd0fea22ab6db79caff79a547cc07572077631646*",".{0,1000}4aa99dcaf5030b1c4c7c57edd0fea22ab6db79caff79a547cc07572077631646.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","0","#filehash","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","26063"
"*4aede7350521d2a3d0975833db870f94c50c8d46c28d8b14f930619e35b4b07e*",".{0,1000}4aede7350521d2a3d0975833db870f94c50c8d46c28d8b14f930619e35b4b07e.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","#filehash","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","26101"
"*4af84ffd1badb65ce92e7d89e711b055e363db8bb59d8de5592d1215c626317d*",".{0,1000}4af84ffd1badb65ce92e7d89e711b055e363db8bb59d8de5592d1215c626317d.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","0","#filehash","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","26104"
"*4b23fd7b0179a37fe15bf38ea9ccb0202202d36dcaa882c58a66c1979d37e92c*",".{0,1000}4b23fd7b0179a37fe15bf38ea9ccb0202202d36dcaa882c58a66c1979d37e92c.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","0","#filehash","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","26114"
"*4B2E3A60-9A8F-4F36-8692-14ED9887E7BE*",".{0,1000}4B2E3A60\-9A8F\-4F36\-8692\-14ED9887E7BE.{0,1000}","offensive_tool_keyword","FormThief","Spoofing desktop login applications with WinForms and WPF","T1204.002 - T1056.004 - T1071.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/mlcsec/FormThief","1","0","#GUIDproject","N/A","8","2","173","31","2024-02-19T22:40:09Z","2024-02-19T22:34:07Z","26119"
"*4b4a532b9efe70d220a086a839b59bf80d00368d3f821fb7f81f92eeb9ba3edc*",".{0,1000}4b4a532b9efe70d220a086a839b59bf80d00368d3f821fb7f81f92eeb9ba3edc.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","26124"
"*4bb5b8961566bdbdc3787a847a55730ce32d1822677bcd7c412cf2d7f54262fd*",".{0,1000}4bb5b8961566bdbdc3787a847a55730ce32d1822677bcd7c412cf2d7f54262fd.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","0","#filehash","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","26150"
"*4bb963704e0b986784a5d5b1ad7cc6daffc7e062fedf0025df4974e8b0478602*",".{0,1000}4bb963704e0b986784a5d5b1ad7cc6daffc7e062fedf0025df4974e8b0478602.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","26153"
"*4bbc3665b5dd41184146e64b1b3d563af181600c9375d3e9d99170684a82a8ce*",".{0,1000}4bbc3665b5dd41184146e64b1b3d563af181600c9375d3e9d99170684a82a8ce.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","26155"
"*4bbce282aa26a449030a398e4ff5e980137a05d91f205037ac1bb297f3c36513*",".{0,1000}4bbce282aa26a449030a398e4ff5e980137a05d91f205037ac1bb297f3c36513.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","26156"
"*4bc67e5404e070bce9952de907f957cb0451a92c7a0c468a73755b2947f344c6*",".{0,1000}4bc67e5404e070bce9952de907f957cb0451a92c7a0c468a73755b2947f344c6.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","26160"
"*4c22a00104b52b74247f83b5c50ca09d5e9ed2db3d7d1843fe75fc283d50ffb1*",".{0,1000}4c22a00104b52b74247f83b5c50ca09d5e9ed2db3d7d1843fe75fc283d50ffb1.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","26193"
"*4c9e1588af0f951fbb311cd29bac8ce03c7d00175d5ef6747bab9ef127abc0c4*",".{0,1000}4c9e1588af0f951fbb311cd29bac8ce03c7d00175d5ef6747bab9ef127abc0c4.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","26238"
"*4ce98911b8e13393c58578be23e85776dbf7c95ec878b9f08748d0921855c36b*",".{0,1000}4ce98911b8e13393c58578be23e85776dbf7c95ec878b9f08748d0921855c36b.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","0","#filehash","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","26256"
"*4d29f1251e4ef23a8e22ed209d547e84c421fa736b87646ddd8269c3a0e84093*",".{0,1000}4d29f1251e4ef23a8e22ed209d547e84c421fa736b87646ddd8269c3a0e84093.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","0","#filehash #linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","26276"
"*4d2f66539f067f631db31039ec81707028bb37efcd2ebbf86a1a920d60d75263*",".{0,1000}4d2f66539f067f631db31039ec81707028bb37efcd2ebbf86a1a920d60d75263.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","#filehash","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","26278"
"*4d5ee19778d34bdddd4c391ed860d10d2d3a46c22090fa0e701e263bec6bca2c*",".{0,1000}4d5ee19778d34bdddd4c391ed860d10d2d3a46c22090fa0e701e263bec6bca2c.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","#filehash","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","26291"
"*4d710fdd6e18bf8ad16847a9e03cf858b20eaeec3e6b8fe9ac1b29eb36883892*",".{0,1000}4d710fdd6e18bf8ad16847a9e03cf858b20eaeec3e6b8fe9ac1b29eb36883892.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","26296"
"*4d9b2297358dbe1d72168480ab67ef7b992c2b84d4f09d71d906c941523f7b74*",".{0,1000}4d9b2297358dbe1d72168480ab67ef7b992c2b84d4f09d71d906c941523f7b74.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","0","#filehash","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","26312"
"*4e09f3d552d00f6ade653b2a9c289a411062b14fab2148f7accab8c8428c9bdb*",".{0,1000}4e09f3d552d00f6ade653b2a9c289a411062b14fab2148f7accab8c8428c9bdb.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#filehash","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","26341"
"*4e19296bcc9b552e7993c02d573a1a5102e0733873aced32809d68c4d0b8428d*",".{0,1000}4e19296bcc9b552e7993c02d573a1a5102e0733873aced32809d68c4d0b8428d.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","26351"
"*4e50d7d853d7b14ecbaa3ec881d83deac55fb19d4934a6f7ab0cb887b7dbf991*",".{0,1000}4e50d7d853d7b14ecbaa3ec881d83deac55fb19d4934a6f7ab0cb887b7dbf991.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","26364"
"*4e6ce0dc8e2b945807e72bc1006cc3ed126542ee95395ccbf973a47cc8b7f04a*",".{0,1000}4e6ce0dc8e2b945807e72bc1006cc3ed126542ee95395ccbf973a47cc8b7f04a.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","26371"
"*4e82ec92f2cd6fd2a1f62c874170a00ec419bae8ad713f2ec1d3a25ad1746693*",".{0,1000}4e82ec92f2cd6fd2a1f62c874170a00ec419bae8ad713f2ec1d3a25ad1746693.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","#filehash","N/A","10","","N/A","","","","26375"
"*4ED3C17D-33E6-4B86-9FA0-DA774B7CD387*",".{0,1000}4ED3C17D\-33E6\-4B86\-9FA0\-DA774B7CD387.{0,1000}","offensive_tool_keyword","FormThief","Spoofing desktop login applications with WinForms and WPF","T1204.002 - T1056.004 - T1071.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/mlcsec/FormThief","1","0","#GUIDproject","N/A","8","2","173","31","2024-02-19T22:40:09Z","2024-02-19T22:34:07Z","26385"
"*4f28ea38405ad0908c509ed774da63b57606fc2257e76d613e6968ff390867a9*",".{0,1000}4f28ea38405ad0908c509ed774da63b57606fc2257e76d613e6968ff390867a9.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","26412"
"*4f3632bb0c4eb05c443535dd3a773f83b3ac47f20ba75fbc3a2c8e6b80a46c60*",".{0,1000}4f3632bb0c4eb05c443535dd3a773f83b3ac47f20ba75fbc3a2c8e6b80a46c60.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","#filehash","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","26417"
"*4FEAB888-F514-4F2E-A4F7-5989A86A69DE*",".{0,1000}4FEAB888\-F514\-4F2E\-A4F7\-5989A86A69DE.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","0","#GUIDproject","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","26460"
"*4ff7578df7293e50c9bdd48657a6ba0c60e1f6d06a2dd334f605af34fe6f75a5*",".{0,1000}4ff7578df7293e50c9bdd48657a6ba0c60e1f6d06a2dd334f605af34fe6f75a5.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26464"
"*4ff7578df7293e50c9bdd48657a6ba0c60e1f6d06a2dd334f605af34fe6f75a5*",".{0,1000}4ff7578df7293e50c9bdd48657a6ba0c60e1f6d06a2dd334f605af34fe6f75a5.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26465"
"*5042151210128f823c5cc143d52c6df18ea3bab1f834f7613d57600a6afc543e*",".{0,1000}5042151210128f823c5cc143d52c6df18ea3bab1f834f7613d57600a6afc543e.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#filehash","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","26492"
"*505bb78684c53f9fb96c92611bbd7ed7096c166f3621fc602b4f0402e0605621*",".{0,1000}505bb78684c53f9fb96c92611bbd7ed7096c166f3621fc602b4f0402e0605621.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","26499"
"*508764b5a7645ca6cd2968f9ad4a37029a7fe1f45d90b46b2f6c03393f5e2730*",".{0,1000}508764b5a7645ca6cd2968f9ad4a37029a7fe1f45d90b46b2f6c03393f5e2730.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26515"
"*510898a4922120a3e1e10c935f84e2f939a022b739afb38a42cb1b5e3a00172d*",".{0,1000}510898a4922120a3e1e10c935f84e2f939a022b739afb38a42cb1b5e3a00172d.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#filehash #linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","26548"
"*51166803b9409224e3c4cdd77b61002707eed020e3d3e03ffa4b03dfabf1f7e4*",".{0,1000}51166803b9409224e3c4cdd77b61002707eed020e3d3e03ffa4b03dfabf1f7e4.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","#filehash","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","26553"
"*519637a04042d8869004121a6e80c35aa2b2370647de9604cbf3ac4eae79424b*",".{0,1000}519637a04042d8869004121a6e80c35aa2b2370647de9604cbf3ac4eae79424b.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","26589"
"*51C6E016-1428-441D-82E9-BB0EB599BBC8*",".{0,1000}51C6E016\-1428\-441D\-82E9\-BB0EB599BBC8.{0,1000}","offensive_tool_keyword","SharpHose","Asynchronous Password Spraying Tool in C# for Windows Environments","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/ustayready/SharpHose","1","0","#GUIDproject","N/A","10","4","312","62","2023-12-19T21:06:47Z","2020-05-01T22:10:49Z","26603"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26607"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26608"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26609"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26610"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26611"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26612"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26613"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26614"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26615"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26616"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26617"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26618"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26619"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26620"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26621"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26622"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26623"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26624"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26625"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26626"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26627"
"*51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df*",".{0,1000}51d45e6c5df6b43b17afc863794f34000d32fb37cd7c3664efc5bd99039ac3df.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26628"
"*51fecfd2da4eb46257e94548af984f53d88be1e8d476ef0bc64a801588dbb6b5*",".{0,1000}51fecfd2da4eb46257e94548af984f53d88be1e8d476ef0bc64a801588dbb6b5.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","26639"
"*528de69797c36423a1e6b64fa8b1825f354e6707f2ca3760d81a9f58d69d58bb*",".{0,1000}528de69797c36423a1e6b64fa8b1825f354e6707f2ca3760d81a9f58d69d58bb.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","0","#filehash","N/A","8","10","N/A","N/A","N/A","N/A","26674"
"*52b07bced660711b3aa82b4cbf40156689045bcd695df40b1376c76e172beb8d*",".{0,1000}52b07bced660711b3aa82b4cbf40156689045bcd695df40b1376c76e172beb8d.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","#filehash","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","26681"
"*52b9c0a0a0188e47cb4b812aabe5a1832633fe9d66cebf702dfe0de114db0abd*",".{0,1000}52b9c0a0a0188e47cb4b812aabe5a1832633fe9d66cebf702dfe0de114db0abd.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","26685"
"*52c54e36cc278993f45d25a56307059f6b6682d802045eaf8eab92ae577eb2e4*",".{0,1000}52c54e36cc278993f45d25a56307059f6b6682d802045eaf8eab92ae577eb2e4.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","26691"
"*5312f40c37c8be83b7131d03100ca39c7e9862465dd40e62d13f153e4ddf1905*",".{0,1000}5312f40c37c8be83b7131d03100ca39c7e9862465dd40e62d13f153e4ddf1905.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","26704"
"*531870bd9f59ac799dfa6573472db1966cd3a9f8ece84d2f2e409e4384770b4a*",".{0,1000}531870bd9f59ac799dfa6573472db1966cd3a9f8ece84d2f2e409e4384770b4a.{0,1000}","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","0","#filehash","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","26708"
"*532a1b17840d0746c48f98d0f24443bd60111db4f3c5f82872ec5e4e6854438a*",".{0,1000}532a1b17840d0746c48f98d0f24443bd60111db4f3c5f82872ec5e4e6854438a.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#filehash","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","26712"
"*537dfda00b6ce57ca35f3da4eaac5cfc42c4180d5573673a66c4665517d0a208*",".{0,1000}537dfda00b6ce57ca35f3da4eaac5cfc42c4180d5573673a66c4665517d0a208.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","#filehash","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","26736"
"*53a8f4b6cd47f980a97be192fdbf70c028065c7bfdf2e461927c7561eafbea6b*",".{0,1000}53a8f4b6cd47f980a97be192fdbf70c028065c7bfdf2e461927c7561eafbea6b.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","0","#filehash","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","26743"
"*53f349d9fefb61b435f3b257f63ec8720b92cc4446cc08455e53ba9c5ca8071c*",".{0,1000}53f349d9fefb61b435f3b257f63ec8720b92cc4446cc08455e53ba9c5ca8071c.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","0","#filehash","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","26764"
"*5475aa1a750cc743c15ce710fb14490b8a59a278c63b0e049954900eedd9df71*",".{0,1000}5475aa1a750cc743c15ce710fb14490b8a59a278c63b0e049954900eedd9df71.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26803"
"*5475aa1a750cc743c15ce710fb14490b8a59a278c63b0e049954900eedd9df71*",".{0,1000}5475aa1a750cc743c15ce710fb14490b8a59a278c63b0e049954900eedd9df71.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26804"
"*54fa00769c5dfc41a26767786517a7b99a7551b16b5589cf3d5287ae1def8534*",".{0,1000}54fa00769c5dfc41a26767786517a7b99a7551b16b5589cf3d5287ae1def8534.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","26844"
"*553783ac96602dadd391b657eec078f7ab768c1b06bc04373e9fe9068f113041*",".{0,1000}553783ac96602dadd391b657eec078f7ab768c1b06bc04373e9fe9068f113041.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","26865"
"*554F8E48FA40E48E261B91A4F9F1930E099EBF337DFAC826BC41F4E850C4889F*",".{0,1000}554F8E48FA40E48E261B91A4F9F1930E099EBF337DFAC826BC41F4E850C4889F.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","26868"
"*555009ba8f9b57011fef7ca143c78e15d11bce2e471f6b742cbddda5c2d12e60*",".{0,1000}555009ba8f9b57011fef7ca143c78e15d11bce2e471f6b742cbddda5c2d12e60.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","26869"
"*5571bc0232f7f7911042503b2a2224ad420788d999eb819257a00943928a56bb*",".{0,1000}5571bc0232f7f7911042503b2a2224ad420788d999eb819257a00943928a56bb.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","#filehash","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","26878"
"*55A48A19-1A5C-4E0D-A46A-5DB04C1D8B03*",".{0,1000}55A48A19\-1A5C\-4E0D\-A46A\-5DB04C1D8B03.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","0","#GUIDproject","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","26896"
"*55d8c97ec4476f7ada4f2991de85f6ddb973ac4634dc0a08e2c731d75c5700b3*",".{0,1000}55d8c97ec4476f7ada4f2991de85f6ddb973ac4634dc0a08e2c731d75c5700b3.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","#filehash","N/A","9","10","N/A","N/A","N/A","N/A","26916"
"*561c5f3163f3e6864d547c4412339872841fd9b5d365f10a0d95d2bb366b8396*",".{0,1000}561c5f3163f3e6864d547c4412339872841fd9b5d365f10a0d95d2bb366b8396.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","26929"
"*567639e3dc4355c549e9c9cc42988325cb95a0f6e86004d5679ad3e15af7c6cd*",".{0,1000}567639e3dc4355c549e9c9cc42988325cb95a0f6e86004d5679ad3e15af7c6cd.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","26954"
"*56860821457ebef4e71091ee01f6abe3703bc83cc56ae6db40ed140ab1c48043*",".{0,1000}56860821457ebef4e71091ee01f6abe3703bc83cc56ae6db40ed140ab1c48043.{0,1000}","offensive_tool_keyword","Dispossessor","Bruteforce tools used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","26956"
"*56a0e08a01309e17e4e6c753948fd4f341e9a41b1b834b3ce697bffdd90c467b*",".{0,1000}56a0e08a01309e17e4e6c753948fd4f341e9a41b1b834b3ce697bffdd90c467b.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","26970"
"*56c9dd7fe7e9f3e8692fe8e305214cfa2db85424b254f95c97e56e4b35193634*",".{0,1000}56c9dd7fe7e9f3e8692fe8e305214cfa2db85424b254f95c97e56e4b35193634.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26988"
"*56c9dd7fe7e9f3e8692fe8e305214cfa2db85424b254f95c97e56e4b35193634*",".{0,1000}56c9dd7fe7e9f3e8692fe8e305214cfa2db85424b254f95c97e56e4b35193634.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","26989"
"*56f3c70dd9cb4be15fb429491245d75ce48a4cb9d8877f2be6e2493673674606*",".{0,1000}56f3c70dd9cb4be15fb429491245d75ce48a4cb9d8877f2be6e2493673674606.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","27005"
"*57d785125cf62ffdb727ac7f56110dc0ab0403f033caf958b717fc93f963f097*",".{0,1000}57d785125cf62ffdb727ac7f56110dc0ab0403f033caf958b717fc93f963f097.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","27076"
"*580ec64c62709841ca04ba73473f1e8681fde57ebbbbb81d1fe12b075b263057*",".{0,1000}580ec64c62709841ca04ba73473f1e8681fde57ebbbbb81d1fe12b075b263057.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","27090"
"*58297eb7cad8589399f7b0bc92d61c144ee05786dfc06f527826965ae4062f99*",".{0,1000}58297eb7cad8589399f7b0bc92d61c144ee05786dfc06f527826965ae4062f99.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","27097"
"*58338E42-6010-493C-B8C8-2FD2CFC30FFB*",".{0,1000}58338E42\-6010\-493C\-B8C8\-2FD2CFC30FFB.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","#GUIDproject","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","27101"
"*58cd6577c12f1c12a51e8abbe80aa54cd358e7c65a4efa8f28425d98ff0278cc*",".{0,1000}58cd6577c12f1c12a51e8abbe80aa54cd358e7c65a4efa8f28425d98ff0278cc.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","27152"
"*592357cfeb7bbc10865d9e64e4b778bd742a6abb452166e9f9b1eef404f67a31*",".{0,1000}592357cfeb7bbc10865d9e64e4b778bd742a6abb452166e9f9b1eef404f67a31.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","27176"
"*592357cfeb7bbc10865d9e64e4b778bd742a6abb452166e9f9b1eef404f67a31*",".{0,1000}592357cfeb7bbc10865d9e64e4b778bd742a6abb452166e9f9b1eef404f67a31.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","27177"
"*59395105f688ef8c35cf2061928c2cb7f2f5d748518ca9ebfa5ee14a2461915e*",".{0,1000}59395105f688ef8c35cf2061928c2cb7f2f5d748518ca9ebfa5ee14a2461915e.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","27178"
"*598555a7e053c7456ee8a06a892309386e69d473c73284de9bbc0ba73b17e70a*",".{0,1000}598555a7e053c7456ee8a06a892309386e69d473c73284de9bbc0ba73b17e70a.{0,1000}","offensive_tool_keyword","dialupass","This utility enumerates all dialup/VPN entries on your computers. and displays their logon details: User Name. Password. and Domain. You can use it to recover a lost password of your Internet connection or VPN.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/dialupass.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","27197"
"*5a0976fef89e32ddcf62c790f9bb4c174a79004e627c3521604f46bf5cc7bea2*",".{0,1000}5a0976fef89e32ddcf62c790f9bb4c174a79004e627c3521604f46bf5cc7bea2.{0,1000}","offensive_tool_keyword","Invoke-WCMDump","PowerShell script to dump Windows credentials from the Credential Manager Invoke-WCMDump enumerates Windows credentials in the Credential Manager and then extracts available information about each one. Passwords are retrieved for Generic type credentials. but can not be retrived by the same method for Domain type credentials. Credentials are only returned for the current user","T1003 - T1003.003 - T1003.001 - T1552","TA0006 - TA0006 - TA0006 - TA0006","N/A","N/A","Credential Access","https://github.com/peewpw/Invoke-WCMDump","1","0","#filehash","N/A","10","8","722","134","2017-12-12T00:46:33Z","2017-12-09T21:36:59Z","27224"
"*5a0bd791d08f5f9871a1b2fa7f1aea81d0aeb90c7df95fe0534d3faac1847e74*",".{0,1000}5a0bd791d08f5f9871a1b2fa7f1aea81d0aeb90c7df95fe0534d3faac1847e74.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","#filehash","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","27225"
"*5a1f9b0e-9f7c-4673-bf16-4740707f41b7*",".{0,1000}5a1f9b0e\-9f7c\-4673\-bf16\-4740707f41b7.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","#GUIDproject","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","27233"
"*5a2e947aace9e081ecd2cfa7bc2e485528238555c7eeb6bcca560576d4750a50*",".{0,1000}5a2e947aace9e081ecd2cfa7bc2e485528238555c7eeb6bcca560576d4750a50.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","27238"
"*5a66c739cbd2e664a77e6dbbdcb318ca7a99e1a98e9314b0a90ea20378cdb9bd*",".{0,1000}5a66c739cbd2e664a77e6dbbdcb318ca7a99e1a98e9314b0a90ea20378cdb9bd.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","#filehash","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","27252"
"*5a9b8cfd138823a0d9799afc9eb70f28ec2ede90a1db1fde81d8bd70e5613fba*",".{0,1000}5a9b8cfd138823a0d9799afc9eb70f28ec2ede90a1db1fde81d8bd70e5613fba.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","27265"
"*5aaed5c8657383a894443a92a259182d9dc2c01de72a80460fff4a636e20c65b*",".{0,1000}5aaed5c8657383a894443a92a259182d9dc2c01de72a80460fff4a636e20c65b.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","27268"
"*5ac7b2c9c03ec6be6c8e0ea6ffd0b9ca0c69a8f2472d3e183780bfc6f86fc7f6*",".{0,1000}5ac7b2c9c03ec6be6c8e0ea6ffd0b9ca0c69a8f2472d3e183780bfc6f86fc7f6.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","27275"
"*5b095728389373e05a038fea724aa2dd66c3ff68b830cc651fd92177afe8c8b3*",".{0,1000}5b095728389373e05a038fea724aa2dd66c3ff68b830cc651fd92177afe8c8b3.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","27298"
"*5b3811e463d5b424593910cbf7fd06218e993f8399a9add27b053f98bc984587*",".{0,1000}5b3811e463d5b424593910cbf7fd06218e993f8399a9add27b053f98bc984587.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","#filehash","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","27311"
"*5b55d8a0b50b89156ef7d09cffede9385fdad53301c16f2570a1888e7ee1cdf7*",".{0,1000}5b55d8a0b50b89156ef7d09cffede9385fdad53301c16f2570a1888e7ee1cdf7.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","#filehash","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","27322"
"*5b992399231bc699bda60ec893e9c5af0ccded956ebfe5d02eaa41cb91fea9c8*",".{0,1000}5b992399231bc699bda60ec893e9c5af0ccded956ebfe5d02eaa41cb91fea9c8.{0,1000}","greyware_tool_keyword","ChromeCookiesView","displays the list of all cookies stored by Google Chrome Web browser - abused by attackers","T1539 - T1005 - T1070.004 - T1552.001","TA0006 - TA0008 - TA0009","N/A","Evilnum - MuddyWater","Credential Access","https://www.nirsoft.net/utils/chrome_cookies_view.html","1","0","#filehash","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","8","10","N/A","N/A","N/A","N/A","27356"
"*5be325905df8aab7089ab2348d89343f55a2f88dadd75de8f382e8fa026451bd*",".{0,1000}5be325905df8aab7089ab2348d89343f55a2f88dadd75de8f382e8fa026451bd.{0,1000}","offensive_tool_keyword","MailPassView","Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","27378"
"*5be325905df8aab7089ab2348d89343f55a2f88dadd75de8f382e8fa026451bd*",".{0,1000}5be325905df8aab7089ab2348d89343f55a2f88dadd75de8f382e8fa026451bd.{0,1000}","offensive_tool_keyword","MailPassView","Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","27379"
"*5c177feedd58a6ccc8287dee8c767dd486f2b5c55c234360be17f85fcbaa4501*",".{0,1000}5c177feedd58a6ccc8287dee8c767dd486f2b5c55c234360be17f85fcbaa4501.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","#filehash","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","27392"
"*5c7e09b63bd99851d8b93241f3907917c07af3903aa024da0bd549ae1fc373f7*",".{0,1000}5c7e09b63bd99851d8b93241f3907917c07af3903aa024da0bd549ae1fc373f7.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","0","#filehash","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","27424"
"*5c85b965c19ff7f7742980f90965279aa0ae2ea4c50317ad7680b56d6e3ed9d5*",".{0,1000}5c85b965c19ff7f7742980f90965279aa0ae2ea4c50317ad7680b56d6e3ed9d5.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","27427"
"*5ccafa7f7b00774dd423a64460ef3d1c551ee95f076107cb8353f6271819f4d7*",".{0,1000}5ccafa7f7b00774dd423a64460ef3d1c551ee95f076107cb8353f6271819f4d7.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","#filehash","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","27444"
"*5cdec4449506fe06e507619c8f1a66d890d96bb2ea30f6ea37f997853a52b243*",".{0,1000}5cdec4449506fe06e507619c8f1a66d890d96bb2ea30f6ea37f997853a52b243.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","0","#filehash","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","27448"
"*5d16081315e1588a26019bb5195f2f72f278a3c86acf8cc1c072b791960beabf*",".{0,1000}5d16081315e1588a26019bb5195f2f72f278a3c86acf8cc1c072b791960beabf.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","27466"
"*5d17e9dd54752bf9071caeccace27123897fe33de26db8c6f3e544abd11f7cb2*",".{0,1000}5d17e9dd54752bf9071caeccace27123897fe33de26db8c6f3e544abd11f7cb2.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","0","#filehash","N/A","7","10","N/A","N/A","N/A","N/A","27467"
"*5D3EF551-3D1F-468E-A75B-764F436D577D*",".{0,1000}5D3EF551\-3D1F\-468E\-A75B\-764F436D577D.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","#GUIDproject","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","27492"
"*5d975e81c68574849bb0fec4c6d2116a4ba7dd58bdd1710463ab75d9a8054bc3*",".{0,1000}5d975e81c68574849bb0fec4c6d2116a4ba7dd58bdd1710463ab75d9a8054bc3.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","#filehash","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","27513"
"*5db4c8112942c658a4f14d16fff13781dd705273c0050b2ada09ec79c7cb7c87*",".{0,1000}5db4c8112942c658a4f14d16fff13781dd705273c0050b2ada09ec79c7cb7c87.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","#filehash","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","27521"
"*5DE7F97C-B97B-489F-A1E4-9F9656317F94*",".{0,1000}5DE7F97C\-B97B\-489F\-A1E4\-9F9656317F94.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","#GUIDproject","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","27534"
"*5df2061e118e67da27199797b696b33b0176f35d155b2a1204b4fd11ea6d25bb*",".{0,1000}5df2061e118e67da27199797b696b33b0176f35d155b2a1204b4fd11ea6d25bb.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","0","#filehash","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","27538"
"*5e00926cb43b56a330532ce5c4f0988172d49d28840ed490526976a7b2ea2479*",".{0,1000}5e00926cb43b56a330532ce5c4f0988172d49d28840ed490526976a7b2ea2479.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","#filehash","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","27542"
"*5e438cc32aa2a58190adc379d070d815afd1b03284eb7922b8daed40014ad1ef*",".{0,1000}5e438cc32aa2a58190adc379d070d815afd1b03284eb7922b8daed40014ad1ef.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","27563"
"*5e5e21abed5ff9e25cd2ea1c626a1f0ffe6194d1e2c74dfec8aebc0789b2dee1*",".{0,1000}5e5e21abed5ff9e25cd2ea1c626a1f0ffe6194d1e2c74dfec8aebc0789b2dee1.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","#filehash","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","27570"
"*5e87e7fe137ab8f51780b6646e74e942efa89a4ff95cb190dd0bf35a5dcf59e8*",".{0,1000}5e87e7fe137ab8f51780b6646e74e942efa89a4ff95cb190dd0bf35a5dcf59e8.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","#filehash","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","27583"
"*5eabd7d957e56a9cb9a918f7e9f72dc76a0481954c2f93ad5264095b5dbb6897*",".{0,1000}5eabd7d957e56a9cb9a918f7e9f72dc76a0481954c2f93ad5264095b5dbb6897.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","27593"
"*5eabd7d957e56a9cb9a918f7e9f72dc76a0481954c2f93ad5264095b5dbb6897*",".{0,1000}5eabd7d957e56a9cb9a918f7e9f72dc76a0481954c2f93ad5264095b5dbb6897.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","27594"
"*5eabd7d957e56a9cb9a918f7e9f72dc76a0481954c2f93ad5264095b5dbb6897*",".{0,1000}5eabd7d957e56a9cb9a918f7e9f72dc76a0481954c2f93ad5264095b5dbb6897.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","27595"
"*5F026C27-F8E6-4052-B231-8451C6A73838*",".{0,1000}5F026C27\-F8E6\-4052\-B231\-8451C6A73838.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","#GUIDproject","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","27613"
"*5f87b4ab00f09c64f4d30fcfbf19e9e6945971c74d28370c720e52b83f7decf3*",".{0,1000}5f87b4ab00f09c64f4d30fcfbf19e9e6945971c74d28370c720e52b83f7decf3.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","27642"
"*5f8fdd73abce168e8b44db54ad203a66d4983d1fd2563bb5922c0aaef9abc4ea*",".{0,1000}5f8fdd73abce168e8b44db54ad203a66d4983d1fd2563bb5922c0aaef9abc4ea.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","0","#filehash","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","27646"
"*60724a25dd319ec57b77e16c52e52a09c7b82ed4ea38dab6d6c2e880dcebb439*",".{0,1000}60724a25dd319ec57b77e16c52e52a09c7b82ed4ea38dab6d6c2e880dcebb439.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","27707"
"*60a78c06f7db71904cc08748c5b507bd88ed8a08c31f21d8a796c562a3f0c5b9*",".{0,1000}60a78c06f7db71904cc08748c5b507bd88ed8a08c31f21d8a796c562a3f0c5b9.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","0","#filehash","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","27717"
"*60D02E32-1711-4D9E-9AC2-10627C52EB40*",".{0,1000}60D02E32\-1711\-4D9E\-9AC2\-10627C52EB40.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz GUID project","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#GUIDproject","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","27724"
"*610f948ee1af2ac334186ca21a3bea4d819a45fee51c2753fe1cd0bb8cc30d1d*",".{0,1000}610f948ee1af2ac334186ca21a3bea4d819a45fee51c2753fe1cd0bb8cc30d1d.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","27739"
"*6126c4f3c62340df9f501ef98b7266ef2b0fd668a9b286d4bc36eff5e46095bc*",".{0,1000}6126c4f3c62340df9f501ef98b7266ef2b0fd668a9b286d4bc36eff5e46095bc.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","#filehash","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","27747"
"*61573b0cc19ea7bfb6ebe0ad6285d490710a1a09db5e32ab7e029ee466874bcc*",".{0,1000}61573b0cc19ea7bfb6ebe0ad6285d490710a1a09db5e32ab7e029ee466874bcc.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","27765"
"*61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1*",".{0,1000}61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","27792"
"*61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1*",".{0,1000}61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","27793"
"*61d81c3ef4a77bd815d196b650e773ed31a507320c43c52bb9f6798eff4d3413*",".{0,1000}61d81c3ef4a77bd815d196b650e773ed31a507320c43c52bb9f6798eff4d3413.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","27799"
"*620d4c08d472520f16e52e35c1eb622c43fe583b40b977b258828ac05f439dba*",".{0,1000}620d4c08d472520f16e52e35c1eb622c43fe583b40b977b258828ac05f439dba.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","27812"
"*620d4c08d472520f16e52e35c1eb622c43fe583b40b977b258828ac05f439dba*",".{0,1000}620d4c08d472520f16e52e35c1eb622c43fe583b40b977b258828ac05f439dba.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","27813"
"*623F0079-5871-4237-B872-70FDFC2D8C52*",".{0,1000}623F0079\-5871\-4237\-B872\-70FDFC2D8C52.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","#GUIDproject","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","27822"
"*62440D3B8BE22B9353AC1374CC6ED1FAF4476908FE6D8E9FBD3AA62004EFEF3E*",".{0,1000}62440D3B8BE22B9353AC1374CC6ED1FAF4476908FE6D8E9FBD3AA62004EFEF3E.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#filehash","manually compiled","10","10","N/A","N/A","N/A","N/A","27824"
"*62a32ce26d8954a32e41cb222e6c2fab2e25b3b99d7567a051a3875a0d5ee7e3*",".{0,1000}62a32ce26d8954a32e41cb222e6c2fab2e25b3b99d7567a051a3875a0d5ee7e3.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","27845"
"*62a32ce26d8954a32e41cb222e6c2fab2e25b3b99d7567a051a3875a0d5ee7e3*",".{0,1000}62a32ce26d8954a32e41cb222e6c2fab2e25b3b99d7567a051a3875a0d5ee7e3.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","27846"
"*62f11b4ae2f0d26ed55efd4c918cfec1bd95036f507cf2dbf3295949831366ca*",".{0,1000}62f11b4ae2f0d26ed55efd4c918cfec1bd95036f507cf2dbf3295949831366ca.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#filehash","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","27873"
"*63e9c4ad28c4ee5fd63bee6124590a0edb6c7dc4b20d1b4f6aefdb53f5b94a1a*",".{0,1000}63e9c4ad28c4ee5fd63bee6124590a0edb6c7dc4b20d1b4f6aefdb53f5b94a1a.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","27940"
"*6448c50a9a80154c2f1ca5b7525ffc8822f16562b1774a54efd066fcc80620e8*",".{0,1000}6448c50a9a80154c2f1ca5b7525ffc8822f16562b1774a54efd066fcc80620e8.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","27971"
"*646698ef7a2a2cf03c2068c8e1c8b2f8fc18128b6027100c45acfe18b5c6d177*",".{0,1000}646698ef7a2a2cf03c2068c8e1c8b2f8fc18128b6027100c45acfe18b5c6d177.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","27981"
"*64d2173109cdc67df6e9e15a275b4ed0b5488397c290b996ffd3ed445f361b79*",".{0,1000}64d2173109cdc67df6e9e15a275b4ed0b5488397c290b996ffd3ed445f361b79.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","0","#filehash","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","28007"
"*64D84D51-F462-4A24-85EA-845C97238C09*",".{0,1000}64D84D51\-F462\-4A24\-85EA\-845C97238C09.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","#GUIDproject","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","28011"
"*64e8b1efc560e837ac87e1fe231b92781d5eb9dfc3688d10fd38ed32f5556640*",".{0,1000}64e8b1efc560e837ac87e1fe231b92781d5eb9dfc3688d10fd38ed32f5556640.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","28013"
"*651e286fdf6d57e43df7aeb51d819999ecc28621bdefb834a5ef57d41dcf7336*",".{0,1000}651e286fdf6d57e43df7aeb51d819999ecc28621bdefb834a5ef57d41dcf7336.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","28032"
"*65514a7171c001cd3bcc99f90efca058fe8b22ba896194eb60ea2249fbce66ee*",".{0,1000}65514a7171c001cd3bcc99f90efca058fe8b22ba896194eb60ea2249fbce66ee.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","28042"
"*658C8B7F-3664-4A95-9572-A3E5871DFC06*",".{0,1000}658C8B7F\-3664\-4A95\-9572\-A3E5871DFC06.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","#GUIDproject","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","28060"
"*658C8B7F-3664-4A95-9572-A3E5871DFC06*",".{0,1000}658C8B7F\-3664\-4A95\-9572\-A3E5871DFC06.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","#GUIDproject","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","28061"
"*658C8B7F-3664-4A95-9572-A3E5871DFC06*",".{0,1000}658C8B7F\-3664\-4A95\-9572\-A3E5871DFC06.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","#GUIDproject","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","28062"
"*65b73f44795c9d8a7ac35a5d730787d72c2ceaa15ff0a8788038bee7b56edf48*",".{0,1000}65b73f44795c9d8a7ac35a5d730787d72c2ceaa15ff0a8788038bee7b56edf48.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","28072"
"*66092d1e08e55e35b60dc348f2f59d69c0768a09ce411a50fc0d161bfab3303d*",".{0,1000}66092d1e08e55e35b60dc348f2f59d69c0768a09ce411a50fc0d161bfab3303d.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","28097"
"*6646a6c4e3006b90ff7009eb28cd9d5ff182d7f4d8465dbe63357a8c054257bb*",".{0,1000}6646a6c4e3006b90ff7009eb28cd9d5ff182d7f4d8465dbe63357a8c054257bb.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","28109"
"*665a22568c5d38db4ce74dde13053e8a66baf91356e4f35a9e2957c205a09f1a*",".{0,1000}665a22568c5d38db4ce74dde13053e8a66baf91356e4f35a9e2957c205a09f1a.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#filehash #linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","28116"
"*66928c3316a12091995198710e0c537430dacefac1dbe78f12a331e1520142bd*",".{0,1000}66928c3316a12091995198710e0c537430dacefac1dbe78f12a331e1520142bd.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28129"
"*66928c3316a12091995198710e0c537430dacefac1dbe78f12a331e1520142bd*",".{0,1000}66928c3316a12091995198710e0c537430dacefac1dbe78f12a331e1520142bd.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28130"
"*66e0681a500c726ed52e5ea9423d2654*",".{0,1000}66e0681a500c726ed52e5ea9423d2654.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","28150"
"*6788355188c40674e65fd8d2bd610ec4be42d1a5d78116990c0d109863c39a3e*",".{0,1000}6788355188c40674e65fd8d2bd610ec4be42d1a5d78116990c0d109863c39a3e.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","28188"
"*67d132f09b67e82cb54b941814c28737974165bcec5139909ed455fe97f2ab41*",".{0,1000}67d132f09b67e82cb54b941814c28737974165bcec5139909ed455fe97f2ab41.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","28201"
"*67f6f13cd32457711eb5171e7f87942319edd25e5463ac770e7666d71b1382b7*",".{0,1000}67f6f13cd32457711eb5171e7f87942319edd25e5463ac770e7666d71b1382b7.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","28208"
"*6881a17bb0b124e295cfbf2fae1165babe35a3dda065dd246dad52b107ef3252*",".{0,1000}6881a17bb0b124e295cfbf2fae1165babe35a3dda065dd246dad52b107ef3252.{0,1000}","offensive_tool_keyword","Dispossessor","Bruteforce tools used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","28235"
"*6905595a21a2a1d669fb80a6fd3f97db4692d98ad9e33eae64466c7cfbaabb8b*",".{0,1000}6905595a21a2a1d669fb80a6fd3f97db4692d98ad9e33eae64466c7cfbaabb8b.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","28262"
"*6936c267e3cbb3bb7f418e26594bbf7367b7d2c8de6ad5d0e88c2cb3485dfcd9*",".{0,1000}6936c267e3cbb3bb7f418e26594bbf7367b7d2c8de6ad5d0e88c2cb3485dfcd9.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","28279"
"*69ace7287faa4854605ab46018d92332ba0d16ff926ebf17330359a4dbd7d693*",".{0,1000}69ace7287faa4854605ab46018d92332ba0d16ff926ebf17330359a4dbd7d693.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#filehash","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","28314"
"*6a0b2e5491caa977cc4efcea1a90b67480126b0d3148d1436add939bfbe785d5*",".{0,1000}6a0b2e5491caa977cc4efcea1a90b67480126b0d3148d1436add939bfbe785d5.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","28338"
"*6a4345d4d5465097dfbe8ba3d2007c7200c8cf320f9123abc1bf03f12dbe6b4d*",".{0,1000}6a4345d4d5465097dfbe8ba3d2007c7200c8cf320f9123abc1bf03f12dbe6b4d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28355"
"*6a4345d4d5465097dfbe8ba3d2007c7200c8cf320f9123abc1bf03f12dbe6b4d*",".{0,1000}6a4345d4d5465097dfbe8ba3d2007c7200c8cf320f9123abc1bf03f12dbe6b4d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28356"
"*6a484c1db7718949c7027abde97e164c7e7e4e4214e3e29fe48ac4364c0cd23c*",".{0,1000}6a484c1db7718949c7027abde97e164c7e7e4e4214e3e29fe48ac4364c0cd23c.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","#filehash","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","28360"
"*6A5942A4-9086-408E-A9B4-05ABC34BFD58*",".{0,1000}6A5942A4\-9086\-408E\-A9B4\-05ABC34BFD58.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","#GUIDproject","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","28363"
"*6a5edddee3c2cd833864b0cae1a3a8e64bf48fef7bd421d7a779340bf55f8751*",".{0,1000}6a5edddee3c2cd833864b0cae1a3a8e64bf48fef7bd421d7a779340bf55f8751.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","0","#filehash","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","28364"
"*6a5edddee3c2cd833864b0cae1a3a8e64bf48fef7bd421d7a779340bf55f8751*",".{0,1000}6a5edddee3c2cd833864b0cae1a3a8e64bf48fef7bd421d7a779340bf55f8751.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","0","#filehash","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","28365"
"*6b1017d1325f9f981edbaf071defdda45e26af30eb2a6819c039a6a17e8a14c7*",".{0,1000}6b1017d1325f9f981edbaf071defdda45e26af30eb2a6819c039a6a17e8a14c7.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","28397"
"*6b8453724d41251986a3dc94f0e725d07a4c1b9171228e89ee8ef0daef3b0b2c*",".{0,1000}6b8453724d41251986a3dc94f0e725d07a4c1b9171228e89ee8ef0daef3b0b2c.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28422"
"*6b8453724d41251986a3dc94f0e725d07a4c1b9171228e89ee8ef0daef3b0b2c*",".{0,1000}6b8453724d41251986a3dc94f0e725d07a4c1b9171228e89ee8ef0daef3b0b2c.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28423"
"*6babb664a4c688234f19f258d7a4de2ffd2b8eb51a9ae6c35ea0bee20d214453*",".{0,1000}6babb664a4c688234f19f258d7a4de2ffd2b8eb51a9ae6c35ea0bee20d214453.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","28433"
"*6c44d6bfc218285f9f359e67c18bb652b16602dbcd524128a2a8996823a683ee*",".{0,1000}6c44d6bfc218285f9f359e67c18bb652b16602dbcd524128a2a8996823a683ee.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","28470"
"*6cc5645274bdacebf9b7d37b49f7440184722f021e13c407df2f7fc71c2b8e5f*",".{0,1000}6cc5645274bdacebf9b7d37b49f7440184722f021e13c407df2f7fc71c2b8e5f.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","28510"
"*6d5aef94f94fcf9b0987102f2b436e37f173e9638b08d1cd45d14132071617db*",".{0,1000}6d5aef94f94fcf9b0987102f2b436e37f173e9638b08d1cd45d14132071617db.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","28540"
"*6d6a190059cb9ace0b4e16aace82f752ae57df9b36db03508acb3bb4fabe4d05*",".{0,1000}6d6a190059cb9ace0b4e16aace82f752ae57df9b36db03508acb3bb4fabe4d05.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","28549"
"*6d955490b7ccb6ef77222ec41f494c186050fd9b6b022451ab8ec48104d79673*",".{0,1000}6d955490b7ccb6ef77222ec41f494c186050fd9b6b022451ab8ec48104d79673.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28559"
"*6e7d2c54b036019f32df4238d9f26e97efe246df82c687ee8033c7c9fe5a9f09*",".{0,1000}6e7d2c54b036019f32df4238d9f26e97efe246df82c687ee8033c7c9fe5a9f09.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","#filehash","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","28617"
"*6E8D2C12-255B-403C-9EF3-8A097D374DB2*",".{0,1000}6E8D2C12\-255B\-403C\-9EF3\-8A097D374DB2.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","0","#GUIDproject","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","28621"
"*6ed65758ecfa41680c567082d18526278b6e446b37046b578c6b1bf531d81f59*",".{0,1000}6ed65758ecfa41680c567082d18526278b6e446b37046b578c6b1bf531d81f59.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","28641"
"*6f14aa417bc4b85c47ef65bfed84e2b7728b1cb8bdd1c0cfc6eb6cd7fd0db7c0*",".{0,1000}6f14aa417bc4b85c47ef65bfed84e2b7728b1cb8bdd1c0cfc6eb6cd7fd0db7c0.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","#filehash","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","28666"
"*6f46d85ab9aef2bf824b8714f29f9ff189a390c56294ab82308178e86fad472d*",".{0,1000}6f46d85ab9aef2bf824b8714f29f9ff189a390c56294ab82308178e86fad472d.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","#filehash","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","28682"
"*6f7204e9f37025c754fd990061bda4246aa63d13e4f9fe951c7a2871c2ecf5f5*",".{0,1000}6f7204e9f37025c754fd990061bda4246aa63d13e4f9fe951c7a2871c2ecf5f5.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","28694"
"*6FC09BDB-365F-4691-BBD9-CB7F69C9527A*",".{0,1000}6FC09BDB\-365F\-4691\-BBD9\-CB7F69C9527A.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#GUIDproject","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","28715"
"*6fd569e4c0b8bb63b28317f10ca965d4921b126f601ce72824e40f71465b03ba*",".{0,1000}6fd569e4c0b8bb63b28317f10ca965d4921b126f601ce72824e40f71465b03ba.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28719"
"*6fd569e4c0b8bb63b28317f10ca965d4921b126f601ce72824e40f71465b03ba*",".{0,1000}6fd569e4c0b8bb63b28317f10ca965d4921b126f601ce72824e40f71465b03ba.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28720"
"*6FFCCF81-6C3C-4D3F-B15F-35A86D0B497F*",".{0,1000}6FFCCF81\-6C3C\-4D3F\-B15F\-35A86D0B497F.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","0","#GUIDproject","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","28729"
"*70aaf2b367b97fa35d599a6db4d08875206ef18c99d8c8c5b5f25e4f5509931a*",".{0,1000}70aaf2b367b97fa35d599a6db4d08875206ef18c99d8c8c5b5f25e4f5509931a.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","28773"
"*70c62e0f2725a158d53c4fe2be205bb5ae07264a85af693741761e7fb7c8c521*",".{0,1000}70c62e0f2725a158d53c4fe2be205bb5ae07264a85af693741761e7fb7c8c521.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28783"
"*70c62e0f2725a158d53c4fe2be205bb5ae07264a85af693741761e7fb7c8c521*",".{0,1000}70c62e0f2725a158d53c4fe2be205bb5ae07264a85af693741761e7fb7c8c521.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","28784"
"*713c7d03ee5e75b2cacae76a91418ce7855faf39c485f97aed1e277bab87de47*",".{0,1000}713c7d03ee5e75b2cacae76a91418ce7855faf39c485f97aed1e277bab87de47.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","#filehash","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","28819"
"*71461ca71bcebb5fefa9394fe8e9a5a47c102195064d1f4cb5f24d330c9be97d*",".{0,1000}71461ca71bcebb5fefa9394fe8e9a5a47c102195064d1f4cb5f24d330c9be97d.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#filehash","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","28821"
"*716ba53b9245b9f98cd68f191e20451f7a6d54864486051e8ce1f08132df97e4*",".{0,1000}716ba53b9245b9f98cd68f191e20451f7a6d54864486051e8ce1f08132df97e4.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","28828"
"*7186796941:AAHmCxfhfQvNwDAtlvAmGY-N9c5sFXhHpNM*",".{0,1000}7186796941\:AAHmCxfhfQvNwDAtlvAmGY\-N9c5sFXhHpNM.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","default telegram secrets","10","","N/A","","","","28833"
"*71e42659e0e9e225d76c33796093aaf32bc1f29359a6f8a4105b6e07c1c10df6*",".{0,1000}71e42659e0e9e225d76c33796093aaf32bc1f29359a6f8a4105b6e07c1c10df6.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","28860"
"*7202dbae30292ab2e370ff0fbcb4cdb5ef765e1e290968f7222d65c24e4645ba*",".{0,1000}7202dbae30292ab2e370ff0fbcb4cdb5ef765e1e290968f7222d65c24e4645ba.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","28864"
"*72147820461101ca9687ef5177cafad482953946d1b93c54c1cfc69a953496ae*",".{0,1000}72147820461101ca9687ef5177cafad482953946d1b93c54c1cfc69a953496ae.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","28867"
"*726888af98eaa956dd40e486f4fcb93d7e12880f9540d9f28aabda8f90035c1a*",".{0,1000}726888af98eaa956dd40e486f4fcb93d7e12880f9540d9f28aabda8f90035c1a.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","28905"
"*72c3a786661ee9742cf1d0e3b99b89e976911ed87971695f08487cf42d7fc29d*",".{0,1000}72c3a786661ee9742cf1d0e3b99b89e976911ed87971695f08487cf42d7fc29d.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","28927"
"*72d57c0c42ccd4ec3a220ac3c91cbb49b25cfcabebd30e36539980b52cfd49a4*",".{0,1000}72d57c0c42ccd4ec3a220ac3c91cbb49b25cfcabebd30e36539980b52cfd49a4.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","28935"
"*73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f*",".{0,1000}73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","28956"
"*7331b5c04c58757162a4448cc22df3483cbc4c38823a0e11026830f6cdfabf75*",".{0,1000}7331b5c04c58757162a4448cc22df3483cbc4c38823a0e11026830f6cdfabf75.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","28959"
"*736b362973af7010de9bf1cea58547a17a236e81a2084c344cf06a1b184698bb*",".{0,1000}736b362973af7010de9bf1cea58547a17a236e81a2084c344cf06a1b184698bb.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","#filehash","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","28975"
"*736c69887df76672923ad7ae8b1b1754f13f96d3ae5e2eea7259e29163af71d0*",".{0,1000}736c69887df76672923ad7ae8b1b1754f13f96d3ae5e2eea7259e29163af71d0.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","0","#filehash","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","28976"
"*73882b9c273a72eb49fc2854de8b37ef3012115c0e62267acb8b955a681ec312*",".{0,1000}73882b9c273a72eb49fc2854de8b37ef3012115c0e62267acb8b955a681ec312.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","28982"
"*738dd06fea4b4b507c0438eac77c8ed3267ed9617b51c565ea05f21529999164*",".{0,1000}738dd06fea4b4b507c0438eac77c8ed3267ed9617b51c565ea05f21529999164.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","28984"
"*738f3dce5ad63a16b2cf8b236d8d374022f121c0990e92adc214a6d03b0dc345*",".{0,1000}738f3dce5ad63a16b2cf8b236d8d374022f121c0990e92adc214a6d03b0dc345.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","0","#filehash","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","28985"
"*73B2C22B-C020-45B7-BF61-B48F49A2693F*",".{0,1000}73B2C22B\-C020\-45B7\-BF61\-B48F49A2693F.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","0","#GUIDproject","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","28995"
"*73c6754604666d7e05ed07db7ebc79fa3fe8d85cb049132c1b7b7d33181a70e6*",".{0,1000}73c6754604666d7e05ed07db7ebc79fa3fe8d85cb049132c1b7b7d33181a70e6.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","0","#filehash","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","28999"
"*7409b573c0e8e5ab73e6e3fafbe635438fbfd6f2acb57a31c859f43ad623f64f*",".{0,1000}7409b573c0e8e5ab73e6e3fafbe635438fbfd6f2acb57a31c859f43ad623f64f.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29016"
"*7409b573c0e8e5ab73e6e3fafbe635438fbfd6f2acb57a31c859f43ad623f64f*",".{0,1000}7409b573c0e8e5ab73e6e3fafbe635438fbfd6f2acb57a31c859f43ad623f64f.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29017"
"*744e50af5566fa5ab70d4db70d35b3b89d75018e00b6b1e8e6280030482353bc*",".{0,1000}744e50af5566fa5ab70d4db70d35b3b89d75018e00b6b1e8e6280030482353bc.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","29036"
"*745bdc69fd7d712f65419c126b3ab5524fb96a511a21fea2d2b261607b3b2c55*",".{0,1000}745bdc69fd7d712f65419c126b3ab5524fb96a511a21fea2d2b261607b3b2c55.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","29042"
"*746726f4bb20bc303db072b0496a69e91b409285bad1c5507d1969ef19d27380*",".{0,1000}746726f4bb20bc303db072b0496a69e91b409285bad1c5507d1969ef19d27380.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","0","#filehash","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","29045"
"*746c0a01b163c57f729738cfe39c1c83d0b938aa48f07d1f866c1b8adaec4aa0*",".{0,1000}746c0a01b163c57f729738cfe39c1c83d0b938aa48f07d1f866c1b8adaec4aa0.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","29046"
"*74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6*",".{0,1000}74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","#filehash","N/A","9","10","N/A","N/A","N/A","N/A","29047"
"*7498456870aa9d28a3ec5fd9bab4838bd4a0a35c2f41ac8da9116326337f8b7e*",".{0,1000}7498456870aa9d28a3ec5fd9bab4838bd4a0a35c2f41ac8da9116326337f8b7e.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","29052"
"*74a30d4ca766db4424a21073abf73dff319832d6af8db37a0ec45edae12d897d*",".{0,1000}74a30d4ca766db4424a21073abf73dff319832d6af8db37a0ec45edae12d897d.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","0","#filehash","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","29053"
"*74c63668a8b03c046dcb1293ccffd2e0f7b4dd22210a4faff3d29a0db5761d20*",".{0,1000}74c63668a8b03c046dcb1293ccffd2e0f7b4dd22210a4faff3d29a0db5761d20.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","29066"
"*75007cb1974bca92234e5e178b17a429922c54676bc446d032464e358d26510a*",".{0,1000}75007cb1974bca92234e5e178b17a429922c54676bc446d032464e358d26510a.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","29082"
"*75682eac28a36100019a0606879be2a615e6c221b212833b2eb9ab83f6360cd6*",".{0,1000}75682eac28a36100019a0606879be2a615e6c221b212833b2eb9ab83f6360cd6.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","0","#filehash","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","29107"
"*757c6b973f06e169ec2346c818f211559a084fd2adaed2e0e9e232541b62b557*",".{0,1000}757c6b973f06e169ec2346c818f211559a084fd2adaed2e0e9e232541b62b557.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#filehash","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","29108"
"*75f068e65a36c0dfcd7b59c00ab3a0e73f6bc07ca84091f472caada25e32cfcd*",".{0,1000}75f068e65a36c0dfcd7b59c00ab3a0e73f6bc07ca84091f472caada25e32cfcd.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","0","#filehash","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","29146"
"*760980ec830603bf3bee659f92e939d2af88eef7bc50c2911cce1a41d35d881d*",".{0,1000}760980ec830603bf3bee659f92e939d2af88eef7bc50c2911cce1a41d35d881d.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","29150"
"*76c7648f79cc5a78f49e9ca24b26a82348e0292b3676ae04bdf22a88cb7eeadc*",".{0,1000}76c7648f79cc5a78f49e9ca24b26a82348e0292b3676ae04bdf22a88cb7eeadc.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#filehash","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","29193"
"*76d64e0cf551962a2ba20813933207dd398d1d06383c27765874219642218eca*",".{0,1000}76d64e0cf551962a2ba20813933207dd398d1d06383c27765874219642218eca.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","29198"
"*76FFA92B-429B-4865-970D-4E7678AC34EA*",".{0,1000}76FFA92B\-429B\-4865\-970D\-4E7678AC34EA.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","0","#GUIDproject","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","29208"
"*776b64a95ccc334446805d680288c7ac35f1e938ee43115c1911f1c2fed27312*",".{0,1000}776b64a95ccc334446805d680288c7ac35f1e938ee43115c1911f1c2fed27312.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","29245"
"*77b681a78da38b33f408ccdc747438550186a348f670d2faaa05ef75f9337973*",".{0,1000}77b681a78da38b33f408ccdc747438550186a348f670d2faaa05ef75f9337973.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","29267"
"*77cfad99621ef6951ec4809a6641e2d7623238b66afa3f6e993703eeff161da6*",".{0,1000}77cfad99621ef6951ec4809a6641e2d7623238b66afa3f6e993703eeff161da6.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29273"
"*77cfad99621ef6951ec4809a6641e2d7623238b66afa3f6e993703eeff161da6*",".{0,1000}77cfad99621ef6951ec4809a6641e2d7623238b66afa3f6e993703eeff161da6.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29274"
"*77efc4024d86cf813ea6f93ef2b98dd4ff8bb8a46f0fd145465786690a27b169*",".{0,1000}77efc4024d86cf813ea6f93ef2b98dd4ff8bb8a46f0fd145465786690a27b169.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","#filehash","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","29283"
"*78177028fe6c048b40b90f696adfdcbcbda0a7c9f678125bbead5b4f116098fc*",".{0,1000}78177028fe6c048b40b90f696adfdcbcbda0a7c9f678125bbead5b4f116098fc.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","29294"
"*7876ba8fb2f4a1e4802f1f2c1030b9bc708f3981264fea33e261be7e05966169*",".{0,1000}7876ba8fb2f4a1e4802f1f2c1030b9bc708f3981264fea33e261be7e05966169.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","0","#filehash","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","29324"
"*78a924220cf74c45f237414aa61e73f066f175f0cc47649dc0668769941ed305*",".{0,1000}78a924220cf74c45f237414aa61e73f066f175f0cc47649dc0668769941ed305.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","0","#filehash","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","29335"
"*78b4ff5e1bbac4a8bde265705a5c6e36b41bb2a9170f8f060a09bb1552549af2*",".{0,1000}78b4ff5e1bbac4a8bde265705a5c6e36b41bb2a9170f8f060a09bb1552549af2.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","29339"
"*78DE9716-84E8-4469-A5AE-F3E43181C28B*",".{0,1000}78DE9716\-84E8\-4469\-A5AE\-F3E43181C28B.{0,1000}","offensive_tool_keyword","FormThief","Spoofing desktop login applications with WinForms and WPF","T1204.002 - T1056.004 - T1071.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/mlcsec/FormThief","1","0","#GUIDproject","N/A","8","2","173","31","2024-02-19T22:40:09Z","2024-02-19T22:34:07Z","29352"
"*78fa6d6f41b506791944c470b4cceb3af184a9c6fcaa804d706763cb9c29b52b*",".{0,1000}78fa6d6f41b506791944c470b4cceb3af184a9c6fcaa804d706763cb9c29b52b.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","29359"
"*7943C5FF-C219-4E0B-992E-0ECDEB2681F3*",".{0,1000}7943C5FF\-C219\-4E0B\-992E\-0ECDEB2681F3.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","#GUIDproject","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","29374"
"*7971e955309e5158aa13fe774596224af88ae64e53f09bd2ffb863acbf88864a*",".{0,1000}7971e955309e5158aa13fe774596224af88ae64e53f09bd2ffb863acbf88864a.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","29393"
"*79c1d4ab8f425095d2d9f2a18a0cab08d31b686b149fba3db24a13e2bc7299ee*",".{0,1000}79c1d4ab8f425095d2d9f2a18a0cab08d31b686b149fba3db24a13e2bc7299ee.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","29410"
"*79C9BBA3-A0EA-431C-866C-77004802D8A0*",".{0,1000}79C9BBA3\-A0EA\-431C\-866C\-77004802D8A0.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#GUIDproject","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","29413"
"*79ef2d4f2ad91311f14fc200acb71e78a47eb9a4f23e776649fb1b0b06c69dd2*",".{0,1000}79ef2d4f2ad91311f14fc200acb71e78a47eb9a4f23e776649fb1b0b06c69dd2.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","29421"
"*7a3a00796caebdd1e5d80cc330ea232e62fecefc264492892c3ff93f15c977a2*",".{0,1000}7a3a00796caebdd1e5d80cc330ea232e62fecefc264492892c3ff93f15c977a2.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29448"
"*7a3a00796caebdd1e5d80cc330ea232e62fecefc264492892c3ff93f15c977a2*",".{0,1000}7a3a00796caebdd1e5d80cc330ea232e62fecefc264492892c3ff93f15c977a2.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29449"
"*7A87DEAE-7B94-4986-9294-BD69B12A9732*",".{0,1000}7A87DEAE\-7B94\-4986\-9294\-BD69B12A9732.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#GUIDproject","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","29478"
"*7aa369f9365c35abe1cfea6a209a8a6071d7af3377a357f94721860c02e4d332*",".{0,1000}7aa369f9365c35abe1cfea6a209a8a6071d7af3377a357f94721860c02e4d332.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","0","#filehash","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","29489"
"*7accd179e8a6b2fc907e7e8d087c52a7f48084852724b03d25bebcada1acbca5*",".{0,1000}7accd179e8a6b2fc907e7e8d087c52a7f48084852724b03d25bebcada1acbca5.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29499"
"*7adf4cdaa2190d19969e9f2fe6315d586fd5b709466ef2c84379b8b3a595ffc8*",".{0,1000}7adf4cdaa2190d19969e9f2fe6315d586fd5b709466ef2c84379b8b3a595ffc8.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#filehash","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","29503"
"*7b2ce8fed0da2a756ac78ee68f0885399ee5fa57e6a182e3b8fbffc1c523710d*",".{0,1000}7b2ce8fed0da2a756ac78ee68f0885399ee5fa57e6a182e3b8fbffc1c523710d.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","29524"
"*7b41987489d49340783b4b6604899143c2c6c67f66708d80df217c509ff8b4dd*",".{0,1000}7b41987489d49340783b4b6604899143c2c6c67f66708d80df217c509ff8b4dd.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","29528"
"*7bc64714fb90bddef226c04fb69f30d689384e3f0dfb89934c73ad1486e76e3a*",".{0,1000}7bc64714fb90bddef226c04fb69f30d689384e3f0dfb89934c73ad1486e76e3a.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#filehash","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","29559"
"*7bcebf955c725d8d50ee161d523e06891dadb93fb98fc9fe74a1056c374c767c*",".{0,1000}7bcebf955c725d8d50ee161d523e06891dadb93fb98fc9fe74a1056c374c767c.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","29563"
"*7c6036ed3f0b67af1cc73941987fbe7884789264691d05604e8a5e8b3cd9b5a1*",".{0,1000}7c6036ed3f0b67af1cc73941987fbe7884789264691d05604e8a5e8b3cd9b5a1.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","29603"
"*7c9132c6c40c456396370d2e9cec4ee32b8cd289b29ccca946ea79f185eeaeed*",".{0,1000}7c9132c6c40c456396370d2e9cec4ee32b8cd289b29ccca946ea79f185eeaeed.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","29620"
"*7cabf5918c2f097e102d28085a8171e98832c150aa10ddbcd1d05e8030f184ef*",".{0,1000}7cabf5918c2f097e102d28085a8171e98832c150aa10ddbcd1d05e8030f184ef.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#filehash","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","29628"
"*7ce3b3c16cdaa2dfae51fbcf163ac75947127a9fd5e2d3c588480e3629345e8f*",".{0,1000}7ce3b3c16cdaa2dfae51fbcf163ac75947127a9fd5e2d3c588480e3629345e8f.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#filehash","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","29647"
"*7d2dfbf053a420ad3857171642cbec5738196a0ead931f93737d16e14b7faec4*",".{0,1000}7d2dfbf053a420ad3857171642cbec5738196a0ead931f93737d16e14b7faec4.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","29665"
"*7da421d00cd50570a79a82803c170d043fa3b2253ae2f0697e103072c34d39f1*",".{0,1000}7da421d00cd50570a79a82803c170d043fa3b2253ae2f0697e103072c34d39f1.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","29696"
"*7da54ac68e35d2604980ef414a6ec8b696bf6ec5df2b32ad7596bee48db883c6*",".{0,1000}7da54ac68e35d2604980ef414a6ec8b696bf6ec5df2b32ad7596bee48db883c6.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","29697"
"*7e158727df39c819d0b51228683ec4d1f1e9a949da480d6852445fa968814f46*",".{0,1000}7e158727df39c819d0b51228683ec4d1f1e9a949da480d6852445fa968814f46.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","0","#filehash #linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","29724"
"*7E47D586-DDC6-4382-848C-5CF0798084E1*",".{0,1000}7E47D586\-DDC6\-4382\-848C\-5CF0798084E1.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#GUIDproject","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","29745"
"*7eb2d2b7d0eaf25f822afa65e9887683ad2c1dd48c2cc447a76a6526222acf06*",".{0,1000}7eb2d2b7d0eaf25f822afa65e9887683ad2c1dd48c2cc447a76a6526222acf06.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","29773"
"*7ec9b36feeace5d4903be2adb2e1454af948a393c311b5513bfad0e9995b87e7*",".{0,1000}7ec9b36feeace5d4903be2adb2e1454af948a393c311b5513bfad0e9995b87e7.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","0","#filehash","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","29782"
"*7ef6a655e0c09263822565e5022ff3bd33494f1bedc2062862f769ebd2c93897*",".{0,1000}7ef6a655e0c09263822565e5022ff3bd33494f1bedc2062862f769ebd2c93897.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","29790"
"*7f005c1ea9c2021b5db5807fdf9e8e9f502b28f089ff17dc85b7d480a3e3d143*",".{0,1000}7f005c1ea9c2021b5db5807fdf9e8e9f502b28f089ff17dc85b7d480a3e3d143.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","#filehash","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","29794"
"*7f5ac429cd84d6ac935855b8a7656b830a6eefa1884f7fddd8c7c893c6b09ca4*",".{0,1000}7f5ac429cd84d6ac935855b8a7656b830a6eefa1884f7fddd8c7c893c6b09ca4.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","#filehash","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","29820"
"*7f73a800a012c6b522a92074901c256d947a7a080bc2efb3da65784b2f50a054*",".{0,1000}7f73a800a012c6b522a92074901c256d947a7a080bc2efb3da65784b2f50a054.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","29826"
"*7fe5b73ee8105622ab74be4fae9f5f0a9b2a8b496770d84b58a7c0ce8a457551*",".{0,1000}7fe5b73ee8105622ab74be4fae9f5f0a9b2a8b496770d84b58a7c0ce8a457551.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","29854"
"*7fef9543926764b6093a5ab10ea9d092f9a97acae14dbfd423a7c52cc9454fdb*",".{0,1000}7fef9543926764b6093a5ab10ea9d092f9a97acae14dbfd423a7c52cc9454fdb.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#filehash","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","29855"
"*7ffce7f6d7262f214d78e6b7fd8d07119835cba4b04ce334260665d7c8fb369a*",".{0,1000}7ffce7f6d7262f214d78e6b7fd8d07119835cba4b04ce334260665d7c8fb369a.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","#filehash","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","29861"
"*7z2john.pl*",".{0,1000}7z2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","29867"
"*80086e7ab0990319d4f61b69990eda05ff16dcd836c3b489b2bf8a189bc0c08e*",".{0,1000}80086e7ab0990319d4f61b69990eda05ff16dcd836c3b489b2bf8a189bc0c08e.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","29873"
"*8019f095c7cf482767df31cd411cc53c4e30a23c599aa9381391326a6e7c6304*",".{0,1000}8019f095c7cf482767df31cd411cc53c4e30a23c599aa9381391326a6e7c6304.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","29881"
"*802a7ba4f023cd272eba8de0488848a7667ac0eeb3844108bdca994491846404*",".{0,1000}802a7ba4f023cd272eba8de0488848a7667ac0eeb3844108bdca994491846404.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","0","#filehash","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","29891"
"*803c76c8edc3cb686137d642d75fcedd54b89461c719504f2e5f8a3235c3f7c3*",".{0,1000}803c76c8edc3cb686137d642d75fcedd54b89461c719504f2e5f8a3235c3f7c3.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","#filehash","N/A","8","1","N/A","N/A","N/A","N/A","29896"
"*806ffe052652b8848d19fe26c63ecc35742077d87bbe04102b048a7c9c644c22*",".{0,1000}806ffe052652b8848d19fe26c63ecc35742077d87bbe04102b048a7c9c644c22.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#filehash","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","29909"
"*80a9520b464f4bd7b4747c897a66a3c41a9100cb9efcd94614e2bd053247285a*",".{0,1000}80a9520b464f4bd7b4747c897a66a3c41a9100cb9efcd94614e2bd053247285a.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","29926"
"*80BA63A4-7D41-40E9-A722-6DD58B28BF7E*",".{0,1000}80BA63A4\-7D41\-40E9\-A722\-6DD58B28BF7E.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#GUIDproject","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","29934"
"*80ed17895205205c5a769d18715cb74a623cee6a5379bb8142d2c8c533c759b2*",".{0,1000}80ed17895205205c5a769d18715cb74a623cee6a5379bb8142d2c8c533c759b2.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","#filehash","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","29946"
"*81027e82ed224ca43c939b8df5f99bf13e9d2191b177ae4d339075930ab2bb5b*",".{0,1000}81027e82ed224ca43c939b8df5f99bf13e9d2191b177ae4d339075930ab2bb5b.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29952"
"*81027e82ed224ca43c939b8df5f99bf13e9d2191b177ae4d339075930ab2bb5b*",".{0,1000}81027e82ed224ca43c939b8df5f99bf13e9d2191b177ae4d339075930ab2bb5b.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29953"
"*814708C9-2320-42D2-A45F-31E42DA06A94*",".{0,1000}814708C9\-2320\-42D2\-A45F\-31E42DA06A94.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","#GUIDproject","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","29971"
"*816d7616238958dfe0bb811a063eb3102efd82eff14408f5cab4cb5258bfd019*",".{0,1000}816d7616238958dfe0bb811a063eb3102efd82eff14408f5cab4cb5258bfd019.{0,1000}","offensive_tool_keyword","VNCPassView","recover the passwords stored by the VNC tool","T1003 - T1555 - T1081","TA0006 - TA0007","N/A","GoGoogle - 8BASE","Credential Access","https://www.nirsoft.net/utils/vnc_password.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","29983"
"*8173d4d17cb728e6f2c5e2ce8124ce7eb0f459dc62085bcaab786abf1f6b37a7*",".{0,1000}8173d4d17cb728e6f2c5e2ce8124ce7eb0f459dc62085bcaab786abf1f6b37a7.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","0","#filehash","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","29984"
"*81a235c1c9cdb34c44f468239bd06a590a54cc4fcd624c676200097b45d55165*",".{0,1000}81a235c1c9cdb34c44f468239bd06a590a54cc4fcd624c676200097b45d55165.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29995"
"*81a235c1c9cdb34c44f468239bd06a590a54cc4fcd624c676200097b45d55165*",".{0,1000}81a235c1c9cdb34c44f468239bd06a590a54cc4fcd624c676200097b45d55165.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","29996"
"*81e1e9186bb461b669b4bbd4dab4534c980e6d2bc27975e6ec7305bc935cf429*",".{0,1000}81e1e9186bb461b669b4bbd4dab4534c980e6d2bc27975e6ec7305bc935cf429.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#filehash","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","30011"
"*82e7270fab0c067f74ca4c8c8d0228ad49cb16149ea036ff6ec4a4fa62088c76*",".{0,1000}82e7270fab0c067f74ca4c8c8d0228ad49cb16149ea036ff6ec4a4fa62088c76.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30082"
"*82e7270fab0c067f74ca4c8c8d0228ad49cb16149ea036ff6ec4a4fa62088c76*",".{0,1000}82e7270fab0c067f74ca4c8c8d0228ad49cb16149ea036ff6ec4a4fa62088c76.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30083"
"*82F417BE-49BF-44FF-9BBD-64FECEA181D7*",".{0,1000}82F417BE\-49BF\-44FF\-9BBD\-64FECEA181D7.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","#GUIDproject","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","30089"
"*8347E81B-89FC-42A9-B22C-F59A6A572DEC*",".{0,1000}8347E81B\-89FC\-42A9\-B22C\-F59A6A572DEC.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","0","#GUIDproject","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","30114"
"*8347E81B-89FC-42A9-B22C-F59A6A572DEC*",".{0,1000}8347E81B\-89FC\-42A9\-B22C\-F59A6A572DEC.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","0","#GUIDproject","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","30115"
"*83536b1df51e5954c757179b70419fe5567df58f3ed029998e6ca82f7c0a15a7*",".{0,1000}83536b1df51e5954c757179b70419fe5567df58f3ed029998e6ca82f7c0a15a7.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","30117"
"*837f6333561b575fc379d692f6f197a375feabb6c942170e262d36ef21709325*",".{0,1000}837f6333561b575fc379d692f6f197a375feabb6c942170e262d36ef21709325.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#filehash","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","30127"
"*83803142d36f4e09346394ae2038353977bd16389fd80e09dc7fc1e8850e1365*",".{0,1000}83803142d36f4e09346394ae2038353977bd16389fd80e09dc7fc1e8850e1365.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","#filehash","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","30128"
"*83b65d33d21b01395de5b5537e36f18eb8f16237a64f3a8f17991dc652d1a61a*",".{0,1000}83b65d33d21b01395de5b5537e36f18eb8f16237a64f3a8f17991dc652d1a61a.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","#filehash","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","30139"
"*83b65d33d21b01395de5b5537e36f18eb8f16237a64f3a8f17991dc652d1a61a*",".{0,1000}83b65d33d21b01395de5b5537e36f18eb8f16237a64f3a8f17991dc652d1a61a.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","#filehash","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","30140"
"*83dd7c7738c5409a2f50d06f38eb82be09a232794771c87d81080220e6ab5195*",".{0,1000}83dd7c7738c5409a2f50d06f38eb82be09a232794771c87d81080220e6ab5195.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30149"
"*83DF0D0B-8FC6-4BCA-9982-4D26523515A2*",".{0,1000}83DF0D0B\-8FC6\-4BCA\-9982\-4D26523515A2.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","#GUIDproject","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","30150"
"*8484a8848d429d954636f8c6c170bdd73d96288325b902eb43c3403f0650b5e6*",".{0,1000}8484a8848d429d954636f8c6c170bdd73d96288325b902eb43c3403f0650b5e6.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","30195"
"*84A7E50E-B0F0-4B3D-98CD-F32CDB1EB8CA*",".{0,1000}84A7E50E\-B0F0\-4B3D\-98CD\-F32CDB1EB8CA.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","#GUIDproject","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","30202"
"*84d6bf44ebad6338855d9e4abafaed229c778a645c18e1bd5a343bf930c75110*",".{0,1000}84d6bf44ebad6338855d9e4abafaed229c778a645c18e1bd5a343bf930c75110.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30216"
"*853d769d63efcbc5d78f3f81c7cae176bf34c248d3bbbf6f32b4bc5d5de561e8*",".{0,1000}853d769d63efcbc5d78f3f81c7cae176bf34c248d3bbbf6f32b4bc5d5de561e8.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","30246"
"*8560ec462441496a3bd6b0266ed1b023cdb1870a190aaa9dbb34ffcc6e6dd281*",".{0,1000}8560ec462441496a3bd6b0266ed1b023cdb1870a190aaa9dbb34ffcc6e6dd281.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","30255"
"*85929c3b220867064975eb8a6ca57cd5b22b801e3f805e653f298f3e6cebe6a3*",".{0,1000}85929c3b220867064975eb8a6ca57cd5b22b801e3f805e653f298f3e6cebe6a3.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30267"
"*85ef86a80dfd91208cf5eaaafd220a584c591ed83c22ee039b31b9849d7428d0*",".{0,1000}85ef86a80dfd91208cf5eaaafd220a584c591ed83c22ee039b31b9849d7428d0.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","30285"
"*862f7ba58bbf77543812637ecc32d277fce062d21bc97587e5816e8fb05634e3*",".{0,1000}862f7ba58bbf77543812637ecc32d277fce062d21bc97587e5816e8fb05634e3.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#filehash","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","30294"
"*863e5c3db9d52c8af4ad2976dbfe510a8eaaec2affba50a5abd916e440e18804*",".{0,1000}863e5c3db9d52c8af4ad2976dbfe510a8eaaec2affba50a5abd916e440e18804.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","30295"
"*863f8f71cce6acffa596561047c4592087b08a66438bd5500a4053169f31a9ce*",".{0,1000}863f8f71cce6acffa596561047c4592087b08a66438bd5500a4053169f31a9ce.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30296"
"*8648dfc2aff4508e8469d1ed4a7a775b558527bfb0050ba4ed75db259b07943d*",".{0,1000}8648dfc2aff4508e8469d1ed4a7a775b558527bfb0050ba4ed75db259b07943d.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","#filehash","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","30300"
"*86FF6D04-208C-442F-B27C-E4255DD39402*",".{0,1000}86FF6D04\-208C\-442F\-B27C\-E4255DD39402.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz GUID project","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#GUIDproject","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30348"
"*8714f9c15c56b5a6aebb5e90fe59a2f952df8f0759d776e851a1064f159e89a0*",".{0,1000}8714f9c15c56b5a6aebb5e90fe59a2f952df8f0759d776e851a1064f159e89a0.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#filehash","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","30356"
"*87582936adeabd882de92613193a3fefdc2d388238a7c67c3bb41666ac3b2dda*",".{0,1000}87582936adeabd882de92613193a3fefdc2d388238a7c67c3bb41666ac3b2dda.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","30373"
"*87623bf79b1d7bbd0e66a6e6c5e534afdef66debdd5ff363648cb5482e7a6ed7*",".{0,1000}87623bf79b1d7bbd0e66a6e6c5e534afdef66debdd5ff363648cb5482e7a6ed7.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30379"
"*8793997d31b23280ec1a46ff7fd065a6510ea66fcbf12651583244805e958212*",".{0,1000}8793997d31b23280ec1a46ff7fd065a6510ea66fcbf12651583244805e958212.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","#filehash","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","30396"
"*87beb1086bd0d4b1a6e66fa634eadcbf379c7fae17967f61b8cf97fad6bb4887*",".{0,1000}87beb1086bd0d4b1a6e66fa634eadcbf379c7fae17967f61b8cf97fad6bb4887.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","#filehash","N/A","10","","N/A","","","","30408"
"*887e0ff0707e46e7f309f6e12eaddd4161b6b3aa88a705857ac55590cdc4c64a*",".{0,1000}887e0ff0707e46e7f309f6e12eaddd4161b6b3aa88a705857ac55590cdc4c64a.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","0","#filehash","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","30467"
"*88888dcb2ac77d09b3c68c26f025f1e1ba9db667f3950a79a110896de297e162*",".{0,1000}88888dcb2ac77d09b3c68c26f025f1e1ba9db667f3950a79a110896de297e162.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","0","#filehash","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","30472"
"*889a7d961d4e847d37d3019ccd1625a335d2e2d18c6fb1ec1d41aa4df679f553*",".{0,1000}889a7d961d4e847d37d3019ccd1625a335d2e2d18c6fb1ec1d41aa4df679f553.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30478"
"*88dc61a50afafe0e0ffff60913d45f2abe2a298c2c8a067fc7044e7251eb9012*",".{0,1000}88dc61a50afafe0e0ffff60913d45f2abe2a298c2c8a067fc7044e7251eb9012.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#filehash","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","30491"
"*8909f956ab41ad565935485870d05b47db8482c703aa7ea142ef1eff310e8b89*",".{0,1000}8909f956ab41ad565935485870d05b47db8482c703aa7ea142ef1eff310e8b89.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30505"
"*8943acdb8de2a40ca4fd8e1a2f98029aa6e8d78c9f19430b6ac557b6fb8ce4cb*",".{0,1000}8943acdb8de2a40ca4fd8e1a2f98029aa6e8d78c9f19430b6ac557b6fb8ce4cb.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","30521"
"*8943acdb8de2a40ca4fd8e1a2f98029aa6e8d78c9f19430b6ac557b6fb8ce4cb*",".{0,1000}8943acdb8de2a40ca4fd8e1a2f98029aa6e8d78c9f19430b6ac557b6fb8ce4cb.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","30522"
"*896106aa70f9ffdb5b219cbc1abcbdcff59bf05a339dcf9a2b9e095160f59e98*",".{0,1000}896106aa70f9ffdb5b219cbc1abcbdcff59bf05a339dcf9a2b9e095160f59e98.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","#filehash","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","30529"
"*89e27312c55e98af1c2f4882a53b08abc4a54fc8d6c09959447f2444b3ccece1*",".{0,1000}89e27312c55e98af1c2f4882a53b08abc4a54fc8d6c09959447f2444b3ccece1.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30562"
"*8a24643b1ae79babbba0995d870bf0992cfc9acfef6459727c603ef5b61c261f*",".{0,1000}8a24643b1ae79babbba0995d870bf0992cfc9acfef6459727c603ef5b61c261f.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","30586"
"*8a274c53950fe680f5b5eb76594aa0b30facdf93187277d03653334a5224f6a0*",".{0,1000}8a274c53950fe680f5b5eb76594aa0b30facdf93187277d03653334a5224f6a0.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30587"
"*8a3bfd492f149d5c83675dd30e6ad94160534c980665609d6142f246552ac684*",".{0,1000}8a3bfd492f149d5c83675dd30e6ad94160534c980665609d6142f246552ac684.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","30596"
"*8ac384fed6ad25cb08874eb3dc9b45c80084fa5518ec5a7fa79e3f5d5e40b66e*",".{0,1000}8ac384fed6ad25cb08874eb3dc9b45c80084fa5518ec5a7fa79e3f5d5e40b66e.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","30624"
"*8aec1bef3b7e7e8d8adcf79bdc1d0efcd6eaa94c2fa22e42dd1b21ecc49333cd*",".{0,1000}8aec1bef3b7e7e8d8adcf79bdc1d0efcd6eaa94c2fa22e42dd1b21ecc49333cd.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30634"
"*8aec1bef3b7e7e8d8adcf79bdc1d0efcd6eaa94c2fa22e42dd1b21ecc49333cd*",".{0,1000}8aec1bef3b7e7e8d8adcf79bdc1d0efcd6eaa94c2fa22e42dd1b21ecc49333cd.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30635"
"*8aec1bef3b7e7e8d8adcf79bdc1d0efcd6eaa94c2fa22e42dd1b21ecc49333cd*",".{0,1000}8aec1bef3b7e7e8d8adcf79bdc1d0efcd6eaa94c2fa22e42dd1b21ecc49333cd.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30636"
"*8aec1bef3b7e7e8d8adcf79bdc1d0efcd6eaa94c2fa22e42dd1b21ecc49333cd*",".{0,1000}8aec1bef3b7e7e8d8adcf79bdc1d0efcd6eaa94c2fa22e42dd1b21ecc49333cd.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30637"
"*8b081e47fc6d4ab5dc0483dcc7243ff66911b9e660ab8ad9296a7144e95dbd47*",".{0,1000}8b081e47fc6d4ab5dc0483dcc7243ff66911b9e660ab8ad9296a7144e95dbd47.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","30647"
"*8b27ef8f7cbae47922e672618e39abe7fa626c7405a67b12d7a88c1da8b06cad*",".{0,1000}8b27ef8f7cbae47922e672618e39abe7fa626c7405a67b12d7a88c1da8b06cad.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","0","#filehash","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","30655"
"*8b43f966bd55fe366e37e1974cdbe61cb01618c4df5298df928de0e2599b6050*",".{0,1000}8b43f966bd55fe366e37e1974cdbe61cb01618c4df5298df928de0e2599b6050.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30665"
"*8b53f3b214e31f24b635bc45651cf7004da4718cb0b8c844d27836153711da3d*",".{0,1000}8b53f3b214e31f24b635bc45651cf7004da4718cb0b8c844d27836153711da3d.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","30672"
"*8b5b0e03d4d5becb309f86a7149dd0573f89c19bcd4f8becb7d86b17c90a6c04*",".{0,1000}8b5b0e03d4d5becb309f86a7149dd0573f89c19bcd4f8becb7d86b17c90a6c04.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","30674"
"*8b86dff9da37df4824039ae6da4e3ad9b27b2c25805990ede69b2e036dc30996*",".{0,1000}8b86dff9da37df4824039ae6da4e3ad9b27b2c25805990ede69b2e036dc30996.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","0","#filehash","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","30682"
"*8bb972b4dc7e0c5b8db0be349ecf62043e69ea1273d5298f8e55c02fa047712c*",".{0,1000}8bb972b4dc7e0c5b8db0be349ecf62043e69ea1273d5298f8e55c02fa047712c.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#filehash","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","30697"
"*8bc52fc1dbd2e9319241d826b23a227132199b37951c8222c901b6ab069c4084*",".{0,1000}8bc52fc1dbd2e9319241d826b23a227132199b37951c8222c901b6ab069c4084.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","30703"
"*8c18fe10b673b128e86bb6f1b6dd34eae23c4428ec66e8496d94fd04cfc17784*",".{0,1000}8c18fe10b673b128e86bb6f1b6dd34eae23c4428ec66e8496d94fd04cfc17784.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30728"
"*8c18fe10b673b128e86bb6f1b6dd34eae23c4428ec66e8496d94fd04cfc17784*",".{0,1000}8c18fe10b673b128e86bb6f1b6dd34eae23c4428ec66e8496d94fd04cfc17784.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30729"
"*8c1e9d935d60c007bd43d10b206cd229c851b654562e6bb93ce009481d827afb*",".{0,1000}8c1e9d935d60c007bd43d10b206cd229c851b654562e6bb93ce009481d827afb.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30733"
"*8c6291f935445adc486c03da6169b471fc2436d5b594972b14eaeb37350aa3ef*",".{0,1000}8c6291f935445adc486c03da6169b471fc2436d5b594972b14eaeb37350aa3ef.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30754"
"*8c97b09ebb432e60c9aef665c6db2be79a6439f1c59f683f36568f0bddda0c38*",".{0,1000}8c97b09ebb432e60c9aef665c6db2be79a6439f1c59f683f36568f0bddda0c38.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30773"
"*8c97b09ebb432e60c9aef665c6db2be79a6439f1c59f683f36568f0bddda0c38*",".{0,1000}8c97b09ebb432e60c9aef665c6db2be79a6439f1c59f683f36568f0bddda0c38.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30774"
"*8e068fd6cafac177fcf10e61a2672c0e572180bc20270e47e55525ad027d729d*",".{0,1000}8e068fd6cafac177fcf10e61a2672c0e572180bc20270e47e55525ad027d729d.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","30870"
"*8e0a61ae75c32370711ca475269fb91dfeb09534a1da08a4f3f1e71c13c1eaa9*",".{0,1000}8e0a61ae75c32370711ca475269fb91dfeb09534a1da08a4f3f1e71c13c1eaa9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","30871"
"*8e4b218bdbd8e098fff749fe5e5bbf00275d21f398b34216a573224e192094b8*",".{0,1000}8e4b218bdbd8e098fff749fe5e5bbf00275d21f398b34216a573224e192094b8.{0,1000}","offensive_tool_keyword","OperaPassView","OperaPassView is a small password recovery tool that decrypts the content of the Opera Web browser password file (wand.dat) and displays the list of all Web site passwords stored in this file","T1003 - T1555 - T1145","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/opera_password_recovery.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","30899"
"*8ebbf29735fb137a1de8df693e7762685ecf873e5b83fc927cd561e170c275bd*",".{0,1000}8ebbf29735fb137a1de8df693e7762685ecf873e5b83fc927cd561e170c275bd.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","30927"
"*8ef62495d042ae030268ca52d01baece60c79f34d49a113ef5c2322e7041c053*",".{0,1000}8ef62495d042ae030268ca52d01baece60c79f34d49a113ef5c2322e7041c053.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#filehash","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","30940"
"*8f0c9eaabea10640a0e534b55d46c1d61aa92bb370d4696fb9e7b3c8bb965d8d*",".{0,1000}8f0c9eaabea10640a0e534b55d46c1d61aa92bb370d4696fb9e7b3c8bb965d8d.{0,1000}","offensive_tool_keyword","Dispossessor","Bruteforce tools used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","30951"
"*90229D7D-5CC2-4C1E-80D3-4B7C7289B480*",".{0,1000}90229D7D\-5CC2\-4C1E\-80D3\-4B7C7289B480.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#GUIDproject","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","31014"
"*90c6e84dbeb83eef349d9ac17b1e005c12f42d74cea94a6c0f16a999792ac3f9*",".{0,1000}90c6e84dbeb83eef349d9ac17b1e005c12f42d74cea94a6c0f16a999792ac3f9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31064"
"*90c6e84dbeb83eef349d9ac17b1e005c12f42d74cea94a6c0f16a999792ac3f9*",".{0,1000}90c6e84dbeb83eef349d9ac17b1e005c12f42d74cea94a6c0f16a999792ac3f9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31065"
"*90e767d5fd29fc406847b5ac6151a713643596625209245d3440fd8908ff7427*",".{0,1000}90e767d5fd29fc406847b5ac6151a713643596625209245d3440fd8908ff7427.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","31075"
"*912018ab3c6b16b39ee84f17745ff0c80a33cee241013ec35d0281e40c0658d9*",".{0,1000}912018ab3c6b16b39ee84f17745ff0c80a33cee241013ec35d0281e40c0658d9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31091"
"*912018ab3c6b16b39ee84f17745ff0c80a33cee241013ec35d0281e40c0658d9*",".{0,1000}912018ab3c6b16b39ee84f17745ff0c80a33cee241013ec35d0281e40c0658d9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31092"
"*9120da326f6d13c492ca42da217b25a24515ca0d2f468acde8ddb5d5417c6652*",".{0,1000}9120da326f6d13c492ca42da217b25a24515ca0d2f468acde8ddb5d5417c6652.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","31093"
"*91292bac-72b4-4aab-9e5f-2bc1843c8ea3*",".{0,1000}91292bac\-72b4\-4aab\-9e5f\-2bc1843c8ea3.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","#GUIDproject","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","31096"
"*912ddcb057ae0b41311be77a00ad2952ab1521c12fc712284a4fbfb58f1105be*",".{0,1000}912ddcb057ae0b41311be77a00ad2952ab1521c12fc712284a4fbfb58f1105be.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31098"
"*91502e94bd83b8803e91d20d1b231c112d65561f588b92e888982f7753374e8d*",".{0,1000}91502e94bd83b8803e91d20d1b231c112d65561f588b92e888982f7753374e8d.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#filehash","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","31111"
"*91ee16300f9af0ed8c9de365bcb3eeb8e1cf0d7b8b75ce8866ccaf8433fef75a*",".{0,1000}91ee16300f9af0ed8c9de365bcb3eeb8e1cf0d7b8b75ce8866ccaf8433fef75a.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","0","#filehash","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","31151"
"*920B8C5B-0DC5-4BD7-B6BB-D14B39BFC9FE*",".{0,1000}920B8C5B\-0DC5\-4BD7\-B6BB\-D14B39BFC9FE.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","0","#GUIDproject","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","31155"
"*921157808497e5fe57f27fdb490be391f0f28bacffdb8cb9ed233bc3929b85a3*",".{0,1000}921157808497e5fe57f27fdb490be391f0f28bacffdb8cb9ed233bc3929b85a3.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","31161"
"*921BB3E1-15EE-4bbe-83D4-C4CE176A481B*",".{0,1000}921BB3E1\-15EE\-4bbe\-83D4\-C4CE176A481B.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz UUID","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#GUIDproject","uuid","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31162"
"*923195967668d70c92c62877cb79a93afecc4eb5144ce6609503123617d55bf3*",".{0,1000}923195967668d70c92c62877cb79a93afecc4eb5144ce6609503123617d55bf3.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31171"
"*92d262037522935fde4039ff17bdc6648c294519417e605477d78a9f0e84f20a*",".{0,1000}92d262037522935fde4039ff17bdc6648c294519417e605477d78a9f0e84f20a.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","31223"
"*9306e6c0e310b8146db022c3387eb9bb6076a13fb73e45ae98927b3dfb43872b*",".{0,1000}9306e6c0e310b8146db022c3387eb9bb6076a13fb73e45ae98927b3dfb43872b.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","31239"
"*933f98396260d2400250b8bd4897ab13bf4399fa276fa1e20391a446da68b4cc*",".{0,1000}933f98396260d2400250b8bd4897ab13bf4399fa276fa1e20391a446da68b4cc.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#filehash","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","31252"
"*935D33C5-62F1-40FE-8DB0-46B6E01342FB*",".{0,1000}935D33C5\-62F1\-40FE\-8DB0\-46B6E01342FB.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#GUIDproject","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","31260"
"*938e42fe50266db91748e07d22a54e73c9d5d25d81b5d50e475f3fc6e09d1cb1*",".{0,1000}938e42fe50266db91748e07d22a54e73c9d5d25d81b5d50e475f3fc6e09d1cb1.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","0","#filehash","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","31271"
"*93ade5b0b20ac4c950f3610f96c9f76a8cab972e793ed6364a2f2276965690f8*",".{0,1000}93ade5b0b20ac4c950f3610f96c9f76a8cab972e793ed6364a2f2276965690f8.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","31276"
"*93ba29924f9e4124a73302d5ec2da5f7891922d9420cb0ca8649b6e7a9e59894*",".{0,1000}93ba29924f9e4124a73302d5ec2da5f7891922d9420cb0ca8649b6e7a9e59894.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31280"
"*93ba29924f9e4124a73302d5ec2da5f7891922d9420cb0ca8649b6e7a9e59894*",".{0,1000}93ba29924f9e4124a73302d5ec2da5f7891922d9420cb0ca8649b6e7a9e59894.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31281"
"*93d8276129ccc984a4063772029e8db9002dfd82028c24864b5767cd6c7ce17d*",".{0,1000}93d8276129ccc984a4063772029e8db9002dfd82028c24864b5767cd6c7ce17d.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","31289"
"*941e4b332bf0cbb3573b3936b114a41f1d416bb96ba13c333f6269074a8ae7f6*",".{0,1000}941e4b332bf0cbb3573b3936b114a41f1d416bb96ba13c333f6269074a8ae7f6.{0,1000}","offensive_tool_keyword","OperaPassView","OperaPassView is a small password recovery tool that decrypts the content of the Opera Web browser password file (wand.dat) and displays the list of all Web site passwords stored in this file","T1003 - T1555 - T1145","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/opera_password_recovery.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","31306"
"*94795fd89366e01bd6ce6471ff27c3782e2e16377a848426cf0b2e6baee9449b*",".{0,1000}94795fd89366e01bd6ce6471ff27c3782e2e16377a848426cf0b2e6baee9449b.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31325"
"*94795fd89366e01bd6ce6471ff27c3782e2e16377a848426cf0b2e6baee9449b*",".{0,1000}94795fd89366e01bd6ce6471ff27c3782e2e16377a848426cf0b2e6baee9449b.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31326"
"*94cae63dcbabb71c5dd43f55fd09caeffdcd7628a02a112fb3cba36698ef72bc*",".{0,1000}94cae63dcbabb71c5dd43f55fd09caeffdcd7628a02a112fb3cba36698ef72bc.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","31348"
"*94ebb5f2aef9398a08a40e352a09bf6f83e01c0a666e3adb017636af3e0bee12*",".{0,1000}94ebb5f2aef9398a08a40e352a09bf6f83e01c0a666e3adb017636af3e0bee12.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","31359"
"*952c94381c139e9d0b212d7f854ad261827e6694eac3e17b2c606ff9f54a7e91*",".{0,1000}952c94381c139e9d0b212d7f854ad261827e6694eac3e17b2c606ff9f54a7e91.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","#filehash","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","31381"
"*95A40D7C-F3F7-4C45-8C5A-D384DE50B6C9*",".{0,1000}95A40D7C\-F3F7\-4C45\-8C5A\-D384DE50B6C9.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","0","#GUIDproject","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","31417"
"*95f9539c17bfa24ee0d7206b1fb2b195885b94e82d6bd7276bfccf2f0ceb9ac4*",".{0,1000}95f9539c17bfa24ee0d7206b1fb2b195885b94e82d6bd7276bfccf2f0ceb9ac4.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","0","#filehash","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","31444"
"*960ad2b1c19c9d10ecd0c64f6aee01d77564ac9e48b76247a217b637c1a6d482*",".{0,1000}960ad2b1c19c9d10ecd0c64f6aee01d77564ac9e48b76247a217b637c1a6d482.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","#filehash","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","31448"
"*96632f716df30af567da00d3624e245d162d0a05ac4b4e7cbadf63f04ca8d3da*",".{0,1000}96632f716df30af567da00d3624e245d162d0a05ac4b4e7cbadf63f04ca8d3da.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31464"
"*96632f716df30af567da00d3624e245d162d0a05ac4b4e7cbadf63f04ca8d3da*",".{0,1000}96632f716df30af567da00d3624e245d162d0a05ac4b4e7cbadf63f04ca8d3da.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31465"
"*96920d601c95d13be934e071544eda074e9b36329e0b53735214519434aa41a0*",".{0,1000}96920d601c95d13be934e071544eda074e9b36329e0b53735214519434aa41a0.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#filehash","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","31478"
"*96a355ad3176a2753b403b71f5e39c36dfb0489b621822f7da459519ed6bc4be*",".{0,1000}96a355ad3176a2753b403b71f5e39c36dfb0489b621822f7da459519ed6bc4be.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","31484"
"*96cff9ea19fa5ef9e119e9b00f67d9744efa55bd15df77248201ac09050d8322*",".{0,1000}96cff9ea19fa5ef9e119e9b00f67d9744efa55bd15df77248201ac09050d8322.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","31496"
"*970c07b17ca0d662ea2c5b0958efcf8e28053ee8d2a2c78436cce460413933b1*",".{0,1000}970c07b17ca0d662ea2c5b0958efcf8e28053ee8d2a2c78436cce460413933b1.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","31509"
"*97484211-4726-4129-86AA-AE01D17690BE*",".{0,1000}97484211\-4726\-4129\-86AA\-AE01D17690BE.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","#GUIDProject","N/A","8","1","N/A","N/A","N/A","N/A","31521"
"*97699449246070bc8195e1cf1f14b94dc2ee429cb03128bb7e7e254981eb71a0*",".{0,1000}97699449246070bc8195e1cf1f14b94dc2ee429cb03128bb7e7e254981eb71a0.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","31531"
"*97b39ac28794a7610ed83ad65e28c605397ea7be878109c35228c126d43e2f46*",".{0,1000}97b39ac28794a7610ed83ad65e28c605397ea7be878109c35228c126d43e2f46.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#filehash","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","31540"
"*981d1e5d88087f716ebb0cf8b39ffe7d3e44c36bc1e34452c8eaf2eaa56c05f9*",".{0,1000}981d1e5d88087f716ebb0cf8b39ffe7d3e44c36bc1e34452c8eaf2eaa56c05f9.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","#filehash","N/A","8","1","N/A","N/A","N/A","N/A","31565"
"*9842380cb6f04a1ba1d6d161b14999037cd66f7bbde2bd55bf89835e20a5cdae*",".{0,1000}9842380cb6f04a1ba1d6d161b14999037cd66f7bbde2bd55bf89835e20a5cdae.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31575"
"*9842380cb6f04a1ba1d6d161b14999037cd66f7bbde2bd55bf89835e20a5cdae*",".{0,1000}9842380cb6f04a1ba1d6d161b14999037cd66f7bbde2bd55bf89835e20a5cdae.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31576"
"*985ac7064c18852f34f9243d5d51703fca8e5540efe1d01a259640b5798c2724*",".{0,1000}985ac7064c18852f34f9243d5d51703fca8e5540efe1d01a259640b5798c2724.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","31584"
"*989cb6a23ecba5fb7785a1e23b61b84c12ff45723eb98bb885905768e0a9550a*",".{0,1000}989cb6a23ecba5fb7785a1e23b61b84c12ff45723eb98bb885905768e0a9550a.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","0","#filehash","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","31606"
"*98ad711010195669ee57216b2b376e81fec7437ceab10ab369fee7598d931a1a*",".{0,1000}98ad711010195669ee57216b2b376e81fec7437ceab10ab369fee7598d931a1a.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","31612"
"*98d590b2d7e7ee6c87e251a26f155e9c20765829e8ac291092d139aaa6fae676*",".{0,1000}98d590b2d7e7ee6c87e251a26f155e9c20765829e8ac291092d139aaa6fae676.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#filehash","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","31622"
"*99$1a7F1qr2HihoXfs/56u5XMdpDZ83N6hW/HI=*",".{0,1000}99\$1a7F1qr2HihoXfs\/56u5XMdpDZ83N6hW\/HI\=.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","31631"
"*99292BAC-72B4-4AAB-9E5F-2BC1843C8EA3*",".{0,1000}99292BAC\-72B4\-4AAB\-9E5F\-2BC1843C8EA3.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","#GUIDproject","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","31643"
"*99383be21201b97e739e06f5c89a815cd4a296030985505f238862aecbbb7a77*",".{0,1000}99383be21201b97e739e06f5c89a815cd4a296030985505f238862aecbbb7a77.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","#filehash","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","31647"
"*996d133f79b2762f547dcd6900326835517586359ffe5f443c40336983a9a2e7*",".{0,1000}996d133f79b2762f547dcd6900326835517586359ffe5f443c40336983a9a2e7.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","#filehash","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","31661"
"*99e25d4179b7a0419d07f671ab86f25a86582e256e0862fc431eb7f93cfb3ced*",".{0,1000}99e25d4179b7a0419d07f671ab86f25a86582e256e0862fc431eb7f93cfb3ced.{0,1000}","offensive_tool_keyword","OpenChromeDumps","OpenChrome Dump used with GrabChrome for credential access","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Yanluowang - Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","31695"
"*9a193c64e8f1aceb242bf7435f04279b140e19273a2c7c0ff99561fd7abd9652*",".{0,1000}9a193c64e8f1aceb242bf7435f04279b140e19273a2c7c0ff99561fd7abd9652.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","31710"
"*9a1f3ecde8800a00c549fbfa3cf55acbb811fec282d2bea19b27cca9bfe8b947*",".{0,1000}9a1f3ecde8800a00c549fbfa3cf55acbb811fec282d2bea19b27cca9bfe8b947.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","31711"
"*9a30590136ad955b56d367ca00f3d9feb50d4a3fb1d643fc8e3bb3cbcfd1dfa1*",".{0,1000}9a30590136ad955b56d367ca00f3d9feb50d4a3fb1d643fc8e3bb3cbcfd1dfa1.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","#filehash","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","31718"
"*9a4b0023e443b33d85280eedb510864c42b4146c8e6e5f742444b3eff0aae55f*",".{0,1000}9a4b0023e443b33d85280eedb510864c42b4146c8e6e5f742444b3eff0aae55f.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","31726"
"*9ab8a5bbfcdac675219e4415487b8a34270102bb34089609378abe8ea071d13a*",".{0,1000}9ab8a5bbfcdac675219e4415487b8a34270102bb34089609378abe8ea071d13a.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","31760"
"*9ad6a5728ea235b3ed9522a352a6f39fa92d3ac2b5bfebc6fae66638deb76b49*",".{0,1000}9ad6a5728ea235b3ed9522a352a6f39fa92d3ac2b5bfebc6fae66638deb76b49.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31766"
"*9ad6a5728ea235b3ed9522a352a6f39fa92d3ac2b5bfebc6fae66638deb76b49*",".{0,1000}9ad6a5728ea235b3ed9522a352a6f39fa92d3ac2b5bfebc6fae66638deb76b49.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31767"
"*9aeafd043bc6edebba1acbf6f457a63be0edd623899f6245b71ac2e7ba61e03d*",".{0,1000}9aeafd043bc6edebba1acbf6f457a63be0edd623899f6245b71ac2e7ba61e03d.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","31772"
"*9b361496733f31eed59d74b17f7eab74e3175f69e14fb24f9dbde5a359c2c39b*",".{0,1000}9b361496733f31eed59d74b17f7eab74e3175f69e14fb24f9dbde5a359c2c39b.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","#filehash","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","31787"
"*9b4c1be9061e211f2133b67de7e5e51eb6ecf3f035f917a52137395bcbb8bf2e*",".{0,1000}9b4c1be9061e211f2133b67de7e5e51eb6ecf3f035f917a52137395bcbb8bf2e.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31794"
"*9b4c1be9061e211f2133b67de7e5e51eb6ecf3f035f917a52137395bcbb8bf2e*",".{0,1000}9b4c1be9061e211f2133b67de7e5e51eb6ecf3f035f917a52137395bcbb8bf2e.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31795"
"*9b4c57e7b68da80e3949caccaca1742dfdbe31be6f033096f8c9d72a7a0e7947*",".{0,1000}9b4c57e7b68da80e3949caccaca1742dfdbe31be6f033096f8c9d72a7a0e7947.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","31796"
"*9b723acfd67b3a99b88251493db23b8af6fedc8e36395096acec7332f61b86ba*",".{0,1000}9b723acfd67b3a99b88251493db23b8af6fedc8e36395096acec7332f61b86ba.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","#filehash","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","31806"
"*9b7e60f60ab5e2680554d392c3e8a84b9e367a6e452eaab011d1eef963aad894*",".{0,1000}9b7e60f60ab5e2680554d392c3e8a84b9e367a6e452eaab011d1eef963aad894.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","#filehash","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","31811"
"*9bc52d5f3a9d6d2a442de0ee8f417692b2e27993707dd5f07d17b92f9ae84684*",".{0,1000}9bc52d5f3a9d6d2a442de0ee8f417692b2e27993707dd5f07d17b92f9ae84684.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#filehash #linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","31830"
"*9bfad1d826217983cbf0bb46c9578f592002d7893e0e359ef30f888c3693ad3c*",".{0,1000}9bfad1d826217983cbf0bb46c9578f592002d7893e0e359ef30f888c3693ad3c.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","#filehash","N/A","10","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","31840"
"*9c08b2701019c0b4860a85af161c64c303400d720c494aaeade5c2d0d2607118*",".{0,1000}9c08b2701019c0b4860a85af161c64c303400d720c494aaeade5c2d0d2607118.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","31845"
"*9c46104f36627ea0842bf00c050e6fb43befa60e56369e7d4ea843a198e16323*",".{0,1000}9c46104f36627ea0842bf00c050e6fb43befa60e56369e7d4ea843a198e16323.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","31862"
"*9c8c6832651517a7f48e8cf246721ee80be13e61222f12ff5876f7cfb92a6308*",".{0,1000}9c8c6832651517a7f48e8cf246721ee80be13e61222f12ff5876f7cfb92a6308.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","31880"
"*9dc2d1ac93b43a6f3450e6d99201dfa4b7e75e8872d97b6cc90e455201ff0c83*",".{0,1000}9dc2d1ac93b43a6f3450e6d99201dfa4b7e75e8872d97b6cc90e455201ff0c83.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","31959"
"*9de97ca3add57fbe16c2752b22478d49eacdd3d8f1c032bb43792a83ca92e5ca*",".{0,1000}9de97ca3add57fbe16c2752b22478d49eacdd3d8f1c032bb43792a83ca92e5ca.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","31965"
"*9e2e7dd4185ca2abe91139c009790c2a8991e8c652ef8b0d80989a4070c764f0*",".{0,1000}9e2e7dd4185ca2abe91139c009790c2a8991e8c652ef8b0d80989a4070c764f0.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","0","#filehash","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","31979"
"*9e3a20cef67c034ac59b4793a8aa34cbdc7e130fe0ae791fe74059ba4ba0983d*",".{0,1000}9e3a20cef67c034ac59b4793a8aa34cbdc7e130fe0ae791fe74059ba4ba0983d.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","31985"
"*9e415352dda775398d02d9dd203367ce365c562da6227f72b77fb2916550345f*",".{0,1000}9e415352dda775398d02d9dd203367ce365c562da6227f72b77fb2916550345f.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","31989"
"*9e49c482faf12eaefc62f5724c083e35de138b15d2c593db2398577ebd6fdf33*",".{0,1000}9e49c482faf12eaefc62f5724c083e35de138b15d2c593db2398577ebd6fdf33.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31991"
"*9e49c482faf12eaefc62f5724c083e35de138b15d2c593db2398577ebd6fdf33*",".{0,1000}9e49c482faf12eaefc62f5724c083e35de138b15d2c593db2398577ebd6fdf33.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","31992"
"*9E9BB94C-1FBE-4D0B-83B7-E42C83FC5D45*",".{0,1000}9E9BB94C\-1FBE\-4D0B\-83B7\-E42C83FC5D45.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#GUIDproject","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","32012"
"*9ec223a7538868ec25a3823217038beedef36d8dd1f8e388c056bf79fd864b93*",".{0,1000}9ec223a7538868ec25a3823217038beedef36d8dd1f8e388c056bf79fd864b93.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","0","#filehash","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","32025"
"*9EE27D63-6AC9-4037-860B-44E91BAE7F0D*",".{0,1000}9EE27D63\-6AC9\-4037\-860B\-44E91BAE7F0D.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","0","#GUIDproject","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","32035"
"*9f10e67d819156bec13f1a307df49dcf21bd91ddff45205818e402899e58ccca*",".{0,1000}9f10e67d819156bec13f1a307df49dcf21bd91ddff45205818e402899e58ccca.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","#filehash","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","32046"
"*9f7bb583f87b8cfc56d4319cdcfeb865c0db77a0f2110f87d5c694c7f7a0e514*",".{0,1000}9f7bb583f87b8cfc56d4319cdcfeb865c0db77a0f2110f87d5c694c7f7a0e514.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32081"
"*9f7bb583f87b8cfc56d4319cdcfeb865c0db77a0f2110f87d5c694c7f7a0e514*",".{0,1000}9f7bb583f87b8cfc56d4319cdcfeb865c0db77a0f2110f87d5c694c7f7a0e514.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32082"
"*9ff84ad7a284229d49078e3bda95630c060e7845e94169065b47e285795747ad*",".{0,1000}9ff84ad7a284229d49078e3bda95630c060e7845e94169065b47e285795747ad.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","32121"
"*A fast multi protocol credential bruteforcer/sprayer/enumerator*",".{0,1000}A\sfast\smulti\sprotocol\scredential\sbruteforcer\/sprayer\/enumerator.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","32128"
"*a very fast brute force webshell password tool.*",".{0,1000}a\svery\sfast\sbrute\sforce\swebshell\spassword\stool\..{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","32142"
"*a0010bd12872028ba8a53276313527f7a332a23d4cdd0caed1060a45916e8cb4*",".{0,1000}a0010bd12872028ba8a53276313527f7a332a23d4cdd0caed1060a45916e8cb4.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32145"
"*a0010bd12872028ba8a53276313527f7a332a23d4cdd0caed1060a45916e8cb4*",".{0,1000}a0010bd12872028ba8a53276313527f7a332a23d4cdd0caed1060a45916e8cb4.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32146"
"*a01a3fe8fd6c3ff03908efd3321438df49365d0f64fa0a862419e31112936e3e*",".{0,1000}a01a3fe8fd6c3ff03908efd3321438df49365d0f64fa0a862419e31112936e3e.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#filehash","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","32154"
"*a07dd62cf32175dc33bd37663dd3c89eef9413c805ad448e0e5a252b5cb5527f*",".{0,1000}a07dd62cf32175dc33bd37663dd3c89eef9413c805ad448e0e5a252b5cb5527f.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","#filehash","N/A","10","","N/A","","","","32176"
"*a0b465738c8244eae2e5b1c2574e621b044405cf9c3a574e44737ff08f9ea442*",".{0,1000}a0b465738c8244eae2e5b1c2574e621b044405cf9c3a574e44737ff08f9ea442.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059 - T1070.004","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","#filehash","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","32190"
"*a0e17777243f0190053238f503971fc85321ffa8dc12b80bc50b93a2c0d3ea23*",".{0,1000}a0e17777243f0190053238f503971fc85321ffa8dc12b80bc50b93a2c0d3ea23.{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","0","#filehash","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","32202"
"*A0F044C5-D910-4720-B082-58824E372281*",".{0,1000}A0F044C5\-D910\-4720\-B082\-58824E372281.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#GUIDproject","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","32208"
"*a11f916dc20d775bd4961ae27388d2ac5a6613a45e58589040aacd8e70042a23*",".{0,1000}a11f916dc20d775bd4961ae27388d2ac5a6613a45e58589040aacd8e70042a23.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","32224"
"*a12e94a01c3d1cee2942d15b20d30b9574eb23418b20563c134565ead57ed96f*",".{0,1000}a12e94a01c3d1cee2942d15b20d30b9574eb23418b20563c134565ead57ed96f.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32232"
"*a12e94a01c3d1cee2942d15b20d30b9574eb23418b20563c134565ead57ed96f*",".{0,1000}a12e94a01c3d1cee2942d15b20d30b9574eb23418b20563c134565ead57ed96f.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32233"
"*a1b2d9ea6e99d95f0e69e4aed2008823f52a7bbea2e1e1a102e8ab2fcc370829*",".{0,1000}a1b2d9ea6e99d95f0e69e4aed2008823f52a7bbea2e1e1a102e8ab2fcc370829.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","32265"
"*a2a8f773388c06df995500e1d74e8855b11771b21474af4efad67362cc32119e*",".{0,1000}a2a8f773388c06df995500e1d74e8855b11771b21474af4efad67362cc32119e.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32343"
"*a2a8f773388c06df995500e1d74e8855b11771b21474af4efad67362cc32119e*",".{0,1000}a2a8f773388c06df995500e1d74e8855b11771b21474af4efad67362cc32119e.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32344"
"*a2b0e31afa53dfc587fa9e80abddbb6bb01d1050d5e68359f6f298a84fa6625e*",".{0,1000}a2b0e31afa53dfc587fa9e80abddbb6bb01d1050d5e68359f6f298a84fa6625e.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","#filehash","N/A","10","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","32347"
"*a315f75d50a2c54a6d1bb84cca077e6894870d8a1e60010ffd1307a295c8b9f7*",".{0,1000}a315f75d50a2c54a6d1bb84cca077e6894870d8a1e60010ffd1307a295c8b9f7.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","32364"
"*a32580495d4c71174e41935bf681c053aef15993a80c663f224790588b713742*",".{0,1000}a32580495d4c71174e41935bf681c053aef15993a80c663f224790588b713742.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#filehash","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","32368"
"*a36e3489d4317d70fd2cb100020b0c53d575988b790ec33c4c4d204e5e834016*",".{0,1000}a36e3489d4317d70fd2cb100020b0c53d575988b790ec33c4c4d204e5e834016.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","#filehash","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","32386"
"*a3ededd9d0451b04eee2d9160448739af710bd5f380322e0b5992e9b64e1e3a5*",".{0,1000}a3ededd9d0451b04eee2d9160448739af710bd5f380322e0b5992e9b64e1e3a5.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32417"
"*a3ededd9d0451b04eee2d9160448739af710bd5f380322e0b5992e9b64e1e3a5*",".{0,1000}a3ededd9d0451b04eee2d9160448739af710bd5f380322e0b5992e9b64e1e3a5.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32418"
"*a4058df23cf217a43482e2f6fa20e55ef9005d20713a6860a4974da0fe731e64*",".{0,1000}a4058df23cf217a43482e2f6fa20e55ef9005d20713a6860a4974da0fe731e64.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#filehash","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","32425"
"*a45833f0ee2541c060b8154389fdca5cf5bd19f460352eae83c4fbe024edc803*",".{0,1000}a45833f0ee2541c060b8154389fdca5cf5bd19f460352eae83c4fbe024edc803.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","32449"
"*a48708d0c27daec437448a1363e63b53d518cf00e60d701fe5f6292ffab1df00*",".{0,1000}a48708d0c27daec437448a1363e63b53d518cf00e60d701fe5f6292ffab1df00.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","#filehash","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","32464"
"*a50f337900d9adf19bfda21fa5d89c5b1525cbb96c1cddb9443e62d56f5a8e5b*",".{0,1000}a50f337900d9adf19bfda21fa5d89c5b1525cbb96c1cddb9443e62d56f5a8e5b.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","32498"
"*a5553553f4c9056cff908df93f4dd7f498a9ce180048d1331ed00028d644ea00*",".{0,1000}a5553553f4c9056cff908df93f4dd7f498a9ce180048d1331ed00028d644ea00.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","32519"
"*a568c8a8c28b7ceeee2f5eec82f94dd4fb0fc06175b2ee3043f863a68451ebbd*",".{0,1000}a568c8a8c28b7ceeee2f5eec82f94dd4fb0fc06175b2ee3043f863a68451ebbd.{0,1000}","offensive_tool_keyword","Necro-Stealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/Necro-Stealer","1","0","#filehash","N/A","8","1","6","1","2022-12-06T16:06:55Z","2022-12-06T15:52:17Z","32528"
"*a58ef464df86f0f3dfab3123cae2fbfd6cb86b707f9dfa4a281ea0e9a40a858d*",".{0,1000}a58ef464df86f0f3dfab3123cae2fbfd6cb86b707f9dfa4a281ea0e9a40a858d.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","32546"
"*a591699874d0a2c26c1d9e47561ee2a3043fc3ea458c09a7ab8a24a25150cd0a*",".{0,1000}a591699874d0a2c26c1d9e47561ee2a3043fc3ea458c09a7ab8a24a25150cd0a.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","0","#filehash","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","32549"
"*a5e57662131399ad586e4b5c4a942bc9029104331953fdbdbfd6e8a0cdad9ccc*",".{0,1000}a5e57662131399ad586e4b5c4a942bc9029104331953fdbdbfd6e8a0cdad9ccc.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","32568"
"*a60a04cda101deaab5c2aa8b25c715fffc7a4f3e9813fa6d53a5b25dd4126fe2*",".{0,1000}a60a04cda101deaab5c2aa8b25c715fffc7a4f3e9813fa6d53a5b25dd4126fe2.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#filehash","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","32578"
"*a65b022127a9e19bdb6e119e020cf70a89c4d59a156b8040d74a8f489dc490c2*",".{0,1000}a65b022127a9e19bdb6e119e020cf70a89c4d59a156b8040d74a8f489dc490c2.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32611"
"*a65b022127a9e19bdb6e119e020cf70a89c4d59a156b8040d74a8f489dc490c2*",".{0,1000}a65b022127a9e19bdb6e119e020cf70a89c4d59a156b8040d74a8f489dc490c2.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32612"
"*A6F8500F-68BC-4EFC-962A-6C6E68D893AF*",".{0,1000}A6F8500F\-68BC\-4EFC\-962A\-6C6E68D893AF.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","#GUIDproject","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","32640"
"*a6fe51ded3889aaf77c7b55814220c6e2ba19fac731f4387c472713d3b454dca*",".{0,1000}a6fe51ded3889aaf77c7b55814220c6e2ba19fac731f4387c472713d3b454dca.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","32644"
"*A71FCCEB-C1C5-4ADB-A949-462B653C2937*",".{0,1000}A71FCCEB\-C1C5\-4ADB\-A949\-462B653C2937.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#GUIDProject","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","32655"
"*a74524600479028cf1f6231ddfa1e701c98f333667461a3b20124ee3b36bd650*",".{0,1000}a74524600479028cf1f6231ddfa1e701c98f333667461a3b20124ee3b36bd650.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","32664"
"*a77a13a5a04bd0753a883fbefab58bc0504cd151303e285bb3799d6c38196a30*",".{0,1000}a77a13a5a04bd0753a883fbefab58bc0504cd151303e285bb3799d6c38196a30.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","32681"
"*a78b41d1e1383a0aefbaba58881d1aa5b4a76457828ab5d60cb3b10ab075ca49*",".{0,1000}a78b41d1e1383a0aefbaba58881d1aa5b4a76457828ab5d60cb3b10ab075ca49.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","32687"
"*a7aa95075ecb1e4b2201ac1962eac88639e816ebf94c0d08b2bd5da274a981db*",".{0,1000}a7aa95075ecb1e4b2201ac1962eac88639e816ebf94c0d08b2bd5da274a981db.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","32700"
"*a7e8aade00d2cd5aeb6ec40d5b64f6cac88f120efb4efb719567e758af5892c2*",".{0,1000}a7e8aade00d2cd5aeb6ec40d5b64f6cac88f120efb4efb719567e758af5892c2.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","0","#filehash","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","32720"
"*a814e455a709e0ee42fdec62b57f9a62cc3af6d31b2f54ff9d869a6736ded903*",".{0,1000}a814e455a709e0ee42fdec62b57f9a62cc3af6d31b2f54ff9d869a6736ded903.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32732"
"*a814e455a709e0ee42fdec62b57f9a62cc3af6d31b2f54ff9d869a6736ded903*",".{0,1000}a814e455a709e0ee42fdec62b57f9a62cc3af6d31b2f54ff9d869a6736ded903.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32733"
"*a829137b318890cb77f6a1ce28ce4dbaa4a39e19ef91b75f4f50dfc2b1a992bf*",".{0,1000}a829137b318890cb77f6a1ce28ce4dbaa4a39e19ef91b75f4f50dfc2b1a992bf.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#filehash","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","32737"
"*a8421a872b4c4eccc02a0ebb623f9ecc2991e949e4134fc184ca1822da0e5c4c*",".{0,1000}a8421a872b4c4eccc02a0ebb623f9ecc2991e949e4134fc184ca1822da0e5c4c.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","#filehash","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","32749"
"*a87fea89545bb209dcc98edfe23e5171def343793d956308ef1c9b5c1e477990*",".{0,1000}a87fea89545bb209dcc98edfe23e5171def343793d956308ef1c9b5c1e477990.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","32759"
"*a88a0af4e583fbae14ad5003c85f29949b720db848e373668924880369fa8fbd*",".{0,1000}a88a0af4e583fbae14ad5003c85f29949b720db848e373668924880369fa8fbd.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","32762"
"*a89da438ecbe2e8c5f65e2bcbf5d82a84d26ba56dff46eb180c9de213f5a1871*",".{0,1000}a89da438ecbe2e8c5f65e2bcbf5d82a84d26ba56dff46eb180c9de213f5a1871.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","#filehash","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","32768"
"*a8fca4711a214b5b154a7a9f31018bff0eb59ddc8dfe8bad04dde7f90972437a*",".{0,1000}a8fca4711a214b5b154a7a9f31018bff0eb59ddc8dfe8bad04dde7f90972437a.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","#filehash","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","32794"
"*a909221a35b3fda0f6149de8e58186909cd0efae15bbba614b9a15d4b7d15fd3*",".{0,1000}a909221a35b3fda0f6149de8e58186909cd0efae15bbba614b9a15d4b7d15fd3.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","32800"
"*a92acb50dd8f358f4b2fb99a6f50332006c7823712acd62b88cadfe01c517d9b*",".{0,1000}a92acb50dd8f358f4b2fb99a6f50332006c7823712acd62b88cadfe01c517d9b.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32807"
"*a92acb50dd8f358f4b2fb99a6f50332006c7823712acd62b88cadfe01c517d9b*",".{0,1000}a92acb50dd8f358f4b2fb99a6f50332006c7823712acd62b88cadfe01c517d9b.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32808"
"*A9386992-CFAC-468A-BD41-78382212E5B9*",".{0,1000}A9386992\-CFAC\-468A\-BD41\-78382212E5B9.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","0","#GUIDproject","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","32812"
"*a96e22322b009000a8b0b8cf7229f4e40c36b260f1076f1c225c12a43613c405*",".{0,1000}a96e22322b009000a8b0b8cf7229f4e40c36b260f1076f1c225c12a43613c405.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#filehash","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","32828"
"*a9830d372873174b5e855d0ba4b0f14912e007657bfe0bdcddae7f10e0ea7a03*",".{0,1000}a9830d372873174b5e855d0ba4b0f14912e007657bfe0bdcddae7f10e0ea7a03.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","32833"
"*a98576591e0e03e13239e35f8e02e30b71b6e4109f568a3d245af6ac67591699*",".{0,1000}a98576591e0e03e13239e35f8e02e30b71b6e4109f568a3d245af6ac67591699.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32835"
"*a98576591e0e03e13239e35f8e02e30b71b6e4109f568a3d245af6ac67591699*",".{0,1000}a98576591e0e03e13239e35f8e02e30b71b6e4109f568a3d245af6ac67591699.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32836"
"*a9bbb6cb0597d7f59a85f981550e52f148f023a0576434ba9396bc8f5eb3f989*",".{0,1000}a9bbb6cb0597d7f59a85f981550e52f148f023a0576434ba9396bc8f5eb3f989.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","32857"
"*a9d6d8e1051e28d933a3979f20e8fd7eb85611d2014502d093aa879681bbbc26*",".{0,1000}a9d6d8e1051e28d933a3979f20e8fd7eb85611d2014502d093aa879681bbbc26.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","0","#filehash","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","32864"
"*aafdc7daa6d0f982d64819a332aebc9576b166c78c38a16b065274e8c5dc518e*",".{0,1000}aafdc7daa6d0f982d64819a332aebc9576b166c78c38a16b065274e8c5dc518e.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32949"
"*aafdc7daa6d0f982d64819a332aebc9576b166c78c38a16b065274e8c5dc518e*",".{0,1000}aafdc7daa6d0f982d64819a332aebc9576b166c78c38a16b065274e8c5dc518e.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","32950"
"*ab48a8d28e53fb65d460c4faa8cc44d8e00c9684b7fb4dd2598223d7e2963da6*",".{0,1000}ab48a8d28e53fb65d460c4faa8cc44d8e00c9684b7fb4dd2598223d7e2963da6.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","#filehash","N/A","10","","N/A","","","","32978"
"*ab86676468036b6f915ffcefd6e05aa56bf02459a383c46dff095d5852a996e2*",".{0,1000}ab86676468036b6f915ffcefd6e05aa56bf02459a383c46dff095d5852a996e2.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","33004"
"*ABC32DBD-B697-482D-A763-7BA82FE9CEA2*",".{0,1000}ABC32DBD\-B697\-482D\-A763\-7BA82FE9CEA2.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","0","#GUIDproject","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","33020"
"*ac i ntds* *create full*",".{0,1000}ac\si\sntds.{0,1000}\s.{0,1000}create\sfull.{0,1000}","greyware_tool_keyword","ntdsutil","creating a full backup of the Active Directory database ","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","33049"
"*ac i ntds*\\127.0.0.1\ADMIN$\*",".{0,1000}ac\si\sntds.{0,1000}\\\\127\.0\.0\.1\\ADMIN\$\\.{0,1000}","greyware_tool_keyword","wmic","The actor has executed WMIC commands [T1047] to create a copy of the ntds.dit file and SYSTEM registry hive using ntdsutil.exe","T1047 - T1005 - T1567.001","TA0002 - TA0003 - TA0007","N/A","MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR","Credential Access","https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","33050"
"*ac0eb86fafd0ca2e1450238cfb023c1c82b6d24fec249623ff1d0e161b7727c6*",".{0,1000}ac0eb86fafd0ca2e1450238cfb023c1c82b6d24fec249623ff1d0e161b7727c6.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","#filehash","N/A","9","10","N/A","N/A","N/A","N/A","33056"
"*ac0eb86fafd0ca2e1450238cfb023c1c82b6d24fec249623ff1d0e161b7727c6*",".{0,1000}ac0eb86fafd0ca2e1450238cfb023c1c82b6d24fec249623ff1d0e161b7727c6.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","#filehash","N/A","9","10","N/A","N/A","N/A","N/A","33057"
"*ac237c0f9cc970822dee74c4251b50a87c637af3d8b087ceb5162aaee4b67381*",".{0,1000}ac237c0f9cc970822dee74c4251b50a87c637af3d8b087ceb5162aaee4b67381.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","33066"
"*ac24f9111a5e72c85f2b32ce3c09f46814363c98383be1e972839d89b1a3d18c*",".{0,1000}ac24f9111a5e72c85f2b32ce3c09f46814363c98383be1e972839d89b1a3d18c.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","33067"
"*ac3107cf-291c-449b-9121-55cd37f6383e*",".{0,1000}ac3107cf\-291c\-449b\-9121\-55cd37f6383e.{0,1000}","offensive_tool_keyword","Necro-Stealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/Necro-Stealer","1","0","#GUIDproject","N/A","8","1","6","1","2022-12-06T16:06:55Z","2022-12-06T15:52:17Z","33071"
"*ac4319f7349146fa891f608416dbf40475ebfdbbbec155939eb34d8fa1a67079*",".{0,1000}ac4319f7349146fa891f608416dbf40475ebfdbbbec155939eb34d8fa1a67079.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","#filehash","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","33075"
"*ac49d2041cd57b1efba672c3305b621ebb265380010b8951cda01c055a7e1e64*",".{0,1000}ac49d2041cd57b1efba672c3305b621ebb265380010b8951cda01c055a7e1e64.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","#filehash","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","33078"
"*acb7923ed1efb328d724977f2507a7a721a6c7cf630a3b37a9f4d7a3a2c7010c*",".{0,1000}acb7923ed1efb328d724977f2507a7a721a6c7cf630a3b37a9f4d7a3a2c7010c.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","33101"
"*acc6cd307e1dd184b722a082c177639e78421f79b0e3b26fa602f1ce8392cc4f*",".{0,1000}acc6cd307e1dd184b722a082c177639e78421f79b0e3b26fa602f1ce8392cc4f.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#filehash","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","33103"
"*AccessTokenImpersonationAccount*",".{0,1000}AccessTokenImpersonationAccount.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","33110"
"*acd7392528b68181416263c966f899f4cd0b6430951ca09900739601c588eb5d*",".{0,1000}acd7392528b68181416263c966f899f4cd0b6430951ca09900739601c588eb5d.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","33115"
"*aCSHELL/../../../../../../../*",".{0,1000}aCSHELL\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/.{0,1000}","offensive_tool_keyword","POC","CVE-2024-24919","T1005 - T1006 - T1078 - T1110 - T1135 - T1185","TA0001 - TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/LucasKatashi/CVE-2024-24919","1","1","#linux","N/A","10","1","13","5","2024-05-30T17:08:11Z","2024-05-30T16:23:18Z","33150"
"*AD240C26-717F-4937-A4CD-5827BDC315E6*",".{0,1000}AD240C26\-717F\-4937\-A4CD\-5827BDC315E6.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#GUIDProject","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","33197"
"*ad7136daff93312ebb41fe388da46d2814ab6504e23b3c90b2a56a0426a558e3*",".{0,1000}ad7136daff93312ebb41fe388da46d2814ab6504e23b3c90b2a56a0426a558e3.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#filehash","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","33217"
"*ad97557e81bf680c9c796b2673a34562a0f80cb27b88bf53fe20a9a281723e07*",".{0,1000}ad97557e81bf680c9c796b2673a34562a0f80cb27b88bf53fe20a9a281723e07.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","33227"
"*Adamantium-Thief-master*",".{0,1000}Adamantium\-Thief\-master.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","1","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","33239"
"*adbed7685fc512f48cf0edb1eb0df16fed97c52d5eab0fe70e88286c47d53e3d*",".{0,1000}adbed7685fc512f48cf0edb1eb0df16fed97c52d5eab0fe70e88286c47d53e3d.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#filehash","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","33245"
"*adconnectdump.py*",".{0,1000}adconnectdump\.py.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","33251"
"*adconnectdump-master*",".{0,1000}adconnectdump\-master.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","33252"
"*ADCSCoercePotato.cpp*",".{0,1000}ADCSCoercePotato\.cpp.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","33259"
"*ADCSCoercePotato.exe*",".{0,1000}ADCSCoercePotato\.exe.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","33260"
"*ADCSCoercePotato.sln*",".{0,1000}ADCSCoercePotato\.sln.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","33261"
"*ADCSCoercePotato.vcxproj*",".{0,1000}ADCSCoercePotato\.vcxproj.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","33262"
"*ADCSCoercePotato\n- @decoder_it 2024\*",".{0,1000}ADCSCoercePotato\\n\-\s\@decoder_it\s2024\\.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","0","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","33263"
"*adcsync.py -*",".{0,1000}adcsync\.py\s\-.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","0","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","33273"
"*--add-data rarreg.key*",".{0,1000}\-\-add\-data\srarreg\.key.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","33325"
"*Add-KeePassConfigTrigger *",".{0,1000}Add\-KeePassConfigTrigger\s.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","33330"
"*Add-KeePassConfigTrigger*",".{0,1000}Add\-KeePassConfigTrigger.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","33331"
"*AddKeePassTrigger.ps1*",".{0,1000}AddKeePassTrigger\.ps1.{0,1000}","offensive_tool_keyword","crackmapexec","Keepass exploitations from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","33332"
"*Add-KeyCredentials -target *",".{0,1000}Add\-KeyCredentials\s\-target\s.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","33335"
"*ADFSDump.csproj*",".{0,1000}ADFSDump\.csproj.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","1","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","33430"
"*ADFSDump.exe*",".{0,1000}ADFSDump\.exe.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","1","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","33431"
"*ADFSDump.sln*",".{0,1000}ADFSDump\.sln.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","1","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","33436"
"*ADFSpoof.py*",".{0,1000}ADFSpoof\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","33437"
"*ADFSpray.csv*",".{0,1000}ADFSpray\.csv.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","1","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","33439"
"*adfspray.git*",".{0,1000}adfspray\.git.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","1","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","33440"
"*ADFSpray.py*",".{0,1000}ADFSpray\.py.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","1","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","33441"
"*ADFSRelay -*",".{0,1000}ADFSRelay\s\-.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","0","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","33442"
"*ADFSRelay-main*",".{0,1000}ADFSRelay\-main.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","0","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","33443"
"*AdPassHunt (PUA)*",".{0,1000}AdPassHunt\s\(PUA\).{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","33471"
"*ADPassHunt.exe*",".{0,1000}ADPassHunt\.exe.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","33472"
"*ADSync passwords can be read or modified as local administrator only for ADSync version *",".{0,1000}ADSync\spasswords\scan\sbe\sread\sor\smodified\sas\slocal\sadministrator\sonly\sfor\sADSync\sversion\s.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","0","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","33487"
"*ADSyncDecrypt.exe*",".{0,1000}ADSyncDecrypt\.exe.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","33488"
"*ADSyncGather.exe*",".{0,1000}ADSyncGather\.exe.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","33491"
"*ADSyncQuery*ADSync.mdf*.txt*",".{0,1000}ADSyncQuery.{0,1000}ADSync\.mdf.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","0","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","33492"
"*Adware/Gsecdump*",".{0,1000}Adware\/Gsecdump.{0,1000}","signature_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","33508"
"*adxcsouf2john.py*",".{0,1000}adxcsouf2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33510"
"*ae320a69dd18e08c9cfb026f247978522ffde2acddeff93a5406c9b584dbc430*",".{0,1000}ae320a69dd18e08c9cfb026f247978522ffde2acddeff93a5406c9b584dbc430.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#filehash","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","33529"
"*ae320a69dd18e08c9cfb026f247978522ffde2acddeff93a5406c9b584dbc430*",".{0,1000}ae320a69dd18e08c9cfb026f247978522ffde2acddeff93a5406c9b584dbc430.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#filehash","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","33530"
"*AE844C23-294E-4690-8CF3-2E5F9769D8E0*",".{0,1000}AE844C23\-294E\-4690\-8CF3\-2E5F9769D8E0.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","#GUIDproject","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","33553"
"*aeachknmefphepccionboohckonoeemg*",".{0,1000}aeachknmefphepccionboohckonoeemg.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","33567"
"*AEC0EBBA-3BE4-4B5C-8F5C-0BB8DDDA7148*",".{0,1000}AEC0EBBA\-3BE4\-4B5C\-8F5C\-0BB8DDDA7148.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#GUIDProject","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","33571"
"*aef6ce3014add838cf676b57957d630cd2bb15b0c9193cf349bcffecddbc3623*",".{0,1000}aef6ce3014add838cf676b57957d630cd2bb15b0c9193cf349bcffecddbc3623.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","33587"
"*aef6ce3014add838cf676b57957d630cd2bb15b0c9193cf349bcffecddbc3623*",".{0,1000}aef6ce3014add838cf676b57957d630cd2bb15b0c9193cf349bcffecddbc3623.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","33588"
"*aem2john.py*",".{0,1000}aem2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33592"
"*AERTSW50ZXJuYWxzXHg4Nlx2Y3J1bnRpbWUxNDBfdGhyZWFkcy5kbGxQSwECFAAUAAAACAAnnY1YrbP4grERAAA9RQAADwAAAAAAAAAAAAAAAABk7yEARFNJbnRlcm5hbHMuY2F0UEsFBgAAAAAwADAAdRAAAEIBIgAAAA==*",".{0,1000}AERTSW50ZXJuYWxzXHg4Nlx2Y3J1bnRpbWUxNDBfdGhyZWFkcy5kbGxQSwECFAAUAAAACAAnnY1YrbP4grERAAA9RQAADwAAAAAAAAAAAAAAAABk7yEARFNJbnRlcm5hbHMuY2F0UEsFBgAAAAAwADAAdRAAAEIBIgAAAA\=\=.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","#base64","base64 rubeus","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","33602"
"*aes*83fb558645767abb199755eafb4fbc5167113da8ee69f13267388dc3adcdb088*",".{0,1000}aes.{0,1000}83fb558645767abb199755eafb4fbc5167113da8ee69f13267388dc3adcdb088.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","#filehash","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","33603"
"*af190cf0778fc031a0db2eb2e36aaa0a09dea5495ce8a50d6e3eee439db3dc7a*",".{0,1000}af190cf0778fc031a0db2eb2e36aaa0a09dea5495ce8a50d6e3eee439db3dc7a.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","33615"
"*af6d177df40fcf715f752557c9fd2483a5e194c1c468625a76a4862632db5cb6*",".{0,1000}af6d177df40fcf715f752557c9fd2483a5e194c1c468625a76a4862632db5cb6.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#filehash","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","33633"
"*af763332f70cf0137ebcb1d237e55a00c6fc0698982fec44fb012db4cb1be5df*",".{0,1000}af763332f70cf0137ebcb1d237e55a00c6fc0698982fec44fb012db4cb1be5df.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","0","#filehash #linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","33638"
"*af91c925c3a6ba14dea50a5d24593c48cc02e7bfc23b7a02eaf59dd55c3ae6cd*",".{0,1000}af91c925c3a6ba14dea50a5d24593c48cc02e7bfc23b7a02eaf59dd55c3ae6cd.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","0","#filehash","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","33644"
"*afbcbjpbpfadlkmhmclhkeeodmamcflc*",".{0,1000}afbcbjpbpfadlkmhmclhkeeodmamcflc.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","33655"
"*affa24f6e1fd339093365bfce238b94ec6948d4d1c401fc7dffc4921e9da0187*",".{0,1000}affa24f6e1fd339093365bfce238b94ec6948d4d1c401fc7dffc4921e9da0187.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","33675"
"*agoakfejjabomempkjlepdflaleeobhb*",".{0,1000}agoakfejjabomempkjlepdflaleeobhb.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","33727"
"*aholpfdialjgjfhomihkjbmgjidlcdno*",".{0,1000}aholpfdialjgjfhomihkjbmgjidlcdno.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","33734"
"*aiifbnbfobpmeekipheeijimdpnlpgpp*",".{0,1000}aiifbnbfobpmeekipheeijimdpnlpgpp.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","33741"
"*airbase-ng -*",".{0,1000}airbase\-ng\s\-.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33743"
"*aircrack.txt*",".{0,1000}aircrack\.txt.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33745"
"*Aircrack-ng*",".{0,1000}Aircrack\-ng.{0,1000}","offensive_tool_keyword","aircrack","WiFi security auditing tools suite.","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33746"
"*aircrack-ptw-*",".{0,1000}aircrack\-ptw\-.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33748"
"*airdecap-ng -*",".{0,1000}airdecap\-ng\s\-.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33749"
"*aireplay-ng -*",".{0,1000}aireplay\-ng\s\-.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33752"
"*Airgeddon*",".{0,1000}Airgeddon.{0,1000}","offensive_tool_keyword","Airgeddon","This is a multi-use bash script for Linux systems to audit wireless networks.","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/v1s1t0r1sh3r3/airgeddon","1","0","#linux","N/A","5","10","6882","1209","2025-04-15T19:43:18Z","2016-03-18T10:34:56Z","33753"
"*airgraph-ng -*",".{0,1000}airgraph\-ng\s\-.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33754"
"*airodump-ng *",".{0,1000}airodump\-ng\s.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33757"
"*airodump-ng *",".{0,1000}airodump\-ng\s.{0,1000}","offensive_tool_keyword","aircrack","WiFi security auditing tools suite.","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33758"
"*airolib-ng airolib-db*",".{0,1000}airolib\-ng\sairolib\-db.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33760"
"*airserv-ng -*",".{0,1000}airserv\-ng\s\-.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33762"
"*airtun-ng -a *",".{0,1000}airtun\-ng\s\-a\s.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","33763"
"*aix2john.pl*",".{0,1000}aix2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33764"
"*aix2john.py*",".{0,1000}aix2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33765"
"*AlessandroZ/LaZagne*",".{0,1000}AlessandroZ\/LaZagne.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","33784"
"*Alexander Hagenah (@xaitax)*",".{0,1000}Alexander\sHagenah\s\(\@xaitax\).{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","#content","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","33785"
"*alexa-top-20000-sites.txt*",".{0,1000}alexa\-top\-20000\-sites\.txt.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","33786"
"*All Dump files will be stored in C:\\Users\\Public*",".{0,1000}All\sDump\sfiles\swill\sbe\sstored\sin\sC\:\\\\Users\\\\Public.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","33794"
"*All good in the hood. Check Temp for test.txt*",".{0,1000}All\sgood\sin\sthe\shood\.\sCheck\sTemp\sfor\stest\.txt.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","33797"
"*amkmjjmmflddogmhpjloimipbofnfjih*",".{0,1000}amkmjjmmflddogmhpjloimipbofnfjih.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","33837"
"*andotp2john.py*",".{0,1000}andotp2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33870"
"*AndrewSpecial.cpp*",".{0,1000}AndrewSpecial\.cpp.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","1","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","33871"
"*AndrewSpecial.exe*",".{0,1000}AndrewSpecial\.exe.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","1","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","33872"
"*AndrewSpecial-master*",".{0,1000}AndrewSpecial\-master.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","1","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","33873"
"*androidbackup2john.py*",".{0,1000}androidbackup2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33875"
"*androidfde2john.py*",".{0,1000}androidfde2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33876"
"*ansible2john.py*",".{0,1000}ansible2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33890"
"*aodkkagnadcbobfpggfnjeongemjbjca*",".{0,1000}aodkkagnadcbobfpggfnjeongemjbjca.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","33924"
"*apedx765p-stoedx765re.jsedx765on*",".{0,1000}apedx765p\-stoedx765re\.jsedx765on.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","33935"
"*apex2john.py*",".{0,1000}apex2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33936"
"*APIHookInjectorBin.exe*",".{0,1000}APIHookInjectorBin\.exe.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","33953"
"*APIHookInjectorBin.log*",".{0,1000}APIHookInjectorBin\.log.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","#logfile","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","33954"
"*APIHookInjectorBin.pdb*",".{0,1000}APIHookInjectorBin\.pdb.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","33955"
"*APIHookInjectorBin.sln*",".{0,1000}APIHookInjectorBin\.sln.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","33956"
"*apop2john.py*",".{0,1000}apop2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33962"
"*'app_bound_encrypted_key' not found in Local State file*",".{0,1000}\'app_bound_encrypted_key\'\snot\sfound\sin\sLocal\sState\sfile.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","#content","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","33969"
"*applenotes2john.py*",".{0,1000}applenotes2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","33984"
"*Application.Hacktool.SessionGopher*",".{0,1000}Application\.Hacktool\.SessionGopher.{0,1000}","signature_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","#Avsignature","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","33987"
"*Application.Lazagne.H*",".{0,1000}Application\.Lazagne\.H.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","33988"
"*apt install crunch*",".{0,1000}apt\sinstall\scrunch.{0,1000}","offensive_tool_keyword","crunch","Generate a dictionary file containing words with a minimum and maximum length","T1596 - T1596.001","TA0043","N/A","N/A","Credential Access","https://sourceforge.net/projects/crunch-wordlist/","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","34004"
"*apt install gpp-decrypt*",".{0,1000}apt\sinstall\sgpp\-decrypt.{0,1000}","offensive_tool_keyword","gpp-decrypt","Decrypt the given Group Policy Preferences","T1552.002 - T1212","TA0009 - TA0006","N/A","N/A","Credential Access","https://gitlab.com/kalilinux/packages/gpp-decrypt","1","0","N/A","N/A","6","10","N/A","N/A","N/A","N/A","34007"
"*apt install wce*",".{0,1000}apt\sinstall\swce.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","0","N/A","N/A","8","4","N/A","N/A","N/A","N/A","34017"
"*apt* install john*",".{0,1000}apt.{0,1000}\sinstall\sjohn.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","34020"
"*apt-get -y install tor *",".{0,1000}apt\-get\s\-y\sinstall\stor\s.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","0","N/A","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","34032"
"*apypykatz.py*",".{0,1000}apypykatz\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","34039"
"*Arno0x/NtlmRelayToEWS*",".{0,1000}Arno0x\/NtlmRelayToEWS.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","34067"
"*aruba2john.py*",".{0,1000}aruba2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","34107"
"*Arvanaghi/SessionGopher*",".{0,1000}Arvanaghi\/SessionGopher.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","1","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","34108"
"*ASR_bypass_to_dump_LSASS.cs*",".{0,1000}ASR_bypass_to_dump_LSASS\.cs.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","#content","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","34124"
"*asrep2kirbi*",".{0,1000}asrep2kirbi.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","34127"
"*Asreproast.*",".{0,1000}Asreproast\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","34131"
"*ASREPRoast.ps1*",".{0,1000}ASREPRoast\.ps1.{0,1000}","offensive_tool_keyword","ASREPRoast","Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. ","T1558.003","TA0006","N/A","N/A","Credential Access","https://github.com/HarmJ0y/ASREPRoast","1","1","N/A","N/A","N/A","3","202","58","2018-09-25T03:26:00Z","2017-01-14T21:07:57Z","34132"
"*asreproast_*.txt*",".{0,1000}asreproast_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","34133"
"*ASRepToHashcat*",".{0,1000}ASRepToHashcat.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","34139"
"*ATK/MultiDump-*",".{0,1000}ATK\/MultiDump\-.{0,1000}","signature_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","#Avsignature","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","34186"
"*ATK/SharpDump-A*",".{0,1000}ATK\/SharpDump\-A.{0,1000}","signature_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#Avsignature","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","34191"
"*atmail2john.pl*",".{0,1000}atmail2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","34203"
"*atomizer imap *",".{0,1000}atomizer\simap\s.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","34204"
"*atomizer lync *",".{0,1000}atomizer\slync\s.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","34205"
"*atomizer owa *",".{0,1000}atomizer\sowa\s.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","34206"
"*atomizer.py -*",".{0,1000}atomizer\.py\s\-.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","34207"
"*atomizer.py imap *",".{0,1000}atomizer\.py\simap\s.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","34208"
"*atomizer.py lync *",".{0,1000}atomizer\.py\slync\s.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","34209"
"*atomizer.py owa *",".{0,1000}atomizer\.py\sowa\s.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","34210"
"*ATPMiniDump*",".{0,1000}ATPMiniDump.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","1","N/A","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","34215"
"*ATT_BITLOCKER_MSFVE_RECOVERY_PASSWORD*ATTm591788*",".{0,1000}ATT_BITLOCKER_MSFVE_RECOVERY_PASSWORD.{0,1000}ATTm591788.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","34217"
"*attacker.shadowCredObjects.Count*",".{0,1000}attacker\.shadowCredObjects\.Count.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#content","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","34222"
"*Attempting Risky Operation: Opening Handle Directly to Lsass Process*",".{0,1000}Attempting\sRisky\sOperation\:\sOpening\sHandle\sDirectly\sto\sLsass\sProcess.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","34234"
"*attrib +r +a +s +h ""%PROGRAMFILES%\Media player"" /S /D*",".{0,1000}attrib\s\+r\s\+a\s\+s\s\+h\s\""\%PROGRAMFILES\%\\Media\splayer\""\s\/S\s\/D.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","34239"
"*attrib +s +h desktop.ini*",".{0,1000}attrib\s\+s\s\+h\sdesktop\.ini.{0,1000}","greyware_tool_keyword","attrib","NTLM Leak via Desktop.ini","T1564.001","TA0005","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Anti-Forensics.md","1","0","N/A","N/A","N/A","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","34243"
"*Author: @ShitSecure*",".{0,1000}Author\:\s\@ShitSecure.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","34266"
"*auto_exploit_blank_password*",".{0,1000}auto_exploit_blank_password.{0,1000}","offensive_tool_keyword","pxethief","PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager","T1555.004 - T1555.002","TA0006","N/A","N/A","Credential Access","https://github.com/MWR-CyberSec/PXEThief","1","1","N/A","N/A","N/A","4","368","57","2024-05-29T15:07:15Z","2022-08-12T22:16:46Z","34270"
"*autokerberoast.ps1*",".{0,1000}autokerberoast\.ps1.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","34302"
"*autokerberoast_noMimikatz.ps1",".{0,1000}autokerberoast_noMimikatz\.ps1","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","34303"
"*autoKirbi2hashcat.py*",".{0,1000}autoKirbi2hashcat\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","34304"
"*autoTGS_NtlmCrack.py*",".{0,1000}autoTGS_NtlmCrack\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","34325"
"*AvDump.exe --pid * --dump_file *.dmp*",".{0,1000}AvDump\.exe\s\-\-pid\s.{0,1000}\s\-\-dump_file\s.{0,1000}\.dmp.{0,1000}","greyware_tool_keyword","AVDump","Avast AV to dump LSASS (C:\Program Files\Avast Software\Avast)","T1003.001 - T1059.001 - T1106","TA0006","N/A","Dispossessor","Credential Access","https://rosesecurity.gitbook.io/red-teaming-ttps/windows#av-lsass-dump","1","0","N/A","lolbin","8","9","N/A","N/A","N/A","N/A","34341"
"*AWS Account Bruteforce Ratelimit! Sleeping for *",".{0,1000}AWS\sAccount\sBruteforce\sRatelimit!\sSleeping\sfor\s.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","0","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","34384"
"*axcrypt2john.py*",".{0,1000}axcrypt2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","34389"
"*aydinnyunus/PassDetective*",".{0,1000}aydinnyunus\/PassDetective.{0,1000}","offensive_tool_keyword","PassDetective","PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets","T1059 - T1059.004 - T1552 - T1552.001","TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/aydinnyunus/PassDetective","1","1","N/A","N/A","7","2","129","8","2024-06-19T10:39:39Z","2023-07-22T12:31:57Z","34390"
"*azizjon.m@gmail.com*",".{0,1000}azizjon\.m\@gmail\.com.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","#email","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","34393"
"*AzureAD AutoLogon Brute*",".{0,1000}AzureAD\sAutoLogon\sBrute.{0,1000}","offensive_tool_keyword","AzureAD_Autologon_Brute","Brute force attack tool for Azure AD Autologon","T1110 - T1078 - T1114 - T1087","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/AzureAD_Autologon_Brute","1","0","N/A","N/A","N/A","2","101","20","2024-06-27T12:23:42Z","2021-10-01T05:20:25Z","34396"
"*AzureAD_Autologon_Brute*",".{0,1000}AzureAD_Autologon_Brute.{0,1000}","offensive_tool_keyword","AzureAD_Autologon_Brute","Brute force attack tool for Azure AD Autologon","T1110 - T1078 - T1114 - T1087","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/AzureAD_Autologon_Brute","1","1","N/A","N/A","N/A","2","101","20","2024-06-27T12:23:42Z","2021-10-01T05:20:25Z","34397"
"*azuread_decrypt_msol_*.ps1*",".{0,1000}azuread_decrypt_msol_.{0,1000}\.ps1.{0,1000}","offensive_tool_keyword","powershell","method of dumping the MSOL service account (which allows a DCSync) used by Azure AD Connect Sync","T1003.006","TA0006","N/A","N/A","Credential Access","https://gist.github.com/analyticsearch/7453d22d737e46657eb57c44d5cf4cbb","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","34399"
"*-b bleeding-jumbo*",".{0,1000}\-b\sbleeding\-jumbo.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","34407"
"*b016e0fb93032d4ab6f2fb2ec6388e3117442d836bed2fe38ae8b73d7b825c5e*",".{0,1000}b016e0fb93032d4ab6f2fb2ec6388e3117442d836bed2fe38ae8b73d7b825c5e.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","34413"
"*b016e0fb93032d4ab6f2fb2ec6388e3117442d836bed2fe38ae8b73d7b825c5e*",".{0,1000}b016e0fb93032d4ab6f2fb2ec6388e3117442d836bed2fe38ae8b73d7b825c5e.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","34414"
"*b095b574cadcf9fc517eedd434df402bdbf680f19ebe0c1298dd8f0818dfe5e8*",".{0,1000}b095b574cadcf9fc517eedd434df402bdbf680f19ebe0c1298dd8f0818dfe5e8.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","34434"
"*b096ce8b9397269012bccaef5a419211cb74d1157d4340453a3a39b68da7cf10*",".{0,1000}b096ce8b9397269012bccaef5a419211cb74d1157d4340453a3a39b68da7cf10.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","0","#filehash","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","34437"
"*b09a40f998e8bc112841842ed56d8e843e5df98f4b53657098924fd10325a4b9*",".{0,1000}b09a40f998e8bc112841842ed56d8e843e5df98f4b53657098924fd10325a4b9.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","0","#filehash","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","34440"
"*b09adb4d79fd71cba1d5c51c514d4a10e08f92fed9eca3637a2f68d6c2f8e835*",".{0,1000}b09adb4d79fd71cba1d5c51c514d4a10e08f92fed9eca3637a2f68d6c2f8e835.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","34441"
"*b0cf4ccee3c06fe7d3c7ff2afbfefbe972f82008ec5b2f8a5e5d5cb9a58861a2*",".{0,1000}b0cf4ccee3c06fe7d3c7ff2afbfefbe972f82008ec5b2f8a5e5d5cb9a58861a2.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#filehash","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","34451"
"*b10cfda1-f24f-441b-8f43-80cb93e786ec*",".{0,1000}b10cfda1\-f24f\-441b\-8f43\-80cb93e786ec.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#GUIDproject","N/A","10","10","N/A","N/A","N/A","N/A","34465"
"*b20f667c2539954744ddcb7f1d673c2a6dc0c4a934df45a3cca15a203a661c88*",".{0,1000}b20f667c2539954744ddcb7f1d673c2a6dc0c4a934df45a3cca15a203a661c88.{0,1000}","offensive_tool_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","34530"
"*b2383e05411ba4a0e24dbfc67e5e4e1ddeae37acdf1137bccbf8d190d13c78a5*",".{0,1000}b2383e05411ba4a0e24dbfc67e5e4e1ddeae37acdf1137bccbf8d190d13c78a5.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","#filehash","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","34539"
"*b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e*",".{0,1000}b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e.{0,1000}","offensive_tool_keyword","lslsass","dump active logon session password hashes from the lsass process (old tool for vista and older)","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","34549"
"*b264796db3513dbee419561215cb7c5863d70088dd5e8286829801bc72c27d0b*",".{0,1000}b264796db3513dbee419561215cb7c5863d70088dd5e8286829801bc72c27d0b.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","34557"
"*b2790bce687c664f57f7dc0c08ac27488506fd510bdf4cc20d87d03a22270c0f*",".{0,1000}b2790bce687c664f57f7dc0c08ac27488506fd510bdf4cc20d87d03a22270c0f.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","34561"
"*b2790bce687c664f57f7dc0c08ac27488506fd510bdf4cc20d87d03a22270c0f*",".{0,1000}b2790bce687c664f57f7dc0c08ac27488506fd510bdf4cc20d87d03a22270c0f.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","34562"
"*b2929f86fa6ae92dbbe1efe6e8523ed214beea67b52e6384ee22116689c0098e*",".{0,1000}b2929f86fa6ae92dbbe1efe6e8523ed214beea67b52e6384ee22116689c0098e.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","34570"
"*b2a02c9a9eb70c92a0af31a0485b345375b545a639f01e3cba8bdb5b09149662*",".{0,1000}b2a02c9a9eb70c92a0af31a0485b345375b545a639f01e3cba8bdb5b09149662.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","34575"
"*b350e1226b7d00487b47bec0f48320e85e3fb2546dc359cba3f2d77c75b5c599*",".{0,1000}b350e1226b7d00487b47bec0f48320e85e3fb2546dc359cba3f2d77c75b5c599.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","34621"
"*b3639781bbed6842e8168ad211da8d0d3ba32d47152c2bc2e57f056665232ddd*",".{0,1000}b3639781bbed6842e8168ad211da8d0d3ba32d47152c2bc2e57f056665232ddd.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","34625"
"*b3c2a6fe40c1c3688b2ea12b7211a3573f1fcfb0fc092e20826db40f8a2fba63*",".{0,1000}b3c2a6fe40c1c3688b2ea12b7211a3573f1fcfb0fc092e20826db40f8a2fba63.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","34652"
"*b3d7df3faa7bbeddf70a0c3cb586ce3d38aa1bfd787da67dd2338ec72a27bb74*",".{0,1000}b3d7df3faa7bbeddf70a0c3cb586ce3d38aa1bfd787da67dd2338ec72a27bb74.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","34659"
"*b3eba9d048c4b7cd8e01d81baa74daf0eb097f584c946ac0ab10ba08de1a8d7b*",".{0,1000}b3eba9d048c4b7cd8e01d81baa74daf0eb097f584c946ac0ab10ba08de1a8d7b.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","34663"
"*b3f9b4b2534e4e7cf71b72d5f37b0745e0f6eda8ecc81c1e4139319f4cd56b34*",".{0,1000}b3f9b4b2534e4e7cf71b72d5f37b0745e0f6eda8ecc81c1e4139319f4cd56b34.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","34668"
"*b41498d3c4883fb374dce5c9923c60b5ac901775909ae74d13a05851b80cc221*",".{0,1000}b41498d3c4883fb374dce5c9923c60b5ac901775909ae74d13a05851b80cc221.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","#filehash","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","34676"
"*b4ce5c82a51a7281bb0d04463c110471ca73f39813ed11c5c51d48d6cf7733e5*",".{0,1000}b4ce5c82a51a7281bb0d04463c110471ca73f39813ed11c5c51d48d6cf7733e5.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","0","#filehash","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","34729"
"*b4dba70d556511c9a7dbf152960bd1e72c9149142f694f87d2d53b63d61a0803*",".{0,1000}b4dba70d556511c9a7dbf152960bd1e72c9149142f694f87d2d53b63d61a0803.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","34733"
"*b4dba70d556511c9a7dbf152960bd1e72c9149142f694f87d2d53b63d61a0803*",".{0,1000}b4dba70d556511c9a7dbf152960bd1e72c9149142f694f87d2d53b63d61a0803.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","34734"
"*b4rtik/ATPMiniDump*",".{0,1000}b4rtik\/ATPMiniDump.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","1","N/A","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","34747"
"*b4rtik/SharpMiniDump*",".{0,1000}b4rtik\/SharpMiniDump.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","1","N/A","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","34750"
"*b5b0c796fe213a7f4a840d46a10ad4d36eb26521c19e026ae5f46b17f390b77a*",".{0,1000}b5b0c796fe213a7f4a840d46a10ad4d36eb26521c19e026ae5f46b17f390b77a.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","34799"
"*b670fbc71576142dedbc158f3b6b9e0a5889068759a13b2c8bdc14d1b85074a8*",".{0,1000}b670fbc71576142dedbc158f3b6b9e0a5889068759a13b2c8bdc14d1b85074a8.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","34851"
"*b683f658cc3320b969164f1dd01ce028c2a2e8f69ed56695415805cb601b96cc*",".{0,1000}b683f658cc3320b969164f1dd01ce028c2a2e8f69ed56695415805cb601b96cc.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","0","#filehash","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","34856"
"*b683f658cc3320b969164f1dd01ce028c2a2e8f69ed56695415805cb601b96cc*",".{0,1000}b683f658cc3320b969164f1dd01ce028c2a2e8f69ed56695415805cb601b96cc.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","0","#filehash","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","34857"
"*b68e24dd90e163f0048746d1c49d16f82e62608ac441df90c5f18b0b79b8b879*",".{0,1000}b68e24dd90e163f0048746d1c49d16f82e62608ac441df90c5f18b0b79b8b879.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","34861"
"*b6be69e72453d7363a2570495b36897124c72b2676351307f9d0d1b2a90f1b9d*",".{0,1000}b6be69e72453d7363a2570495b36897124c72b2676351307f9d0d1b2a90f1b9d.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","34876"
"*B7355478-EEE0-46A7-807A-23CF0C5295AE*",".{0,1000}B7355478\-EEE0\-46A7\-807A\-23CF0C5295AE.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","#GUIDproject","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","34913"
"*b7554de4073bb94a00faac4f83fc081f418158073d75ac53d06af29fde8efe9d*",".{0,1000}b7554de4073bb94a00faac4f83fc081f418158073d75ac53d06af29fde8efe9d.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","34921"
"*b7ac3213e10a169498f8e34b434aced491debb07d2e82c59c86f8c0c6581cf51*",".{0,1000}b7ac3213e10a169498f8e34b434aced491debb07d2e82c59c86f8c0c6581cf51.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","0","#filehash","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","34948"
"*b7b67e33ca53799aa1be6a7aa7677363b8a0e711091bccd2e49f501d5dc22de7*",".{0,1000}b7b67e33ca53799aa1be6a7aa7677363b8a0e711091bccd2e49f501d5dc22de7.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","#filehash","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","34952"
"*b875051a6d584b37810ea48923af45e20d1367adfa94266bfe47a1a35d76b03a*",".{0,1000}b875051a6d584b37810ea48923af45e20d1367adfa94266bfe47a1a35d76b03a.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#filehash","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","35008"
"*b91166d5623d4077003ae8527e9169092994f5c189c8a3820b32e204b4230578*",".{0,1000}b91166d5623d4077003ae8527e9169092994f5c189c8a3820b32e204b4230578.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#filehash","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","35048"
"*B92B6B67-C7C8-4548-85EE-A215D74C000D*",".{0,1000}B92B6B67\-C7C8\-4548\-85EE\-A215D74C000D.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#GUIDproject","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","35055"
"*b99078f0abc00a579cf218f3ed1d1ca89fffd5c328239303bf98432732df00f0*",".{0,1000}b99078f0abc00a579cf218f3ed1d1ca89fffd5c328239303bf98432732df00f0.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","#filehash","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","35083"
"*b9946bcbb56b9088f6d5ab8660665ea8f80c5f3d08df6e4531362653d07de2c9*",".{0,1000}b9946bcbb56b9088f6d5ab8660665ea8f80c5f3d08df6e4531362653d07de2c9.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","35087"
"*b9d705378ce1af446cc51bbbeccdda2d05bbc6b3c9249f3b69661d5f763dafaa*",".{0,1000}b9d705378ce1af446cc51bbbeccdda2d05bbc6b3c9249f3b69661d5f763dafaa.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","35098"
"*BA1F3992-9654-4424-A0CC-26158FDFBF74*",".{0,1000}BA1F3992\-9654\-4424\-A0CC\-26158FDFBF74.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","0","#GUIDProject","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","35110"
"*BA1F3992-9654-4424-A0CC-26158FDFBF74*",".{0,1000}BA1F3992\-9654\-4424\-A0CC\-26158FDFBF74.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","#GUIDProject","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","35111"
"*ba64c77b96c7de18007ca116ca8c8f93c3bba3cdc631e1a041e9d0afb46ae989*",".{0,1000}ba64c77b96c7de18007ca116ca8c8f93c3bba3cdc631e1a041e9d0afb46ae989.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","35120"
"*babelstrike.py -*",".{0,1000}babelstrike\.py\s\-.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","0","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","35146"
"*BabelStrike-main*",".{0,1000}BabelStrike\-main.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","1","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","35147"
"*Backdoor:Python/*",".{0,1000}Backdoor\:Python\/.{0,1000}","signature_keyword","Antivirus Signature","Antivirus signature - a tool used within a command-line interface on 64bit Windows computers to extract the NTLM (LanMan) hashes from LSASS.exe in memory. This tool may be used in conjunction with malware or other penetration testing tools to obtain credentials for use in Windows authentication systems","N/A","N/A","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","35196"
"*Bad password counts dont replicate between domain controllers. Only the PDC knows the real amount of those. Be sure to target the PDC so that accounts don't get locked out*",".{0,1000}Bad\spassword\scounts\sdont\sreplicate\sbetween\sdomain\scontrollers\.\sOnly\sthe\sPDC\sknows\sthe\sreal\samount\sof\sthose\.\sBe\ssure\sto\starget\sthe\sPDC\sso\sthat\saccounts\sdon\'t\sget\slocked\sout.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","35224"
"*bad0968b9492c3161ea9b67ecf8520054f90e6d196a7ea0050c8076b2ed2d2a2*",".{0,1000}bad0968b9492c3161ea9b67ecf8520054f90e6d196a7ea0050c8076b2ed2d2a2.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","35225"
"*bad19a193019cf92068c5cc4f95906a4e54744349ba8e303e6aee4324e95002d*",".{0,1000}bad19a193019cf92068c5cc4f95906a4e54744349ba8e303e6aee4324e95002d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","35226"
"*Bad-Pdf*",".{0,1000}Bad\-Pdf.{0,1000}","offensive_tool_keyword","Bad-PDF","Bad-PDF create malicious PDF file to steal NTLM(NTLMv1/NTLMv2) Hashes from windows machines. it utilize vulnerability disclosed by checkpoint team to create the malicious PDF file. Bad-Pdf reads the NTLM hashes using Responder listener.","T1566.001 - T1189 - T1068 - T1207 - T1048 - T1003","TA0001 - TA0002 - TA0003 - TA0009 - TA0010 - TA0011","N/A","N/A","Credential Access","https://github.com/deepzec/Bad-Pdf","1","1","N/A","N/A","N/A","10","1105","220","2020-08-19T06:54:51Z","2018-04-29T15:21:35Z","35247"
"*baf93de7d2d00045f677a77eeb729753c930f4d0be125a6f32db82cfe7592846*",".{0,1000}baf93de7d2d00045f677a77eeb729753c930f4d0be125a6f32db82cfe7592846.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","35280"
"*bb8a907ebbe611f271b35d461b15ccb8e90e36567e9963ea9a64ba4fe3d7d1bc*",".{0,1000}bb8a907ebbe611f271b35d461b15ccb8e90e36567e9963ea9a64ba4fe3d7d1bc.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","35368"
"*bbf4a68d05e79d8d2ce0bbd948a713ddafcb74b4ababa5f43c154592bc09e897*",".{0,1000}bbf4a68d05e79d8d2ce0bbd948a713ddafcb74b4ababa5f43c154592bc09e897.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","0","#filehash","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","35407"
"*bbfe2aee2092d981bd2822b8fde8db0ed264f0f86ed445d8987d99b505fd0ff5*",".{0,1000}bbfe2aee2092d981bd2822b8fde8db0ed264f0f86ed445d8987d99b505fd0ff5.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","0","#filehash","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","35410"
"*bc11b2b14526fef7b745fa22f0359235fab202060716f0c9544e4ef899c7312e*",".{0,1000}bc11b2b14526fef7b745fa22f0359235fab202060716f0c9544e4ef899c7312e.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","#filehash","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","35424"
"*bc600d653659564adc9f526dbba502d0b2fa47c82192b0c14fd25f45d81eec6d*",".{0,1000}bc600d653659564adc9f526dbba502d0b2fa47c82192b0c14fd25f45d81eec6d.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","0","#filehash","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","35444"
"*BCHASH-Rijndael-128.unverified.test-vectors.txt*",".{0,1000}BCHASH\-Rijndael\-128\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35504"
"*BCHASH-Rijndael-256.unverified.test-vectors.txt*",".{0,1000}BCHASH\-Rijndael\-256\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35505"
"*bd61c5daaad30b420817fb1fd2f0447c3b66a1900ba69fd4cd724d1e6897ab41*",".{0,1000}bd61c5daaad30b420817fb1fd2f0447c3b66a1900ba69fd4cd724d1e6897ab41.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","35535"
"*bd7552c78fd3f852e39b140051c4a1aa5a30a14e23eee49cfb570e19b4dbb0fa*",".{0,1000}bd7552c78fd3f852e39b140051c4a1aa5a30a14e23eee49cfb570e19b4dbb0fa.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","35545"
"*be76da790e34b58cd8f35913154aa4d4a749372918cd00324993370bd086ba5a*",".{0,1000}be76da790e34b58cd8f35913154aa4d4a749372918cd00324993370bd086ba5a.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","#filehash","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","35619"
"*be9b23c9cf6731a8ae3d288871d277e64ca0caa5020433c4516b58e10f5e641f*",".{0,1000}be9b23c9cf6731a8ae3d288871d277e64ca0caa5020433c4516b58e10f5e641f.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","35626"
"*be9cd67ca6ef0d87c8dacebef75d1f62b38cff5b8ba4ad2f0eb382ab54081317*",".{0,1000}be9cd67ca6ef0d87c8dacebef75d1f62b38cff5b8ba4ad2f0eb382ab54081317.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","35628"
"*BEBE6A01-0C03-4A7C-8FE9-9285F01C0B03*",".{0,1000}BEBE6A01\-0C03\-4A7C\-8FE9\-9285F01C0B03.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#GUIDproject","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","35745"
"*BEBE6A01-0C03-4A7C-8FE9-9285F01C0B03*",".{0,1000}BEBE6A01\-0C03\-4A7C\-8FE9\-9285F01C0B03.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#GUIDproject","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","35746"
"*bee3d0ac0967389571ea8e3a8c0502306b3dbf009e8155f00a2829417ac079fc*",".{0,1000}bee3d0ac0967389571ea8e3a8c0502306b3dbf009e8155f00a2829417ac079fc.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","35758"
"*bee3d0ac0967389571ea8e3a8c0502306b3dbf009e8155f00a2829417ac079fc*",".{0,1000}bee3d0ac0967389571ea8e3a8c0502306b3dbf009e8155f00a2829417ac079fc.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","35759"
"*bee3d0ac0967389571ea8e3a8c0502306b3dbf009e8155f00a2829417ac079fc*",".{0,1000}bee3d0ac0967389571ea8e3a8c0502306b3dbf009e8155f00a2829417ac079fc.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","35760"
"*bee3d0ac0967389571ea8e3a8c0502306b3dbf009e8155f00a2829417ac079fc*",".{0,1000}bee3d0ac0967389571ea8e3a8c0502306b3dbf009e8155f00a2829417ac079fc.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","35761"
"*bee821a0267335398f5db2ced5c2e2687ced844c8a1627d111d4fd0692b791e6*",".{0,1000}bee821a0267335398f5db2ced5c2e2687ced844c8a1627d111d4fd0692b791e6.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","0","#filehash","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","35762"
"*BernKing/ChromeStealer*",".{0,1000}BernKing\/ChromeStealer.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","1","N/A","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","35814"
"*BesoToken.exe list*",".{0,1000}BesoToken\.exe\slist.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","0","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","35820"
"*BesoToken-master*",".{0,1000}BesoToken\-master.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","1","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","35821"
"*besside-ng -W -v *",".{0,1000}besside\-ng\s\-W\s\-v\s.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","35822"
"*bestcrypt2john.py*",".{0,1000}bestcrypt2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35824"
"*bestcryptve2john.py*",".{0,1000}bestcryptve2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35825"
"*betterdefaultpasslist*",".{0,1000}betterdefaultpasslist.{0,1000}","offensive_tool_keyword","betterdefaultpasslist","list includes default credentials from various manufacturers for their products like NAS. ERP. ICS etc.. that are used for standard products like mssql. vnc. oracle and so on useful for network bruteforcing","T1110 - T1111 - T1112 - T1113 - T1114 - T1115 - T1116 - T1117 - T1118 - T1119","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/govolution/betterdefaultpasslist","1","1","N/A","N/A","N/A","7","605","134","2024-10-04T18:03:58Z","2016-09-24T16:21:44Z","35832"
"*bfa29dd2bd1a62ce4133eca34faa6f46005557eea07f3bf5c8b4afce8006160d*",".{0,1000}bfa29dd2bd1a62ce4133eca34faa6f46005557eea07f3bf5c8b4afce8006160d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","35877"
"*bfe768938d3186ff5a221c06902e18c4e67aa4d7c11b07aa54aeeb3746e31efe*",".{0,1000}bfe768938d3186ff5a221c06902e18c4e67aa4d7c11b07aa54aeeb3746e31efe.{0,1000}","offensive_tool_keyword","Dispossessor","Bruteforce tools used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","35894"
"*bfnaelmomeimhlpmgjnjophhpkkoljpa*",".{0,1000}bfnaelmomeimhlpmgjnjophhpkkoljpa.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","35901"
"*bhghoamapcdpbohphigoooaddinpkbai*",".{0,1000}bhghoamapcdpbohphigoooaddinpkbai.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","35907"
"*bhhhlbepdkbapadjdnnojkbgioiodbic*",".{0,1000}bhhhlbepdkbapadjdnnojkbgioiodbic.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","35908"
"*bHNhc3MuZXhl*",".{0,1000}bHNhc3MuZXhl.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#base64","base64 lsass.exe","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","35909"
"*bin/GoAWSConsoleSpray*",".{0,1000}bin\/GoAWSConsoleSpray.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","0","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","35926"
"*Binedx765ance Chaedx765in Waledx765let*",".{0,1000}Binedx765ance\sChaedx765in\sWaledx765let.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","35959"
"*bitcoin2john.py*",".{0,1000}bitcoin2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35964"
"*BitLockerToGo*.kdbx*",".{0,1000}BitLockerToGo.{0,1000}\.kdbx.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35966"
"*BitLockerToGo*\Network\Cookies*",".{0,1000}BitLockerToGo.{0,1000}\\Network\\Cookies.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35967"
"*BitLockerToGo*360Browser*",".{0,1000}BitLockerToGo.{0,1000}360Browser.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35968"
"*BitLockerToGo*Anydesk*",".{0,1000}BitLockerToGo.{0,1000}Anydesk.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35969"
"*BitLockerToGo*Binance*",".{0,1000}BitLockerToGo.{0,1000}Binance.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35970"
"*BitLockerToGo*Bitcoin*",".{0,1000}BitLockerToGo.{0,1000}Bitcoin.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35971"
"*BitLockerToGo*BraveSoftware*",".{0,1000}BitLockerToGo.{0,1000}BraveSoftware.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35972"
"*BitLockerToGo*CocCoc*",".{0,1000}BitLockerToGo.{0,1000}CocCoc.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35973"
"*BitLockerToGo*Coinomi*",".{0,1000}BitLockerToGo.{0,1000}Coinomi.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35974"
"*BitLockerToGo*ElectronCash*",".{0,1000}BitLockerToGo.{0,1000}ElectronCash.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35975"
"*BitLockerToGo*Electrum*",".{0,1000}BitLockerToGo.{0,1000}Electrum.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35976"
"*BitLockerToGo*Electrum*",".{0,1000}BitLockerToGo.{0,1000}Electrum.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35977"
"*BitLockerToGo*Electrum*",".{0,1000}BitLockerToGo.{0,1000}Electrum.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35978"
"*BitLockerToGo*Electrum*",".{0,1000}BitLockerToGo.{0,1000}Electrum.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35979"
"*BitLockerToGo*Epic Privacy Browser*",".{0,1000}BitLockerToGo.{0,1000}Epic\sPrivacy\sBrowser.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35980"
"*BitLockerToGo*Ethereum*",".{0,1000}BitLockerToGo.{0,1000}Ethereum.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35981"
"*BitLockerToGo*Exodus*",".{0,1000}BitLockerToGo.{0,1000}Exodus.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35982"
"*BitLockerToGo*Filezilla*",".{0,1000}BitLockerToGo.{0,1000}Filezilla.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://securelist.com/fake-captcha-delivers-lumma-amadey/114312/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35983"
"*BitLockerToGo*Ledger*",".{0,1000}BitLockerToGo.{0,1000}Ledger.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35984"
"*BitLockerToGo*MailBird*",".{0,1000}BitLockerToGo.{0,1000}MailBird.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35985"
"*BitLockerToGo*metamask*",".{0,1000}BitLockerToGo.{0,1000}metamask.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://www.cyfirma.com/research/lumma-stealer-tactics-impact-and-defense-strategies/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35986"
"*BitLockerToGo*telegram*",".{0,1000}BitLockerToGo.{0,1000}telegram.{0,1000}","greyware_tool_keyword","BitLockerToGo","BitLocker To Go is legitimate Windows utility used for managing BitLocker encryption - abused by Malware like LummaSteale to manipulate registry keys - search for cryptocurrency wallets and credentials and exfiltrate sensitive data","T1218 - T1055 - T1112 - T1056 - T1555","TA0005 - TA0007 - TA0009","Lumma Stealer","N/A","Credential Access","https://securelist.com/fake-captcha-delivers-lumma-amadey/114312/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","35987"
"*bitsadmin/fakelogonscreen*",".{0,1000}bitsadmin\/fakelogonscreen.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","35993"
"*bitshares2john.py*",".{0,1000}bitshares2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35997"
"*bitwarden2john.py*",".{0,1000}bitwarden2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","35998"
"*bks2john.py*",".{0,1000}bks2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","36007"
"*blacklanternsecurity/trevorproxy*",".{0,1000}blacklanternsecurity\/trevorproxy.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","36019"
"*blacklanternsecurity/TREVORspray*",".{0,1000}blacklanternsecurity\/TREVORspray.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","36020"
"*Blank Grabber [Builder]""",".{0,1000}Blank\sGrabber\s\[Builder\]\""","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","36032"
"*Blank Grabber [Fake Error Builder]""",".{0,1000}Blank\sGrabber\s\[Fake\sError\sBuilder\]\""","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","36033"
"*Blank Grabber [File Pumper]""",".{0,1000}Blank\sGrabber\s\[File\sPumper\]\""","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","36034"
"*Blank-c/Blank-Grabber*",".{0,1000}Blank\-c\/Blank\-Grabber.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","1","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","36035"
"*BlankOBF v2: Obfuscates Python code to make it unreadable and hard to reverse*",".{0,1000}BlankOBF\sv2\:\sObfuscates\sPython\scode\sto\smake\sit\sunreadable\sand\shard\sto\sreverse.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","36038"
"*blendin/3snake*",".{0,1000}blendin\/3snake.{0,1000}","offensive_tool_keyword","3snake","Tool for extracting information from newly spawned processes","T1003 - T1110 - T1552 - T1505","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/blendin/3snake","1","1","N/A","N/A","7","8","752","109","2022-02-14T17:42:10Z","2018-02-07T21:03:15Z","36040"
"*blockchain2john.py*",".{0,1000}blockchain2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","36045"
"*BloodHound ZIP File identified, extracting*",".{0,1000}BloodHound\sZIP\sFile\sidentified,\sextracting.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","36063"
"*bmarchev/Forensike*",".{0,1000}bmarchev\/Forensike.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","1","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","36100"
"*Brex765ave-Broedx765wser\\Usedx765er Data*",".{0,1000}Brex765ave\-Broedx765wser\\\\Usedx765er\sData.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","36232"
"*BrowserDataGrabber.exe*",".{0,1000}BrowserDataGrabber\.exe.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","1","N/A","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","36248"
"*BrowserDataGrabber-master.zip*",".{0,1000}BrowserDataGrabber\-master\.zip.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","1","N/A","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","36249"
"*BrowserGhost.exe*",".{0,1000}BrowserGhost\.exe.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","36251"
"*Browser-password-stealer.git*",".{0,1000}Browser\-password\-stealer\.git.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","1","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","36254"
"*Browser-password-stealer-master*",".{0,1000}Browser\-password\-stealer\-master.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","1","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","36255"
"*Brute forcing passwords for *",".{0,1000}Brute\sforcing\spasswords\sfor\s.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","0","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","36273"
"*brute_force_ntlm.sh*",".{0,1000}brute_force_ntlm\.sh.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","36278"
"*bruteforce *.txt*",".{0,1000}bruteforce\s.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","36279"
"*bruteforce.go*",".{0,1000}bruteforce\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","36281"
"*bruteforce_attack(*",".{0,1000}bruteforce_attack\(.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","36285"
"*bruteforce_mode_kerberos_mode*",".{0,1000}bruteforce_mode_kerberos_mode.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","36286"
"*bruteforce_mode_ntlm_mode*",".{0,1000}bruteforce_mode_ntlm_mode.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","36287"
"*bruteforce_try_password_or_hash(*",".{0,1000}bruteforce_try_password_or_hash\(.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","36288"
"*bruteforce_try_user(*",".{0,1000}bruteforce_try_user\(.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","36289"
"*bruteForceCombos*",".{0,1000}bruteForceCombos.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","36291"
"*Brute-force-Instagram-*.git*",".{0,1000}Brute\-force\-Instagram\-.{0,1000}\.git.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","1","N/A","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","36292"
"*bruteForceUser*",".{0,1000}bruteForceUser.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","36296"
"*brutespray -*",".{0,1000}brutespray\s\-.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","36308"
"*brutespray.exe*",".{0,1000}brutespray.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","36309"
"*brutespray.go*",".{0,1000}brutespray\.go.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","36310"
"*brutespray/brute*",".{0,1000}brutespray\/brute.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","36311"
"*brutespray-output*",".{0,1000}brutespray\-output.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","36312"
"*bruteuser.go*",".{0,1000}bruteuser\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","36315"
"*bruteuserCmd*",".{0,1000}bruteuserCmd.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","36316"
"*BruteX*",".{0,1000}BruteX.{0,1000}","offensive_tool_keyword","BruteX","Automatically brute force all services running on a target. Open ports. Usernames Passwords","T1110","TA0007 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/1N3/BruteX","1","0","N/A","N/A","10","10","2066","613","2024-08-18T23:18:37Z","2015-06-01T22:28:19Z","36317"
"*BTW i use ARCH. A - Jeffrey Epstein. R - didnt. C - kill. H - himself*",".{0,1000}BTW\si\suse\sARCH\.\sA\s\-\sJeffrey\sEpstein\.\sR\s\-\sdidnt\.\sC\s\-\skill\.\sH\s\-\shimself.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","36330"
"*bugch3ck/SharpAltSecIds*",".{0,1000}bugch3ck\/SharpAltSecIds.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","1","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","36342"
"*Build Evil Lsass Twin*",".{0,1000}Build\sEvil\sLsass\sTwin.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","36344"
"*Build with love for POC only*",".{0,1000}Build\swith\slove\sfor\sPOC\sonly.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","36350"
"*Building Evil Lsass Twin*",".{0,1000}Building\sEvil\sLsass\sTwin.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","36386"
"*BulletsPassView.exe*",".{0,1000}BulletsPassView\.exe.{0,1000}","offensive_tool_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36390"
"*BulletsPassView.zip*",".{0,1000}BulletsPassView\.zip.{0,1000}","offensive_tool_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36391"
"*BulletsPassView_setup.exe*",".{0,1000}BulletsPassView_setup\.exe.{0,1000}","offensive_tool_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36392"
"*BulletsPassView_x64.exe*",".{0,1000}BulletsPassView_x64\.exe.{0,1000}","offensive_tool_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","36393"
"*BurpSuite-SecretFinder*",".{0,1000}BurpSuite\-SecretFinder.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","1","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","36423"
"*by @ricardojoserf*",".{0,1000}by\s\@ricardojoserf.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","36436"
"*By b4rtik & uf0*",".{0,1000}By\sb4rtik\s\&\suf0.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","0","#content","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","36437"
"*By Cneeliz @Outflank 2019*",".{0,1000}By\sCneeliz\s\@Outflank\s2019.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#content","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","36439"
"*byinarie/teams_dump*",".{0,1000}byinarie\/teams_dump.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1560.001 - T1555.003 - T1113 - T1557","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","7","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","36442"
"*byinarie/teams_dump*",".{0,1000}byinarie\/teams_dump.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","36443"
"*BypassCredGuard/zipball*",".{0,1000}BypassCredGuard\/zipball.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","36473"
"*BypassCredGuard-master*",".{0,1000}BypassCredGuard\-master.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","36474"
"*byt3bl33d3r/DeathStar*",".{0,1000}byt3bl33d3r\/DeathStar.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","36515"
"*byt3bl33d3r/SprayingToolkit*",".{0,1000}byt3bl33d3r\/SprayingToolkit.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","36523"
"*C:\\SPRAY_*.dmp*",".{0,1000}C\:\\\\SPRAY_.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","36543"
"*C:\\temp\\debug.dmp*",".{0,1000}C\:\\\\temp\\\\debug\.dmp.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","36544"
"*C:\\Users\\DARKN3T\\Downloads*",".{0,1000}C\:\\\\Users\\\\DARKN3T\\\\Downloads.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","36548"
"*C:\\Users\\Public\\callback.el*",".{0,1000}C\:\\\\Users\\\\Public\\\\callback\.el.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","36550"
"*C:\kernel.dmp*",".{0,1000}C\:\\kernel\.dmp.{0,1000}","offensive_tool_keyword","DumpKernel-S1.ps1","SentinelHelper to perform a live kernel dump in a Windows environment","T1055 - T1003 - T1112","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8f29e09d74b73e1dec3f9049c4358e80","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","36571"
"*C:\SPRAY_*.dmp*",".{0,1000}C\:\\SPRAY_.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","36579"
"*c:\temp\nc.exe*",".{0,1000}c\:\\temp\\nc\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","36588"
"*C:\Users\*\lsass_*.dmp*",".{0,1000}C\:\\Users\\.{0,1000}\\lsass_.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","0","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","36597"
"*C:\Users\Public\backup.enc*",".{0,1000}C\:\\Users\\Public\\backup\.enc.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","36602"
"*C:\Users\Public\syslog.dat*",".{0,1000}C\:\\Users\\Public\\syslog\.dat.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","36608"
"*C:\Users\Public\syslog.zip*",".{0,1000}C\:\\Users\\Public\\syslog\.zip.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","36609"
"*c:\windows\temp\test.tmp farmer*",".{0,1000}c\:\\windows\\temp\\test\.tmp\sfarmer.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","0","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","36626"
"*c03ef8106c58c8980b7859e0a8ee2363d70e2b7f1346356127c826faf2c0caa3*",".{0,1000}c03ef8106c58c8980b7859e0a8ee2363d70e2b7f1346356127c826faf2c0caa3.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","36651"
"*c04b117bc1e5883c3c85ab2823071b33dbf1344e581e250fa5d80a8fae6b338b*",".{0,1000}c04b117bc1e5883c3c85ab2823071b33dbf1344e581e250fa5d80a8fae6b338b.{0,1000}","offensive_tool_keyword","ADFSDump-PS","ADFSDump to assist with GoldenSAML","T1078 - T1552.004 - T1558.004","TA0006 ","N/A","N/A","Credential Access","https://github.com/ZephrFish/ADFSDump-PS","1","0","#filehash","N/A","10","1","31","8","2024-05-20T00:00:19Z","2024-05-19T00:46:28Z","36655"
"*c07272b6a537d203f886cd195e1ad2def64123c52c61a5d0652b26f1b288553d*",".{0,1000}c07272b6a537d203f886cd195e1ad2def64123c52c61a5d0652b26f1b288553d.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","36667"
"*c0fdcce36afa206ce080c1b8602ecf18fdc23a207078cb437594d7f674b2a693*",".{0,1000}c0fdcce36afa206ce080c1b8602ecf18fdc23a207078cb437594d7f674b2a693.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#filehash","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","36705"
"*C13C80ED-ED7A-4F27-93B1-DE6FD30A7B43*",".{0,1000}C13C80ED\-ED7A\-4F27\-93B1\-DE6FD30A7B43.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","0","#GUIDproject","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","36721"
"*c18989d8b80f11117c403bc1c8f8afac0a807f1acdf67ecffcf50402164c11eb*",".{0,1000}c18989d8b80f11117c403bc1c8f8afac0a807f1acdf67ecffcf50402164c11eb.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","36739"
"*c1a30c8a226a6099fa0fc3d39e1fe4e83763ad52c41675b607ab569b7957f8a7*",".{0,1000}c1a30c8a226a6099fa0fc3d39e1fe4e83763ad52c41675b607ab569b7957f8a7.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","36744"
"*c1f971aa959ea7722c8bc41a6677ad83230e129d69424c16835c3d000756582e*",".{0,1000}c1f971aa959ea7722c8bc41a6677ad83230e129d69424c16835c3d000756582e.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","#filehash","N/A","10","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","36763"
"*c1fb599493390e17676176219c5cdd8f4b4bca43696b6a54ded88c9b28f741ff*",".{0,1000}c1fb599493390e17676176219c5cdd8f4b4bca43696b6a54ded88c9b28f741ff.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","#filehash","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","36764"
"*C23B51C4-2475-4FC6-9B3A-27D0A2B99B0F*",".{0,1000}C23B51C4\-2475\-4FC6\-9B3A\-27D0A2B99B0F.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#GUIDproject","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","36791"
"*c23c160ea84911fa0041045b64551322f282d2d68b5c2689c4bd992c2f7c9267*",".{0,1000}c23c160ea84911fa0041045b64551322f282d2d68b5c2689c4bd992c2f7c9267.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","36792"
"*c2635225a206bbd00ab89ef7e8418acdee38e2f2969be43c9d04031f3fbb0e14*",".{0,1000}c2635225a206bbd00ab89ef7e8418acdee38e2f2969be43c9d04031f3fbb0e14.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","36803"
"*c2635225a206bbd00ab89ef7e8418acdee38e2f2969be43c9d04031f3fbb0e14*",".{0,1000}c2635225a206bbd00ab89ef7e8418acdee38e2f2969be43c9d04031f3fbb0e14.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","36804"
"*c299346734b17df1a8dc47d97145c756938307fbd249837ff4dc697befd2961b*",".{0,1000}c299346734b17df1a8dc47d97145c756938307fbd249837ff4dc697befd2961b.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","0","#filehash","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","36819"
"*c2a640190d6567ec2b613cb2f3a37496a4df5450c577e4326b13457f69ba7160*",".{0,1000}c2a640190d6567ec2b613cb2f3a37496a4df5450c577e4326b13457f69ba7160.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","36822"
"*c2db7182d606ef3d00a40360e62f16a47aea5d39872bb5bab4b115d4da864394*",".{0,1000}c2db7182d606ef3d00a40360e62f16a47aea5d39872bb5bab4b115d4da864394.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","36834"
"*c35aa22a683405cb282d97f125cb785cd7767591c96f4d00a27e5ac92b494f6c*",".{0,1000}c35aa22a683405cb282d97f125cb785cd7767591c96f4d00a27e5ac92b494f6c.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","#filehash","N/A","10","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","36910"
"*c3b7a095eb5860b4414e354becc07bf30a9133737164b89b689873ee9f9c7bd6*",".{0,1000}c3b7a095eb5860b4414e354becc07bf30a9133737164b89b689873ee9f9c7bd6.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","36943"
"*c4abc4537dc209944170e16642c57b9c0d97d9de38557ee3ed3ac27ee68f9b91*",".{0,1000}c4abc4537dc209944170e16642c57b9c0d97d9de38557ee3ed3ac27ee68f9b91.{0,1000}","offensive_tool_keyword","Credphisher","prompt a user for credentials using a Windows credential dialog","T1056.002 - T1003 ","TA0006","N/A","N/A","Credential Access","https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher","1","0","#filehash","N/A","7","2","136","34","2024-10-18T12:12:38Z","2021-04-12T00:00:03Z","37000"
"*C4RD N4M3: *| NUMB3R:*",".{0,1000}C4RD\sN4M3\:\s.{0,1000}\|\sNUMB3R\:.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","37031"
"*C50B26839FCDA18B4DB6560EB826E94C*",".{0,1000}C50B26839FCDA18B4DB6560EB826E94C.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#imphash","N/A","10","10","N/A","N/A","N/A","N/A","37035"
"*c5cb049d25fab0401c450f94a536898884681ee07c56b485ba4c6066b1dae710*",".{0,1000}c5cb049d25fab0401c450f94a536898884681ee07c56b485ba4c6066b1dae710.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","37098"
"*c5cb049d25fab0401c450f94a536898884681ee07c56b485ba4c6066b1dae710*",".{0,1000}c5cb049d25fab0401c450f94a536898884681ee07c56b485ba4c6066b1dae710.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","37099"
"*C666C98C-84C3-4A5A-A73B-2FC711CFCB7F*",".{0,1000}C666C98C\-84C3\-4A5A\-A73B\-2FC711CFCB7F.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#GUIDproject","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","37133"
"*c672719ea7d0abfbf7b69605b975d697afeb5cad770e9cb68e57ee18d7e598d1*",".{0,1000}c672719ea7d0abfbf7b69605b975d697afeb5cad770e9cb68e57ee18d7e598d1.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","37139"
"*c749894ea43c267418df93c7dd6b74ef25826d6c4a5461226ec800ae2efd1921*",".{0,1000}c749894ea43c267418df93c7dd6b74ef25826d6c4a5461226ec800ae2efd1921.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","0","#filehash","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","37200"
"*c7600f446daa53037a63ad765e0873a9c45adfd8944e5fee1c1586936ecf2928*",".{0,1000}c7600f446daa53037a63ad765e0873a9c45adfd8944e5fee1c1586936ecf2928.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","#filehash","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","37205"
"*C7A0003B-98DC-4D57-8F09-5B90AAEFBDF4*",".{0,1000}C7A0003B\-98DC\-4D57\-8F09\-5B90AAEFBDF4.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","0","#GUIDproject","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","37223"
"*C7A0003B-98DC-4D57-8F09-5B90AAEFBDF4*",".{0,1000}C7A0003B\-98DC\-4D57\-8F09\-5B90AAEFBDF4.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#GUIDproject","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","37224"
"*c7b633d9ffcddd84074219649dae082184e2331c07b395db5e2ffa9abe316355*",".{0,1000}c7b633d9ffcddd84074219649dae082184e2331c07b395db5e2ffa9abe316355.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","37229"
"*c7c8b6fb-4e59-494e-aeeb-40cf342a7e88*",".{0,1000}c7c8b6fb\-4e59\-494e\-aeeb\-40cf342a7e88.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","0","#GUIDproject","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","37238"
"*c7d3092d358e4828259d3b137eec1edeab112e2a70920c5912c76724e956ba47*",".{0,1000}c7d3092d358e4828259d3b137eec1edeab112e2a70920c5912c76724e956ba47.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","37240"
"*c7d41f5a0fe15661632d70cde6b34787f87e4818d7c592ffa0c5b074fdb15712*",".{0,1000}c7d41f5a0fe15661632d70cde6b34787f87e4818d7c592ffa0c5b074fdb15712.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","0","#filehash #linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","37241"
"*c862cc7e0faabfff2c8e8e58cf7fca200ae534aa5f58857331d1377187a19d3a*",".{0,1000}c862cc7e0faabfff2c8e8e58cf7fca200ae534aa5f58857331d1377187a19d3a.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","0","#filehash","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","37282"
"*c86c8e44048907b077f48cfb1d2de1eee216ff699e3a6ce240b6d107b7a6f128*",".{0,1000}c86c8e44048907b077f48cfb1d2de1eee216ff699e3a6ce240b6d107b7a6f128.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","37285"
"*c86c8e44048907b077f48cfb1d2de1eee216ff699e3a6ce240b6d107b7a6f128*",".{0,1000}c86c8e44048907b077f48cfb1d2de1eee216ff699e3a6ce240b6d107b7a6f128.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","37286"
"*c8808822c7f2fb60db3809d0700f739e39dca8c3d4918d01daa696ef8ed6a819*",".{0,1000}c8808822c7f2fb60db3809d0700f739e39dca8c3d4918d01daa696ef8ed6a819.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","37297"
"*c88d86aee55b31827ab4782d05bd44922276955909c43c69f0fb15377cc64374*",".{0,1000}c88d86aee55b31827ab4782d05bd44922276955909c43c69f0fb15377cc64374.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","37304"
"*c92580318be4effdb37aa67145748826f6a9e285bc2426410dc280e61e3c7620*",".{0,1000}c92580318be4effdb37aa67145748826f6a9e285bc2426410dc280e61e3c7620.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","37340"
"*c9598fe89c9f4ca470ce47b556fea6289b05b1850c629c2c2f51f2efc995247c*",".{0,1000}c9598fe89c9f4ca470ce47b556fea6289b05b1850c629c2c2f51f2efc995247c.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","37359"
"*c96ef7d84ab7d43b03330daf4e78c11aa9407662f4a18d1824fa1506694c8c56*",".{0,1000}c96ef7d84ab7d43b03330daf4e78c11aa9407662f4a18d1824fa1506694c8c56.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#filehash","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","37363"
"*c97df5d25ea1e9ed5b95606adc492cfb6d4fe97e2a538fcaef0ea66f1a239e64*",".{0,1000}c97df5d25ea1e9ed5b95606adc492cfb6d4fe97e2a538fcaef0ea66f1a239e64.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","#filehash","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","37366"
"*c97e849bf283c760811373be29c588adc6ad820d7695a7552e87be693bea0ee6*",".{0,1000}c97e849bf283c760811373be29c588adc6ad820d7695a7552e87be693bea0ee6.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","#filehash","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","37368"
"*ca698d8da51b0df3302f8e8593f3fceecf8c513d92a73bc3b585363a4d09bc61*",".{0,1000}ca698d8da51b0df3302f8e8593f3fceecf8c513d92a73bc3b585363a4d09bc61.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","37445"
"*ca8e5157e4c093be717f36225fc1fb1fb4ffb1cf404cc9738c9a9fb7d41da29d*",".{0,1000}ca8e5157e4c093be717f36225fc1fb1fb4ffb1cf404cc9738c9a9fb7d41da29d.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","37457"
"*caadd01f003376a0d92f5bcc416a1702802c5c1072907644e29f39fb2c6c513c*",".{0,1000}caadd01f003376a0d92f5bcc416a1702802c5c1072907644e29f39fb2c6c513c.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","37469"
"*cace36a7ea185c8a675356f6e3eeb5b1d466666f7853aa9813df486c5178cbdf*",".{0,1000}cace36a7ea185c8a675356f6e3eeb5b1d466666f7853aa9813df486c5178cbdf.{0,1000}","greyware_tool_keyword","MozillaCookiesView","nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors","T1070 - T1552.001 - T1125 - T1005","TA0009 - TA0005","N/A","MuddyWater","Credential Access","https://www.nirsoft.net/utils/mzcv.html","1","0","#filehash","N/A","7","10","N/A","N/A","N/A","N/A","37486"
"*CacheDump service successfully installed*",".{0,1000}CacheDump\sservice\ssuccessfully\sinstalled.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#content","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","37489"
"*cachedump.exe*",".{0,1000}cachedump\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","37490"
"*cachedump64.exe*",".{0,1000}cachedump64\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","37492"
"*CallDllMainSC1/ThisIsNotTheStringYouAreLookingFor*",".{0,1000}CallDllMainSC1\/ThisIsNotTheStringYouAreLookingFor.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","0","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","37539"
"*Cancelling the password spray.*",".{0,1000}Cancelling\sthe\spassword\sspray\..{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","37548"
"*can-kat/cstealer*",".{0,1000}can\-kat\/cstealer.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","1","N/A","N/A","10","","N/A","","","","37551"
"*Cannot enable SE_DEBUG_NAME privilege on remote host*",".{0,1000}Cannot\senable\sSE_DEBUG_NAME\sprivilege\son\sremote\shost.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","37552"
"*Cannot enumerate SAM objects*",".{0,1000}Cannot\senumerate\sSAM\sobjects.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","37555"
"*Cannot get LSASS PID on remote host*",".{0,1000}Cannot\sget\sLSASS\sPID\son\sremote\shost.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","37556"
"*Cannot load SAM functions on remote host*",".{0,1000}Cannot\sload\sSAM\sfunctions\son\sremote\shost.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","37557"
"*Cannot open LSA policy on remote host*",".{0,1000}Cannot\sopen\sLSA\spolicy\son\sremote\shost.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","37558"
"*Cannot open registry key HKLM\SECURITY\Policy\Secrets on remote host*",".{0,1000}Cannot\sopen\sregistry\skey\sHKLM\\SECURITY\\Policy\\Secrets\son\sremote\shost.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","37559"
"*Cannot open SAM on remote host*",".{0,1000}Cannot\sopen\sSAM\son\sremote\shost.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","37560"
"*Can't find DHCP Server PID. Exiting.*",".{0,1000}Can\'t\sfind\sDHCP\sServer\sPID\.\sExiting\..{0,1000}","offensive_tool_keyword","StealDhcpSecrets","DHCP Server DNS Password Stealer","T1552 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/tree/master/PasswordStealing/DHCP","1","0","#content","content","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","37563"
"*capturetokenphish.ps1*",".{0,1000}capturetokenphish\.ps1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","37574"
"*capturetokenphish.py*",".{0,1000}capturetokenphish\.py.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","37575"
"*cardano2john.py*",".{0,1000}cardano2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","37578"
"*cat *bash-history*",".{0,1000}cat\s.{0,1000}bash\-history.{0,1000}","greyware_tool_keyword","cat","linux commands abused by attackers","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","37603"
"*cat /etc/passwd*",".{0,1000}cat\s\/etc\/passwd.{0,1000}","greyware_tool_keyword","cat","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","37612"
"*cat /etc/shadow*",".{0,1000}cat\s\/etc\/shadow.{0,1000}","greyware_tool_keyword","cat","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","37613"
"*cat /etc/sudoers*",".{0,1000}cat\s\/etc\/sudoers.{0,1000}","greyware_tool_keyword","cat","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","37616"
"*cb4490df575c59cc338804d8401be9782981fa7a5e9785a03781a3c135a8d837*",".{0,1000}cb4490df575c59cc338804d8401be9782981fa7a5e9785a03781a3c135a8d837.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","37655"
"*CB790E12-603E-4C7C-9DC1-14A50819AF8C*",".{0,1000}CB790E12\-603E\-4C7C\-9DC1\-14A50819AF8C.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#GUIDproject","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","37673"
"*cb8f501c3b38552612b6303dfec0479df31b9c79a5fbec5462614f9a1d7eba67*",".{0,1000}cb8f501c3b38552612b6303dfec0479df31b9c79a5fbec5462614f9a1d7eba67.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","37676"
"*cba64638575e382bab065f43dc60b76943bce77854a80af38debeb803edb96e4*",".{0,1000}cba64638575e382bab065f43dc60b76943bce77854a80af38debeb803edb96e4.{0,1000}","offensive_tool_keyword","VNCPassView","recover the passwords stored by the VNC tool","T1003 - T1555 - T1081","TA0006 - TA0007","N/A","GoGoogle - 8BASE","Credential Access","https://www.nirsoft.net/utils/vnc_password.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","37682"
"*cba7954a3a44198ede1f02ab8b4ce571d089b72b1dab61bd5cf004958a5e1172*",".{0,1000}cba7954a3a44198ede1f02ab8b4ce571d089b72b1dab61bd5cf004958a5e1172.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","0","#filehash","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","37684"
"*cbec6150e83403631fe741f0c50e516170279645c246638b0148e1b87c0848e7*",".{0,1000}cbec6150e83403631fe741f0c50e516170279645c246638b0148e1b87c0848e7.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","37698"
"*cc24850f03dccbd8ee3a372b06b2a77a95e5314bb68d2483b1814935978b7003*",".{0,1000}cc24850f03dccbd8ee3a372b06b2a77a95e5314bb68d2483b1814935978b7003.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","#filehash","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","37730"
"*cc585d962904351ce1d92195b0fc79034dc3b13144f7c7ff24cd9f768b25e9ef*",".{0,1000}cc585d962904351ce1d92195b0fc79034dc3b13144f7c7ff24cd9f768b25e9ef.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","37750"
"*cc585d962904351ce1d92195b0fc79034dc3b13144f7c7ff24cd9f768b25e9ef*",".{0,1000}cc585d962904351ce1d92195b0fc79034dc3b13144f7c7ff24cd9f768b25e9ef.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","37751"
"*cc81272307a9b746b67a9e9a52fbe5bc1f70f75c869480b517e16f34e20b80f5*",".{0,1000}cc81272307a9b746b67a9e9a52fbe5bc1f70f75c869480b517e16f34e20b80f5.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","37762"
"*cc8ca4e1e0d6613bd6f040f098f59ff05cea4b9ca74262ec7319ce9846e51a6e*",".{0,1000}cc8ca4e1e0d6613bd6f040f098f59ff05cea4b9ca74262ec7319ce9846e51a6e.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","37767"
"*cc9d7b88c9fe25358764727439bc55d5df36dc828b2b620b05c9b6129109588a*",".{0,1000}cc9d7b88c9fe25358764727439bc55d5df36dc828b2b620b05c9b6129109588a.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#filehash","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","37773"
"*ccache2john.py*",".{0,1000}ccache2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","37779"
"*ccache2john.py*",".{0,1000}ccache2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","37780"
"*ccb9d0f9cd95c1665d9646771f7e21af912106f7cc7541c338552b66ca0df512*",".{0,1000}ccb9d0f9cd95c1665d9646771f7e21af912106f7cc7541c338552b66ca0df512.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","37788"
"*CCob/lsarelayx*",".{0,1000}CCob\/lsarelayx.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","1","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","37816"
"*CCob/MirrorDump*",".{0,1000}CCob\/MirrorDump.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","1","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","37817"
"*CCob/Shwmae*",".{0,1000}CCob\/Shwmae.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","1","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","37818"
"*CD517B47-6CA1-4AC3-BC37-D8A27F2F03A0*",".{0,1000}CD517B47\-6CA1\-4AC3\-BC37\-D8A27F2F03A0.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","0","#GUIDproject","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","37861"
"*cd7e4cd71cb803de24f7b8fc6c6946f96e9b9a95dd3c0888309b42446ba87b94*",".{0,1000}cd7e4cd71cb803de24f7b8fc6c6946f96e9b9a95dd3c0888309b42446ba87b94.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#filehash","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","37873"
"*CD8FD3D4-15FD-489C-A334-91F551B98022*",".{0,1000}CD8FD3D4\-15FD\-489C\-A334\-91F551B98022.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#GUIDproject","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","37882"
"*cd9c66c8-8fcb-4d43-975b-a9c8d02ad090*",".{0,1000}cd9c66c8\-8fcb\-4d43\-975b\-a9c8d02ad090.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","0","#GUIDproject","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","37886"
"*CDC4F57A-A3F7-459B-87BF-6219DADF6284*",".{0,1000}CDC4F57A\-A3F7\-459B\-87BF\-6219DADF6284.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#GUIDProject","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","37899"
"*cdcb96e58514e182d0799884b64872caff34ed0eb552d842015941a7540347e7*",".{0,1000}cdcb96e58514e182d0799884b64872caff34ed0eb552d842015941a7540347e7.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","37901"
"*ce0ae1416a4841144e8a377eed2a11fef988b08042606bac8121b4a4abd5391e*",".{0,1000}ce0ae1416a4841144e8a377eed2a11fef988b08042606bac8121b4a4abd5391e.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","0","#filehash","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","37934"
"*ce4255704740f395be5713b049b97814ce537c440b1249850bcb62794dcc7f56*",".{0,1000}ce4255704740f395be5713b049b97814ce537c440b1249850bcb62794dcc7f56.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","0","#filehash","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","37951"
"*ce4abd249e1f6497549ca7a2e814c8232f42597ce8b02f77fd3dde31a723a501*",".{0,1000}ce4abd249e1f6497549ca7a2e814c8232f42597ce8b02f77fd3dde31a723a501.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","37954"
"*ce8cdc354e0ff5b4aa329e1ef3e55aaabfcb1a592c697b327e93b59f5ae9a217*",".{0,1000}ce8cdc354e0ff5b4aa329e1ef3e55aaabfcb1a592c697b327e93b59f5ae9a217.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","37974"
"*cerbrutus.py*",".{0,1000}cerbrutus\.py.{0,1000}","offensive_tool_keyword","cerbrutus","Network brute force tool. written in Python. Faster than other existing solutions (including the main leader in the network brute force market).","T1110 - T1040 - T1496","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/Cerbrutus-BruteForcer/cerbrutus","1","1","N/A","N/A","N/A","4","385","57","2021-08-22T19:05:45Z","2021-07-07T19:11:40Z","37998"
"*Cerbrutus-BruteForcer*",".{0,1000}Cerbrutus\-BruteForcer.{0,1000}","offensive_tool_keyword","cerbrutus","Network brute force tool. written in Python. Faster than other existing solutions (including the main leader in the network brute force market).","T1110 - T1040 - T1496","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/Cerbrutus-BruteForcer/cerbrutus","1","1","N/A","N/A","N/A","4","385","57","2021-08-22T19:05:45Z","2021-07-07T19:11:40Z","37999"
"*Certipy not found. Please install Certipy before running ADCSync*",".{0,1000}Certipy\snot\sfound\.\sPlease\sinstall\sCertipy\sbefore\srunning\sADCSync.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","0","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","38016"
"*certipy req -u * -p * -target-ip * -dc-ip * -ca *",".{0,1000}certipy\sreq\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-target\-ip\s.{0,1000}\s\-dc\-ip\s.{0,1000}\s\-ca\s.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","0","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","38020"
"*certsync *--dc-ip*",".{0,1000}certsync\s.{0,1000}\-\-dc\-ip.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","0","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","38031"
"*certsync -u *",".{0,1000}certsync\s\-u\s.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","0","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","38032"
"*certsync-master.zip*",".{0,1000}certsync\-master\.zip.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","1","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","38035"
"*cf0ef69e85418ec61f9200a26553738987c546710243bfae6c86b25edfdb5651*",".{0,1000}cf0ef69e85418ec61f9200a26553738987c546710243bfae6c86b25edfdb5651.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","38044"
"*CF924967-0AEC-43B2-B891-D67B6DB9F523*",".{0,1000}CF924967\-0AEC\-43B2\-B891\-D67B6DB9F523.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","0","#GUIDproject","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","38076"
"*cgBlAGcAIABzAGEAdgBlACAAaABrAGwAbQBcAHMAYQBtACAAMQ*",".{0,1000}cgBlAGcAIABzAGEAdgBlACAAaABrAGwAbQBcAHMAYQBtACAAMQ.{0,1000}","offensive_tool_keyword","SamDumpCable","Dump users sam and system hive and exfiltrate them","T1003.002 - T1564.001","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SamDumpCable","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","38110"
"*cgeeodpfagjceefieflmdfphplkenlfk*",".{0,1000}cgeeodpfagjceefieflmdfphplkenlfk.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","38111"
"*ch0sys/DUBrute*",".{0,1000}ch0sys\/DUBrute.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","1","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","38115"
"*CH3CK70K3N(*",".{0,1000}CH3CK70K3N\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","38116"
"*Changing NTLM credentials of current logon session *",".{0,1000}Changing\sNTLM\scredentials\sof\scurrent\slogon\ssession\s.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","38127"
"*Changing NTLM credentials of logon session *",".{0,1000}Changing\sNTLM\scredentials\sof\slogon\ssession\s.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","38128"
"*check that our dll as been injected : NTHASH*",".{0,1000}check\sthat\sour\sdll\sas\sbeen\sinjected\s\:\sNTHASH.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","38145"
"*check_ppl_requirements*",".{0,1000}check_ppl_requirements.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","38149"
"*cheetah.py -*",".{0,1000}cheetah\.py\s\-.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","38164"
"*chgpass.exe*Administrator *",".{0,1000}chgpass\.exe.{0,1000}Administrator\s.{0,1000}","greyware_tool_keyword","chgpass","reset the local administrator password","T1098.003 - T1078.003 - T1003.002","TA0006","N/A","N/A","Credential Access","https://x.com/decoder_it/status/1882851589352051144","1","0","N/A","N/A","7","7","N/A","N/A","N/A","N/A","38166"
"*chgpass.exe*DSRM*",".{0,1000}chgpass\.exe.{0,1000}DSRM.{0,1000}","greyware_tool_keyword","chgpass","reset the DSRM password which is the local administrator account on the domain controller stored in the local SAM","T1098.003 - T1078.003 - T1003.002","TA0006","N/A","N/A","Credential Access","https://x.com/decoder_it/status/1882851589352051144","1","0","N/A","N/A","7","7","N/A","N/A","N/A","N/A","38167"
"*chknull.zip*",".{0,1000}chknull\.zip.{0,1000}","offensive_tool_keyword","ChkNull","Checks for Users with No passwords","T1078 - T1201","TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/classic_hacking_tools","1","1","N/A","N/A","N/A","1","4","1","2024-06-27T09:35:42Z","2023-04-16T01:49:12Z","38187"
"*chntpw Edit User Info & Passwords*",".{0,1000}chntpw\sEdit\sUser\sInfo\s\&\sPasswords.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38200"
"*chntpw.com/download*",".{0,1000}chntpw\.com\/download.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38201"
"*chntpw.static*",".{0,1000}chntpw\.static.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38202"
"*chocolate.kirbi*",".{0,1000}chocolate\.kirbi.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","38208"
"*Chredx765ome\\Usedx765er Datedx765a*",".{0,1000}Chredx765ome\\\\Usedx765er\sDatedx765a.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","38221"
"*chrismaddalena/SharpCloud*",".{0,1000}chrismaddalena\/SharpCloud.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","38222"
"*Chroedx765mium\\Useedx765r Data*",".{0,1000}Chroedx765mium\\\\Useedx765r\sData.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","38225"
"*Chrome App-Bound Encryption - Decryption*",".{0,1000}Chrome\sApp\-Bound\sEncryption\s\-\sDecryption.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","#content","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","38226"
"*Chrome Password Recovery*",".{0,1000}Chrome\sPassword\sRecovery.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38227"
"*Chrome Passwords List!*",".{0,1000}Chrome\sPasswords\sList!.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38228"
"*ChromeAppBound::BytesToHexString(en crypted_key.data*",".{0,1000}ChromeAppBound\:\:BytesToHexString\(en\scrypted_key\.data.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","#content","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","38233"
"*ChromeCookiesView.exe*",".{0,1000}ChromeCookiesView\.exe.{0,1000}","greyware_tool_keyword","ChromeCookiesView","displays the list of all cookies stored by Google Chrome Web browser - abused by attackers","T1539 - T1005 - T1070.004 - T1552.001","TA0006 - TA0008 - TA0009","N/A","Evilnum - MuddyWater","Credential Access","https://www.nirsoft.net/utils/chrome_cookies_view.html","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","8","10","N/A","N/A","N/A","N/A","38236"
"*chromecookiesview.zip*",".{0,1000}chromecookiesview\.zip.{0,1000}","greyware_tool_keyword","ChromeCookiesView","displays the list of all cookies stored by Google Chrome Web browser - abused by attackers","T1539 - T1005 - T1070.004 - T1552.001","TA0006 - TA0008 - TA0009","N/A","Evilnum - MuddyWater","Credential Access","https://www.nirsoft.net/utils/chrome_cookies_view.html","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","8","10","N/A","N/A","N/A","N/A","38237"
"*chromecookiesview-x64.zip*",".{0,1000}chromecookiesview\-x64\.zip.{0,1000}","greyware_tool_keyword","ChromeCookiesView","displays the list of all cookies stored by Google Chrome Web browser - abused by attackers","T1539 - T1005 - T1070.004 - T1552.001","TA0006 - TA0008 - TA0009","N/A","Evilnum - MuddyWater","Credential Access","https://www.nirsoft.net/utils/chrome_cookies_view.html","1","1","N/A","https://documents.trendmicro.com/assets/white_papers/wp_new_muddywater_findings_uncovered.pdf","8","10","N/A","N/A","N/A","N/A","38238"
"*ChromeDump.git*",".{0,1000}ChromeDump\.git.{0,1000}","offensive_tool_keyword","chromedump","ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser","T1059.007 - T1114.001 - T1518.001 - T1552.002","TA0005 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/g4l4drim/ChromeDump","1","1","N/A","N/A","N/A","1","55","1","2024-10-12T14:07:36Z","2023-01-26T20:44:06Z","38240"
"*chromedump.py*",".{0,1000}chromedump\.py.{0,1000}","offensive_tool_keyword","chromedump","ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser","T1059.007 - T1114.001 - T1518.001 - T1552.002","TA0005 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/g4l4drim/ChromeDump","1","1","N/A","N/A","N/A","1","55","1","2024-10-12T14:07:36Z","2023-01-26T20:44:06Z","38241"
"*ChromeDump-main.zip*",".{0,1000}ChromeDump\-main\.zip.{0,1000}","offensive_tool_keyword","chromedump","ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser","T1059.007 - T1114.001 - T1518.001 - T1552.002","TA0005 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/g4l4drim/ChromeDump","1","1","N/A","N/A","N/A","1","55","1","2024-10-12T14:07:36Z","2023-01-26T20:44:06Z","38243"
"*ChromeKatz/Memory.cpp*",".{0,1000}ChromeKatz\/Memory\.cpp.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38244"
"*ChromeKatz/Process.cpp*",".{0,1000}ChromeKatz\/Process\.cpp.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38245"
"*ChromeKatz\Memory.cpp*",".{0,1000}ChromeKatz\\Memory\.cpp.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38246"
"*ChromeKatz\Process.cpp*",".{0,1000}ChromeKatz\\Process\.cpp.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38247"
"*chromepass.exe*",".{0,1000}chromepass\.exe.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38250"
"*chromepass.zip*",".{0,1000}chromepass\.zip.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38251"
"*ChromeStealer.exe*",".{0,1000}ChromeStealer\.exe.{0,1000}","offensive_tool_keyword","ChromeStealer","extract and decrypt stored passwords from Google Chrome","T1555.003 - T1003.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/BernKing/ChromeStealer","1","1","N/A","N/A","8","2","145","18","2024-07-25T08:27:10Z","2024-07-14T13:27:30Z","38255"
"*CICADA8-Research/Spyndicapped*",".{0,1000}CICADA8\-Research\/Spyndicapped.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","1","N/A","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","38276"
"*cisco2john.pl*",".{0,1000}cisco2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","38285"
"*CiscoCXSecurity/creddump7*",".{0,1000}CiscoCXSecurity\/creddump7.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","38286"
"*citronneur/pamspy*",".{0,1000}citronneur\/pamspy.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","1","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","38289"
"*citronneur/pamspy/releases*",".{0,1000}citronneur\/pamspy\/releases.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","1","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","38290"
"*cjelfplplebdjjenllpjcblmjkfcffne*",".{0,1000}cjelfplplebdjjenllpjcblmjkfcffne.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","38291"
"*Clear-KeyCredentials -target *",".{0,1000}Clear\-KeyCredentials\s\-target\s.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","38309"
"*Clear-RecycleBin -Force -ErrorAction SilentlyContinue*",".{0,1000}Clear\-RecycleBin\s\-Force\s\-ErrorAction\sSilentlyContinue.{0,1000}","greyware_tool_keyword","powershell","Deletes contents of recycle bin","T1056.002 - T1566.001 - T1567.002","TA0004 - TA0040 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/-OMG-Credz-Plz","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","38314"
"*clem9669/hashcat-rule*",".{0,1000}clem9669\/hashcat\-rule.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","38315"
"*clem9669_case.rule*",".{0,1000}clem9669_case\.rule.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","38316"
"*clem9669_large.rule*",".{0,1000}clem9669_large\.rule.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","38317"
"*clem9669_medium.rule*",".{0,1000}clem9669_medium\.rule.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","38318"
"*clem9669_small.rule*",".{0,1000}clem9669_small\.rule.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","38319"
"*clem9669_wordlist_medium.7z*",".{0,1000}clem9669_wordlist_medium\.7z.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","38320"
"*clem9669_wordlist_small.7z*",".{0,1000}clem9669_wordlist_small\.7z.{0,1000}","offensive_tool_keyword","wordlists","Various wordlists FR & EN - Cracking French passwords","T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/clem9669/wordlists","1","1","N/A","N/A","N/A","3","280","45","2025-04-22T14:34:10Z","2020-10-21T14:37:53Z","38321"
"*clr2of8/DPAT*",".{0,1000}clr2of8\/DPAT.{0,1000}","offensive_tool_keyword","DPAT","Domain Password Audit Tool for Pentesters","T1003 - T1087 - T1110 - T1555","TA0006 - TA0004 - TA0002 - TA0005","N/A","N/A","Credential Access","https://github.com/clr2of8/DPAT","1","1","N/A","N/A","10","10","954","156","2022-06-24T21:41:43Z","2016-11-22T22:00:21Z","38385"
"*cmd smb *-u*-p*",".{0,1000}cmd\ssmb\s.{0,1000}\-u.{0,1000}\-p.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38410"
"*cmd.exe /c arp -a > C:\windows\*.out 2>&1*",".{0,1000}cmd\.exe\s\/c\sarp\s\-a\s\>\sC\:\\windows\\.{0,1000}\.out\s2\>\&1.{0,1000}","signature_keyword","arp","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","38417"
"*cmd.exe' successfully created with LOGON_TYPE = 9*",".{0,1000}cmd\.exe\'\ssuccessfully\screated\swith\sLOGON_TYPE\s\=\s9.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","#content","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","38459"
"*cmd/bruteforce.go*",".{0,1000}cmd\/bruteforce\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","38470"
"*cmd/bruteuser.go*",".{0,1000}cmd\/bruteuser\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","38471"
"*cme*-macOS-latest-*",".{0,1000}cme.{0,1000}\-macOS\-latest\-.{0,1000}","offensive_tool_keyword","crackmapexec","macOS default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38502"
"*cme*-ubuntu-latest-*",".{0,1000}cme.{0,1000}\-ubuntu\-latest\-.{0,1000}","offensive_tool_keyword","crackmapexec","ubuntu default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38503"
"*cme*-windows-latest-*",".{0,1000}cme.{0,1000}\-windows\-latest\-.{0,1000}","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral move","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38504"
"*cme/cme.conf*",".{0,1000}cme\/cme\.conf.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38505"
"*cme-macOS-latest-*.zip*",".{0,1000}cme\-macOS\-latest\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38530"
"*cme-ubuntu-latest-*.zip*",".{0,1000}cme\-ubuntu\-latest\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38531"
"*cme-windows-latest-*.zip*",".{0,1000}cme\-windows\-latest\-.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38532"
"*Coded by LimerBoy <3*",".{0,1000}Coded\sby\sLimerBoy\s\<3.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","38570"
"*coinomi2john.py*",".{0,1000}coinomi2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","38622"
"*-Command ""--signature --driver""*",".{0,1000}\-Command\s\""\-\-signature\s\-\-driver\"".{0,1000}","offensive_tool_keyword","PowerSharpPack","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","0","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","38665"
"*Commands/Brute.*",".{0,1000}Commands\/Brute\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","38683"
"*Commands/Createnetonly.*",".{0,1000}Commands\/Createnetonly\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","38684"
"*Commands/Logonsession.*",".{0,1000}Commands\/Logonsession\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","38690"
"*Commands/Preauthscan.*",".{0,1000}Commands\/Preauthscan\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","38692"
"*Commands/Silver.*",".{0,1000}Commands\/Silver\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","38701"
"*common_passwords.txt*",".{0,1000}common_passwords\.txt.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","38710"
"*Compiling mstscax dll proxy*",".{0,1000}Compiling\smstscax\sdll\sproxy.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","38724"
"*Compiling proxy argon2.dll*",".{0,1000}Compiling\sproxy\sargon2\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","38725"
"*comsvcs.dll*#+00024764*",".{0,1000}comsvcs\.dll.{0,1000}\#\+00024764.{0,1000}","greyware_tool_keyword","comsvcs.dll","Dumping credentials with Minidump ordinal format (suspicious)","T1003","TA0006","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38738"
"*comsvcs.dll*#24*",".{0,1000}comsvcs\.dll.{0,1000}\#24.{0,1000}","greyware_tool_keyword","comsvcs.dll","Dumping credentials with Minidump ordinal format (suspicious)","T1003","TA0006","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38739"
"*comsvcs.dll*MiniDump*lsass*full*",".{0,1000}comsvcs\.dll,\sMiniDump.{0,1000}lsass.{0,1000}full.{0,1000}","greyware_tool_keyword","comsvcs.dll","Dumping lsass credentials","T1003","TA0006","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38740"
"*comsvcs.dll, MiniDump *",".{0,1000}comsvcs\.dll,\sMiniDump\s.{0,1000}","greyware_tool_keyword","rundll32","Caling MiniDump function - dump memory of a process (often abused to dump lsass process)","T1218.011 - T1003","TA0006 - TA0005 - TA0002","N/A","Black Basta","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38741"
"*comsvcs.dll,#24 *",".{0,1000}comsvcs\.dll,\#24\s.{0,1000}","greyware_tool_keyword","rundll32","Calling MiniDump export by ordinal - dump memory of a process (often abused to dump lsass process","T1218.011 - T1003","TA0006 - TA0005 - TA0002","N/A","Black Basta","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","38742"
"*Connect-AzureAD -AadAccessToken -AccountId *",".{0,1000}Connect\-AzureAD\s\-AadAccessToken\s\-AccountId\s.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","0","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","38767"
"*conpass -d * -u * -p *",".{0,1000}conpass\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","0","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","38773"
"*conpass v* - Continuous password spraying tool*",".{0,1000}conpass\sv.{0,1000}\s\-\sContinuous\spassword\sspraying\stool.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","0","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","38774"
"*Converting and saving TGT in UNIX format to file wce_ccache*",".{0,1000}Converting\sand\ssaving\sTGT\sin\sUNIX\sformat\sto\sfile\swce_ccache.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","38814"
"*cookie-katz chrome *",".{0,1000}cookie\-katz\schrome\s.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38833"
"*cookie-katz chrome *",".{0,1000}cookie\-katz\schrome\s.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38834"
"*cookie-katz edge *",".{0,1000}cookie\-katz\sedge\s.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38835"
"*CookieKatz Minidump parser*",".{0,1000}CookieKatz\sMinidump\sparser.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38836"
"*CookieKatz Minidump parser*",".{0,1000}CookieKatz\sMinidump\sparser.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38837"
"*cookie-katz webview *",".{0,1000}cookie\-katz\swebview\s.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38838"
"*CookieKatz.exe*",".{0,1000}CookieKatz\.exe.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38839"
"*CookieKatzBOF.cpp*",".{0,1000}CookieKatzBOF\.cpp.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38840"
"*CookieKatzBOF.x64*",".{0,1000}CookieKatzBOF\.x64.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38841"
"*CookieKatzBOF.zip*",".{0,1000}CookieKatzBOF\.zip.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38842"
"*CookieKatzMinidump.exe*",".{0,1000}CookieKatzMinidump\.exe.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","38843"
"*Cookies stolen and saved successfully!""",".{0,1000}Cookies\sstolen\sand\ssaved\ssuccessfully!\""","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","N/A","10","","N/A","","","","38845"
"*copy *\NTDS\ntds.dit *\Temp\*.*",".{0,1000}copy\s.{0,1000}\\NTDS\\ntds\.dit\s.{0,1000}\\Temp\\.{0,1000}\..{0,1000}","greyware_tool_keyword","copy","the actor creating a Shadow Copy and then extracting a copy of the ntds.dit file from it.","T1003.001 - T1567.001 - T1070.004","TA0005 - TA0003 - TA0007","N/A","Volt Typhoon","Credential Access","https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","38874"
"*copy *PROCEXP.sys*C:\Windows\System32\WindowsPowershell\*",".{0,1000}copy\s.{0,1000}PROCEXP\.sys.{0,1000}C\:\\Windows\\System32\\WindowsPowershell\\.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","0","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","38876"
"*copy \*\HarddiskVolumeShadowCopy1\windows\system32\config\sam C:\*",".{0,1000}copy\s\\.{0,1000}\\HarddiskVolumeShadowCopy1\\windows\\system32\\config\\sam\sC\:\\.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Dumping secrets from a Volume Shadow Copy We can also create a Volume Shadow Copy of the SAM and SYSTEM files (which are always locked on the current system) so we can still copy them over to our local system. An elevated prompt is required for this.","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","38879"
"*copy \*\HarddiskVolumeShadowCopy1\windows\system32\config\system C:\*",".{0,1000}copy\s\\.{0,1000}\\HarddiskVolumeShadowCopy1\\windows\\system32\\config\\system\sC\:\\.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Dumping secrets from a Volume Shadow Copy We can also create a Volume Shadow Copy of the SAM and SYSTEM files (which are always locked on the current system) so we can still copy them over to our local system. An elevated prompt is required for this.","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","38880"
"*core/sprayers/lync.py*",".{0,1000}core\/sprayers\/lync\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","38896"
"*CoreSecurity/impacket/*",".{0,1000}CoreSecurity\/impacket\/.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","38899"
"*Could not find address marker in shellcode*",".{0,1000}Could\snot\sfind\saddress\smarker\sin\sshellcode.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#content","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","38902"
"*Cowpatty*",".{0,1000}Cowpatty.{0,1000}","offensive_tool_keyword","Cowpatty","coWPAtty - Brute-force dictionary attack against WPA-PSK.","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/joswr1ght/cowpatty","1","1","N/A","network exploitation tool","N/A","3","207","51","2018-12-04T22:26:47Z","2017-08-14T20:33:22Z","38927"
"*cp /etc/passwd*",".{0,1000}cp\s\/etc\/passwd.{0,1000}","greyware_tool_keyword","cp","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","38932"
"*cp /etc/shadow*",".{0,1000}cp\s\/etc\/shadow.{0,1000}","greyware_tool_keyword","cp","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","38934"
"*Cr3dOv3r*",".{0,1000}Cr3dOv3r.{0,1000}","offensive_tool_keyword","Cr3dOv3r","Know the dangers of credential reuse attacks.","T1110 - T1555 - T1003","TA0006 - TA0040 - TA0003","N/A","N/A","Credential Access","https://github.com/D4Vinci/Cr3dOv3r","1","1","N/A","N/A","N/A","10","2050","413","2024-10-14T19:20:12Z","2017-11-13T20:49:57Z","38943"
"*cracf2john.py*",".{0,1000}cracf2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","38944"
"*crack_it(nt_hash, lm_pass)*",".{0,1000}crack_it\(nt_hash,\slm_pass\).{0,1000}","offensive_tool_keyword","DPAT","Domain Password Audit Tool for Pentesters","T1003 - T1087 - T1110 - T1555","TA0006 - TA0004 - TA0002 - TA0005","N/A","N/A","Credential Access","https://github.com/clr2of8/DPAT","1","0","#content","N/A","10","10","954","156","2022-06-24T21:41:43Z","2016-11-22T22:00:21Z","38946"
"*cracklord-master.*",".{0,1000}cracklord\-master\..{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","38955"
"*cracklord-queued*_amd64.deb*",".{0,1000}cracklord\-queued.{0,1000}_amd64\.deb.{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","38956"
"*cracklord-resourced*_amd64.deb*",".{0,1000}cracklord\-resourced.{0,1000}_amd64\.deb.{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","38957"
"*crackmapexec*",".{0,1000}crackmapexec.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec execution name. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks ","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38958"
"*crackmapexec.exe*",".{0,1000}crackmapexec\.exe.{0,1000}","offensive_tool_keyword","crackmapexec","windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","38960"
"*crackpkcs12*",".{0,1000}crackpkcs12.{0,1000}","offensive_tool_keyword","crackpkcs12","A multithreaded program to crack PKCS#12 files (p12 and pfx extensions) by Aestu","T1110 - T1185 - T1114","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/crackpkcs12/crackpkcs12","1","1","N/A","N/A","N/A","2","153","29","2019-04-26T18:38:11Z","2015-03-19T22:26:17Z","38964"
"*crackTGS*",".{0,1000}crackTGS.{0,1000}","offensive_tool_keyword","ASREPRoast","Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. ","T1558.003","TA0006","N/A","N/A","Credential Access","https://github.com/HarmJ0y/ASREPRoast","1","0","N/A","N/A","N/A","3","202","58","2018-09-25T03:26:00Z","2017-01-14T21:07:57Z","38965"
"*crcreditcards.txt*",".{0,1000}crcreditcards\.txt.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","38976"
"*CrealPasswords.txt*",".{0,1000}CrealPasswords\.txt.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","38983"
"*Create %d IP@Loginl;Password*",".{0,1000}Create\s\%d\sIP\@Loginl\;Password.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","0","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","38984"
"*CREATE TABLE [LDAPHUNTERFINDINGS]*",".{0,1000}CREATE\sTABLE\s\[LDAPHUNTERFINDINGS\].{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","0","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","38990"
"*create_dummy_dll_file*",".{0,1000}create_dummy_dll_file.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","38993"
"*create_protected_process_as_user*",".{0,1000}create_protected_process_as_user.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","38996"
"*Created by Usman Sikander (a.k.a offensive-panda)*",".{0,1000}Created\sby\sUsman\sSikander\s\(a\.k\.a\soffensive\-panda\).{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","39002"
"*CreateFile(""twin.txt""*",".{0,1000}CreateFile\(\""twin\.txt\"".{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","39005"
"*Creating a TGT ticket for the user*",".{0,1000}Creating\sa\sTGT\sticket\sfor\sthe\suser.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","0","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","39028"
"*Creating offline copies of the LSASS process to perform memory dumps on*",".{0,1000}Creating\soffline\scopies\sof\sthe\sLSASS\sprocess\sto\sperform\smemory\sdumps\son.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","39030"
"*creddump7 -*",".{0,1000}creddump7\s\-.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","39036"
"*creddump7.exe*",".{0,1000}creddump7\.exe.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","39037"
"*creddump7.win32.*",".{0,1000}creddump7\.win32\..{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","39038"
"*CredentialKatz*",".{0,1000}CredentialKatz.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#content","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","39048"
"*CredHistView.exe*",".{0,1000}CredHistView\.exe.{0,1000}","offensive_tool_keyword","credhistview","This tool allows you to decrypt the CREDHIST file and view the SHA1 and NTLM hashes of all previous passwords you used on your system","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/credhist_view.html","1","1","N/A","N/A","9","9","N/A","N/A","N/A","N/A","39055"
"*credhistview.zip*",".{0,1000}credhistview\.zip.{0,1000}","offensive_tool_keyword","credhistview","This tool allows you to decrypt the CREDHIST file and view the SHA1 and NTLM hashes of all previous passwords you used on your system","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/credhist_view.html","1","1","N/A","N/A","9","9","N/A","N/A","N/A","N/A","39056"
"*credmaster.py *",".{0,1000}credmaster\.py\s.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","39057"
"*CredMaster\passwords.txt*",".{0,1000}CredMaster\\passwords\.txt.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","39058"
"*CredsLeaker*",".{0,1000}CredsLeaker.{0,1000}","offensive_tool_keyword","CredsLeaker","This script used to display a powershell credentials box asked the user for credentials. However. That was highly noticeable. Now its time to utilize Windows Security popup!","T1087 - T1056 - T1003 - T1059 - T1110","TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/Dviros/CredsLeaker","1","1","N/A","N/A","N/A","4","316","68","2021-03-31T11:49:57Z","2018-03-05T07:53:31Z","39065"
"*Credz-Plz.ps1*",".{0,1000}Credz\-Plz\.ps1.{0,1000}","offensive_tool_keyword","OMG-Credz-Plz","A script used to prompt the target to enter their creds to later be exfiltrated with dropbox.","T1056.002 - T1566.001 - T1567.002","TA0004 - TA0040 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/-OMG-Credz-Plz","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","39067"
"*Credz-Plz-Execute.txt*",".{0,1000}Credz\-Plz\-Execute\.txt.{0,1000}","offensive_tool_keyword","OMG-Credz-Plz","A script used to prompt the target to enter their creds to later be exfiltrated with dropbox.","T1056.002 - T1566.001 - T1567.002","TA0004 - TA0040 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/-OMG-Credz-Plz","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","39068"
"*crk_get_key1*",".{0,1000}crk_get_key1.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","39074"
"*crk_get_key2*",".{0,1000}crk_get_key2.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","39075"
"*crk_max_keys_per_crypt*",".{0,1000}crk_max_keys_per_crypt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","39076"
"*crk_methods.*",".{0,1000}crk_methods\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","39077"
"*crk_password_loop*",".{0,1000}crk_password_loop.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","39078"
"*crop.exe \\*\*.lnk \\*\harvest \\*\harvest*",".{0,1000}crop\.exe\s\\\\.{0,1000}\\.{0,1000}\.lnk\s\\\\.{0,1000}\\harvest\s\\\\.{0,1000}\\harvest.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","0","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","39088"
"*crowbar*",".{0,1000}crowbar.{0,1000}","offensive_tool_keyword","Crowbar","Crowbar (formally known as Levye) is a brute forcing tool that can be used during penetration tests. It was developed to brute force some protocols in a different manner according to other popular brute forcing tools. As an example. while most brute forcing tools use username and password for SSH brute force. Crowbar uses SSH key(s). This allows for any private keys that have been obtained during penetration tests. to be used to attack other SSH servers.","T1110 - T1114 - T1189 - T1051 - T1552","TA0002 - TA0006 - TA0008","N/A","Dispossessor","Credential Access","https://github.com/galkan/crowbar","1","0","N/A","N/A","N/A","10","1440","319","2023-12-19T20:57:36Z","2014-09-30T07:46:23Z","39121"
"*crpasswords.txt*",".{0,1000}crpasswords\.txt.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","39124"
"*crunch * -o *.txt*",".{0,1000}crunch\s.{0,1000}\s\-o\s.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","crunch","Generate a dictionary file containing words with a minimum and maximum length","T1596 - T1596.001","TA0043","N/A","N/A","Credential Access","https://sourceforge.net/projects/crunch-wordlist/","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","39128"
"*CStealer Builder ~ *",".{0,1000}CStealer\sBuilder\s\~\s.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","0","N/A","N/A","10","","N/A","","","","39170"
"*CStealer_assets\*",".{0,1000}CStealer_assets\\.{0,1000}","offensive_tool_keyword","cstealer","stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/can-kat/cstealer","1","0","N/A","N/A","10","","N/A","","","","39171"
"*C-Sto/gosecretsdump*",".{0,1000}C\-Sto\/gosecretsdump.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","39172"
"*cube0x0/MiniDump*",".{0,1000}cube0x0\/MiniDump.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","39188"
"*cube0x0/MiniDump*",".{0,1000}cube0x0\/MiniDump.{0,1000}","offensive_tool_keyword","onex","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","N/A","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","39189"
"*curl -F * https://*.gofile.io/uploadFile*",".{0,1000}curl\s\-F\s.{0,1000}\shttps\:\/\/.{0,1000}\.gofile\.io\/uploadFile.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","39196"
"*customWmiExec*wmiexec.py*",".{0,1000}customWmiExec.{0,1000}wmiexec\.py.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","39233"
"*cut -d: -f1 /etc/passwd*",".{0,1000}cut\s\-d\:\s\-f1\s\/etc\/passwd.{0,1000}","greyware_tool_keyword","cut","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","39234"
"*cyclone.hashesorg.hashkiller.combined*",".{0,1000}cyclone\.hashesorg\.hashkiller\.combined.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","39317"
"*-d * bruteforce -*",".{0,1000}\-d\s.{0,1000}\sbruteforce\s\-.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","39326"
"*d027404d259a269dc52eb697868f7e91cd32888fc9659d1851441aaa9ea3b8bd*",".{0,1000}d027404d259a269dc52eb697868f7e91cd32888fc9659d1851441aaa9ea3b8bd.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","39343"
"*d044393f7a9e9536cc03cec12137074d41dd338c0182bbd8a4ca165f79f5a3d9*",".{0,1000}d044393f7a9e9536cc03cec12137074d41dd338c0182bbd8a4ca165f79f5a3d9.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#filehash","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","39351"
"*d090bea299c6fb0956ce4a6450d0bfe1e3e0aa952a67b718f26e3668e41aac56*",".{0,1000}d090bea299c6fb0956ce4a6450d0bfe1e3e0aa952a67b718f26e3668e41aac56.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","0","#filehash","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","39373"
"*d0fd70c59cf45c5c1eb9c73ba1ccfa433d715a3a57b1312a26a02c60210cbfb8*",".{0,1000}d0fd70c59cf45c5c1eb9c73ba1ccfa433d715a3a57b1312a26a02c60210cbfb8.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#filehash","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","39404"
"*d0fd70c59cf45c5c1eb9c73ba1ccfa433d715a3a57b1312a26a02c60210cbfb8*",".{0,1000}d0fd70c59cf45c5c1eb9c73ba1ccfa433d715a3a57b1312a26a02c60210cbfb8.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#filehash","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","39405"
"*D116BEC7-8DEF-4FCE-BF84-C8504EF4E481*",".{0,1000}D116BEC7\-8DEF\-4FCE\-BF84\-C8504EF4E481.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","0","#GUIDproject","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","39414"
"*d14447f41d11e0ed192d9161a60cee139fe8b01d921bbdff56abc01a5a653161*",".{0,1000}d14447f41d11e0ed192d9161a60cee139fe8b01d921bbdff56abc01a5a653161.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","39425"
"*d14447f41d11e0ed192d9161a60cee139fe8b01d921bbdff56abc01a5a653161*",".{0,1000}d14447f41d11e0ed192d9161a60cee139fe8b01d921bbdff56abc01a5a653161.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","39426"
"*d14884d8a7f74e96a4450e1b1e65636b3a2810274963e4a6eb28e161effe1216*",".{0,1000}d14884d8a7f74e96a4450e1b1e65636b3a2810274963e4a6eb28e161effe1216.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","39428"
"*d14884d8a7f74e96a4450e1b1e65636b3a2810274963e4a6eb28e161effe1216*",".{0,1000}d14884d8a7f74e96a4450e1b1e65636b3a2810274963e4a6eb28e161effe1216.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","#filehash","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","39429"
"*d14be0c5477fc937b2cc00367931e1181d8897ce98a560cff48e0939840a096b*",".{0,1000}d14be0c5477fc937b2cc00367931e1181d8897ce98a560cff48e0939840a096b.{0,1000}","offensive_tool_keyword","Necro-Stealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/Necro-Stealer","1","0","#filehash","N/A","8","1","6","1","2022-12-06T16:06:55Z","2022-12-06T15:52:17Z","39431"
"*d169a3057a62c9cc881c25e8f78c915c2c967a7c537a270239c87a1cad44b76e*",".{0,1000}d169a3057a62c9cc881c25e8f78c915c2c967a7c537a270239c87a1cad44b76e.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","39438"
"*d16d7eaa9f5abcafb83da10a9b729f7c9b090bf209fd7b9ea820ed942c328d60*",".{0,1000}d16d7eaa9f5abcafb83da10a9b729f7c9b090bf209fd7b9ea820ed942c328d60.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","39439"
"*D1D4BB1C-798D-47B0-8525-061D40CB9E44*",".{0,1000}D1D4BB1C\-798D\-47B0\-8525\-061D40CB9E44.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#GUIDProject","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","39469"
"*d1e9bbf0fb621285de6ea7b4c2b3f8dc2a15d0e51639eafb8f2fb8aca47054e0*",".{0,1000}d1e9bbf0fb621285de6ea7b4c2b3f8dc2a15d0e51639eafb8f2fb8aca47054e0.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","39479"
"*d21f5b2cbd06f1f679bcc65b7d40fc203c1f7008dac678f7edf14577d8c2246f*",".{0,1000}d21f5b2cbd06f1f679bcc65b7d40fc203c1f7008dac678f7edf14577d8c2246f.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","39505"
"*d2888f1714566be066719ca2bcbe9e5948a002a7f12070397b306e96442c26aa*",".{0,1000}d2888f1714566be066719ca2bcbe9e5948a002a7f12070397b306e96442c26aa.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#filehash","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","39527"
"*d30f51bfd62695df96ba94cde14a7fae466b29ef45252c6ad19d57b4a87ff44e*",".{0,1000}d30f51bfd62695df96ba94cde14a7fae466b29ef45252c6ad19d57b4a87ff44e.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","39564"
"*d30f51bfd62695df96ba94cde14a7fae466b29ef45252c6ad19d57b4a87ff44e*",".{0,1000}d30f51bfd62695df96ba94cde14a7fae466b29ef45252c6ad19d57b4a87ff44e.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","39565"
"*d328400cdc424aa3a54ad23f20979aca1324d1de62e28a69c18819671e597b03*",".{0,1000}d328400cdc424aa3a54ad23f20979aca1324d1de62e28a69c18819671e597b03.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","39572"
"*d33f6e8b7b07e293f431cb39fb4463d854500921ee23fd661143a5c01785417b*",".{0,1000}d33f6e8b7b07e293f431cb39fb4463d854500921ee23fd661143a5c01785417b.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","39579"
"*d3468041efe888dda240f4aafc6182365b39dfe0ca7ae9c5c5acc0802a34bc5d*",".{0,1000}d3468041efe888dda240f4aafc6182365b39dfe0ca7ae9c5c5acc0802a34bc5d.{0,1000}","offensive_tool_keyword","Dispossessor","Bruteforce tools used by Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","39583"
"*D35A55BD-3189-498B-B72F-DC798172E505*",".{0,1000}D35A55BD\-3189\-498B\-B72F\-DC798172E505.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#GUIDproject","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","39586"
"*d3821591de381cb2861c5cf554009e51d7afe51b7c14e89b6f06a666bab949ff*",".{0,1000}d3821591de381cb2861c5cf554009e51d7afe51b7c14e89b6f06a666bab949ff.{0,1000}","offensive_tool_keyword","RouterPassView","help you to recover your lost password from your router file","T1002 - T1552 - T1027","TA0006 - TA0007","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/router_password_recovery.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","39598"
"*d3924d3bf6f59335a1e5453d80eaaa7404cea2e342105c3e69ddfb943aeb29c6*",".{0,1000}d3924d3bf6f59335a1e5453d80eaaa7404cea2e342105c3e69ddfb943aeb29c6.{0,1000}","offensive_tool_keyword","Ask4Creds","Prompt User for credentials","T1056 - T1071","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Leo4j/Ask4Creds","1","0","#filehash","N/A","8","1","1","0","2024-03-20T17:09:21Z","2023-11-12T15:21:40Z","39605"
"*D3CrYP7V41U3(*",".{0,1000}D3CrYP7V41U3\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","39625"
"*d3lb3@protonmail.com*",".{0,1000}d3lb3\@protonmail\.com.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","#email","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","39641"
"*d42056fad9278acecf2a979acd6aa24bd1e757c8429a424b245dbc0a39bde9a2*",".{0,1000}d42056fad9278acecf2a979acd6aa24bd1e757c8429a424b245dbc0a39bde9a2.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","39646"
"*d4ba2464d2d3450db40ac57c7e0d6d7a7e4ac72c44cbd6ce9e4b3366f3a8907b*",".{0,1000}d4ba2464d2d3450db40ac57c7e0d6d7a7e4ac72c44cbd6ce9e4b3366f3a8907b.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","#filehash","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","39689"
"*d53fb2aa459eb50e3d16f17835db3246e3016389cfa63c126263e24fa18729e7*",".{0,1000}d53fb2aa459eb50e3d16f17835db3246e3016389cfa63c126263e24fa18729e7.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","0","#filehash","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","39720"
"*d583e8ee91ab53e8c797b3beb22bfb8b9e775f88436798225e2ec361832a8942*",".{0,1000}d583e8ee91ab53e8c797b3beb22bfb8b9e775f88436798225e2ec361832a8942.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","39747"
"*d5b211c3a68fdd0231c3f6aa72dc980b8481e47fca6ce40605021d3e6222d7c5*",".{0,1000}d5b211c3a68fdd0231c3f6aa72dc980b8481e47fca6ce40605021d3e6222d7c5.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","39756"
"*d5fb8f91ffff93aecf6c68f864ce853a541d0bb7b53db3f5eb2fd6b8310cc5f2*",".{0,1000}d5fb8f91ffff93aecf6c68f864ce853a541d0bb7b53db3f5eb2fd6b8310cc5f2.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059 - T1070.004","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","#filehash","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","39772"
"*d6304a65276af87fe87a4cddf75f571d1c73c601710fffebe9da17d762d521d2*",".{0,1000}d6304a65276af87fe87a4cddf75f571d1c73c601710fffebe9da17d762d521d2.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","#filehash","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","39781"
"*d650f132e50bca7c7a06965617a46e32e68f1066cf15cf04c2759bbcb81fbf68*",".{0,1000}d650f132e50bca7c7a06965617a46e32e68f1066cf15cf04c2759bbcb81fbf68.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","39793"
"*d6521cf735fc2bb7f7c308b488c869d7cf4136c97b08cf0219ca2d6e64134290*",".{0,1000}d6521cf735fc2bb7f7c308b488c869d7cf4136c97b08cf0219ca2d6e64134290.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","39794"
"*d6521cf735fc2bb7f7c308b488c869d7cf4136c97b08cf0219ca2d6e64134290*",".{0,1000}d6521cf735fc2bb7f7c308b488c869d7cf4136c97b08cf0219ca2d6e64134290.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","39795"
"*D6948EFC-AA15-413D-8EF1-032C149D3FBB*",".{0,1000}D6948EFC\-AA15\-413D\-8EF1\-032C149D3FBB.{0,1000}","offensive_tool_keyword","FormThief","Spoofing desktop login applications with WinForms and WPF","T1204.002 - T1056.004 - T1071.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/mlcsec/FormThief","1","0","#GUIDproject","N/A","8","2","173","31","2024-02-19T22:40:09Z","2024-02-19T22:34:07Z","39820"
"*D6AAED62-BBFC-4F2A-A2A4-35EC5B2A4E07*",".{0,1000}D6AAED62\-BBFC\-4F2A\-A2A4\-35EC5B2A4E07.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","0","#GUIDproject","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","39823"
"*d71c3ea3ec686a8c080f8310b25cfe4696773a06fe151d03eb9a69de9147abcb*",".{0,1000}d71c3ea3ec686a8c080f8310b25cfe4696773a06fe151d03eb9a69de9147abcb.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","39852"
"*d75a64a4ef72a0c5bbdf8703bc5be50ee1569bad06a77a59e18a525c80c27a99*",".{0,1000}d75a64a4ef72a0c5bbdf8703bc5be50ee1569bad06a77a59e18a525c80c27a99.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","39870"
"*d780134609e2b5c9ec6b75e35c5f6eefcb1527105a584c6fbcff5dee33cebd37*",".{0,1000}d780134609e2b5c9ec6b75e35c5f6eefcb1527105a584c6fbcff5dee33cebd37.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","39880"
"*d7935f00dbd30fe83bd877aa2e841b8aa0c0ded7f2867b677a6e24d3fd3daaba*",".{0,1000}d7935f00dbd30fe83bd877aa2e841b8aa0c0ded7f2867b677a6e24d3fd3daaba.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","39886"
"*d7a74608cdc46702dca5c703ad3bbc40c8b97ce6cea40695b7499987a70a9331*",".{0,1000}d7a74608cdc46702dca5c703ad3bbc40c8b97ce6cea40695b7499987a70a9331.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","39894"
"*D8091ED0-5E78-4AF5-93EE-A5AA6E978430*",".{0,1000}D8091ED0\-5E78\-4AF5\-93EE\-A5AA6E978430.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","#GUIDproject","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","39920"
"*d81d498e8a18f7075fa20adaaa81a754f33513ba4b6ffac9874aff874641c532*",".{0,1000}d81d498e8a18f7075fa20adaaa81a754f33513ba4b6ffac9874aff874641c532.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#filehash","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","39925"
"*d83b72b8147d812d79c480142f74fa123115349052ab1d88df742c0cc8c1aca5*",".{0,1000}d83b72b8147d812d79c480142f74fa123115349052ab1d88df742c0cc8c1aca5.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","39932"
"*d854d2be5826183cb7c1317e3d920871fd467d5506b70e3c5147599ca2704ee6*",".{0,1000}d854d2be5826183cb7c1317e3d920871fd467d5506b70e3c5147599ca2704ee6.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","39940"
"*d86bebcde6d5835cd2237d4e37df9858102002a4b9211aa3827e4bec0eca9897*",".{0,1000}d86bebcde6d5835cd2237d4e37df9858102002a4b9211aa3827e4bec0eca9897.{0,1000}","offensive_tool_keyword","m365-fatigue","automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.","T1110.001 - T1078.001 - T1556.004","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/0xB455/m365-fatigue","1","0","#filehash","N/A","10","1","77","7","2024-04-08T14:53:44Z","2023-11-30T13:33:03Z","39953"
"*D8FC3807-CEAA-4F6A-9C8F-CC96F99D1F04*",".{0,1000}D8FC3807\-CEAA\-4F6A\-9C8F\-CC96F99D1F04.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#GUIDproject","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","39979"
"*d907d7686b725441db1deb645a7079ca79f4dd1d8a18ca4b2bb98c12622603ef*",".{0,1000}d907d7686b725441db1deb645a7079ca79f4dd1d8a18ca4b2bb98c12622603ef.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","#filehash","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","39984"
"*d94e140fdb653c7fbfbc293a5f5ec37b012470dc4c2767b0040daf54aafb47f9*",".{0,1000}d94e140fdb653c7fbfbc293a5f5ec37b012470dc4c2767b0040daf54aafb47f9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","40004"
"*d94e140fdb653c7fbfbc293a5f5ec37b012470dc4c2767b0040daf54aafb47f9*",".{0,1000}d94e140fdb653c7fbfbc293a5f5ec37b012470dc4c2767b0040daf54aafb47f9.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","40005"
"*d9770865ea739a8f1702a2651538f4f4de2d92888d188d8ace2c79936f9c2688*",".{0,1000}d9770865ea739a8f1702a2651538f4f4de2d92888d188d8ace2c79936f9c2688.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","40007"
"*d9770865ea739a8f1702a2651538f4f4de2d92888d188d8ace2c79936f9c2688*",".{0,1000}d9770865ea739a8f1702a2651538f4f4de2d92888d188d8ace2c79936f9c2688.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","40008"
"*d9adb9ecfa37595ce0dd2d8b4841334b32243bd30455fba4f59ce44a33efcdc4*",".{0,1000}d9adb9ecfa37595ce0dd2d8b4841334b32243bd30455fba4f59ce44a33efcdc4.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","0","#filehash","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","40023"
"*d9b9491fbe838aa7d97c46ef81f42c9c9748aabec0697d9abde6ddd6b464c1eb*",".{0,1000}d9b9491fbe838aa7d97c46ef81f42c9c9748aabec0697d9abde6ddd6b464c1eb.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","40031"
"*d9e58e0a47eacc9ccb42322516dcd21658aedb39e1dd64ff4af86e4fca648ddc*",".{0,1000}d9e58e0a47eacc9ccb42322516dcd21658aedb39e1dd64ff4af86e4fca648ddc.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","40042"
"*da5d6eca1efe3219fa8102a0afbf9823dc8b2c00dd53af20960ed29bca1b2cef*",".{0,1000}da5d6eca1efe3219fa8102a0afbf9823dc8b2c00dd53af20960ed29bca1b2cef.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","#filehash","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","40061"
"*da9735d88a845e465aa4fe4968df15b97ba4b6565f150a48ead7a3ca7298df93*",".{0,1000}da9735d88a845e465aa4fe4968df15b97ba4b6565f150a48ead7a3ca7298df93.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","#filehash","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","40073"
"*daa60ab697e9a8cd8ec70c7cc31de5692de1c878c425514788229e791c746e6b*",".{0,1000}daa60ab697e9a8cd8ec70c7cc31de5692de1c878c425514788229e791c746e6b.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","40078"
"*dadf9d853d94eb24a563cc2bba0c5539c8e92bf6340ac823f00af44b25a5a148*",".{0,1000}dadf9d853d94eb24a563cc2bba0c5539c8e92bf6340ac823f00af44b25a5a148.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","40090"
"*daf3ed8ab5cb22d59e4b1de343f15e343c7e2383547f38f550b1e18a3cf8d11d*",".{0,1000}daf3ed8ab5cb22d59e4b1de343f15e343c7e2383547f38f550b1e18a3cf8d11d.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","0","#filehash","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","40100"
"*dafthack/DomainPasswordSpray*",".{0,1000}dafthack\/DomainPasswordSpray.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","40105"
"*dafthack/MailSniper*",".{0,1000}dafthack\/MailSniper.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","40108"
"*DanMcInerney/Empire*",".{0,1000}DanMcInerney\/Empire.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","40128"
"*DanMcInerney/icebreaker*",".{0,1000}DanMcInerney\/icebreaker.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","40129"
"*DanMcInerney/theHarvester*",".{0,1000}DanMcInerney\/theHarvester.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","40131"
"*dashlane2john.py*",".{0,1000}dashlane2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","40159"
"*datr=80ZzUfKqDOjwL8pauwqMjHTa*",".{0,1000}datr\=80ZzUfKqDOjwL8pauwqMjHTa.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://raw.githubusercontent.com/Sup3r-Us3r/scripts/master/fb-brute.pl","1","0","N/A","N/A","7","10","N/A","N/A","N/A","N/A","40181"
"*db03400af112a7969ba2d68288b9dc908b2d234d62184fd5f01079749c4bf09e*",".{0,1000}db03400af112a7969ba2d68288b9dc908b2d234d62184fd5f01079749c4bf09e.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","#filehash","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","40198"
"*db385ea6858db4b4cb49897df9ec6d5cc4675aaf675e692466b3b50218e0eeca*",".{0,1000}db385ea6858db4b4cb49897df9ec6d5cc4675aaf675e692466b3b50218e0eeca.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","40220"
"*db385ea6858db4b4cb49897df9ec6d5cc4675aaf675e692466b3b50218e0eeca*",".{0,1000}db385ea6858db4b4cb49897df9ec6d5cc4675aaf675e692466b3b50218e0eeca.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","40221"
"*db5a054172dcde3aebfb86b08e3bf8992f9df3d22e2028fd5154c647e7361ceb*",".{0,1000}db5a054172dcde3aebfb86b08e3bf8992f9df3d22e2028fd5154c647e7361ceb.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","0","#filehash","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","40230"
"*db65c744d5de72d0e727cf670e992aeec6e4e195298e71f22c095eb63df4f923*",".{0,1000}db65c744d5de72d0e727cf670e992aeec6e4e195298e71f22c095eb63df4f923.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","40238"
"*db7d3e12a58a102b76c1f6e041d0a464ccbffc346dbc338a8cb4a7e5ec508b6c*",".{0,1000}db7d3e12a58a102b76c1f6e041d0a464ccbffc346dbc338a8cb4a7e5ec508b6c.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","#filehash","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","40246"
"*dbb049e7216149b1723b7dbbf9e3e80ce4a0f2d78b2afa8b2cf451c1e5d97b91*",".{0,1000}dbb049e7216149b1723b7dbbf9e3e80ce4a0f2d78b2afa8b2cf451c1e5d97b91.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","#filehash","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","40262"
"*dbc10feaef6ccaf49866bac8d3ddc48729e7163639d6e0fcdad9e8f90178896b*",".{0,1000}dbc10feaef6ccaf49866bac8d3ddc48729e7163639d6e0fcdad9e8f90178896b.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","40266"
"*dBCSPwd*aad3b435b51404eeaad3b435b51404ee*",".{0,1000}dBCSPwd.{0,1000}aad3b435b51404eeaad3b435b51404ee.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","0","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","40277"
"*dbed4217e61d4deba7cfb5aa97aef6687507d9bd990110cc31b0d35ee32acada*",".{0,1000}dbed4217e61d4deba7cfb5aa97aef6687507d9bd990110cc31b0d35ee32acada.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#filehash","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","40287"
"*DC3E0E14-6342-41C9-BECC-3653BF533CCC*",".{0,1000}DC3E0E14\-6342\-41C9\-BECC\-3653BF533CCC.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","0","#GUIDproject","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","40316"
"*dc86081b57b7809bfd3df4c8ed664ca0a786a239bdb522ea129f66571f4fd992*",".{0,1000}dc86081b57b7809bfd3df4c8ed664ca0a786a239bdb522ea129f66571f4fd992.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","40329"
"*dc8e495f3d1ee0060009f69bcdc8b60265879d41d20dd0367a638a101d3a19c6*",".{0,1000}dc8e495f3d1ee0060009f69bcdc8b60265879d41d20dd0367a638a101d3a19c6.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","40333"
"*dc8e495f3d1ee0060009f69bcdc8b60265879d41d20dd0367a638a101d3a19c6*",".{0,1000}dc8e495f3d1ee0060009f69bcdc8b60265879d41d20dd0367a638a101d3a19c6.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","40334"
"*dc95d92765b7ff96b8311920bfc939a9f234e961efc7c8fa4effe5d39ec13ea1*",".{0,1000}dc95d92765b7ff96b8311920bfc939a9f234e961efc7c8fa4effe5d39ec13ea1.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","40337"
"*dcipher-cli*",".{0,1000}dcipher\-cli.{0,1000}","offensive_tool_keyword","dcipher-cli","Crack hashes using online rainbow & lookup table attack services. right from your terminal.","T1110.001 - T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/k4m4/dcipher-cli","1","0","N/A","N/A","N/A","3","233","27","2023-01-05T16:13:56Z","2018-04-08T18:21:44Z","40365"
"*dcsync.py*",".{0,1000}dcsync\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","40394"
"*dcsync.py*",".{0,1000}dcsync\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","40395"
"*DCSyncer.exe*",".{0,1000}DCSyncer\.exe.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","40404"
"*DCSyncer-master.zip*",".{0,1000}DCSyncer\-master\.zip.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","40405"
"*DCSyncer-x64.exe*",".{0,1000}DCSyncer\-x64\.exe.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","40406"
"*dd05c2d2a5d00de8f4ef3dd6d8e2304d2ecb3787e97edd0e38867d047b0936a0*",".{0,1000}dd05c2d2a5d00de8f4ef3dd6d8e2304d2ecb3787e97edd0e38867d047b0936a0.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","0","#filehash","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","40411"
"*dd09d2d4ba9ffc6ddc939ede8a494a4aaadccdcfa441576499f1b85d8580f97e*",".{0,1000}dd09d2d4ba9ffc6ddc939ede8a494a4aaadccdcfa441576499f1b85d8580f97e.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","40412"
"*dd3f2e3349c378e1a415c4a6ad450cd3ae4ea29f3fe15d0a72bff64a44e1362a*",".{0,1000}dd3f2e3349c378e1a415c4a6ad450cd3ae4ea29f3fe15d0a72bff64a44e1362a.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","40428"
"*dd3f2e3349c378e1a415c4a6ad450cd3ae4ea29f3fe15d0a72bff64a44e1362a*",".{0,1000}dd3f2e3349c378e1a415c4a6ad450cd3ae4ea29f3fe15d0a72bff64a44e1362a.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","40429"
"*dd86be9a1fb1198264e1a01247473be5e1498ef549a91b7c7143e5cfc25784e1*",".{0,1000}dd86be9a1fb1198264e1a01247473be5e1498ef549a91b7c7143e5cfc25784e1.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","#filehash","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","40452"
"*ddbf3299675ffdd7e3475f8a4848f3ab6cdff8819348c75b9ac4d8fb76569a2c*",".{0,1000}ddbf3299675ffdd7e3475f8a4848f3ab6cdff8819348c75b9ac4d8fb76569a2c.{0,1000}","signature_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","#filehash","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","40471"
"*de3a20c75f66c663508436a2a3d049987158976535bb5e5eaa63823dbf6d7e3f*",".{0,1000}de3a20c75f66c663508436a2a3d049987158976535bb5e5eaa63823dbf6d7e3f.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","40506"
"*debian.org/pkg-security-team/creddump7*",".{0,1000}debian\.org\/pkg\-security\-team\/creddump7.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","40541"
"*debugfs /dev/*",".{0,1000}debugfs\s\/dev\/.{0,1000}","greyware_tool_keyword","debugdfs","Linux SIEM Bypass with debugdfs shell","T1059 - T1053 - T1037","TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Anti-Forensics.md","1","0","#linux","N/A","N/A","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","40549"
"*Dec0ne/ShadowSpray*",".{0,1000}Dec0ne\/ShadowSpray.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","1","N/A","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","40554"
"*dece45d516d8421e39684618e0b571f94d31dfaf0d0d20d6f4593f4ab67edb0b*",".{0,1000}dece45d516d8421e39684618e0b571f94d31dfaf0d0d20d6f4593f4ab67edb0b.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","40563"
"*deced84e656eb8ae4d4c57dfea5d0a74b558f5975621a9ae0d25d59d3c550f4f*",".{0,1000}deced84e656eb8ae4d4c57dfea5d0a74b558f5975621a9ae0d25d59d3c550f4f.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","40564"
"*decipher_mremoteng.jar*",".{0,1000}decipher_mremoteng\.jar.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","40567"
"*decoded_lsass.dmp*",".{0,1000}decoded_lsass\.dmp.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","40569"
"*decoder-it/ADCSCoercePotato*",".{0,1000}decoder\-it\/ADCSCoercePotato.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","1","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","40571"
"*decoder-it/TokenStealer*",".{0,1000}decoder\-it\/TokenStealer.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","40575"
"*decrypt.py .\*.txt utf-16-le*",".{0,1000}decrypt\.py\s\.\\.{0,1000}\.txt\sutf\-16\-le.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","0","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","40578"
"*decrypt_chrome_password(*",".{0,1000}decrypt_chrome_password\(.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","40579"
"*decrypt_chrome_password.py*",".{0,1000}decrypt_chrome_password\.py.{0,1000}","offensive_tool_keyword","decrypt-chrome-passwords","A simple program to decrypt chrome password saved on your machine.","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/ohyicong/decrypt-chrome-passwords","1","1","N/A","N/A","10","10","966","211","2024-07-31T14:08:55Z","2020-12-28T15:11:12Z","40580"
"*decrypt_chrome_v20_cookie.py*",".{0,1000}decrypt_chrome_v20_cookie\.py.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","1","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","40581"
"*decrypt-chrome-passwords-main*",".{0,1000}decrypt\-chrome\-passwords\-main.{0,1000}","offensive_tool_keyword","decrypt-chrome-passwords","A simple program to decrypt chrome password saved on your machine.","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/ohyicong/decrypt-chrome-passwords","1","1","N/A","N/A","10","10","966","211","2024-07-31T14:08:55Z","2020-12-28T15:11:12Z","40582"
"*Decrypting DPAPI data with masterkey *",".{0,1000}Decrypting\sDPAPI\sdata\swith\smasterkey\s.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","40583"
"*Decrypt-RDCMan -FilePath*",".{0,1000}Decrypt\-RDCMan\s\-FilePath.{0,1000}","offensive_tool_keyword","Decrypt-RDCMan","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1555.005 - T1145 - T1003","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1","1","0","N/A","N/A","9","1","1","1","2016-12-01T14:06:24Z","2017-11-22T23:18:39Z","40586"
"*Decrypt-RDCMan.ps1*",".{0,1000}Decrypt\-RDCMan\.ps1.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","1","N/A","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","40587"
"*DecryptRDCManager.exe*",".{0,1000}DecryptRDCManager\.exe.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","1","N/A","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","40588"
"*DecryptTeamViewer: Pillaging registry for TeamViewer information*",".{0,1000}DecryptTeamViewer\:\sPillaging\sregistry\sfor\sTeamViewer\sinformation.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","0","#content","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","40590"
"*DecryptTeamViewer-master.zip*",".{0,1000}DecryptTeamViewer\-master\.zip.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","1","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","40591"
"*deepinstinct/Lsass-Shtinkering*",".{0,1000}deepinstinct\/Lsass\-Shtinkering.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","40617"
"*deepinstinct/LsassSilentProcessExit*",".{0,1000}deepinstinct\/LsassSilentProcessExit.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","40618"
"*deepsound2john.py*",".{0,1000}deepsound2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","40621"
"*DefaultCreds-cheat-sheet*",".{0,1000}DefaultCreds\-cheat\-sheet.{0,1000}","offensive_tool_keyword","DefaultCreds-cheat-sheet","One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password","T1110.001 - T1110.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/ihebski/DefaultCreds-cheat-sheet","1","1","N/A","N/A","N/A","10","6048","726","2025-04-15T13:13:19Z","2021-01-01T19:02:36Z","40638"
"*define DHCP_KEY _T(""SYSTEM\\CurrentControlSet\\Services\\DHCPServer\\ServicePrivateData""*",".{0,1000}define\sDHCP_KEY\s_T\(\""SYSTEM\\\\CurrentControlSet\\\\Services\\\\DHCPServer\\\\ServicePrivateData\"".{0,1000}","offensive_tool_keyword","StealDhcpSecrets","DHCP Server DNS Password Stealer","T1552 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/tree/master/PasswordStealing/DHCP","1","0","#registry","content","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","40670"
"*DelegationBOF.*",".{0,1000}DelegationBOF\..{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","1","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","40723"
"*DELETE FROM LDAPHUNTERFINDINGS*",".{0,1000}DELETE\sFROM\sLDAPHUNTERFINDINGS.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","0","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","40724"
"*dementor - rough PoC to connect to spoolss to elicit machine account authentication *",".{0,1000}dementor\s\-\srough\sPoC\sto\sconnect\sto\sspoolss\sto\selicit\smachine\saccount\sauthentication\s.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","40735"
"*dementor.py -d * -u * -p *",".{0,1000}dementor\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","rough PoC to connect to spoolss to elicit machine account authentication","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","40736"
"*denandz/KeeFarce*",".{0,1000}denandz\/KeeFarce.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","1","N/A","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","40742"
"*denandz/SecretServerSecretStealer*",".{0,1000}denandz\/SecretServerSecretStealer.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","1","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","40743"
"*deploycaptureserver.ps1*",".{0,1000}deploycaptureserver\.ps1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","40748"
"*Description'>IE Passwords Viewer*",".{0,1000}Description\'\>IE\sPasswords\sViewer.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40755"
"*df0be334160f7fbd522056f8944947f228aa93479fe3981c84a221d2cd733ddc*",".{0,1000}df0be334160f7fbd522056f8944947f228aa93479fe3981c84a221d2cd733ddc.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#filehash","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","40789"
"*df110ed12c12b69bd7791fccb00ecb9ef8eb38f694fb8252cb9d55590362d8fc*",".{0,1000}df110ed12c12b69bd7791fccb00ecb9ef8eb38f694fb8252cb9d55590362d8fc.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","40790"
"*df8687a87b12b4cfcd9cad7082ed7c92bb43726b0d026aeeae6efd575539c0e8*",".{0,1000}df8687a87b12b4cfcd9cad7082ed7c92bb43726b0d026aeeae6efd575539c0e8.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","#filehash","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","40825"
"*Dialup/VPN Password Recovery*",".{0,1000}Dialup\/VPN\sPassword\sRecovery.{0,1000}","offensive_tool_keyword","dialupass","This utility enumerates all dialup/VPN entries on your computers. and displays their logon details: User Name. Password. and Domain. You can use it to recover a lost password of your Internet connection or VPN.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/dialupass.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40870"
"*Dialup/VPN Passwords List*",".{0,1000}Dialup\/VPN\sPasswords\sList.{0,1000}","offensive_tool_keyword","dialupass","This utility enumerates all dialup/VPN entries on your computers. and displays their logon details: User Name. Password. and Domain. You can use it to recover a lost password of your Internet connection or VPN.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/dialupass.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40871"
"*Dialupass.exe*",".{0,1000}Dialupass\.exe.{0,1000}","offensive_tool_keyword","dialupass","This utility enumerates all dialup/VPN entries on your computers. and displays their logon details: User Name. Password. and Domain. You can use it to recover a lost password of your Internet connection or VPN.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/dialupass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40872"
"*Dialupass.zip*",".{0,1000}Dialupass\.zip.{0,1000}","offensive_tool_keyword","dialupass","This utility enumerates all dialup/VPN entries on your computers. and displays their logon details: User Name. Password. and Domain. You can use it to recover a lost password of your Internet connection or VPN.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/dialupass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40873"
"*Dictionary brute force attack on SSH services*",".{0,1000}Dictionary\sbrute\sforce\sattack\son\sSSH\sservices.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","0","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","40875"
"*dievus/lnkbomb*",".{0,1000}dievus\/lnkbomb.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","1","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","40881"
"*dir /a:h C:\Users\*\AppData\Local\Microsoft\Credentials\*",".{0,1000}dir\s\/a\:h\sC\:\\Users\\.{0,1000}\\AppData\\Local\\Microsoft\\Credentials\\.{0,1000}","greyware_tool_keyword","dir","Find Potential Credential in Files - This directory often contains encrypted credentials or other sensitive files related to user accounts","T1005 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40902"
"*dir /a:h C:\Users\*\AppData\Roaming\Microsoft\Credentials\*",".{0,1000}dir\s\/a\:h\sC\:\\Users\\.{0,1000}\\AppData\\Roaming\\Microsoft\\Credentials\\.{0,1000}","greyware_tool_keyword","dir","Find Potential Credential in Files - This directory often contains encrypted credentials or other sensitive files related to user accounts","T1005 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","40903"
"*dirb/wordlists*",".{0,1000}dirb\/wordlists.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","40912"
"*dirkjanm/ROADtoken*",".{0,1000}dirkjanm\/ROADtoken.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","1","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","40931"
"*Disabling RDPStrike*",".{0,1000}Disabling\sRDPStrike.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","0","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","40992"
"*Disabling RdpThief*",".{0,1000}Disabling\sRdpThief.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#content","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","40993"
"*diskcryptor2john.py*",".{0,1000}diskcryptor2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","41038"
"*diskshadow /s *",".{0,1000}diskshadow\s\/s\s.{0,1000}","greyware_tool_keyword","diskshadow","diskshadow.exe abused by attackers with a script to create a VSS on a DC or delete the shadow copies on the systems","T1003 - T1084 - T1070","TA0006 - TA0007 - TA0005","N/A","BlackBasta","Credential Access","https://x.com/SecurityAura/status/1869579192905703735","1","0","N/A","could be legitimate scripts","10","10","N/A","N/A","N/A","N/A","41040"
"*diskshadow -s *",".{0,1000}diskshadow\s\-s\s.{0,1000}","greyware_tool_keyword","diskshadow","diskshadow.exe abused by attackers with a script to create a VSS on a DC or delete the shadow copies on the systems","T1003 - T1084 - T1070","TA0006 - TA0007 - TA0005","N/A","BlackBasta","Credential Access","https://x.com/SecurityAura/status/1869579192905703735","1","0","N/A","could be legitimate scripts","10","10","N/A","N/A","N/A","N/A","41042"
"*diskshadow.exe /s *",".{0,1000}diskshadow\.exe\s\/s\s.{0,1000}","greyware_tool_keyword","diskshadow","diskshadow.exe abused by attackers with a script to create a VSS on a DC or delete the shadow copies on the systems","T1003 - T1084 - T1070","TA0006 - TA0007 - TA0005","N/A","BlackBasta","Credential Access","https://x.com/SecurityAura/status/1869579192905703735","1","0","N/A","could be legitimate scripts","10","10","N/A","N/A","N/A","N/A","41043"
"*diskshadow.exe -s *",".{0,1000}diskshadow\.exe\s\-s\s.{0,1000}","greyware_tool_keyword","diskshadow","diskshadow.exe abused by attackers with a script to create a VSS on a DC or delete the shadow copies on the systems","T1003 - T1084 - T1070","TA0006 - TA0007 - TA0005","N/A","BlackBasta","Credential Access","https://x.com/SecurityAura/status/1869579192905703735","1","0","N/A","could be legitimate scripts","10","10","N/A","N/A","N/A","N/A","41045"
"*diskshadow.exe"" /s *",".{0,1000}diskshadow\.exe\""\s\/s\s.{0,1000}","greyware_tool_keyword","diskshadow","diskshadow.exe abused by attackers with a script to create a VSS on a DC or delete the shadow copies on the systems","T1003 - T1084 - T1070","TA0006 - TA0007 - TA0005","N/A","BlackBasta","Credential Access","https://x.com/SecurityAura/status/1869579192905703735","1","0","N/A","could be legitimate scripts","10","10","N/A","N/A","N/A","N/A","41046"
"*diskshadow.exe"" -s *",".{0,1000}diskshadow\.exe\""\s\-s\s.{0,1000}","greyware_tool_keyword","diskshadow","diskshadow.exe abused by attackers with a script to create a VSS on a DC or delete the shadow copies on the systems","T1003 - T1084 - T1070","TA0006 - TA0007 - TA0005","N/A","BlackBasta","Credential Access","https://x.com/SecurityAura/status/1869579192905703735","1","0","N/A","could be legitimate scripts","10","10","N/A","N/A","N/A","N/A","41048"
"*DIT Explorer Credential Extractor*",".{0,1000}DIT\sExplorer\sCredential\sExtractor.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#content","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41070"
"*DitExplorer.Core*",".{0,1000}DitExplorer\.Core.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41071"
"*DitExplorer.CredentialExtraction*",".{0,1000}DitExplorer\.CredentialExtraction.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41072"
"*DitExplorer.EseInterop*",".{0,1000}DitExplorer\.EseInterop.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41073"
"*DitExplorer.Ntds*",".{0,1000}DitExplorer\.Ntds.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41074"
"*DitExplorer.UI.*",".{0,1000}DitExplorer\.UI\..{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41075"
"*DitExplorer.UI.WpfApp.dll*",".{0,1000}DitExplorer\.UI\.WpfApp\.dll.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41076"
"*DitExplorer.UI.WpfApp.exe*",".{0,1000}DitExplorer\.UI\.WpfApp\.exe.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41077"
"*DitExplorer-v1.0-win64-release.zip*",".{0,1000}DitExplorer\-v1\.0\-win64\-release\.zip.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41078"
"*DitExplorer-v1.0-win64-release-standalone.zip*",".{0,1000}DitExplorer\-v1\.0\-win64\-release\-standalone\.zip.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41079"
"*diversenok/TokenUniverse*",".{0,1000}diversenok\/TokenUniverse.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","41082"
"*djhohnstein/SharpChromium*",".{0,1000}djhohnstein\/SharpChromium.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","41084"
"*dllexploit.*",".{0,1000}dllexploit\..{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","1","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","41111"
"*dllinject.py*",".{0,1000}dllinject\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41121"
"*dmg2john.py*",".{0,1000}dmg2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","41145"
"*dngmlblcodfobpdpecaadgfbcggfjfnm*",".{0,1000}dngmlblcodfobpdpecaadgfbcggfjfnm.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","41158"
"*DNS-Enum-*-*.log*",".{0,1000}DNS\-Enum\-.{0,1000}\-.{0,1000}\.log.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","41261"
"*doc/extras/HACKING.*",".{0,1000}doc\/extras\/HACKING\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","41307"
"*docker build . -t spraycharles*",".{0,1000}docker\sbuild\s\.\s\-t\sspraycharles.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","41311"
"*docker build -t credmaster*",".{0,1000}docker\sbuild\s\-t\scredmaster.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","41313"
"*docker build -t legba .*",".{0,1000}docker\sbuild\s\-t\slegba\s\..{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","41316"
"*docker run legba*",".{0,1000}docker\srun\slegba.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","41339"
"*docstring for bruteforce.*",".{0,1000}docstring\sfor\sbruteforce\..{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","41355"
"*Domain/CommandCollection*",".{0,1000}Domain\/CommandCollection.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","41369"
"*DomainPasswordSpray*",".{0,1000}DomainPasswordSpray.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!","t1110 - T1114 - T1555","TA0006 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","N/A","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","41380"
"*DomainPasswordSpray.ps1*",".{0,1000}DomainPasswordSpray\.ps1.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","41381"
"*DomainPasswordSpray.ps1*",".{0,1000}DomainPasswordSpray\.ps1.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","1","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","41382"
"*DomainPasswordSpray.psm1*",".{0,1000}DomainPasswordSpray\.psm1.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","41383"
"*domcachedump.py*",".{0,1000}domcachedump\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41394"
"*domcachedumplive.py*",".{0,1000}domcachedumplive\.py.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","41395"
"*donapapi -pvk *",".{0,1000}donapapi\s\-pvk\s.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41400"
"*Done! Check for existing lsass.dmp file into current folder*",".{0,1000}Done!\sCheck\sfor\sexisting\slsass\.dmp\sfile\sinto\scurrent\sfolder.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","#content","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","41405"
"*DoNotUseThisPassword123!*",".{0,1000}DoNotUseThisPassword123!.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","0","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","41406"
"*donpapi -credz *",".{0,1000}donpapi\s\-credz\s.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41408"
"*donpapi.lazagne.softwares*",".{0,1000}donpapi\.lazagne\.softwares.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41409"
"*donpapi.myseatbelt'*",".{0,1000}donpapi\.myseatbelt\'.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41410"
"*DonPAPI.py *",".{0,1000}DonPAPI\.py\s.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41411"
"*donpapi-master.zip*",".{0,1000}donpapi\-master\.zip.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41413"
"*Don't be evil with this. I created this tool to learn*",".{0,1000}Don\'t\sbe\sevil\swith\sthis\.\sI\screated\sthis\stool\sto\slearn.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","41414"
"*Don't use your cat's name as a password!*",".{0,1000}Don\'t\suse\syour\scat\'s\sname\sas\sa\spassword!.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#content","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","41417"
"*doredry/TokenFinder*",".{0,1000}doredry\/TokenFinder.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","1","N/A","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","41434"
"*dothatlsassthing*",".{0,1000}dothatlsassthing.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","0","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","41437"
"*download.weakpass.com/*",".{0,1000}download\.weakpass\.com\/.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","41464"
"*dpapi/decryptor.py*",".{0,1000}dpapi\/decryptor\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","10","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","41499"
"*dpapi_pick/credhist.py*",".{0,1000}dpapi_pick\/credhist\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41523"
"*DPAPImk2john.py*",".{0,1000}DPAPImk2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","41524"
"*dpl4hydra *",".{0,1000}dpl4hydra\s.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","41525"
"*dpl4hydra.sh*",".{0,1000}dpl4hydra\.sh.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","41526"
"*dpl4hydra_*.csv*",".{0,1000}dpl4hydra_.{0,1000}\.csv.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","41527"
"*dpl4hydra_*.tmp*",".{0,1000}dpl4hydra_.{0,1000}\.tmp.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","41528"
"*dpl4hydra_linksys*",".{0,1000}dpl4hydra_linksys.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","41529"
"*dploot -*",".{0,1000}dploot\s\-.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41530"
"*dploot sccm -d*",".{0,1000}dploot\ssccm\s\-d.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41531"
"*dploot*backupkey*",".{0,1000}dploot.{0,1000}backupkey.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41532"
"*dploot*browser*",".{0,1000}dploot.{0,1000}browser.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41533"
"*dploot*certificates*",".{0,1000}dploot.{0,1000}certificates.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41534"
"*dploot*credentials*",".{0,1000}dploot.{0,1000}credentials.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41535"
"*dploot*machinecertificates*",".{0,1000}dploot.{0,1000}machinecertificates.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41536"
"*dploot*machinecredentials*",".{0,1000}dploot.{0,1000}machinecredentials.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41537"
"*dploot*machinemasterkeys*",".{0,1000}dploot.{0,1000}machinemasterkeys.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41538"
"*dploot*machinevaults*",".{0,1000}dploot.{0,1000}machinevaults.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41539"
"*dploot*masterkeys*",".{0,1000}dploot.{0,1000}masterkeys.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41540"
"*dploot*vaults*",".{0,1000}dploot.{0,1000}vaults.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41541"
"*dploot*wifi*",".{0,1000}dploot.{0,1000}wifi.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41542"
"*dploot.lib.dpapi*",".{0,1000}dploot\.lib\.dpapi.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41543"
"*dploot.lib.smb*",".{0,1000}dploot\.lib\.smb.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41544"
"*dploot.triage.*",".{0,1000}dploot\.triage\..{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41545"
"*dploot.triage.sccm import SCCMTriage*",".{0,1000}dploot\.triage\.sccm\simport\sSCCMTriage.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41546"
"*dploot/releases/download/*/dploot*",".{0,1000}dploot\/releases\/download\/.{0,1000}\/dploot.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41547"
"*dploot_linux_adm64*",".{0,1000}dploot_linux_adm64.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","#linux","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41548"
"*dploot-main.zip*",".{0,1000}dploot\-main\.zip.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41549"
"*DragonCastle - @TheXC3LL*",".{0,1000}DragonCastle\s\-\s\@TheXC3LL.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","41556"
"*DragonCastle.dll*",".{0,1000}DragonCastle\.dll.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","41557"
"*dragoncastle.py -*",".{0,1000}dragoncastle\.py\s\-.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","0","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","41558"
"*DuBrute v*",".{0,1000}DuBrute\sv.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","0","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","41606"
"*dubrute.exe*",".{0,1000}dubrute\.exe.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","1","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","41607"
"*DUBrute_v*",".{0,1000}DUBrute_v.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","0","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","41608"
"*Dump AAD connect account credential in current context*",".{0,1000}Dump\sAAD\sconnect\saccount\scredential\sin\scurrent\scontext.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","0","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","41616"
"*Dump cookies from Chrome or Edge*",".{0,1000}Dump\scookies\sfrom\sChrome\sor\sEdge.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#content","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","41619"
"*Dump Credential Manager for all logged in users*",".{0,1000}Dump\sCredential\sManager\sfor\sall\slogged\sin\susers.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#content","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","41620"
"*Dump Kerberos tickets to file*",".{0,1000}Dump\sKerberos\stickets\sto\sfile.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","41621"
"*Dump looted SCCM secrets to specified directory*",".{0,1000}Dump\slooted\sSCCM\ssecrets\sto\sspecified\sdirectory.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41622"
"*Dump lsass.exe using MiniDumpWriteDump*",".{0,1000}Dump\slsass\.exe\susing\sMiniDumpWriteDump.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","41623"
"*Dump SCCM secrets from WMI requests results*",".{0,1000}Dump\sSCCM\ssecrets\sfrom\sWMI\srequests\sresults.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","41624"
"*dump_chrome_user*",".{0,1000}dump_chrome_user.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41625"
"*dump_CREDENTIAL_MSOFFICE*",".{0,1000}dump_CREDENTIAL_MSOFFICE.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41626"
"*dump_CREDENTIAL_TASKSCHEDULER(*",".{0,1000}dump_CREDENTIAL_TASKSCHEDULER\(.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41627"
"*dump_CREDENTIAL_TASKSCHEDULER*",".{0,1000}dump_CREDENTIAL_TASKSCHEDULER.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41628"
"*dump_CREDENTIAL_TSE*",".{0,1000}dump_CREDENTIAL_TSE.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41629"
"*dump_firefox_user*",".{0,1000}dump_firefox_user.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41632"
"*dump_jenkins*",".{0,1000}dump_jenkins.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41634"
"*dump_keepassx*",".{0,1000}dump_keepassx.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41635"
"*dump_lsass(*",".{0,1000}dump_lsass\(.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41636"
"*dump_ssh_keys*",".{0,1000}dump_ssh_keys.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41643"
"*dump_tomcat*",".{0,1000}dump_tomcat.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41644"
"*dump_VAULT_INTERNET_EXPLORER*",".{0,1000}dump_VAULT_INTERNET_EXPLORER.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41645"
"*dump_VAULT_NGC_LOCAL_ACCOOUNT*",".{0,1000}dump_VAULT_NGC_LOCAL_ACCOOUNT.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41646"
"*dump_VAULT_WIN_BIO_KEY*",".{0,1000}dump_VAULT_WIN_BIO_KEY.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41647"
"*dump_webconf*",".{0,1000}dump_webconf.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41648"
"*dump_webpass*",".{0,1000}dump_webpass.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41649"
"*dump_wifi_wpa_*",".{0,1000}dump_wifi_wpa_.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","41650"
"*DumpAADSyncCreds.csproj*",".{0,1000}DumpAADSyncCreds\.csproj.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","1","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","41653"
"*DumpAADSyncCreds.exe*",".{0,1000}DumpAADSyncCreds\.exe.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","1","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","41654"
"*DumpAADSyncCreds.sln*",".{0,1000}DumpAADSyncCreds\.sln.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","1","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","41655"
"*--dump-bitlocker*--ntds-file *",".{0,1000}\-\-dump\-bitlocker.{0,1000}\-\-ntds\-file\s.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","41656"
"*DumpCreds*",".{0,1000}DumpCreds.{0,1000}","offensive_tool_keyword","DumpCreds","Dumpcreds is a tool that may be used to extract various credentials from running processes. I just take a look at mimipenguin(https://github.com/huntergregal/mimipenguin) and tried to improve it a bit","T1055 - T1003 - T1216 - T1002 - T1552","TA0002 - TA0003 - TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/ponypot/dumpcreds","1","1","N/A","N/A","N/A","1","6","1","2019-10-08T07:26:31Z","2017-10-10T12:57:42Z","41660"
"*Dumped by AvDump*",".{0,1000}Dumped\sby\sAvDump.{0,1000}","greyware_tool_keyword","AVDump","Avast AV to dump LSASS (C:\Program Files\Avast Software\Avast)","T1003.001 - T1059.001 - T1106","TA0006","N/A","Dispossessor","Credential Access","N/A","1","0","#content","lolbin","8","9","N/A","N/A","N/A","N/A","41664"
"*Dumpert by Outflank*",".{0,1000}Dumpert\sby\sOutflank.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#content","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41666"
"*dumpert.dmp*",".{0,1000}dumpert\.dmp.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41668"
"*Dumpert.exe*",".{0,1000}Dumpert\.exe.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41670"
"*Dumpert.git*",".{0,1000}Dumpert\.git.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41671"
"*dumpert.py*",".{0,1000}dumpert\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41672"
"*dumpert_path=*",".{0,1000}dumpert_path\=.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41673"
"*Dumpert-Aggressor*",".{0,1000}Dumpert\-Aggressor.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41675"
"*dumpertdll*",".{0,1000}dumpertdll.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41676"
"*Dumpert-DLL*",".{0,1000}Dumpert\-DLL.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41677"
"*dumpertdll.py*",".{0,1000}dumpertdll\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","41678"
"*Dumping cached domain logon information *",".{0,1000}Dumping\scached\sdomain\slogon\sinformation\s.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","41680"
"*Dumping Domain Credentials (*",".{0,1000}Dumping\sDomain\sCredentials\s\(.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","41681"
"*Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot*",".{0,1000}Dumping\sLSASS\smemory\swith\sMiniDumpWriteDump\son\sPssCaptureSnapShot.{0,1000}","offensive_tool_keyword","ATPMiniDump","Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis","T1003 - T1005 - T1055 - T1218","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/b4rtik/ATPMiniDump","1","0","#content","N/A","N/A","3","255","46","2019-12-02T15:01:22Z","2019-11-29T19:49:54Z","41682"
"*dumping passwords from %s (pid:*",".{0,1000}dumping\spasswords\sfrom\s\%s\s\(pid\:.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#content","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","41683"
"*DumpKernel-S1.ps1*",".{0,1000}DumpKernel\-S1\.ps1.{0,1000}","offensive_tool_keyword","DumpKernel-S1.ps1","SentinelHelper to perform a live kernel dump in a Windows environment","T1055 - T1003 - T1112","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8f29e09d74b73e1dec3f9049c4358e80","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","41684"
"*DumpLSASS-main.zip*",".{0,1000}DumpLSASS\-main\.zip.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","1","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","41686"
"*dumpmethod.dumpert*",".{0,1000}dumpmethod\.dumpert.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#content","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41687"
"*DumpNParse-main.zip*",".{0,1000}DumpNParse\-main\.zip.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","1","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","41688"
"*DumpNTLMInfo.py*",".{0,1000}DumpNTLMInfo\.py.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","1","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","41690"
"*DumpProcessPid -targetPID * -outputFile*",".{0,1000}DumpProcessPid\s\-targetPID\s.{0,1000}\s\-outputFile.{0,1000}","greyware_tool_keyword","SentinelAgent","dump a process with SentinelAgent.exe","T1003 - T1055","TA0006 - TA0005","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e","1","0","N/A","N/A","8","7","N/A","N/A","N/A","N/A","41695"
"*DumpShellcode.*",".{0,1000}DumpShellcode\..{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","41697"
"*DumpShellcode.exe*",".{0,1000}DumpShellcode\.exe.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","41698"
"*DumpShellcode\*",".{0,1000}DumpShellcode\\.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","41699"
"*dumpy.exe --dump*",".{0,1000}dumpy\.exe\s\-\-dump.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","0","N/A","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","41703"
"*e0327c1218fd3723e20acc780e20135f41abca35c35e0f97f7eccac265f4f44e*",".{0,1000}e0327c1218fd3723e20acc780e20135f41abca35c35e0f97f7eccac265f4f44e.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#filehash","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","41732"
"*E0362605-CC11-4CD5-AFF7-B50934438658*",".{0,1000}E0362605\-CC11\-4CD5\-AFF7\-B50934438658.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","41734"
"*E0362605-CC11-4CD5-AFF7-B50934438658*",".{0,1000}E0362605\-CC11\-4CD5\-AFF7\-B50934438658.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","0","#GUIDproject","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","41735"
"*E049487C-C5BD-471E-99AE-C756E70B6520*",".{0,1000}E049487C\-C5BD\-471E\-99AE\-C756E70B6520.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz GUID project","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#GUIDproject","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","41737"
"*e05b1fa26c9571a7c6111e64a5d710f7bd03fa9795ac68a5f405ba3ac99503e5*",".{0,1000}e05b1fa26c9571a7c6111e64a5d710f7bd03fa9795ac68a5f405ba3ac99503e5.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","41744"
"*e0e4200ebb8381797450c5f7da031a1c389c31c3351370daa1b53c715ea07097*",".{0,1000}e0e4200ebb8381797450c5f7da031a1c389c31c3351370daa1b53c715ea07097.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","41788"
"*e0e5c3370cdbc6fbe0531ffc55979217b24d4f0eaf18ed7567c4ffc6baf8845a*",".{0,1000}e0e5c3370cdbc6fbe0531ffc55979217b24d4f0eaf18ed7567c4ffc6baf8845a.{0,1000}","offensive_tool_keyword","Rust-Malware-Samples","open source informations stealer in rust","T1003 - T1083 - T1114 - T1074","TA0006 - TA0009 - TA0005","N/A","N/A","Credential Access","https://github.com/Whitecat18/Rust-for-Malware-Development/tree/main/Malware-Samples","1","0","#filehash","N/A","10","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","41789"
"*e1cd2b55-3b4f-41bd-a168-40db41e34349*",".{0,1000}e1cd2b55\-3b4f\-41bd\-a168\-40db41e34349.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","0","#GUIDproject","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","41849"
"*E1D50AB4-E1CD-4C31-AED5-E957D2E6B01F*",".{0,1000}E1D50AB4\-E1CD\-4C31\-AED5\-E957D2E6B01F.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#GUIDproject","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","41852"
"*e1ed880a56c4cbe995035969850bb409996edba8e31c05d654f525112026633f*",".{0,1000}e1ed880a56c4cbe995035969850bb409996edba8e31c05d654f525112026633f.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","41860"
"*E2596512-8A36-4D48-8AA1-9791E48A16CC*",".{0,1000}E2596512\-8A36\-4D48\-8AA1\-9791E48A16CC.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#GUIDProject","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","41896"
"*e273485e4f1382b7848b6c263cf0ce9e37aa783e9e781630aaa50daffea5aeb2*",".{0,1000}e273485e4f1382b7848b6c263cf0ce9e37aa783e9e781630aaa50daffea5aeb2.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","41899"
"*e292dfd2c82421324fdc94d544472f78528bdd862148509cab29ecdcbf9d8c4c*",".{0,1000}e292dfd2c82421324fdc94d544472f78528bdd862148509cab29ecdcbf9d8c4c.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","#filehash","N/A","10","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","41912"
"*e2964ea4bc4e439e55f46ed309904e9592145858076d65363a2bbbab0bd608cc*",".{0,1000}e2964ea4bc4e439e55f46ed309904e9592145858076d65363a2bbbab0bd608cc.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","41915"
"*e2c3b2d10ba4db5f13e05de8197818f8ce94da878b5eba6c82a7feb73340b538*",".{0,1000}e2c3b2d10ba4db5f13e05de8197818f8ce94da878b5eba6c82a7feb73340b538.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","41924"
"*E2FDD6CC-9886-456C-9021-EE2C47CF67B7*",".{0,1000}E2FDD6CC\-9886\-456C\-9021\-EE2C47CF67B7.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","0","#GUIDproject","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","41940"
"*e3126e7a17ffcf6e659b3b603134067a47769e74244032cb6e23a5532913291c*",".{0,1000}e3126e7a17ffcf6e659b3b603134067a47769e74244032cb6e23a5532913291c.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","41953"
"*e336612e451075ecb75b27bd473aa21aba4f0a98df3cef57ad303894cce4f34b*",".{0,1000}e336612e451075ecb75b27bd473aa21aba4f0a98df3cef57ad303894cce4f34b.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","41961"
"*e382edfe2f7c38cb3d6abd20c75e1ac24ddc19f921aba4b92dda3e1774e45240*",".{0,1000}e382edfe2f7c38cb3d6abd20c75e1ac24ddc19f921aba4b92dda3e1774e45240.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","0","#filehash","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","41983"
"*e3a0aa509ad07aab04f9a052a9abc681d414871cd0277deef4b95ea98f1243c8*",".{0,1000}e3a0aa509ad07aab04f9a052a9abc681d414871cd0277deef4b95ea98f1243c8.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#filehash","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","41988"
"*e3bd611e8aa3d18d81944ebdabf51ce9aed8eb414a95ee8eb6d45ca0ebd58003*",".{0,1000}e3bd611e8aa3d18d81944ebdabf51ce9aed8eb414a95ee8eb6d45ca0ebd58003.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","#filehash","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","42000"
"*e415296f956351bc4060d03fa52512415f353e26236b7fd97642f7ef608ca4e9*",".{0,1000}e415296f956351bc4060d03fa52512415f353e26236b7fd97642f7ef608ca4e9.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","#filehash","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","42021"
"*e4b84fd04cf067c5bdcab91f85599ab53671d9eda16a60590886824b8b5e7cab*",".{0,1000}e4b84fd04cf067c5bdcab91f85599ab53671d9eda16a60590886824b8b5e7cab.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","42059"
"*e4bc4fc4b8f65caedc7302900804da6af5689a7f3a03b31ae62433b24f393568*",".{0,1000}e4bc4fc4b8f65caedc7302900804da6af5689a7f3a03b31ae62433b24f393568.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","#filehash","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","42060"
"*e5285e73892bee5dd811a25cc0f2848fbe995c0aebfa2fd4ac533a8f2a619cec*",".{0,1000}e5285e73892bee5dd811a25cc0f2848fbe995c0aebfa2fd4ac533a8f2a619cec.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","42089"
"*e52f7c5cdfbcfd07c3af1a5d4b192e804f2a29cc1cacff6573ad701cbeb8440a*",".{0,1000}e52f7c5cdfbcfd07c3af1a5d4b192e804f2a29cc1cacff6573ad701cbeb8440a.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","#filehash","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","42091"
"*E54195F0-060C-4B24-98F2-AD9FB5351045*",".{0,1000}E54195F0\-060C\-4B24\-98F2\-AD9FB5351045.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","#GUIDproject","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","42096"
"*e56bee79647fdae60a15c1dc283a990121cd5f387900929ca044dff8e0e2b427*",".{0,1000}e56bee79647fdae60a15c1dc283a990121cd5f387900929ca044dff8e0e2b427.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","42110"
"*e58f5924f64e96f3f84ef788dde5fc6699f91086a8fbc4797065670a37a3cbcd*",".{0,1000}e58f5924f64e96f3f84ef788dde5fc6699f91086a8fbc4797065670a37a3cbcd.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","0","#filehash","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","42123"
"*e5a991c13b8ba7bd2e435dec2682cd31de0013b3455c18e3883608e75363de3b*",".{0,1000}e5a991c13b8ba7bd2e435dec2682cd31de0013b3455c18e3883608e75363de3b.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","0","#filehash","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","42130"
"*e60c210687e79347d06f9a144ee84417ba9ac4c1f303720f2fe4509734d670d6*",".{0,1000}e60c210687e79347d06f9a144ee84417ba9ac4c1f303720f2fe4509734d670d6.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","42147"
"*e60c210687e79347d06f9a144ee84417ba9ac4c1f303720f2fe4509734d670d6*",".{0,1000}e60c210687e79347d06f9a144ee84417ba9ac4c1f303720f2fe4509734d670d6.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","42148"
"*E6104BC9-FEA9-4EE9-B919-28156C1F2EDE*",".{0,1000}E6104BC9\-FEA9\-4EE9\-B919\-28156C1F2EDE.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","#GUIDproject","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","42150"
"*e685904d607a73c1916b6a7d9cc2eb42e4afd1cf2e77e728b7dbeb141eda2735*",".{0,1000}e685904d607a73c1916b6a7d9cc2eb42e4afd1cf2e77e728b7dbeb141eda2735.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#filehash","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","42185"
"*e6b9b81643f27334434561f226d95e6729518eb4eb016e5a54a809fab583ef4d*",".{0,1000}e6b9b81643f27334434561f226d95e6729518eb4eb016e5a54a809fab583ef4d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","42197"
"*e6b9b81643f27334434561f226d95e6729518eb4eb016e5a54a809fab583ef4d*",".{0,1000}e6b9b81643f27334434561f226d95e6729518eb4eb016e5a54a809fab583ef4d.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","42198"
"*e6be8653e8355627406150a70434675aaad1cab5dbe2116237df5bf2ff7f4b45*",".{0,1000}e6be8653e8355627406150a70434675aaad1cab5dbe2116237df5bf2ff7f4b45.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","42200"
"*e6e05a88178633c271919ae5ea4c9633991774e2fd345ffe3052c209e2ef31d5*",".{0,1000}e6e05a88178633c271919ae5ea4c9633991774e2fd345ffe3052c209e2ef31d5.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","0","#filehash","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","42211"
"*e6e97a564798df361f372645253f7601dbfd3c762c4143326df41a574bc97d22*",".{0,1000}e6e97a564798df361f372645253f7601dbfd3c762c4143326df41a574bc97d22.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","42217"
"*e71c92b2228f78010d91f373ea3c1ed474c0b6298c3b9615edf9edb42be35abb*",".{0,1000}e71c92b2228f78010d91f373ea3c1ed474c0b6298c3b9615edf9edb42be35abb.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","42231"
"*e71cda5e7c018f18aefcdfbce171cfeee7b8d556e5036d8b8f0864efc5f2156b*",".{0,1000}e71cda5e7c018f18aefcdfbce171cfeee7b8d556e5036d8b8f0864efc5f2156b.{0,1000}","offensive_tool_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","42232"
"*e7542c38e0b979f920fb88b59b25c3d6ae433ca145f7758938b322a71accecae*",".{0,1000}e7542c38e0b979f920fb88b59b25c3d6ae433ca145f7758938b322a71accecae.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","42252"
"*e7ce68e94b4b3a3f8ba4e660edd00c794af6d158ce6f993d74d9732cfd83f2c7*",".{0,1000}e7ce68e94b4b3a3f8ba4e660edd00c794af6d158ce6f993d74d9732cfd83f2c7.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","42288"
"*e80bda100b7b75500bd6f4cc09e566e5467c784876bc01ba934ea8792daf8b11*",".{0,1000}e80bda100b7b75500bd6f4cc09e566e5467c784876bc01ba934ea8792daf8b11.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","0","#filehash #linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","42312"
"*e81284fcd76acab65fcb296db056f50a4fa61eb120581ff2d494006d97f2f762*",".{0,1000}e81284fcd76acab65fcb296db056f50a4fa61eb120581ff2d494006d97f2f762.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","#filehash","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","42314"
"*e81a8f8ad804c4d83869d7806a303ff04f31cce376c5df8aada2e9db2c1eeb98*",".{0,1000}e81a8f8ad804c4d83869d7806a303ff04f31cce376c5df8aada2e9db2c1eeb98.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","42316"
"*e81a8f8ad804c4d83869d7806a303ff04f31cce376c5df8aada2e9db2c1eeb98*",".{0,1000}e81a8f8ad804c4d83869d7806a303ff04f31cce376c5df8aada2e9db2c1eeb98.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","42317"
"*e82a6a97f9239b0e6bd68c9ce795dc7ae29f6e008bfb8ab63f2dfe9e94817bea*",".{0,1000}e82a6a97f9239b0e6bd68c9ce795dc7ae29f6e008bfb8ab63f2dfe9e94817bea.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","42318"
"*E82BCAD1-0D2B-4E95-B382-933CF78A8128*",".{0,1000}E82BCAD1\-0D2B\-4E95\-B382\-933CF78A8128.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","0","#GUIDproject","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","42322"
"*e8467998e22a50d952a786c2ce337493cdd4d32a7e035a7af58bdc3c9b3f17ed*",".{0,1000}e8467998e22a50d952a786c2ce337493cdd4d32a7e035a7af58bdc3c9b3f17ed.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#filehash","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","42328"
"*e8930c16d171577f55aa0cbdd8fe5fe656bba46751cd44e2e2fda325b6f6e9b9*",".{0,1000}e8930c16d171577f55aa0cbdd8fe5fe656bba46751cd44e2e2fda325b6f6e9b9.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","42342"
"*E8CA6917-CB06-4128-96CD-59676731B24A*",".{0,1000}E8CA6917\-CB06\-4128\-96CD\-59676731B24A.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#GUIDProject","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","42362"
"*e8ddad70f68375dbf38d0e8550acf1e53f5382e0bf9a0ee8f02f8b1c6222db81*",".{0,1000}e8ddad70f68375dbf38d0e8550acf1e53f5382e0bf9a0ee8f02f8b1c6222db81.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","#filehash","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","42367"
"*e8fa4ebebd818555956378e99e7cf03fe694f105e45c4531824166d7689997f4*",".{0,1000}e8fa4ebebd818555956378e99e7cf03fe694f105e45c4531824166d7689997f4.{0,1000}","offensive_tool_keyword","Rust-Malware-Samples","open source informations stealer in rust","T1003 - T1083 - T1114 - T1074","TA0006 - TA0009 - TA0005","N/A","N/A","Credential Access","https://github.com/Whitecat18/Rust-for-Malware-Development/tree/main/Malware-Samples","1","0","#filehash","N/A","10","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","42377"
"*e9073493a75df11850c5f3e6738b108c831ed0346bd6b9c5e5cd18e4bd4d645e*",".{0,1000}e9073493a75df11850c5f3e6738b108c831ed0346bd6b9c5e5cd18e4bd4d645e.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","42382"
"*E9172085-1595-4E98-ABF8-E890D2489BB5*",".{0,1000}E9172085\-1595\-4E98\-ABF8\-E890D2489BB5.{0,1000}","offensive_tool_keyword","GlobalUnProtect","Decrypt GlobalProtect configuration and cookie files.","T1552 - T1003 - T1555","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rotarydrone/GlobalUnProtect","1","0","#GUIDproject","N/A","9","2","147","19","2024-09-10T20:19:24Z","2024-09-04T15:31:52Z","42384"
"*e94c578a73298e4f6dbb5b3cb4cf4adcea54f6a971e88428f651cd555e5932b0*",".{0,1000}e94c578a73298e4f6dbb5b3cb4cf4adcea54f6a971e88428f651cd555e5932b0.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","0","#filehash","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","42396"
"*e953e1f2e64f00273fe92e24d434d7a6619bb873d43bef5dd330d42de591dc8d*",".{0,1000}e953e1f2e64f00273fe92e24d434d7a6619bb873d43bef5dd330d42de591dc8d.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","#filehash","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","42399"
"*e97da4284459149541ef261a6de0bec7ef8a3d2d28d3384b7b256c089d524690*",".{0,1000}e97da4284459149541ef261a6de0bec7ef8a3d2d28d3384b7b256c089d524690.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#filehash","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","42412"
"*e98bb5dcf6f202575e80431612a35d072adca1f57cb74d9e198dd51e6fe6a483*",".{0,1000}e98bb5dcf6f202575e80431612a35d072adca1f57cb74d9e198dd51e6fe6a483.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","42416"
"*ea17314d15bea466526ba9ca154009f04f46da461899ac4533d00479317703b8*",".{0,1000}ea17314d15bea466526ba9ca154009f04f46da461899ac4533d00479317703b8.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#filehash","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","42452"
"*EA92F1E6-3F34-48F8-8B0A-F2BBC19220EF*",".{0,1000}EA92F1E6\-3F34\-48F8\-8B0A\-F2BBC19220EF.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#GUIDproject","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","42493"
"*eab9878a9916e998587cf5587e3ac5ce0e5509713b3afe6e64003e8c6962b565*",".{0,1000}eab9878a9916e998587cf5587e3ac5ce0e5509713b3afe6e64003e8c6962b565.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","#filehash","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","42506"
"*eapmd5tojohn*",".{0,1000}eapmd5tojohn.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","42521"
"*easside-ng -* -s 127.0.0.1*",".{0,1000}easside\-ng\s\-.{0,1000}\s\-s\s127\.0\.0\.1.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","42525"
"*eb046b68a014aded4f81bb952edadd283a0cd5a36fc416b89d391df3daaa6d9e*",".{0,1000}eb046b68a014aded4f81bb952edadd283a0cd5a36fc416b89d391df3daaa6d9e.{0,1000}","offensive_tool_keyword","PwDump8","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://download.openwall.net/pub/projects/john/contrib/pwdump/pwdump8-8.2.zip","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","42532"
"*eb9c1a8804daed7c8ace37adc87ac66b52e7363666e5af7912bb17695df9b4f4*",".{0,1000}eb9c1a8804daed7c8ace37adc87ac66b52e7363666e5af7912bb17695df9b4f4.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","0","#filehash","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","42568"
"*ebb285411e3ba9431b7c211c1e8ba97753699805f03663cbc367798b4db2c1fc*",".{0,1000}ebb285411e3ba9431b7c211c1e8ba97753699805f03663cbc367798b4db2c1fc.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","42579"
"*ebf94bb78b8deae210b897fd7c7da691e9fcfd215e641f28c5a0056a69e63aa6*",".{0,1000}ebf94bb78b8deae210b897fd7c7da691e9fcfd215e641f28c5a0056a69e63aa6.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#filehash","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","42595"
"*ebffe9aadf0e6b25df7573ca04de5b12d79ad0103d1fd936e333660b4359006c*",".{0,1000}ebffe9aadf0e6b25df7573ca04de5b12d79ad0103d1fd936e333660b4359006c.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","0","#filehash","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","42602"
"*ebfidpplhabeedpnhjnobghokpiioolj*",".{0,1000}ebfidpplhabeedpnhjnobghokpiioolj.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","42603"
"*ec2aaff0-b349-4855-9093-96acf6ee3299*",".{0,1000}ec2aaff0\-b349\-4855\-9093\-96acf6ee3299.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","0","#GUIDProject","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","42617"
"*echo [.ShellClassInfo] > desktop.ini*",".{0,1000}echo\s\[\.ShellClassInfo\]\s\>\sdesktop\.ini.{0,1000}","greyware_tool_keyword","attrib","NTLM Leak via Desktop.ini","T1555.003 - T1081.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Anti-Forensics.md","1","0","N/A","N/A","10","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","42702"
"*echo IconResource=\\*\* >> desktop.ini*",".{0,1000}echo\sIconResource\=\\\\.{0,1000}\\.{0,1000}\s\>\>\sdesktop\.ini.{0,1000}","greyware_tool_keyword","attrib","NTLM Leak via Desktop.ini","T1555.003 - T1081.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Anti-Forensics.md","1","0","N/A","N/A","10","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","42720"
"*ecryptfs2john.py*",".{0,1000}ecryptfs2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","42745"
"*ed2f501408a7a6e1a854c29c4b0bc5648a6aa8612432df829008931b3e34bf56*",".{0,1000}ed2f501408a7a6e1a854c29c4b0bc5648a6aa8612432df829008931b3e34bf56.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","42765"
"*ed99b1d4757d0848ced6b91f18326c42127f6f79ad1cc7e7fafeee91388004e3*",".{0,1000}ed99b1d4757d0848ced6b91f18326c42127f6f79ad1cc7e7fafeee91388004e3.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","0","#filehash","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","42791"
"*ed9d3ee993fe0a36bb7a7fce3940112ea29eccca58165738a758c58a3fe0ae54*",".{0,1000}ed9d3ee993fe0a36bb7a7fce3940112ea29eccca58165738a758c58a3fe0ae54.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","#filehash","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","42792"
"*eda5a3b5c4316ec711ae975cdf6a483e244ac195e06254a0e9bade484d9c0533*",".{0,1000}eda5a3b5c4316ec711ae975cdf6a483e244ac195e06254a0e9bade484d9c0533.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","42795"
"*eda5a3b5c4316ec711ae975cdf6a483e244ac195e06254a0e9bade484d9c0533*",".{0,1000}eda5a3b5c4316ec711ae975cdf6a483e244ac195e06254a0e9bade484d9c0533.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","42796"
"*edd9d1b4-27f7-424a-aa21-794b19231741*",".{0,1000}edd9d1b4\-27f7\-424a\-aa21\-794b19231741.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","0","#GUIDproject","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","42808"
"*edf8c7fe2bd7241aafa9109be239698bc7e840097ffaec13a6a593876bdb6e97*",".{0,1000}edf8c7fe2bd7241aafa9109be239698bc7e840097ffaec13a6a593876bdb6e97.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","0","#filehash","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","42815"
"*edrsandblast.py*",".{0,1000}edrsandblast\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","42833"
"*ee29e80a2e8c469655fe215eac14c2fbb201116e40fd056dcd1f602e1959263b*",".{0,1000}ee29e80a2e8c469655fe215eac14c2fbb201116e40fd056dcd1f602e1959263b.{0,1000}","offensive_tool_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","#filehash","N/A","10","8","N/A","N/A","N/A","N/A","42863"
"*ee30d8fb660ce3a25a8664c6214f2766a7099bdd78392009d961d22b7fd3ded2*",".{0,1000}ee30d8fb660ce3a25a8664c6214f2766a7099bdd78392009d961d22b7fd3ded2.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","0","#filehash","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","42867"
"*EE728741-4BD4-4F7C-8E41-B8328706EA84*",".{0,1000}EE728741\-4BD4\-4F7C\-8E41\-B8328706EA84.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","#GUIDproject","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","42887"
"*EF143476-E53D-4C39-8DBB-A6AC7883236C*",".{0,1000}EF143476\-E53D\-4C39\-8DBB\-A6AC7883236C.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","#GUIDproject","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","42931"
"*ef644b1554eb1561456e7e20b136f4fff16c3a02e821d06da3c3a6dd9aa168bc*",".{0,1000}ef644b1554eb1561456e7e20b136f4fff16c3a02e821d06da3c3a6dd9aa168bc.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","42952"
"*ef98c122f795f0c0d7719fc02825df198cdd373ba56e17940d28ffaf13f5fce3*",".{0,1000}ef98c122f795f0c0d7719fc02825df198cdd373ba56e17940d28ffaf13f5fce3.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","42960"
"*ef9c57ffe31d8ceeb51daeac466dc8835807ab7d9fd3ff05ada8ce9b4836d924*",".{0,1000}ef9c57ffe31d8ceeb51daeac466dc8835807ab7d9fd3ff05ada8ce9b4836d924.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","#filehash","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","42962"
"*efa66f6391ec471ca52cd053159c8a8778f11f921da14e6daf76387f8c9afcd5*",".{0,1000}efa66f6391ec471ca52cd053159c8a8778f11f921da14e6daf76387f8c9afcd5.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#filehash","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","42968"
"*efbglgofoippbgcjepnhiblaibcnclgk*",".{0,1000}efbglgofoippbgcjepnhiblaibcnclgk.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","42975"
"*efchatz/pandora*",".{0,1000}efchatz\/pandora.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","1","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","42978"
"*efe42a7eb08755abbb5c91b36ead35cdafbd82d1e34016046cb4be5861cb2053*",".{0,1000}efe42a7eb08755abbb5c91b36ead35cdafbd82d1e34016046cb4be5861cb2053.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","#filehash","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","42983"
"*eff1f6144cbc0b092a09dc06009fc3709c937347d9b5991560588204fc183414*",".{0,1000}eff1f6144cbc0b092a09dc06009fc3709c937347d9b5991560588204fc183414.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","#filehash","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","42988"
"*egjidjbpglichdcondbcbdnbeeppgdph*",".{0,1000}egjidjbpglichdcondbcbdnbeeppgdph.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","43018"
"*eigblbgjknlfbajkfhopmcojidlgcehm*",".{0,1000}eigblbgjknlfbajkfhopmcojidlgcehm.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","43034"
"*ejabberd2john.py*",".{0,1000}ejabberd2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43035"
"*ejbalbakoplchlghecdalmeeeajnimhm*",".{0,1000}ejbalbakoplchlghecdalmeeeajnimhm.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","43036"
"*ejjladinnckdgjemekebdpeokbikhfci*",".{0,1000}ejjladinnckdgjemekebdpeokbikhfci.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","43037"
"*electrum2john.py*",".{0,1000}electrum2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43048"
"*elementalsouls/DumpLSASS*",".{0,1000}elementalsouls\/DumpLSASS.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","1","N/A","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","43049"
"*elnerd/Get-NetNTLM*",".{0,1000}elnerd\/Get\-NetNTLM.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","1","N/A","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","43073"
"*Email Password-Recovery*",".{0,1000}Email\s\sPassword\-Recovery.{0,1000}","offensive_tool_keyword","MailPassView","Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43077"
"*empire_exec.py*",".{0,1000}empire_exec\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","43104"
"*encdatavault2john.py*",".{0,1000}encdatavault2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43136"
"*encfs2john.py*",".{0,1000}encfs2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43137"
"*encrypted LSASS dump*",".{0,1000}encrypted\sLSASS\sdump.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","43152"
"*Encryption.config values are encrypted with DPAPI, decrypting*",".{0,1000}Encryption\.config\svalues\sare\sencrypted\swith\sDPAPI,\sdecrypting.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","43159"
"*enpass2john.py*",".{0,1000}enpass2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43175"
"*enpass5tojohn.py*",".{0,1000}enpass5tojohn\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43176"
"*enum_avproducts.py*",".{0,1000}enum_avproducts\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","43187"
"*Error converting offlinesam path*",".{0,1000}Error\sconverting\sofflinesam\spath.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43239"
"*Error parsing lsass dump with pypykatz*",".{0,1000}Error\sparsing\slsass\sdump\swith\spypykatz.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","43240"
"*Error: Could not create a thread for the shellcode*",".{0,1000}Error\:\sCould\snot\screate\sa\sthread\sfor\sthe\sshellcode.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","43241"
"*erwan2212/NTHASH-FPC*",".{0,1000}erwan2212\/NTHASH\-FPC.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","43243"
"*Esentutl*/p /o *.dit*",".{0,1000}Esentutl.{0,1000}\/p\s\/o\s.{0,1000}\.dit.{0,1000}","greyware_tool_keyword","esentutl","extract the AD Database","T1005 - T1006 - T1564.004 - T1105 - T1570 - T1003.003","TA0006 - TA0005 - TA0003 - TA0010","N/A","Chimera - menuPass","Credential Access","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43249"
"*esentutl.exe /y /vss *:\windows\ntds\ntds.dit*",".{0,1000}esentutl\.exe\s\/y\s\/vss\s.{0,1000}\:\\windows\\ntds\\ntds\.dit.{0,1000}","greyware_tool_keyword","esentutl","extract the AD Database","T1005 - T1006 - T1564.004 - T1105 - T1570 - T1003.003","TA0006 - TA0005 - TA0003 - TA0010","N/A","Chimera - menuPass","Credential Access","https://lolbas-project.github.io/lolbas/Binaries/Esentutl/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43250"
"*ethereum2john.py*",".{0,1000}ethereum2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","43283"
"*EtwHash.exe*",".{0,1000}EtwHash\.exe.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","1","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","43289"
"*EtwHash.git*",".{0,1000}EtwHash\.git.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","1","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","43290"
"*ETWHash.sln*",".{0,1000}ETWHash\.sln.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","1","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","43291"
"*EvanMcBroom/lsa-whisperer*",".{0,1000}EvanMcBroom\/lsa\-whisperer.{0,1000}","greyware_tool_keyword","lsa-whisperer","Tools for interacting with authentication packages using their individual message protocols","T1556.002 - T1003.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/EvanMcBroom/lsa-whisperer","1","1","N/A","N/A","6","4","316","29","2025-04-01T13:54:17Z","2022-08-04T14:35:45Z","43301"
"*EventAggregation.dll.bak*",".{0,1000}EventAggregation\.dll\.bak.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","43305"
"*EventAggregation.dll.bak*",".{0,1000}EventAggregation\.dll\.bak.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","43306"
"*EventAggregation.dll.patched*",".{0,1000}EventAggregation\.dll\.patched.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","43307"
"*EventAggregationPH.dll*",".{0,1000}EventAggregationPH\.dll.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","43308"
"*EvilLsassTwin.exe*",".{0,1000}EvilLsassTwin\.exe.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43353"
"*EvilLsassTwin.exe*",".{0,1000}EvilLsassTwin\.exe.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43354"
"*EvilLsassTwin.nim*",".{0,1000}EvilLsassTwin\.nim.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43355"
"*EvilLsassTwin.nim*",".{0,1000}EvilLsassTwin\.nim.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43356"
"*evilsocket/legba*",".{0,1000}evilsocket\/legba.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","1","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","43385"
"*evilsocket@gmail.com*",".{0,1000}evilsocket\@gmail\.com.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","0","1","#email","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","43386"
"*EvilTwin.bin*",".{0,1000}EvilTwin\.bin.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43388"
"*EvilTwin.dmp*",".{0,1000}EvilTwin\.dmp.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43389"
"*EvilTwin.dmp*",".{0,1000}EvilTwin\.dmp.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43390"
"*EvilTwin.dmp*",".{0,1000}EvilTwin\.dmp.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43391"
"*EvilTwinServer.nim*",".{0,1000}EvilTwinServer\.nim.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43392"
"*EvilTwinServer.nim*",".{0,1000}EvilTwinServer\.nim.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","43393"
"*--exec-method smbexec*",".{0,1000}\-\-exec\-method\ssmbexec.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","43451"
"*Execute('SELECT origin_url,username_value,password_value,length(password_value*",".{0,1000}Execute\(\'SELECT\sorigin_url,username_value,password_value,length\(password_value.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","43460"
"*execute_assembly SharpCloud*",".{0,1000}execute_assembly\sSharpCloud.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","0","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","43463"
"*Extedx765ensioedx765ns/*",".{0,1000}Extedx765ensioedx765ns\/.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","43630"
"*External Drive Password Recovery*",".{0,1000}External\sDrive\sPassword\sRecovery.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43635"
"*ExtPassword.exe*",".{0,1000}ExtPassword\.exe.{0,1000}","offensive_tool_keyword","ExtPassword.exe","Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer","T1081 - T1003 - T1212","TA0006 - TA0009","N/A","LockBit","Credential Access","https://www.nirsoft.net/utils/external_drive_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43650"
"*ExtractBitLockerKeys*@podalirius_*",".{0,1000}ExtractBitLockerKeys.{0,1000}\@podalirius_.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","0","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","43654"
"*ExtractBitlockerKeys.ps1*",".{0,1000}ExtractBitlockerKeys\.ps1.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","1","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","43655"
"*ExtractBitlockerKeys.py*",".{0,1000}ExtractBitlockerKeys\.py.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","1","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","43656"
"*ExtractBitlockerKeys-main*",".{0,1000}ExtractBitlockerKeys\-main.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","1","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","43657"
"*ExtractFileInfoViaNTDLL*",".{0,1000}ExtractFileInfoViaNTDLL.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","43659"
"*ExtractFirefoxProfileData(*",".{0,1000}ExtractFirefoxProfileData\(.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","43660"
"*extracttgsrepfrompcap.py*",".{0,1000}extracttgsrepfrompcap\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","43664"
"*extra-scripts*timecrack.py*",".{0,1000}extra\-scripts.{0,1000}timecrack\.py.{0,1000}","offensive_tool_keyword","Timeroast","Timeroasting takes advantage of Windows NTP authentication mechanism allowing unauthenticated attackers to effectively request a password hash of any computer or trust account by sending an NTP request with that account's RID","T1558.003 - T1059.003 - T1078.004","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/SecuraBV/Timeroast","1","1","N/A","N/A","10","3","282","28","2023-07-04T07:12:57Z","2023-01-18T09:04:05Z","43665"
"*f:\temp\pass.html*",".{0,1000}f\:\\temp\\pass\.html.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43670"
"*f:\temp\passwords.html*",".{0,1000}f\:\\temp\\passwords\.html.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","43671"
"*F00A3B5F-D9A9-4582-BBCE-FD10EFBF0C17*",".{0,1000}F00A3B5F\-D9A9\-4582\-BBCE\-FD10EFBF0C17.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","#GUIDproject","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","43676"
"*f038fdbc3ed50ebbf1ebc1c814836bcf93b4c149e5856ccf9b5400da8a974117*",".{0,1000}f038fdbc3ed50ebbf1ebc1c814836bcf93b4c149e5856ccf9b5400da8a974117.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","0","#filehash","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","43682"
"*f038fdbc3ed50ebbf1ebc1c814836bcf93b4c149e5856ccf9b5400da8a974117*",".{0,1000}f038fdbc3ed50ebbf1ebc1c814836bcf93b4c149e5856ccf9b5400da8a974117.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","#filehash","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","43683"
"*f049f7c98172f7696d6a0b312c91010720970f825eb4cff5c76c151e15f16951*",".{0,1000}f049f7c98172f7696d6a0b312c91010720970f825eb4cff5c76c151e15f16951.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","0","#filehash","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","43688"
"*f04f854c5bbfa8a33358efd2bb3e700e9be687250548a1cb21de1d661b5f04ff*",".{0,1000}f04f854c5bbfa8a33358efd2bb3e700e9be687250548a1cb21de1d661b5f04ff.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","0","#filehash #linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","43691"
"*f0b1a06aa6d5ea27814565755c6bfe2520dd71c4df02768fe7d621c3c3d0db75*",".{0,1000}f0b1a06aa6d5ea27814565755c6bfe2520dd71c4df02768fe7d621c3c3d0db75.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","0","#filehash","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","43715"
"*f14052ce01a373effaf1c74eeed9ccda8ac4f6cf3407727d4a5871df9f195f57*",".{0,1000}f14052ce01a373effaf1c74eeed9ccda8ac4f6cf3407727d4a5871df9f195f57.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","43748"
"*f150333a3943f2c7398e0dd3f97a2cb3f1c1653a220785a977ba9a7ff692dab1*",".{0,1000}f150333a3943f2c7398e0dd3f97a2cb3f1c1653a220785a977ba9a7ff692dab1.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","#filehash","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","43757"
"*F1527C49-CA1F-4994-BB9D-E20DD2C607FD*",".{0,1000}F1527C49\-CA1F\-4994\-BB9D\-E20DD2C607FD.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","0","#GUIDproject","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","43760"
"*F1653F20-D47D-4F29-8C55-3C835542AF5F*",".{0,1000}F1653F20\-D47D\-4F29\-8C55\-3C835542AF5F.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","0","#GUIDproject","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","43768"
"*F1653F20-D47D-4F29-8C55-3C835542AF5F*",".{0,1000}F1653F20\-D47D\-4F29\-8C55\-3C835542AF5F.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","0","#GUIDproject","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","43769"
"*f2514c44ea0566d15601e6179fab45dbb023b78cb0903a28196a31599f17be00*",".{0,1000}f2514c44ea0566d15601e6179fab45dbb023b78cb0903a28196a31599f17be00.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059 - T1070.004","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","#filehash","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","43821"
"*f253b430b9d2dafe0e67a9974e7a806f21c6589c02aed1cdc595d23fe619f492*",".{0,1000}f253b430b9d2dafe0e67a9974e7a806f21c6589c02aed1cdc595d23fe619f492.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","43822"
"*f2691b74-129f-4ac2-a88a-db4b0f36b609*",".{0,1000}f2691b74\-129f\-4ac2\-a88a\-db4b0f36b609.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","0","#GUIDproject","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","43825"
"*f2c7d2d0539d1549c8f1a9a461b467d6ef0d4eb40c3ab8ba5412398d65a6f398*",".{0,1000}f2c7d2d0539d1549c8f1a9a461b467d6ef0d4eb40c3ab8ba5412398d65a6f398.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","43844"
"*f2c7d2d0539d1549c8f1a9a461b467d6ef0d4eb40c3ab8ba5412398d65a6f398*",".{0,1000}f2c7d2d0539d1549c8f1a9a461b467d6ef0d4eb40c3ab8ba5412398d65a6f398.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","43845"
"*f2ca48973b72ab97f4cb482062d2ab8778078107767a36062e11243a3265e756*",".{0,1000}f2ca48973b72ab97f4cb482062d2ab8778078107767a36062e11243a3265e756.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","43847"
"*f2ee8facc06d5525d4bb73e079e8b599a0a2893351193013ba45ca311dbac50e*",".{0,1000}f2ee8facc06d5525d4bb73e079e8b599a0a2893351193013ba45ca311dbac50e.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","0","#filehash","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","43854"
"*f34b6048a755da93e66d8335d69d98eecc76dcb4ea0e7b816dc9af12ba8b6b22*",".{0,1000}f34b6048a755da93e66d8335d69d98eecc76dcb4ea0e7b816dc9af12ba8b6b22.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","43881"
"*f372c2d7604f63043b3ffe8d382b6ac45a719bd125a7e7f13691eb223a8db509*",".{0,1000}f372c2d7604f63043b3ffe8d382b6ac45a719bd125a7e7f13691eb223a8db509.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","43890"
"*f379a925c80b2f5959d3b3a0658895f7dad370b7478736a2957bc1ae2b59f14c*",".{0,1000}f379a925c80b2f5959d3b3a0658895f7dad370b7478736a2957bc1ae2b59f14c.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","#filehash","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","43891"
"*f392e058d65cc84f23773a88424d5a9e6a6987f790c52e0fb032e8538b5aec36*",".{0,1000}f392e058d65cc84f23773a88424d5a9e6a6987f790c52e0fb032e8538b5aec36.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","0","#filehash","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","43897"
"*f3bdfbd2b36064266a9d9e4452aba93cb97980c37dbe472e0b3b72e1485500ab*",".{0,1000}f3bdfbd2b36064266a9d9e4452aba93cb97980c37dbe472e0b3b72e1485500ab.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","43911"
"*f44118e8d6e227dea16f78d905178cf64ef019a5145aebc06d04d41ea5fc6482*",".{0,1000}f44118e8d6e227dea16f78d905178cf64ef019a5145aebc06d04d41ea5fc6482.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","43952"
"*f4d042d26b74e99f7442cbd0b9e3587f512fc6367f5759d6451d28856526db15*",".{0,1000}f4d042d26b74e99f7442cbd0b9e3587f512fc6367f5759d6451d28856526db15.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","#filehash","N/A","10","","N/A","","","","43989"
"*f4f736012e96fda525525508fdfb99ddd93d1e114b1a3b616234f6c47ffb84c9*",".{0,1000}f4f736012e96fda525525508fdfb99ddd93d1e114b1a3b616234f6c47ffb84c9.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","43999"
"*f55b17e5f63a4f87b16061fc2d44c366bd5868c30104ef273e783c087d2ef3cb*",".{0,1000}f55b17e5f63a4f87b16061fc2d44c366bd5868c30104ef273e783c087d2ef3cb.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#filehash","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","44025"
"*f56f11c598a47a0313a3f4e0929a45a6ed7529119189d7434fbe39721e190083*",".{0,1000}f56f11c598a47a0313a3f4e0929a45a6ed7529119189d7434fbe39721e190083.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#filehash","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","44029"
"*f61ebc6c8692c620a57b7b167206e74131df5e4d651ae55713392bde4b0e8b9f*",".{0,1000}f61ebc6c8692c620a57b7b167206e74131df5e4d651ae55713392bde4b0e8b9f.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#filehash","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","44086"
"*f6e16eee3494ad168fa124552fba957ba8ddf8e7d96eedeef33f9e2afe1e9257*",".{0,1000}f6e16eee3494ad168fa124552fba957ba8ddf8e7d96eedeef33f9e2afe1e9257.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","#filehash","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","44135"
"*f6efa1ba7a66dddb2a14a652d4f96f365c73e3b15f5f40822eefbff9fc46a57c*",".{0,1000}f6efa1ba7a66dddb2a14a652d4f96f365c73e3b15f5f40822eefbff9fc46a57c.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#filehash","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","44141"
"*f6f082606e6725734c4ad3fef4e9d1ae5669ebab5c9085e6ab3b409793ca2000*",".{0,1000}f6f082606e6725734c4ad3fef4e9d1ae5669ebab5c9085e6ab3b409793ca2000.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","#filehash","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","44142"
"*f7dc6083af1eac05ea39386513b98d2942134e6e2c7e236e070c71d6469650a7*",".{0,1000}f7dc6083af1eac05ea39386513b98d2942134e6e2c7e236e070c71d6469650a7.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","44188"
"*f80eda59c7a3c13a369756294727a931e983916bdbd1b9b0b4e010b84d6ce450*",".{0,1000}f80eda59c7a3c13a369756294727a931e983916bdbd1b9b0b4e010b84d6ce450.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","44204"
"*f8184ce6c3b95b88dda27b246cff8039986843082f8689081c97d59161bc878d*",".{0,1000}f8184ce6c3b95b88dda27b246cff8039986843082f8689081c97d59161bc878d.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","#filehash","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","44208"
"*f8240f1a0ce4d4a1ec3e880c7bc56fee6c3c790d48ec20bc35ac5ffad8861798*",".{0,1000}f8240f1a0ce4d4a1ec3e880c7bc56fee6c3c790d48ec20bc35ac5ffad8861798.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","44213"
"*F835A9E7-2542-45C2-9D85-EC0C9FDFFB16*",".{0,1000}F835A9E7\-2542\-45C2\-9D85\-EC0C9FDFFB16.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","#GUIDproject","N/A","10","","N/A","","","","44219"
"*f93277bd46aec52cc14875cb9439a8ab5f226cf4f857196e2b423391dd67ec93*",".{0,1000}f93277bd46aec52cc14875cb9439a8ab5f226cf4f857196e2b423391dd67ec93.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","#filehash","N/A","10","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","44287"
"*f96865aaead8186eba43688e85b6632375f4f058dd1f867152fbc7b6d64344dd*",".{0,1000}f96865aaead8186eba43688e85b6632375f4f058dd1f867152fbc7b6d64344dd.{0,1000}","offensive_tool_keyword","o365-attack-toolkit","A toolkit to attack Office365","T1110 - T1114 - T1119 - T1197 - T1087.002","TA0001 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/o365-attack-toolkit","1","0","#filehash","N/A","10","10","1068","217","2020-11-06T12:09:26Z","2019-07-22T10:39:46Z","44301"
"*f97334c71892acdc50380141f0c6144363b7a55a1fe5adf01543b2adbd2d7e44*",".{0,1000}f97334c71892acdc50380141f0c6144363b7a55a1fe5adf01543b2adbd2d7e44.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","0","#filehash","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","44302"
"*f988bd7635bc12561e00eeb4aff027bd8014dc9b13600c8e8fb597ac9de5c3cf*",".{0,1000}f988bd7635bc12561e00eeb4aff027bd8014dc9b13600c8e8fb597ac9de5c3cf.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","0","#filehash","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","44307"
"*f9ac9d3510fb8c2a50b03605454263af27cf68ef4f27458c03b12607a0f8ebd3*",".{0,1000}f9ac9d3510fb8c2a50b03605454263af27cf68ef4f27458c03b12607a0f8ebd3.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","44314"
"*fa06c45e4522706565bea7e2532ba67cf2cad3e57e38157c09e46445c1dd100a*",".{0,1000}fa06c45e4522706565bea7e2532ba67cf2cad3e57e38157c09e46445c1dd100a.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","#filehash","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","44341"
"*fa220acf9aa2972ac3ed01e854cfa219e017a533c0e629740b03151cf962dd91*",".{0,1000}fa220acf9aa2972ac3ed01e854cfa219e017a533c0e629740b03151cf962dd91.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","44353"
"*fa8ff7e30ab51f8331ad6d9792d470406de52d66681c2b788361eb578558f913*",".{0,1000}fa8ff7e30ab51f8331ad6d9792d470406de52d66681c2b788361eb578558f913.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","44375"
"*faa491fa7733cf0c51ffdcf97be3fd48231863ff59b4f6922e11bbb747bf1806*",".{0,1000}faa491fa7733cf0c51ffdcf97be3fd48231863ff59b4f6922e11bbb747bf1806.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#filehash","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","44381"
"*faca9e856c369b63d6698c74b1d59b062a9a8d9fe84b8f753c299c9961026395*",".{0,1000}faca9e856c369b63d6698c74b1d59b062a9a8d9fe84b8f753c299c9961026395.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","0","#filehash","N/A","10","10","N/A","N/A","N/A","N/A","44388"
"*fadfbd1210e864f660aabfc5cb6ae807721ae2d54df0e328d13bc62bcec66e6f*",".{0,1000}fadfbd1210e864f660aabfc5cb6ae807721ae2d54df0e328d13bc62bcec66e6f.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","44397"
"*fadfbd1210e864f660aabfc5cb6ae807721ae2d54df0e328d13bc62bcec66e6f*",".{0,1000}fadfbd1210e864f660aabfc5cb6ae807721ae2d54df0e328d13bc62bcec66e6f.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","44398"
"*faf7eccc7aa509a6ac4b65b15e5bd91101a21ec9dd519b9917e7f0ce5f9191e5*",".{0,1000}faf7eccc7aa509a6ac4b65b15e5bd91101a21ec9dd519b9917e7f0ce5f9191e5.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","44405"
"*Failed in m1n1dumpIT:*",".{0,1000}Failed\sin\sm1n1dumpIT\:.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","44410"
"*Failed logins before lockout is: *max_sam_lock*",".{0,1000}Failed\slogins\sbefore\slockout\sis\:\s.{0,1000}max_sam_lock.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","44411"
"*Failed to create a dump of the forked process*",".{0,1000}Failed\sto\screate\sa\sdump\sof\sthe\sforked\sprocess.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","44414"
"*Failed to dump lsass*",".{0,1000}Failed\sto\sdump\slsass.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","44415"
"*fakelogonscreen*.zip*",".{0,1000}fakelogonscreen.{0,1000}\.zip.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","44444"
"*FakeLogonScreen.csproj*",".{0,1000}FakeLogonScreen\.csproj.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","44445"
"*FakeLogonScreen.Properties.Resources*",".{0,1000}FakeLogonScreen\.Properties\.Resources.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","0","#content","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","44446"
"*FakeLogonScreen_trunk.zip*",".{0,1000}FakeLogonScreen_trunk\.zip.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","44447"
"*FakeLogonScreenToFile.exe*",".{0,1000}FakeLogonScreenToFile\.exe.{0,1000}","offensive_tool_keyword","fakelogonscreen","Fake Windows logon screen to steal passwords","T1056.002 - T1078 - T1110 - T1555","TA0006 - TA0003 - TA0009","N/A","N/A","Credential Access","https://github.com/bitsadmin/fakelogonscreen","1","1","N/A","N/A","10","10","1325","236","2020-02-03T23:28:01Z","2020-02-01T18:51:35Z","44448"
"*farmer.exe *\windows\temp*",".{0,1000}farmer\.exe\s.{0,1000}\\windows\\temp.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","0","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","44454"
"*farmer.exe 8888 60*",".{0,1000}farmer\.exe\s8888\s60.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","0","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","44455"
"*Farmer\Farmer.csproj*",".{0,1000}Farmer\\Farmer\.csproj.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","0","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","44456"
"*Farmer-main.zip*",".{0,1000}Farmer\-main\.zip.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","1","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","44457"
"*fasttrack/wordlist.txt*",".{0,1000}fasttrack\/wordlist\.txt.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","44463"
"*fb120f28b0e4d979b147635e9549362bb12e35d4b24a345fc5f208dd089ae4cb*",".{0,1000}fb120f28b0e4d979b147635e9549362bb12e35d4b24a345fc5f208dd089ae4cb.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","44471"
"*fb93ead7778fa1593e651220420a86f63afcf3fdfc673f19c801b5de71ab5ac8*",".{0,1000}fb93ead7778fa1593e651220420a86f63afcf3fdfc673f19c801b5de71ab5ac8.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","44506"
"*FB9B5E61-7C34-4280-A211-E979E1D6977F*",".{0,1000}FB9B5E61\-7C34\-4280\-A211\-E979E1D6977F.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz GUID project","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#GUIDproject","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","44510"
"*f-bader/TokenTacticsV2*",".{0,1000}f\-bader\/TokenTacticsV2.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","1","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","44514"
"*fbe35bdcceb19b3c20e8a212a5a6fa853e9d452321b75da7bbbb7666631c6dc4*",".{0,1000}fbe35bdcceb19b3c20e8a212a5a6fa853e9d452321b75da7bbbb7666631c6dc4.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","#filehash","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","44530"
"*fbee25dd2d6b1faf917f4f6a90113e3c520125f325915b7dd70f304dd2dab4b1*",".{0,1000}fbee25dd2d6b1faf917f4f6a90113e3c520125f325915b7dd70f304dd2dab4b1.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","0","#filehash","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","44533"
"*fc22650b89b63d52f14ec5d17c0ee92b1d897825c6b7eb3db391e18268567d25*",".{0,1000}fc22650b89b63d52f14ec5d17c0ee92b1d897825c6b7eb3db391e18268567d25.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","0","#filehash","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","44545"
"*fc77b7dc19250416baf67ae9f87e85ebad700032b0d437c0bc2176b2585fca95*",".{0,1000}fc77b7dc19250416baf67ae9f87e85ebad700032b0d437c0bc2176b2585fca95.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","44568"
"*fc77b7dc19250416baf67ae9f87e85ebad700032b0d437c0bc2176b2585fca95*",".{0,1000}fc77b7dc19250416baf67ae9f87e85ebad700032b0d437c0bc2176b2585fca95.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","44569"
"*fc97c521e6bd003e20bd27d2de03f954e9f557167a015bcbe3322b60542fca4e*",".{0,1000}fc97c521e6bd003e20bd27d2de03f954e9f557167a015bcbe3322b60542fca4e.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","44582"
"*fcbcac521d37905835cbe924d2bca822513682a9cfa0d48945673e5b72d86709*",".{0,1000}fcbcac521d37905835cbe924d2bca822513682a9cfa0d48945673e5b72d86709.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","0","#filehash","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","44600"
"*FCE81BDA-ACAC-4892-969E-0414E765593B*",".{0,1000}FCE81BDA\-ACAC\-4892\-969E\-0414E765593B.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","0","#GUIDproject","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","44612"
"*fcrackzip *",".{0,1000}fcrackzip\s.{0,1000}","offensive_tool_keyword","fcrackzip","a Free/Fast Zip Password Cracker","T1473 - T1021.002","TA0005 - TA0008","N/A","N/A","Credential Access","https://manpages.ubuntu.com/manpages/trusty/man1/fcrackzip.1.html","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","44619"
"*fcrackzip *",".{0,1000}fcrackzip\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","44620"
"*fd0571eeb3d23326429a47df6b1104383efca78191f36099897ec29e5a4da50e*",".{0,1000}fd0571eeb3d23326429a47df6b1104383efca78191f36099897ec29e5a4da50e.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","#filehash","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","44624"
"*fd8303c18bb8893e7d539cced09d4765805a37bd9ac5c92951ab381c70eec2a7*",".{0,1000}fd8303c18bb8893e7d539cced09d4765805a37bd9ac5c92951ab381c70eec2a7.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","0","#filehash #linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","44660"
"*fdb1df0047a31328f0796bd07caf642efc35651ad78389025eb5afa2748bcd04*",".{0,1000}fdb1df0047a31328f0796bd07caf642efc35651ad78389025eb5afa2748bcd04.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","0","#filehash","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","44677"
"*fde22ab519e821b78566ad716fe961d55cec7a447be32e5405f46d10f2e9b233*",".{0,1000}fde22ab519e821b78566ad716fe961d55cec7a447be32e5405f46d10f2e9b233.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","44696"
"*FDF5A0F3-73DA-4A8B-804F-EDD499A176EF*",".{0,1000}FDF5A0F3\-73DA\-4A8B\-804F\-EDD499A176EF.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#GUIDproject","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","44702"
"*fe06cf10cad44865c87cb7a2eef5d3b7614309ce016389add8260f19f16d770b*",".{0,1000}fe06cf10cad44865c87cb7a2eef5d3b7614309ce016389add8260f19f16d770b.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","44707"
"*fe1e030312bcb26de66eea442200e4d73ff88307784fe6f1f72f776efcd5e9be*",".{0,1000}fe1e030312bcb26de66eea442200e4d73ff88307784fe6f1f72f776efcd5e9be.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","44714"
"*fe1e030312bcb26de66eea442200e4d73ff88307784fe6f1f72f776efcd5e9be*",".{0,1000}fe1e030312bcb26de66eea442200e4d73ff88307784fe6f1f72f776efcd5e9be.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#filehash","Dispossessor samples","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","44715"
"*fe2952ae150d2a92e6ef03f68022dc10a792fb8c3e44a46cf2ce1e095e45b9d4*",".{0,1000}fe2952ae150d2a92e6ef03f68022dc10a792fb8c3e44a46cf2ce1e095e45b9d4.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","#filehash","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","44719"
"*fe5fc5bfd15a4c3dbf5d057bcf109d4f4d1b8835085acca6c13508e7baf074a3*",".{0,1000}fe5fc5bfd15a4c3dbf5d057bcf109d4f4d1b8835085acca6c13508e7baf074a3.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","44731"
"*fe5fc5bfd15a4c3dbf5d057bcf109d4f4d1b8835085acca6c13508e7baf074a3*",".{0,1000}fe5fc5bfd15a4c3dbf5d057bcf109d4f4d1b8835085acca6c13508e7baf074a3.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archives hashes","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#filehash","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","44732"
"*fed9b7e5d2f1b284d5f757fcf95f97d8deb08b794d2764b0318cde7f95cc0496*",".{0,1000}fed9b7e5d2f1b284d5f757fcf95f97d8deb08b794d2764b0318cde7f95cc0496.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","0","#filehash","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","44767"
"*Fertiliser.exe \\*",".{0,1000}Fertiliser\.exe\s\\\\.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","0","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","44787"
"*Fetching domain information through a Kerberos auth over LDAP*",".{0,1000}Fetching\sdomain\sinformation\sthrough\sa\sKerberos\sauth\sover\sLDAP.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","44789"
"*Fetching domain information through NTLM over LDAP*",".{0,1000}Fetching\sdomain\sinformation\sthrough\sNTLM\sover\sLDAP.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","44790"
"*ff7db32d94ef4b9e11ced9226a8e4a62eb0ec932e66b4655b845dd7f717bf94a*",".{0,1000}ff7db32d94ef4b9e11ced9226a8e4a62eb0ec932e66b4655b845dd7f717bf94a.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#filehash","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","44820"
"*ffnbelfdoeiohenkjibnmadjiehjhajb*",".{0,1000}ffnbelfdoeiohenkjibnmadjiehjhajb.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","44863"
"*fgdump.exe*",".{0,1000}fgdump\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","44878"
"*fgexec -c *",".{0,1000}fgexec\s\-c\s.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","N/A","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","44879"
"*fgexec.exe*",".{0,1000}fgexec\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","44880"
"*fhbohimaelbohpjbbldcngcnapndodjp*",".{0,1000}fhbohimaelbohpjbbldcngcnapndodjp.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","44881"
"*fhilaheimglignddkjgofkcbgekhenbh*",".{0,1000}fhilaheimglignddkjgofkcbgekhenbh.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","44882"
"*FileMonitor has injected FileMonitorHook into process *",".{0,1000}FileMonitor\shas\sinjected\sFileMonitorHook\sinto\sprocess\s.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","0","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","44912"
"*filezilla2john.py*",".{0,1000}filezilla2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","44926"
"*fin3ss3g0d/secretsdump*",".{0,1000}fin3ss3g0d\/secretsdump.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fin3ss3g0d/secretsdump.py","1","0","N/A","N/A","10","3","216","25","2023-07-31T20:08:46Z","2023-07-25T16:29:32Z","44935"
"*find / -name id_dsa 2>*",".{0,1000}find\s\/\s\-name\sid_dsa\s2\>.{0,1000}","greyware_tool_keyword","find","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","44966"
"*find / -name id_rsa 2>*",".{0,1000}find\s\/\s\-name\sid_rsa\s2\>.{0,1000}","greyware_tool_keyword","find","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","44968"
"*find_domain.sh *",".{0,1000}find_domain\.sh\s.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","0","#linux","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","45018"
"*Find-AdminLogonScripts.ps1*",".{0,1000}Find\-AdminLogonScripts\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45025"
"*Find-KeePassconfig *",".{0,1000}Find\-KeePassconfig\s.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","45068"
"*Find-KeePassconfig C:\*",".{0,1000}Find\-KeePassconfig\sC\:\\.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45070"
"*Find-KeePassconfig*",".{0,1000}Find\-KeePassconfig.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","45072"
"*Find-LogonScriptCredentials -LogonScripts*",".{0,1000}Find\-LogonScriptCredentials\s\-LogonScripts.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","0","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45088"
"*Find-LogonScriptCredentials.ps1*",".{0,1000}Find\-LogonScriptCredentials\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45089"
"*findstr *BEGIN CERTIFICATE*",".{0,1000}findstr\s.{0,1000}BEGIN\sCERTIFICATE.{0,1000}","offensive_tool_keyword","findstr","findstr used to find credentials","T1003 - T1057 - T1070 - T1082 - T1552","TA0001 - TA0002 - TA0005 - TA0007 - TA0011","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","6","10","N/A","N/A","N/A","N/A","45109"
"*findstr *confidential*",".{0,1000}findstr\s.{0,1000}confidential.{0,1000}","offensive_tool_keyword","findstr","findstr used to find credentials","T1003 - T1057 - T1070 - T1082 - T1552","TA0001 - TA0002 - TA0005 - TA0007 - TA0011","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","6","10","N/A","N/A","N/A","N/A","45110"
"*findstr *cpassword *\sysvol\*.xml*",".{0,1000}findstr\s.{0,1000}cpassword\s.{0,1000}\\sysvol\\.{0,1000}\.xml.{0,1000}","greyware_tool_keyword","findstr","linux commands abused by attackers - gpp finder","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","N/A","greyware_tools high risks of false positives","6","10","N/A","N/A","N/A","N/A","45111"
"*findstr *net use*",".{0,1000}findstr\s.{0,1000}net\suse.{0,1000}","offensive_tool_keyword","findstr","findstr used to find credentials","T1003 - T1057 - T1070 - T1082 - T1552","TA0001 - TA0002 - TA0005 - TA0007 - TA0011","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","6","10","N/A","N/A","N/A","N/A","45112"
"*findstr *password*",".{0,1000}findstr\s.{0,1000}password.{0,1000}","offensive_tool_keyword","findstr","findstr used to find credentials","T1003 - T1057 - T1070 - T1082 - T1552","TA0001 - TA0002 - TA0005 - TA0007 - TA0011","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","6","10","N/A","N/A","N/A","N/A","45113"
"*findstr *vnc.ini*",".{0,1000}findstr\s.{0,1000}vnc\.ini.{0,1000}","greyware_tool_keyword","findstr","linux commands abused by attackers","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","N/A","greyware_tools high risks of false positives","6","10","N/A","N/A","N/A","N/A","45114"
"*findstr /S /I cpassword *\policies\*.xml*",".{0,1000}findstr\s\/S\s\/I\scpassword\s.{0,1000}\\policies\\.{0,1000}\.xml.{0,1000}","offensive_tool_keyword","findstr","findstr used to find credentials","T1003 - T1057 - T1070 - T1082 - T1552","TA0001 - TA0002 - TA0005 - TA0007 - TA0011","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","6","10","N/A","N/A","N/A","N/A","45115"
"*findstr /S cpassword $env:*\sysvol\*.xml*",".{0,1000}findstr\s\/S\scpassword\s\$env\:.{0,1000}\\sysvol\\.{0,1000}\.xml.{0,1000}","greyware_tool_keyword","findstr","Find GPP Passwords in SYSVOL - search for occurrences of the term ""cpassword"" in all XML files within the SYSVOL directory of the domain controller - The ""cpassword"" string refers to a weakly encrypted password stored in some Group Policy Preferences (GPP) files","T1003.008 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45116"
"*findstr /S cpassword %*%\sysvol\*.xml*",".{0,1000}findstr\s\/S\scpassword\s\%.{0,1000}\%\\sysvol\\.{0,1000}\.xml.{0,1000}","greyware_tool_keyword","findstr","Find GPP Passwords in SYSVOL - search for occurrences of the term ""cpassword"" in all XML files within the SYSVOL directory of the domain controller - The ""cpassword"" string refers to a weakly encrypted password stored in some Group Policy Preferences (GPP) files","T1003.008 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45117"
"*findstr /si secret *.docx*",".{0,1000}findstr\s\/si\ssecret\s.{0,1000}\.docx.{0,1000}","greyware_tool_keyword","findstr","linux commands abused by attackers","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","N/A","greyware_tools high risks of false positives","6","10","N/A","N/A","N/A","N/A","45118"
"*findstr lsass*",".{0,1000}findstr\slsass.{0,1000}","offensive_tool_keyword","findstr","findstr used to find lsass pid in order to dump lsass process","T1003 - T1057 - T1070 - T1082 - T1552","TA0001 - TA0002 - TA0005 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","N/A","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","45119"
"*Find-UnsafeLogonScriptPermissions.ps1*",".{0,1000}Find\-UnsafeLogonScriptPermissions\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45129"
"*Find-UnsafeUNCPermissions -UNCScripts*",".{0,1000}Find\-UnsafeUNCPermissions\s\-UNCScripts.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","0","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45130"
"*Find-UnsafeUNCPermissions.ps1*",".{0,1000}Find\-UnsafeUNCPermissions\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45131"
"*fir3d0g/mimidogz*",".{0,1000}fir3d0g\/mimidogz.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","45136"
"*firefox_decrypt.py*",".{0,1000}firefox_decrypt\.py.{0,1000}","offensive_tool_keyword","firefox_decrypt","Firefox Decrypt is a tool to extract passwords from Mozilla","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/unode/firefox_decrypt","1","1","N/A","N/A","10","10","2172","317","2024-11-08T13:52:34Z","2014-01-17T13:25:02Z","45141"
"*firefox_decrypt-main*",".{0,1000}firefox_decrypt\-main.{0,1000}","offensive_tool_keyword","firefox_decrypt","Firefox Decrypt is a tool to extract passwords from Mozilla","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/unode/firefox_decrypt","1","1","N/A","N/A","10","10","2172","317","2024-11-08T13:52:34Z","2014-01-17T13:25:02Z","45142"
"*Flangvik/TeamFiltration*",".{0,1000}Flangvik\/TeamFiltration.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","45167"
"*fnjhmkhhmkbjkkabndcnnogagogbneec*",".{0,1000}fnjhmkhhmkbjkkabndcnnogagogbneec.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45184"
"*fnnegphlobjdpkhecapkijjdkgcjhkib*",".{0,1000}fnnegphlobjdpkhecapkijjdkgcjhkib.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45185"
"*for /f """"tokens=2 delims= """" %*tasklist /fi """"Imagename eq lsass.exe*",".{0,1000}for\s\/f\s\""tokens\=2\sdelims\=\s\""\s\%.{0,1000}tasklist\s\/fi\s\""Imagename\seq\slsass\.exe.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","45196"
"*For fun and (no) profit : lets hook rtlcomparememory in lsass.exe*",".{0,1000}For\sfun\sand\s\(no\)\sprofit\s\:\slets\shook\srtlcomparememory\sin\slsass\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","45202"
"*forkatz.exe*",".{0,1000}forkatz\.exe.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","45221"
"*forkatz.sln*",".{0,1000}forkatz\.sln.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","45222"
"*forkatz.vcxproj*",".{0,1000}forkatz\.vcxproj.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","45223"
"*forkatz-main*",".{0,1000}forkatz\-main.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","1","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","45224"
"*Forwards WebAuthn assertion requests to a compromised host running the Shwmae Windows Hello abuse tool*",".{0,1000}Forwards\sWebAuthn\sassertion\srequests\sto\sa\scompromised\shost\srunning\sthe\sShwmae\sWindows\sHello\sabuse\stool.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","45240"
"*Found a sideloaded DLL, assuming injection already performed*",".{0,1000}Found\sa\ssideloaded\sDLL,\sassuming\sinjection\salready\sperformed.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","45241"
"*found-passwords.txt*",".{0,1000}found\-passwords\.txt.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","45242"
"*fox-it/adconnectdump*",".{0,1000}fox\-it\/adconnectdump.{0,1000}","offensive_tool_keyword","adconnectdump","Dump Azure AD Connect credentials for Azure AD and Active Directory","T1003.004 - T1059.001 - T1082","TA0006 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/fox-it/adconnectdump","1","1","N/A","N/A","10","7","668","88","2024-11-10T22:00:16Z","2019-04-09T07:41:42Z","45246"
"*framework.win32.domcachedump*",".{0,1000}framework\.win32\.domcachedump.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","45254"
"*framework.win32.domcachedumplive*",".{0,1000}framework\.win32\.domcachedumplive.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#content","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","45255"
"*framework.win32.lsasecrets*",".{0,1000}framework\.win32\.lsasecrets.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","45256"
"*framework.win32.lsasecretslive*",".{0,1000}framework\.win32\.lsasecretslive.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#content","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","45257"
"*from . import knowsmore*",".{0,1000}from\s\.\simport\sknowsmore.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","45278"
"*from burp import*",".{0,1000}from\sburp\simport.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","0","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","45299"
"*from conpass.ntlminfo import *",".{0,1000}from\sconpass\.ntlminfo\simport\s.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","0","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","45300"
"*from conpass.password import *",".{0,1000}from\sconpass\.password\simport\s.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","0","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","45301"
"*from https://github.com/S3cur3Th1sSh1t/Nim_Dinvoke*",".{0,1000}from\shttps\:\/\/github\.com\/S3cur3Th1sSh1t\/Nim_Dinvoke.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","45316"
"*from https://www.stevencampbell.info/Nim-Convert-Shellcode-to-UUID*",".{0,1000}from\shttps\:\/\/www\.stevencampbell\.info\/Nim\-Convert\-Shellcode\-to\-UUID.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","45317"
"*from knowsmore import knowsmore*",".{0,1000}from\sknowsmore\simport\sknowsmore.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","45319"
"*from o365spray.__main__*",".{0,1000}from\so365spray\.__main__.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","#content","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","45330"
"*from o365spray.core.utils*",".{0,1000}from\so365spray\.core\.utils.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","#content","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","45331"
"*from requests_ntlm import HttpNtlmAuth*",".{0,1000}from\srequests_ntlm\simport\sHttpNtlmAuth.{0,1000}","greyware_tool_keyword","requests-ntlm","HTTP NTLM Authentication for Requests Library","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://pypi.org/project/requests-ntlm/","1","0","N/A","N/A","8","9","N/A","N/A","N/A","N/A","45341"
"*from spraycharles import *",".{0,1000}from\sspraycharles\simport\s.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","45348"
"*fsockopen(*0.0.0.0*4444*exec(*",".{0,1000}fsockopen\(.{0,1000}0\.0\.0\.0.{0,1000}4444.{0,1000}exec\(.{0,1000}","offensive_tool_keyword","OMGLogger","Key logger which sends each and every key stroke of target remotely/locally.","T1056.001 - T1562.001","TA0004 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/OMGLogger","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","45369"
"*fugawi/EASSniper*",".{0,1000}fugawi\/EASSniper.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","1","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","45402"
"*function Decrypt-RDCMan*",".{0,1000}function\sDecrypt\-RDCMan.{0,1000}","offensive_tool_keyword","Decrypt-RDCMan","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1","1","0","N/A","N/A","9","1","1","1","2016-12-01T14:06:24Z","2017-11-22T23:18:39Z","45414"
"*function Find-KeePassconfig*",".{0,1000}function\sFind\-KeePassconfig.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45416"
"*function Local:Inject-RemoteShellcode *",".{0,1000}function\sLocal\:Inject\-RemoteShellcode\s.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","45425"
"*fuzz_option.pl*",".{0,1000}fuzz_option\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","45436"
"*G0ldenGunSec/SharpSecDump*",".{0,1000}G0ldenGunSec\/SharpSecDump.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","45450"
"*G374U70F111(*",".{0,1000}G374U70F111\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45454"
"*G3770K3N(*",".{0,1000}G3770K3N\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45455"
"*G3770K3N1NF0(*",".{0,1000}G3770K3N1NF0\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45456"
"*G37800KM4rK5(*",".{0,1000}G37800KM4rK5\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45457"
"*G3781111N6(*",".{0,1000}G3781111N6\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45458"
"*G3784D63(*",".{0,1000}G3784D63\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45459"
"*G378r0W53r5(br0W53rP47H5)*",".{0,1000}G378r0W53r5\(br0W53rP47H5\).{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45460"
"*G37C00K13(*",".{0,1000}G37C00K13\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45461"
"*G37C0D35(*",".{0,1000}G37C0D35\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45462"
"*G37CC5(*",".{0,1000}G37CC5\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45463"
"*G37D15C0rD(*",".{0,1000}G37D15C0rD\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45464"
"*G37D474(*",".{0,1000}G37D474\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45465"
"*G37H1570rY(*",".{0,1000}G37H1570rY\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45466"
"*G37P455W(*",".{0,1000}G37P455W\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45467"
"*G37UHQ6U11D5(*",".{0,1000}G37UHQ6U11D5\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45468"
"*G37UHQFr13ND5(*",".{0,1000}G37UHQFr13ND5\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45469"
"*G37W3851735(*",".{0,1000}G37W3851735\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45470"
"*G47H3rZ1P5(*",".{0,1000}G47H3rZ1P5\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","45472"
"*gabriellandau/PPLFault*",".{0,1000}gabriellandau\/PPLFault.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","45473"
"*geli2john.py*",".{0,1000}geli2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","45540"
"*gemailhack.py*",".{0,1000}gemailhack\.py.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/Ha3MrX/Gemail-Hack","1","1","N/A","N/A","7","10","1062","400","2024-01-17T15:12:44Z","2018-04-19T13:48:41Z","45542"
"*generate_golden_saml*",".{0,1000}generate_golden_saml.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","45564"
"*Generator IP@Login;Password*",".{0,1000}Generator\sIP\@Login\;Password.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","0","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","45597"
"*genmkvpwd *",".{0,1000}genmkvpwd\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","45605"
"*gentilkiwi*",".{0,1000}gentilkiwi.{0,1000}","offensive_tool_keyword","mimikatz","author of mimikatz and multiple other windows exploitation tools","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45607"
"*Get_DPAPI_Protected_Files*",".{0,1000}Get_DPAPI_Protected_Files.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","45632"
"*get_hijackeable_dllname*",".{0,1000}get_hijackeable_dllname.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","45634"
"*get_masterkeys_from_lsass*",".{0,1000}get_masterkeys_from_lsass.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","45639"
"*Get-AccessTokenWithPRT*",".{0,1000}Get\-AccessTokenWithPRT.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","45827"
"*Get-ADUsernameFromEWS*",".{0,1000}Get\-ADUsernameFromEWS.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","45862"
"*Get-ASREPHash*",".{0,1000}Get\-ASREPHash.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","AS-REP roasting Get the hash for a roastable user using ASREPRoast.ps1","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","45884"
"*Get-AzureTokenFromESTSCookie *",".{0,1000}Get\-AzureTokenFromESTSCookie\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","45897"
"*Get-AzureTokenFromESTSCookie -ESTSAuthCookie *",".{0,1000}Get\-AzureTokenFromESTSCookie\s\-ESTSAuthCookie\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","45898"
"*Get-BaseLineResponseTimeEAS*",".{0,1000}Get\-BaseLineResponseTimeEAS.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","45900"
"*Get-ChildItem -Hidden C:\Users\*\AppData\Local\Microsoft\Credentials\*",".{0,1000}Get\-ChildItem\s\-Hidden\sC\:\\Users\\.{0,1000}\\AppData\\Local\\Microsoft\\Credentials\\.{0,1000}","greyware_tool_keyword","powershell","Find Potential Credential in Files - This directory often contains encrypted credentials or other sensitive files related to user accounts","T1005 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45914"
"*Get-ChildItem -Hidden C:\Users\*\AppData\Roaming\Microsoft\Credentials\*",".{0,1000}Get\-ChildItem\s\-Hidden\sC\:\\Users\\.{0,1000}\\AppData\\Roaming\\Microsoft\\Credentials\\.{0,1000}","greyware_tool_keyword","powershell","Find Potential Credential in Files - This directory often contains encrypted credentials or other sensitive files related to user accounts","T1005 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45915"
"*Get-ChromeDump *",".{0,1000}Get\-ChromeDump\s.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45917"
"*Get-ChromePasswords.ps1*",".{0,1000}Get\-ChromePasswords\.ps1.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","45922"
"*GetChromeSecrets*",".{0,1000}GetChromeSecrets.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","45923"
"*Get-ComputerDetails*",".{0,1000}Get\-ComputerDetails.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","45933"
"*Get-Content ""$env:LOCALAPPDATA\microsoft\remote desktop connection manager\rdcman.settings*",".{0,1000}Get\-Content\s\""\$env\:LOCALAPPDATA\\microsoft\\remote\sdesktop\sconnection\smanager\\rdcman\.settings.{0,1000}","offensive_tool_keyword","Decrypt-RDCMan","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1","1","0","N/A","N/A","9","1","1","1","2016-12-01T14:06:24Z","2017-11-22T23:18:39Z","45936"
"*getCreds1passwordappEntries1.h*",".{0,1000}getCreds1passwordappEntries1\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","45942"
"*getCreds1passwordappEntries2.h*",".{0,1000}getCreds1passwordappEntries2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","45943"
"*getCreds1passwordappMaster.h*",".{0,1000}getCreds1passwordappMaster\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","45944"
"*getCreds1passwordplugin.h*",".{0,1000}getCreds1passwordplugin\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","45945"
"*getCreds1passwordplugin2.h*",".{0,1000}getCreds1passwordplugin2\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","45946"
"*get-delegation *All*",".{0,1000}get\-delegation\s.{0,1000}All.{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","0","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","45959"
"*get-delegation *Unconstrained*",".{0,1000}get\-delegation\s.{0,1000}Unconstrained.{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","0","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","45960"
"*Get-DomainAdmins.ps1*",".{0,1000}Get\-DomainAdmins\.ps1.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","0","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","45966"
"*Get-DomainUserList -Domain * -RemoveDisabled *",".{0,1000}Get\-DomainUserList\s\-Domain\s.{0,1000}\s\-RemoveDisabled\s.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","45998"
"*getent passwd | cut -d: -f1*",".{0,1000}getent\spasswd\s\|\scut\s\-d\:\s\-f1.{0,1000}","greyware_tool_keyword","getent","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","46000"
"*Get-ExchangeAccessToken*",".{0,1000}Get\-ExchangeAccessToken.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","46003"
"*Get-ExoPsAccessToken*",".{0,1000}Get\-ExoPsAccessToken.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","46004"
"*Get-FirefoxPasswords *",".{0,1000}Get\-FirefoxPasswords\s.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46018"
"*Get-FirefoxPasswords.ps1*",".{0,1000}Get\-FirefoxPasswords\.ps1.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46019"
"*Get-ForgedUserAgent *",".{0,1000}Get\-ForgedUserAgent\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","46020"
"*Get-ForgedUserAgent.ps1*",".{0,1000}Get\-ForgedUserAgent\.ps1.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","1","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","46021"
"*Get-GPPAutologons*",".{0,1000}Get\-GPPAutologons.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46034"
"*Get-GPPPasswords*",".{0,1000}Get\-GPPPasswords.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46047"
"*Get-HeadersWithPrtCookies*",".{0,1000}Get\-HeadersWithPrtCookies.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","46053"
"*Get-ItemProperty -Path HKLM:\Software\TightVNC\Server -Name *Password* | select -ExpandProperty Password*",".{0,1000}Get\-ItemProperty\s\-Path\sHKLM\:\\Software\\TightVNC\\Server\s\-Name\s.{0,1000}Password.{0,1000}\s\|\sselect\s\-ExpandProperty\sPassword.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","TightVNC password (convert to Hex then decrypt with e.g.: https://github.com/frizb/PasswordDecrypts)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","#registry","N/A","N/A","N/A","N/A","N/A","N/A","N/A","46065"
"*GetKcpPasswordInfo*",".{0,1000}GetKcpPasswordInfo.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46067"
"*Get-KeePassConfigTrigger *",".{0,1000}Get\-KeePassConfigTrigger\s.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46069"
"*Get-KeePassConfigTrigger*",".{0,1000}Get\-KeePassConfigTrigger.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46070"
"*Get-KeePassDatabaseKey *",".{0,1000}Get\-KeePassDatabaseKey\s.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46071"
"*Get-KeePassDatabaseKey*",".{0,1000}Get\-KeePassDatabaseKey.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46074"
"*Get-KIWI_KERBEROS_LOGON_SESSION*",".{0,1000}Get\-KIWI_KERBEROS_LOGON_SESSION.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","0","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","46088"
"*getlsasrvaddr.exe *",".{0,1000}getlsasrvaddr\.exe\s.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","46109"
"*GetLSASRVaddresses v%s - (c) 2011 Hernan Ochoa*",".{0,1000}GetLSASRVaddresses\sv\%s\s\-\s\(c\)\s2011\sHernan\sOchoa.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","46110"
"*Get-MSSQLAllCredentials*",".{0,1000}Get\-MSSQLAllCredentials.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","0","N/A","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","46120"
"*Get-MSSQLAllCredentials*",".{0,1000}Get\-MSSQLAllCredentials.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","1","N/A","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","46121"
"*Get-MSSQLCredentialPasswords*",".{0,1000}Get\-MSSQLCredentialPasswords.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","1","N/A","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","46122"
"*Get-MSSQLLinkPasswords*",".{0,1000}Get\-MSSQLLinkPasswords.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","1","N/A","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","46124"
"*Get-NetNTLM-Hash *",".{0,1000}Get\-NetNTLM\-Hash\s.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","0","N/A","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","46146"
"*getnthash.py -key *",".{0,1000}getnthash\.py\s\-key\s.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","46161"
"*Get-PEHeader.ps1*",".{0,1000}Get\-PEHeader\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46181"
"*getProcUAC1password.h*",".{0,1000}getProcUAC1password\.h.{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","N/A","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","46190"
"*GetRegistryValue*SOFTWARE\Veeam\Veeam Backup Catalog*",".{0,1000}GetRegistryValue.{0,1000}SOFTWARE\\Veeam\\Veeam\sBackup\sCatalog.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059 - T1070.004","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","#registry","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","46201"
"*Get-RemoteCachedCredential*",".{0,1000}Get\-RemoteCachedCredential.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Get cached credentials (if any)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","46205"
"*Get-RemoteLocalAccountHash*",".{0,1000}Get\-RemoteLocalAccountHash.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Get local account hashes","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","46210"
"*Get-RemoteMachineAccountHash*",".{0,1000}Get\-RemoteMachineAccountHash.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Get machine account hash for silver ticket attack","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","46214"
"*get-spns All*",".{0,1000}get\-spns\sAll.{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","0","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","46243"
"*get-spns ASREP*",".{0,1000}get\-spns\sASREP.{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","0","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","46244"
"*get-spns spns*",".{0,1000}get\-spns\sspns.{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","0","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","46245"
"*getTGT.py -dc-ip*",".{0,1000}getTGT\.py\s\-dc\-ip.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","0","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","46290"
"*gettgtpkinit.py -cert-pfx *",".{0,1000}gettgtpkinit\.py\s\-cert\-pfx\s.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","46292"
"*Get-UserPRTToken*",".{0,1000}Get\-UserPRTToken.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","46309"
"*GetUserSPNs.vbs*",".{0,1000}GetUserSPNs\.vbs.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","46314"
"*GhostPack/KeeThief*",".{0,1000}GhostPack\/KeeThief.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","46394"
"*GhostPack/Rubeus*",".{0,1000}GhostPack\/Rubeus.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","46398"
"*GhostPack/SafetyKatz*",".{0,1000}GhostPack\/SafetyKatz.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","46399"
"*GhostPack/SharpDPAPI*",".{0,1000}GhostPack\/SharpDPAPI.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","46401"
"*GhostPack/SharpDump*",".{0,1000}GhostPack\/SharpDump.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","1","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","46402"
"*gimmecredz*",".{0,1000}gimmecredz.{0,1000}","offensive_tool_keyword","gimmecredz","This tool can help pentesters to quickly dump all credz from known location. such as .bash_history. config files. wordpress credentials. and so on","T1003 - T1081 - T1552","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xmitsurugi/gimmecredz","1","1","N/A","N/A","N/A","2","169","26","2020-01-25T21:56:20Z","2018-09-25T15:46:50Z","46412"
"*gist.github.com/byt3bl33d3r/19a48fff8fdc34cc1dd1f1d2807e1b7f*",".{0,1000}gist\.github\.com\/byt3bl33d3r\/19a48fff8fdc34cc1dd1f1d2807e1b7f.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","1","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","46416"
"*git clone * /tmp/cheetah*",".{0,1000}git\sclone\s.{0,1000}\s\/tmp\/cheetah.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","46417"
"*github.io/weakpass/generator/*",".{0,1000}github\.io\/weakpass\/generator\/.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","46442"
"*gitjdm/dumper2020*",".{0,1000}gitjdm\/dumper2020.{0,1000}","offensive_tool_keyword","dumper2020","Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/gitjdm/dumper2020","1","1","N/A","N/A","10","1","76","5","2020-12-29T03:55:21Z","2020-10-04T17:25:21Z","46444"
"*gitleaks*",".{0,1000}gitleaks.{0,1000}","offensive_tool_keyword","Gitleaks","Gitleaks is a SAST tool for detecting hardcoded secrets like passwords. api keys. and tokens in git repos. Gitleaks aims to be the easy-to-use. all-in-one solution for finding secrets. past or present. in your code.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/zricethezav/gitleaks","1","1","N/A","N/A","N/A","10","19587","1590","2025-04-16T21:10:47Z","2018-01-27T18:19:31Z","46447"
"*GlobalUnProtect.exe*",".{0,1000}GlobalUnProtect\.exe.{0,1000}","offensive_tool_keyword","GlobalUnProtect","Decrypt GlobalProtect configuration and cookie files.","T1552 - T1003 - T1555","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rotarydrone/GlobalUnProtect","1","1","N/A","N/A","9","2","147","19","2024-09-10T20:19:24Z","2024-09-04T15:31:52Z","46471"
"*gMSADumper.py*",".{0,1000}gMSADumper\.py.{0,1000}","offensive_tool_keyword","gMSADumper","Lists who can read any gMSA password blobs and parses them if the current user has access.","T1552.001 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/micahvandeusen/gMSADumper","1","1","N/A","N/A","N/A","3","274","51","2024-02-12T02:15:32Z","2021-04-10T00:15:24Z","46478"
"*GMSAPasswordReader.exe*",".{0,1000}GMSAPasswordReader\.exe.{0,1000}","offensive_tool_keyword","GMSAPasswordReader","Reads the password blob from a GMSA account using LDAP and parses the values into hashes for re-use.","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/rvazarkar/GMSAPasswordReader","1","1","N/A","N/A","7","3","219","34","2023-02-17T14:37:40Z","2020-01-19T19:06:20Z","46480"
"*GMSAPasswordReader-master*",".{0,1000}GMSAPasswordReader\-master.{0,1000}","offensive_tool_keyword","GMSAPasswordReader","Reads the password blob from a GMSA account using LDAP and parses the values into hashes for re-use.","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/rvazarkar/GMSAPasswordReader","1","1","N/A","N/A","7","3","219","34","2023-02-17T14:37:40Z","2020-01-19T19:06:20Z","46483"
"*GMShellcode*",".{0,1000}GMShellcode.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","46484"
"*GMShellcode.*",".{0,1000}GMShellcode\..{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","46485"
"*GMShellcode\*",".{0,1000}GMShellcode\\.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","46486"
"*go build lock.go && go build shock.go && go build barrel.go*",".{0,1000}go\sbuild\slock\.go\s\&\&\sgo\sbuild\sshock\.go\s\&\&\sgo\sbuild\sbarrel\.go.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","46491"
"*go run lock.go -o disk*",".{0,1000}go\srun\slock\.go\s\-o\sdisk.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","46496"
"*go run shock.go -o knwondlls*",".{0,1000}go\srun\sshock\.go\s\-o\sknwondlls.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","46499"
"*go thru each line in passwords.lst*",".{0,1000}go\sthru\seach\sline\sin\spasswords\.lst.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","46500"
"*GoAWSConsoleSpray -*",".{0,1000}GoAWSConsoleSpray\s\-.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","0","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","46505"
"*GoAWSConsoleSpray.exe*",".{0,1000}GoAWSConsoleSpray\.exe.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","1","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","46506"
"*GoAWSConsoleSpray@latest*",".{0,1000}GoAWSConsoleSpray\@latest.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","0","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","46507"
"*GoAWSConsoleSpray-master.zip*",".{0,1000}GoAWSConsoleSpray\-master\.zip.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","1","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","46508"
"*gocrack@password.crackers.local*",".{0,1000}gocrack\@password\.crackers\.local.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","N/A","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","46524"
"*gocrack_v*_darwin_x64_hashcat_v3_6_0.zip*",".{0,1000}gocrack_v.{0,1000}_darwin_x64_hashcat_v3_6_0\.zip.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","1","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","46525"
"*gocrack_v*_linux_x64_hashcat_v3_6_0.zip*",".{0,1000}gocrack_v.{0,1000}_linux_x64_hashcat_v3_6_0\.zip.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","1","#linux","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","46526"
"*GodFault.exe*",".{0,1000}GodFault\.exe.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","46527"
"*GodFault\GodFault*",".{0,1000}GodFault\\GodFault.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","46528"
"*GoldenGMSA.exe*",".{0,1000}GoldenGMSA\.exe.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","1","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","46579"
"*GoldenGMSA-main*",".{0,1000}GoldenGMSA\-main.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","1","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","46580"
"*go-lsass --host *",".{0,1000}go\-lsass\s\-\-host\s.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","0","#linux","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","46583"
"*google-chrome/cookies.txt*",".{0,1000}google\-chrome\/cookies\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","46590"
"*google-chrome/credit_cards.txt*",".{0,1000}google\-chrome\/credit_cards\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","46591"
"*google-chrome/history.txt*",".{0,1000}google\-chrome\/history\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","46592"
"*google-chrome/login_data.txt*",".{0,1000}google\-chrome\/login_data\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","46593"
"*google-chrome\cookies.txt*",".{0,1000}google\-chrome\\cookies\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","46594"
"*google-chrome\credit_cards.txt*",".{0,1000}google\-chrome\\credit_cards\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","46595"
"*google-chrome\history.txt*",".{0,1000}google\-chrome\\history\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","46596"
"*google-chrome\login_data.txt*",".{0,1000}google\-chrome\\login_data\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","46597"
"*go-secdump -*",".{0,1000}go\-secdump\s\-.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","0","N/A","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","46611"
"*go-secdump.exe*",".{0,1000}go\-secdump\.exe.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","1","N/A","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","46612"
"*go-secdump-main*",".{0,1000}go\-secdump\-main.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","1","N/A","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","46613"
"*gosecretsdump v* (@C__Sto*",".{0,1000}gosecretsdump\sv.{0,1000}\s\(\@C__Sto.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","46615"
"*gosecretsdump/cmd*",".{0,1000}gosecretsdump\/cmd.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","46616"
"*gosecretsdump_win*.exe*",".{0,1000}gosecretsdump_win.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","46617"
"*Got encrypted TGT for * but couldn't convert to hash*",".{0,1000}Got\sencrypted\sTGT\sfor\s.{0,1000}\sbut\scouldn\'t\sconvert\sto\shash.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","46633"
"*Got expected RPC_S_SERVER_UNAVAILABLE exception. Attack worked*",".{0,1000}Got\sexpected\sRPC_S_SERVER_UNAVAILABLE\sexception\.\sAttack\sworked.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","46634"
"*gpg2john.*",".{0,1000}gpg2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","46659"
"*gpp_autologin.py*",".{0,1000}gpp_autologin\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","46664"
"*gpp_password.py*",".{0,1000}gpp_password\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","46665"
"*gppassword.py*",".{0,1000}gppassword\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","46667"
"*gpp-decrypt *",".{0,1000}gpp\-decrypt\s.{0,1000}","offensive_tool_keyword","gpp-decrypt","Decrypt the given Group Policy Preferences","T1552.002 - T1212","TA0009 - TA0006","N/A","N/A","Credential Access","https://gitlab.com/kalilinux/packages/gpp-decrypt","1","0","N/A","N/A","6","10","N/A","N/A","N/A","N/A","46668"
"*gpp-decrypt.rb*",".{0,1000}gpp\-decrypt\.rb.{0,1000}","offensive_tool_keyword","gpp-decrypt","Decrypt the given Group Policy Preferences","T1552.002 - T1212","TA0009 - TA0006","N/A","N/A","Credential Access","https://gitlab.com/kalilinux/packages/gpp-decrypt","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","46670"
"*Grab Password From IE Window*",".{0,1000}Grab\sPassword\sFrom\sIE\sWindow.{0,1000}","offensive_tool_keyword","RouterPassView","help you to recover your lost password from your router file","T1002 - T1552 - T1027","TA0006 - TA0007","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/router_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46673"
"*Grabbed by Blank Grabber | *",".{0,1000}Grabbed\sby\sBlank\sGrabber\s\|\s.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","46674"
"*grep *password /var/www*",".{0,1000}grep\s.{0,1000}password\s\/var\/www.{0,1000}","greyware_tool_keyword","grep","search for passwords","T1005 - T1083 - T1213","TA0006","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md","1","0","#linux","N/A","N/A","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","46706"
"*grep :0: /etc/passwd*",".{0,1000}grep\s\:0\:\s\/etc\/passwd.{0,1000}","greyware_tool_keyword","grep","Look for users with a UID of 0","T1005 - T1083 - T1213","TA0006","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md","1","0","#linux","N/A","N/A","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","46708"
"*grep*|pwd=|passwd=|password=*",".{0,1000}grep.{0,1000}\|pwd\=\|passwd\=\|password\=.{0,1000}","greyware_tool_keyword","grep","search for passwords","T1005 - T1083 - T1213","TA0006","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md","1","0","#linux","N/A","N/A","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","46713"
"*grep*password|pwd|pass*",".{0,1000}grep.{0,1000}password\|pwd\|pass.{0,1000}","greyware_tool_keyword","grep","search for passwords","T1213 - T1081","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md","1","0","#linux","N/A","N/A","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","46714"
"*gsecdump-v2b5.exe*",".{0,1000}gsecdump\-v2b5\.exe.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","46727"
"*-H lm-hash:nt-hash*",".{0,1000}\-H\slm\-hash\:nt\-hash.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","46812"
"*-H 'LMHASH:NTHASH'*",".{0,1000}\-H\s\'LMHASH\:NTHASH\'.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","46813"
"*-H 'NTHASH'*",".{0,1000}\-H\s\'NTHASH\'.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","46814"
"*Ha3MrX/Gemail-Hack*",".{0,1000}Ha3MrX\/Gemail\-Hack.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/Ha3MrX/Gemail-Hack","1","1","N/A","N/A","7","10","1062","400","2024-01-17T15:12:44Z","2018-04-19T13:48:41Z","46830"
"*Hacked by Skenda Unikkatil*",".{0,1000}Hacked\sby\sSkenda\sUnikkatil.{0,1000}","offensive_tool_keyword","DUBrute","RDP Bruteforcer","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/ch0sys/DUBrute","1","0","N/A","N/A","10","1","37","28","2018-02-19T13:03:14Z","2017-06-15T08:55:46Z","46838"
"*Hackndo/conpass*",".{0,1000}Hackndo\/conpass.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","1","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","46850"
"*Hackndo/sprayhound*",".{0,1000}Hackndo\/sprayhound.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","1","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","46852"
"*hackndo@gmail.com*",".{0,1000}hackndo\@gmail\.com.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","#email","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","46853"
"*HackTool.DecryptRDCMan*",".{0,1000}HackTool\.DecryptRDCMan.{0,1000}","signature_keyword","Decrypt-RDCMan","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1","1","0","#Avsignature","N/A","9","1","1","1","2016-12-01T14:06:24Z","2017-11-22T23:18:39Z","46862"
"*Hacktool.Gsecdump*",".{0,1000}Hacktool\.Gsecdump.{0,1000}","signature_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46866"
"*Hacktool.Lazagne*",".{0,1000}Hacktool\.Lazagne.{0,1000}","signature_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","#Avsignature","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","46872"
"*HackTool.LsassDumper*",".{0,1000}HackTool\.LsassDumper.{0,1000}","signature_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","#Avsignature","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","46875"
"*HackTool.MSIL.KeeFarce*",".{0,1000}HackTool\.MSIL\.KeeFarce.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","#Avsignature","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","46879"
"*HackTool.MSIL.SharpDump32.SM*",".{0,1000}HackTool\.MSIL\.SharpDump32\.SM.{0,1000}","signature_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#Avsignature","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","46881"
"*HackTool.PasswordStealer*",".{0,1000}HackTool\.PasswordStealer.{0,1000}","signature_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","46885"
"*HackTool.PS1.SessionGopher*",".{0,1000}HackTool\.PS1\.SessionGopher.{0,1000}","signature_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","#Avsignature","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","46891"
"*Hacktool.PTHToolkit*",".{0,1000}Hacktool\.PTHToolkit.{0,1000}","signature_keyword","lslsass","dump active logon session password hashes from the lsass process (old tool for vista and older)","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46892"
"*HackTool.RdpThief*",".{0,1000}HackTool\.RdpThief.{0,1000}","signature_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#Avsignature","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","46893"
"*Hacktool.SharpDump*",".{0,1000}Hacktool\.SharpDump.{0,1000}","signature_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#Avsignature","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","46895"
"*HackTool.Win32.NirsoftPT.SM*",".{0,1000}HackTool\.Win32\.NirsoftPT\.SM.{0,1000}","signature_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46904"
"*HackTool.Win32.PWDump*",".{0,1000}HackTool\.Win32\.PWDump.{0,1000}","signature_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","46906"
"*HackTool.Win32.PWDump*",".{0,1000}HackTool\.Win32\.PWDump.{0,1000}","signature_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","46907"
"*HackTool.Win32.RouterScan*",".{0,1000}HackTool\.Win32\.RouterScan.{0,1000}","signature_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#Avsignature","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","46908"
"*HackTool/Gsecdump*",".{0,1000}HackTool\/Gsecdump.{0,1000}","signature_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46915"
"*HackTool:MSIL/SharpDump*",".{0,1000}HackTool\:MSIL\/SharpDump.{0,1000}","signature_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#Avsignature","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","46927"
"*HackTool:PowerShell/DecryptRDCMan*",".{0,1000}HackTool\:PowerShell\/DecryptRDCMan.{0,1000}","signature_keyword","Decrypt-RDCMan","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1","1","0","#Avsignature","N/A","9","1","1","1","2016-12-01T14:06:24Z","2017-11-22T23:18:39Z","46932"
"*HackTool:Win32/Gsecdump*",".{0,1000}HackTool\:Win32\/Gsecdump.{0,1000}","signature_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46950"
"*HackTool:Win32/KeeFarce*",".{0,1000}HackTool\:Win32\/KeeFarce.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","#Avsignature","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","46952"
"*HackTool:Win32/Netpasss.AB!MTB*",".{0,1000}HackTool\:Win32\/Netpasss\.AB!MTB.{0,1000}","signature_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46954"
"*HackTool:Win32/Passview!MSR*",".{0,1000}HackTool\:Win32\/Passview!MSR.{0,1000}","signature_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46955"
"*HackTool:Win32/Passview!MSR*",".{0,1000}HackTool\:Win32\/Passview!MSR.{0,1000}","signature_keyword","VNCPassView","recover the passwords stored by the VNC tool","T1003 - T1555 - T1081","TA0006 - TA0007","N/A","GoGoogle - 8BASE","Credential Access","https://www.nirsoft.net/utils/vnc_password.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46956"
"*HackTool:Win32/Passview!MTB*",".{0,1000}HackTool\:Win32\/Passview!MTB.{0,1000}","signature_keyword","MailPassView","Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients","T1003 - T1081 - T1110","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46957"
"*HackTool:Win32/PWDump*",".{0,1000}HackTool\:Win32\/PWDump.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46958"
"*HackTool:Win32/PWDump*",".{0,1000}HackTool\:Win32\/PWDump.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","46959"
"*HackTool:Win32/PWDump*",".{0,1000}HackTool\:Win32\/PWDump.{0,1000}","signature_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","46960"
"*HackTool:Win32/RouterScan*",".{0,1000}HackTool\:Win32\/RouterScan.{0,1000}","signature_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","#Avsignature","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","46961"
"*Hagrid29/DumpAADSyncCreds*",".{0,1000}Hagrid29\/DumpAADSyncCreds.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","1","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","46973"
"*handle_nessus_file*",".{0,1000}handle_nessus_file.{0,1000}","offensive_tool_keyword","crackmapexec","function name from nessus.py from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","46990"
"*handlekatz.py*",".{0,1000}handlekatz\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","46991"
"*Happy Hacking*Enjoy Dump!*",".{0,1000}Happy\sHacking.{0,1000}Enjoy\sDump!.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","46999"
"*harvestcrop.exe * *",".{0,1000}harvestcrop\.exe\s.{0,1000}\s.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","0","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","47007"
"*has no pre auth required. Dumping hash to crack offline:*",".{0,1000}has\sno\spre\sauth\srequired\.\sDumping\shash\sto\scrack\soffline\:.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","47008"
"*Hash-Buster*",".{0,1000}Hash\-Buster.{0,1000}","offensive_tool_keyword","Hash-Buster","hash cracking tool ","T1201 - T1110 - T1021","TA0001 - TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/s0md3v/Hash-Buster","1","1","N/A","N/A","N/A","10","1809","401","2024-12-10T13:50:26Z","2017-07-03T17:28:51Z","47012"
"*hashcat*",".{0,1000}hashcat.{0,1000}","offensive_tool_keyword","hashcat","Worlds fastest and most advanced password recovery utility.","T1110.001 - T1003.001 - T1021.001","TA0006 - TA0009 - TA0010","N/A","Black Basta","Credential Access","https://github.com/hashcat/hashcat","1","0","#linux","N/A","10","10","22481","3046","2024-08-16T23:50:35Z","2015-12-04T14:46:51Z","47013"
"*hashcat-*.7z*",".{0,1000}hashcat\-.{0,1000}\.7z.{0,1000}","offensive_tool_keyword","hashcat","Worlds fastest and most advanced password recovery utility.","T1110.001 - T1003.001 - T1021.001","TA0006 - TA0009 - TA0010","N/A","Black Basta","Credential Access","https://github.com/hashcat/hashcat","1","1","#linux","N/A","10","10","22481","3046","2024-08-16T23:50:35Z","2015-12-04T14:46:51Z","47014"
"*hashcat.git*",".{0,1000}hashcat\.git.{0,1000}","offensive_tool_keyword","hashcat","Worlds fastest and most advanced password recovery utility.","T1110.001 - T1003.001 - T1021.001","TA0006 - TA0009 - TA0010","N/A","Black Basta","Credential Access","https://github.com/hashcat/hashcat","1","1","#linux","N/A","10","10","22481","3046","2024-08-16T23:50:35Z","2015-12-04T14:46:51Z","47015"
"*hashcat/hashcat*",".{0,1000}hashcat\/hashcat.{0,1000}","offensive_tool_keyword","hashcat","Worlds fastest and most advanced password recovery utility.","T1110.001 - T1003.001 - T1021.001","TA0006 - TA0009 - TA0010","N/A","Black Basta","Credential Access","https://github.com/hashcat/hashcat","1","1","#linux","N/A","10","10","22481","3046","2024-08-16T23:50:35Z","2015-12-04T14:46:51Z","47016"
"*hashcat-rule-master*",".{0,1000}hashcat\-rule\-master.{0,1000}","offensive_tool_keyword","hashcat-rule","Rule for hashcat or john. Aiming to crack how people generate their password","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/clem9669/hashcat-rule","1","1","#linux","N/A","10","5","435","47","2024-09-02T20:14:15Z","2020-03-06T17:20:40Z","47017"
"*hashdump.py*",".{0,1000}hashdump\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","47018"
"*hashedBootKey CheckSum failed, Syskey startup password probably in use! :(*",".{0,1000}hashedBootKey\sCheckSum\sfailed,\sSyskey\sstartup\spassword\sprobably\sin\suse!\s\:\(.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","47024"
"*hashview*@*localhost*",".{0,1000}hashview.{0,1000}\@.{0,1000}localhost.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","47032"
"*hashview/config.conf*",".{0,1000}hashview\/config\.conf.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","47033"
"*hashview/hashview*",".{0,1000}hashview\/hashview.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","47034"
"*hashview-agent.*.tgz*",".{0,1000}hashview\-agent\..{0,1000}\.tgz.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","47035"
"*hashview-agent.py*",".{0,1000}hashview\-agent\.py.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","47036"
"*hccapx2john.py*",".{0,1000}hccapx2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","47067"
"*hekatomb -hashes *",".{0,1000}hekatomb\s\-hashes\s.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","N/A","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","47084"
"*hekatomb-*.tar.gz*",".{0,1000}hekatomb\-.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","1","N/A","N/A","10","","N/A","","","","47085"
"*hekatomb*-hashes *",".{0,1000}hekatomb.{0,1000}\-hashes\s.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","0","N/A","N/A","10","","N/A","","","","47086"
"*hekatomb-*-py3-none-any.whl*",".{0,1000}hekatomb\-.{0,1000}\-py3\-none\-any\.whl.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","1","N/A","N/A","10","","N/A","","","","47087"
"*hekatomb.ad_ldap*",".{0,1000}hekatomb\.ad_ldap.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","N/A","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","47088"
"*hekatomb@thiefin.fr*",".{0,1000}hekatomb\@thiefin\.fr.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","1","#email","N/A","10","","N/A","","","","47089"
"*hello %3e c:\\temp\\test.txt*",".{0,1000}hello\s\%3e\sc\:\\\\temp\\\\test\.txt.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","47092"
"*helviojunior/knowsmore*",".{0,1000}helviojunior\/knowsmore.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","1","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","47115"
"*henry-richard7/Browser-password-stealer*",".{0,1000}henry\-richard7\/Browser\-password\-stealer.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","1","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","47119"
"*Here are some passwords for you, have fun:*",".{0,1000}Here\sare\ssome\spasswords\sfor\syou,\shave\sfun\:.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","0","#content","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","47120"
"*hernan@ampliasecurity.com*",".{0,1000}hernan\@ampliasecurity\.com.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#email","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","47123"
"*HernanRodriguez1/SharpBruteForceSSH*","HernanRodriguez1\/SharpBruteForceSSH","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","1","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","47124"
"*HEUR:HackTool.MSIL.SharpDump.gen*",".{0,1000}HEUR\:HackTool\.MSIL\.SharpDump\.gen.{0,1000}","signature_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#Avsignature","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","47136"
"*HEUR:Trojan-PSW.Win64.NTLM.gen*",".{0,1000}HEUR\:Trojan\-PSW\.Win64\.NTLM\.gen.{0,1000}","signature_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","0","#Avsignature","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","47141"
"*Hibr2Dmp.exe*",".{0,1000}Hibr2Dmp\.exe.{0,1000}","offensive_tool_keyword","Hibr2Dmp","Convert hiberfil.sys to a dump file with hibr2dmp (can be used with windbg to exploit lsass dump)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/mthcht/Purpleteam/blob/main/Simulation/Windows/System/dump_lsass_by_converting_hiberfil_to_dmp.ps1","1","1","N/A","N/A","N/A","2","184","19","2024-12-20T10:22:25Z","2022-12-05T12:40:02Z","47147"
"*HIJACK_DLL_PATH*",".{0,1000}HIJACK_DLL_PATH.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","47174"
"*HKTL_PTHTOOLKIT*",".{0,1000}HKTL_PTHTOOLKIT.{0,1000}","signature_keyword","lslsass","dump active logon session password hashes from the lsass process (old tool for vista and older)","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","47242"
"*HKTL_PWDUMP.*",".{0,1000}HKTL_PWDUMP\..{0,1000}","signature_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","47243"
"*hmaverickadams/autoNTDS*",".{0,1000}hmaverickadams\/autoNTDS.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","1","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","47247"
"*hmeobnfnfcmdkdcmlblgagmfpfboieaf*",".{0,1000}hmeobnfnfcmdkdcmlblgagmfpfboieaf.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","47248"
"*hnfanknocfeofbddgcijnmhnfnkdnaad*",".{0,1000}hnfanknocfeofbddgcijnmhnfnkdnaad.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","47249"
"*hoangprod/AndrewSpecial*",".{0,1000}hoangprod\/AndrewSpecial.{0,1000}","offensive_tool_keyword","AndrewSpecial","AndrewSpecial - dumping lsass memory stealthily","T1003.001 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/hoangprod/AndrewSpecial","1","1","N/A","N/A","10","4","386","98","2019-06-02T02:49:28Z","2019-01-18T19:12:09Z","47251"
"*Hook installed in mstsc.exe, PID *",".{0,1000}Hook\sinstalled\sin\smstsc\.exe,\sPID\s.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","0","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","47264"
"*hook-lsassy.py*",".{0,1000}hook\-lsassy\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","47273"
"*hook-lsassy.py*",".{0,1000}hook\-lsassy\.py.{0,1000}","offensive_tool_keyword","crackmapexec","hook script for lsassy from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","47274"
"*hpglfhgfnhbgpjdenjgmdgoeiappafln*",".{0,1000}hpglfhgfnhbgpjdenjgmdgoeiappafln.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","47299"
"*htdigest2john.py*",".{0,1000}htdigest2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","47311"
"*HTool-GhostPack*",".{0,1000}HTool\-GhostPack.{0,1000}","signature_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#Avsignature","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","47321"
"*HTool-GSECDump*",".{0,1000}HTool\-GSECDump.{0,1000}","signature_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","47322"
"*HTool-Lazagne*",".{0,1000}HTool\-Lazagne.{0,1000}","signature_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","#Avsignature","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","47323"
"*HTool-PassView*",".{0,1000}HTool\-PassView.{0,1000}","signature_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","47324"
"*HTool-SessionGopher*",".{0,1000}HTool\-SessionGopher.{0,1000}","signature_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","#Avsignature","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","47326"
"*http*/john/Test/raw/master/*",".{0,1000}http.{0,1000}\/john\/Test\/raw\/master\/.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","47340"
"*http://*Microsoft.ActiveDirectory.Management.dll*",".{0,1000}http\:\/\/.{0,1000}Microsoft\.ActiveDirectory\.Management\.dll.{0,1000}","offensive_tool_keyword","powershell","redteam technique - import the ActiveDirectory module without the need to install it on the current computer - the dll has been extracted from a Windows 10 x64 with RSAT installed","T1110.001 - T1110.003 - T1110.004","TA0006","N/A","N/A","Credential Access","https://github.com/mthcht/Purpleteam/blob/main/Simulation/Windows/ActiveDirectory/Bruteforce.ps1","1","1","N/A","N/A","N/A","2","184","19","2024-12-20T10:22:25Z","2022-12-05T12:40:02Z","47399"
"*http://0hRIb4t1fWNPYBVA.net/index.php*",".{0,1000}http\:\/\/0hRIb4t1fWNPYBVA\.net\/index\.php.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","47400"
"*http://0x0.st/tm*",".{0,1000}http\:\/\/0x0\.st\/tm.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","47401"
"*http://127.0.0.1/ntdll.dll*",".{0,1000}http\:\/\/127\.0\.0\.1\/ntdll\.dll.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","1","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","47408"
"*http://3wifi.stascorp.com/3wifi.php*",".{0,1000}http\:\/\/3wifi\.stascorp\.com\/3wifi\.php.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","47443"
"*http://hashcrack.com*",".{0,1000}http\:\/\/hashcrack\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47465"
"*http://hashtoolkit.com*",".{0,1000}http\:\/\/hashtoolkit\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47466"
"*http://localhost/shell.jsp?pwd=System.out.println(*",".{0,1000}http\:\/\/localhost\/shell\.jsp\?pwd\=System\.out\.println\(.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","1","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","47470"
"*http://md5.80p.cn*",".{0,1000}http\:\/\/md5\.80p\.cn.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47489"
"*http://md5.gongjuji.net*",".{0,1000}http\:\/\/md5\.gongjuji\.net.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47490"
"*http://md5.gromweb.com*",".{0,1000}http\:\/\/md5\.gromweb\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47491"
"*http://md5.my-addr.com*",".{0,1000}http\:\/\/md5\.my\-addr\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47492"
"*http://md5.tellyou.top*",".{0,1000}http\:\/\/md5\.tellyou\.top.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47493"
"*http://rainbowtables.it64.com*",".{0,1000}http\:\/\/rainbowtables\.it64\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47506"
"*http://ttmd5.com*",".{0,1000}http\:\/\/ttmd5\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47521"
"*http://www.ampliasecurity.com/research/wcefaq.html*",".{0,1000}http\:\/\/www\.ampliasecurity\.com\/research\/wcefaq\.html.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","1","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","47528"
"*http://www.chamd5.org/*",".{0,1000}http\:\/\/www\.chamd5\.org\/.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47529"
"*http://www.dmd5.com*",".{0,1000}http\:\/\/www\.dmd5\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47530"
"*http://www.md5cracker.com*",".{0,1000}http\:\/\/www\.md5cracker\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47536"
"*http://www.nirsoft.net/password_test*",".{0,1000}http\:\/\/www\.nirsoft\.net\/password_test.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47537"
"*http://xmd5.com*",".{0,1000}http\:\/\/xmd5\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47544"
"*httpbrute.py*",".{0,1000}httpbrute\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","47568"
"*https://*Microsoft.ActiveDirectory.Management.dll*",".{0,1000}https\:\/\/.{0,1000}Microsoft\.ActiveDirectory\.Management\.dll.{0,1000}","offensive_tool_keyword","powershell","redteam technique - import the ActiveDirectory module without the need to install it on the current computer - the dll has been extracted from a Windows 10 x64 with RSAT installed","T1110.001 - T1110.003 - T1110.004","TA0006","N/A","N/A","Credential Access","https://github.com/mthcht/Purpleteam/blob/main/Simulation/Windows/ActiveDirectory/Bruteforce.ps1","1","1","N/A","N/A","N/A","2","184","19","2024-12-20T10:22:25Z","2022-12-05T12:40:02Z","47628"
"*https://{server}.gofile.io/uploadFile*",".{0,1000}https\:\/\/\{server\}\.gofile\.io\/uploadFile.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","N/A","10","","N/A","","","","47629"
"*https://0.0.0.0:1337*",".{0,1000}https\:\/\/0\.0\.0\.0\:1337.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","47630"
"*https://badkeys.info/*",".{0,1000}https\:\/\/badkeys\.info\/.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","47682"
"*https://cmd5.la/*",".{0,1000}https\:\/\/cmd5\.la\/.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47713"
"*https://code.google.com/p/creddump/*",".{0,1000}https\:\/\/code\.google\.com\/p\/creddump\/.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","1","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","47716"
"*https://cracker.okx.ch*",".{0,1000}https\:\/\/cracker\.okx\.ch.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47721"
"*https://crackstation.net/*",".{0,1000}https\:\/\/crackstation\.net\/.{0,1000}","offensive_tool_keyword","hack-tools","The all-in-one Red Team browser extension for Web Pentester","T1059.007 - T1505 - T1068 - T1216 - T1547.009","TA0002 - TA0001 - TA0009","N/A","N/A","Credential Access","https://github.com/LasCC/Hack-Tools","1","1","N/A","N/A","9","10","6045","678","2025-01-05T23:10:49Z","2020-06-22T21:42:16Z","47722"
"*https://default-password.info/*",".{0,1000}https\:\/\/default\-password\.info\/.{0,1000}","offensive_tool_keyword","default-password.info","default passwords database","T1110 - T1082","TA0006 - TA0001","N/A","N/A","Credential Access","https://default-password.info/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47729"
"*https://dehash.me*",".{0,1000}https\:\/\/dehash\.me.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47730"
"*https://dirkjanm.io/abusing-azure-ad-sso-with-the-primary-refresh-token/*",".{0,1000}https\:\/\/dirkjanm\.io\/abusing\-azure\-ad\-sso\-with\-the\-primary\-refresh\-token\/.{0,1000}","offensive_tool_keyword","ROADtoken","Abusing Azure AD SSO with the Primary Refresh Token - ROADtoken is a tool that uses the BrowserCore.exe binary to obtain a cookie that can be used with SSO and Azure AD","T1557 - T1078 - T1071.001 - T1552.001","TA0006 ","N/A","N/A","Credential Access","https://github.com/dirkjanm/ROADtoken","1","1","N/A","N/A","7","1","89","17","2020-09-30T16:18:47Z","2020-07-21T12:42:14Z","47732"
"*https://en.hackndo.com/remote-lsass-dump-passwords/*",".{0,1000}https\:\/\/en\.hackndo\.com\/remote\-lsass\-dump\-passwords\/.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","47755"
"*https://erwan2212.github.io/NTHASH-FPC*",".{0,1000}https\:\/\/erwan2212\.github\.io\/NTHASH\-FPC.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","47756"
"*https://hashcracking.ru*",".{0,1000}https\:\/\/hashcracking\.ru.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47792"
"*https://hashes.com*",".{0,1000}https\:\/\/hashes\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47793"
"*https://hashtoolkit.com/generate-hash/?text=*",".{0,1000}https\:\/\/hashtoolkit\.com\/generate\-hash\/\?text\=.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","47794"
"*https://lea.kz*",".{0,1000}https\:\/\/lea\.kz.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47806"
"*https://md5.navisec.it*",".{0,1000}https\:\/\/md5\.navisec\.it.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47819"
"*https://md5decrypt.net*",".{0,1000}https\:\/\/md5decrypt\.net.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47820"
"*https://ntlm.pw*",".{0,1000}https\:\/\/ntlm\.pw.{0,1000}","offensive_tool_keyword","ntlm.pw","Database of NTLM hashes","T1003 - T1555 - T1558","TA0006","N/A","Black Basta","Credential Access","https://ntlm.pw","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","47853"
"*https://ntlm.pw/*",".{0,1000}https\:\/\/ntlm\.pw\/.{0,1000}","offensive_tool_keyword","NTLMSleuth","verify NTLM hash integrity against the robust database of ntlm.pw.","T1003 - T1555","TA0006","N/A","Black Basta","Credential Access","https://github.com/jmarr73/NTLMSleuth","1","1","N/A","N/A","8","1","8","0","2024-08-28T15:21:10Z","2023-12-12T16:41:35Z","47854"
"*https://passwordrecovery.io*",".{0,1000}https\:\/\/passwordrecovery\.io.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","47858"
"*https://ptb.discord.com/api/webhooks/1226217588959215726/AZaNnD4TIN-9sV-t0rsveiQxcROYaCVziI8BUa6CNPsUxdnW9mdHu7HnuQ55kQPXZ8_5*",".{0,1000}https\:\/\/ptb\.discord\.com\/api\/webhooks\/1226217588959215726\/AZaNnD4TIN\-9sV\-t0rsveiQxcROYaCVziI8BUa6CNPsUxdnW9mdHu7HnuQ55kQPXZ8_5.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","47880"
"*https://reedarvin.thearvins.com/*",".{0,1000}https\:\/\/reedarvin\.thearvins\.com\/.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","47908"
"*https://SSHamble.com/*",".{0,1000}https\:\/\/SSHamble\.com\/.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","47938"
"*https://weakpass.com/*",".{0,1000}https\:\/\/weakpass\.com\/.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","47988"
"*https://www.blackhillsinfosec.com/bypass-anti-virus-run-mimikatz*",".{0,1000}https\:\/\/www\.blackhillsinfosec\.com\/bypass\-anti\-virus\-run\-mimikatz.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","48001"
"*https://www.hashkill.com*",".{0,1000}https\:\/\/www\.hashkill\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","48010"
"*https://www.nirsoft.net/toolsdownload/*.exe*",".{0,1000}https\:\/\/www\.nirsoft\.net\/toolsdownload\/.{0,1000}\.exe.{0,1000}","greyware_tool_keyword","nirsoft tools","some of nirsoft tools can be abused by attackers to retrieve passwords ","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","nirsoft.net","1","1","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","48017"
"*https://www.nirsoft.net/toolsdownload/*.zip*",".{0,1000}https\:\/\/www\.nirsoft\.net\/toolsdownload\/.{0,1000}\.zip.{0,1000}","greyware_tool_keyword","nirsoft tools","some of nirsoft tools can be abused by attackers to retrieve passwords ","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","nirsoft.net","1","1","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","48018"
"*https://www.nirsoft.net/utils/*.exe*",".{0,1000}https\:\/\/www\.nirsoft\.net\/utils\/.{0,1000}\.exe.{0,1000}","greyware_tool_keyword","nirsoft tools","some of nirsoft tools can be abused by attackers to retrieve passwords ","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","nirsoft.net","1","1","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","48019"
"*https://www.nirsoft.net/utils/*.zip*",".{0,1000}https\:\/\/www\.nirsoft\.net\/utils\/.{0,1000}\.zip.{0,1000}","greyware_tool_keyword","nirsoft tools","some of nirsoft tools can be abused by attackers to retrieve passwords ","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","nirsoft.net","1","1","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","48020"
"*https://www.somd5.com*",".{0,1000}https\:\/\/www\.somd5\.com.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","48029"
"*HunnicCyber/SharpDomainSpray*",".{0,1000}HunnicCyber\/SharpDomainSpray.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","1","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","48060"
"*hydra * ftp://*",".{0,1000}hydra\s.{0,1000}\sftp\:\/\/.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48073"
"*hydra * http-post-form *",".{0,1000}hydra\s.{0,1000}\shttp\-post\-form\s.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48074"
"*hydra * mysql://*",".{0,1000}hydra\s.{0,1000}\smysql\:\/\/.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48075"
"*hydra * ssh://*",".{0,1000}hydra\s.{0,1000}\sssh\:\/\/.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48076"
"*hydra * telnet://*",".{0,1000}hydra\s.{0,1000}\stelnet\:\/\/.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48077"
"*hydra smtp-enum*",".{0,1000}hydra\ssmtp\-enum.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48078"
"*hydra:x:10001:*",".{0,1000}hydra\:x\:10001\:.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48079"
"*HYDRA_PROXY_HTTP*",".{0,1000}HYDRA_PROXY_HTTP.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48080"
"*hydra-cobaltstrike*",".{0,1000}hydra\-cobaltstrike.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48081"
"*IAAgACAAIAB1AHMAaQBuAGcAIABTAHkAcwB0AGUAbQA7AA0ACgAgACAAIAAgAHUAcwBpAG4AZwAgAFMAeQBzAHQAZQBtAC4AUgB1AG4AdABpAG0AZQAuAEkAbgB0AGUAcgBvAHAAUwBlAHIAdgBpAGMAZQBzADsADQAKACAAIAAgACAAcAB1AGIAbABpAGMAIABjAGwAYQBzAHMAIABMAFMAQQBTAFMARAB1AG0AcAA*",".{0,1000}IAAgACAAIAB1AHMAaQBuAGcAIABTAHkAcwB0AGUAbQA7AA0ACgAgACAAIAAgAHUAcwBpAG4AZwAgAFMAeQBzAHQAZQBtAC4AUgB1AG4AdABpAG0AZQAuAEkAbgB0AGUAcgBvAHAAUwBlAHIAdgBpAGMAZQBzADsADQAKACAAIAAgACAAcAB1AGIAbABpAGMAIABjAGwAYQBzAHMAIABMAFMAQQBTAFMARAB1AG0AcAA.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","48104"
"*iAmAnIndependentStrongPassswordThatNeedsToBeSecure*",".{0,1000}iAmAnIndependentStrongPassswordThatNeedsToBeSecure.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","0","N/A","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","48107"
"*ibmiscanner2john.py*",".{0,1000}ibmiscanner2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","48114"
"*ibnejdfjmmkpcnlpebklmnkoeoihofec*",".{0,1000}ibnejdfjmmkpcnlpebklmnkoeoihofec.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","48115"
"*icebreaker:P@ssword123456*",".{0,1000}icebreaker\:P\@ssword123456.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","48159"
"*icebreaker-master.zip*",".{0,1000}icebreaker\-master\.zip.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","48160"
"*icebreaker-scan.xml*",".{0,1000}icebreaker\-scan\.xml.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","48161"
"*IcebreakerSecurity/DelegationBOF*",".{0,1000}IcebreakerSecurity\/DelegationBOF.{0,1000}","offensive_tool_keyword","DelegationBOF","This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.","T1098 - T1214 - T1552","TA0006","N/A","N/A","Credential Access","https://github.com/IcebreakerSecurity/DelegationBOF","1","1","N/A","N/A","N/A","10","141","23","2022-05-04T14:00:36Z","2022-03-28T20:14:24Z","48163"
"*icyguider/DumpNParse*",".{0,1000}icyguider\/DumpNParse.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","1","N/A","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","48181"
"*iepv.exe /stext *",".{0,1000}iepv\.exe\s\/stext\s.{0,1000}","offensive_tool_keyword","IEPassView","IE PassView scans all Internet Explorer passwords in your system and display them on the main window.","T1555 - T1212","TA0006","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/internet_explorer_password.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","48205"
"*ihamburglar/fgdump*",".{0,1000}ihamburglar\/fgdump.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","1","N/A","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","48226"
"*ijacbjjjpmhencpkoghphdgbooifplmn*",".{0,1000}ijacbjjjpmhencpkoghphdgbooifplmn.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","#browser_extensionid","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","48230"
"*ikescan2john.py*",".{0,1000}ikescan2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","48234"
"*impacket.dcerpc.v5*",".{0,1000}impacket\.dcerpc\.v5.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","48261"
"*impacket.examples.secretsdump*",".{0,1000}impacket\.examples\.secretsdump.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","48262"
"*impacket.smbconnection*",".{0,1000}impacket\.smbconnection.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","0","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","48275"
"*impacketfile.py*",".{0,1000}impacketfile\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","48288"
"*Impersonation #1 done.*",".{0,1000}Impersonation\s\#1\sdone\..{0,1000}","offensive_tool_keyword","StealDhcpSecrets","DHCP Server DNS Password Stealer","T1552 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/tree/master/PasswordStealing/DHCP","1","0","N/A","content","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","48338"
"*Impersonation #1 failed. Exiting*",".{0,1000}Impersonation\s\#1\sfailed\.\sExiting.{0,1000}","offensive_tool_keyword","StealDhcpSecrets","DHCP Server DNS Password Stealer","T1552 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/tree/master/PasswordStealing/DHCP","1","0","N/A","content","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","48339"
"*Impersonation #2 done.*",".{0,1000}Impersonation\s\#2\sdone\..{0,1000}","offensive_tool_keyword","StealDhcpSecrets","DHCP Server DNS Password Stealer","T1552 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/tree/master/PasswordStealing/DHCP","1","0","N/A","content","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","48340"
"*Impersonation #2 failed. Exiting*",".{0,1000}Impersonation\s\#2\sfailed\.\sExiting.{0,1000}","offensive_tool_keyword","StealDhcpSecrets","DHCP Server DNS Password Stealer","T1552 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/tree/master/PasswordStealing/DHCP","1","0","N/A","content","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","48341"
"*import apypykatz*",".{0,1000}import\sapypykatz.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","48359"
"*import BaseSprayModule*",".{0,1000}import\sBaseSprayModule.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","48361"
"*import BlankOBF*",".{0,1000}import\sBlankOBF.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","48362"
"*import DCSYNC*",".{0,1000}import\sDCSYNC.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","0","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","48368"
"*import DPLootSMBConnection*",".{0,1000}import\sDPLootSMBConnection.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","48371"
"*import IBurpExtender*",".{0,1000}import\sIBurpExtender.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","0","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","48376"
"*import pypykatz*",".{0,1000}import\spypykatz.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","48390"
"*import udmp_parser*",".{0,1000}import\sudmp_parser.{0,1000}","offensive_tool_keyword","udmp-parser","A Cross-Platform C++ parser library for Windows user minidumps.","T1005 - T1059.003 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/0vercl0k/udmp-parser","1","0","N/A","N/A","6","3","202","23","2024-11-20T15:58:21Z","2022-01-30T18:56:21Z","48405"
"*Importedx765ant Fileedx765s/Proedx765file*",".{0,1000}Importedx765ant\sFileedx765s\/Proedx765file.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","48419"
"*Import-Module *Microsoft.ActiveDirectory.Management.dll*",".{0,1000}Import\-Module\s.{0,1000}Microsoft\.ActiveDirectory\.Management\.dll.{0,1000}","offensive_tool_keyword","powershell","redteam technique - import the ActiveDirectory module without the need to install it on the current computer - the dll has been extracted from a Windows 10 x64 with RSAT installed","T1110.001 - T1110.003 - T1110.004","TA0006","N/A","N/A","Credential Access","https://github.com/mthcht/Purpleteam/blob/main/Simulation/Windows/ActiveDirectory/Bruteforce.ps1","1","0","N/A","N/A","N/A","2","184","19","2024-12-20T10:22:25Z","2022-12-05T12:40:02Z","48422"
"*include ""MSFRottenPotato.h""*",".{0,1000}include\s\""MSFRottenPotato\.h\"".{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","0","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","48442"
"*incognito* list_tokens -u*",".{0,1000}incognito.{0,1000}\slist_tokens\s\-u.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Token Manipulation Tokens can be impersonated from other users with a session/running processes on the machine. Most C2 frameworks have functionality for this built-in (such as the Steal Token functionality in Cobalt Strike)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","48450"
"*incognito.exe*",".{0,1000}incognito\.exe.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Token Manipulation Tokens can be impersonated from other users with a session/running processes on the machine. Most C2 frameworks have functionality for this built-in (such as the Steal Token functionality in Cobalt Strike)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","48451"
"*info@skelsecprojects.com*",".{0,1000}info\@skelsecprojects\.com.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","#email","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","48475"
"*Initialised lsarelayx*",".{0,1000}Initialised\slsarelayx.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","0","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","48487"
"*initialize_fake_thread_state*",".{0,1000}initialize_fake_thread_state.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","48488"
"*initialize_spoofed_callstack*",".{0,1000}initialize_spoofed_callstack.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","48489"
"*Initializing domainDumper()*",".{0,1000}Initializing\sdomainDumper\(\).{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","48491"
"*Injecting backdoor into discord*",".{0,1000}Injecting\sbackdoor\sinto\sdiscord.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","48530"
"*Injecting into mstsc.exe*",".{0,1000}Injecting\sinto\smstsc\.exe.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","0","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","48532"
"*Injecting shellcode into PID: *",".{0,1000}Injecting\sshellcode\sinto\sPID\:\s.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","48535"
"*Injecting shellcode into PowerShell*",".{0,1000}Injecting\sshellcode\sinto\sPowerShell.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","48537"
"*INSERT INTO LDAPHUNTERFINDINGS *",".{0,1000}INSERT\sINTO\sLDAPHUNTERFINDINGS\s.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","0","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","48593"
"*insert_top_100_passwords_1_G*",".{0,1000}insert_top_100_passwords_1_G.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","48594"
"*InsidePro-PasswordsPro.rule*",".{0,1000}InsidePro\-PasswordsPro\.rule.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","48595"
"*install certsync*",".{0,1000}install\scertsync.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","0","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","48603"
"*install dploot*",".{0,1000}install\sdploot.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","48606"
"*install hydra-gtk*",".{0,1000}install\shydra\-gtk.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","48613"
"*install kerbrute*",".{0,1000}install\skerbrute.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","48616"
"*install pypykatz*",".{0,1000}install\spypykatz.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","48623"
"*install samdump2*",".{0,1000}install\ssamdump2.{0,1000}","offensive_tool_keyword","samdump2","Retrieves syskey and extract hashes from Windows 2k/NT/XP/Vista SAM.","T1003.002 - T1564.001","TA0006 - TA0010","N/A","Black Basta","Credential Access","https://salsa.debian.org/pkg-security-team/samdump2","1","0","N/A","N/A","10","6","N/A","N/A","N/A","N/A","48625"
"*install udmp_parser*",".{0,1000}install\sudmp_parser.{0,1000}","offensive_tool_keyword","udmp-parser","A Cross-Platform C++ parser library for Windows user minidumps.","T1005 - T1059.003 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/0vercl0k/udmp-parser","1","0","N/A","N/A","6","3","202","23","2024-11-20T15:58:21Z","2022-01-30T18:56:21Z","48631"
"*int PotatoAPI::findNTLMBytes*",".{0,1000}int\sPotatoAPI\:\:findNTLMBytes.{0,1000}","offensive_tool_keyword","ADCSCoercePotato","coercing machine authentication but specific for ADCS server","T1187","TA0006","N/A","N/A","Credential Access","https://github.com/decoder-it/ADCSCoercePotato","1","0","N/A","N/A","10","3","224","31","2024-05-05T14:42:23Z","2024-02-26T12:08:34Z","48729"
"*Interesting? there are multiple .NET runtimes loaded in KeePass*",".{0,1000}Interesting?\sthere\sare\smultiple\s\.NET\sruntimes\sloaded\sin\sKeePass.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","48738"
"*Internal-Monologue.exe*",".{0,1000}Internal\-Monologue\.exe.{0,1000}","offensive_tool_keyword","Internal-Monologue","Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS","T1003 - T1051 - T1574 - T1110 - T1547","TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/eladshamir/Internal-Monologue","1","1","N/A","N/A","N/A","10","1512","240","2018-10-11T12:13:08Z","2017-12-09T05:59:01Z","48740"
"*InternalMonologueDll*",".{0,1000}InternalMonologueDll.{0,1000}","offensive_tool_keyword","Internal-Monologue","Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS","T1003 - T1051 - T1574 - T1110 - T1547","TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/eladshamir/Internal-Monologue","1","1","N/A","N/A","N/A","10","1512","240","2018-10-11T12:13:08Z","2017-12-09T05:59:01Z","48741"
"*InternalMonologueExe*",".{0,1000}InternalMonologueExe.{0,1000}","offensive_tool_keyword","Internal-Monologue","Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS","T1003 - T1051 - T1574 - T1110 - T1547","TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/eladshamir/Internal-Monologue","1","1","N/A","N/A","N/A","10","1512","240","2018-10-11T12:13:08Z","2017-12-09T05:59:01Z","48742"
"*Invoke-ASREPRoast*",".{0,1000}Invoke\-ASREPRoast.{0,1000}","offensive_tool_keyword","ASREPRoast","Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. ","T1558.003","TA0006","N/A","N/A","Credential Access","https://github.com/HarmJ0y/ASREPRoast","1","1","N/A","N/A","N/A","3","202","58","2018-09-25T03:26:00Z","2017-01-14T21:07:57Z","48840"
"*Invoke-AutoKerberoast*",".{0,1000}Invoke\-AutoKerberoast.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/xan7r/kerberoast","1","1","N/A","N/A","N/A","1","73","18","2017-07-22T22:28:12Z","2016-06-08T22:58:45Z","48843"
"*Invoke-AzureAdPasswordSprayAttack*",".{0,1000}Invoke\-AzureAdPasswordSprayAttack.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","1","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","48848"
"*Invoke-AzurePasswordSpray*",".{0,1000}Invoke\-AzurePasswordSpray.{0,1000}","offensive_tool_keyword","Invoke-AzurePasswordSpray","This cmdlet is used to perform a password spray attack against Azure accounts using legacy Basic Authentication","T1110.003 - T1553.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/tobor88/PowerShell-Red-Team/blob/master/Invoke-AzurePasswordSpray.ps1","1","1","N/A","N/A","N/A","6","520","92","2023-12-08T15:50:39Z","2019-11-20T22:07:50Z","48850"
"*Invoke-BruteAvailableLogons*",".{0,1000}Invoke\-BruteAvailableLogons.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","48874"
"*Invoke-BruteLogonAccount*",".{0,1000}Invoke\-BruteLogonAccount.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","48877"
"*Invoke-BruteLogonList*",".{0,1000}Invoke\-BruteLogonList.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","48878"
"*Invoke-Cats -pwds*",".{0,1000}Invoke\-Cats\s\-pwds.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","48890"
"*Invoke-Cats.ps1*",".{0,1000}Invoke\-Cats\.ps1.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","48891"
"*Invoke-CleverSpray*",".{0,1000}Invoke\-CleverSpray.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","0","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","48903"
"*Invoke-CleverSpray.ps1*",".{0,1000}Invoke\-CleverSpray\.ps1.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","1","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","48904"
"*Invoke-Dogz.ps1*",".{0,1000}Invoke\-Dogz\.ps1.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","48965"
"*Invoke-DomainHarvestOWA*",".{0,1000}Invoke\-DomainHarvestOWA.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","48967"
"*Invoke-DomainPasswordSpray*",".{0,1000}Invoke\-DomainPasswordSpray.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","48968"
"*Invoke-DomainPasswordSpray*",".{0,1000}Invoke\-DomainPasswordSpray.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","1","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","48969"
"*Invoke-DumpOWAMailboxViaMSGraphApi*",".{0,1000}Invoke\-DumpOWAMailboxViaMSGraphApi.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","48984"
"*Invoke-ForgeUserAgent*",".{0,1000}Invoke\-ForgeUserAgent.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","49050"
"*Invoke-Get-FirefoxPasswords*",".{0,1000}Invoke\-Get\-FirefoxPasswords.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","49052"
"*Invoke-GlobalMailSearch*",".{0,1000}Invoke\-GlobalMailSearch.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49055"
"*Invoke-GlobalO365MailSearch*",".{0,1000}Invoke\-GlobalO365MailSearch.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49057"
"*Invoke-GrabTheHash*",".{0,1000}Invoke\-GrabTheHash.{0,1000}","offensive_tool_keyword","Invoke-GrabTheHash","Get the NTLM Hash for the User or Machine Account TGT held in your current session","T1558.004 - T1003.004","TA0006","N/A","N/A","Credential Access","https://github.com/Leo4j/Invoke-GrabTheHash","1","1","N/A","N/A","8","1","6","1","2023-10-26T10:52:51Z","2023-08-22T12:14:53Z","49063"
"*Invoke-InjectGEvent*",".{0,1000}Invoke\-InjectGEvent.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49098"
"*Invoke-InjectGEventAPI*",".{0,1000}Invoke\-InjectGEventAPI.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49099"
"*Invoke-MassCommand.ps1*",".{0,1000}Invoke\-MassCommand\.ps1.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49168"
"*Invoke-MassMimikatz*",".{0,1000}Invoke\-MassMimikatz.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49169"
"*Invoke-MassSearch.ps1*",".{0,1000}Invoke\-MassSearch\.ps1.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49170"
"*Invoke-MassTokens.ps1*",".{0,1000}Invoke\-MassTokens\.ps1.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","1","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49171"
"*Invoke-MimiDoggies*",".{0,1000}Invoke\-MimiDoggies.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","0","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","49183"
"*Invoke-Mimidogz*",".{0,1000}Invoke\-Mimidogz.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","0","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","49184"
"*Invoke-Mimidogz.ps1*",".{0,1000}Invoke\-Mimidogz\.ps1.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","49185"
"*Invoke-mimikittenz*",".{0,1000}Invoke\-mimikittenz.{0,1000}","offensive_tool_keyword","Dispossessor","credential scripts used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","49204"
"*Invoke-MonitorCredSniper*",".{0,1000}Invoke\-MonitorCredSniper.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49210"
"*Invoke-MSSprinkler*",".{0,1000}Invoke\-MSSprinkler.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","1","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","49217"
"*Invoke-OpenInboxFinder*",".{0,1000}Invoke\-OpenInboxFinder.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49248"
"*Invoke-OpenOWAMailboxInBrowser*",".{0,1000}Invoke\-OpenOWAMailboxInBrowser.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","49249"
"*Invoke-PassSpray*",".{0,1000}Invoke\-PassSpray.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","1","N/A","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","49264"
"*Invoke-PasswordSprayEAS*",".{0,1000}Invoke\-PasswordSprayEAS.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","1","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","49266"
"*Invoke-PasswordSprayEAS*",".{0,1000}Invoke\-PasswordSprayEAS.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49267"
"*Invoke-PasswordSprayEWS*",".{0,1000}Invoke\-PasswordSprayEWS.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49268"
"*Invoke-PasswordSprayGmail*",".{0,1000}Invoke\-PasswordSprayGmail.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49269"
"*Invoke-PasswordSprayOWA*",".{0,1000}Invoke\-PasswordSprayOWA.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49270"
"*Invoke-PostDump*",".{0,1000}Invoke\-PostDump.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","49311"
"*Invoke-PowerExtract*",".{0,1000}Invoke\-PowerExtract.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","49317"
"*Invoke-PowerThIEf*",".{0,1000}Invoke\-PowerThIEf.{0,1000}","offensive_tool_keyword","Invoke-PowerThIEf","An IE Post Exploitation Library released at Steelcon in Sheffield 7th July 2018.","T1027 - T1053 - T1114 - T1059 - T1204","TA0002 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/nettitude/Invoke-PowerThIEf","1","0","N/A","N/A","N/A","2","130","29","2025-02-27T23:17:17Z","2018-07-10T09:14:58Z","49346"
"*Invoke-Pre2kSpray*",".{0,1000}Invoke\-Pre2kSpray.{0,1000}","offensive_tool_keyword","Invoke-Pre2kSpray","Enumerate domain machine accounts and perform pre2k password spraying.","T1087.002 - T1110.003","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/eversinc33/Invoke-Pre2kSpray","1","1","N/A","N/A","8","1","69","11","2023-07-14T06:50:22Z","2023-07-05T10:07:38Z","49352"
"*Invoke-Pwds.ps1*",".{0,1000}Invoke\-Pwds\.ps1.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","1","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","49402"
"*Invoke-RDPThief *",".{0,1000}Invoke\-RDPThief\s.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","0","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","49406"
"*Invoke-RDPThief.ps1*",".{0,1000}Invoke\-RDPThief\.ps1.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","1","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","49407"
"*Invoke-RefreshToAzureCoreManagementToken *",".{0,1000}Invoke\-RefreshToAzureCoreManagementToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49424"
"*Invoke-RefreshToAzureManagementToken *",".{0,1000}Invoke\-RefreshToAzureManagementToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49425"
"*Invoke-RefreshToDODMSGraphToken *",".{0,1000}Invoke\-RefreshToDODMSGraphToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49426"
"*Invoke-RefreshToGraphToken *",".{0,1000}Invoke\-RefreshToGraphToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49427"
"*Invoke-RefreshToMAMToken *",".{0,1000}Invoke\-RefreshToMAMToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49428"
"*Invoke-RefreshToMSGraphToken *",".{0,1000}Invoke\-RefreshToMSGraphToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49429"
"*Invoke-RefreshToMSGraphToken -domain -ClientId *",".{0,1000}Invoke\-RefreshToMSGraphToken\s\-domain\s\-ClientId\s.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","0","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","49430"
"*Invoke-RefreshToMSManageToken *",".{0,1000}Invoke\-RefreshToMSManageToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49431"
"*Invoke-RefreshToMSTeamsToken *",".{0,1000}Invoke\-RefreshToMSTeamsToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49432"
"*Invoke-RefreshToOfficeAppsToken *",".{0,1000}Invoke\-RefreshToOfficeAppsToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49433"
"*Invoke-RefreshToOfficeManagementToken *",".{0,1000}Invoke\-RefreshToOfficeManagementToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49434"
"*Invoke-RefreshToOneDriveToken *",".{0,1000}Invoke\-RefreshToOneDriveToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49435"
"*Invoke-RefreshToOutlookToken *",".{0,1000}Invoke\-RefreshToOutlookToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49436"
"*Invoke-RefreshToSharePointToken *",".{0,1000}Invoke\-RefreshToSharePointToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49437"
"*Invoke-RefreshToSubstrateToken *",".{0,1000}Invoke\-RefreshToSubstrateToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49439"
"*Invoke-RefreshToToken *",".{0,1000}Invoke\-RefreshToToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49440"
"*Invoke-RefreshToYammerToken *",".{0,1000}Invoke\-RefreshToYammerToken\s.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","0","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","49441"
"*Invoke-RemoteMimikatz*",".{0,1000}Invoke\-RemoteMimikatz.{0,1000}","offensive_tool_keyword","mimikatz","PowerShell Scripts focused on Post-Exploitation Capabilities","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/xorrior/RandomPS-Scripts","1","1","N/A","N/A","10","4","318","86","2017-12-29T17:16:42Z","2015-02-25T04:52:01Z","49446"
"*Invoke-RestMethod -ContentType 'Application/Json' -Uri $discord -Method Post -Body ($Body | ConvertTo-Json)*",".{0,1000}Invoke\-RestMethod\s\-ContentType\s\'Application\/Json\'\s\-Uri\s\$discord\s\-Method\sPost\s\-Body\s\(\$Body\s\|\sConvertTo\-Json\).{0,1000}","offensive_tool_keyword","WLAN-Windows-Passwords","Opens PowerShell hidden - grabs wlan passwords - saves as a cleartext in a variable and exfiltrates info via Discord Webhook.","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/WLAN-Windows-Passwords","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","49449"
"*Invoke-RestMethod -Uri https://content.dropboxapi.com/2/files/upload -Method Post -InFile * -Headers *",".{0,1000}Invoke\-RestMethod\s\-Uri\shttps\:\/\/content\.dropboxapi\.com\/2\/files\/upload\s\-Method\sPost\s\s\-InFile\s.{0,1000}\s\s\-Headers\s.{0,1000}","offensive_tool_keyword","OMG-Credz-Plz","A script used to prompt the target to enter their creds to later be exfiltrated with dropbox.","T1056.002 - T1566.001 - T1567.002","TA0004 - TA0040 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/-OMG-Credz-Plz","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","49450"
"*Invoke-SCOMDecrypt*",".{0,1000}Invoke\-SCOMDecrypt.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","49499"
"*Invoke-ScriptSentry*",".{0,1000}Invoke\-ScriptSentry.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","0","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","49500"
"*Invoke-SecretDecrypt*",".{0,1000}Invoke\-SecretDecrypt.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","1","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","49512"
"*Invoke-SecretStealer*",".{0,1000}Invoke\-SecretStealer.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","1","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","49514"
"*Invoke-SessionGopher*",".{0,1000}Invoke\-SessionGopher.{0,1000}","offensive_tool_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","1","N/A","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","49547"
"*Invoke-Shellcode -ProcessId ",".{0,1000}Invoke\-Shellcode\s\-ProcessId\s","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","49627"
"*Invoke-SpraySinglePassword*",".{0,1000}Invoke\-SpraySinglePassword.{0,1000}","offensive_tool_keyword","Invoke-Pre2kSpray","Enumerate domain machine accounts and perform pre2k password spraying.","T1087.002 - T1110.003","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/eversinc33/Invoke-Pre2kSpray","1","1","N/A","N/A","8","1","69","11","2023-07-14T06:50:22Z","2023-07-05T10:07:38Z","49689"
"*Invoke-TokenManipulation -CreateProcess *cmd.exe*",".{0,1000}Invoke\-TokenManipulation\s\-CreateProcess\s.{0,1000}cmd\.exe.{0,1000}","offensive_tool_keyword","PewPewPew","host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server","T1059.001 - T1102 - T1056 - T1071 - T1086 - T1123","TA0011 - TA0010 - TA0005 - TA0002 - TA0009 - TA0006","N/A","N/A","Credential Access","https://github.com/PowerShellEmpire/PowerTools","1","0","N/A","N/A","10","10","2106","815","2021-12-28T21:00:42Z","2014-03-06T14:49:51Z","49761"
"*Invoke-TokenManipulation*",".{0,1000}Invoke\-TokenManipulation.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Invoke-TokenManipulation script Tokens can be impersonated from other users with a session/running processes on the machine. Most C2 frameworks have functionality for this built-in (such as the Steal Token functionality in Cobalt Strike)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","49762"
"*Invoke-UsernameHarvestEAS*",".{0,1000}Invoke\-UsernameHarvestEAS.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","1","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","49794"
"*Invoke-UsernameHarvestEAS*",".{0,1000}Invoke\-UsernameHarvestEAS.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49795"
"*Invoke-UsernameHarvestGmail*",".{0,1000}Invoke\-UsernameHarvestGmail.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49796"
"*Invoke-UsernameHarvestOWA*",".{0,1000}Invoke\-UsernameHarvestOWA.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","49797"
"*Invoke-VeeamGetCreds*",".{0,1000}Invoke\-VeeamGetCreds.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","49807"
"*Invoke-WCMDump*",".{0,1000}Invoke\-WCMDump.{0,1000}","offensive_tool_keyword","Invoke-WCMDump","PowerShell script to dump Windows credentials from the Credential Manager Invoke-WCMDump enumerates Windows credentials in the Credential Manager and then extracts available information about each one. Passwords are retrieved for Generic type credentials. but can not be retrived by the same method for Domain type credentials. Credentials are only returned for the current user","T1003 - T1003.003 - T1003.001 - T1552","TA0006 - TA0006 - TA0006 - TA0006","N/A","N/A","Credential Access","https://github.com/peewpw/Invoke-WCMDump","1","1","N/A","N/A","10","8","722","134","2017-12-12T00:46:33Z","2017-12-09T21:36:59Z","49818"
"*iomoath/SharpSpray*",".{0,1000}iomoath\/SharpSpray.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","1","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","49895"
"*ios7tojohn.pl*",".{0,1000}ios7tojohn\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","49899"
"*is_proxy_stub_dll_loaded*",".{0,1000}is_proxy_stub_dll_loaded.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","49943"
"*it will extract domain controller private key through RPC uses it to decrypt all credentials*",".{0,1000}it\swill\sextract\sdomain\scontroller\sprivate\skey\sthrough\sRPC\suses\sit\sto\sdecrypt\sall\scredentials.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","N/A","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","49949"
"*itm4n/PPLmedic*",".{0,1000}itm4n\/PPLmedic.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","1","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","49959"
"*itunes_backup2john.pl*",".{0,1000}itunes_backup2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","49968"
"*iwork2john.py*",".{0,1000}iwork2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","49982"
"*jblndlipeogpafnldhgmapagcccfchpi*",".{0,1000}jblndlipeogpafnldhgmapagcccfchpi.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","50038"
"*jfjallid/go-lsass*",".{0,1000}jfjallid\/go\-lsass.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","1","N/A","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","50052"
"*jfjallid/go-secdump*",".{0,1000}jfjallid\/go\-secdump.{0,1000}","offensive_tool_keyword","go-secdump","Tool to remotely dump secrets from the Windows registry","T1003.002 - T1012 - T1059.003","TA0006 - TA0003 - TA0002","N/A","N/A","Credential Access","https://github.com/jfjallid/go-secdump","1","1","N/A","N/A","10","5","457","51","2025-02-21T19:16:11Z","2023-02-23T17:02:50Z","50053"
"*jmarr73/NTLMSleuth*",".{0,1000}jmarr73\/NTLMSleuth.{0,1000}","offensive_tool_keyword","NTLMSleuth","verify NTLM hash integrity against the robust database of ntlm.pw.","T1003 - T1555","TA0006","N/A","Black Basta","Credential Access","https://github.com/jmarr73/NTLMSleuth","1","1","N/A","N/A","8","1","8","0","2024-08-28T15:21:10Z","2023-12-12T16:41:35Z","50064"
"*jmmcatee/cracklord*",".{0,1000}jmmcatee\/cracklord.{0,1000}","offensive_tool_keyword","cracklord","Queue and resource system for cracking passwords","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/jmmcatee/cracklord","1","1","N/A","N/A","10","4","388","70","2022-09-22T09:30:14Z","2013-12-09T23:10:54Z","50065"
"*john * --incremental*",".{0,1000}john\s.{0,1000}\s\-\-incremental.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50082"
"*john * -w=*",".{0,1000}john\s.{0,1000}\s\-w\=.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50083"
"*john * --wordlist=*",".{0,1000}john\s.{0,1000}\s\-\-wordlist\=.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper is a fast password cracker.","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/magnumripper/JohnTheRipper","1","0","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50084"
"*john *-groups*",".{0,1000}john\s.{0,1000}\-groups.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50085"
"*john *htdigest*",".{0,1000}john\s.{0,1000}htdigest.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50086"
"*john *-inc *",".{0,1000}john\s.{0,1000}\-inc\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50087"
"*john *-incremental *",".{0,1000}john\s.{0,1000}\-incremental\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50088"
"*john *-shells*",".{0,1000}john\s.{0,1000}\-shells.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50089"
"*john *-show*",".{0,1000}john\s.{0,1000}\-show.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50090"
"*john *-single*",".{0,1000}john\s.{0,1000}\-single.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50091"
"*john *-users*",".{0,1000}john\s.{0,1000}\-users.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50092"
"*john *-wordlist*",".{0,1000}john\s.{0,1000}\-wordlist.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50093"
"*john *--wordlist*",".{0,1000}john\s.{0,1000}\-\-wordlist.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50094"
"*john hashes*",".{0,1000}john\shashes.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50096"
"*john NTDS.dit*",".{0,1000}john\sNTDS\.dit.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper is a fast password cracker.","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/magnumripper/JohnTheRipper","1","0","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50097"
"*john --show *",".{0,1000}john\s\-\-show\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50098"
"*john --status*",".{0,1000}john\s\-\-status.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50099"
"*John the Ripper*",".{0,1000}John\sthe\sRipper.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50100"
"*john --wordlist*",".{0,1000}john\s\-\-wordlist.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50101"
"*John*the*Ripper*",".{0,1000}John.{0,1000}the.{0,1000}Ripper.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper is a fast password cracker.","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/magnumripper/JohnTheRipper","1","0","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50103"
"*john.bash_completion*",".{0,1000}john\.bash_completion.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50104"
"*john.session.log*",".{0,1000}john\.session\.log.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","#logfile","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50105"
"*john.zsh_completion*",".{0,1000}john\.zsh_completion.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50106"
"*john/password.lst*",".{0,1000}john\/password\.lst.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","50107"
"*john/run/fuzz.dic*",".{0,1000}john\/run\/fuzz\.dic.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50108"
"*john/src/ztex/*",".{0,1000}john\/src\/ztex\/.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50109"
"*john_log_format*",".{0,1000}john_log_format.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50113"
"*john_mpi.c*",".{0,1000}john_mpi\.c.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50114"
"*john_register_all*",".{0,1000}john_register_all.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50115"
"*JohnTheRipper *",".{0,1000}JohnTheRipper\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50117"
"*JohnTheRipper/*",".{0,1000}JohnTheRipper\/.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50118"
"*jojonas/SharpSAMDump*",".{0,1000}jojonas\/SharpSAMDump.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","1","N/A","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","50128"
"*JPG0mez/ADCSync*",".{0,1000}JPG0mez\/ADCSync.{0,1000}","offensive_tool_keyword","adcsync","Use ESC1 to perform a makeshift DCSync and dump hashes","T1003.006 - T1021","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/JPG0mez/ADCSync","1","1","N/A","N/A","9","3","205","22","2023-11-02T21:41:08Z","2023-10-04T01:56:50Z","50140"
"*js-cracker-client/cracker.js*",".{0,1000}js\-cracker\-client\/cracker\.js.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","50150"
"*K1W1F01D3r(*",".{0,1000}K1W1F01D3r\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","50189"
"*K1W1F113(*",".{0,1000}K1W1F113\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","50190"
"*KatzSystemArchitecture*",".{0,1000}KatzSystemArchitecture.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","50232"
"*KcpPassword.cs*",".{0,1000}KcpPassword\.cs.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","50246"
"*kdcdump2john.py*",".{0,1000}kdcdump2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50247"
"*keepass_common_plug.*",".{0,1000}keepass_common_plug\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50263"
"*keepass_discover.py*",".{0,1000}keepass_discover\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","50264"
"*keepass2john *.kdbx*",".{0,1000}keepass2john\s.{0,1000}\.kdbx.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50265"
"*KeePassConfig.ps1*",".{0,1000}KeePassConfig\.ps1.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","50268"
"*KeePassLib.Keys.KcpPassword*",".{0,1000}KeePassLib\.Keys\.KcpPassword.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","50271"
"*keepass-password-dumper*",".{0,1000}keepass\-password\-dumper.{0,1000}","offensive_tool_keyword","keepass-password-dumper","KeePass Master Password Dumper is a simple proof-of-concept tool used to dump the master password from KeePass's memory. Apart from the first password character it is mostly able to recover the password in plaintext. No code execution on the target system is required. just a memory dump","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/vdohney/keepass-password-dumper","1","1","N/A","N/A","N/A","7","639","59","2023-08-17T19:26:55Z","2023-05-01T17:08:55Z","50272"
"*keepass-password-dumper*",".{0,1000}keepass\-password\-dumper.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50273"
"*keepassxcfox.dll*",".{0,1000}keepassxcfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","50274"
"*KeePwn --*",".{0,1000}KeePwn\s\-\-.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50275"
"*KeePwn parse_dump *",".{0,1000}KeePwn\sparse_dump\s.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50276"
"*KeePwn plugin *",".{0,1000}KeePwn\splugin\s.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50277"
"*KeePwn trigger *",".{0,1000}KeePwn\strigger\s.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50280"
"*KeePwn v* - by Julien BEDEL*",".{0,1000}KeePwn\sv.{0,1000}\s\-\sby\sJulien\sBEDEL.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50281"
"*keepwn.__main__:main*",".{0,1000}keepwn\.__main__\:main.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50282"
"*keepwn.core.*",".{0,1000}keepwn\.core\..{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50283"
"*keepwn.core.parse_dump*",".{0,1000}keepwn\.core\.parse_dump.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50284"
"*keepwn.core.plugin*",".{0,1000}keepwn\.core\.plugin.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50285"
"*keepwn.core.search*",".{0,1000}keepwn\.core\.search.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50286"
"*keepwn.core.trigger*",".{0,1000}keepwn\.core\.trigger.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50287"
"*KeePwn.py *",".{0,1000}KeePwn\.py\s.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50288"
"*keepwn.utils.*",".{0,1000}keepwn\.utils\..{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","0","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50289"
"*KeePwn-main.zip*",".{0,1000}KeePwn\-main\.zip.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","50290"
"*KeeTheft/Dinvoke*",".{0,1000}KeeTheft\/Dinvoke.{0,1000}","offensive_tool_keyword","KeeThiefSyscalls","Patch GhostPack/KeeThief for it to use DInvoke and syscalls","T1003.001 - T1558.002","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/Metro-Holografix/KeeThiefSyscalls","1","1","N/A","private github repo","10","","N/A","","","","50291"
"*KeeThief*",".{0,1000}KeeThief.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","50292"
"*KeeThiefSyscalls*",".{0,1000}KeeThiefSyscalls.{0,1000}","offensive_tool_keyword","KeeThiefSyscalls","Patch GhostPack/KeeThief for it to use DInvoke and syscalls","T1003.001 - T1558.002","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/Metro-Holografix/KeeThiefSyscalls","1","1","N/A","private github repo","10","","N/A","","","","50295"
"*kerberoast /*",".{0,1000}kerberoast\s\/.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","50300"
"*Kerberoast.*",".{0,1000}Kerberoast\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","50306"
"*kerberoast.py*",".{0,1000}kerberoast\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","50307"
"*KerberOPSEC.csproj*",".{0,1000}KerberOPSEC\.csproj.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","50317"
"*KerberOPSEC.exe*",".{0,1000}KerberOPSEC\.exe.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","50318"
"*KerberOPSEC-x64.exe*",".{0,1000}KerberOPSEC\-x64\.exe.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","50319"
"*KerberOPSEC-x86.exe*",".{0,1000}KerberOPSEC\-x86\.exe.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","50320"
"*kerberos/decryptor.py*",".{0,1000}kerberos\/decryptor\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","50323"
"*kerberos::golden*",".{0,1000}kerberos\:\:golden.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","50328"
"*kerberos::list*",".{0,1000}kerberos\:\:list.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","50331"
"*kerberos::ptt *.kirbi*",".{0,1000}kerberos\:\:ptt\s.{0,1000}\.kirbi.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","0","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","50334"
"*kerberos::ptt*",".{0,1000}kerberos\:\:ptt.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","50335"
"*kerberos-ldap-password-hunter.sh*",".{0,1000}kerberos\-ldap\-password\-hunter\.sh.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","1","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","50344"
"*kerbrute -*",".{0,1000}kerbrute\s\-.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50351"
"*kerbrute userenum *",".{0,1000}kerbrute\suserenum\s.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","0","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50355"
"*kerbrute*bruteforce*",".{0,1000}kerbrute.{0,1000}bruteforce.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50356"
"*kerbrute.go*",".{0,1000}kerbrute\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50357"
"*kerbrute/cmd*",".{0,1000}kerbrute\/cmd.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50358"
"*kerbrute/util*",".{0,1000}kerbrute\/util.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50359"
"*kerbrute_*.exe*",".{0,1000}kerbrute_.{0,1000}\.exe.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50360"
"*kerbrute_darwin_386*",".{0,1000}kerbrute_darwin_386.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","#linux","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50361"
"*kerbrute_darwin_amd64*",".{0,1000}kerbrute_darwin_amd64.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","#linux","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50362"
"*kerbrute_linux*",".{0,1000}kerbrute_linux.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","#linux","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50364"
"*kerbrute_windows*",".{0,1000}kerbrute_windows.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50368"
"*kerbrute_windows_386.exe*",".{0,1000}kerbrute_windows_386\.exe.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50369"
"*kerbrute_windows_amd64.exe*",".{0,1000}kerbrute_windows_amd64\.exe.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50370"
"*kerbrute-master*",".{0,1000}kerbrute\-master.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50371"
"*KerbruteSession*",".{0,1000}KerbruteSession.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","50372"
"*keychain2john.py*",".{0,1000}keychain2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50390"
"*keyring2john.py*",".{0,1000}keyring2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50430"
"*keystedx765ore*",".{0,1000}keystedx765ore.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","50434"
"*keystore2john.py*",".{0,1000}keystore2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50435"
"*Kill CacheDump service (shouldn't be used)*",".{0,1000}Kill\sCacheDump\sservice\s\(shouldn\'t\sbe\sused\).{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","#content","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","50455"
"*KiRBi ticket for mimikatz*",".{0,1000}KiRBi\sticket\sfor\smimikatz.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","50485"
"*kirbi_to_hashcat.py*",".{0,1000}kirbi_to_hashcat\.py.{0,1000}","offensive_tool_keyword","Timeroast","Timeroasting takes advantage of Windows NTP authentication mechanism allowing unauthenticated attackers to effectively request a password hash of any computer or trust account by sending an NTP request with that account's RID","T1558.003 - T1059.003 - T1078.004","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/SecuraBV/Timeroast","1","1","N/A","N/A","10","3","282","28","2023-07-04T07:12:57Z","2023-01-18T09:04:05Z","50487"
"*kirbi2john.*",".{0,1000}kirbi2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50488"
"*kirbi2john.py*",".{0,1000}kirbi2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50489"
"*kirbi2john.py*",".{0,1000}kirbi2john\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","50490"
"*kirbikator.exe*",".{0,1000}kirbikator\.exe.{0,1000}","offensive_tool_keyword","kekeo","access the LSA (Local Security Authority) and manipulate Kerberos tickets. potentially allowing adversaries to gain unauthorized access to Active Directory resources and CIFS file shares","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gentilkiwi/kekeo","1","1","N/A","N/A","N/A","10","1463","214","2021-12-14T10:56:48Z","2015-01-13T21:24:09Z","50491"
"*Kittens love cookies too! >:3*",".{0,1000}Kittens\slove\scookies\stoo!\s\>\:3.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","0","#content","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","50500"
"*KIWI_CLOUDAP_LOGON_LIST_ENTRY_21H2*",".{0,1000}KIWI_CLOUDAP_LOGON_LIST_ENTRY_21H2.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","50513"
"*KIWI_KERBEROS_BUFFER*",".{0,1000}KIWI_KERBEROS_BUFFER.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","50516"
"*kmahyyg/mremoteng-decrypt*",".{0,1000}kmahyyg\/mremoteng\-decrypt.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","50523"
"*knavesec/CredMaster*",".{0,1000}knavesec\/CredMaster.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","50525"
"*kncchdigobghenbbaddojjnnaogfppfj*",".{0,1000}kncchdigobghenbbaddojjnnaogfppfj.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","50526"
"*known_hosts2john.py*",".{0,1000}known_hosts2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50529"
"*knowsmore --create-db*",".{0,1000}knowsmore\s\-\-create\-db.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","50530"
"*Komedx765eta\\Usedx765er Daedx765ta*",".{0,1000}Komedx765eta\\\\Usedx765er\sDaedx765ta.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","50549"
"*kpcyrd/badtouch*",".{0,1000}badtouch.{0,1000}","offensive_tool_keyword","badtouch","Scriptable network authentication cracker","T1110 - T1210.001 - T1558.003","TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/kpcyrd/badtouch","1","0","N/A","N/A","N/A","5","410","45","2023-12-19T14:50:40Z","2018-03-15T22:27:56Z","50552"
"*kpfopkelmapcoipemfendmdcghnegimn*",".{0,1000}kpfopkelmapcoipemfendmdcghnegimn.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","50553"
"*krb2john.py*",".{0,1000}krb2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50584"
"*krbroast-pcap2hashcat.py*",".{0,1000}krbroast\-pcap2hashcat\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","50623"
"*Kudaes/Dumpy*",".{0,1000}Kudaes\/Dumpy.{0,1000}","offensive_tool_keyword","Dumpy","Reuse open handles to dynamically dump LSASS","T1003.001 - T1055.001 - T1083","TA0006","N/A","N/A","Credential Access","https://github.com/Kudaes/Dumpy","1","1","N/A","N/A","10","3","243","24","2024-04-04T07:42:26Z","2021-10-13T21:54:59Z","50649"
"*kuhl_m_dpapi_chrome.c*",".{0,1000}kuhl_m_dpapi_chrome\.c.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","50651"
"*kuhl_m_lsadump.c*",".{0,1000}kuhl_m_lsadump\.c.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","50652"
"*kuhl_m_sekurlsa_utils.c*",".{0,1000}kuhl_m_sekurlsa_utils\.c.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","50661"
"*kwallet2john.py*",".{0,1000}kwallet2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50664"
"*L""NanoDumpPwd""*",".{0,1000}L\""NanoDumpPwd\"".{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","50669"
"*'l', 's', 'a', 's', 's', '.', 'e', 'x', 'e'*",".{0,1000}\'l\',\s\'s\',\s\'a\',\s\'s\',\s\'s\',\s\'\.\',\s\'e\',\s\'x\',\s\'e\'.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","50670"
"*'l','s','a','s','s','.','e','x','e'*",".{0,1000}\'l\',\'s\',\'a\',\'s\',\'s\',\'\.\',\'e\',\'x\',\'e\'.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","50671"
"*L04DUr118(h00k*",".{0,1000}L04DUr118\(h00k.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","50673"
"*L0phtCrack*",".{0,1000}L0phtCrack.{0,1000}","offensive_tool_keyword","L0phtCrack","L0phtCrack attempts to crack Windows passwords from hashes which it can obtain (given proper access) from stand-alone Windows workstations. networked servers. primary domain controllers. or Active Directory. In some cases it can sniff the hashes off the wire. It also has numerous methods of generating password guesses (dictionary. brute force. etc). LC5 was discontinued by Symantec in 2006. then re-acquired by the original L0pht guys and reborn as LC6 in 2009. For free alternatives. consider ophcrack. Cain and Abel. or John the Ripper. For downloads and more information. visit the L0phtCrack homepage.","T1003 - T1110 - T1212 - T1552 - T1609","TA0001 - TA0002 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Credential Access","http://www.l0phtcrack.com/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","50676"
"*LANMAN password IS however set. Will now install new password as NT pass instead*",".{0,1000}LANMAN\spassword\sIS\showever\sset\.\sWill\snow\sinstall\snew\spassword\sas\sNT\spass\sinstead.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","50787"
"*LAPSDecrypt.*",".{0,1000}LAPSDecrypt\..{0,1000}","offensive_tool_keyword","LAPSDecrypt","Quick POC looking at how encryption works for LAPS (v2)","T1552.004","TA0003","N/A","N/A","Credential Access","https://gist.github.com/xpn/23dc5b6c260a7571763ca8ca745c32f4","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","50795"
"*LAPSDumper-main*",".{0,1000}LAPSDumper\-main.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","1","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","50798"
"*lastpass_sniffed_fmt_plug*",".{0,1000}lastpass_sniffed_fmt_plug.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50810"
"*lastpass2john.py*",".{0,1000}lastpass2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50811"
"*laZagne.exe browsers*",".{0,1000}laZagne\.exe\sbrowsers.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","50845"
"*Lazagne.exe*",".{0,1000}Lazagne\.exe.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","50846"
"*Lazagne.py*",".{0,1000}Lazagne\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","50848"
"*lazagne.softwares.sysadmin.aws*",".{0,1000}lazagne\.softwares\.sysadmin\.aws.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","50849"
"*lazagne.softwares.windows*",".{0,1000}lazagne\.softwares\.windows.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","50850"
"*lazagne.tar.gz*",".{0,1000}lazagne\.tar\.gz.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","0","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","50851"
"*LaZagneForensic*",".{0,1000}LaZagneForensic.{0,1000}","offensive_tool_keyword","LaZagneForensic","Windows passwords decryption from dump files","T1003 - T1081 - T1082","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/AlessandroZ/LaZagneForensic","1","1","N/A","N/A","N/A","5","498","111","2023-02-02T16:36:21Z","2018-02-01T15:44:31Z","50852"
"*LaZagne-master.zip*",".{0,1000}LaZagne\-master\.zip.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","50853"
"*L-codes/pwcrack-framework*",".{0,1000}L\-codes\/pwcrack\-framework.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","50861"
"*L'D', L'b', L'g', L'h', L'e', L'l', L'p', L'.', L'd', L'l', L'l', L'\0'*",".{0,1000}L\'D\',\sL\'b\',\sL\'g\',\sL\'h\',\sL\'e\',\sL\'l\',\sL\'p\',\sL\'\.\',\sL\'d\',\sL\'l\',\sL\'l\',\sL\'\\0\'.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","50862"
"*LDAP PASSWORD ENUM*",".{0,1000}LDAP\sPASSWORD\sENUM.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","0","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","50864"
"*LDAPWordlistHarvester.ps1*",".{0,1000}LDAPWordlistHarvester\.ps1.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","1","N/A","N/A","5","","N/A","","","","50905"
"*LDAPWordlistHarvester.py*",".{0,1000}LDAPWordlistHarvester\.py.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","1","N/A","N/A","5","","N/A","","","","50906"
"*LDAPWordlistHarvester-main*",".{0,1000}LDAPWordlistHarvester\-main.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","1","N/A","N/A","5","","N/A","","","","50907"
"*ldif2john.pl*",".{0,1000}ldif2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50916"
"*leftp/BackupCreds*",".{0,1000}leftp\/BackupCreds.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","1","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","50926"
"*legba * --username*",".{0,1000}legba\s.{0,1000}\s\-\-username.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50929"
"*legba amqp *--target *",".{0,1000}legba\samqp\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50930"
"*legba dns *--data *",".{0,1000}legba\sdns\s.{0,1000}\-\-data\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50931"
"*legba ftp *--target *",".{0,1000}legba\sftp\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50932"
"*legba http *--http-payload *",".{0,1000}legba\shttp\s.{0,1000}\-\-http\-payload\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50933"
"*legba http.basic *--target *",".{0,1000}legba\shttp\.basic\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50934"
"*legba http.enum *--http*",".{0,1000}legba\shttp\.enum\s.{0,1000}\-\-http.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50935"
"*legba http.ntlm1 *",".{0,1000}legba\shttp\.ntlm1\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50936"
"*legba http.ntlm2 *",".{0,1000}legba\shttp\.ntlm2\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50937"
"*legba imap *--target *",".{0,1000}legba\simap\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50938"
"*legba kerberos *--target *",".{0,1000}legba\skerberos\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50939"
"*legba kerberos*--kerberos-realm *",".{0,1000}legba\skerberos.{0,1000}\-\-kerberos\-realm\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50940"
"*legba ldap *--ldap-domain*",".{0,1000}legba\sldap\s.{0,1000}\-\-ldap\-domain.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50941"
"*legba mongodb* --target *",".{0,1000}legba\smongodb.{0,1000}\s\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50942"
"*legba mssql * --target *",".{0,1000}legba\smssql\s.{0,1000}\s\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50943"
"*legba mysql * --target *",".{0,1000}legba\smysql\s.{0,1000}\s\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50944"
"*legba pgsql * --target *",".{0,1000}legba\spgsql\s.{0,1000}\s\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50945"
"*legba pop3 *--target *",".{0,1000}legba\spop3\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50946"
"*legba rdp *--target *",".{0,1000}legba\srdp\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50947"
"*legba sftp *--target *",".{0,1000}legba\ssftp\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50948"
"*legba smtp *--target *",".{0,1000}legba\ssmtp\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50949"
"*legba ssh *--target *",".{0,1000}legba\sssh\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50950"
"*legba stomp *--target*",".{0,1000}legba\sstomp\s.{0,1000}\-\-target.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50951"
"*legba telnet *--telnet-*",".{0,1000}legba\stelnet\s.{0,1000}\-\-telnet\-.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50952"
"*legba vnc* --target *",".{0,1000}legba\svnc.{0,1000}\s\-\-target\s.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50953"
"*legba-main.zip*",".{0,1000}legba\-main\.zip.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","1","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","50954"
"*Leo4j/Ask4Creds*",".{0,1000}Leo4j\/Ask4Creds.{0,1000}","offensive_tool_keyword","Ask4Creds","Prompt User for credentials","T1056 - T1071","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Leo4j/Ask4Creds","1","1","N/A","N/A","8","1","1","0","2024-03-20T17:09:21Z","2023-11-12T15:21:40Z","50962"
"*Leo4j/KeyCredentialLink*",".{0,1000}Leo4j\/KeyCredentialLink.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","1","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","50968"
"*Leo4j/PassSpray*",".{0,1000}Leo4j\/PassSpray.{0,1000}","offensive_tool_keyword","PassSpray","Domain Password Spray","T1110.003 - T1078","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/PassSpray","1","1","N/A","N/A","10","1","7","3","2025-02-20T10:07:43Z","2023-11-16T13:35:49Z","50969"
"*LetMeowIn.exe*",".{0,1000}LetMeowIn\.exe.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","1","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","50978"
"*LetMeowIn-main.zip*",".{0,1000}LetMeowIn\-main\.zip.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","1","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","50979"
"*lgandx/Pcredz*",".{0,1000}lgandx\/Pcredz.{0,1000}","offensive_tool_keyword","Pcredz","This tool extracts Credit card numbers. NTLM(DCE-RPC. HTTP. SQL. LDAP. etc). Kerberos (AS-REQ Pre-Auth etype 23). HTTP Basic. SNMP. POP. SMTP. FTP. IMAP. etc from a pcap file or from a live interface.","T1116 - T1003 - T1002 - T1001 - T1005 - T1552","TA0003 - TA0002 - TA0011","N/A","N/A","Credential Access","https://github.com/lgandx/Pcredz","1","1","N/A","N/A","N/A","10","2100","413","2025-01-27T10:34:00Z","2014-04-07T02:03:33Z","50985"
"*lgmpcpglpngdoalbgeoldeajfclnhafa*",".{0,1000}lgmpcpglpngdoalbgeoldeajfclnhafa.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","50988"
"*lib/ForgeTicket.*",".{0,1000}lib\/ForgeTicket\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","50994"
"*lib/S4U.*",".{0,1000}lib\/S4U\..{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","50995"
"*libFuzzer-HOWTO.*",".{0,1000}libFuzzer\-HOWTO\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","50998"
"*-LIBGCCW32-EH-3-SJLJ-GTHR-MINGW32*",".{0,1000}\-LIBGCCW32\-EH\-3\-SJLJ\-GTHR\-MINGW32.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","50999"
"*libreoffice2john.py*",".{0,1000}libreoffice2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51002"
"*LimerBoy/Adamantium-Thief*",".{0,1000}LimerBoy\/Adamantium\-Thief.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","1","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","51033"
"*lion2john.pl*",".{0,1000}lion2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51091"
"*lion2john-alt.pl*",".{0,1000}lion2john\-alt\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51092"
"*list/steal token of user *default NT AUTHORITY\\SYSTEM for comamnd execution*",".{0,1000}list\/steal\stoken\sof\suser\s\.{0,1000}default\sNT\sAUTHORITY\\\\SYSTEM\sfor\scomamnd\sexecution.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","0","#content","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","51096"
"*List-KeyCredentials -target *",".{0,1000}List\-KeyCredentials\s\-target\s.{0,1000}","offensive_tool_keyword","KeyCredentialLink","Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute","T1098 - T1550","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/Leo4j/KeyCredentialLink","1","0","N/A","N/A","10","1","21","3","2024-06-05T13:44:39Z","2024-06-05T13:19:49Z","51113"
"*listLocalAdminAccess(*",".{0,1000}listLocalAdminAccess\(.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","51114"
"*listPwnableTargets(*",".{0,1000}listPwnableTargets\(.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","51118"
"*Live Dump Capture Dump Data API ended. NT Status: STATUS_SUCCESS.*",".{0,1000}Live\sDump\sCapture\sDump\sData\sAPI\sended\.\sNT\sStatus\:\sSTATUS_SUCCESS\..{0,1000}","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","0","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","51129"
"*lmhash*aad3b435b51404eeaad3b435b51404ee*",".{0,1000}lmhash.{0,1000}aad3b435b51404eeaad3b435b51404ee.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","0","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","51147"
"*L'n', L't', L'd', L'l', L'l', L'.', L'd', L'l', L'l', L'\0'*",".{0,1000}L\'n\',\sL\'t\',\sL\'d\',\sL\'l\',\sL\'l\',\sL\'\.\',\sL\'d\',\sL\'l\',\sL\'l\',\sL\'\\0\'.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","51154"
"*lnkbomb.py *",".{0,1000}lnkbomb\.py\s.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","0","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","51157"
"*lnkbomb-1.0.zip*",".{0,1000}lnkbomb\-1\.0\.zip.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","1","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","51158"
"*load mimikatz windbg extension, extracts credential from crash dump*",".{0,1000}load\smimikatz\swindbg\sextension,\sextracts\scredential\sfrom\scrash\sdump.{0,1000}","offensive_tool_keyword","Forensike","Remotely dump NT hashes through Windows Crash dumps","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/bmarchev/Forensike","1","0","N/A","N/A","10","1","27","3","2024-10-29T00:13:50Z","2024-02-01T13:52:55Z","51165"
"*Load the passwords from another Windows user or external drive*",".{0,1000}Load\sthe\spasswords\sfrom\sanother\sWindows\suser\sor\sexternal\sdrive.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51166"
"*Load the passwords of the current logged-on user*",".{0,1000}Load\sthe\spasswords\sof\sthe\scurrent\slogged\-on\suser.{0,1000}","offensive_tool_keyword","chromepass","ChromePass is a small password recovery tool for Windows that allows you to view the user names and passwords stored by Google Chrome Web browser. For each password entry. the following information is displayed: Origin URL. Action URL. User Name Field. Password Field. User Name. Password. and Created Time. It allows you to get the passwords from your current running system. or from a user profile stored on external drive.","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","GoGoogle - GOBLIN PANDA - Loki","Credential Access","https://www.nirsoft.net/utils/chromepass.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51167"
"*load_ssp *.dll*",".{0,1000}load_ssp\s.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","51170"
"*load_ssp.x64.exe *.dll*",".{0,1000}load_ssp\.x64\.exe\s.{0,1000}\.dll.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","51171"
"*LoadEWSDLL*",".{0,1000}LoadEWSDLL.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","51183"
"*Locedx765al Extensedx765ion Settinedx765gs*",".{0,1000}Locedx765al\sExtensedx765ion\sSettinedx765gs.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","51254"
"*Loedx765gin Daedx765ta*",".{0,1000}Loedx765gin\sDaedx765ta.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","51314"
"*Logedx765in Daedx765ta Foedx765r Accedx765ount*",".{0,1000}Logedx765in\sDaedx765ta\sFoedx765r\sAccedx765ount.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","51322"
"*login-securite/conpass*",".{0,1000}login\-securite\/conpass.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","1","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","51330"
"*login-securite/lsassy*",".{0,1000}login\-securite\/lsassy.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51331"
"*login-securite/lsassy*",".{0,1000}login\-securite\/lsassy.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51332"
"*logs/Responder-Session.log*",".{0,1000}logs\/Responder\-Session\.log.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","51343"
"*logs/ridenum.log*",".{0,1000}logs\/ridenum\.log.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","51344"
"*logs/shares-with-SCF.txt*",".{0,1000}logs\/shares\-with\-SCF\.txt.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","51345"
"*logs/theHarvester.py.log*",".{0,1000}logs\/theHarvester\.py\.log.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","51346"
"*loot_mysql_passwords(*",".{0,1000}loot_mysql_passwords\(.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","0","N/A","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","51361"
"*LostMyPassword.exe*",".{0,1000}LostMyPassword\.exe.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51366"
"*LostMyPassword.zip*",".{0,1000}LostMyPassword\.zip.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51367"
"*LostMyPasswordx64.zip*",".{0,1000}LostMyPasswordx64\.zip.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51368"
"*lotus2john.py*",".{0,1000}lotus2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51369"
"*lpfcbjknijpeeillifnkikgncikgfhdo*",".{0,1000}lpfcbjknijpeeillifnkikgncikgfhdo.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","51371"
"*L'S', L'e', L'D', L'e', L'b', L'u', L'g', L'P', L'r', L'i', L'v', L'i', L'l', L'e', L'g', L'e'*",".{0,1000}L\'S\',\sL\'e\',\sL\'D\',\sL\'e\',\sL\'b\',\sL\'u\',\sL\'g\',\sL\'P\',\sL\'r\',\sL\'i\',\sL\'v\',\sL\'i\',\sL\'l\',\sL\'e\',\sL\'g\',\sL\'e\'.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","51376"
"*LSA dump programe (bootkey/syskey) - pwdump and others*",".{0,1000}LSA\sdump\sprograme\s\(bootkey\/syskey\)\s\-\spwdump\sand\sothers.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51378"
"*lsa_decryptor.py*",".{0,1000}lsa_decryptor\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","51379"
"*lsa_decryptor_nt*.py*",".{0,1000}lsa_decryptor_nt.{0,1000}\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","51380"
"*lsadecryptor_lsa_decryptor*",".{0,1000}lsadecryptor_lsa_decryptor.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","51382"
"*lsadump::*",".{0,1000}lsadump\:\:.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51384"
"*lsarelayx Starting....*",".{0,1000}lsarelayx\sStarting\.\.\.\..{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","0","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","51403"
"*lsarelayx.exe*",".{0,1000}lsarelayx\.exe.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","1","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","51404"
"*lsarelayx_0.1_ALPHA.zip*",".{0,1000}lsarelayx_0\.1_ALPHA\.zip.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","1","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","51405"
"*LSASecretDefaultPassword*",".{0,1000}LSASecretDefaultPassword.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","10","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","51407"
"*lsasecrets.py*",".{0,1000}lsasecrets\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","10","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","51408"
"*-LSASecrets.txt*",".{0,1000}\-LSASecrets\.txt.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","51409"
"*lsasecretslive.py*",".{0,1000}lsasecretslive\.py.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","51410"
"*Lsass Dump File Created*",".{0,1000}Lsass\sDump\sFile\sCreated.{0,1000}","offensive_tool_keyword","EvilLsassTwin","attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.","T1003.001 - T1055 - T1093","TA0006 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","9","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","51413"
"*lsass dump saved to: *",".{0,1000}lsass\sdump\ssaved\sto\:\s.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","0","#content","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","51416"
"*Lsass minidump can be imported in *",".{0,1000}Lsass\sminidump\scan\sbe\simported\sin\s.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#content","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","51417"
"*LSASS minidump file for *",".{0,1000}LSASS\sminidump\sfile\sfor\s.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","51418"
"*lsass*rundll32.exe *comsvcs.dll, MiniDump *.dmp full*",".{0,1000}lsass.{0,1000}rundll32\.exe\s.{0,1000}comsvcs\.dll,\sMiniDump\s.{0,1000}\.dmp\sfull.{0,1000}","greyware_tool_keyword","rundll32","dumping lsass","T1003 - T1055.011 - T1564.002","TA0005 - TA0006","N/A","Black Basta","Credential Access","N/A","1","0","N/A","observed in exploitations by mthcht","10","10","N/A","N/A","N/A","N/A","51419"
"*lsass.dmp*",".{0,1000}lsass\.dmp.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Dump LSASS memory through a process snapshot (-r) avoiding interacting with it directly","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51420"
"*lsass.dmp*",".{0,1000}lsass\.dmp.{0,1000}","offensive_tool_keyword","lsass","Dump LSASS memory through a process snapshot (-r) avoiding interacting with it directly","T1110","N/A","N/A","N/A","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51421"
"*lsass.dmp*",".{0,1000}lsass\.dmp.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","51422"
"*lsass.exe*.dmp*",".{0,1000}lsass\.exe.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","0","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","51423"
"*lsassDumpRetryCount*",".{0,1000}lsassDumpRetryCount.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","51430"
"*Lsass-Mdump*",".{0,1000}Lsass\-Mdump.{0,1000}","signature_keyword","Antivirus Signature","Dump LSASS memory through a process snapshot (-r) avoiding interacting with it directly","T1110","TA0006","N/A","N/A","Credential Access","lsass dump malware signature","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","51432"
"*LsassSilentProcessExit.cpp*",".{0,1000}LsassSilentProcessExit\.cpp.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","51434"
"*LsassSilentProcessExit.exe*",".{0,1000}LsassSilentProcessExit\.exe.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","51435"
"*LsassSilentProcessExit.vcxproj*",".{0,1000}LsassSilentProcessExit\.vcxproj.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","0","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","51436"
"*LsassSilentProcessExit-master*",".{0,1000}LsassSilentProcessExit\-master.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","51437"
"*lsassy *",".{0,1000}lsassy\s.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51438"
"*lsassy -*",".{0,1000}lsassy\s\-.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","51439"
"*lsassy.*",".{0,1000}lsassy\..{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51441"
"*lsassy.impacketfile*",".{0,1000}lsassy\.impacketfile.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51442"
"*lsassy/dumpmethod*",".{0,1000}lsassy\/dumpmethod.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51443"
"*lsassy_dump*",".{0,1000}lsassy_dump.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","51444"
"*lsassy_linux_amd64*",".{0,1000}lsassy_linux_amd64.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","#linux","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51447"
"*lsassy_logger.*",".{0,1000}lsassy_logger\..{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51448"
"*lsassy_windows_amd64*",".{0,1000}lsassy_windows_amd64.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51449"
"*lsassy-linux-x64-*",".{0,1000}lsassy\-linux\-x64\-.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","#linux","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51450"
"*lsassy-MacOS-x64-*",".{0,1000}lsassy\-MacOS\-x64\-.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51451"
"*lsassy-windows-latest.zip*",".{0,1000}lsassy\-windows\-latest\.zip.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51452"
"*lsassy-windows-x64-*.exe",".{0,1000}lsassy\-windows\-x64\-.{0,1000}\.exe","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51453"
"*Luct0r/KerberOPSEC*",".{0,1000}Luct0r\/KerberOPSEC.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","1","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","51472"
"*luks2john.py*",".{0,1000}luks2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51475"
"*Luna Grabber | Created By Smug*",".{0,1000}Luna\sGrabber\s\|\sCreated\sBy\sSmug.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","51476"
"*Luna Grabber Builder - Running on v*",".{0,1000}Luna\sGrabber\sBuilder\s\-\sRunning\son\sv.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","51477"
"*lyncsmash.git*",".{0,1000}lyncsmash\.git.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","51491"
"*lyncsmash.log*",".{0,1000}lyncsmash\.log.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","#logfile","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","51492"
"*lyncsmash.py*",".{0,1000}lyncsmash\.py.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","51493"
"*lyncsmash-master*",".{0,1000}lyncsmash\-master.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","51494"
"*-m dumpert *",".{0,1000}\-m\sdumpert\s.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","51499"
"*'M', 'i', 'n', 'i', 'D', 'u', 'm', 'p', 'W', 'r', 'i', 't', 'e', 'D', 'u', 'm', 'p'*",".{0,1000}\'M\',\s\'i\',\s\'n\',\s\'i\',\s\'D\',\s\'u\',\s\'m\',\s\'p\',\s\'W\',\s\'r\',\s\'i\',\s\'t\',\s\'e\',\s\'D\',\s\'u\',\s\'m\',\s\'p\'.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","51502"
"*'M','i','n','i','D','u','m','p','W','r','i','t','e','D','u','m','p'*",".{0,1000}\'M\',\'i\',\'n\',\'i\',\'D\',\'u\',\'m\',\'p\',\'W\',\'r\',\'i\',\'t\',\'e\',\'D\',\'u\',\'m\',\'p\'.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","51503"
"*m4ll0k/SecretFinder*",".{0,1000}m4ll0k\/SecretFinder.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","1","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","51512"
"*mac2john.py*",".{0,1000}mac2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51521"
"*mac2john-alt.py*",".{0,1000}mac2john\-alt\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51522"
"*mailpv.exe*",".{0,1000}mailpv\.exe.{0,1000}","offensive_tool_keyword","mailpv","Mail PassView is a small password-recovery tool that reveals the passwords and other account details in email clients","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51553"
"*mailpv.zip*",".{0,1000}mailpv\.zip.{0,1000}","offensive_tool_keyword","mailpv","Mail PassView is a small password-recovery tool that reveals the passwords and other account details in email clients","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/mailpv.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","51554"
"*MailSniper.ps1*",".{0,1000}MailSniper\.ps1.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","51556"
"*makebof.bat*",".{0,1000}makebof\.bat.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","51578"
"*makeivs-ng -b *",".{0,1000}makeivs\-ng\s\-b\s.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","51580"
"*MakeMeEnterpriseAdmin.ps1*",".{0,1000}MakeMeEnterpriseAdmin\.ps1.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","51588"
"*Malicious Shortcut Generator*",".{0,1000}Malicious\sShortcut\sGenerator.{0,1000}","offensive_tool_keyword","lnkbomb","Malicious shortcut generator for collecting NTLM hashes from insecure file shares.","T1023.003 - T1557.002 - T1046","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/dievus/lnkbomb","1","0","N/A","N/A","10","4","327","58","2024-10-22T17:51:10Z","2022-01-03T04:17:11Z","51598"
"*manager/keepass.py*",".{0,1000}manager\/keepass\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","51632"
"*manager/mRemoteNG.py*",".{0,1000}manager\/mRemoteNG\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","51633"
"*mandiant/ADFSDump*",".{0,1000}mandiant\/ADFSDump.{0,1000}","offensive_tool_keyword","ADFSDump","A C# tool to dump all sorts of goodies from AD FS","T1081 - T1003 - T1114 - T1212","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/mandiant/ADFSDump","1","1","N/A","N/A","10","4","349","67","2023-08-07T16:58:37Z","2019-03-20T22:31:16Z","51637"
"*mandiant/gocrack*",".{0,1000}mandiant\/gocrack.{0,1000}","offensive_tool_keyword","gocrack","GoCrack is a management frontend for password cracking tools written in Go","T1110 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/mandiant/gocrack","1","1","N/A","N/A","9","10","1233","242","2025-04-14T16:20:05Z","2017-10-23T14:43:59Z","51640"
"*map_payload_dll*",".{0,1000}map_payload_dll.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","51654"
"*mcafee_epo2john.py*",".{0,1000}mcafee_epo2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51690"
"*Md4-128.unverified.test-vectors.txt*",".{0,1000}Md4\-128\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51695"
"*Md5-128.unverified.test-vectors.txt*",".{0,1000}Md5\-128\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","51696"
"*mdavis332/DomainPasswordSpray*",".{0,1000}mdavis332\/DomainPasswordSpray.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","10","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","51697"
"*mdsecactivebreach/DragonCastle*",".{0,1000}mdsecactivebreach\/DragonCastle.{0,1000}","offensive_tool_keyword","DragonCastle","A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.","T1003 - T1547.005 - T1055 - T1557","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/DragonCastle","1","1","N/A","N/A","10","3","298","38","2022-10-26T10:19:55Z","2022-10-26T10:18:37Z","51708"
"*mdsecactivebreach/Farmer*",".{0,1000}mdsecactivebreach\/Farmer.{0,1000}","offensive_tool_keyword","Farmer","Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.","T1557.001 - T1056.004 - T1078.003","TA0006 - TA0004 - TA0001","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/Farmer","1","1","N/A","N/A","10","4","379","61","2021-04-28T15:27:24Z","2021-02-22T14:32:29Z","51709"
"*Meckazin/ChromeKatz*",".{0,1000}Meckazin\/ChromeKatz.{0,1000}","offensive_tool_keyword","ChromeKatz","Dump cookies directly from Chrome process memory","T1555.003 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Meckazin/ChromeKatz","1","1","N/A","N/A","10","10","1171","115","2024-11-26T12:53:22Z","2023-12-07T22:27:06Z","51712"
"*media_variable_file_cryptography.py*",".{0,1000}media_variable_file_cryptography\.py.{0,1000}","offensive_tool_keyword","pxethief","PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager","T1555.004 - T1555.002","TA0006","N/A","N/A","Credential Access","https://github.com/MWR-CyberSec/PXEThief","1","1","N/A","N/A","N/A","4","368","57","2024-05-29T15:07:15Z","2022-08-12T22:16:46Z","51716"
"*Meedx765taMaedx765sk*",".{0,1000}Meedx765taMaedx765sk.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","51721"
"*MegaManSec/SSH-Snake*",".{0,1000}MegaManSec\/SSH\-Snake.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","51727"
"*memory*mimipy.py*",".{0,1000}memory.{0,1000}mimipy\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","51754"
"*memory/onepassword.py*",".{0,1000}memory\/onepassword\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","51755"
"*memorydump.py*",".{0,1000}memorydump\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","51756"
"*memorydump.py*",".{0,1000}memorydump\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","51757"
"*Meowmycks/LetMeowIn*",".{0,1000}Meowmycks\/LetMeowIn.{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","1","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","51761"
"*met_inject.py*",".{0,1000}met_inject\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","51890"
"*mez-0/DecryptRDCManager*",".{0,1000}mez\-0\/DecryptRDCManager.{0,1000}","offensive_tool_keyword","DecryptRDCManager","decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI","T1003 - T1552 - T1081 - T1027","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mez-0/DecryptRDCManager","1","1","N/A","N/A","8","1","73","7","2020-09-29T10:12:58Z","2020-09-29T08:53:46Z","51929"
"*mfgccjchihfkkindfppnaooecgfneiii*",".{0,1000}mfgccjchihfkkindfppnaooecgfneiii.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","51931"
"*mgffkfbidihjpoaomajlbgchddlicgpn*",".{0,1000}mgffkfbidihjpoaomajlbgchddlicgpn.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","51937"
"*micahvandeusen/gMSADumper*",".{0,1000}micahvandeusen\/gMSADumper.{0,1000}","offensive_tool_keyword","gMSADumper","Lists who can read any gMSA password blobs and parses them if the current user has access.","T1552.001 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/micahvandeusen/gMSADumper","1","1","N/A","N/A","N/A","3","274","51","2024-02-12T02:15:32Z","2021-04-10T00:15:24Z","51945"
"*Micedx765rosoft*",".{0,1000}Micedx765rosoft.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","51946"
"*microsoft-edge/cookies.txt*",".{0,1000}microsoft\-edge\/cookies\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","51972"
"*microsoft-edge/credit_cards.txt*",".{0,1000}microsoft\-edge\/credit_cards\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","51973"
"*microsoft-edge/history.txt*",".{0,1000}microsoft\-edge\/history\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","51974"
"*microsoft-edge/login_data.txt*",".{0,1000}microsoft\-edge\/login_data\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","51975"
"*microsoft-edge\cookies.txt*",".{0,1000}microsoft\-edge\\cookies\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","51976"
"*microsoft-edge\credit_cards.txt*",".{0,1000}microsoft\-edge\\credit_cards\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","51977"
"*microsoft-edge\history.txt*",".{0,1000}microsoft\-edge\\history\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","51978"
"*microsoft-edge\login_data.txt*",".{0,1000}microsoft\-edge\\login_data\.txt.{0,1000}","offensive_tool_keyword","Browser-password-stealer","This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!","T1003.002 - T1056.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/henry-richard7/Browser-password-stealer","1","0","N/A","N/A","10","5","423","62","2024-07-12T10:30:42Z","2020-09-15T09:23:56Z","51979"
"*MIDL_INTERFACE(""A949CB4E-C4F9-44C4-B213-6BF8AA9AC69C"")*",".{0,1000}MIDL_INTERFACE\(\""A949CB4E\-C4F9\-44C4\-B213\-6BF8AA9AC69C\""\).{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","0","#content","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","51981"
"*mimidogz-master.zip*",".{0,1000}mimidogz\-master\.zip.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","52005"
"*mimidrv*",".{0,1000}mimidrv.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation ","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52007"
"*mimidrv.sys*",".{0,1000}mimidrv\.sys.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation ","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52009"
"*mimikatz_trunk.7z*",".{0,1000}mimikatz_trunk\.7z.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archive names","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52035"
"*mimikatz_trunk.zip*",".{0,1000}mimikatz_trunk\.zip.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz archive names","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52036"
"*MimikatzStream should be at offset *",".{0,1000}MimikatzStream\sshould\sbe\sat\soffset\s.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","#content","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","52044"
"*mimikatzsvc*",".{0,1000}mimikatzsvc.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52045"
"*mimikittenz*",".{0,1000}mimikittenz.{0,1000}","offensive_tool_keyword","mimikittenz","mimikittenz is a post-exploitation powershell tool that utilizes the Windows function ReadProcessMemory() in order to extract plain-text passwords from various target processes mimikittenz can also easily extract other kinds of juicy info from target processes using regex patterns including but not limited Encryption Keys & All the other goodstuff","T1003 - T1216 - T1552 - T1002 - T1083","TA0003 - TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/orlyjamie/mimikittenz","1","1","N/A","N/A","10","10","1840","334","2024-06-28T11:10:03Z","2016-07-04T13:57:18Z","52046"
"*mimilib*",".{0,1000}mimilib.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation ","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52051"
"*mimilove*",".{0,1000}mimilove.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation ","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52055"
"*mimilove.exe*",".{0,1000}mimilove\.exe.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation ","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52056"
"*mimilove_kerberos*",".{0,1000}mimilove_kerberos.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52058"
"*mimilove_lsasrv*",".{0,1000}mimilove_lsasrv.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52059"
"*mimipenguin.*",".{0,1000}mimipenguin.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","1","#linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","52061"
"*mimipenguin_*.tar.gz*",".{0,1000}mimipenguin_.{0,1000}\.tar\.gz.{0,1000}","offensive_tool_keyword","mimipenguin","A tool to dump the login password from the current linux user","T1003.007","TA0006 - TA0002 ","N/A","TeamTNT","Credential Access","https://github.com/huntergregal/mimipenguin","1","1","#linux","N/A","10","10","3940","644","2023-05-17T13:20:46Z","2017-03-28T21:24:28Z","52069"
"*mimipy.py*",".{0,1000}mimipy\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","52071"
"*mimipy_loot_passwords*",".{0,1000}mimipy_loot_passwords.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","0","N/A","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","52072"
"*mimispool.dll*",".{0,1000}mimispool\.dll.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation ","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","52077"
"*minidump*minikerberos*",".{0,1000}minidump.{0,1000}minikerberos.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","52079"
"*minidump.* lsass.dmp*",".{0,1000}minidump\..{0,1000}\slsass\.dmp.{0,1000}","offensive_tool_keyword","onex","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","N/A","N/A","N/A","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","52080"
"*Minidump.exe*",".{0,1000}Minidump\.exe.{0,1000}","offensive_tool_keyword","bof-collection","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","N/A","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","52081"
"*minidump.lsakeys*",".{0,1000}minidump\.lsakeys.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","#content","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","52083"
"*Minidump.sln*",".{0,1000}Minidump\.sln.{0,1000}","offensive_tool_keyword","bof-collection","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","1","N/A","N/A","N/A","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","52084"
"*minidumptomemsharp.lsa.lsaproviderduper.boo*",".{0,1000}minidumptomemsharp\.lsa\.lsaproviderduper\.boo.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","52087"
"*MiniDumpWriteDump(hLsass*",".{0,1000}MiniDumpWriteDump\(hLsass.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","52088"
"*MiniDumpWriteDump(lsass*",".{0,1000}MiniDumpWriteDump\(lsass.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","52089"
"*mirrordump.py*",".{0,1000}mirrordump\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","52111"
"*mitmdump -s aerosol.py*",".{0,1000}mitmdump\s\-s\saerosol\.py.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","52156"
"*mlcsec/FormThief*",".{0,1000}mlcsec\/FormThief.{0,1000}","offensive_tool_keyword","FormThief","Spoofing desktop login applications with WinForms and WPF","T1204.002 - T1056.004 - T1071.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/mlcsec/FormThief","1","1","N/A","N/A","8","2","173","31","2024-02-19T22:40:09Z","2024-02-19T22:34:07Z","52173"
"*mobaxtermfox.dll*",".{0,1000}mobaxtermfox\.dll.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","52178"
"*--mode 3 --type handshake --essid * --verbose -d dicts/* --read *.cap*",".{0,1000}\-\-mode\s3\s\-\-type\shandshake\s\-\-essid\s.{0,1000}\s\-\-verbose\s\-d\sdicts\/.{0,1000}\s\-\-read\s.{0,1000}\.cap.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","0","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","52209"
"*--mode 3 --type pmkid --verbose -d dicts/* --read *.txt*",".{0,1000}\-\-mode\s3\s\-\-type\spmkid\s\-\-verbose\s\-d\sdicts\/.{0,1000}\s\-\-read\s.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","0","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","52210"
"*modules*daclread.py*",".{0,1000}modules.{0,1000}daclread\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","52240"
"*Moedx765zilla\\Firedx765efox\\Profedx765iles*",".{0,1000}Moedx765zilla\\\\Firedx765efox\\\\Profedx765iles.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","52249"
"*monero2john.py*",".{0,1000}monero2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52254"
"*money2john.py*",".{0,1000}money2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52255"
"*mongodb2john.js*",".{0,1000}mongodb2john\.js.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52256"
"*moonD4rk/HackBrowserData*",".{0,1000}moonD4rk\/HackBrowserData.{0,1000}","offensive_tool_keyword","HackBrowserData","Decrypt passwords/cookies/history/bookmarks from the browser","T1555.003 - T1552.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/moonD4rk/HackBrowserData","1","1","N/A","N/A","N/A","10","12216","1656","2025-04-06T01:32:13Z","2020-06-18T03:24:31Z","52276"
"*mosquitto2john.py*",".{0,1000}mosquitto2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52285"
"*Moziedx765lla Firefedx765ox*",".{0,1000}Moziedx765lla\sFirefedx765ox.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","52296"
"*mozilla2john.py*",".{0,1000}mozilla2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52303"
"*mremoteng_decrypt.py*",".{0,1000}mremoteng_decrypt\.py.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/haseebT/mRemoteNG-Decrypt","1","1","N/A","N/A","8","2","146","42","2023-07-06T16:15:20Z","2019-05-27T05:25:57Z","52319"
"*mremoteng_decrypt.py*",".{0,1000}mremoteng_decrypt\.py.{0,1000}","offensive_tool_keyword","mRemoteNG-Decrypt","Python script to decrypt passwords stored by mRemoteNG","T1555.003 - T1110.003 - T1003 - T1081","TA0006 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/kmahyyg/mremoteng-decrypt","1","1","N/A","N/A","8","1","83","21","2022-10-29T16:02:26Z","2019-05-11T09:09:49Z","52320"
"*mRemoteNG-local.py*",".{0,1000}mRemoteNG\-local\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","52321"
"*msfcallback.bin*",".{0,1000}msfcallback\.bin.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","52353"
"*MSIL.ClipBanker*",".{0,1000}MSIL\.ClipBanker.{0,1000}","signature_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","#Avsignature","N/A","8","1","N/A","N/A","N/A","N/A","52462"
"*MSIL/ClipBanker*",".{0,1000}MSIL\/ClipBanker.{0,1000}","signature_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","0","#Avsignature","N/A","8","1","N/A","N/A","N/A","N/A","52463"
"*MSIL/KeeThief.A!tr.pws*",".{0,1000}MSIL\/KeeThief\.A!tr\.pws.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#Avsignature","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","52467"
"*MSIL/PSW.KeeThief.A*",".{0,1000}MSIL\/PSW\.KeeThief\.A.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#Avsignature","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","52468"
"*MSOLSpray *",".{0,1000}MSOLSpray\s.{0,1000}","offensive_tool_keyword","MSOLSpray","This module will perform password spraying against Microsoft Online accounts (Azure/O365)","T1110.003 - T1553.003 - T1621","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/MSOLSpray","1","0","N/A","network exploitation tool","10","10","964","174","2024-03-19T11:03:06Z","2020-03-16T13:38:22Z","52475"
"*MSOLSpray.git*",".{0,1000}MSOLSpray\.git.{0,1000}","offensive_tool_keyword","MSOLSpray","This module will perform password spraying against Microsoft Online accounts (Azure/O365)","T1110.003 - T1553.003 - T1621","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/MSOLSpray","1","1","N/A","network exploitation tool","10","10","964","174","2024-03-19T11:03:06Z","2020-03-16T13:38:22Z","52476"
"*MSOLSpray.ps1*",".{0,1000}MSOLSpray\.ps1.{0,1000}","offensive_tool_keyword","MSOLSpray","This module will perform password spraying against Microsoft Online accounts (Azure/O365)","T1110.003 - T1553.003 - T1621","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/MSOLSpray","1","1","N/A","network exploitation tool","10","10","964","174","2024-03-19T11:03:06Z","2020-03-16T13:38:22Z","52477"
"*MSOLSpray-master*",".{0,1000}MSOLSpray\-master.{0,1000}","offensive_tool_keyword","MSOLSpray","This module will perform password spraying against Microsoft Online accounts (Azure/O365)","T1110.003 - T1553.003 - T1621","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/dafthack/MSOLSpray","1","1","N/A","network exploitation tool","10","10","964","174","2024-03-19T11:03:06Z","2020-03-16T13:38:22Z","52478"
"*mspass.exe*",".{0,1000}mspass\.exe.{0,1000}","offensive_tool_keyword","mspass","MessenPass can only be used to recover the passwords for the current logged-on user on your local computer. and it only works if you chose the remember your password in one of the above programs. You cannot use this utility for grabbing the passwords of other users.","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/mspass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52479"
"*mspass.zip*",".{0,1000}mspass\.zip.{0,1000}","offensive_tool_keyword","mspass","MessenPass can only be used to recover the passwords for the current logged-on user on your local computer. and it only works if you chose the remember your password in one of the above programs. You cannot use this utility for grabbing the passwords of other users.","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/mspass.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52480"
"*mssqlsvc.kirbi*",".{0,1000}mssqlsvc\.kirbi.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Crack with TGSRepCrack","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","52501"
"*multibit2john.py*",".{0,1000}multibit2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52512"
"*mustafashykh/router-scan*",".{0,1000}mustafashykh\/router\-scan.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","1","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","52516"
"*mv *.ccache *.ccache*",".{0,1000}mv\s.{0,1000}\.ccache\s.{0,1000}\.ccache.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","0","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","52520"
"*-my.sharepoint.com/personal/Fakeuser*",".{0,1000}\-my\.sharepoint\.com\/personal\/Fakeuser.{0,1000}","offensive_tool_keyword","onedrive_user_enum","enumerate valid onedrive users","T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/onedrive_user_enum","1","1","N/A","network exploitation tool","N/A","7","663","83","2025-04-17T00:13:11Z","2019-03-05T08:54:38Z","52523"
"*-my.sharepoint.com/personal/TESTUSER_*",".{0,1000}\-my\.sharepoint\.com\/personal\/TESTUSER_.{0,1000}","offensive_tool_keyword","onedrive_user_enum","enumerate valid onedrive users","T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/onedrive_user_enum","1","1","N/A","network exploitation tool","N/A","7","663","83","2025-04-17T00:13:11Z","2019-03-05T08:54:38Z","52524"
"*myseatbelt.py*",".{0,1000}myseatbelt\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","52531"
"*MZCookiesView*cookies.sqlite*",".{0,1000}MZCookiesView.{0,1000}cookies\.sqlite.{0,1000}","greyware_tool_keyword","MozillaCookiesView","nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors","T1070 - T1552.001 - T1125 - T1005","TA0009 - TA0005","N/A","MuddyWater","Credential Access","https://www.nirsoft.net/utils/mzcv.html","1","0","N/A","N/A","7","10","N/A","N/A","N/A","N/A","52557"
"*MzHmO/NtlmThief*",".{0,1000}MzHmO\/NtlmThief.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","52559"
"*MzHmO/TGSThief*",".{0,1000}MzHmO\/TGSThief.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","1","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","52563"
"*-n ntds.dit -c hashcat*",".{0,1000}\-n\sntds\.dit\s\-c\shashcat.{0,1000}","offensive_tool_keyword","DPAT","Domain Password Audit Tool for Pentesters","T1003 - T1087 - T1110 - T1555","TA0006 - TA0004 - TA0002 - TA0005","N/A","N/A","Credential Access","https://github.com/clr2of8/DPAT","1","0","N/A","N/A","10","10","954","156","2022-06-24T21:41:43Z","2016-11-22T22:00:21Z","52564"
"*n00py/LAPSDumper*",".{0,1000}n00py\/LAPSDumper.{0,1000}","offensive_tool_keyword","LAPSDumper","Dumping LAPS from Python","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/n00py/LAPSDumper","1","1","N/A","N/A","10","3","267","35","2022-12-07T18:35:28Z","2020-12-19T05:15:10Z","52565"
"*n1nj4sec/mimipy*",".{0,1000}n1nj4sec\/mimipy.{0,1000}","offensive_tool_keyword","mimipy","Tool to dump passwords from various processes memory","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/n1nj4sec/mimipy","1","1","N/A","N/A","10","3","207","36","2017-04-30T00:09:15Z","2017-04-05T21:06:32Z","52570"
"*n37sn4k3/BrowserDataGrabber*",".{0,1000}n37sn4k3\/BrowserDataGrabber.{0,1000}","offensive_tool_keyword","Browser Data Grabber","credential access tool used by the Dispossessor ransomware group","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Dispossessor","Credential Access","https://github.com/n37sn4k3/BrowserDataGrabber","1","1","N/A","N/A","10","1","7","4","2018-05-28T15:49:03Z","2018-05-04T12:33:32Z","52571"
"*namespace BackupCreds*",".{0,1000}namespace\sBackupCreds.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","52602"
"*namespace NTLMInjector*",".{0,1000}namespace\sNTLMInjector.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","0","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","52611"
"*namespace POSTDump*",".{0,1000}namespace\sPOSTDump.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","#content","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","52612"
"*namespace POSTMiniDump*",".{0,1000}namespace\sPOSTMiniDump.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","#content","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","52613"
"*namespace Rubeus*",".{0,1000}namespace\sRubeus.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","52618"
"*namespace SafetyDump*",".{0,1000}namespace\sSafetyDump.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","0","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","52619"
"*nanjmdknhkinifnkgdcggcfnhdaammmj*",".{0,1000}nanjmdknhkinifnkgdcggcfnhdaammmj.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","52628"
"*nanodump *",".{0,1000}nanodump\s.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52630"
"*nanodump -*",".{0,1000}nanodump\s\-.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52631"
"*nanodump.*",".{0,1000}nanodump\..{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","52632"
"*nanodump.*",".{0,1000}nanodump\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52633"
"*nanodump.git*",".{0,1000}nanodump\.git.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52634"
"*nanodump.x64*",".{0,1000}nanodump\.x64.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52635"
"*nanodump.x64.exe*",".{0,1000}nanodump\.x64\.exe.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52636"
"*nanodump.x86*",".{0,1000}nanodump\.x86.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52637"
"*nanodump_ppl_dump*",".{0,1000}nanodump_ppl_dump.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52641"
"*nanodump_ppl_dump.x64*",".{0,1000}nanodump_ppl_dump\.x64.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52642"
"*nanodump_ppl_dump.x86*",".{0,1000}nanodump_ppl_dump\.x86.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52643"
"*nanodump_ppl_medic*",".{0,1000}nanodump_ppl_medic.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52644"
"*nanodump_ppl_medic.x64*",".{0,1000}nanodump_ppl_medic\.x64.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52645"
"*nanodump_ppl_medic.x86*",".{0,1000}nanodump_ppl_medic\.x86.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52646"
"*nanodump_ssp*",".{0,1000}nanodump_ssp.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","52647"
"*nanodump_ssp*",".{0,1000}nanodump_ssp.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52648"
"*nanodump_ssp.x64*",".{0,1000}nanodump_ssp\.x64.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52649"
"*nanodump_ssp.x64.dll*",".{0,1000}nanodump_ssp\.x64\.dll.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52651"
"*nanodump_ssp.x86*",".{0,1000}nanodump_ssp\.x86.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52652"
"*nanodump_ssp_embedded.*",".{0,1000}nanodump_ssp_embedded\..{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","52653"
"*NanoDumpPPLmedicPipe*",".{0,1000}NanoDumpPPLmedicPipe.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","52656"
"*NanoDumpSSPPipe*",".{0,1000}NanoDumpSSPPipe.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","52657"
"*NanoDumpWriteDump*",".{0,1000}NanoDumpWriteDump.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","52658"
"*NativeDump.exe *.dmp*",".{0,1000}NativeDump\.exe\s.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","52676"
"*nc64 127.0.0.1 9000 -e cmd.exe*",".{0,1000}nc64\s127\.0\.0\.1\s9000\s\-e\scmd\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","52713"
"*nc64 -L -vv -p 9000*",".{0,1000}nc64\s\-L\s\-vv\s\-p\s9000.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","52714"
"*nccgroup/SCOMDecrypt*",".{0,1000}nccgroup\/SCOMDecrypt.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","52725"
"*ncrack-*.dmg*",".{0,1000}ncrack\-.{0,1000}\.dmg.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","#macos","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52726"
"*ncrack-*-setup.exe*",".{0,1000}ncrack\-.{0,1000}\-setup\.exe.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52727"
"*ncrack.exe*",".{0,1000}ncrack\.exe.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52728"
"*NcrackInstaller.exe*",".{0,1000}NcrackInstaller\.exe.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52729"
"*ncrack-master.zip*",".{0,1000}ncrack\-master\.zip.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52730"
"*ncrack-services*",".{0,1000}ncrack\-services.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","52731"
"*NecroStealer.exe*",".{0,1000}NecroStealer\.exe.{0,1000}","offensive_tool_keyword","Necro-Stealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/Necro-Stealer","1","1","N/A","N/A","8","1","6","1","2022-12-06T16:06:55Z","2022-12-06T15:52:17Z","52737"
"*neo2john.py*",".{0,1000}neo2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","52751"
"*neo4jconnection.py*",".{0,1000}neo4jconnection\.py.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","1","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","52754"
"*net localgroup administrators darkcodersc /add*",".{0,1000}net\slocalgroup\sadministrators\sdarkcodersc\s\/add.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","0","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","52817"
"*net localgroup administrators icebreaker*",".{0,1000}net\slocalgroup\sadministrators\sicebreaker.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","52819"
"*net localgroup guests GuestUser /add*",".{0,1000}net\slocalgroup\sguests\sGuestUser\s\/add.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","0","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","52822"
"*net localgroup users GuestUser /delete*",".{0,1000}net\slocalgroup\susers\sGuestUser\s\/delete.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","0","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","52823"
"*net stop "".NET Runtime Optimization Service""*",".{0,1000}net\sstop\s\""\.NET\sRuntime\sOptimization\sService\"".{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52840"
"*net stop dnscache*",".{0,1000}net\sstop\sdnscache.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52886"
"*net stop DPS*",".{0,1000}net\sstop\sDPS.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52887"
"*net stop gupdatem*",".{0,1000}net\sstop\sgupdatem.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52896"
"*net stop msiserver*",".{0,1000}net\sstop\smsiserver.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52928"
"*net stop OfficeClickToRun*",".{0,1000}net\sstop\sOfficeClickToRun.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52954"
"*net stop PcaSvc*",".{0,1000}net\sstop\sPcaSvc.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52955"
"*net stop sedsvc*",".{0,1000}net\sstop\ssedsvc.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52968"
"*net stop sppsvc*",".{0,1000}net\sstop\ssppsvc.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","52979"
"*net stop SysMain*",".{0,1000}net\sstop\sSysMain.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53001"
"*net stop TrustedInstaller*",".{0,1000}net\sstop\sTrustedInstaller.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53008"
"*net user /add icebreaker *",".{0,1000}net\suser\s\/add\sicebreaker\s.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","53034"
"*net user darkcodersc /add*",".{0,1000}net\suser\sdarkcodersc\s\/add.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","0","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","53042"
"*net user darkcodersc trousers*",".{0,1000}net\suser\sdarkcodersc\strousers.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","0","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","53043"
"*net user GuestUser /add*",".{0,1000}net\suser\sGuestUser\s\/add.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","0","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","53047"
"*net user HackMe *",".{0,1000}net\suser\sHackMe\s.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","0","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","53048"
"*net user HackMe /add*",".{0,1000}net\suser\sHackMe\s\/add.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","0","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","53049"
"*net user HackMe ozlq6qwm*",".{0,1000}net\suser\sHackMe\sozlq6qwm.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","0","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","53050"
"*net1 stop gupdatem*",".{0,1000}net1\sstop\sgupdatem.{0,1000}","greyware_tool_keyword","net","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53125"
"*Net-GPPPassword.cs*",".{0,1000}Net\-GPPPassword\.cs.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","53153"
"*Net-GPPPassword.exe*",".{0,1000}Net\-GPPPassword\.exe.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","53154"
"*Net-GPPPassword_dotNET*",".{0,1000}Net\-GPPPassword_dotNET.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","53155"
"*Net-GPPPassword-master*",".{0,1000}Net\-GPPPassword\-master.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","53156"
"*NETLMv2_fmt_plug.*",".{0,1000}NETLMv2_fmt_plug\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53163"
"*netntlm.pl *",".{0,1000}netntlm\.pl\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53168"
"*NetNTLMtoSilverTicket.git*",".{0,1000}NetNTLMtoSilverTicket\.git.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","1","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","53169"
"*NetNTLMtoSilverTicket-master*",".{0,1000}NetNTLMtoSilverTicket\-master.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","1","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","53170"
"*netpass.exe*",".{0,1000}netpass\.exe.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53171"
"*netpass.zip*",".{0,1000}netpass\.zip.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53172"
"*netpass_x64.exe*",".{0,1000}netpass_x64\.exe.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53173"
"*netpass-x64.zip*",".{0,1000}netpass\-x64\.zip.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53174"
"*netsh interface portproxy add v4tov4*listenaddress=* listenport=*connectaddress=*connectport*",".{0,1000}netsh\sinterface\sportproxy\sadd\sv4tov4.{0,1000}listenaddress\=.{0,1000}\slistenport\=.{0,1000}connectaddress\=.{0,1000}connectport.{0,1000}","greyware_tool_keyword","netsh","The actor has used the following commands to enable port forwarding [T1090] on the host","T1090.003 - T1123","TA0005 - TA0002","N/A","Volt Typhoon - Naikon - APT32 - Magic Hound - Lazarus Group - Carbanak - Dragonfly","Credential Access","https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","53200"
"*netsh wlan show profile $wlan key=clear | Select-String *?<=Key Content\s+:\s*",".{0,1000}netsh\swlan\sshow\sprofile\s\$wlan\skey\=clear\s\|\sSelect\-String\s.{0,1000}\?\<\=Key\sContent\\s\+\:\\s.{0,1000}","offensive_tool_keyword","WLAN-Windows-Passwords","Opens PowerShell hidden - grabs wlan passwords - saves as a cleartext in a variable and exfiltrates info via Discord Webhook.","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/WLAN-Windows-Passwords","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","53206"
"*netsh wlan show profiles *key=clear*",".{0,1000}netsh\swlan\sshow\sprofiles\skey\=clear.{0,1000}","greyware_tool_keyword","netsh","display saved Wi-Fi profiles including plaintext passwords on a Windows system","T1003 - T1552.001","TA0006 - TA0009","N/A","Volt Typhoon - Naikon - APT32 - Magic Hound - Lazarus Group - Carbanak - Dragonfly","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53207"
"*netsh.exe interface ip delete arpcache >C:\Windows\TEMP\ipconfig.out 2>&1*",".{0,1000}netsh\.exe\sinterface\sip\sdelete\sarpcache\s\>C\:\\Windows\\TEMP\\ipconfig\.out\s2\>\&1.{0,1000}","offensive_tool_keyword","KerberOPSEC","OPSEC safe Kerberoasting in C#","T1558.003","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/Luct0r/KerberOPSEC","1","0","N/A","N/A","10","2","191","21","2022-06-14T18:10:25Z","2022-01-07T17:20:40Z","53212"
"*netsh.exe wlan show profiles key=clear*",".{0,1000}netsh\.exe\swlan\sshow\sprofiles\skey\=clear.{0,1000}","greyware_tool_keyword","netsh","display saved Wi-Fi profiles including plaintext passwords on a Windows system","T1003 - T1552.001","TA0006 - TA0009","N/A","Volt Typhoon - Naikon - APT32 - Magic Hound - Lazarus Group - Carbanak - Dragonfly","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53214"
"*NetSPI/Powershell-Modules*",".{0,1000}NetSPI\/Powershell\-Modules.{0,1000}","offensive_tool_keyword","PowerUpSQL","NetSPI powershell modules to gather credentials","T1552.001 - T1555.004 - T1003","TA0006 - TA0009 - TA0010","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/NetSPI/Powershell-Modules","1","1","N/A","N/A","10","2","168","101","2019-06-06T15:54:47Z","2014-02-28T21:24:21Z","53219"
"*nettitude/ETWHash*",".{0,1000}nettitude\/ETWHash.{0,1000}","offensive_tool_keyword","ETWHash","C# POC to extract NetNTLMv1/v2 hashes from ETW provider","T1556.001","TA0009 ","N/A","N/A","Credential Access","https://github.com/nettitude/ETWHash","1","1","N/A","N/A","N/A","3","256","29","2023-05-10T06:45:06Z","2023-04-26T15:53:01Z","53236"
"*Netwedx765ork\\Cookedx765ies*",".{0,1000}Netwedx765ork\\\\Cookedx765ies.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","53241"
"*Network Password Recovery v*",".{0,1000}Network\sPassword\sRecovery\sv.{0,1000}","offensive_tool_keyword","netpass","When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password.","T1081 - T1003 - T1555","TA0006 - TA0009","N/A","Kimsuky - XDSpy - TRAVELING SPIDER","Credential Access","https://www.nirsoft.net/utils/network_password_recovery.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53242"
"*network2john.lua*",".{0,1000}network2john\.lua.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53243"
"*New credentials found for user * on *",".{0,1000}New\scredentials\sfound\sfor\suser\s.{0,1000}\son\s.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","N/A","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","53251"
"*New password cracked! MTLM: *",".{0,1000}New\spassword\scracked!\sMTLM\:\s.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","53252"
"*-nh 127.0.0.1 -nP 7687 -nu neo4j -np *",".{0,1000}\-nh\s127\.0\.0\.1\s\-nP\s7687\s\-nu\sneo4j\s\-np\s.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","0","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","53325"
"*NiceRAT | * Stealer*",".{0,1000}NiceRAT\s\|\s.{0,1000}\s\sStealer.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","53331"
"*NiceRAT-main.zip*",".{0,1000}NiceRAT\-main\.zip.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","53332"
"*nickzer0/RagingRotator*",".{0,1000}nickzer0\/RagingRotator.{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","1","N/A","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","53336"
"*nIFS=* read -s pass\necho -e *User=*$(whoami)*Password=*$pass*> /var/tmp*",".{0,1000}nIFS\=.{0,1000}\sread\s\-s\spass\\necho\s\-e\s.{0,1000}User\=.{0,1000}\$\(whoami\).{0,1000}Password\=.{0,1000}\$pass.{0,1000}\>\s\/var\/tmp.{0,1000}","offensive_tool_keyword","sudoSnatch","sudoSnatch payload grabs sudo password in plain text and imediately after target uses sudo command and sends it back to attacker remotely/locally.","T1552.001 - T1056.001 - T1071.001","TA0006 - TA0004 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SudoSnatch","1","0","#linux","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","53388"
"*NirPassView (PUA)*",".{0,1000}NirPassView\s\(PUA\).{0,1000}","signature_keyword","bulletpassview","BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file.","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/bullets_password_view.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","53434"
"*Nirsoft PasswordFox (PUA)*",".{0,1000}Nirsoft\sPasswordFox\s\(PUA\).{0,1000}","signature_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","53435"
"*nkbihfbeogaeaoehlefnkodbefgpgknn*",".{0,1000}nkbihfbeogaeaoehlefnkodbefgpgknn.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","53452"
"*nkddgncdjgjfcddamfgcmfnlhccnimig*",".{0,1000}nkddgncdjgjfcddamfgcmfnlhccnimig.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","53453"
"*nlbmnnijcnlegkjjpcfjclmcfggfefdm*",".{0,1000}nlbmnnijcnlegkjjpcfjclmcfggfefdm.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","53455"
"*nmap -T3 -sT -Pn -n --open -p135 -oG -*",".{0,1000}nmap\s\-T3\s\-sT\s\-Pn\s\-n\s\-\-open\s\-p135\s\-oG\s\-.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","53475"
"*nmap/ncrack*",".{0,1000}nmap\/ncrack.{0,1000}","offensive_tool_keyword","ncrack","High-speed network authentication cracking tool.","T1110.001 - T1110.002 - T1110.003","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/nmap/ncrack","1","1","N/A","N/A","N/A","10","1123","250","2024-04-14T21:37:48Z","2015-12-21T23:48:00Z","53477"
"*No cached domain password found!*",".{0,1000}No\scached\sdomain\spassword\sfound!.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","0","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","53485"
"*No pwnable targets. Quitting.*",".{0,1000}No\spwnable\stargets\.\sQuitting\..{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","53488"
"*NoFault\NoFault.*",".{0,1000}NoFault\\NoFault\..{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","53511"
"*noseyparker report --datastore *",".{0,1000}noseyparker\sreport\s\-\-datastore\s.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","0","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53563"
"*noseyparker scan --datastore *",".{0,1000}noseyparker\sscan\s\-\-datastore\s.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","0","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53564"
"*noseyparker summarize --datastore *",".{0,1000}noseyparker\ssummarize\s\-\-datastore\s.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","0","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53565"
"*noseyparker-cli*",".{0,1000}noseyparker\-cli.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53566"
"*noseyparker-main*",".{0,1000}noseyparker\-main.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53567"
"*noseyparker-v*-universal-macos*",".{0,1000}noseyparker\-v.{0,1000}\-universal\-macos.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53568"
"*noseyparker-v*-x86_64-unknown-linux-gnu*",".{0,1000}noseyparker\-v.{0,1000}\-x86_64\-unknown\-linux\-gnu.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","#linux","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","53569"
"*NotLSASS.zip*",".{0,1000}NotLSASS\.zip.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","53577"
"*NotLSASS1.zip*",".{0,1000}NotLSASS1\.zip.{0,1000}","offensive_tool_keyword","MirrorDump","LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory","T1003 - T1055 - T1574","TA0006 - TA0005 - TA0003","N/A","N/A","Credential Access","https://github.com/CCob/MirrorDump","1","0","N/A","N/A","10","3","265","58","2021-03-18T18:19:00Z","2021-03-18T18:18:56Z","53578"
"*notsoshant/DCSyncer*",".{0,1000}notsoshant\/DCSyncer.{0,1000}","offensive_tool_keyword","DCSyncer","Perform DCSync operation","T1003.006","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/notsoshant/DCSyncer","1","1","N/A","N/A","10","2","143","22","2024-11-05T20:03:27Z","2020-06-06T17:20:22Z","53582"
"*novelbfh.zip*",".{0,1000}novelbfh\.zip.{0,1000}","offensive_tool_keyword","novelbfh","Brute force Novell hacking tool -- Circa 1993","T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/classic_hacking_tools","1","1","N/A","N/A","N/A","1","4","1","2024-06-27T09:35:42Z","2023-04-16T01:49:12Z","53586"
"*NSAKEY/nsa-rules*",".{0,1000}NSAKEY\/nsa\-rules.{0,1000}","offensive_tool_keyword","nsa-rules","Password cracking rules and masks for hashcat that I generated from cracked passwords.","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/NSAKEY/nsa-rules","1","1","N/A","N/A","10","6","547","125","2017-01-03T11:53:25Z","2016-02-15T20:49:32Z","53610"
"*nsa-rules-master*",".{0,1000}nsa\-rules\-master.{0,1000}","offensive_tool_keyword","nsa-rules","Password cracking rules and masks for hashcat that I generated from cracked passwords.","T1110.002 - T1021.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/NSAKEY/nsa-rules","1","1","N/A","N/A","10","6","547","125","2017-01-03T11:53:25Z","2016-02-15T20:49:32Z","53611"
"*nselib/data/passwords.lst*",".{0,1000}nselib\/data\/passwords\.lst.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","53616"
"*ntdissector -*",".{0,1000}ntdissector\s\-.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","0","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","53625"
"*ntdissector-main*",".{0,1000}ntdissector\-main.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","1","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","53626"
"*ntds/ntds.py*",".{0,1000}ntds\/ntds\.py.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","0","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","53637"
"*NTDSHashes.dump*",".{0,1000}NTDSHashes\.dump.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","53641"
"*ntdsutil ""ac in ntds"" roles*",".{0,1000}ntdsutil\s\""ac\sin\sntds\""\sroles.{0,1000}","greyware_tool_keyword","ntdsutil","Misuse of this command could indicate an attempt to transfer or seize FSMO roles which are critical for Active Directory operations","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53642"
"*ntdsutil ""activate instance ntds"" authoritative restore*",".{0,1000}ntdsutil\s\""activate\sinstance\sntds\""\sauthoritative\srestore.{0,1000}","greyware_tool_keyword","ntdsutil","An attacker could use this to revert changes in AD for persistence","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53643"
"*ntdsutil *activate instance ntds* ifm*",".{0,1000}ntdsutil\s.{0,1000}activate\sinstance\sntds.{0,1000}\sifm.{0,1000}","greyware_tool_keyword","ntdsutil","create an installation media set from the NTDS database (Install From Media). This could be abused to exfiltrate the Active Directory database for offline attacks or manipulation.","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53644"
"*ntdsutil \""ac i ntds\""*",".{0,1000}ntdsutil\s\\\""ac\si\sntds\\\"".{0,1000}","greyware_tool_keyword","ntdsutil","Misuse of this command could indicate an attempt to transfer or seize FSMO roles which are critical for Active Directory operations","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53645"
"*ntdsutil files*",".{0,1000}ntdsutil\sfiles.{0,1000}","greyware_tool_keyword","ntdsutil","An attacker might use this command to manipulate or inspect the AD database files","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53646"
"*ntdsutil metadata cleanup*",".{0,1000}ntdsutil\smetadata\scleanup.{0,1000}","greyware_tool_keyword","ntdsutil","could indicate an attempt to manipulate the directory's metadata","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53647"
"*ntdsutil partition management*",".{0,1000}ntdsutil\spartition\smanagement.{0,1000}","greyware_tool_keyword","ntdsutil","Attackers could abuse this to manipulate directory partitions","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53648"
"*ntdsutil snapshot*",".{0,1000}ntdsutil\ssnapshot.{0,1000}","greyware_tool_keyword","ntdsutil","Snapshots contain a copy of the AD database and attackers may use it to obtain sensitive information","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53649"
"*ntdsutil.exe *ac i ntds* *ifm* *create full *c:\ProgramData*",".{0,1000}ntdsutil\.exe\s.{0,1000}ac\si\sntds.{0,1000}\s.{0,1000}ifm.{0,1000}\s.{0,1000}create\sfull\s.{0,1000}c\:\\ProgramData.{0,1000}","greyware_tool_keyword","ntdsutil","creating a full backup of the Active Directory database and saving it to the \temp directory","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53650"
"*ntdsutil.exe *ac i ntds* *ifm* *create full *users\public*",".{0,1000}ntdsutil\.exe\s.{0,1000}ac\si\sntds.{0,1000}\s.{0,1000}ifm.{0,1000}\s.{0,1000}create\sfull\s.{0,1000}users\\public.{0,1000}","greyware_tool_keyword","ntdsutil","creating a full backup of the Active Directory database and saving it to the \temp directory","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53651"
"*ntdsutil.exe *ac i ntds*ifm*create full *temp*",".{0,1000}ntdsutil\.exe\s.{0,1000}ac\si\sntds.{0,1000}ifm.{0,1000}create\sfull\s.{0,1000}temp.{0,1000}","greyware_tool_keyword","ntdsutil","creating a full backup of the Active Directory database and saving it to the \temp directory","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","53652"
"*NTHASH /enumproc *",".{0,1000}NTHASH\s\/enumproc\s.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53655"
"*NTHASH /runas *",".{0,1000}NTHASH\s\/runas\s.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53656"
"*NTHASH /runaschild /pid*",".{0,1000}NTHASH\s\/runaschild\s\/pid.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53657"
"*NTHASH /runastoken *",".{0,1000}NTHASH\s\/runastoken\s.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53658"
"*NTHASH /runwmi *",".{0,1000}NTHASH\s\/runwmi\s.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53659"
"*NTHASH* /cryptunprotectdata /binary:*",".{0,1000}NTHASH.{0,1000}\s\/cryptunprotectdata\s\/binary\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53660"
"*NTHASH* /cryptunprotectdata /input:*",".{0,1000}NTHASH.{0,1000}\s\/cryptunprotectdata\s\/input\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53661"
"*NTHASH* /dumpsam*",".{0,1000}NTHASH.{0,1000}\s\/dumpsam.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53662"
"*NTHASH* /enumcred*",".{0,1000}NTHASH.{0,1000}\s\/enumcred.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53663"
"*NTHASH* /enumvault*",".{0,1000}NTHASH.{0,1000}\s\/enumvault.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53664"
"*NTHASH* /getlsakeys*",".{0,1000}NTHASH.{0,1000}\s\/getlsakeys.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53665"
"*NTHASH* /wlansvc /binary:*",".{0,1000}NTHASH.{0,1000}\s\/wlansvc\s\/binary\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53666"
"*NTHASH-win32.exe*",".{0,1000}NTHASH\-win32\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53667"
"*NTHASH-win64.exe*",".{0,1000}NTHASH\-win64\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53668"
"*NTLM credentials successfully changed!*",".{0,1000}NTLM\scredentials\ssuccessfully\schanged!.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","53669"
"*NTLM credentials successfully deleted!*",".{0,1000}NTLM\scredentials\ssuccessfully\sdeleted!.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","53670"
"*NTLM TlRMTVNTUAACAAAABgAGADgAAAAFAomiESIzRFVmd4gAAAAAAAAAAIAAgAA+AAAABQLODgAAAA9TAE0AQgACAAYAUwBNAEIAAQAWAFMATQBCAC0AVABPAE8ATABLAEkAVAAEABIAcwBtAGIALgBsAG8AYwBhAGwAAwAoAHMAZQByAHYAZQByADIAMAAwADMALgBzAG0AYgAuAGwAbwBjAGEAbAAFABIAcwBtAGIALgBsAG8AYwBhAGwAAAAAAA==*",".{0,1000}NTLM\sTlRMTVNTUAACAAAABgAGADgAAAAFAomiESIzRFVmd4gAAAAAAAAAAIAAgAA\+AAAABQLODgAAAA9TAE0AQgACAAYAUwBNAEIAAQAWAFMATQBCAC0AVABPAE8ATABLAEkAVAAEABIAcwBtAGIALgBsAG8AYwBhAGwAAwAoAHMAZQByAHYAZQByADIAMAAwADMALgBzAG0AYgAuAGwAbwBjAGEAbAAFABIAcwBtAGIALgBsAG8AYwBhAGwAAAAAAA\=\=.{0,1000}","offensive_tool_keyword","Get-NetNTLM","Powershell module to get the NetNTLMv2 hash of the current user","T1110.003 - T1557.001 - T1040","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/elnerd/Get-NetNTLM","1","0","#content","N/A","7","1","93","18","2022-07-05T20:55:33Z","2019-02-11T23:09:54Z","53671"
"*ntlmdecoder.py*",".{0,1000}ntlmdecoder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","53675"
"*ntlm-info.py*",".{0,1000}ntlm\-info\.py.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","53677"
"*NTLMInjector.ps1*",".{0,1000}NTLMInjector\.ps1.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","1","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","53678"
"*ntlmRelayToEWS -*",".{0,1000}ntlmRelayToEWS\s\-.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","0","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","53689"
"*ntlmRelayToEWS.py*",".{0,1000}ntlmRelayToEWS\.py.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","53690"
"*NtlmRelayToEWS-master*",".{0,1000}NtlmRelayToEWS\-master.{0,1000}","offensive_tool_keyword","NtlmRelayToEWS","ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)","T1212 - T1557 - T1040 - T1078","TA0008 - TA0006","N/A","N/A","Credential Access","https://github.com/Arno0x/NtlmRelayToEWS","1","1","N/A","N/A","10","4","331","60","2018-01-15T12:48:02Z","2017-10-13T18:00:50Z","53691"
"*ntlmrelayx.py*",".{0,1000}ntlmrelayx\.py.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","1","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","53697"
"*ntlmrelayx.py.log*",".{0,1000}ntlmrelayx\.py\.log.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","53700"
"*NTLMSleuth.ps1*",".{0,1000}NTLMSleuth\.ps1.{0,1000}","offensive_tool_keyword","NTLMSleuth","verify NTLM hash integrity against the robust database of ntlm.pw.","T1003 - T1555","TA0006","N/A","Black Basta","Credential Access","https://github.com/jmarr73/NTLMSleuth","1","1","N/A","N/A","8","1","8","0","2024-08-28T15:21:10Z","2023-12-12T16:41:35Z","53705"
"*NTLMSleuth.sh*",".{0,1000}NTLMSleuth\.sh.{0,1000}","offensive_tool_keyword","NTLMSleuth","verify NTLM hash integrity against the robust database of ntlm.pw.","T1003 - T1555","TA0006","N/A","Black Basta","Credential Access","https://github.com/jmarr73/NTLMSleuth","1","1","N/A","N/A","8","1","8","0","2024-08-28T15:21:10Z","2023-12-12T16:41:35Z","53706"
"*NtlmThief.exe*",".{0,1000}NtlmThief\.exe.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","53707"
"*NtlmThief.sln*",".{0,1000}NtlmThief\.sln.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","53708"
"*NtlmThief.vcxproj*",".{0,1000}NtlmThief\.vcxproj.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","53709"
"*NtlmThief-main*",".{0,1000}NtlmThief\-main.{0,1000}","offensive_tool_keyword","NtlmThief","Extracting NetNTLM without touching lsass.exe","T1558.003 - T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/MzHmO/NtlmThief","1","1","N/A","N/A","10","3","235","33","2023-11-27T14:50:10Z","2023-11-26T08:14:50Z","53710"
"*ntlmv1.py --ntlmv1 *::*",".{0,1000}ntlmv1\.py\s\-\-ntlmv1\s.{0,1000}\:\:.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","53711"
"*ntlmv1.py*",".{0,1000}ntlmv1\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","53712"
"*nuitka --onefile barrel.py*",".{0,1000}nuitka\s\-\-onefile\sbarrel\.py.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","53741"
"*nuitka --onefile lock.py*",".{0,1000}nuitka\s\-\-onefile\slock\.py.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","53742"
"*nuitka --onefile shock.py*",".{0,1000}nuitka\s\-\-onefile\sshock\.py.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","53743"
"*nyxgeek/lyncsmash*",".{0,1000}nyxgeek\/lyncsmash.{0,1000}","offensive_tool_keyword","lyncsmash","a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","N/A","N/A","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","53776"
"*O365 Enumeration via ActiveSync module --*",".{0,1000}O365\sEnumeration\svia\sActiveSync\smodule\s\-\-.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","53785"
"*O365 Enumeration via Office.com module --*",".{0,1000}O365\sEnumeration\svia\sOffice\.com\smodule\s\-\-.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","53786"
"*O365 Enumeration via OneDrive module --*",".{0,1000}O365\sEnumeration\svia\sOneDrive\smodule\s\-\-.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","53787"
"*O365 Spraying via ActiveSync module --*",".{0,1000}O365\sSpraying\svia\sActiveSync\smodule\s\-\-.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","53788"
"*O365 Spraying via ADFS module --*",".{0,1000}O365\sSpraying\svia\sADFS\smodule\s\-\-.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","53789"
"*O365 Spraying via MSOL module --*",".{0,1000}O365\sSpraying\svia\sMSOL\smodule\s\-\-.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","53790"
"*o365-attack-toolkit*",".{0,1000}o365\-attack\-toolkit.{0,1000}","offensive_tool_keyword","o365-attack-toolkit","A toolkit to attack Office365","T1110 - T1114 - T1119 - T1197 - T1087.002","TA0001 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/mdsecactivebreach/o365-attack-toolkit","1","1","N/A","N/A","10","10","1068","217","2020-11-06T12:09:26Z","2019-07-22T10:39:46Z","53792"
"*o365enum.py*",".{0,1000}o365enum\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","53796"
"*o365spray --enum *",".{0,1000}o365spray\s\-\-enum\s.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","53801"
"*o365spray --spray *",".{0,1000}o365spray\s\-\-spray\s.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","53802"
"*o365spray --validate*",".{0,1000}o365spray\s\-\-validate.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","N/A","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","53803"
"*o365spray.core.handlers.sprayer*",".{0,1000}o365spray\.core\.handlers\.sprayer.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","#content","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","53804"
"*Offensive-Panda/LsassReflectDumping*",".{0,1000}Offensive\-Panda\/LsassReflectDumping.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","1","N/A","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","53844"
"*Offensive-Panda/ShadowDumper/*",".{0,1000}Offensive\-Panda\/ShadowDumper\/.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","1","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","53845"
"*office2john.py*",".{0,1000}office2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53847"
"*Offline SAM Editing Tool - Changed*",".{0,1000}Offline\sSAM\sEditing\sTool\s\-\sChanged.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53850"
"*Offline SAM Editing Tool*",".{0,1000}Offline\sSAM\sEditing\sTool.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53851"
"*Offline SAM loaded successfully*",".{0,1000}Offline\sSAM\sloaded\ssuccessfully.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53852"
"*Offline SAM Tool\r\nUse with caution!*",".{0,1000}Offline\sSAM\sTool\\r\\nUse\swith\scaution!.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53853"
"*offlinereg-win32.exe*",".{0,1000}offlinereg\-win32\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53856"
"*offlinereg-win64.exe*",".{0,1000}offlinereg\-win64\.exe.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","1","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","53857"
"*oh365userfinder.py*",".{0,1000}oh365userfinder\.py.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","N/A","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","53866"
"*ojggmchlghnjlapmfbnjholfjkiidbch*",".{0,1000}ojggmchlghnjlapmfbnjholfjkiidbch.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","53876"
"*Okta-Password-Sprayer*",".{0,1000}Okta\-Password\-Sprayer.{0,1000}","offensive_tool_keyword","Okta-Password-Sprayer","This script is a multi-threaded Okta password sprayer.","T1110 - T1110.003 - T1621","TA0006","N/A","N/A","Credential Access","https://github.com/Rhynorater/Okta-Password-Sprayer","1","1","N/A","N/A","10","1","70","16","2024-01-05T16:24:38Z","2018-09-24T23:39:16Z","53877"
"*-OMG-Credz-Plz*",".{0,1000}\-OMG\-Credz\-Plz.{0,1000}","offensive_tool_keyword","OMG-Credz-Plz","A script used to prompt the target to enter their creds to later be exfiltrated with dropbox.","T1056.002 - T1566.001 - T1567.002","TA0004 - TA0040 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/-OMG-Credz-Plz","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","53887"
"*OMGdump.zip*",".{0,1000}OMGdump\.zip.{0,1000}","offensive_tool_keyword","SamDumpCable","Dump users sam and system hive and exfiltrate them","T1003.002 - T1564.001","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SamDumpCable","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","53888"
"*OMGLoggerDecoder*",".{0,1000}OMGLoggerDecoder.{0,1000}","offensive_tool_keyword","OMGLogger","Key logger which sends each and every key stroke of target remotely/locally.","T1056.001 - T1562.001","TA0004 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/OMGLogger","1","1","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","53890"
"*Omnispray | Modular Enumeration and Password Spraying Framework*",".{0,1000}Omnispray\s\|\sModular\sEnumeration\sand\sPassword\sSpraying\sFramework.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","53894"
"*OmriBaso/BesoToken*",".{0,1000}OmriBaso\/BesoToken.{0,1000}","offensive_tool_keyword","BesoToken","A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).","T1134 - T1003.002","TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/OmriBaso/BesoToken","1","1","N/A","N/A","10","1","93","14","2022-11-23T10:45:07Z","2022-11-21T01:07:51Z","53895"
"*onedrive_enum.py*",".{0,1000}onedrive_enum\.py.{0,1000}","offensive_tool_keyword","onedrive_user_enum","enumerate valid onedrive users","T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/onedrive_user_enum","1","1","N/A","network exploitation tool","N/A","7","663","83","2025-04-17T00:13:11Z","2019-03-05T08:54:38Z","53903"
"*onedrive_user_enum.git*",".{0,1000}onedrive_user_enum\.git.{0,1000}","offensive_tool_keyword","onedrive_user_enum","enumerate valid onedrive users","T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/onedrive_user_enum","1","1","N/A","network exploitation tool","N/A","7","663","83","2025-04-17T00:13:11Z","2019-03-05T08:54:38Z","53906"
"*online_brute.gz.torrent*",".{0,1000}online_brute\.gz\.torrent.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","53926"
"*ookjlbkiijinhpmnjffcofjonbfbgaoc*",".{0,1000}ookjlbkiijinhpmnjffcofjonbfbgaoc.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","53929"
"*opcgpfmipidbgpenhmajoajpbobppdil*",".{0,1000}opcgpfmipidbgpenhmajoajpbobppdil.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","53931"
"*Opedx765era Neoedx765n\\Usedx765er Daedx765ta*",".{0,1000}Opedx765era\sNeoedx765n\\\\Usedx765er\sDaedx765ta.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","53932"
"*Opedx765era Softwedx765are\\Opedx765era GX Staedx765ble*",".{0,1000}Opedx765era\sSoftwedx765are\\\\Opedx765era\sGX\sStaedx765ble.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","53933"
"*Opeedx765ra Softedx765ware\\Opedx765era Staedx765ble*",".{0,1000}Opeedx765ra\sSoftedx765ware\\\\Opedx765era\sStaedx765ble.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","53934"
"*Open Source Developer, Grzegorz Tworek*",".{0,1000}Open\sSource\sDeveloper,\sGrzegorz\sTworek.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53935"
"*openbsd_softraid2john.py*",".{0,1000}openbsd_softraid2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53942"
"*openChromeDumpsHTML.exe*",".{0,1000}openChromeDumpsHTML\.exe.{0,1000}","offensive_tool_keyword","OpenChromeDumps","OpenChrome Dump used with GrabChrome for credential access","T1003 - T1555 - T1081 - T1552","TA0006","N/A","Yanluowang - Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53961"
"*openssl2john.py*",".{0,1000}openssl2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53974"
"*openwall.John.appdata.xml*",".{0,1000}openwall\.John\.appdata\.xml.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53978"
"*openwall.John.desktop*",".{0,1000}openwall\.John\.desktop.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53979"
"*openwall/john*",".{0,1000}openwall\/john.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","53980"
"*OperaPassView.exe*",".{0,1000}OperaPassView\.exe.{0,1000}","offensive_tool_keyword","OperaPassView","OperaPassView is a small password recovery tool that decrypts the content of the Opera Web browser password file (wand.dat) and displays the list of all Web site passwords stored in this file","T1003 - T1555 - T1145","TA0006 - TA0009","N/A","BlackSuit - Royal - GoGoogle - XDSpy","Credential Access","https://www.nirsoft.net/utils/opera_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","53985"
"*ophcrack*",".{0,1000}ophcrack.{0,1000}","offensive_tool_keyword","ophcrack","Windows password cracker based on rainbow tables.","T1110.003 - T1555.003 - T1110.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://gitlab.com/objectifsecurite/ophcrack","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","53988"
"*options.bruteforced_protocol*",".{0,1000}options\.bruteforced_protocol.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","53990"
"*Options.shadowCredCertificatePassword*",".{0,1000}Options\.shadowCredCertificatePassword.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#content","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","53991"
"*Orange-Cyberdefense/KeePwn*",".{0,1000}Orange\-Cyberdefense\/KeePwn.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","54005"
"*Orange-Cyberdefense/KeePwn*",".{0,1000}Orange\-Cyberdefense\/KeePwn.{0,1000}","offensive_tool_keyword","KeePwn","A python tool to automate KeePass discovery and secret extraction","T1555 - T1003 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Orange-Cyberdefense/KeePwn","1","1","N/A","N/A","10","5","486","47","2024-12-12T12:47:07Z","2023-01-27T13:59:38Z","54006"
"*Outflank-Dumpert*",".{0,1000}Outflank\-Dumpert.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","54053"
"*outflanknl/Dumpert*",".{0,1000}outflanknl\/Dumpert.{0,1000}","offensive_tool_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","1","N/A","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","54055"
"*outflanknl/Net-GPPPassword*",".{0,1000}outflanknl\/Net\-GPPPassword.{0,1000}","offensive_tool_keyword","Net-GPPPassword",".NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences.","T1059.001 - T1552.007","TA0002 - TA0006","N/A","N/A","Credential Access","https://github.com/outflanknl/Net-GPPPassword","1","1","N/A","N/A","10","2","172","36","2019-12-18T10:14:32Z","2019-10-14T12:35:46Z","54057"
"*OutlookEmailAbuse.ps1*",".{0,1000}OutlookEmailAbuse\.ps1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","54066"
"*output*-lsass.dmp*",".{0,1000}output.{0,1000}\-lsass\.dmp.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","54233"
"*OutputTokens.txt --onedrive --owa*",".{0,1000}OutputTokens\.txt\s\-\-onedrive\s\-\-owa.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","54273"
"*owa */autodiscover/autodiscover.xml* --recon*",".{0,1000}owa\s.{0,1000}\/autodiscover\/autodiscover\.xml.{0,1000}\s\-\-recon.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","54277"
"*OWA Enumeration via ActiveSync timing module --*",".{0,1000}OWA\sEnumeration\svia\sActiveSync\stiming\smodule\s\-\-.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","54278"
"*OWA Spraying via ActiveSync module --*",".{0,1000}OWA\sSpraying\svia\sActiveSync\smodule\s\-\-.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","54279"
"*Ox-Bruter.pl*",".{0,1000}Ox\-Bruter\.pl.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://raw.githubusercontent.com/Sup3r-Us3r/scripts/master/fb-brute.pl","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","54282"
"*P@ss4Hagrid29*",".{0,1000}P\@ss4Hagrid29.{0,1000}","offensive_tool_keyword","DumpAADSyncCreds","C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.","T1555 - T1110","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Hagrid29/DumpAADSyncCreds","1","0","N/A","N/A","10","1","39","3","2023-06-24T16:17:36Z","2022-03-27T18:43:44Z","54285"
"*p0dalirius/ExtractBitlockerKeys*",".{0,1000}p0dalirius\/ExtractBitlockerKeys.{0,1000}","offensive_tool_keyword","ExtractBitlockerKeys","A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.","T1003.002 - T1039 - T1087.002","TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/p0dalirius/ExtractBitlockerKeys","1","1","N/A","N/A","10","4","368","54","2025-01-31T09:39:55Z","2023-09-19T07:28:11Z","54288"
"*p0dalirius/LDAPWordlistHarvester*",".{0,1000}p0dalirius\/LDAPWordlistHarvester.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","1","N/A","N/A","5","","N/A","","","","54289"
"*p0dalirius/pyLAPS*",".{0,1000}p0dalirius\/pyLAPS.{0,1000}","offensive_tool_keyword","pyLAPS","A simple way to read and write LAPS passwords from linux.","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/p0dalirius/pyLAPS","1","1","#linux","N/A","9","2","105","16","2024-10-28T08:36:38Z","2021-10-05T18:35:21Z","54290"
"*PacketSnifferClass1*",".{0,1000}PacketSnifferClass1.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54351"
"*pacman -S hekatomb*",".{0,1000}pacman\s\-S\shekatomb.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","N/A","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","54355"
"*padlock2john.py*",".{0,1000}padlock2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54372"
"*pamspy: Failed to increase RLIMIT_MEMLOCK limit!*",".{0,1000}pamspy\:\sFailed\sto\sincrease\sRLIMIT_MEMLOCK\slimit!.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#linux #content","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","54391"
"*pamspy: Failed to load BPF program: *",".{0,1000}pamspy\:\sFailed\sto\sload\sBPF\sprogram\:\s.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#linux #content","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","54392"
"*pamspy: Unable to find pam_get_authtok function in*",".{0,1000}pamspy\:\sUnable\sto\sfind\spam_get_authtok\sfunction\sin.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#linux #content","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","54393"
"*parse_nessus_file*",".{0,1000}parse_nessus_file.{0,1000}","offensive_tool_keyword","crackmapexec","function name from nessus.py from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","54408"
"*parse_nmap_xml*",".{0,1000}parse_nmap_xml.{0,1000}","offensive_tool_keyword","crackmapexec","function name from nmap.py from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","54409"
"*parser.exe -a *.dmp*",".{0,1000}parser\.exe\s\-a\s.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","udmp-parser","A Cross-Platform C++ parser library for Windows user minidumps.","T1005 - T1059.003 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/0vercl0k/udmp-parser","1","0","N/A","N/A","6","3","202","23","2024-11-20T15:58:21Z","2022-01-30T18:56:21Z","54414"
"*parser.exe -a *.dmp*",".{0,1000}parser\.exe\s\-a\s.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","udmp-parser","A Cross-Platform C++ parser library for Windows user minidumps.","T1005 - T1059.003 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/0vercl0k/udmp-parser","1","0","N/A","N/A","6","3","202","23","2024-11-20T15:58:21Z","2022-01-30T18:56:21Z","54415"
"*PassDetective extract*",".{0,1000}PassDetective\sextract.{0,1000}","offensive_tool_keyword","PassDetective","PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets","T1059 - T1059.004 - T1552 - T1552.001","TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/aydinnyunus/PassDetective","1","0","N/A","N/A","7","2","129","8","2024-06-19T10:39:39Z","2023-07-22T12:31:57Z","54416"
"*PassDetective-main.*",".{0,1000}PassDetective\-main\..{0,1000}","offensive_tool_keyword","PassDetective","PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets","T1059 - T1059.004 - T1552 - T1552.001","TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/aydinnyunus/PassDetective","1","1","N/A","N/A","7","2","129","8","2024-06-19T10:39:39Z","2023-07-22T12:31:57Z","54417"
"*passphrase-rule1.rule*",".{0,1000}passphrase\-rule1\.rule.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54423"
"*passphrase-rule2.rule*",".{0,1000}passphrase\-rule2\.rule.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54424"
"*passphrase-wordlist*",".{0,1000}passphrase\-wordlist.{0,1000}","offensive_tool_keyword","passphrase-wordlist","This project includes a massive wordlist of phrases (over 20 million) and two hashcat rule files for GPU-based cracking. The rules will create over 1.000 permutations of each phase.","T1003 - T1110 - T1113 - T1137","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/initstring/passphrase-wordlist","1","0","N/A","N/A","N/A","10","1297","173","2025-04-12T07:58:51Z","2017-12-05T20:53:13Z","54425"
"*PassSpray: Valid Credentials Obtained!*",".{0,1000}PassSpray\:\sValid\sCredentials\sObtained!.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","0","#content","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","54427"
"*passthehashbrowns/SharpRDPThief*",".{0,1000}passthehashbrowns\/SharpRDPThief.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","0","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","54442"
"*passware-kit-forensic.sls*",".{0,1000}passware\-kit\-forensic\.sls.{0,1000}","offensive_tool_keyword","Passware Kit Forensic","Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.passware.com/kit-forensic/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54443"
"*PasswareKitForensic_*_Setup.dmg*",".{0,1000}PasswareKitForensic_.{0,1000}_Setup\.dmg.{0,1000}","offensive_tool_keyword","Passware Kit Forensic","Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.passware.com/kit-forensic/","1","1","#macos","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54444"
"*PasswareKitForensic_*_Setup.msi*",".{0,1000}PasswareKitForensic_.{0,1000}_Setup\.msi.{0,1000}","offensive_tool_keyword","Passware Kit Forensic","Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.passware.com/kit-forensic/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54445"
"*passware-kit-forensic-64bit.msi*",".{0,1000}passware\-kit\-forensic\-64bit\.msi.{0,1000}","offensive_tool_keyword","Passware Kit Forensic","Passware Kit Forensic is the complete encrypted electronic evidence discovery solution that reports and decrypts all password-protected items on a computer","T1003 - T1021 - T1056 - T1110 - T1212 - T1552","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.passware.com/kit-forensic/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","54446"
"*passwd*john*",".{0,1000}passwd.{0,1000}john.{0,1000}","greyware_tool_keyword","passwd","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","54447"
"*Password Spraying EAS at https://*",".{0,1000}Password\sSpraying\sEAS\sat\shttps\:\/\/.{0,1000}","offensive_tool_keyword","EASSniper","EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)","T1110 - T1078.003 - T1087.002 - T1059.001","TA0006 -TA0007 - TA0009 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/fugawi/EASSniper","1","0","N/A","N/A","10","1","5","4","2018-04-17T23:23:31Z","2018-04-17T22:43:51Z","54452"
"*Password spraying lockout policy reset time *",".{0,1000}Password\sspraying\slockout\spolicy\sreset\stime\s.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","54453"
"*Password spraying the following passwords: *",".{0,1000}Password\sspraying\sthe\sfollowing\spasswords\:\s.{0,1000}","offensive_tool_keyword","Omnispray","Modular Enumeration and Password Spraying Framework","T1110 - T1078.003 - T1087.002 - T1621","TA0001 - TA0002 - TA0006 - TA0007 - TA0009","N/A","N/A","Credential Access","https://github.com/0xZDH/Omnispray","1","0","N/A","N/A","10","2","118","19","2024-04-10T20:05:46Z","2021-02-25T07:28:06Z","54454"
"*Password spraying using paired usernames:passwords*",".{0,1000}Password\sspraying\susing\spaired\susernames\:passwords.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","#content","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","54455"
"*Password:Waza1234*",".{0,1000}Password\:Waza1234.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","0","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","54461"
"*password|pwd|creds|cred|secret|userpw*",".{0,1000}password\|pwd\|creds\|cred\|secret\|userpw.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","0","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","54468"
"*passwordfox.exe*",".{0,1000}passwordfox\.exe.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54472"
"*passwordfox.zip*",".{0,1000}passwordfox\.zip.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54473"
"*passwordfox-x64.zip*",".{0,1000}passwordfox\-x64\.zip.{0,1000}","offensive_tool_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54474"
"*PasswordHashesView.exe*",".{0,1000}PasswordHashesView\.exe.{0,1000}","offensive_tool_keyword","PasswordHashesView","displays the SHA1 hash and the NTLM hash of the login password for users currently logged into your system","T1003 - T1081","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/alpha/passwordhashesview-x64.zip","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","54475"
"*passwordhashesview.zip*",".{0,1000}passwordhashesview\.zip.{0,1000}","offensive_tool_keyword","PasswordHashesView","displays the SHA1 hash and the NTLM hash of the login password for users currently logged into your system","T1003 - T1081","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/alpha/passwordhashesview-x64.zip","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","54476"
"*passwordhashesview-x64.zip*",".{0,1000}passwordhashesview\-x64\.zip.{0,1000}","offensive_tool_keyword","PasswordHashesView","displays the SHA1 hash and the NTLM hash of the login password for users currently logged into your system","T1003 - T1081","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/alpha/passwordhashesview-x64.zip","1","1","N/A","N/A","10","9","N/A","N/A","N/A","N/A","54477"
"*Passwords stolen and saved successfully!*",".{0,1000}Passwords\sstolen\sand\ssaved\ssuccessfully!.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","N/A","10","","N/A","","","","54479"
"*Passwords to users complete. Please see cracked-users.txt*",".{0,1000}Passwords\sto\susers\scomplete\.\sPlease\ssee\scracked\-users\.txt.{0,1000}","offensive_tool_keyword","autoNTDS","autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat","T1003 - T1059 - T1021.002 - T1213","TA0006 - TA0008 - TA0005 - TA0002","N/A","N/A","Credential Access","https://github.com/hmaverickadams/autoNTDS","1","0","N/A","N/A","10","2","109","14","2023-10-31T22:03:58Z","2023-10-30T23:10:58Z","54480"
"*Password-Scripts*",".{0,1000}Password\-Scripts.{0,1000}","offensive_tool_keyword","Password-Scripts","Password Scripts xploitation ","T1210 - T1555 - T1110 - T1554 - T1553","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/laconicwolf/Password-Scripts","1","0","N/A","N/A","N/A","2","108","37","2019-10-08T17:57:49Z","2017-10-20T17:17:23Z","54483"
"*PasswordSpray *",".{0,1000}PasswordSpray\s.{0,1000}","offensive_tool_keyword","DomainPasswordSpray","DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!","t1110 - T1114 - T1555","TA0006 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/dafthack/DomainPasswordSpray","1","0","N/A","N/A","N/A","10","1865","388","2024-07-11T18:18:57Z","2016-10-04T23:37:37Z","54484"
"*passwordspray*--user-as-pass*",".{0,1000}passwordspray.{0,1000}\-\-user\-as\-pass.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","54485"
"*passwordspray.go*",".{0,1000}passwordspray\.go.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","54486"
"*passwordSprayCmd*",".{0,1000}passwordSprayCmd.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","54487"
"*patator*",".{0,1000}patator.{0,1000}","offensive_tool_keyword","patator","Patator was written out of frustration from using Hydra. Medusa. Ncrack. Metasploit modules and Nmap NSE scripts for password guessing attacks. I opted for a different approach in order to not create yet another brute-forcing tool and avoid repeating the same shortcomings. Patator is a multi-threaded tool written in Python. that strives to be more reliable and flexible than his fellow predecessors.","T1110 - T1111 - T1210 - T1558.004","TA0006 - TA0005","N/A","Dispossessor","Credential Access","https://github.com/lanjelot/patator","1","0","N/A","N/A","10","10","3704","808","2025-02-17T11:00:36Z","2014-08-25T00:56:21Z","54499"
"*pcap2john.py*",".{0,1000}pcap2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54571"
"*Pcredz -d *",".{0,1000}Pcredz\s\-d\s.{0,1000}","offensive_tool_keyword","Pcredz","This tool extracts Credit card numbers. NTLM(DCE-RPC. HTTP. SQL. LDAP. etc). Kerberos (AS-REQ Pre-Auth etype 23). HTTP Basic. SNMP. POP. SMTP. FTP. IMAP. etc from a pcap file or from a live interface.","T1116 - T1003 - T1002 - T1001 - T1005 - T1552","TA0003 - TA0002 - TA0011","N/A","N/A","Credential Access","https://github.com/lgandx/Pcredz","1","0","N/A","N/A","N/A","10","2100","413","2025-01-27T10:34:00Z","2014-04-07T02:03:33Z","54592"
"*Pcredz -f *",".{0,1000}Pcredz\s\-f\s.{0,1000}","offensive_tool_keyword","Pcredz","This tool extracts Credit card numbers. NTLM(DCE-RPC. HTTP. SQL. LDAP. etc). Kerberos (AS-REQ Pre-Auth etype 23). HTTP Basic. SNMP. POP. SMTP. FTP. IMAP. etc from a pcap file or from a live interface.","T1116 - T1003 - T1002 - T1001 - T1005 - T1552","TA0003 - TA0002 - TA0011","N/A","N/A","Credential Access","https://github.com/lgandx/Pcredz","1","0","N/A","N/A","N/A","10","2100","413","2025-01-27T10:34:00Z","2014-04-07T02:03:33Z","54593"
"*Pcredz -i *",".{0,1000}Pcredz\s\-i\s.{0,1000}","offensive_tool_keyword","Pcredz","This tool extracts Credit card numbers. NTLM(DCE-RPC. HTTP. SQL. LDAP. etc). Kerberos (AS-REQ Pre-Auth etype 23). HTTP Basic. SNMP. POP. SMTP. FTP. IMAP. etc from a pcap file or from a live interface.","T1116 - T1003 - T1002 - T1001 - T1005 - T1552","TA0003 - TA0002 - TA0011","N/A","N/A","Credential Access","https://github.com/lgandx/Pcredz","1","0","N/A","N/A","N/A","10","2100","413","2025-01-27T10:34:00Z","2014-04-07T02:03:33Z","54595"
"*pcunlocker_ent_trial.zip*",".{0,1000}pcunlocker_ent_trial\.zip.{0,1000}","greyware_tool_keyword","pcunlocker","Reset and unlock forgotten Windows login password","T1078","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://www.pcunlocker.com/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54596"
"*pdadjkfkgcafgbceimcpbkalnfnepbnk*",".{0,1000}pdadjkfkgcafgbceimcpbkalnfnepbnk.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","54599"
"*pdf2john.pl*",".{0,1000}pdf2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54603"
"*peiga/DumpThatLSASS*",".{0,1000}peiga\/DumpThatLSASS.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","1","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","54625"
"*pem2john.py*",".{0,1000}pem2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54629"
"*pentest\\sam.hive*",".{0,1000}pentest\\\\sam\.hive.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","54632"
"*pentest\\system.hive*",".{0,1000}pentest\\\\system\.hive.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","54633"
"*pentestmonkey/pysecdump*",".{0,1000}pentestmonkey\/pysecdump.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","54638"
"*Perform password spraying for all active users on a domain*",".{0,1000}Perform\spassword\sspraying\sfor\sall\sactive\susers\son\sa\sdomain.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","0","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","54651"
"*Performing attack with current NTLM settings on current user*",".{0,1000}Performing\sattack\swith\scurrent\sNTLM\ssettings\son\scurrent\suser.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","0","#content","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","54653"
"*peterdocter/quarkspwdump*",".{0,1000}peterdocter\/quarkspwdump.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","1","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","54712"
"*petitpotam.py*",".{0,1000}petitpotam\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","54720"
"*pfx2john.py*",".{0,1000}pfx2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54746"
"*pgpdisk2john.py*",".{0,1000}pgpdisk2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54751"
"*pgpsda2john.py*",".{0,1000}pgpsda2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54752"
"*pgpwde2john.py*",".{0,1000}pgpwde2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54753"
"*phkbamefinggmakgklpkljjmgibohnba*",".{0,1000}phkbamefinggmakgklpkljjmgibohnba.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","54781"
"*PhrozenIO/win-brute-logon*",".{0,1000}PhrozenIO\/win\-brute\-logon.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","1","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","54829"
"*physmem2profit.exe*",".{0,1000}physmem2profit\.exe.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","1","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","54831"
"*Physmem2profit.sln*",".{0,1000}Physmem2profit\.sln.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","54832"
"*physmem2profit-public.zip*",".{0,1000}physmem2profit\-public\.zip.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","1","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","54833"
"*Pickfordmatt/SharpLocker*",".{0,1000}Pickfordmatt\/SharpLocker.{0,1000}","offensive_tool_keyword","SharpLocker","get current user credentials by popping a fake Windows lock screen","T1056.002 - T1204.002 - T1071.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/Pickfordmatt/SharpLocker","1","1","N/A","N/A","10","7","616","145","2020-05-27T22:56:34Z","2019-05-31T11:16:38Z","54838"
"*ping localhost -n 3 > NUL && del /A H /F *",".{0,1000}ping\slocalhost\s\-n\s3\s\>\sNUL\s\&\&\sdel\s\/A\sH\s\/F\s.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","54845"
"*pip install conpass*",".{0,1000}pip\sinstall\sconpass.{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","0","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","54860"
"*pip install knowsmore*",".{0,1000}pip\sinstall\sknowsmore.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","54868"
"*pip install lsassy*",".{0,1000}pip\sinstall\slsassy.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","54869"
"*pip3 install --upgrade knowsmore*",".{0,1000}pip3\sinstall\s\-\-upgrade\sknowsmore.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","54887"
"*pipe\\gsecdump_*",".{0,1000}pipe\\\\gsecdump_.{0,1000}","offensive_tool_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#namedpipe","N/A","10","10","N/A","N/A","N/A","N/A","54888"
"*pixiewps -e*",".{0,1000}pixiewps\s\-e.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","54909"
"*pkgs.org/download/chntpw*",".{0,1000}pkgs\.org\/download\/chntpw.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54915"
"*pkt_comm/word_gen.*",".{0,1000}pkt_comm\/word_gen\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54921"
"*pkt_comm/word_list*",".{0,1000}pkt_comm\/word_list.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","54922"
"*Please be sure impacket and ldapsearch are installed and your /etc/krb5.conf file is clean*",".{0,1000}Please\sbe\ssure\simpacket\sand\sldapsearch\sare\sinstalled\sand\syour\s\/etc\/krb5\.conf\sfile\sis\sclean.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","0","#linux","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","54927"
"*Please be sure impacket is installed in your system*",".{0,1000}Please\sbe\ssure\simpacket\sis\sinstalled\sin\syour\ssystem.{0,1000}","offensive_tool_keyword","LDAP-Password-Hunter","LDAP Password Hunter is a tool which wraps features of getTGT.py (Impacket) and ldapsearch in order to look up for password stored in LDAP database","T1558.003 - T1003.003 - T1078.003 - T1212","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/oldboy21/LDAP-Password-Hunter","1","0","N/A","N/A","10","2","198","25","2023-01-06T15:32:34Z","2021-07-26T14:27:01Z","54929"
"*Please select command [PASSWORDS/HISTORY/COOKIES/AUTOFILL/CREDIT_CARDS/BOOKMARKS]*",".{0,1000}Please\sselect\scommand\s\[PASSWORDS\/HISTORY\/COOKIES\/AUTOFILL\/CREDIT_CARDS\/BOOKMARKS\].{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","54932"
"*Please use the -Password option to specify a unique password to spray*",".{0,1000}Please\suse\sthe\s\-Password\soption\sto\sspecify\sa\sunique\spassword\sto\sspray.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","0","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","54934"
"*Please use the -User option to specify a unique username to spray*",".{0,1000}Please\suse\sthe\s\-User\soption\sto\sspecify\sa\sunique\susername\sto\sspray.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","0","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","54935"
"*poetry run hekatomb*",".{0,1000}poetry\srun\shekatomb.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/ProcessusT/HEKATOMB","1","0","N/A","N/A","10","6","510","59","2024-07-31T19:05:30Z","2022-09-09T15:07:15Z","54984"
"*pogostick.net/~pnh/ntpasswd/*",".{0,1000}pogostick\.net\/\~pnh\/ntpasswd\/.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","54988"
"*Policy SPN target name validation might be restricting full DRSUAPI dump*",".{0,1000}Policy\sSPN\starget\sname\svalidation\smight\sbe\srestricting\sfull\sDRSUAPI\sdump.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","54997"
"*Policy SPN target name validation might be restricting full DRSUAPI dump*",".{0,1000}Policy\sSPN\starget\sname\svalidation\smight\sbe\srestricting\sfull\sDRSUAPI\sdump.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","54998"
"*Possible Password found in Registry Key: *",".{0,1000}Possible\sPassword\sfound\sin\sRegistry\sKey\:\s.{0,1000}","offensive_tool_keyword","Rust-Malware-Samples","open source informations stealer in rust","T1003 - T1083 - T1114 - T1074","TA0006 - TA0009 - TA0005","N/A","N/A","Credential Access","https://github.com/Whitecat18/Rust-for-Malware-Development/tree/main/Malware-Samples","1","0","N/A","N/A","10","10","2123","53","2025-04-22T18:09:57Z","2024-02-12T16:55:06Z","55090"
"*POSTDump*PROCEXP.sys*",".{0,1000}POSTDump.{0,1000}PROCEXP\.sys.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55105"
"*PostDump.exe *",".{0,1000}PostDump\.exe\s.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55106"
"*POSTDump.git*",".{0,1000}POSTDump\.git.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55107"
"*PostDump.ps1",".{0,1000}PostDump\.ps1","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection","T1003","TA0006","N/A","Black Basta","Credential Access","https://github.com/S3cur3Th1sSh1t/PowerSharpPack","1","1","N/A","N/A","10","10","1581","308","2025-04-14T13:31:01Z","2020-04-06T16:34:52Z","55108"
"*POSTDump\Postdump.cs*",".{0,1000}POSTDump\\Postdump\.cs.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55109"
"*POSTDump\PROCEXP.sys*",".{0,1000}POSTDump\\PROCEXP\.sys.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55110"
"*POSTDump-main*",".{0,1000}POSTDump\-main.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55111"
"*POSTMiniDump.Data*",".{0,1000}POSTMiniDump\.Data.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","#content","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55115"
"*POSTMiniDump.MiniDump*",".{0,1000}POSTMiniDump\.MiniDump.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","#content","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55116"
"*POSTMiniDump.Utils*",".{0,1000}POSTMiniDump\.Utils.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","#content","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","55117"
"*PowerBruteLogon.*",".{0,1000}PowerBruteLogon\..{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","55135"
"*PowerBruteLogon.zip*",".{0,1000}PowerBruteLogon\.zip.{0,1000}","offensive_tool_keyword","PowerBruteLogon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/PowerBruteLogon","1","1","N/A","N/A","8","2","124","22","2023-11-09T10:38:29Z","2021-12-01T09:40:22Z","55136"
"*PowerExtract-main.zip*",".{0,1000}PowerExtract\-main\.zip.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","55145"
"*PowerMemory*",".{0,1000}PowerMemory.{0,1000}","offensive_tool_keyword","PowerMemory","Exploit the credentials present in files and memory","T1003 - T1555 - T1213 - T1558","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/giMini/PowerMemory","1","0","N/A","N/A","N/A","9","840","204","2023-05-25T17:58:53Z","2015-08-29T17:09:23Z","55158"
"*powerseb/PowerExtract*",".{0,1000}powerseb\/PowerExtract.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","55174"
"*powerseb/PowerExtract*",".{0,1000}powerseb\/PowerExtract.{0,1000}","offensive_tool_keyword","powerextract","This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process","T1003 - T1055 - T1003.001 - T1055.012","TA0007 - TA0002","N/A","N/A","Credential Access","https://github.com/powerseb/PowerExtract","1","1","N/A","N/A","N/A","2","117","14","2025-03-28T10:49:43Z","2021-12-11T15:24:44Z","55175"
"*powershell -c *\windows\system32\inetsrv\appcmd.exe list apppool /@t:*",".{0,1000}powershell\s\-c\s.{0,1000}\\windows\\system32\\inetsrv\\appcmd\.exe\slist\sapppool\s\/\@t\:.{0,1000}","greyware_tool_keyword","powershell","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/Pennyw0rth/NetExec","1","0","N/A","Checking For Hidden Credentials With Appcmd.exe","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","55184"
"*powershell Get-ItemPropertyValue -Path {}:SOFTWARE\\Roblox\\RobloxStudioBrowser\\roblox.com -Name .ROBLOSECURITY*",".{0,1000}powershell\sGet\-ItemPropertyValue\s\-Path\s\{\}\:SOFTWARE\\\\Roblox\\\\RobloxStudioBrowser\\\\roblox\.com\s\-Name\s\.ROBLOSECURITY.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","#registry","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","55196"
"*powershell Get-ItemPropertyValue -Path 'HKLM:SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SoftwareProtectionPlatform' -Name BackupProductKeyDefault*",".{0,1000}powershell\sGet\-ItemPropertyValue\s\-Path\s\'HKLM\:SOFTWARE\\\\Microsoft\\\\Windows\sNT\\\\CurrentVersion\\\\SoftwareProtectionPlatform\'\s\-Name\sBackupProductKeyDefault.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","#registry","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","55197"
"*Powershell LDAPWordlistHarvester*",".{0,1000}Powershell\sLDAPWordlistHarvester.{0,1000}","offensive_tool_keyword","LDAPWordlistHarvester","A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.","T1210.001 - T1087.003 - T1110","TA0001 - TA0006 - TA0007","N/A","Black Basta","Credential Access","https://github.com/p0dalirius/LDAPWordlistHarvester","1","0","N/A","N/A","5","","N/A","","","","55202"
"*PowerShell/HackTool.SessionGopher*",".{0,1000}PowerShell\/HackTool\.SessionGopher.{0,1000}","signature_keyword","SessionGopher","uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.","T1047 - T1003.008 - T1552.004 - T1555.003","TA0006","N/A","PYSA - DarkSide - Sphinx","Credential Access","https://github.com/Arvanaghi/SessionGopher","1","0","#Avsignature","N/A","10","10","1255","173","2022-11-22T21:33:23Z","2017-03-08T02:49:32Z","55245"
"*ppl* --elevate-handle *.dmp*",".{0,1000}ppl.{0,1000}\s\-\-elevate\-handle\s.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","55328"
"*ppl_medic_dll.*",".{0,1000}ppl_medic_dll\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","55330"
"*PPLBlade.dmp*",".{0,1000}PPLBlade\.dmp.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","1","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","55331"
"*PPLBlade.exe*",".{0,1000}PPLBlade\.exe.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","1","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","55332"
"*PPLBlade-main.*",".{0,1000}PPLBlade\-main\..{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","1","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","55333"
"*PPLdump*",".{0,1000}PPLdump.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","1","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","55335"
"*PPLdump.exe*",".{0,1000}PPLdump\.exe.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","1","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","55336"
"*ppldump.py*",".{0,1000}ppldump\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","55337"
"*ppldump_embedded*",".{0,1000}ppldump_embedded.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","55339"
"*PPLdump64.exe*",".{0,1000}PPLdump64\.exe.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","1","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","55340"
"*PPLdumpDll*",".{0,1000}PPLdumpDll.{0,1000}","offensive_tool_keyword","ppldump","Dump the memory of a PPL with a userland exploit","T1003 - T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/itm4n/PPLdump","1","1","N/A","N/A","10","9","868","140","2022-07-24T14:03:14Z","2021-04-07T13:12:47Z","55341"
"*PPLFault.*",".{0,1000}PPLFault\..{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","55342"
"*pplfault.cna*",".{0,1000}pplfault\.cna.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","55343"
"*PPLFault.exe*",".{0,1000}PPLFault\.exe.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","55344"
"*PPLFaultDumpBOF*",".{0,1000}PPLFaultDumpBOF.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","55345"
"*PPLFault-Localhost-SMB.ps1*",".{0,1000}PPLFault\-Localhost\-SMB\.ps1.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","55346"
"*PPLFaultPayload.dll*",".{0,1000}PPLFaultPayload\.dll.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","55348"
"*PPLFaultPayload.dll*",".{0,1000}PPLFaultPayload\.dll.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","55349"
"*PPLFaultTemp*",".{0,1000}PPLFaultTemp.{0,1000}","offensive_tool_keyword","cobaltstrike","Takes the original PPLFault and the original included DumpShellcode and combinds it all into a BOF targeting cobalt strike.","T1055 - T1078.003","TA0002 - TA0006","N/A","APT19 - MAZE - APT32 - APT37 - APT41 - Aquatic Panda - AvosLocker - Black Basta - BlackByte - BlackCat - BlackSuit - CL0P - Cactus - Chimera - Cobalt Group - Conti - Common Raven - CopyKittens - Cuba - Dagon Locker - DarkHydrus - Diavol - Earth Lusca - EvilCorp* - FIN6 - FIN7 - Hive - Indrik Spider - Karakurt - Leviathan - LockBit - LuminousMoth - Mustang Panda - NetWalker - Nokoyawa - PLAY - Phobos - Qilin - Quantum - REvil - RagnarLocker - RansomEXX - Royal - Ryuk - Snatch - TA505 - Threat Group-3390 - Trigona - Vice Society - Wizard Spider - XingLocker - Yanluowang - menuPass - Unit 29155 - Akira - APT15 - APT26 - BRONZE STARLIGHT - COZY BEAR - Sandworm","Credential Access","https://github.com/trustedsec/PPLFaultDumpBOF","1","1","N/A","N/A","N/A","2","140","11","2023-05-17T12:57:20Z","2023-05-16T13:02:22Z","55350"
"*PPLFaultTemp*",".{0,1000}PPLFaultTemp.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","1","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","55351"
"*PPLmedicDll.def*",".{0,1000}PPLmedicDll\.def.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","55356"
"*PPLmedicDll.dll*",".{0,1000}PPLmedicDll\.dll.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","1","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","55357"
"*pplsystem.exe *",".{0,1000}pplsystem\.exe\s.{0,1000}","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","0","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","55358"
"*ppypykatz.py*",".{0,1000}ppypykatz\.py.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","1","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","55360"
"*praetorian.com/blog/relaying-to-adfs-attacks/*",".{0,1000}praetorian\.com\/blog\/relaying\-to\-adfs\-attacks\/.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","55363"
"*praetorian-inc/ADFSRelay*",".{0,1000}praetorian\-inc\/ADFSRelay.{0,1000}","offensive_tool_keyword","ADFSRelay","NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS","T1140 - T1212 - T1557","TA0007 - TA0008 - TA0006","N/A","Black Basta","Credential Access","https://github.com/praetorian-inc/ADFSRelay","1","1","N/A","N/A","10","2","179","15","2022-06-22T03:01:00Z","2022-05-12T01:20:14Z","55364"
"*praetorian-inc/noseyparker*",".{0,1000}praetorian\-inc\/noseyparker.{0,1000}","offensive_tool_keyword","noseyparker","Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.","T1583 - T1059.001 - T1059.003","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/praetorian-inc/noseyparker","1","1","N/A","N/A","8","10","1903","100","2025-03-07T20:15:34Z","2022-11-08T23:09:17Z","55366"
"*prepare_ppl_command_line*",".{0,1000}prepare_ppl_command_line.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","55370"
"*print_shtinkering_crash_location*",".{0,1000}print_shtinkering_crash_location.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","55377"
"*Println(""DO WESTERN!!""*",".{0,1000}Println\(\""DO\sWESTERN!!\"".{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","0","#content","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","55381"
"*privilege::debug*",".{0,1000}privilege\:\:debug.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","55437"
"*Probable-Wordlists*",".{0,1000}Probable\-Wordlists.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","55465"
"*procdump* lsass.exe *.dmp*",".{0,1000}procdump.{0,1000}\slsass\.exe\s.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","onex","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","N/A","N/A","N/A","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","55467"
"*procdump*lsass*",".{0,1000}procdump.{0,1000}lsass.{0,1000}","greyware_tool_keyword","Procdump","dump lsass process with procdump","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55468"
"*procdump*lsass*",".{0,1000}procdump.{0,1000}lsass.{0,1000}","greyware_tool_keyword","Procdump","dump lsass process with procdump","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55469"
"*procdump.exe* -ma*",".{0,1000}procdump\.exe.{0,1000}\s\-ma.{0,1000}","greyware_tool_keyword","Procdump","full dump with procdump (often used to dump lsass)","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55471"
"*procdump.exe*lsass*",".{0,1000}procdump\.exe.{0,1000}lsass.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Dump LSASS memory through a process snapshot (-r) avoiding interacting with it directly","T1003.001","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","55472"
"*procdump_embedded*",".{0,1000}procdump_embedded.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","55475"
"*procdump_path=*",".{0,1000}procdump_path\=.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","55476"
"*procdump64*lsass*",".{0,1000}procdump64.{0,1000}lsass.{0,1000}","greyware_tool_keyword","Procdump","dump lsass process with procdump","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55477"
"*procdump64.exe -ma lsass.exe*",".{0,1000}procdump64\.exe\s\-ma\slsass\.exe.{0,1000}","offensive_tool_keyword","MiniDump","C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/cube0x0/MiniDump","1","0","N/A","N/A","10","3","291","48","2021-10-13T18:00:46Z","2021-08-14T12:26:16Z","55478"
"*procdump64.exe*",".{0,1000}procdump64\.exe.{0,1000}","greyware_tool_keyword","Procdump","usage of procdump (often used to dump lsass)","T1003.001","TA0006","N/A","LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor","Credential Access","https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55479"
"*ProcDumpHandler.py -r *",".{0,1000}ProcDumpHandler\.py\s\-r\s.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","55480"
"*process must run as NT AUTHORITY\\SYSTEM to dump lsass memory*",".{0,1000}process\smust\srun\sas\sNT\sAUTHORITY\\\\SYSTEM\sto\sdump\slsass\smemory.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","0","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","55486"
"*Processus-Thief/HEKATOMB*",".{0,1000}Processus\-Thief\/HEKATOMB.{0,1000}","offensive_tool_keyword","HEKATOMB","Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them","T1003 - T1555.002 - T1482 - T1087","TA0006 - TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/Processus-Thief/HEKATOMB","1","1","N/A","N/A","10","","N/A","","","","55542"
"*produkey.zip*",".{0,1000}produkey\.zip.{0,1000}","greyware_tool_keyword","produkey","ProduKey is a small utility that displays the ProductID and the CD-Key of Microsoft Office (Microsoft Office 2003. Microsoft Office 2007). Windows (Including Windows 8/7/Vista). Exchange Server. and SQL Server installed on your computer. You can view this information for your current running operating system. or for another operating system/computer - by using command-line options. This utility can be useful if you lost the product key of your Windows/Office. and you want to reinstall it on your computer.","T1003.001 - T1003.002 - T1012 - T1057 - T1518","TA0006 - TA0007 - TA0009","N/A","Evilnum","Credential Access","https://www.nirsoft.net/utils/product_cd_key_viewer.html","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","55560"
"*produkey_setup.exe*",".{0,1000}produkey_setup\.exe.{0,1000}","greyware_tool_keyword","produkey","ProduKey is a small utility that displays the ProductID and the CD-Key of Microsoft Office (Microsoft Office 2003. Microsoft Office 2007). Windows (Including Windows 8/7/Vista). Exchange Server. and SQL Server installed on your computer. You can view this information for your current running operating system. or for another operating system/computer - by using command-line options. This utility can be useful if you lost the product key of your Windows/Office. and you want to reinstall it on your computer.","T1003.001 - T1003.002 - T1012 - T1057 - T1518","TA0006 - TA0007 - TA0009","N/A","Evilnum","Credential Access","https://www.nirsoft.net/utils/product_cd_key_viewer.html","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","55561"
"*produkey-x64.zip*",".{0,1000}produkey\-x64\.zip.{0,1000}","greyware_tool_keyword","produkey","ProduKey is a small utility that displays the ProductID and the CD-Key of Microsoft Office (Microsoft Office 2003. Microsoft Office 2007). Windows (Including Windows 8/7/Vista). Exchange Server. and SQL Server installed on your computer. You can view this information for your current running operating system. or for another operating system/computer - by using command-line options. This utility can be useful if you lost the product key of your Windows/Office. and you want to reinstall it on your computer.","T1003.001 - T1003.002 - T1012 - T1057 - T1518","TA0006 - TA0007 - TA0009","N/A","Evilnum","Credential Access","https://www.nirsoft.net/utils/product_cd_key_viewer.html","1","1","N/A","N/A","6","10","N/A","N/A","N/A","N/A","55562"
"*Program.MiniDump minidump*",".{0,1000}Program\.MiniDump\sminidump.{0,1000}","offensive_tool_keyword","DumpNParse","A Combination LSASS Dumper and LSASS Parser","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/icyguider/DumpNParse","1","0","#content","N/A","10","2","150","24","2021-11-21T14:25:24Z","2021-11-21T14:18:42Z","55589"
"*projectb-temp/mimidogz*",".{0,1000}projectb\-temp\/mimidogz.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","1","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","55602"
"*prosody2john.py*",".{0,1000}prosody2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","55608"
"*ps_token2john.py*",".{0,1000}ps_token2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","55660"
"*pscp *@*.kirbi*",".{0,1000}pscp\s.{0,1000}\@.{0,1000}\.kirbi.{0,1000}","greyware_tool_keyword","putty","credential cache retrieving with pscp putty","T1550 - T1140 - T1071","TA0006 - TA0010 - TA0005","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","8","7","N/A","N/A","N/A","N/A","55684"
"*pse2john.py*",".{0,1000}pse2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","55685"
"*pstgdump.exe*",".{0,1000}pstgdump\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55734"
"*PstPassword.exe*",".{0,1000}PstPassword\.exe.{0,1000}","offensive_tool_keyword","PstPassword","recover the PST passwords of Outlook","T1212","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/pst_password.html","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","55735"
"*pstpassword.zip*",".{0,1000}pstpassword\.zip.{0,1000}","offensive_tool_keyword","PstPassword","recover the PST passwords of Outlook","T1212","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/pst_password.html","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","55736"
"*pstpassword_setup.exe*",".{0,1000}pstpassword_setup\.exe.{0,1000}","offensive_tool_keyword","PstPassword","recover the PST passwords of Outlook","T1212","TA0006","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/pst_password.html","1","1","N/A","N/A","9","10","N/A","N/A","N/A","N/A","55737"
"*PSWtool*",".{0,1000}PSWtool.{0,1000}","signature_keyword","Antivirus Signature","highly revelant Antivirus signature. Programs classified as PSWTool can be used to view or restore forgotten often hidden passwords. They can also be used with malicious intent. even though the programs themselves have no malicious payload.","N/A","N/A","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","55739"
"*PSWTool.PasswordFox.*",".{0,1000}PSWTool\.PasswordFox\..{0,1000}","signature_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","55740"
"*PSWTool.Win32.PassView*",".{0,1000}PSWTool\.Win32\.PassView.{0,1000}","signature_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","55741"
"*PSWTool.Win32.PWDump*",".{0,1000}PSWTool\.Win32\.PWDump.{0,1000}","signature_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","55742"
"*PSWTool.Win64.FirePass.*",".{0,1000}PSWTool\.Win64\.FirePass\..{0,1000}","signature_keyword","passwordfox","recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox","T1555.003 - T1003 - T1083","TA0006 ","N/A","LockBit - GoGoogle - 8BASE - XDSpy","Credential Access","https://www.nirsoft.net/utils/passwordfox.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","55743"
"*PSWTool.Win64.Gsecdmp*",".{0,1000}PSWTool\.Win64\.Gsecdmp.{0,1000}","signature_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","55744"
"*PUA:Win32/PassShow*",".{0,1000}PUA\:Win32\/PassShow.{0,1000}","signature_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","55793"
"*PUA:Win32/PassShow*",".{0,1000}PUA\:Win32\/PassShow.{0,1000}","signature_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","55794"
"*public class LSASSDump*",".{0,1000}public\sclass\sLSASSDump.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","55796"
"*public class NTLMInjector*",".{0,1000}public\sclass\sNTLMInjector.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","0","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","55797"
"*Public\lsass.dmp*",".{0,1000}Public\\lsass\.dmp.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","55800"
"*pwcrack initdb*",".{0,1000}pwcrack\sinitdb.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","55848"
"*pwcrack updatedb*",".{0,1000}pwcrack\supdatedb.{0,1000}","offensive_tool_keyword","pwcrack-framework","Password Crack Framework","T1110 - T1003 - T1059","TA0006","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","0","N/A","N/A","10","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","55849"
"*PWCrack*",".{0,1000}PWCrack.{0,1000}","offensive_tool_keyword","PWCrack","cracking tool for multiple hash type","T1110 - T1111 - T1210 - T1558.002 - T1555","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/L-codes/pwcrack-framework","1","1","N/A","N/A","N/A","6","515","59","2024-02-25T13:08:56Z","2018-07-01T08:33:55Z","55850"
"*PWCrack-PWDump*",".{0,1000}PWCrack\-PWDump.{0,1000}","signature_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","55851"
"*PWCrack-Pwdump.*",".{0,1000}PWCrack\-Pwdump\..{0,1000}","signature_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","55852"
"*pwd*/*/rules/best64.rule*",".{0,1000}pwd.{0,1000}\/.{0,1000}\/rules\/best64\.rule.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Crack the hash with Hashcat","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","55853"
"*PWDump *",".{0,1000}PWDump\s.{0,1000}","signature_keyword","Antivirus Signature","Antivirus signature - a tool used within a command-line interface on 64bit Windows computers to extract the NTLM (LanMan) hashes from LSASS.exe in memory. This tool may be used in conjunction with malware or other penetration testing tools to obtain credentials for use in Windows authentication systems","N/A","N/A","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","55864"
"*pwdump -f *",".{0,1000}pwdump\s\-f\s.{0,1000}","offensive_tool_keyword","PwDump8","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://download.openwall.net/pub/projects/john/contrib/pwdump/pwdump8-8.2.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","55865"
"*Pwdump v7.1 - raw password extractor*",".{0,1000}Pwdump\sv7\.1\s\-\sraw\spassword\sextractor.{0,1000}","offensive_tool_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","55866"
"*PwDump v8.2 - dumps windows password hashes*",".{0,1000}PwDump\sv8\.2\s\-\sdumps\swindows\spassword\shashes.{0,1000}","offensive_tool_keyword","PwDump8","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://download.openwall.net/pub/projects/john/contrib/pwdump/pwdump8-8.2.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","55867"
"*PWDump*",".{0,1000}PWDump\..{0,1000}","offensive_tool_keyword","pwdump","a tool used within a command-line interface on 64bit Windows computers to extract the NTLM (LanMan) hashes from LSASS.exe in memory. This tool may be used in conjunction with malware or other penetration testing tools to obtain credentials for use in Windows authentication systems","T1003 - T1110.001 - T1555.003 - T1003.002","TA0006","N/A","menuPass - APT41 - Threat Group-3390 - APT1 - Turla - APT39 - FIN5","Credential Access","https://ftp.samba.org/pub/samba/pwdump/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55868"
"*PWDump.*",".{0,1000}PWDump\..{0,1000}","offensive_tool_keyword","pwdump","a tool used within a command-line interface on 64bit Windows computers to extract the NTLM (LanMan) hashes from LSASS.exe in memory. This tool may be used in conjunction with malware or other penetration testing tools to obtain credentials for use in Windows authentication systems","T1003 - T1110.001 - T1555.003 - T1003.002","TA0006","N/A","menuPass - APT41 - Threat Group-3390 - APT1 - Turla - APT39 - FIN5","Credential Access","https://ftp.samba.org/pub/samba/pwdump/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55869"
"*pwdump.exe*",".{0,1000}pwdump\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","55870"
"*pwdump.py SYSTEM SAM*",".{0,1000}pwdump\.py\sSYSTEM\sSAM.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","55871"
"*pwdump/cachedump*",".{0,1000}pwdump\/cachedump.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://github.com/ihamburglar/fgdump","1","0","N/A","N/A","10","1","8","4","2012-01-14T19:05:42Z","2015-10-11T17:08:47Z","55872"
"*PWDump7 Raw Password Extractor (PUA)*",".{0,1000}PWDump7\sRaw\sPassword\sExtractor\s\(PUA\).{0,1000}","signature_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","55873"
"*PwDump7.exe*",".{0,1000}PwDump7\.exe.{0,1000}","offensive_tool_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","55874"
"*PWDumpDLLPath*",".{0,1000}PWDumpDLLPath.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","55875"
"*PWDumpEXEPath*",".{0,1000}PWDumpEXEPath.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","55876"
"*PWDumpX (PUA)*",".{0,1000}PWDumpX\s\(PUA\).{0,1000}","signature_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","55878"
"*PWDumpX *",".{0,1000}PWDumpX\s.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","55879"
"*PWDumpX v1.0*",".{0,1000}PWDumpX\sv1\.0.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","55880"
"*PWDumpX.zip*",".{0,1000}PWDumpX\.zip.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","1","N/A","N/A","10","8","N/A","N/A","N/A","N/A","55881"
"*-PWHashes.txt*",".{0,1000}\-PWHashes\.txt.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","55883"
"*pw-inspector -*",".{0,1000}pw\-inspector\s\-.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","55884"
"*pw-inspector.*",".{0,1000}pw\-inspector\..{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","55885"
"*pwnagotchi*",".{0,1000}pwnagotchi.{0,1000}","offensive_tool_keyword","pwnagotchi","Pwnagotchi is an A2C-based AI leveraging bettercap that learns from its surrounding WiFi environment to maximize the crackable WPA key material it captures (either passively. or by performing authentication and association attacks). This material is collected as PCAP files containing any form of handshake supported by hashcat. including PMKIDs. full and half WPA handshakes","T1562.004 - T1040 - T1557.001","TA0002 - TA0003 - TA0040","N/A","N/A","Credential Access","https://github.com/evilsocket/pwnagotchi","1","0","N/A","network exploitation tool","N/A","10","8267","1185","2025-03-31T09:38:00Z","2019-09-19T13:07:15Z","55890"
"*pwned-passwords-ntlm*",".{0,1000}pwned\-passwords\-ntlm.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","55906"
"*pwsafe2john.py*",".{0,1000}pwsafe2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","55916"
"*pxethief *",".{0,1000}pxethief\s.{0,1000}","offensive_tool_keyword","pxethief","PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager","T1555.004 - T1555.002","TA0006","N/A","N/A","Credential Access","https://github.com/MWR-CyberSec/PXEThief","1","0","N/A","N/A","N/A","4","368","57","2024-05-29T15:07:15Z","2022-08-12T22:16:46Z","55918"
"*pxethief.py*",".{0,1000}pxethief\.py.{0,1000}","offensive_tool_keyword","pxethief","PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager","T1555.004 - T1555.002","TA0006","N/A","N/A","Credential Access","https://github.com/MWR-CyberSec/PXEThief","1","1","N/A","N/A","N/A","4","368","57","2024-05-29T15:07:15Z","2022-08-12T22:16:46Z","55919"
"*pydictor*",".{0,1000}pydictor.{0,1000}","offensive_tool_keyword","pydictor","pydictor A powerful and useful hacker dictionary builder for a brute-force attack","T1110 - T1111 - T1210 - T1558.004","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/LandGrey/pydictor","1","0","N/A","N/A","N/A","10","3360","642","2024-12-05T02:45:11Z","2016-08-17T08:16:56Z","55938"
"*pyinstaller -F barrel.py*",".{0,1000}pyinstaller\s\-F\sbarrel\.py.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","55977"
"*pyinstaller -F lock.py*",".{0,1000}pyinstaller\s\-F\slock\.py.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","55979"
"*pyinstaller -F shock.py*",".{0,1000}pyinstaller\s\-F\sshock\.py.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","55980"
"*pyLAPS-main*",".{0,1000}pyLAPS\-main.{0,1000}","offensive_tool_keyword","pyLAPS","A simple way to read and write LAPS passwords from linux.","T1136.001 - T1112 - T1078.001","TA0002 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/p0dalirius/pyLAPS","1","1","#linux","N/A","9","2","105","16","2024-10-28T08:36:38Z","2021-10-05T18:35:21Z","55988"
"*pypykatz *",".{0,1000}pypykatz\s.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","55992"
"*pypykatz lsa minidump*",".{0,1000}pypykatz\slsa\sminidump.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","55994"
"*pypykatz.commons*",".{0,1000}pypykatz\.commons.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","55997"
"*pypykatz.dpapi*",".{0,1000}pypykatz\.dpapi.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","55998"
"*pypykatz.exe*",".{0,1000}pypykatz\.exe.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","55999"
"*pypykatz.git*",".{0,1000}pypykatz\.git.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56000"
"*pypykatz.kerberos*",".{0,1000}pypykatz\.kerberos.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56001"
"*pypykatz.lsadecryptor*",".{0,1000}pypykatz\.lsadecryptor.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56002"
"*pypykatz.py*",".{0,1000}pypykatz\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56003"
"*pypykatz.pypykatz*",".{0,1000}pypykatz\.pypykatz.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","56004"
"*pypykatz.pypykatz*",".{0,1000}pypykatz\.pypykatz.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","56005"
"*pypykatz.registry*",".{0,1000}pypykatz\.registry.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56006"
"*pypykatz_rekall.py*",".{0,1000}pypykatz_rekall\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56009"
"*pypykatz-master.zip*",".{0,1000}pypykatz\-master\.zip.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56012"
"*pysecdump -*",".{0,1000}pysecdump\s\-.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","56030"
"*pysecdump v%s *",".{0,1000}pysecdump\sv\%s\s.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#content","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","56031"
"*pysecdump.exe*",".{0,1000}pysecdump\.exe.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","56032"
"*pysecdump.py*",".{0,1000}pysecdump\.py.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","1","N/A","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","56033"
"*pysecdump: Starting shell*",".{0,1000}pysecdump\:\sStarting\sshell.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#content","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","56034"
"*python barrel.go -o debugproc*",".{0,1000}python\sbarrel\.go\s\-o\sdebugproc.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","56055"
"*python barrel.py -o debugproc*",".{0,1000}python\sbarrel\.py\s\-o\sdebugproc.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","56056"
"*python create_dump.py *",".{0,1000}python\screate_dump\.py\s.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","56068"
"*python lock.py -o disk*",".{0,1000}python\slock\.py\s\-o\sdisk.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","56071"
"*python shock.py -o knwondlls*",".{0,1000}python\sshock\.py\s\-o\sknwondlls.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","56085"
"*python.exe* create_dump.py *",".{0,1000}python\.exe.{0,1000}\screate_dump\.py\s.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","56095"
"*Python.Stealer*",".{0,1000}Python\.Stealer.{0,1000}","signature_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","56096"
"*python3 create_dump.py *",".{0,1000}python3\screate_dump\.py\s.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","56102"
"*python3 dump-restore.py*",".{0,1000}python3\sdump\-restore\.py.{0,1000}","offensive_tool_keyword","POSTDump","Another tool to perform minidump of LSASS process using few technics to avoid detection.","T1003 - T1055 - T1562.001 - T1218","TA0005 - TA0003 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","0","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","56103"
"*python3 ntlmv1.py *",".{0,1000}python3\sntlmv1\.py\s.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","56114"
"*python3 TokenFinder*",".{0,1000}python3\sTokenFinder.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","0","N/A","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","56124"
"*python3.exe* create_dump.py *",".{0,1000}python3\.exe.{0,1000}\screate_dump\.py\s.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","0","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","56126"
"*pywhisker.py*",".{0,1000}pywhisker\.py.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","1","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","56133"
"*pywhisker-main*",".{0,1000}pywhisker\-main.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","1","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","56134"
"*QAX-A-Team/BrowserGhost*",".{0,1000}QAX\-A\-Team\/BrowserGhost.{0,1000}","offensive_tool_keyword","BrowserGhost","This is a tool for grabbing browser passwords","T1555.003 - T1555.013 - T1003.008","TA0006","N/A","N/A","Credential Access","https://github.com/QAX-A-Team/BrowserGhost","1","1","N/A","N/A","10","10","1414","206","2022-05-21T14:09:45Z","2020-06-12T12:19:06Z","56140"
"*QuarksADDumper*",".{0,1000}QuarksADDumper.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","1","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","56160"
"*quarkslab/quarkspwdump*",".{0,1000}quarkslab\/quarkspwdump.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","1","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","56161"
"*quarks-pwdump.exe*",".{0,1000}quarks\-pwdump\.exe.{0,1000}","offensive_tool_keyword","quarkspwdump","Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems","T1003 - T1003.001 - T1059","TA0006","N/A","LOTUS PANDA - PowerPool - Calypso","Credential Access","https://github.com/peterdocter/quarkspwdump","1","1","N/A","N/A","9","1","12","8","2015-06-25T04:22:21Z","2015-07-14T08:18:08Z","56162"
"*quarks-pwdump.exe*",".{0,1000}quarks\-pwdump\.exe.{0,1000}","offensive_tool_keyword","quarkspwdump","Dump various types of Windows credentials without injecting in any process","T1003 - T1555","TA0006","N/A","N/A","Credential Access","https://github.com/quarkslab/quarkspwdump","1","1","N/A","N/A","10","5","427","142","2023-01-13T03:45:25Z","2013-02-13T15:16:30Z","56163"
"*QwA6AFwAVQBzAGUAcgBzAFwAUAB1AGIAbABpAGMAXABiAGEAYwBrAHUAcAAuAGUAbgBjAA==*",".{0,1000}QwA6AFwAVQBzAGUAcgBzAFwAUAB1AGIAbABpAGMAXABiAGEAYwBrAHUAcAAuAGUAbgBjAA\=\=.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","56188"
"*QwA6AFwAVQBzAGUAcgBzAFwAUAB1AGIAbABpAGMAXABzAHkAcwBsAG8AZwAuAGQAYQB0AA==*",".{0,1000}QwA6AFwAVQBzAGUAcgBzAFwAUAB1AGIAbABpAGMAXABzAHkAcwBsAG8AZwAuAGQAYQB0AA\=\=.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","56189"
"*QwA6AFwAVQBzAGUAcgBzAFwAUAB1AGIAbABpAGMAXABzAHkAcwBsAG8AZwAuAHoAaQBwAA==*",".{0,1000}QwA6AFwAVQBzAGUAcgBzAFwAUAB1AGIAbABpAGMAXABzAHkAcwBsAG8AZwAuAHoAaQBwAA\=\=.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","56190"
"*r3F0rM47(listt*",".{0,1000}r3F0rM47\(listt.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","56203"
"*radius2john.pl*",".{0,1000}radius2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","56208"
"*radius2john.py*",".{0,1000}radius2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","56209"
"*RagingRotator-main.*",".{0,1000}RagingRotator\-main\..{0,1000}","offensive_tool_keyword","RagingRotator","A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.","T1110 - T1027 - T1071 - T1090 - T1621","TA0006 - TA0005 - TA0001","N/A","N/A","Credential Access","https://github.com/nickzer0/RagingRotator","1","1","N/A","N/A","10","1","79","7","2024-06-06T19:31:34Z","2023-09-01T15:19:38Z","56215"
"*RainbowCrack*",".{0,1000}RainbowCrack.{0,1000}","offensive_tool_keyword","RainbowCrack","The RainbowCrack tool is a hash cracker that makes use of a large-scale time-memory trade-off. A traditional brute force cracker tries all possible plaintexts one by one. which can be time consuming for complex passwords. RainbowCrack uses a time-memory trade-off to do all the cracking-time computation in advance and store the results in so-called rainbow tables. It does take a long time to precompute the tables but RainbowCrack can be hundreds of times faster than a brute force cracker once the precomputation is finished. For downloads and more information. visit the RainbowCrack homepage","T1110 - T1027 - T1071 - T1090 - T1621","TA0001 - TA0002 - TA0003 - TA0005 - TA0007 - TA0011","N/A","N/A","Credential Access","http://project-rainbowcrack.com/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","56223"
"*randomize_sw2_seed.py*",".{0,1000}randomize_sw2_seed\.py.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","56241"
"*rar2john *",".{0,1000}rar2john\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","56274"
"*rar2john.*",".{0,1000}rar2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","56275"
"*rastamouse.me/dumping-lsass-with-duplicated-handles*",".{0,1000}rastamouse\.me\/dumping\-lsass\-with\-duplicated\-handles.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","0","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","56285"
"*raw.githubusercontent.com/Flangvik/statistically-likely-usernames/*",".{0,1000}raw\.githubusercontent\.com\/Flangvik\/statistically\-likely\-usernames\/.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","56386"
"*rawSHA1_linkedIn_fmt_plug*",".{0,1000}rawSHA1_linkedIn_fmt_plug.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","56393"
"*RDP Recognizer Login Parser*",".{0,1000}RDP\sRecognizer\sLogin\sParser.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","56438"
"*RDPCredentialStealer.zip*",".{0,1000}RDPCredentialStealer\.zip.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","56452"
"*RDPCredentialStealer-main*",".{0,1000}RDPCredentialStealer\-main.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","56453"
"*RDPCredsStealerDLL.*",".{0,1000}RDPCredsStealerDLL\..{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","56454"
"*RDPCredsStealerDLL.dll*",".{0,1000}RDPCredsStealerDLL\.dll.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","56455"
"*RDPSpray*",".{0,1000}RDPSpray.{0,1000}","offensive_tool_keyword","RDPSpray","Tool for password spraying RDP","T1110.001 - T1555.002","TA0006 - TA0040 - TA0003","N/A","N/A","Credential Access","https://github.com/dafthack/RDPSpray","1","1","N/A","N/A","N/A","1","95","28","2018-10-12T18:32:51Z","2018-10-12T18:29:52Z","56467"
"*RDPStrike enabled*",".{0,1000}RDPStrike\senabled.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","0","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","56468"
"*RdpStrike.x64.bin*",".{0,1000}RdpStrike\.x64\.bin.{0,1000}","offensive_tool_keyword","RdpStrike","Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP","T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/0xEr3bus/RdpStrike","1","1","N/A","N/A","10","3","238","27","2024-06-11T19:40:05Z","2024-06-11T19:31:50Z","56469"
"*RdpThief enabled *",".{0,1000}RdpThief\senabled\s.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","#content","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","56470"
"*RdpThief.dll*",".{0,1000}RdpThief\.dll.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","1","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","56472"
"*RdpThief.exe*",".{0,1000}RdpThief\.exe.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","1","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","56473"
"*RdpThief_x64.tmp*",".{0,1000}RdpThief_x64\.tmp.{0,1000}","offensive_tool_keyword","RdpThief","Extracting Clear Text Passwords from mstsc.exe using API Hooking.","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/0x09AL/RdpThief","1","0","N/A","N/A","10","10","1311","361","2024-07-20T06:58:02Z","2019-11-03T17:54:38Z","56474"
"*rdrleakdiag.exe /p * /o * /fullmemdmp /wait 1*",".{0,1000}rdrleakdiag\.exe\s\/p\s.{0,1000}\s\/o\s.{0,1000}\s\/fullmemdmp\s\/wait\s1.{0,1000}","greyware_tool_keyword","rdrleakdiag","Microsoft Windows resource leak diagnostic tool potentially dumping lsass process","T1003","TA0006 - TA0005","N/A","N/A","Credential Access","https://lolbas-project.github.io/lolbas/Binaries/Rdrleakdiag/","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","56477"
"*rdrleakdiag.exe -p (Get-Process lsass)*",".{0,1000}rdrleakdiag\.exe\s\-p\s\(Get\-Process\slsass\).{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","0","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","56478"
"*rdrleakdiag.py*",".{0,1000}rdrleakdiag\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","56479"
"*Real-Passwords*",".{0,1000}Real\-Passwords.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","56495"
"*reedarvin@gmail.com*",".{0,1000}reedarvin\@gmail\.com.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#email","N/A","10","8","N/A","N/A","N/A","N/A","56597"
"*reg add ""HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint"" /f /v PackagePointAndPrintOnly /t REG_DWORD /d 1*",".{0,1000}reg\sadd\s\""HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\sNT\\Printers\\PackagePointAndPrint\""\s\/f\s\/v\sPackagePointAndPrintOnly\s\/t\sREG_DWORD\s\/d\s1.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#registry","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","56684"
"*reg add ""HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint"" /f /v PackagePointAndPrintOnly /t REG_DWORD /d 1*",".{0,1000}reg\sadd\s\""HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\sNT\\Printers\\PackagePointAndPrint\""\s\/f\s\/v\sPackagePointAndPrintOnly\s\/t\sREG_DWORD\s\/d\s1.{0,1000}","greyware_tool_keyword","reg","mimikatz command","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","BlackSuit - Royal - Black Basta - Akira - Phobos - PLAY - Karakurt - Scattered Spider - AvosLocker - LockBit - Conti - Bassterlord - Quantum - PYSA - NetWalker - GoGoogle - 8BASE - Trigona - Cuba - RansomEXX - BlackCat","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#registry","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","56685"
"*reg add ""HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint"" /f /v PackagePointAndPrintServerList /t REG_DWORD /d 1*",".{0,1000}reg\sadd\s\""HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\sNT\\Printers\\PackagePointAndPrint\""\s\/f\s\/v\sPackagePointAndPrintServerList\s\/t\sREG_DWORD\s\/d\s1.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#registry","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","56686"
"*reg add ""HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint"" /f /v PackagePointAndPrintServerList /t REG_DWORD /d 1*",".{0,1000}reg\sadd\s\""HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\sNT\\Printers\\PackagePointAndPrint\""\s\/f\s\/v\sPackagePointAndPrintServerList\s\/t\sREG_DWORD\s\/d\s1.{0,1000}","greyware_tool_keyword","reg","mimikatz command","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","BlackSuit - Royal - Black Basta - Akira - Phobos - PLAY - Karakurt - Scattered Spider - AvosLocker - LockBit - Conti - Bassterlord - Quantum - PYSA - NetWalker - GoGoogle - 8BASE - Trigona - Cuba - RansomEXX - BlackCat","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#registry","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","56687"
"*reg add ""HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint\ListofServers"" /f /v 1 /t REG_SZ /d *",".{0,1000}reg\sadd\s\""HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\sNT\\Printers\\PackagePointAndPrint\\ListofServers\""\s\/f\s\/v\s1\s\/t\sREG_SZ\s\/d\s.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#registry","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","56688"
"*reg add ""HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PackagePointAndPrint\ListofServers"" /f /v 1 /t REG_SZ /d *",".{0,1000}reg\sadd\s\""HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\sNT\\Printers\\PackagePointAndPrint\\ListofServers\""\s\/f\s\/v\s1\s\/t\sREG_SZ\s\/d\s.{0,1000}","greyware_tool_keyword","reg","mimikatz command","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","BlackSuit - Royal - Black Basta - Akira - Phobos - PLAY - Karakurt - Scattered Spider - AvosLocker - LockBit - Conti - Bassterlord - Quantum - PYSA - NetWalker - GoGoogle - 8BASE - Trigona - Cuba - RansomEXX - BlackCat","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#registry","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","56689"
"*reg add ""HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint"" /f /v RestrictDriverInstallationToAdministrators /t REG_DWORD /d 0*",".{0,1000}reg\sadd\s\""HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\sNT\\Printers\\PointAndPrint\""\s\/f\s\/v\sRestrictDriverInstallationToAdministrators\s\/t\sREG_DWORD\s\/d\s0.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#registry","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","56690"
"*reg add ""HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint"" /f /v RestrictDriverInstallationToAdministrators /t REG_DWORD /d 0*",".{0,1000}reg\sadd\s\""HKLM\\SOFTWARE\\Policies\\Microsoft\\Windows\sNT\\Printers\\PointAndPrint\""\s\/f\s\/v\sRestrictDriverInstallationToAdministrators\s\/t\sREG_DWORD\s\/d\s0.{0,1000}","greyware_tool_keyword","reg","mimikatz command","T1003 - T1021.001 - T1053 - T1055 - T1057 - T1059.003 - T1070 - T1071 - T1078.002 - T1078.003 - T1078.005 - T1106 - T1136 - T1204 - T1218 - T1547 - T1555.003 - T1555.004 - T1573 - T1574 - T1596 - T1543","TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 - TA0010 - TA0040","N/A","BlackSuit - Royal - Black Basta - Akira - Phobos - PLAY - Karakurt - Scattered Spider - AvosLocker - LockBit - Conti - Bassterlord - Quantum - PYSA - NetWalker - GoGoogle - 8BASE - Trigona - Cuba - RansomEXX - BlackCat","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#registry","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","56691"
"*reg add HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest /v UseLogonCredential /t REG_DWORD /d /f 1*",".{0,1000}reg\sadd\sHKLM\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\s\/v\sUseLogonCredential\s\/t\sREG_DWORD\s\/d\s\/f\s1.{0,1000}","greyware_tool_keyword","reg","allows the storage of plaintext passwords in memory","T1003.001 - T1112","TA0006 - TA0005","N/A","Rancor - OilRig - Dragonfly - GALLIUM - Turla","Credential Access","N/A","1","0","#registry","N/A","10","10","N/A","N/A","N/A","N/A","56736"
"*reg add HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest /v UseLogonCredential /t REG_DWORD /d 1 /f*",".{0,1000}reg\sadd\sHKLM\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\s\/v\sUseLogonCredential\s\/t\sREG_DWORD\s\/d\s1\s\/f.{0,1000}","greyware_tool_keyword","reg","allows the storage of plaintext passwords in memory","T1003.001 - T1112","TA0006 - TA0005","N/A","Rancor - OilRig - Dragonfly - GALLIUM - Turla","Credential Access","N/A","1","0","#registry","N/A","10","10","N/A","N/A","N/A","N/A","56737"
"*reg add HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest /v UseLogonCredential /t REG_DWORD /d 1 /f*",".{0,1000}reg\sadd\sHKLM\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\s\/v\sUseLogonCredential\s\/t\sREG_DWORD\s\/d\s1\s\/f.{0,1000}","greyware_tool_keyword","reg","Enables WDigest authentication - storing plaintext credentials in memory. This exposes the system to credential theft attacks","T1003.001 - T1547.001 - T1552.001","TA0005 - TA0006","N/A","N/A","Credential Access","N/A","1","0","#registry","N/A","10","10","N/A","N/A","N/A","N/A","56738"
"*reg add HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest /v UseLogonCredential /t REG_DWORD /f /d 1*",".{0,1000}reg\sadd\sHKLM\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\s\/v\sUseLogonCredential\s\/t\sREG_DWORD\s\/f\s\/d\s1.{0,1000}","greyware_tool_keyword","reg","allows the storage of plaintext passwords in memory","T1003.001 - T1112 - T1112","TA0006 - TA0005","N/A","Rancor - OilRig - Dragonfly - GALLIUM - Turla","Credential Access","N/A","1","0","#registry","N/A","10","10","N/A","N/A","N/A","N/A","56740"
"*reg delete ""HKLM\SYSTEM\Remote Manipulator System"" /f*",".{0,1000}reg\sdelete\s\""HKLM\\SYSTEM\\Remote\sManipulator\sSystem\""\s\/f.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","#registry","N/A","9","10","N/A","N/A","N/A","N/A","56791"
"*reg delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU /va /f*",".{0,1000}reg\sdelete\sHKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU\s\/va\s\/f.{0,1000}","offensive_tool_keyword","reg","Delete run box history","T1056.002 - T1566.001 - T1567.002","TA0004 - TA0040 - TA0010","N/A","Rancor - OilRig - Dragonfly - GALLIUM - Turla","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/-OMG-Credz-Plz","1","0","#registry","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","56796"
"*reg query hkcu\software\*\putty\session*",".{0,1000}reg\squery\shkcu\\software\\.{0,1000}\\putty\\session.{0,1000}","greyware_tool_keyword","reg","credential access with reg","T1555 - T1003","TA0007 - TA0006","N/A","APT41","Credential Access","https://medium.com/detect-fyi/playbook-hunting-chinese-apt-379a6b950492","1","0","#registry","N/A","7","7","N/A","N/A","N/A","N/A","56808"
"*reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ /v RunAsPPL*",".{0,1000}reg\squery\sHKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\\s\/v\sRunAsPPL.{0,1000}","greyware_tool_keyword","reg","NetExec (a.k.a nxc) is a post-exploitation tool that helps automate assessing the security of large Active Directory networks.","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","Rancor - OilRig - Dragonfly - GALLIUM - Turla","Credential Access","https://github.com/Pennyw0rth/NetExec","1","0","#registry","Checking For Hidden Credentials With Appcmd.exe","10","10","4066","459","2025-04-20T00:08:29Z","2023-09-08T15:36:00Z","56812"
"*reg query HKLM /f password /t REG_SZ /s *",".{0,1000}reg\squery\sHKLM\s\/f\spassword\s\s\/t\sREG_SZ\s\s\/s\s.{0,1000}","greyware_tool_keyword","reg","Searching the Registry for Passwords","T1552.001 - T1012","TA0006 - TA0009","N/A","N/A","Credential Access","N/A","1","0","#registry","N/A","10","10","N/A","N/A","N/A","N/A","56815"
"*reg query hklm\software\OpenSSH*",".{0,1000}reg\squery\shklm\\software\\OpenSSH.{0,1000}","greyware_tool_keyword","reg","credential access with reg","T1555 - T1003","TA0007 - TA0006","N/A","APT41","Credential Access","https://medium.com/detect-fyi/playbook-hunting-chinese-apt-379a6b950492","1","0","#registry","N/A","7","7","N/A","N/A","N/A","N/A","56819"
"*reg query hklm\software\OpenSSH\Agent*",".{0,1000}reg\squery\shklm\\software\\OpenSSH\\Agent.{0,1000}","greyware_tool_keyword","reg","credential access with reg","T1555 - T1003","TA0007 - TA0006","N/A","APT41","Credential Access","https://medium.com/detect-fyi/playbook-hunting-chinese-apt-379a6b950492","1","0","#registry","N/A","7","7","N/A","N/A","N/A","N/A","56821"
"*reg query hklm\software\realvnc*",".{0,1000}reg\squery\shklm\\software\\realvnc.{0,1000}","greyware_tool_keyword","reg","credential access with reg","T1555 - T1003","TA0007 - TA0006","N/A","APT41","Credential Access","https://medium.com/detect-fyi/playbook-hunting-chinese-apt-379a6b950492","1","0","#registry","N/A","7","7","N/A","N/A","N/A","N/A","56823"
"*reg query hklm\software\realvnc\Allusers*",".{0,1000}reg\squery\shklm\\software\\realvnc\\Allusers.{0,1000}","greyware_tool_keyword","reg","credential access with reg","T1555 - T1003","TA0007 - TA0006","N/A","APT41","Credential Access","https://medium.com/detect-fyi/playbook-hunting-chinese-apt-379a6b950492","1","0","#registry","N/A","7","7","N/A","N/A","N/A","N/A","56825"
"*reg query hklm\software\realvnc\Allusers\vncserver*",".{0,1000}reg\squery\shklm\\software\\realvnc\\Allusers\\vncserver.{0,1000}","greyware_tool_keyword","reg","credential access with reg","T1555 - T1003","TA0007 - TA0006","N/A","APT41","Credential Access","https://medium.com/detect-fyi/playbook-hunting-chinese-apt-379a6b950492","1","0","#registry","N/A","7","7","N/A","N/A","N/A","N/A","56827"
"*reg query hklm\software\realvnc\vncserver*",".{0,1000}reg\squery\shklm\\software\\realvnc\\vncserver.{0,1000}","greyware_tool_keyword","reg","credential access with reg","T1555 - T1003","TA0007 - TA0006","N/A","APT41","Credential Access","https://medium.com/detect-fyi/playbook-hunting-chinese-apt-379a6b950492","1","0","#registry","N/A","7","7","N/A","N/A","N/A","N/A","56829"
"*reg save hklm\sam 1337*",".{0,1000}reg\ssave\shklm\\sam\s1337.{0,1000}","offensive_tool_keyword","SamDumpCable","Dump users sam and system hive and exfiltrate them","T1003.002 - T1564.001","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SamDumpCable","1","0","#registry","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","56837"
"*reg save hklm\system 1337*",".{0,1000}reg\ssave\shklm\\system\s1337.{0,1000}","offensive_tool_keyword","SamDumpCable","Dump users sam and system hive and exfiltrate them","T1003.002 - T1564.001","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SamDumpCable","1","0","#registry","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","56842"
"*reg.exe export HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion*",".{0,1000}reg\.exe\sexport\sHKEY_LOCAL_MACHINE\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#registry","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","56857"
"*reg.exe query hklm ^| findstr /i \\OFFLINE'*",".{0,1000}reg\.exe\squery\shklm\s\^\|\sfindstr\s\/i\s\\\\OFFLINE\'.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#registry","N/A","10","10","N/A","N/A","N/A","N/A","56858"
"*reg.exe query hklm ^| findstr /i \OFFLINE*",".{0,1000}reg\.exe\squery\shklm\s\^\|\sfindstr\s\/i\s\\OFFLINE.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","#registry","N/A","10","10","N/A","N/A","N/A","N/A","56859"
"*reg.exe query hklm\security\policy\secrets*",".{0,1000}reg\.exe\squery\shklm\\security\\policy\\secrets.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","#registry","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","56860"
"*reg.exe save HKLM\*",".{0,1000}reg\.exe\ssave\sHKLM\\.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","0","#registry","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","56861"
"*rekallreader.py*",".{0,1000}rekallreader\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","56916"
"*ReleaseKeePass.exe*",".{0,1000}ReleaseKeePass\.exe.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","56929"
"*ReleaseKeeTheft.exe*",".{0,1000}ReleaseKeeTheft\.exe.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","56930"
"*rem call nthash-win64 /getntlmhash*",".{0,1000}rem\scall\snthash\-win64\s\/getntlmhash.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","56933"
"*rem cheap bruteforce ... very slow ... ok for a few passwords*",".{0,1000}rem\scheap\sbruteforce\s\.\.\.\svery\sslow\s\.\.\.\sok\sfor\sa\sfew\spasswords.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","56934"
"*REM Title: Harvester_OF_SORROW*",".{0,1000}REM\sTitle\:\sHarvester_OF_SORROW.{0,1000}","offensive_tool_keyword","Harvester_OF_SORROW","The payload opens firefox about:logins and tabs and arrows its way through options. It then takes a screen shot with the first set of log in credentials made visible. Finally it sends the screenshot to an email of your choosing.","T1056.001 - T1113 - T1512 - T1566.001 - T1059.006","TA0004 - TA0009 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/blob/master/payloads/library/credentials/Harvester_OF_SORROW/payload.txt","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","56937"
"*RemoteDesktopPassView.zip*",".{0,1000}RemoteDesktopPassView\.zip.{0,1000}","offensive_tool_keyword","rdpv","RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.","T1110 - T1560.001 - T1555.003 - T1212","TA0006 - TA0007","N/A","Phobos - GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/remote_desktop_password.html","1","0","N/A","N/A","8","10","N/A","N/A","N/A","N/A","57017"
"*Remove-Item (Get-PSreadlineOption).HistorySavePath*",".{0,1000}Remove\-Item\s\(Get\-PSreadlineOption\)\.HistorySavePath.{0,1000}","offensive_tool_keyword","powershell","Delete powershell history","T1056.002 - T1566.001 - T1567.002","TA0004 - TA0040 - TA0010","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/-OMG-Credz-Plz","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","57088"
"*Remove-KeePassConfigTrigger*",".{0,1000}Remove\-KeePassConfigTrigger.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","1","N/A","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","57100"
"*RemoveKeePassTrigger.ps1*",".{0,1000}RemoveKeePassTrigger\.ps1.{0,1000}","offensive_tool_keyword","crackmapexec","Keepass exploitations from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","57101"
"*RePRGM/Nimperiments*",".{0,1000}RePRGM\/Nimperiments.{0,1000}","offensive_tool_keyword","EvilLsassTwin","Dumping lsass","T1003 - T1560.001 - T1022 - T1027.002","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin","1","1","N/A","N/A","10","2","151","18","2024-12-23T05:06:31Z","2022-09-13T12:42:13Z","57139"
"*Responder.py -I *",".{0,1000}Responder\.py\s\-I\s.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","57174"
"*RestartKeePass.ps1*",".{0,1000}RestartKeePass\.ps1.{0,1000}","offensive_tool_keyword","crackmapexec","Keepass exploitations from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","57187"
"*restic2john.py*",".{0,1000}restic2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","57200"
"*restore_signature.sh *.dmp*",".{0,1000}restore_signature\.sh\s.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","#linux","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","57202"
"*resuming a previous NTDS.DIT dump session*",".{0,1000}resuming\sa\sprevious\sNTDS\.DIT\sdump\ssession.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","57209"
"*resutlStrBrwsrOfshit*",".{0,1000}resutlStrBrwsrOfshit.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","57210"
"*returnvar/wce*",".{0,1000}returnvar\/wce.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","1","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","57220"
"*ricardojoserf/adfsbrute*",".{0,1000}ricardojoserf\/adfsbrute.{0,1000}","offensive_tool_keyword","adfsbrute","test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks","T1110.003 - T1110.001 - T1110","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ricardojoserf/adfsbrute","1","1","N/A","N/A","8","2","172","33","2021-04-23T16:43:59Z","2020-10-02T16:28:35Z","57301"
"*ricardojoserf/NativeDump*",".{0,1000}ricardojoserf\/NativeDump.{0,1000}","offensive_tool_keyword","NativeDump","Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/ricardojoserf/NativeDump","1","1","N/A","N/A","10","6","586","86","2024-12-17T15:36:57Z","2024-02-22T15:16:16Z","57303"
"*ricardojoserf/TrickDump*",".{0,1000}ricardojoserf\/TrickDump.{0,1000}","offensive_tool_keyword","TrickDump","Dump lsass using only NTAPIS running 3 programs to create 3 JSON and 1 ZIP file and generate the Minidump later!","T1003.001 - T1027.002 - T1106 - T1212","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/ricardojoserf/TrickDump","1","1","N/A","N/A","10","5","444","50","2025-02-06T20:49:56Z","2024-06-24T12:24:59Z","57304"
"*Ripemd-160.test-vectors.txt*",".{0,1000}Ripemd\-160\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","57322"
"*Riskware/WebBrowserPassView*",".{0,1000}Riskware\/WebBrowserPassView.{0,1000}","signature_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","57330"
"*riskydissonance/SafetyDump*",".{0,1000}riskydissonance\/SafetyDump.{0,1000}","offensive_tool_keyword","SafetyDump","in memory process dumper - uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output","T1003.005 - T1059.001 - T1105 - T1071.001","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","1","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","57331"
"*rockyou.txt.gz*",".{0,1000}rockyou\.txt\.gz.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","57428"
"*rockyou.txt.gz*",".{0,1000}rockyou\.txt\.gz.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","57429"
"*rockyou-30000.*",".{0,1000}rockyou\-30000\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","57430"
"*Romain Bentz (pixis - @hackanddo)*",".{0,1000}Romain\sBentz\s\(pixis\s\-\s\@hackanddo\).{0,1000}","offensive_tool_keyword","conpass","Continuous password spraying tool","T1110.001 - T1110 - T1078.001 - T1201","TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://github.com/login-securite/conpass","1","0","N/A","N/A","10","2","181","17","2025-03-03T15:05:25Z","2022-12-15T18:03:42Z","57448"
"*Ronedx765in Walledx765et*",".{0,1000}Ronedx765in\sWalledx765et.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","57449"
"*root cargo new --bin legba*",".{0,1000}root\scargo\snew\s\-\-bin\slegba.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","57454"
"*ropnop/kerbrute*",".{0,1000}ropnop\/kerbrute.{0,1000}","offensive_tool_keyword","kerbrute","A tool to perform Kerberos pre-auth bruteforcing","T1110.003 - T1558.001","TA0006 - TA0001","N/A","N/A","Credential Access","https://github.com/ropnop/kerbrute","1","1","N/A","N/A","10","10","2872","438","2024-08-20T10:56:06Z","2019-02-03T18:21:17Z","57479"
"*rotarydrone/GlobalUnProtect*",".{0,1000}rotarydrone\/GlobalUnProtect.{0,1000}","offensive_tool_keyword","GlobalUnProtect","Decrypt GlobalProtect configuration and cookie files.","T1552 - T1003 - T1555","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rotarydrone/GlobalUnProtect","1","1","N/A","N/A","9","2","147","19","2024-09-10T20:19:24Z","2024-09-04T15:31:52Z","57481"
"*RouterPassView.exe*",".{0,1000}RouterPassView\.exe.{0,1000}","offensive_tool_keyword","RouterPassView","help you to recover your lost password from your router file","T1002 - T1552 - T1027","TA0006 - TA0007","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/router_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57487"
"*routerpassview.zip*",".{0,1000}routerpassview\.zip.{0,1000}","offensive_tool_keyword","RouterPassView","help you to recover your lost password from your router file","T1002 - T1552 - T1027","TA0006 - TA0007","N/A","BlackSuit - Royal - GoGoogle","Credential Access","https://www.nirsoft.net/utils/router_password_recovery.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57488"
"*routerpasswords.com/*",".{0,1000}routerpasswords\.com\/.{0,1000}","offensive_tool_keyword","routerpasswords.com","find default routers passwords","T1110.003 - T1200","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md","1","1","N/A","N/A","N/A","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","57489"
"*RowTeam/SharpDecryptPwd*",".{0,1000}RowTeam\/SharpDecryptPwd.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","1","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","57492"
"*rpcdump.py * | grep MS-RPRN*",".{0,1000}rpcdump\.py\s.{0,1000}\s\|\sgrep\sMS\-RPRN.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","57510"
"*Rubeus*currentluid*",".{0,1000}Rubeus.{0,1000}currentluid.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57570"
"*Rubeus*harvest*",".{0,1000}Rubeus.{0,1000}harvest.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57571"
"*Rubeus*logonsession*",".{0,1000}Rubeus.{0,1000}logonsession.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57572"
"*Rubeus*monitor*",".{0,1000}Rubeus.{0,1000}monitor.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57573"
"*Rubeus.Commands*",".{0,1000}Rubeus\.Commands.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57575"
"*Rubeus.exe*",".{0,1000}Rubeus\.exe.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57578"
"*Rubeus.git*",".{0,1000}Rubeus\.git.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57580"
"*Rubeus.Kerberos*",".{0,1000}Rubeus\.Kerberos.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57581"
"*Rubeus.lib*",".{0,1000}Rubeus\.lib.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57582"
"*Rubeus-master*",".{0,1000}Rubeus\-master.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","1","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","57600"
"*rules/d3ad0ne.rule*",".{0,1000}rules\/d3ad0ne\.rule.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","57653"
"*run --rm -it xshuden/cheetah*",".{0,1000}run\s\-\-rm\s\-it\sxshuden\/cheetah.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","57668"
"*Run WCE indefinitely, waiting for new credentials/logon sessions*",".{0,1000}Run\sWCE\sindefinitely,\swaiting\sfor\snew\scredentials\/logon\ssessions.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","57673"
"*run_ppl_dump_exploit*",".{0,1000}run_ppl_dump_exploit.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","57675"
"*run_ppl_medic_exploit*",".{0,1000}run_ppl_medic_exploit.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","57676"
"*rundll32 *RunRubeus*",".{0,1000}rundll32\s.{0,1000}RunRubeus.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","57696"
"*rundll32*comsvcs.dll MiniDump *",".{0,1000}rundll32.{0,1000}comsvcs\.dll\sMiniDump\s.{0,1000}","greyware_tool_keyword","rundll32","Caling MiniDump function - dump memory of a process (often abused to dump lsass process)","T1218.011 - T1003","TA0006 - TA0005 - TA0002","N/A","Black Basta","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57703"
"*Running password spray against %d users*",".{0,1000}Running\spassword\sspray\sagainst\s\%d\susers.{0,1000}","offensive_tool_keyword","o365spray","Username enumeration and password spraying tool aimed at Microsoft O365","T1110.003 - T1087.002","TA0007 - TA0006","N/A","N/A","Credential Access","https://github.com/0xZDH/o365spray","1","0","#content","N/A","8","9","846","100","2024-11-06T00:49:23Z","2019-08-07T14:47:45Z","57722"
"*runZeroInc/sshamble*",".{0,1000}runZeroInc\/sshamble.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","57749"
"*rvazarkar/GMSAPasswordReader*",".{0,1000}rvazarkar\/GMSAPasswordReader.{0,1000}","offensive_tool_keyword","GMSAPasswordReader","Reads the password blob from a GMSA account using LDAP and parses the values into hashes for re-use.","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/rvazarkar/GMSAPasswordReader","1","1","N/A","N/A","7","3","219","34","2023-02-17T14:37:40Z","2020-01-19T19:06:20Z","57790"
"*rvrsh3ll/Rubeus-Rundll32*",".{0,1000}rvrsh3ll\/Rubeus\-Rundll32.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","1","N/A","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","57794"
"*rvrsh3ll/SharpEdge*",".{0,1000}rvrsh3ll\/SharpEdge.{0,1000}","offensive_tool_keyword","SharpEdge","C# Implementation of Get-VaultCredential - Displays Windows vault credential objects including cleartext web credentials - based on https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-VaultCredential.ps1","T1555.004 - T1552.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/SharpEdge","1","1","N/A","N/A","10","1","14","7","2018-07-31T01:31:21Z","2018-07-31T09:54:11Z","57796"
"*rvrsh3ll/TokenTactics*",".{0,1000}rvrsh3ll\/TokenTactics.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","57798"
"*'S','e','D','e','b','u','g','P','r','i','v','i','l','e','g','e'*",".{0,1000}\'S\',\'e\',\'D\',\'e\',\'b\',\'u\',\'g\',\'P\',\'r\',\'i\',\'v\',\'i\',\'l\',\'e\',\'g\',\'e\'.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","57809"
"*S12cybersecurity/RDPCredentialStealer*",".{0,1000}S12cybersecurity\/RDPCredentialStealer.{0,1000}","offensive_tool_keyword","RDPCredentialStealer","RDPCredentialStealer it's a malware that steal credentials provided by users in RDP using API Hooking with Detours in C++","T1555.001 - T1059.002 - T1552.002","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/S12cybersecurity/RDPCredentialStealer","1","1","N/A","N/A","10","3","245","37","2023-06-14T10:25:33Z","2023-06-13T01:30:26Z","57817"
"*S3cur3Th1sSh1t/SharpVeeamDecryptor*",".{0,1000}S3cur3Th1sSh1t\/SharpVeeamDecryptor.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","1","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","57828"
"*S74r77Hr34D(*",".{0,1000}S74r77Hr34D\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","57847"
"*s74r787Hr34D(*",".{0,1000}s74r787Hr34D\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","57848"
"*sadshade/veeam-creds*",".{0,1000}sadshade\/veeam\-creds.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","57854"
"*safedv/RustiveDump*",".{0,1000}safedv\/RustiveDump.{0,1000}","offensive_tool_keyword","RustiveDump","LSASS memory dumper using only NTAPIs","T1003.001 - T1055 - T1106","TA0006 - TA0008 - TA0011","N/A","N/A","Credential Access","https://github.com/safedv/RustiveDump","1","1","N/A","N/A","10","4","332","43","2025-03-08T12:10:35Z","2024-10-06T16:01:49Z","57863"
"*SafetyDump.exe *",".{0,1000}SafetyDump\.exe\s.{0,1000}","offensive_tool_keyword","SafetyDump","uses the Minidump Windows API to dump process memory before base64 encoding that dump and writing it to standard output. This allows the dump to be redirected to a file or straight back down C2 or through other tools","T1003 - T1140 - T1071 - T1105","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/riskydissonance/SafetyDump","1","0","N/A","N/A","10","2","162","16","2020-10-29T16:25:04Z","2019-12-10T14:45:17Z","57865"
"*SafetyKatz.csproj*",".{0,1000}SafetyKatz\.csproj.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","57868"
"*SafetyKatz.exe*",".{0,1000}SafetyKatz\.exe.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","57871"
"*SafetyKatz.sln*",".{0,1000}SafetyKatz\.sln.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","57876"
"*SafetyKatz-master*",".{0,1000}SafetyKatz\-master.{0,1000}","offensive_tool_keyword","SafetyKatz","SafetyKatz is a combination of slightly modified version of @gentilkiwis Mimikatz project and @subtees .NET PE Loader. First. the MiniDumpWriteDump Win32 API call is used to create a minidump of LSASS to C:\Windows\Temp\debug.bin. Then @subtees PELoader is used to load a customized version of Mimikatz that runs sekurlsa::logonpasswords and sekurlsa::ekeys on the minidump file. removing the file after execution is complete","T1003 - T1055 - T1059 - T1574","TA0002 - TA0003 - TA0008","N/A","APT39","Credential Access","https://github.com/GhostPack/SafetyKatz","1","1","N/A","N/A","10","10","1257","247","2019-10-01T16:47:21Z","2018-07-24T17:44:15Z","57879"
"*SAM hashes extraction for user * failed*",".{0,1000}SAM\shashes\sextraction\sfor\suser\s.{0,1000}\sfailed.{0,1000}","offensive_tool_keyword","donpapi","Dumping DPAPI credentials remotely","T1003.006 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/login-securite/DonPAPI","1","0","N/A","N/A","N/A","10","1110","130","2025-03-24T10:23:58Z","2021-09-27T09:12:51Z","57889"
"*samdump.zip*",".{0,1000}samdump\.zip.{0,1000}","offensive_tool_keyword","samdump","Dumping sam","T1003","TA0006","N/A","N/A","Credential Access","https://github.com/nyxgeek/classic_hacking_tools","1","1","N/A","N/A","N/A","1","4","1","2024-06-27T09:35:42Z","2023-04-16T01:49:12Z","57900"
"*samdump2 *",".{0,1000}samdump2\s.{0,1000}","offensive_tool_keyword","samdump2","Retrieves syskey and extract hashes from Windows 2k/NT/XP/Vista SAM.","T1003.002 - T1564.001","TA0006 - TA0010","N/A","Black Basta","Credential Access","https://salsa.debian.org/pkg-security-team/samdump2","1","0","N/A","N/A","10","6","N/A","N/A","N/A","N/A","57901"
"*samdump2 SYSTEM SAM*",".{0,1000}samdump2\sSYSTEM\sSAM.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","57903"
"*samdump2.c*",".{0,1000}samdump2\.c.{0,1000}","offensive_tool_keyword","samdump2","Retrieves syskey and extract hashes from Windows 2k/NT/XP/Vista SAM.","T1003.002 - T1564.001","TA0006 - TA0010","N/A","Black Basta","Credential Access","https://salsa.debian.org/pkg-security-team/samdump2","1","0","N/A","N/A","10","6","N/A","N/A","N/A","N/A","57904"
"*SamOfflineConnect*",".{0,1000}SamOfflineConnect.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57905"
"*SamOfflineEnumerateDomainsInSamServer*",".{0,1000}SamOfflineEnumerateDomainsInSamServer.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57906"
"*SamOfflineEnumerateUsersInDomain2*",".{0,1000}SamOfflineEnumerateUsersInDomain2.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57907"
"*SamOfflineGetMembersInAlias*",".{0,1000}SamOfflineGetMembersInAlias.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57908"
"*SamOfflineLookupDomainInSamServer*",".{0,1000}SamOfflineLookupDomainInSamServer.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57909"
"*SamOfflineOpenDomain*",".{0,1000}SamOfflineOpenDomain.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57910"
"*SamOfflineOpenUser*",".{0,1000}SamOfflineOpenUser.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57911"
"*SamOfflineQueryInformationAlias*",".{0,1000}SamOfflineQueryInformationAlias.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57912"
"*SamOfflineQueryInformationUser*",".{0,1000}SamOfflineQueryInformationUser.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57913"
"*SamOfflineRemoveMemberFromAlias*",".{0,1000}SamOfflineRemoveMemberFromAlias.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57914"
"*SamOfflineRidToSid*",".{0,1000}SamOfflineRidToSid.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57915"
"*SamOfflineSetInformationAlias*",".{0,1000}SamOfflineSetInformationAlias.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57916"
"*sampasswd -*",".{0,1000}sampasswd\s\-.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57917"
"*samunlock -*",".{0,1000}samunlock\s\-.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57924"
"*samusrgrp -a *",".{0,1000}samusrgrp\s\-a\s.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57925"
"*samusrgrp -r *",".{0,1000}samusrgrp\s\-r\s.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","57926"
"*sap2john.pl*",".{0,1000}sap2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","57935"
"*sccmdecryptpoc.*",".{0,1000}sccmdecryptpoc\..{0,1000}","offensive_tool_keyword","sccmdecryptpoc","SCCM Account Password Decryption POC","T1555.003","TA0006","N/A","N/A","Credential Access","https://gist.github.com/xpn/5f497d2725a041922c427c3aaa3b37d1","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","58151"
"*SCOMDecrypt.csproj*",".{0,1000}SCOMDecrypt\.csproj.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","58192"
"*SCOMDecrypt.exe*",".{0,1000}SCOMDecrypt\.exe.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","58193"
"*SCOMDecrypt.ps1*",".{0,1000}SCOMDecrypt\.ps1.{0,1000}","offensive_tool_keyword","SCOMDecrypt","SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers","T1552.001 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/nccgroup/SCOMDecrypt","1","1","N/A","N/A","10","2","123","22","2023-11-10T07:04:26Z","2017-02-21T16:15:11Z","58194"
"*ScriptSentry-main.zip*",".{0,1000}ScriptSentry\-main\.zip.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","58243"
"*Search your passwords as normal user*",".{0,1000}Search\syour\spasswords\sas\snormal\suser.{0,1000}","offensive_tool_keyword","LostMyPassword","Nirsoft tool that allows you to recover a lost password if it's stored by a software installed on your system","T1040 - T1003 - T1078 - T1518 - T1555","TA0006 - TA0009 ","N/A","LockBit","Credential Access","https://www.nirsoft.net/alpha/lostmypassword-x64.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","58258"
"*Searching for master credentials (2/2)*",".{0,1000}Searching\sfor\smaster\scredentials\s\(2\/2\).{0,1000}","offensive_tool_keyword","pandora","A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers","T1555 - T1003","TA0006 - TA0003","N/A","N/A","Credential Access","https://github.com/efchatz/pandora","1","0","#content","N/A","10","8","738","88","2025-01-09T14:58:57Z","2023-11-03T18:01:31Z","58265"
"*--seclogon-leak-local*",".{0,1000}\-\-seclogon\-leak\-local.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","58291"
"*--seclogon-leak-remote*",".{0,1000}\-\-seclogon\-leak\-remote.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","58292"
"*SecretFinder.py*",".{0,1000}SecretFinder\.py.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","1","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","58298"
"*SecretFinder-master.zip*",".{0,1000}SecretFinder\-master\.zip.{0,1000}","offensive_tool_keyword","secretfinder","SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files","T1083 - T1081 - T1113","TA0003 - TA0002 - TA0007","N/A","N/A","Credential Access","https://github.com/m4ll0k/SecretFinder","1","1","N/A","N/A","N/A","10","2153","405","2024-05-26T09:36:41Z","2020-06-08T10:50:12Z","58299"
"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","gosecretsdump","Dump ntds.dit really fast","T1003","TA0006","N/A","Lockbit - Black Basta","Credential Access","https://github.com/C-Sto/gosecretsdump","1","1","N/A","N/A","10","4","391","50","2021-10-01T09:11:33Z","2018-12-24T05:54:19Z","58308"
"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","impacket","Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself","T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047","TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011","N/A","Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","58309"
"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","secretsdump","secretdump.py from impacket - https://github.com/fortra/impacket","T1003.003","TA0006","Operation Wocao","Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE","Credential Access","https://github.com/fortra/impacket","1","0","N/A","N/A","10","10","14198","3681","2025-04-22T13:40:55Z","2015-04-15T14:04:07Z","58317"
"*secretsdump.py*",".{0,1000}secretsdump\.py.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","58318"
"*securesean/DecryptAutoLogon*",".{0,1000}securesean\/DecryptAutoLogon.{0,1000}","offensive_tool_keyword","DecryptAutoLogon","Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon","T1003.001 - T1555.003 - T1003.006","TA0006","N/A","N/A","Credential Access","https://github.com/securesean/DecryptAutoLogon","1","1","N/A","N/A","10","3","218","32","2020-12-05T16:14:28Z","2020-12-03T20:38:59Z","58326"
"*SecUser1/Necro-Stealer*",".{0,1000}SecUser1\/Necro\-Stealer.{0,1000}","offensive_tool_keyword","Necro-Stealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/Necro-Stealer","1","1","N/A","N/A","8","1","6","1","2022-12-06T16:06:55Z","2022-12-06T15:52:17Z","58331"
"*SecUser1/PredatorTheStealer*",".{0,1000}SecUser1\/PredatorTheStealer.{0,1000}","offensive_tool_keyword","PredatorTheStealer","C++ stealer (passwords - cookies - forms - cards - wallets) ","T1078 - T1114 - T1555 - T1539 - T1212 - T1132","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/SecUser1/PredatorTheStealer","1","1","N/A","N/A","8","1","11","2","2022-12-06T16:46:33Z","2022-12-06T16:34:43Z","58332"
"*sed -i -e 's/ArgumentPtr/NotTodayPal/*",".{0,1000}sed\s\-i\s\-e\s\'s\/ArgumentPtr\/NotTodayPal\/.{0,1000}","offensive_tool_keyword","mimidogz","Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection","T1055 - T1560.001 - T1110.001 - T1003 - T1071","TA0005 - TA0040 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/projectb-temp/mimidogz","1","0","N/A","N/A","10","1","0","0","2019-02-11T10:14:10Z","2019-02-11T10:12:08Z","58334"
"*sekurlsa *",".{0,1000}sekurlsa\s.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation command","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","58339"
"*sekurlsa::logonPasswords full*",".{0,1000}sekurlsa\:\:logonPasswords\sfull.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","58350"
"*sekurlsa::minidump debug.out*",".{0,1000}sekurlsa\:\:minidump\sdebug\.out.{0,1000}","offensive_tool_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","N/A","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","58352"
"*SELECT host_key, name, path, encrypted_value, expires_utc FROM cookies*",".{0,1000}SELECT\shost_key,\sname,\spath,\sencrypted_value,\sexpires_utc\sFROM\scookies.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","58368"
"*SELECT host_key, name, path, encrypted_value, expires_utc FROM cookies*",".{0,1000}SELECT\shost_key,\sname,\spath,\sencrypted_value,\sexpires_utc\sFROM\scookies.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","58369"
"*SELECT name_on_card, expiration_month, expiration_year, card_number_encrypted FROM credit_cards*",".{0,1000}SELECT\sname_on_card,\sexpiration_month,\sexpiration_year,\scard_number_encrypted\sFROM\scredit_cards.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","58371"
"*SELECT origin_url, username_value, password_value FROM logins*",".{0,1000}SELECT\sorigin_url,\susername_value,\spassword_value\sFROM\slogins.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","58372"
"*SELECT origin_url, username_value, password_value FROM logins*",".{0,1000}SELECT\sorigin_url,\susername_value,\spassword_value\sFROM\slogins.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","58373"
"*SELECT user_name, password FROM VeeamBackup.dbo.Credentials*",".{0,1000}SELECT\suser_name,\spassword\sFROM\sVeeamBackup\.dbo\.Credentials.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","0","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","58375"
"*self.sprayer.auth_O365*",".{0,1000}self\.sprayer\.auth_O365.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","58379"
"*Semperis/GoldenGMSA*",".{0,1000}Semperis\/GoldenGMSA.{0,1000}","offensive_tool_keyword","GoldenGMSA","GolenGMSA tool for working with GMSA passwords","T1003.004 - T1078.003 - T1059.006","TA0006 - TA0004 - TA0002","N/A","N/A","Credential Access","https://github.com/Semperis/GoldenGMSA","1","1","N/A","N/A","7","2","144","22","2024-04-11T07:51:57Z","2022-02-03T10:32:05Z","58385"
"*sense2john.py*",".{0,1000}sense2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","58418"
"*servpw.exe*",".{0,1000}servpw\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","58507"
"*servpw64.exe*",".{0,1000}servpw64\.exe.{0,1000}","offensive_tool_keyword","fgdump","A utility for dumping passwords on Windows NT/2000/XP/2003 machines","T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001","TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008","N/A","Volt Typhoon","Credential Access","https://gitlab.com/kalilinux/packages/windows-binaries/-/tree/kali/master/fgdump","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","58508"
"*set_rpc_callstack*",".{0,1000}set_rpc_callstack.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","58562"
"*set_svchost_callstack*",".{0,1000}set_svchost_callstack.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","58564"
"*set_wmi_callstack*",".{0,1000}set_wmi_callstack.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","58565"
"*Set-DomainObject*",".{0,1000}Set\-DomainObject.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Targeted kerberoasting by setting SPN","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","58624"
"*setspn -A HTTP/*",".{0,1000}setspn\s\-A\sHTTP\/.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","0","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","58672"
"*setspn -T medin -Q */*",".{0,1000}setspn\s\-T\smedin\s\-Q\s.{0,1000}\/.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","0","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","58673"
"*setspn.exe -T medin -Q */*",".{0,1000}setspn\.exe\s\-T\smedin\s\-Q\s.{0,1000}\/.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","0","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","58675"
"*Setting up GFlags & SilentProcessExit settings in registry?*",".{0,1000}Setting\sup\sGFlags\s\&\sSilentProcessExit\ssettings\sin\sregistry\?.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","0","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","58680"
"*Sha-2-*512.unverified.test-vectors.txt*",".{0,1000}Sha\-2\-.{0,1000}512\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","58715"
"*Sha-2-256.unverified.test-vectors.txt*",".{0,1000}Sha\-2\-256\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","58716"
"*Sha-2-384.unverified.test-vectors.txt*",".{0,1000}Sha\-2\-384\.unverified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","58717"
"*shadowCredObject.NTHash*",".{0,1000}shadowCredObject\.NTHash.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#content","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","58731"
"*shadowCredObject.samAccountName*",".{0,1000}shadowCredObject\.samAccountName.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#content","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","58732"
"*ShadowDumper.exe*",".{0,1000}ShadowDumper\.exe.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","1","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","58734"
"*ShadowSpray.exe*",".{0,1000}ShadowSpray\.exe.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","1","N/A","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","58762"
"*ShadowSpray.Kerb/1.0*",".{0,1000}ShadowSpray\.Kerb\/1\.0.{0,1000}","offensive_tool_keyword","ShadowSpray","A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.","T1556.005 - T1098.001 - T1098","TA0006 - TA0008 - TA0004","N/A","Black Basta","Credential Access","https://github.com/Dec0ne/ShadowSpray","1","0","#useragent","N/A","10","5","459","80","2022-10-14T13:36:51Z","2022-10-10T08:34:07Z","58765"
"*ShadowStealer.zip*",".{0,1000}ShadowStealer\.zip.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","1","N/A","N/A","10","","N/A","","","","58768"
"*shareenum.py*",".{0,1000}shareenum\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","58779"
"*SharpAltSecIds add*",".{0,1000}SharpAltSecIds\sadd.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","58813"
"*SharpAltSecIds by @bugch3ck*",".{0,1000}SharpAltSecIds\sby\s\@bugch3ck.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","#content","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","58814"
"*SharpAltSecIds command*",".{0,1000}SharpAltSecIds\scommand.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","58815"
"*SharpAltSecIds l /target:*",".{0,1000}SharpAltSecIds\sl\s\/target\:.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","58816"
"*SharpAltSecIds list*",".{0,1000}SharpAltSecIds\slist.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","58817"
"*SharpAltSecIds r /target:*",".{0,1000}SharpAltSecIds\sr\s\/target\:.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","58818"
"*SharpAltSecIds remove*",".{0,1000}SharpAltSecIds\sremove.{0,1000}","offensive_tool_keyword","SharpAltSecIds","Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate","T1098.003 - T1556.002 - T1078","TA0003 - TA0004 - TA0006","N/A","N/A","Credential Access","https://github.com/bugch3ck/SharpAltSecIds","1","0","N/A","N/A","9","1","12","3","2022-05-30T13:50:05Z","2022-05-30T13:40:17Z","58819"
"*SharpBruteForceSSH.cs*",".{0,1000}SharpBruteForceSSH\.cs.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","1","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","58836"
"*SharpBruteForceSSH.exe*",".{0,1000}SharpBruteForceSSH\.exe.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","1","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","58837"
"*SharpChrome* backupkey *.pvk*",".{0,1000}SharpChrome.{0,1000}\sbackupkey\s.{0,1000}\.pvk.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58859"
"*SharpChromium.csproj*",".{0,1000}SharpChromium\.csproj.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","58863"
"*SharpChromium.exe*",".{0,1000}SharpChromium\.exe.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","58864"
"*SharpChromium.sln*",".{0,1000}SharpChromium\.sln.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","58866"
"*SharpChromium-master*",".{0,1000}SharpChromium\-master.{0,1000}","offensive_tool_keyword","SharpChromium",".NET 4.0 CLR Project to retrieve Chromium data such as cookies - history and saved logins.","T1555.003 - T1114.001 - T1555.004","TA0006 - TA0003","N/A","COZY BEAR","Credential Access","https://github.com/djhohnstein/SharpChromium","1","1","N/A","N/A","10","8","712","100","2020-10-23T22:28:13Z","2018-08-06T21:25:21Z","58867"
"*SharpClipboard.exe*",".{0,1000}SharpClipboard\.exe.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","1","N/A","N/A","8","1","N/A","N/A","N/A","N/A","58868"
"*SharpClipboard-master.zip*",".{0,1000}SharpClipboard\-master\.zip.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","1","N/A","N/A","8","1","N/A","N/A","N/A","N/A","58869"
"*sharpcloud.cna*",".{0,1000}sharpcloud\.cna.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","58871"
"*SharpCloud.csproj*",".{0,1000}SharpCloud\.csproj.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","58872"
"*SharpCloud.exe*",".{0,1000}SharpCloud\.exe.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","58873"
"*SharpCloud.sln*",".{0,1000}SharpCloud\.sln.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","58875"
"*SharpCloud-master*",".{0,1000}SharpCloud\-master.{0,1000}","offensive_tool_keyword","SharpCloud","Simple C# for checking for the existence of credential files related to AWS - Microsoft Azure and Google Compute.","T1083 - T1059.001 - T1114.002","TA0007 - TA0002 ","N/A","N/A","Credential Access","https://github.com/chrismaddalena/SharpCloud","1","1","N/A","N/A","10","2","171","29","2018-09-18T02:24:10Z","2018-08-20T15:06:22Z","58876"
"*SharpDecryptPwd *",".{0,1000}SharpDecryptPwd\s.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","58898"
"*SharpDecryptPwd.Commands*",".{0,1000}SharpDecryptPwd\.Commands.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","58899"
"*SharpDecryptPwd.csproj*",".{0,1000}SharpDecryptPwd\.csproj.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","58900"
"*SharpDecryptPwd.exe*",".{0,1000}SharpDecryptPwd\.exe.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","1","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","58901"
"*SharpDecryptPwd.exe*",".{0,1000}SharpDecryptPwd\.exe.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","1","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","58902"
"*SharpDecryptPwd.Lib*",".{0,1000}SharpDecryptPwd\.Lib.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","58903"
"*SharpDecryptPwd.Properties*",".{0,1000}SharpDecryptPwd\.Properties.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","58904"
"*SharpDomainSpray*",".{0,1000}SharpDomainSpray.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","0","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","58907"
"*SharpDomainSpray.*",".{0,1000}SharpDomainSpray\..{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","1","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","58908"
"*SharpDomainSpray-master*",".{0,1000}SharpDomainSpray\-master.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","1","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","58909"
"*SharpDPAPI backupkey*",".{0,1000}SharpDPAPI\sbackupkey.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58915"
"*SharpDPAPI* credentias *",".{0,1000}SharpDPAPI.{0,1000}\scredentias\s.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58920"
"*SharpDPAPI* vaults *",".{0,1000}SharpDPAPI.{0,1000}\svaults\s.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58921"
"*SharpDPAPI.csproj*",".{0,1000}SharpDPAPI\.csproj.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58923"
"*SharpDPAPI.Domain*",".{0,1000}SharpDPAPI\.Domain.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58924"
"*SharpDPAPI.exe*",".{0,1000}SharpDPAPI\.exe.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58926"
"*SharpDPAPI.Helpers.*",".{0,1000}SharpDPAPI\.Helpers\..{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","0","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58928"
"*SharpDPAPI.ps1*",".{0,1000}SharpDPAPI\.ps1.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58929"
"*SharpDPAPI.sln*",".{0,1000}SharpDPAPI\.sln.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58930"
"*SharpDPAPI.txt*",".{0,1000}SharpDPAPI\.txt.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58931"
"*SharpDPAPI-master*",".{0,1000}SharpDPAPI\-master.{0,1000}","offensive_tool_keyword","SharpDPAPI","SharpDPAPI is a C# port of some Mimikatz DPAPI functionality.","T1552.002 - T1059.001 - T1112 - T1649","TA0006 - TA0002","N/A","Conti","Credential Access","https://github.com/GhostPack/SharpDPAPI","1","1","N/A","N/A","10","10","1232","215","2024-06-27T13:39:08Z","2018-08-22T17:39:31Z","58934"
"*SharpLAPS.csproj*",".{0,1000}SharpLAPS\.csproj.{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","1","N/A","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","59058"
"*SharpLAPS.exe*",".{0,1000}SharpLAPS\..{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","1","N/A","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","59060"
"*SharpLAPS.sln*",".{0,1000}SharpLAPS\.sln.{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","1","N/A","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","59061"
"*SharpLAPS-main*",".{0,1000}SharpLAPS\-main.{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","0","N/A","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","59062"
"*SharpMiniDump.exe*",".{0,1000}SharpMiniDump\.exe.{0,1000}","offensive_tool_keyword","SharpMiniDump","Create a minidump of the LSASS process from memory","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/b4rtik/SharpMiniDump","1","1","N/A","N/A","10","3","260","49","2022-11-02T15:47:30Z","2019-09-15T13:45:42Z","59073"
"*SharpRDPThief is a C# implementation of RDPThief*",".{0,1000}SharpRDPThief\sis\sa\sC\#\simplementation\sof\sRDPThief.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","0","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","59106"
"*SharpRDPThief.csproj*",".{0,1000}SharpRDPThief\.csproj.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","1","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","59107"
"*SharpRDPThief.exe*",".{0,1000}SharpRDPThief\.exe.{0,1000}","offensive_tool_keyword","SharpRDPThief","A C# implementation of RDPThief to steal credentials from RDP","T1056.004 - T1110 - T1563.002","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/passthehashbrowns/SharpRDPThief","1","1","N/A","N/A","10","2","160","28","2020-08-28T03:48:51Z","2020-08-26T22:27:36Z","59108"
"*SharpSAMDump.exe*",".{0,1000}SharpSAMDump\.exe.{0,1000}","offensive_tool_keyword","SharpSAMDump","SAM dumping via the registry in C#/.NET","T1003.002 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/jojonas/SharpSAMDump","1","1","N/A","N/A","10","1","48","8","2025-01-16T07:08:58Z","2024-05-27T10:53:27Z","59115"
"*SharpSecDump Info*",".{0,1000}SharpSecDump\sInfo.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","0","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","59125"
"*SharpSecDump.csproj*",".{0,1000}SharpSecDump\.csproj.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","59126"
"*SharpSecDump.exe*",".{0,1000}SharpSecDump\.exe.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","59128"
"*SharpSecDump.sln*",".{0,1000}SharpSecDump\.sln.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","59129"
"*SharpSecDump-master*",".{0,1000}SharpSecDump\-master.{0,1000}","offensive_tool_keyword","SharpSecDump",".Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py","T1003 - T1558","TA0006","N/A","Black Basta - Dispossessor","Credential Access","https://github.com/G0ldenGunSec/SharpSecDump","1","1","N/A","N/A","10","7","609","74","2023-02-16T18:47:26Z","2020-09-01T04:30:24Z","59130"
"*SharpSpray*",".{0,1000}SharpSpray.{0,1000}","offensive_tool_keyword","SharpSpray","This project is a C# port of my PowerSpray.ps1 script. SharpSpray a simple code set to perform a password spraying attack against all users of a domain using LDAP and is compatible with Cobalt Strike.","T1110 - T1558","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/jnqpblc/SharpSpray","1","1","N/A","N/A","N/A","2","195","36","2019-06-30T03:10:52Z","2019-03-04T17:14:07Z","59184"
"*SharpSpray.exe *",".{0,1000}SharpSpray\.exe\s.{0,1000}","offensive_tool_keyword","SharpDomainSpray","Basic password spraying tool for internal tests and red teaming","T1069 - T1021 - T1136 - T1018","TA0007 - TA0003 - TA0002 - TA0001","N/A","N/A","Credential Access","https://github.com/HunnicCyber/SharpDomainSpray","1","0","N/A","N/A","10","1","90","18","2020-03-21T09:17:48Z","2019-06-05T10:47:05Z","59185"
"*SharpSpray\Program.cs*",".{0,1000}SharpSpray\\Program\.cs.{0,1000}","offensive_tool_keyword","SharpSpray","SharpSpray is a Windows domain password spraying tool written in .NET C#","T1110","TA0006","N/A","N/A","Credential Access","https://github.com/iomoath/SharpSpray","1","0","N/A","N/A","10","2","130","21","2021-11-25T19:13:56Z","2021-08-31T16:09:45Z","59187"
"*SharpVeeamDecryptor.exe*",".{0,1000}SharpVeeamDecryptor\.exe.{0,1000}","offensive_tool_keyword","SharpVeeamDecryptor","Decrypt Veeam database passwords","T1555.005 - T1003 - T1059","TA0006 - TA0005 - TA0008","N/A","N/A","Credential Access","https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor","1","1","N/A","used by EMBARGO Ransomware","10","2","158","18","2023-11-07T14:00:47Z","2023-11-07T14:00:45Z","59243"
"*SharpWeb.exe -*",".{0,1000}SharpWeb\.exe\s\-.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","59250"
"*Shellcode path changed:*shellcode_path*",".{0,1000}Shellcode\spath\schanged\:.{0,1000}shellcode_path.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","N/A","print output","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","59307"
"*shmilylty/cheetah*",".{0,1000}shmilylty\/cheetah.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","1","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","59395"
"*shocknawe.py*",".{0,1000}shocknawe\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","59396"
"*shucknt.php*",".{0,1000}shucknt\.php.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","59423"
"*ShuckNT-main*",".{0,1000}ShuckNT\-main.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","59424"
"*ShutdownRepo/pywhisker*",".{0,1000}ShutdownRepo\/pywhisker.{0,1000}","offensive_tool_keyword","pywhisker","Python version of the C# tool for Shadow Credentials attacks","T1552.001 - T1136 - T1098","TA0003 - TA0004 - TA0005","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/pywhisker","1","1","N/A","N/A","10","8","712","89","2025-04-21T16:53:22Z","2021-07-21T19:20:00Z","59425"
"*ShutdownRepo/smartbrute*",".{0,1000}ShutdownRepo\/smartbrute.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","1","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","59427"
"*Shwmae dump *",".{0,1000}Shwmae\sdump\s.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","59428"
"*Shwmae enum *",".{0,1000}Shwmae\senum\s.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","59429"
"*Shwmae prt *",".{0,1000}Shwmae\sprt\s.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","59430"
"*Shwmae prt *",".{0,1000}Shwmae\sprt\s.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","59431"
"*Shwmae sign *",".{0,1000}Shwmae\ssign\s.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","59432"
"*Shwmae webauthn *",".{0,1000}Shwmae\swebauthn\s.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","59433"
"*Shwmae webauthn*",".{0,1000}Shwmae\swebauthn.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","59434"
"*Shwmae.exe sign*",".{0,1000}Shwmae\.exe\ssign.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","59435"
"*signal2john.py*",".{0,1000}signal2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","59451"
"*SilentProcessExitRegistrySetter.cpp*",".{0,1000}SilentProcessExitRegistrySetter\.cpp.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","59484"
"*SilentProcessExitRegistrySetter.exe*",".{0,1000}SilentProcessExitRegistrySetter\.exe.{0,1000}","offensive_tool_keyword","LsassSilentProcessExit","Command line interface to dump LSASS memory to disk via SilentProcessExit","T1003.001 - T1059.003","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/deepinstinct/LsassSilentProcessExit","1","1","N/A","N/A","10","5","445","61","2020-12-23T11:51:21Z","2020-11-29T08:49:42Z","59485"
"*Simone Margaritelli *",".{0,1000}Simone\sMargaritelli\s\.{0,1000}","offensive_tool_keyword","legba","A multiprotocol credentials bruteforcer / password sprayer and enumerator","T1110 - T1110.003 - T1110.001","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/evilsocket/legba","1","0","N/A","N/A","10","10","1577","93","2025-03-01T15:42:29Z","2023-10-23T15:44:06Z","59495"
"*sipdump2john.py*",".{0,1000}sipdump2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","59564"
"*skahwah*wordsmith*",".{0,1000}skahwah.{0,1000}wordsmith.{0,1000}","offensive_tool_keyword","wordsmith","The aim of Wordsmith is to assist with creating tailored wordlists and usernames that are primarilly based on geolocation.","T1210.001 - T1583.001 - T1583.002","TA0007 - ","N/A","N/A","Credential Access","https://github.com/skahwah/wordsmith","1","1","N/A","N/A","N/A","2","167","20","2018-05-03T13:44:01Z","2016-07-06T14:02:51Z","59579"
"*Slowerzs/PPLSystem*","Slowerzs\/PPLSystem","offensive_tool_keyword","PPLSystem","creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.","T1003.002","TA0006","N/A","N/A","Credential Access","https://github.com/Slowerzs/PPLSystem","1","1","N/A","N/A","10","2","190","23","2024-05-29T18:33:35Z","2024-05-22T17:48:49Z","59638"
"*Slowerzs/ThievingFox*",".{0,1000}Slowerzs\/ThievingFox.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","1","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","59639"
"*slyd0g/SharpClipboard*",".{0,1000}slyd0g\/SharpClipboard.{0,1000}","offensive_tool_keyword","SharpClipboard","monitor the content of the clipboard continuously","T1115","TA0006 - TA0009","N/A","N/A","Credential Access","http://github.com/slyd0g/SharpClipboard","1","1","N/A","N/A","8","1","N/A","N/A","N/A","N/A","59643"
"*smart_try_password_or_hash(*",".{0,1000}smart_try_password_or_hash\(.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","59646"
"*smartbrute%2520brute*",".{0,1000}smartbrute\%2520brute.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","59648"
"*smartbrute.py*",".{0,1000}smartbrute\.py.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","1","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","59649"
"*smb.dcsync*",".{0,1000}smb\.dcsync.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","59655"
"*smb_stealth.py*",".{0,1000}smb_stealth\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","59673"
"*-smb2support --no-wcf-server --no-smb-server --no-http-server*",".{0,1000}\-smb2support\s\-\-no\-wcf\-server\s\-\-no\-smb\-server\s\-\-no\-http\-server.{0,1000}","offensive_tool_keyword","lsarelayx","lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on","T1557.001 - T1187 - T1558","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/CCob/lsarelayx","1","0","N/A","N/A","10","6","562","69","2023-04-25T23:15:33Z","2021-11-12T18:55:01Z","59677"
"*smbrelayclient.py*",".{0,1000}smbrelayclient\.py.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","1","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","59718"
"*smbserver.py -payload*",".{0,1000}smbserver\.py\s\-payload.{0,1000}","offensive_tool_keyword","PPLFault","Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.","T1055 - T1078 - T1112 - T1553 - T1555","TA0001 - TA0002 - TA0003 - TA0005 - TA0011","N/A","N/A","Credential Access","https://github.com/gabriellandau/PPLFault","1","0","N/A","N/A","10","6","525","82","2024-02-22T17:23:53Z","2022-09-22T19:39:24Z","59729"
"*smbspider.py*",".{0,1000}smbspider\.py.{0,1000}","offensive_tool_keyword","crackmapexec","protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","1","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","59734"
"*smtp-user-enum*",".{0,1000}smtp\-user\-enum.{0,1000}","offensive_tool_keyword","smtp-user-enum","Username guessing tool primarily for use against the default Solaris SMTP service. Can use either EXPN - VRFY or RCPT TO.","T1133 - T1110.001","TA0007 - TA0006","N/A","N/A","Credential Access","https://pentestmonkey.net/tools/user-enumeration/smtp-user-enum","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","59757"
"*Smug246/Luna-Grabber*",".{0,1000}Smug246\/Luna\-Grabber.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","1","N/A","N/A","10","","N/A","","","","59759"
"*SniffPass.exe*",".{0,1000}SniffPass\.exe.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","59800"
"*sniffpass-x64.zip*",".{0,1000}sniffpass\-x64\.zip.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","59801"
"*Software\NirSoft\SniffPass*",".{0,1000}Software\\NirSoft\\SniffPass.{0,1000}","offensive_tool_keyword","SniffPass","password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly","T1040 - T1071 - T1041","TA0006 - TA0007 - TA0009","N/A","GoGoogle - Kimsuky","Credential Access","https://www.nirsoft.net/utils/password_sniffer.html","1","0","#registry","N/A","10","10","N/A","N/A","N/A","N/A","59867"
"*source physmem2profit*",".{0,1000}source\sphysmem2profit.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","0","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","59889"
"*source/shtinkering.*",".{0,1000}source\/shtinkering\..{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","59896"
"*spindrift.py *--target *",".{0,1000}spindrift\.py\s.{0,1000}\-\-target\s.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","59959"
"*spindrift.py --domain*",".{0,1000}spindrift\.py\s\-\-domain.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","59960"
"*spnroast_*.txt*",".{0,1000}spnroast_.{0,1000}\.txt.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","59978"
"*--spoof-callstack *",".{0,1000}\-\-spoof\-callstack\s.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","0","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","59984"
"*SpoolSample.exe * *",".{0,1000}SpoolSample\.exe\s.{0,1000}\s.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","59999"
"*spray* --recon *.* -u *.txt --threads 10*",".{0,1000}spray.{0,1000}\s\-\-recon\s.{0,1000}\..{0,1000}\s\-u\s.{0,1000}\.txt\s\-\-threads\s10.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","60015"
"*Spray365.git*",".{0,1000}Spray365\.git.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","60016"
"*spray365.py*",".{0,1000}spray365\.py.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","60017"
"*spray365_results_*.json*",".{0,1000}spray365_results_.{0,1000}\.json.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","60018"
"*spraycharles analyze *",".{0,1000}spraycharles\sanalyze\s.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","60026"
"*spraycharles gen extras*",".{0,1000}spraycharles\sgen\sextras.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","60027"
"*spraycharles spray*",".{0,1000}spraycharles\sspray.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","0","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","60028"
"*sprayhound -*",".{0,1000}sprayhound\s\-.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","0","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","60029"
"*sprayhound-master.zip*",".{0,1000}sprayhound\-master\.zip.{0,1000}","offensive_tool_keyword","sprayhound","Password spraying tool and Bloodhound integration","T1110.003 - T1210.001 - T1069.002","TA0006 - TA0007 - TA0003","N/A","N/A","Credential Access","https://github.com/Hackndo/sprayhound","1","1","N/A","N/A","N/A","3","231","19","2024-12-31T08:09:37Z","2020-02-06T17:45:37Z","60031"
"*SprayingToolkit.git*",".{0,1000}SprayingToolkit\.git.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","60036"
"*SprayingToolkit-master*",".{0,1000}SprayingToolkit\-master.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","0","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","60037"
"*SprayingToolkit-master.zip*",".{0,1000}SprayingToolkit\-master\.zip.{0,1000}","offensive_tool_keyword","SprayingToolkit","Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient","T1110 - T1078 - T1133 - T1061 - T1621","TA0001 - TA0002 - TA0003","N/A","N/A","Credential Access","https://github.com/byt3bl33d3r/SprayingToolkit","1","1","N/A","N/A","10","10","1491","269","2022-10-17T01:01:57Z","2018-09-13T09:52:11Z","60038"
"*spraykatz*",".{0,1000}spraykatz.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","1","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","60039"
"*Spyndicapped spy *",".{0,1000}Spyndicapped\sspy\s.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","0","#content","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","60047"
"*spysecdump*",".{0,1000}spysecdump.{0,1000}","offensive_tool_keyword","pysecdump","Python-based tool to dump security information from Windows systems","T1003.001 - T1081 - T1012 - T1005 - T1518.001","TA0006 - TA0007 - TA0043","N/A","Dispossessor","Credential Access","https://github.com/pentestmonkey/pysecdump","1","0","#content","N/A","10","3","270","49","2020-06-22T04:16:16Z","2013-01-19T18:02:26Z","60049"
"*Spyware.KeeThief*",".{0,1000}Spyware\.KeeThief.{0,1000}","offensive_tool_keyword","Keethief","Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.","T1003 - T1055 - T1059 - T1070","TA0006 - TA0005 - TA0008","N/A","EvilCorp* - APT20","Credential Access","https://github.com/GhostPack/KeeThief","1","0","#Avsignature","N/A","10","10","944","154","2020-11-18T18:35:21Z","2016-07-10T19:11:23Z","60050"
"*SQ17H1N6(*",".{0,1000}SQ17H1N6\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","60051"
"*sqldumper.py*",".{0,1000}sqldumper\.py.{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","60055"
"*sqlmap/data/txt/wordlist.txt*",".{0,1000}sqlmap\/data\/txt\/wordlist\.txt.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","60078"
"*src/cracker.*",".{0,1000}src\/cracker\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60091"
"*src/genmkvpwd.*",".{0,1000}src\/genmkvpwd\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60092"
"*src/john.asm*",".{0,1000}src\/john\.asm.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60094"
"*src/tests/NESSIE/*",".{0,1000}src\/tests\/NESSIE\/.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60105"
"*src\pamspy.c*",".{0,1000}src\\pamspy\.c.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","60109"
"*ssh2john *",".{0,1000}ssh2john\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60147"
"*ssh2john.py*",".{0,1000}ssh2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60148"
"*sshamble scan *",".{0,1000}sshamble\sscan\s.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","0","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","60149"
"*sshamble*badkeys*",".{0,1000}sshamble.{0,1000}badkeys.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","60150"
"*sshamble/badkeys*",".{0,1000}sshamble\/badkeys.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","60151"
"*sshamble-main.zip*",".{0,1000}sshamble\-main\.zip.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","60152"
"*ssh-auditor*",".{0,1000}ssh\-auditor.{0,1000}","offensive_tool_keyword","ssh-auditor","The best way to scan for weak ssh passwords on your network.","T1110 - T1114 - T1112 - T1056","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ncsa/ssh-auditor","1","0","N/A","N/A","N/A","7","611","84","2023-12-18T21:46:18Z","2016-11-08T22:47:38Z","60153"
"*sshBruteForce.exe*",".{0,1000}sshBruteForce\.exe.{0,1000}","offensive_tool_keyword","SharpBruteForceSSH","simple SSH brute force tool ","T1110.003 - T1078","TA0006 ","N/A","N/A","Credential Access","https://github.com/HernanRodriguez1/SharpBruteForceSSH","1","1","N/A","N/A","9","1","60","10","2024-04-28T17:56:33Z","2024-04-25T20:06:05Z","60155"
"*sshLooterC*",".{0,1000}sshLooterC.{0,1000}","offensive_tool_keyword","sshLooterC","script to steel password from ssh - Its the C version of sshLooter. which was written in python and have a lot of dependencies to be installed on the infected machine. Now with this C version. you compile it on your machine and send it to the infected machine without installing any dependencies.","T1003 - T1059 - T1083 - T1566 - T1558.003","TA0002 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/mthbernardes/sshLooterC","1","1","N/A","N/A","N/A","3","266","86","2023-06-08T21:12:10Z","2018-12-19T20:25:11Z","60165"
"*ssh-putty-brute -*",".{0,1000}ssh\-putty\-brute\s\-.{0,1000}","offensive_tool_keyword","SSH-PuTTY-login-bruteforcer","Turn PuTTY into an SSH login bruteforcing tool.","T1110.002 - T1059.003 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/InfosecMatter/SSH-PuTTY-login-bruteforcer","1","0","N/A","N/A","9","3","285","81","2020-11-21T07:10:26Z","2020-04-25T07:20:14Z","60169"
"*ssh-putty-brute.ps1*",".{0,1000}ssh\-putty\-brute\.ps1.{0,1000}","offensive_tool_keyword","SSH-PuTTY-login-bruteforcer","Turn PuTTY into an SSH login bruteforcing tool.","T1110.002 - T1059.003 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/InfosecMatter/SSH-PuTTY-login-bruteforcer","1","1","N/A","N/A","9","3","285","81","2020-11-21T07:10:26Z","2020-04-25T07:20:14Z","60170"
"*SSH-PuTTY-login-bruteforcer*",".{0,1000}SSH\-PuTTY\-login\-bruteforcer.{0,1000}","offensive_tool_keyword","SSH-PuTTY-login-bruteforcer","Turn PuTTY into an SSH login bruteforcing tool.","T1110.002 - T1059.003 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/InfosecMatter/SSH-PuTTY-login-bruteforcer","1","1","N/A","N/A","9","3","285","81","2020-11-21T07:10:26Z","2020-04-25T07:20:14Z","60171"
"*SSHSnake.log*",".{0,1000}SSHSnake\.log.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","0","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","60173"
"*SSH-Snake-main*",".{0,1000}SSH\-Snake\-main.{0,1000}","offensive_tool_keyword","SSH-Snake","SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery","T1021.004 - T1027 - T1552.004","TA0002 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/MegaManSec/SSH-Snake","1","1","N/A","N/A","10","10","2065","198","2024-07-25T09:32:07Z","2023-12-03T04:52:38Z","60174"
"*sspr2john.py*",".{0,1000}sspr2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60202"
"*StarfireLab/SharpWeb*",".{0,1000}StarfireLab\/SharpWeb.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","1","N/A","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","60290"
"*staroffice2john.py*",".{0,1000}staroffice2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60293"
"*Started spying using MyAutomationEventHandler*",".{0,1000}Started\sspying\susing\sMyAutomationEventHandler.{0,1000}","offensive_tool_keyword","Spyndicapped","COM ViewLogger - keylogger","T1574.001 - T1574.002 - T1574.009","TA0006","N/A","N/A","Credential Access","https://github.com/CICADA8-Research/Spyndicapped","1","0","#content","N/A","10","4","356","50","2025-01-06T07:31:29Z","2024-12-25T11:47:39Z","60317"
"*Starting bruteforce attack on *",".{0,1000}Starting\sbruteforce\sattack\son\s.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","#content","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","60321"
"*statistically-likely-usernames*",".{0,1000}statistically\-likely\-usernames.{0,1000}","offensive_tool_keyword","statistically-likely-usernames","This resource contains wordlists for creating statistically likely usernames for use in username-enumeration. simulated password-attacks and other security testing tasks.","T1210.001 - T1583.001 - T1583.002","TA0007 - ","N/A","N/A","Credential Access","https://github.com/insidetrust/statistically-likely-usernames","1","1","N/A","N/A","N/A","10","1064","149","2022-08-31T20:27:53Z","2016-02-14T23:24:39Z","60371"
"*stderr.pl/oset*",".{0,1000}stderr\.pl\/oset.{0,1000}","greyware_tool_keyword","oset","Offline SAM Editor Tool to access and edit SAM databases from offline OS disk","T1078 - T1003.002 - T1547.001","TA0003 - TA0006 - TA0007 - TA0005","N/A","N/A","Credential Access","https://x.com/0gtweet/status/1817859483445461406","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","60376"
"*StealDhcpSecrets.c*",".{0,1000}StealDhcpSecrets\.c.{0,1000}","offensive_tool_keyword","StealDhcpSecrets","DHCP Server DNS Password Stealer","T1552 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/tree/master/PasswordStealing/DHCP","1","1","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","60385"
"*StealDhcpSecrets.exe*",".{0,1000}StealDhcpSecrets\.exe.{0,1000}","offensive_tool_keyword","StealDhcpSecrets","DHCP Server DNS Password Stealer","T1552 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/gtworek/PSBits/tree/master/PasswordStealing/DHCP","1","1","N/A","N/A","10","10","3337","542","2025-03-12T19:59:23Z","2019-06-29T13:22:36Z","60386"
"*Stealer finished its work*",".{0,1000}Stealer\sfinished\sits\swork.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60387"
"*Stealer.exe *",".{0,1000}Stealer\.exe\s.{0,1000}","offensive_tool_keyword","Adamantium-Thief","Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.","T1555 - T1003","TA0006","N/A","N/A","Credential Access","https://github.com/LimerBoy/Adamantium-Thief","1","0","N/A","N/A","10","9","818","205","2025-01-12T15:11:50Z","2020-03-01T06:50:15Z","60388"
"*Stealing browser data*",".{0,1000}Stealing\sbrowser\sdata.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60389"
"*Stealing crypto wallets*",".{0,1000}Stealing\scrypto\swallets.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60390"
"*Stealing discord tokens*",".{0,1000}Stealing\sdiscord\stokens.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60391"
"*Stealing Epic session*",".{0,1000}Stealing\sEpic\ssession.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60392"
"*Stealing Growtopia session*",".{0,1000}Stealing\sGrowtopia\ssession.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60393"
"*Stealing Minecraft related files*",".{0,1000}Stealing\sMinecraft\srelated\sfiles.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60394"
"*Stealing Roblox cookies*",".{0,1000}Stealing\sRoblox\scookies.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60395"
"*Stealing Steam session*",".{0,1000}Stealing\sSteam\ssession.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60396"
"*Stealing system information*",".{0,1000}Stealing\ssystem\sinformation.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60397"
"*Stealing telegram sessions*",".{0,1000}Stealing\stelegram\ssessions.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60398"
"*Stealing Uplay session*",".{0,1000}Stealing\sUplay\ssession.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","60399"
"*stolen_passwords.txt*",".{0,1000}stolen_passwords\.txt.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","0","N/A","N/A","10","","N/A","","","","60415"
"*STRING firefox about:logins*",".{0,1000}STRING\sfirefox\sabout\:logins.{0,1000}","offensive_tool_keyword","Harvester_OF_SORROW","The payload opens firefox about:logins and tabs and arrows its way through options. It then takes a screen shot with the first set of log in credentials made visible. Finally it sends the screenshot to an email of your choosing.","T1056.001 - T1113 - T1512 - T1566.001 - T1059.006","TA0004 - TA0009 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/blob/master/payloads/library/credentials/Harvester_OF_SORROW/payload.txt","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","60551"
"*String netsh wlan export profile key=clear*",".{0,1000}String\snetsh\swlan\sexport\sprofile\skey\=clear.{0,1000}","offensive_tool_keyword","wifigrabber","grab wifi password and exfiltrate to a given site","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","60554"
"*strings -n * /dev/mem | grep -i pass*",".{0,1000}strings\s\-n\s.{0,1000}\s\/dev\/mem\s\|\sgrep\s\-i\spass.{0,1000}","greyware_tool_keyword","grep","search for passwords in memory and core dumps","T1005 - T1083 - T1213","TA0006","N/A","N/A","Credential Access","https://github.com/RoseSecurity/Red-Teaming-TTPs/blob/main/Linux.md","1","0","#linux","N/A","N/A","10","1594","198","2025-04-16T21:16:51Z","2021-08-16T17:34:25Z","60555"
"*strip2john.py*",".{0,1000}strip2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60557"
"*submodules.pywerview.requester*",".{0,1000}submodules\.pywerview\.requester.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","60590"
"*succesfully dumped SAM's hash.es to *",".{0,1000}succesfully\sdumped\sSAM\'s\shash\.es\sto\s.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","60594"
"*succesfully dumped SAM's hash.es to *",".{0,1000}succesfully\sdumped\sSAM\'s\shash\.es\sto\s.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","60595"
"*succesfully dumped WINHELLO pin.s to *",".{0,1000}succesfully\sdumped\sWINHELLO\spin\.s\sto\s.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","0","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","60596"
"*Succesfully Mirrored to lsass.exe*",".{0,1000}Succesfully\sMirrored\sto\slsass\.exe.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","0","#content","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","60597"
"*Successfully created dump of the forked process*",".{0,1000}Successfully\screated\sdump\sof\sthe\sforked\sprocess.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","0","#content","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","60603"
"*Successfully downloaded the LSASS dump into local file*",".{0,1000}Successfully\sdownloaded\sthe\sLSASS\sdump\sinto\slocal\sfile.{0,1000}","offensive_tool_keyword","go-lsass","dumping LSASS process remotely","T1003 - T1055 - T1021.005","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/jfjallid/go-lsass","1","0","#content","N/A","9","1","38","5","2024-07-27T10:35:12Z","2023-11-30T18:45:51Z","60605"
"*Successfully dumped lsass process*",".{0,1000}Successfully\sdumped\slsass\sprocess.{0,1000}","offensive_tool_keyword","LsassReflectDumping","leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process","T1003.001 - T1555.003 - T1077","TA0006","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/LsassReflectDumping","1","0","#content","N/A","10","2","198","27","2024-10-19T08:16:13Z","2024-10-17T14:57:30Z","60606"
"*Successfully hijacked KeePassXC.exe*",".{0,1000}Successfully\shijacked\sKeePassXC\.exe.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","60610"
"*Successfully obfuscated file: *.py*",".{0,1000}Successfully\sobfuscated\sfile\:\s.{0,1000}\.py.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","60612"
"*Successfully poisonned consent.exe*",".{0,1000}Successfully\spoisonned\sconsent\.exe.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","60613"
"*Successfully poisonned LogonUI.exe*",".{0,1000}Successfully\spoisonned\sLogonUI\.exe.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","60614"
"*Successfully poisonned MobaXTerm*",".{0,1000}Successfully\spoisonned\sMobaXTerm.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","60615"
"*Successfully poisonned mstsc.exe*",".{0,1000}Successfully\spoisonned\smstsc\.exe.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","60616"
"*Successfully poisonned RDCMan.exe*",".{0,1000}Successfully\spoisonned\sRDCMan\.exe.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","60617"
"*Sucessfully performed AppDomainInjection for KeePass*",".{0,1000}Sucessfully\sperformed\sAppDomainInjection\sfor\sKeePass.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","60618"
"*sudo tmux new -s icebreaker*",".{0,1000}sudo\stmux\snew\s\-s\sicebreaker.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","#linux","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","60641"
"*sunnyelf/cheetah/archive/master.zip*",".{0,1000}sunnyelf\/cheetah\/archive\/master\.zip.{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","1","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","60650"
"*sunnyelf[@hackfun.org]*",".{0,1000}sunnyelf\[\@hackfun\.org\].{0,1000}","offensive_tool_keyword","cheetah","a very fast brute force webshell password tool","T1110 - T1190 - T1505.003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/shmilylty/cheetah","1","0","N/A","N/A","10","7","630","150","2023-04-17T01:33:52Z","2017-04-15T20:03:50Z","60651"
"*SW2_GetSyscallNumber*",".{0,1000}SW2_GetSyscallNumber.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","60684"
"*SW2_PopulateSyscallList*",".{0,1000}SW2_PopulateSyscallList.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","60687"
"*SW2_RVA2VA*",".{0,1000}SW2_RVA2VA.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","60689"
"*SW3_GetSyscallAddress*",".{0,1000}SW3_GetSyscallAddress.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","60690"
"*swisskyrepo/SharpLAPS*",".{0,1000}swisskyrepo\/SharpLAPS.{0,1000}","offensive_tool_keyword","SharpLAPS","Retrieve LAPS password from LDAP","T1552.005 - T1212","TA0006 - TA0007","N/A","Dispossessor","Credential Access","https://github.com/swisskyrepo/SharpLAPS","1","1","N/A","N/A","10","5","408","85","2021-02-17T14:32:16Z","2021-02-16T17:27:41Z","60713"
"*sxxuJBrIRnKNqcH6xJNmUc/7lE0UOrgWJ2vMbaAoR4c=*",".{0,1000}sxxuJBrIRnKNqcH6xJNmUc\/7lE0UOrgWJ2vMbaAoR4c\=.{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","#base64","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","60724"
"*synacktiv/ntdissector*",".{0,1000}synacktiv\/ntdissector.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","1","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","60731"
"*SYSKEY RESET!\nNow please set new administrator password!*",".{0,1000}SYSKEY\sRESET!\\nNow\splease\sset\snew\sadministrator\spassword!.{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","60762"
"*szRemotePWDumpEXEPath*",".{0,1000}szRemotePWDumpEXEPath.{0,1000}","offensive_tool_keyword","PWDumpX","PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://packetstormsecurity.com/files/download/52580/PWDumpX.zip","1","0","#content","N/A","10","8","N/A","N/A","N/A","N/A","60826"
"*-t: force use of Impersonation Privilege*",".{0,1000}\-t\:\sforce\suse\sof\sImpersonation\sPrivilege.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","0","#content","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","60834"
"*T0XlCv1.rule*",".{0,1000}T0XlCv1\.rule.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","60835"
"*t3l3machus/BabelStrike*",".{0,1000}t3l3machus\/BabelStrike.{0,1000}","offensive_tool_keyword","BabelStrike","The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)","T1078 - T1114","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/t3l3machus/BabelStrike","1","1","N/A","N/A","1","2","132","23","2024-07-19T07:02:42Z","2023-01-10T07:59:00Z","60838"
"*TakeDump -SentinelHelper * -ProcessId * -User * -Kernel *",".{0,1000}TakeDump\s\-SentinelHelper\s.{0,1000}\s\-ProcessId\s.{0,1000}\s\-User\s.{0,1000}\s\-Kernel\s.{0,1000}","greyware_tool_keyword","SentinelAgent","dump a process with SentinelAgent.exe","T1003 - T1055","TA0006 - TA0005","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e","1","0","N/A","N/A","8","7","N/A","N/A","N/A","N/A","60885"
"*taskkill /f /im rfusclient.exe*",".{0,1000}taskkill\s\/f\s\/im\srfusclient\.exe.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","60948"
"*taskkill /f /im rutserv.exe*",".{0,1000}taskkill\s\/f\s\/im\srutserv\.exe.{0,1000}","offensive_tool_keyword","RDP Recognizer","could be used to brute force RDP passwords or check for RDP vulnerabilities","T1110 - T1595.002","TA0006","N/A","BianLian","Credential Access","https://www.virustotal.com/gui/file/74788c34f3606e482ad28752c14550dc469bb0c04fa72e184a1e457613c2e4f6/details","1","0","N/A","N/A","9","10","N/A","N/A","N/A","N/A","60949"
"*tasklist /fi *Imagename eq lsass.exe*",".{0,1000}tasklist\s\/fi\s.{0,1000}Imagename\seq\slsass\.exe.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","0","N/A","N/A","10","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","61029"
"*tasklist /fi *Imagename eq lsass.exe*",".{0,1000}tasklist\s\/fi\s.{0,1000}Imagename\seq\slsass\.exe.{0,1000}","greyware_tool_keyword","tasklist","This might indicate an attempt to dump credentials. Investigate the process tree.","T1555","TA0006 - TA0007","N/A","APT5 - APT29 - OilRig - Ke3chang - Earth Lusca - Volt Typhoon - APT1 - Threat Group-3390 - Deep Panda - Turla - Naikon","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","61030"
"*tasklist /fi *Imagename eq lsass.exe*do procdump*",".{0,1000}tasklist\s\/fi\s.{0,1000}Imagename\seq\slsass\.exe.{0,1000}do\sprocdump.{0,1000}","offensive_tool_keyword","spraykatz","Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.","T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008","TA0003 - TA0004 - TA0007","N/A","N/A","Credential Access","https://github.com/aas-n/spraykatz","1","0","N/A","N/A","9","8","763","121","2020-06-20T12:14:00Z","2019-09-09T14:38:28Z","61031"
"*tasklist | findstr lsass*",".{0,1000}tasklist\s\|\sfindstr\slsass.{0,1000}","greyware_tool_keyword","tasklist","get LSASS process ID","T1057 - T1018","TA0007 - TA0006 - TA0005","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","61034"
"*tastypepperoni/PPLBlade*",".{0,1000}tastypepperoni\/PPLBlade.{0,1000}","offensive_tool_keyword","PPLBlade","Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.","T1003.001 - T1027.004 - T1560.001 - T1039 - T1570","TA0006 - TA0005 - TA0010 - TA0003","N/A","N/A","Credential Access","https://github.com/tastypepperoni/PPLBlade","1","1","N/A","N/A","10","6","545","59","2023-08-30T07:59:51Z","2023-08-29T19:36:04Z","61040"
"*TeamFiltration.exe *",".{0,1000}TeamFiltration\.exe\s.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","61058"
"*TeamFiltration\Program.cs*",".{0,1000}TeamFiltration\\Program\.cs.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","0","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","61059"
"*TeamFiltration-v*-linux-x86_64.zip*",".{0,1000}TeamFiltration\-v.{0,1000}\-linux\-x86_64\.zip.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","#linux","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","61060"
"*TeamFiltration-v*-macOS-arm64.zip*",".{0,1000}TeamFiltration\-v.{0,1000}\-macOS\-arm64\.zip.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","61061"
"*TeamFiltration-v*-macOS-x86_64.zip*",".{0,1000}TeamFiltration\-v.{0,1000}\-macOS\-x86_64\.zip.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","61062"
"*TeamFiltration-v*-win-x86_64.zip*",".{0,1000}TeamFiltration\-v.{0,1000}\-win\-x86_64\.zip.{0,1000}","offensive_tool_keyword","TeamFiltration","TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts","T1110 - T1087 - T1560.001 - T1592 - T1071","TA0001 - TA0003 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Flangvik/TeamFiltration","1","1","N/A","N/A","10","10","1132","128","2025-04-10T13:48:00Z","2022-06-28T00:00:28Z","61063"
"*teams_dump.py teams*",".{0,1000}teams_dump\.py\steams.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","0","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","61064"
"*teams_dump-main.zip*",".{0,1000}teams_dump\-main\.zip.{0,1000}","offensive_tool_keyword","teams_dump","PoC for dumping and decrypting cookies in the latest version of Microsoft Teams","T1555 - T1003 - T1114","TA0006 - TA0005 - TA0009","N/A","N/A","Credential Access","https://github.com/byinarie/teams_dump","1","1","N/A","N/A","9","2","132","19","2023-11-12T18:47:55Z","2023-09-18T18:33:32Z","61065"
"*techspence/ScriptSentry*",".{0,1000}techspence\/ScriptSentry.{0,1000}","offensive_tool_keyword","ScriptSentry","ScriptSentry finds misconfigured and dangerous logon scripts.","T1037 - T1037.005 - T1046","TA0005 - TA0007","N/A","N/A","Credential Access","https://github.com/techspence/ScriptSentry","1","1","N/A","N/A","7","6","502","43","2024-12-20T21:27:24Z","2023-07-22T03:17:58Z","61110"
"*tecknicaltom/dsniff*",".{0,1000}tecknicaltom\/dsniff.{0,1000}","offensive_tool_keyword","dsniff","password sniffer. handles FTP. Telnet. SMTP. HTTP. POP. poppass. NNTP. IMAP. SNMP. LDAP. Rlogin. RIP. OSPF. PPTP MS-CHAP. NFS. VRRP. YP/NIS. SOCKS. X11. CVS. IRC. AIM. ICQ. Napster. PostgreSQL. Meeting Maker. Citrix ICA. Symantec pcAnywhere. NAI Sniffer. Microsoft SMB. Oracle SQL*Net. Sybase and Microsoft SQL auth info. dsniff automatically detects and minimally parses each application protocol. only saving the interesting bits. and uses Berkeley DB as its output file format. only logging unique authentication attempts. full TCP/IP reassembly is provided by libnids(3) (likewise for the following tools as well)","T1110 - T1040 - T1074.001 - T1555.002 - T1555.003","TA0001 - TA0002 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/tecknicaltom/dsniff","1","0","N/A","N/A","N/A","3","208","47","2010-06-29T05:53:39Z","2010-06-23T13:11:11Z","61112"
"*telegram2john.py*",".{0,1000}telegram2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61117"
"*temp*whoami.txt*",".{0,1000}temp.{0,1000}whoami\.txt.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","61130"
"*Temp\\rubeus*",".{0,1000}Temp\\\\rubeus.{0,1000}","offensive_tool_keyword","Rubeus","Run Rubeus via Rundll32 (potential application whitelisting bypass technique)","T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004","TA0005 - TA0002 - TA0006 - TA0008 - TA0009","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/rvrsh3ll/Rubeus-Rundll32","1","0","#content","N/A","10","3","200","32","2020-04-25T19:55:27Z","2020-04-24T20:35:38Z","61131"
"*test_lsassy.*",".{0,1000}test_lsassy\..{0,1000}","offensive_tool_keyword","lsassy","Extract credentials from lsass remotely","T1003.001 - T1021.001 - T1021.002 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/login-securite/lsassy","1","1","N/A","N/A","10","10","2105","251","2024-12-31T11:56:19Z","2019-12-03T14:03:41Z","61158"
"*test_tezos2john.py*",".{0,1000}test_tezos2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61162"
"*tester12345678@gmail.com*",".{0,1000}tester12345678\@gmail\.com.{0,1000}","offensive_tool_keyword","CredMaster","CredKing password spraying tool - uses FireProx APIs to rotate IP addresses","T1110.003 - T1596 - T1071.004 - T1621","TA0006 - TA0043","N/A","N/A","Credential Access","https://github.com/knavesec/CredMaster","1","1","#email","N/A","9","10","1070","142","2025-03-19T20:36:21Z","2020-09-25T20:57:42Z","61171"
"*tezos2john.py*",".{0,1000}tezos2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61189"
"*tgscrack.go*",".{0,1000}tgscrack\.go.{0,1000}","offensive_tool_keyword","ASREPRoast","Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. ","T1558.003","TA0006","N/A","N/A","Credential Access","https://github.com/HarmJ0y/ASREPRoast","1","1","N/A","N/A","N/A","3","202","58","2018-09-25T03:26:00Z","2017-01-14T21:07:57Z","61194"
"*tgsrepcrack.*",".{0,1000}tgsrepcrack\..{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Crack with TGSRepCrack","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","61195"
"*tgsrepcrack.py*",".{0,1000}tgsrepcrack\.py.{0,1000}","offensive_tool_keyword","kerberoast","Kerberoast is a series of tools for attacking MS Kerberos implementations","T1550 - T1555 - T1212 - T1558","TA0001 - TA0004 - TA0006","N/A","APT20","Credential Access","https://github.com/nidem/kerberoast","1","1","N/A","N/A","N/A","10","1433","317","2022-12-31T17:17:28Z","2014-09-22T14:46:49Z","61196"
"*TGSThief-main*",".{0,1000}TGSThief\-main.{0,1000}","offensive_tool_keyword","TGSThief","get the TGS of a user whose logon session is just present on the computer","T1558 - T1558.003 - T1078 - T1078.005","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/MzHmO/TGSThief","1","1","N/A","N/A","9","2","181","27","2023-07-25T05:30:39Z","2023-07-23T07:47:05Z","61197"
"*THASH /runts /user:*",".{0,1000}THASH\s\/runts\s\/user\:.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","61212"
"*thc-hydra*",".{0,1000}thc\-hydra.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","61213"
"*thc-hydra.git*",".{0,1000}thc\-hydra\.git.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","61214"
"*thc-hydra.git*",".{0,1000}thc\-hydra\.git.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","61215"
"*The database engine created a new database*temp\Active Directory\ntds.dit*",".{0,1000}The\sdatabase\sengine\screated\sa\snew\sdatabase.{0,1000}temp\\Active\sDirectory\\ntds\.dit.{0,1000}","greyware_tool_keyword","ntdsutil","creating a full backup of the Active Directory database and saving it to the \temp directory","T1003.001 - T1070.004 - T1059","TA0006","N/A","Rhysida - Conti - Yanluowang - Lapsus$ - APT41","Credential Access","N/A","1","0","N/A","greyware tool - risks of False positive !","10","10","N/A","N/A","N/A","N/A","61218"
"*The nanodump was created succesfully*",".{0,1000}The\snanodump\swas\screated\ssuccesfully.{0,1000}","offensive_tool_keyword","DriverDump","abusing the old process explorer driver to grab a privledged handle to lsass and then dump it","T1543 - T1548 - T1562 - T1003 - T1569","TA0005 - TA0003 - TA0004 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/trustedsec/The_Shelf","1","0","N/A","N/A","10","3","247","14","2024-11-25T19:33:34Z","2024-05-22T14:31:52Z","61223"
"*The smart password spraying and bruteforcing tool for Active Directory Domain Services*",".{0,1000}The\ssmart\spassword\sspraying\sand\sbruteforcing\stool\sfor\sActive\sDirectory\sDomain\sServices.{0,1000}","offensive_tool_keyword","smartbrute","Password spraying and bruteforcing tool for Active Directory Domain Services","T1110.001 - T1110.003","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/ShutdownRepo/smartbrute","1","0","N/A","N/A","10","4","365","54","2024-10-27T20:47:29Z","2021-07-16T14:53:29Z","61226"
"*thelinuxchoice/tweetshell*",".{0,1000}thelinuxchoice\/tweetshell.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/SocialBox-Termux","1","1","#linux","N/A","7","10","3581","391","2024-09-02T19:15:22Z","2019-03-28T18:07:05Z","61245"
"*TheresAFewConors/MSSprinkler*",".{0,1000}TheresAFewConors\/MSSprinkler.{0,1000}","offensive_tool_keyword","MSSprinkler","password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach","T1110.003 - T1110.001","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/TheresAFewConors/MSSprinkler","1","1","N/A","N/A","9","1","74","7","2025-02-25T13:32:41Z","2024-09-15T09:54:53Z","61249"
"*The-Viper-One/Invoke-RDPThief*",".{0,1000}The\-Viper\-One\/Invoke\-RDPThief.{0,1000}","offensive_tool_keyword","Invoke-RDPThief","perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials","T1055 - T1056 - T1071 - T1110","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/The-Viper-One/Invoke-RDPThief","1","1","N/A","N/A","10","1","62","8","2025-01-21T20:12:33Z","2024-10-01T20:12:00Z","61252"
"*ThievingFox.py *",".{0,1000}ThievingFox\.py\s.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","61258"
"*threatpatrols/sshamble*",".{0,1000}threatpatrols\/sshamble.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","1","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","61287"
"*ticket.kirbi*",".{0,1000}ticket\.kirbi.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","61312"
"*ticketer.py -nthash *",".{0,1000}ticketer\.py\s\-nthash\s.{0,1000}","offensive_tool_keyword","NetNTLMtoSilverTicket","Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.","T1110.001 - T1558.003 - T1558.004","TA0006 - TA0008 - TA0002","N/A","N/A","Credential Access","https://github.com/NotMedic/NetNTLMtoSilverTicket","1","0","N/A","N/A","10","9","842","113","2021-07-26T15:16:20Z","2019-01-14T15:32:27Z","61315"
"*ticketsplease adfs *",".{0,1000}ticketsplease\sadfs\s.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","0","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","61319"
"*ticketsplease azure *",".{0,1000}ticketsplease\sazure\s.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","0","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","61320"
"*ticketsplease dcsync *",".{0,1000}ticketsplease\sdcsync\s.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","0","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","61321"
"*ticketsplease ldap *",".{0,1000}ticketsplease\sldap\s.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","0","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","61322"
"*ticketsplease saml *",".{0,1000}ticketsplease\ssaml\s.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","0","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","61323"
"*ticketsplease ticket --domain*",".{0,1000}ticketsplease\sticket\s\-\-domain.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","0","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","61324"
"*ticketsplease.modules.*",".{0,1000}ticketsplease\.modules\..{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","61325"
"*Tiger-192.test-vectors.txt*",".{0,1000}Tiger\-192\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61328"
"*timeroast.ps1*",".{0,1000}timeroast\.ps1.{0,1000}","offensive_tool_keyword","Timeroast","Timeroasting takes advantage of Windows NTP authentication mechanism allowing unauthenticated attackers to effectively request a password hash of any computer or trust account by sending an NTP request with that account's RID","T1558.003 - T1059.003 - T1078.004","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/SecuraBV/Timeroast","1","1","N/A","N/A","10","3","282","28","2023-07-04T07:12:57Z","2023-01-18T09:04:05Z","61350"
"*timeroast.py*",".{0,1000}timeroast\.py.{0,1000}","offensive_tool_keyword","Timeroast","Timeroasting takes advantage of Windows NTP authentication mechanism allowing unauthenticated attackers to effectively request a password hash of any computer or trust account by sending an NTP request with that account's RID","T1558.003 - T1059.003 - T1078.004","TA0006 - TA0002 - TA0004","N/A","N/A","Credential Access","https://github.com/SecuraBV/Timeroast","1","1","N/A","N/A","10","3","282","28","2023-07-04T07:12:57Z","2023-01-18T09:04:05Z","61351"
"*TlRMTVNTUAABAAAABYIIAAAAAAAAAAAAAAAAAAAAAAAAAAAAMAAAAAAAAAAwAAAA*",".{0,1000}TlRMTVNTUAABAAAABYIIAAAAAAAAAAAAAAAAAAAAAAAAAAAAMAAAAAAAAAAwAAAA.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","ntlm decoder","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61362"
"*To dump lsass memory using *",".{0,1000}To\sdump\slsass\smemory\susing\s.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","61383"
"*token* -CreateProcess * -ProcessId *",".{0,1000}token.{0,1000}\s\-CreateProcess\s.{0,1000}\s\-ProcessId\s.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Start new process with token of a specific user. Tokens can be impersonated from other users with a session/running processes on the machine. Most C2 frameworks have functionality for this built-in (such as the Steal Token functionality in Cobalt Strike)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","61397"
"*token* -ImpersonateUser -Username *",".{0,1000}token.{0,1000}\s\-ImpersonateUser\s\-Username\s.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Start new process with token of a specific user. Tokens can be impersonated from other users with a session/running processes on the machine. Most C2 frameworks have functionality for this built-in (such as the Steal Token functionality in Cobalt Strike)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","61398"
"*Tokens were extracted to tokens.txt! Enjoy*",".{0,1000}Tokens\swere\sextracted\sto\stokens\.txt!\sEnjoy.{0,1000}","offensive_tool_keyword","TokenFinder","Tool to extract powerful tokens from Office desktop apps memory","T1003 - T1081 - T1110","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/doredry/TokenFinder","1","0","#content","N/A","9","1","71","10","2024-03-01T14:27:34Z","2022-09-21T14:21:07Z","61420"
"*TokenStealer.cpp*",".{0,1000}TokenStealer\.cpp.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","61421"
"*TokenStealer.exe*",".{0,1000}TokenStealer\.exe.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","61422"
"*TokenStealer.sln*",".{0,1000}TokenStealer\.sln.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","61423"
"*TokenStealer.vcxproj*",".{0,1000}TokenStealer\.vcxproj.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","61424"
"*TokenStealer-master*",".{0,1000}TokenStealer\-master.{0,1000}","offensive_tool_keyword","TokenStealer","stealing Windows tokens","T1134 - T1055","TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/decoder-it/TokenStealer","1","1","N/A","N/A","10","2","164","29","2023-10-25T14:08:57Z","2023-10-24T13:06:37Z","61425"
"*TokenTactics.psd1*",".{0,1000}TokenTactics\.psd1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","61430"
"*TokenTactics.psd1*",".{0,1000}TokenTactics\.psd1.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","1","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","61431"
"*TokenTactics.psm1*",".{0,1000}TokenTactics\.psm1.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","61432"
"*TokenTactics.psm1*",".{0,1000}TokenTactics\.psm1.{0,1000}","offensive_tool_keyword","TokenTacticsV2","fork of the great TokenTactics with support for CAE and token endpoint v2","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/f-bader/TokenTacticsV2","1","1","N/A","N/A","6","3","282","38","2025-02-25T14:14:25Z","2022-08-16T17:00:45Z","61433"
"*TokenTactics-main.zip*",".{0,1000}TokenTactics\-main\.zip.{0,1000}","offensive_tool_keyword","TokenTactics","Azure JWT Token Manipulation Toolset","T1134.002 - T1078.004 - T1095","TA0005 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/rvrsh3ll/TokenTactics","1","1","N/A","N/A","6","7","652","105","2024-12-06T15:51:42Z","2021-07-08T02:28:12Z","61434"
"*TokenUniverse.dproj*",".{0,1000}TokenUniverse\.dproj.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","61435"
"*TokenUniverse.exe*",".{0,1000}TokenUniverse\.exe.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","61436"
"*TokenUniverse-master.zip*",".{0,1000}TokenUniverse\-master\.zip.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","61437"
"*TokenUniverse-x64.zip*",".{0,1000}TokenUniverse\-x64\.zip.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","61438"
"*TokenUniverse-x86.zip*",".{0,1000}TokenUniverse\-x86\.zip.{0,1000}","offensive_tool_keyword","TokenUniverse","An advanced tool for working with access tokens and Windows security policy.","T1134 - T1055 - T1056 - T1222 - T1484","TA0004 - TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/diversenok/TokenUniverse","1","1","N/A","N/A","8","6","597","66","2024-07-20T03:18:21Z","2018-06-22T21:02:16Z","61439"
"*Tool-PassView*",".{0,1000}Tool\-PassView.{0,1000}","offensive_tool_keyword","Tool-PassView","Password recovery or exploitation","T1003 - T1021 - T1056 - T1110 - T1212","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/password_recovery_tools.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","61464"
"*Top109Million-probable-v2.txt*",".{0,1000}Top109Million\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61469"
"*Top12Thousand-probable-v2.txt*",".{0,1000}Top12Thousand\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61470"
"*Top1575-probable-v2.txt*",".{0,1000}Top1575\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61471"
"*Top1pt6Million-probable-v2.txt*",".{0,1000}Top1pt6Million\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61472"
"*Top207-probable-v2.txt*",".{0,1000}Top207\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61473"
"*Top29Million-probable-v2.txt*",".{0,1000}Top29Million\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61474"
"*Top2Billion-probable-v2.txt*",".{0,1000}Top2Billion\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61475"
"*Top304Thousand-probable-v2.txt*",".{0,1000}Top304Thousand\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61476"
"*Top353Million-probable-v2.txt*",".{0,1000}Top353Million\-probable\-v2\.txt.{0,1000}","offensive_tool_keyword","Probable-Wordlists","Password wordlists","T1110 - T1114","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/berzerk0/Probable-Wordlists","1","1","N/A","N/A","9","10","8895","1608","2023-10-04T20:22:09Z","2017-04-16T17:08:27Z","61477"
"*Total number of passwords to test: *",".{0,1000}Total\snumber\sof\spasswords\sto\stest\:\s.{0,1000}","offensive_tool_keyword","adfspray","Python3 tool to perform password spraying against Microsoft Online service using various methods","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/xFreed0m/ADFSpray","1","0","N/A","N/A","N/A","1","87","14","2023-03-12T00:21:34Z","2020-04-23T08:56:51Z","61521"
"*toto %3e c:\\temp\\toto.txt*",".{0,1000}toto\s\%3e\sc\:\\\\temp\\\\toto\.txt.{0,1000}","offensive_tool_keyword","NTHASH-FPC","various tools for retrieving windows secrets - Lateral Movement and C2","T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602","TA0006 - TA0007 - TA0008 - TA0009 - TA0011","N/A","N/A","Credential Access","https://github.com/erwan2212/NTHASH-FPC","1","0","N/A","N/A","10","1","35","9","2023-08-13T16:38:53Z","2019-08-09T11:49:55Z","61525"
"*trevorproxy ssh*",".{0,1000}trevorproxy\sssh.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61549"
"*trevorproxy subnet*",".{0,1000}trevorproxy\ssubnet.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61550"
"*trevorspray -*",".{0,1000}trevorspray\s\-.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61552"
"*trevorspray.cli*",".{0,1000}trevorspray\.cli.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61555"
"*trevorspray.enumerators*",".{0,1000}trevorspray\.enumerators.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61556"
"*trevorspray.looters*",".{0,1000}trevorspray\.looters.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61557"
"*trevorspray.py*",".{0,1000}trevorspray\.py.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61558"
"*trevorspray.sprayers*",".{0,1000}trevorspray\.sprayers.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61559"
"*trevorspray/existent_users.txt*",".{0,1000}trevorspray\/existent_users\.txt.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61560"
"*trevorspray/valid_logins.txt*",".{0,1000}trevorspray\/valid_logins\.txt.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61561"
"*TREVORspray-dev*",".{0,1000}TREVORspray\-dev.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61562"
"*TREVORspray-master*",".{0,1000}TREVORspray\-master.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61563"
"*TREVORspray-trevorspray*",".{0,1000}TREVORspray\-trevorspray.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","1","N/A","N/A","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","61564"
"*Troedx765nLiedx765nk*",".{0,1000}Troedx765nLiedx765nk.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","61570"
"*Trojan.Lazagne*",".{0,1000}Trojan\.Lazagne.{0,1000}","signature_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","#Avsignature","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","61579"
"*Trojan.PWS.Stealer.*",".{0,1000}Trojan\.PWS\.Stealer\..{0,1000}","signature_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","61583"
"*TrU57(C00K13s)*",".{0,1000}TrU57\(C00K13s\).{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","61640"
"*truecrypt2john.py*",".{0,1000}truecrypt2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61641"
"*truerustyy/wcreddump*",".{0,1000}truerustyy\/wcreddump.{0,1000}","offensive_tool_keyword","wcreddump","Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.","T1003 - T1110.001","TA0006","N/A","N/A","Credential Access","https://github.com/truerustyy/wcreddump","1","1","#linux #windows","N/A","10","1","75","5","2024-11-18T18:37:28Z","2024-03-05T00:00:20Z","61642"
"*trustedsec/DitExplorer*",".{0,1000}trustedsec\/DitExplorer.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","1","N/A","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","61659"
"*Try opening it with Mimikatz now :)*",".{0,1000}Try\sopening\sit\swith\sMimikatz\snow\s\:\).{0,1000}","offensive_tool_keyword","LetMeowIn","A sophisticated covert Windows-based credential dumper using C++ and MASM x64.","T1003 - T1055.011 - T1148","TA0006","N/A","N/A","Credential Access","https://github.com/Meowmycks/LetMeowIn","1","0","N/A","N/A","10","5","401","70","2024-07-08T15:58:37Z","2024-04-09T16:33:27Z","61664"
"*Trying to bypass UAC (Application will restart)*",".{0,1000}Trying\sto\sbypass\sUAC\s\(Application\swill\srestart\).{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","61668"
"*Trying to disable defender*",".{0,1000}Trying\sto\sdisable\sdefender.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","61669"
"*Trying to dump kernel to C:*",".{0,1000}Trying\sto\sdump\skernel\sto\sC\:.{0,1000}","offensive_tool_keyword","DumpKernel-S1.ps1","SentinelHelper to perform a live kernel dump in a Windows environment","T1055 - T1003 - T1112","TA0005 - TA0006 - TA0010","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8f29e09d74b73e1dec3f9049c4358e80","1","0","N/A","N/A","10","8","N/A","N/A","N/A","N/A","61670"
"*Trying to dump SentinelAgent to *",".{0,1000}Trying\sto\sdump\sSentinelAgent\sto\s.{0,1000}","greyware_tool_keyword","SentinelAgent","dump a process with SentinelAgent.exe","T1003 - T1055","TA0006 - TA0005","N/A","N/A","Credential Access","https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e","1","0","N/A","N/A","8","7","N/A","N/A","N/A","N/A","61671"
"*Trying to exclude bound file from defender*",".{0,1000}Trying\sto\sexclude\sbound\sfile\sfrom\sdefender.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","61672"
"*Trying to exclude the file from Windows defender*",".{0,1000}Trying\sto\sexclude\sthe\sfile\sfrom\sWindows\sdefender.{0,1000}","offensive_tool_keyword","Blank-Grabber","Stealer with multiple functions","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Blank-c/Blank-Grabber","1","0","N/A","N/A","10","9","831","220","2023-08-06T06:26:16Z","2022-01-26T12:04:56Z","61673"
"*tspkg/decryptor.py*",".{0,1000}tspkg\/decryptor\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","61689"
"*Tw1sm/spraycharles*",".{0,1000}Tw1sm\/spraycharles.{0,1000}","offensive_tool_keyword","spraycharles","Low and slow password spraying tool","T1110.003 - T1110.001","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Tw1sm/spraycharles","1","1","N/A","N/A","10","2","195","32","2025-02-09T03:08:09Z","2018-09-17T11:17:47Z","61743"
"*uaf2john.*",".{0,1000}uaf2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61792"
"*UCCAPI/16.0.13328.20130 OC/16.0.13426.20234*",".{0,1000}UCCAPI\/16\.0\.13328\.20130\sOC\/16\.0\.13426\.20234.{0,1000}","greyware_tool_keyword","lyncsmash","default user agent used by lyncsmash.py - a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations ","T1190 - T1087 - T1110","TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/nyxgeek/lyncsmash","1","1","#useragent","greyware_tools high risks of false positives","8","4","337","63","2024-10-01T11:22:01Z","2016-05-20T04:32:41Z","61796"
"*udmp-parser-main*",".{0,1000}udmp\-parser\-main.{0,1000}","offensive_tool_keyword","udmp-parser","A Cross-Platform C++ parser library for Windows user minidumps.","T1005 - T1059.003 - T1027.002","TA0009 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/0vercl0k/udmp-parser","1","1","N/A","N/A","6","3","202","23","2024-11-20T15:58:21Z","2022-01-30T18:56:21Z","61797"
"*uknowsec/SharpDecryptPwd*",".{0,1000}uknowsec\/SharpDecryptPwd.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","61812"
"*unode/firefox_decrypt*",".{0,1000}unode\/firefox_decrypt.{0,1000}","offensive_tool_keyword","firefox_decrypt","Firefox Decrypt is a tool to extract passwords from Mozilla","T1555.003 - T1112 - T1056.001","TA0006 - TA0009 - TA0040","N/A","N/A","Credential Access","https://github.com/unode/firefox_decrypt","1","1","N/A","N/A","10","10","2172","317","2024-11-08T13:52:34Z","2014-01-17T13:25:02Z","61901"
"*unset HISTFILE && HISTSIZE=0 && rm -f $HISTFILE && unset HISTFILE*",".{0,1000}unset\sHISTFILE\s\&\&\sHISTSIZE\=0\s\&\&\srm\s\-f\s\$HISTFILE\s\&\&\sunset\sHISTFILE.{0,1000}","greyware_tool_keyword","unset","disable history logging","T1056.001 - T1562.001","TA0004 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/OMGLogger","1","0","#linux","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","61906"
"*unshadow /etc/passwd*",".{0,1000}unshadow\s\/etc\/passwd.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61916"
"*unshadow passwd shadow > *",".{0,1000}unshadow\spasswd\sshadow\s\>\s.{0,1000}","greyware_tool_keyword","unshadow","linux commands abused by attackers - find guid and suid sensitives perm","T1059.003 - T1053.005 - T1105 - T1012 - T1057 - T1083 - T1041 - T1036 - T1035 - T1562.001 - T1564.001 - T1564.005 - T1564.002 - T1564.003 - T1027 - T1070.001 - T1112 - T1136","TA0003 - TA0007 - TA0008 - TA0010 - TA0006 - TA0002","N/A","N/A","Credential Access","N/A","1","0","#linux","greyware_tools high risks of false positives","N/A","N/A","N/A","N/A","N/A","N/A","61917"
"*unshadow passwd shadow*",".{0,1000}unshadow\spasswd\sshadow.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","#linux","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","61918"
"*UP104D7060F113(*",".{0,1000}UP104D7060F113\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","61922"
"*UP104D70K3N(*",".{0,1000}UP104D70K3N\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","61923"
"*Upload.Password=antichat*",".{0,1000}Upload\.Password\=antichat.{0,1000}","offensive_tool_keyword","RouterScan","a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces","T1110","TA0006 - TA0007","RouterScan","Conti","Credential Access","https://github.com/mustafashykh/router-scan","1","0","N/A","N/A","8","1","83","44","2019-02-24T14:31:16Z","2019-02-24T07:52:22Z","61944"
"*uploading mstscax proxy dll to *",".{0,1000}uploading\smstscax\sproxy\sdll\sto\s.{0,1000}","offensive_tool_keyword","ThievingFox","collection of post-exploitation tools to gather credentials from various password managers","T1555 - T1003 - T1056 - T1070","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Slowerzs/ThievingFox","1","0","N/A","N/A","10","6","535","65","2024-03-28T19:58:03Z","2024-01-20T23:22:52Z","61955"
"*use incognito*",".{0,1000}use\sincognito.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Token Manipulation Tokens can be impersonated from other users with a session/running processes on the machine. Most C2 frameworks have functionality for this built-in (such as the Steal Token functionality in Cobalt Strike)","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","61989"
"*UsePrtAdminAccount*",".{0,1000}UsePrtAdminAccount.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","62009"
"*UsePrtImperonsationAccount*",".{0,1000}UsePrtImperonsationAccount.{0,1000}","offensive_tool_keyword","MailSniper","MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.","T1087.003 - T1110.003 - T1114.002","TA0006 -TA0009 -TA0007","N/A","Leafminer","Credential Access","https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1","1","1","N/A","N/A","N/A","10","3046","580","2024-08-07T18:11:58Z","2016-09-08T00:36:51Z","62010"
"*--user_file*--password_file*",".{0,1000}\-\-user_file.{0,1000}\-\-password_file.{0,1000}","offensive_tool_keyword","Spray365","Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).","T1110.003","TA0006","N/A","N/A","Credential Access","https://github.com/MarkoH17/Spray365","1","1","N/A","N/A","N/A","4","348","58","2022-07-14T14:45:57Z","2021-11-04T18:20:39Z","62016"
"*user_to_secretsdump.py*",".{0,1000}user_to_secretsdump\.py.{0,1000}","offensive_tool_keyword","ntdissector","Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.","T1003.003","TA0006 ","N/A","N/A","Credential Access","https://github.com/synacktiv/ntdissector","1","0","N/A","N/A","9","2","139","17","2024-08-16T14:18:35Z","2023-09-05T12:13:47Z","62018"
"*USER=!!ABSENT!!*OPERATION=adduser*MODGROUP=admin*",".{0,1000}USER\=!!ABSENT!!.{0,1000}OPERATION\=adduser.{0,1000}MODGROUP\=admin.{0,1000}","offensive_tool_keyword","POC","Ivanti Authent Bypass CVE-2024-7593 - Successful exploitation could lead to authentication bypass and creation of an administrator user","T1078 - T1136 - T1078.001","TA0006 - TA0004 - TA0005","N/A","N/A","Credential Access","https://x.com/mthcht/status/1823463842459848906","1","0","N/A","in ivanti vtm audit logs","10","10","N/A","N/A","N/A","N/A","62020"
"*userenum-password-timing*",".{0,1000}userenum\-password\-timing.{0,1000}","offensive_tool_keyword","sshamble","SSHamble is a research tool for analyzing SSH implementations focusing on attacks against authentication - timing analysis and post-session enumeration.","T1021 - T1040 - T1592 - T1033","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/runZeroInc/sshamble","1","0","N/A","N/A","10","10","946","74","2025-04-07T15:08:38Z","2024-07-27T20:32:10Z","62036"
"*username-anarchy *",".{0,1000}username\-anarchy\s.{0,1000}","offensive_tool_keyword","username-anarchy","Tools for generating usernames when penetration testing. Usernames are half the password brute force problem.","T1110 - T1134 - T1078","TA0006","N/A","Black Basta","Credential Access","https://github.com/urbanadventurer/username-anarchy","1","0","N/A","N/A","N/A","10","1000","140","2024-09-20T01:57:59Z","2012-11-07T05:35:10Z","62041"
"*Users\\Public\\lsass.dmp*",".{0,1000}Users\\\\Public\\\\lsass\.dmp.{0,1000}","offensive_tool_keyword","DumpLSASS","Lsass dumping tool - 50 ways of dumping lsass","T1003.001 - T1055.001 - T1620","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/elementalsouls/DumpLSASS","1","0","#content","N/A","10","1","33","5","2024-02-27T11:25:11Z","2023-04-09T12:11:10Z","62049"
"*Users\\Public\\panda.sense*",".{0,1000}Users\\\\Public\\\\panda\.sense.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","62050"
"*Users\Public\callback.el*",".{0,1000}Users\\Public\\callback\.el.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","62052"
"*users\public\example.bin*",".{0,1000}users\\public\\example\.bin.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","0","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","62053"
"*Users\Public\panda.sense*",".{0,1000}Users\\Public\\panda\.sense.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","N/A","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","62054"
"*users\public\temp.bin*",".{0,1000}users\\public\\temp\.bin.{0,1000}","offensive_tool_keyword","forkatz","credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege","T1003.002 - T1558.002 - T1055.001","TA0006 - TA0004","N/A","N/A","Credential Access","https://github.com/Barbarisch/forkatz","1","0","N/A","N/A","10","2","124","16","2021-05-22T00:23:04Z","2021-05-21T18:42:22Z","62055"
"*users_only_cracked_through_lm.html*",".{0,1000}users_only_cracked_through_lm\.html.{0,1000}","offensive_tool_keyword","DPAT","Domain Password Audit Tool for Pentesters","T1003 - T1087 - T1110 - T1555","TA0006 - TA0004 - TA0002 - TA0005","N/A","N/A","Credential Access","https://github.com/clr2of8/DPAT","1","0","N/A","N/A","10","10","954","156","2022-06-24T21:41:43Z","2016-11-22T22:00:21Z","62064"
"*Uses eBPF to dump secrets use by PAM (Authentication) module*",".{0,1000}Uses\seBPF\sto\sdump\ssecrets\suse\sby\sPAM\s\(Authentication\)\smodule.{0,1000}","offensive_tool_keyword","pamspy","Credentials Dumper for Linux using eBPF","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/citronneur/pamspy","1","0","#linux","N/A","10","10","1135","63","2024-09-09T13:19:12Z","2022-07-01T19:33:43Z","62066"
"*using Rubeus.Domain;*",".{0,1000}using\sRubeus\.Domain\;.{0,1000}","offensive_tool_keyword","Rubeus","Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.","T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004","TA0006","N/A","Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR","Credential Access","https://github.com/GhostPack/Rubeus","1","0","N/A","N/A","10","10","4409","804","2025-04-17T10:11:57Z","2018-09-23T23:59:03Z","62087"
"*using SharpDecryptPwd*",".{0,1000}using\sSharpDecryptPwd.{0,1000}","offensive_tool_keyword","SharpDecryptPwd","Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc","T1003.008 - T1555.004 - T1552.002","TA0006","N/A","N/A","Credential Access","https://github.com/RowTeam/SharpDecryptPwd","1","0","N/A","N/A","10","8","769","117","2022-03-04T02:49:31Z","2022-02-25T11:21:43Z","62088"
"*using static BackupCreds.Interop*",".{0,1000}using\sstatic\sBackupCreds\.Interop.{0,1000}","offensive_tool_keyword","BackupCreds","A C# implementation of dumping credentials from Windows Credential Manager","T1003 - T1555","TA0006 - TA0005","N/A","Black Basta","Credential Access","https://github.com/leftp/BackupCreds","1","0","N/A","N/A","9","1","57","10","2023-09-23T10:37:05Z","2023-09-23T06:42:20Z","62094"
"*usr/share/seclists*",".{0,1000}usr\/share\/seclists.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62100"
"*usr/share/wordlists/rockyou.txt*",".{0,1000}usr\/share\/wordlists\/rockyou\.txt.{0,1000}","offensive_tool_keyword","creddump7","extracts various forms of credentials from Windows systems","T1003 - T1081 - T1040 - T1110 - T1555","TA0006 - TA0009","N/A","Sandworm","Credential Access","https://github.com/CiscoCXSecurity/creddump7","1","0","N/A","N/A","10","4","394","106","2020-10-02T13:25:16Z","2014-06-24T13:18:38Z","62101"
"*V1V1/DecryptTeamViewer*",".{0,1000}V1V1\/DecryptTeamViewer.{0,1000}","offensive_tool_keyword","DecryptTeamViewer","Enumerate and decrypt TeamViewer credentials from Windows registry","T1552.001 - T1003 - T1119 - T1012","TA0006 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/V1V1/DecryptTeamViewer","1","1","N/A","N/A","7","3","241","62","2021-12-05T09:19:56Z","2020-02-07T07:50:47Z","62117"
"*vanhauser-thc/thc-hydra*",".{0,1000}vanhauser\-thc\/thc\-hydra.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","1","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","62122"
"*vaultSchema.Add(new Guid(""""4BF4C442-9B8A-41A0-B380-DD4A704DDB28""""*",".{0,1000}vaultSchema\.Add\(new\sGuid\(\""4BF4C442\-9B8A\-41A0\-B380\-DD4A704DDB28\"".{0,1000}","offensive_tool_keyword","SharpWeb","SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records","T1555.003 - T1539 - T1602 - T1074.001","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/StarfireLab/SharpWeb","1","0","#content","N/A","10","8","703","79","2024-11-15T07:05:34Z","2023-10-09T06:48:23Z","62125"
"*vdi2john.pl*",".{0,1000}vdi2john\.pl.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","62153"
"*veeam-creds-main*",".{0,1000}veeam\-creds\-main.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","62164"
"*Veeam-Get-Creds.ps1*",".{0,1000}Veeam\-Get\-Creds\.ps1.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","62165"
"*VeeamGetCreds.yaml*",".{0,1000}VeeamGetCreds\.yaml.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","62166"
"*veeampot.py*",".{0,1000}veeampot\.py.{0,1000}","offensive_tool_keyword","veeam-creds","Collection of scripts to retrieve stored passwords from Veeam Backup","T1003 - T1555.005 - T1552","TA0006 - TA0007","N/A","Dispossessor - Dagon Locker","Credential Access","https://github.com/sadshade/veeam-creds","1","1","N/A","N/A","10","2","126","32","2024-12-12T10:23:54Z","2021-02-05T03:13:08Z","62168"
"*Viedx765valdi\\Usedx765er Data*",".{0,1000}Viedx765valdi\\\\Usedx765er\sData.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","62181"
"*vletoux/NTLMInjector*",".{0,1000}vletoux\/NTLMInjector.{0,1000}","offensive_tool_keyword","NTLMInjector","restore the user password after a password reset (get the previous hash with DCSync)","T1555 - T1556.003 - T1078 - T1110.003 - T1201 - T1003","TA0001 - TA0003 - TA0004 - TA0006 - TA0007","N/A","N/A","Credential Access","https://github.com/vletoux/NTLMInjector","1","1","N/A","N/A","10","2","167","29","2017-06-08T19:01:21Z","2017-06-04T07:25:36Z","62234"
"*vmx2john.py*",".{0,1000}vmx2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","62244"
"*vncdumpdll*",".{0,1000}vncdumpdll.{0,1000}","offensive_tool_keyword","vncpwdump","vnc password sniffer","T1003.003 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.codebus.net/d-2v0u.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62248"
"*VNCPassView.exe*",".{0,1000}VNCPassView\.exe.{0,1000}","signature_keyword","VNCPassView","recover the passwords stored by the VNC tool","T1003 - T1555 - T1081","TA0006 - TA0007","N/A","GoGoogle - 8BASE","Credential Access","https://www.nirsoft.net/utils/vnc_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62251"
"*vncpcap2john.*",".{0,1000}vncpcap2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","62252"
"*vncpwdump.*",".{0,1000}vncpwdump\..{0,1000}","offensive_tool_keyword","vncpwdump","vnc password sniffer","T1003.003 - T1021.001","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.codebus.net/d-2v0u.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62253"
"*vssadmin create shadow /for=C:* \Temp\*.tmp*",".{0,1000}vssadmin\screate\sshadow\s\/for\=C\:.{0,1000}\s\\Temp\\.{0,1000}\.tmp.{0,1000}","greyware_tool_keyword","vssadmin","the actor creating a Shadow Copy and then extracting a copy of the ntds.dit file from it.","T1003.001 - T1567.001 - T1070.004","TA0005 - TA0003 - TA0007","N/A","Volt Typhoon","Credential Access","https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62282"
"*vssadmin delete shadows /shadow=*",".{0,1000}vssadmin\sdelete\sshadows\s\/shadow\=.{0,1000}","offensive_tool_keyword","knowsmore","KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).","T1003 - T1098 - T1134 - T1484 - T1178 - T1078","TA0006 - TA0008 - TA0003 - TA0011 - TA0005","N/A","Black Basta","Credential Access","https://github.com/helviojunior/knowsmore","1","0","N/A","N/A","10","3","223","32","2025-04-14T14:52:09Z","2023-01-09T14:02:37Z","62287"
"*'W','i','n','d','o','w','s','\\','S','y','s','t','e','m','3','2'*",".{0,1000}\'W\',\'i\',\'n\',\'d\',\'o\',\'w\',\'s\',\'\\\\\',\'S\',\'y\',\'s\',\'t\',\'e\',\'m\',\'3\',\'2\'.{0,1000}","offensive_tool_keyword","DumpThatLSASS","Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk","T1003 - T1055.011 - T1027 - T1564.001","TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/peiga/DumpThatLSASS","1","0","N/A","N/A","10","1","31","79","2022-09-24T22:39:04Z","2022-09-24T22:41:19Z","62316"
"*WaaSMedicPayload.dll*",".{0,1000}WaaSMedicPayload\.dll.{0,1000}","offensive_tool_keyword","PPLmedic","Dump the memory of any PPL with a Userland exploit chain","T1003 - T1055 - T1564.001","TA0005 - TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/itm4n/PPLmedic","1","0","N/A","N/A","8","4","333","36","2023-03-17T15:58:24Z","2023-03-10T12:07:01Z","62341"
"*Walledx765ets/Binanedx765ce*",".{0,1000}Walledx765ets\/Binanedx765ce.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","62347"
"*Walledx765ets/Eleedx765ctrum*",".{0,1000}Walledx765ets\/Eleedx765ctrum.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","62348"
"*Walledx765ets/Ethedx765ereum*",".{0,1000}Walledx765ets\/Ethedx765ereum.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","62349"
"*wavestone-cdt/Invoke-CleverSpray*",".{0,1000}wavestone\-cdt\/Invoke\-CleverSpray.{0,1000}","offensive_tool_keyword","Invoke-CleverSpray","Password Spraying Script detecting current and previous passwords of Active Directory User","T1110.003 - T1110.001","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/wavestone-cdt/Invoke-CleverSpray","1","1","N/A","N/A","10","1","65","11","2021-09-09T07:35:32Z","2018-11-29T10:05:25Z","62370"
"*waza1234*",".{0,1000}waza1234.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz exploitation default password","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","1","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","62374"
"*Waza1234/Waza1234/Waza1234/*",".{0,1000}Waza1234\/Waza1234\/Waza1234\/.{0,1000}","offensive_tool_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","N/A","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","62375"
"*WCE %s (Windows Credentials Editor)*",".{0,1000}WCE\s\%s\s\(Windows\sCredentials\sEditor\).{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","62381"
"*wce -i 3e5 -s *",".{0,1000}wce\s\-i\s3e5\s\-s\s.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","0","N/A","N/A","8","4","N/A","N/A","N/A","N/A","62382"
"*WCE v1.0 (Windows Credentials Editor)*",".{0,1000}WCE\sv1\.0\s\(Windows\sCredentials\sEditor\).{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","62383"
"*WCE v1.2 (Windows Credentials Editor)*",".{0,1000}WCE\sv1\.2\s\(Windows\sCredentials\sEditor\).{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","62384"
"*wce*getlsasrvaddr.exe*",".{0,1000}wce.{0,1000}getlsasrvaddr\.exe.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","62385"
"*wce-master.zip*",".{0,1000}wce\-master\.zip.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","62386"
"*wce-universal.exe*",".{0,1000}wce\-universal\.exe.{0,1000}","offensive_tool_keyword","wce","Windows Credentials Editor","T1003.002 - T1003.003 - T1558.001 - T1558.003 - T1110 - T1055.001","TA0006 - TA0005 - TA0002","N/A","APT27 - Turla - FIN5 - GALLIUM - APT22 - FIN6 - Tick - APT40 - APT39 - ","Credential Access","https://www.kali.org/tools/wce/","1","1","N/A","N/A","8","4","N/A","N/A","N/A","N/A","62387"
"*wdigest/decryptor.py*",".{0,1000}wdigest\/decryptor\.py.{0,1000}","offensive_tool_keyword","pypykatz","Mimikatz implementation in pure Python","T1003.002 - T1055 - T1078","TA0003 - TA0002 - TA0004","N/A","Black Basta","Credential Access","https://github.com/skelsec/pypykatz","1","1","N/A","N/A","N/A","10","2989","394","2025-02-27T20:37:07Z","2018-05-25T22:21:20Z","62397"
"*weakpass.com/crack-js*",".{0,1000}weakpass\.com\/crack\-js.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62407"
"*weakpass.com/generate*",".{0,1000}weakpass\.com\/generate.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62408"
"*weakpass.com/wordlist/*",".{0,1000}weakpass\.com\/wordlist\/.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62409"
"*weakpass/crack-js*",".{0,1000}weakpass\/crack\-js.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62410"
"*weakpass_3.7z*",".{0,1000}weakpass_3\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62411"
"*weakpass_3a.7z.torrent*",".{0,1000}weakpass_3a\.7z\.torrent.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62412"
"*weakpass-main.*",".{0,1000}weakpass\-main\..{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","62413"
"*WebAuthn proxy running*",".{0,1000}WebAuthn\sproxy\srunning.{0,1000}","offensive_tool_keyword","Shwmae","Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials","T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002","TA0006 - TA0005 - TA0003 - TA0004","N/A","N/A","Credential Access","https://github.com/CCob/Shwmae","1","0","N/A","N/A","7","2","149","12","2025-01-27T14:36:07Z","2024-03-21T15:05:03Z","62419"
"*WebBrowserPassView.exe*",".{0,1000}WebBrowserPassView\.exe.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62422"
"*WebBrowserPassView.zip*",".{0,1000}WebBrowserPassView\.zip.{0,1000}","offensive_tool_keyword","webBrowserPassView","WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser.","T1003 - T1555 - T1503","TA0006 - TA0007 - TA0009","N/A","Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki","Credential Access","https://www.nirsoft.net/utils/web_browser_password.html","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62424"
"*Wedx765eb Daedx765ta*",".{0,1000}Wedx765eb\sDaedx765ta.{0,1000}","offensive_tool_keyword","LummaC2-Stealer-sample","artifacts from a specific sample of lumma stealer - source code on github","T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539","TA0006 - TA0010","Lumma Stealer","N/A","Credential Access","https://github.com/x86byte/LummaC2-Stealer","1","0","#content","can be used for yara scans","10","1","31","5","2025-02-18T00:38:59Z","2025-02-15T12:28:05Z","62441"
"*WELCOME TO MULTI-METHOD LSASS DUMPING TOOL*",".{0,1000}WELCOME\sTO\sMULTI\-METHOD\sLSASS\sDUMPING\sTOOL.{0,1000}","offensive_tool_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#content","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","62446"
"*werfault_shtinkering*",".{0,1000}werfault_shtinkering.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","62454"
"*werfault_silent_process_exit*",".{0,1000}werfault_silent_process_exit.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","62455"
"*wesside-ng -*",".{0,1000}wesside\-ng\s\-.{0,1000}","offensive_tool_keyword","aircrack","cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption","T1078 - T1496 - T1040","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/aircrack-ng/aircrack-ng","1","0","N/A","N/A","5","10","5967","1032","2024-12-19T21:36:56Z","2018-03-10T17:11:11Z","62458"
"*wevtutil* cl ""Microsoft-Windows-Storage-ATAPort/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Storage\-ATAPort\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62463"
"*wevtutil* cl ""Microsoft-Windows-Storage-ClassPnP/A*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Storage\-ClassPnP\/A.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62464"
"*wevtutil* cl ""Microsoft-Windows-Storage-Disk/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Storage\-Disk\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62465"
"*wevtutil* cl ""Microsoft-Windows-StorageManagement/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-StorageManagement\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62466"
"*wevtutil* cl ""Microsoft-Windows-StorageSpaces-Driver/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-StorageSpaces\-Driver\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62467"
"*wevtutil* cl ""Microsoft-Windows-StorageSpaces-ManagementAgent/WHC*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-StorageSpaces\-ManagementAgent\/WHC.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62468"
"*wevtutil* cl ""Microsoft-Windows-StorageSpaces-SpaceManager/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-StorageSpaces\-SpaceManager\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62469"
"*wevtutil* cl ""Microsoft-Windows-Storage-Storport/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Storage\-Storport\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62470"
"*wevtutil* cl ""Microsoft-Windows-Storage-Tiering/Admin*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Storage\-Tiering\/Admin.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62471"
"*wevtutil* cl ""Microsoft-Windows-Storage-Tiering-IoHeat/Heat*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Storage\-Tiering\-IoHeat\/Heat.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62472"
"*wevtutil* cl ""Microsoft-Windows-Store/Operational*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Store\/Operational.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62473"
"*wevtutil* cl ""Microsoft-Windows-Subsys-Csr/Operational*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Subsys\-Csr\/Operational.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62474"
"*wevtutil* cl ""Microsoft-Windows-Subsys-SMSS/Operational*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Subsys\-SMSS\/Operational.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62475"
"*wevtutil* cl ""Microsoft-Windows-Superfetch/Main*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Superfetch\/Main.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62476"
"*wevtutil* cl ""Microsoft-Windows-Superfetch/PfApLog*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Superfetch\/PfApLog.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62477"
"*wevtutil* cl ""Microsoft-Windows-Superfetch/StoreLog*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Superfetch\/StoreLog.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62478"
"*wevtutil* cl ""Microsoft-Windows-Sysmon/Operational*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Sysmon\/Operational.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62479"
"*wevtutil* cl ""Microsoft-Windows-Sysprep/Analytic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Sysprep\/Analytic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62480"
"*wevtutil* cl ""Microsoft-Windows-System-Profile-HardwareId/Diagnostic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-System\-Profile\-HardwareId\/Diagnostic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62481"
"*wevtutil* cl ""Microsoft-Windows-SystemSettingsHandlers/Debug*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-SystemSettingsHandlers\/Debug.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62482"
"*wevtutil* cl ""Microsoft-Windows-SystemSettingsThreshold/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-SystemSettingsThreshold\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62483"
"*wevtutil* cl ""Microsoft-Windows-TaskbarCPL/Diagnostic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-TaskbarCPL\/Diagnostic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62484"
"*wevtutil* cl ""Microsoft-Windows-TaskScheduler/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-TaskScheduler\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62485"
"*wevtutil* cl ""Microsoft-Windows-TCPIP/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-TCPIP\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62486"
"*wevtutil* cl ""Microsoft-Windows-TerminalServices-*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-TerminalServices\-.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62487"
"*wevtutil* cl ""Microsoft-Windows-Tethering-Manager/Analytic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Tethering\-Manager\/Analytic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62488"
"*wevtutil* cl ""Microsoft-Windows-Tethering-Station/Analytic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Tethering\-Station\/Analytic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62489"
"*wevtutil* cl ""Microsoft-Windows-ThemeCPL/Diagnostic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-ThemeCPL\/Diagnostic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62490"
"*wevtutil* cl ""Microsoft-Windows-ThemeUI/Diagnostic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-ThemeUI\/Diagnostic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62491"
"*wevtutil* cl ""Microsoft-Windows-Threat-Intelligence/Analytic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Threat\-Intelligence\/Analytic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62492"
"*wevtutil* cl ""Microsoft-Windows-Time-Service/Operational*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-Time\-Service\/Operational.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62493"
"*wevtutil* cl ""Microsoft-Windows-TSF-msctf/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-TSF\-msctf\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62494"
"*wevtutil* cl ""Microsoft-Windows-TTS/Diagnostic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-TTS\/Diagnostic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62495"
"*wevtutil* cl ""Microsoft-Windows-TunnelDriver*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-TunnelDriver.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62496"
"*wevtutil* cl ""Microsoft-Windows-TWinUI/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-TWinUI\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62497"
"*wevtutil* cl ""Microsoft-Windows-TZSync/*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-TZSync\/.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62498"
"*wevtutil* cl ""Microsoft-Windows-TZUtil/Operational*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-TZUtil\/Operational.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62499"
"*wevtutil* cl ""Microsoft-Windows-UAC/Operational*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-UAC\/Operational.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62500"
"*wevtutil* cl ""Microsoft-Windows-UAC-FileVirtualization/Operational*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-UAC\-FileVirtualization\/Operational.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62501"
"*wevtutil* cl ""Microsoft-Windows-UIAnimation/Diagnostic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-UIAnimation\/Diagnostic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62502"
"*wevtutil* cl ""Microsoft-Windows-UI-Shell/Diagnostic*",".{0,1000}wevtutil.{0,1000}\scl\s\""Microsoft\-Windows\-UI\-Shell\/Diagnostic.{0,1000}","greyware_tool_keyword","wevtutil","observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older))","T1003.001","TA0006","N/A","APT1","Credential Access","https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62503"
"*wfuzz/wordlist*",".{0,1000}wfuzz\/wordlist.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62522"
"*wgen.py*",".{0,1000}wgen\.py.{0,1000}","offensive_tool_keyword","Python-Wordlist-Generator","Create awesome wordlists with Python.","T1110 - T1588 - T1602","TA0001 - TA0006","N/A","N/A","Credential Access","https://github.com/agusmakmun/Python-Wordlist-Generator","1","0","N/A","N/A","N/A","2","122","35","2019-06-12T13:23:17Z","2015-05-22T12:32:01Z","62525"
"*wget*/drapl0n/DuckyLogger/blob/main/xinput\?raw=true*",".{0,1000}wget.{0,1000}\/drapl0n\/DuckyLogger\/blob\/main\/xinput\\\?raw\=true.{0,1000}","offensive_tool_keyword","OMGLogger","Key logger which sends each and every key stroke of target remotely/locally.","T1056.001 - T1562.001","TA0004 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/OMGLogger","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","62533"
"*wh0amitz/BypassCredGuard*",".{0,1000}wh0amitz\/BypassCredGuard.{0,1000}","offensive_tool_keyword","BypassCredGuard","Credential Guard Bypass Via Patching Wdigest Memory","T1003 - T1112 - T1555.002 - T1574","TA0006 - TA0005 - TA0040","N/A","N/A","Credential Access","https://github.com/wh0amitz/BypassCredGuard","1","1","N/A","N/A","10","4","323","52","2023-02-03T06:55:43Z","2023-01-18T15:16:11Z","62537"
"*Whirlpool-Orig-512.verified.test-vectors.txt*",".{0,1000}Whirlpool\-Orig\-512\.verified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","62556"
"*Whirlpool-Tweak-512.verified.test-vectors.txt*",".{0,1000}Whirlpool\-Tweak\-512\.verified\.test\-vectors\.txt.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","62557"
"*whiskeysaml.py*",".{0,1000}whiskeysaml\.py.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","62562"
"*whiskeysamlandfriends*",".{0,1000}whiskeysamlandfriends.{0,1000}","offensive_tool_keyword","whiskeysamlandfriends","GoldenSAML Attack Libraries and Framework","T1606.002","TA0006","N/A","N/A","Credential Access","https://github.com/secureworks/whiskeysamlandfriends","1","1","N/A","N/A","N/A","1","72","9","2024-06-05T14:56:28Z","2021-11-04T15:30:12Z","62563"
"*WhiteOakSecurity/GoAWSConsoleSpray*",".{0,1000}WhiteOakSecurity\/GoAWSConsoleSpray.{0,1000}","offensive_tool_keyword","GoAWSConsoleSpray","brute-force AWS IAM Console credentials to discover valid logins for user accounts","T1078 - T1110 - T1187 - T1110.001","TA0006 - TA0007 - TA0003 - TA0001","N/A","N/A","Credential Access","https://github.com/WhiteOakSecurity/GoAWSConsoleSpray","1","1","N/A","N/A","9","1","29","5","2022-06-15T18:16:21Z","2022-06-15T18:11:39Z","62565"
"*whoami.py*",".{0,1000}whoami\.py.{0,1000}","offensive_tool_keyword","crackmapexec","A swiss army knife for pentesting networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","62575"
"*wifibroot.py*",".{0,1000}wifibroot\.py.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","62590"
"*wifi-bruteforcer*",".{0,1000}wifi\-bruteforcer.{0,1000}","offensive_tool_keyword","wifi-bruteforcer-fsecurify","Android application to brute force WiFi passwords without requiring a rooted device.","T1110 - T1555 - T1051 - T1081","TA0002 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/faizann24/wifi-bruteforcer-fsecurify","1","1","N/A","network exploitation tool","N/A","10","1324","319","2022-04-16T02:59:36Z","2017-01-02T17:54:33Z","62591"
"*wifi-bruteforcer*",".{0,1000}wifi\-bruteforcer.{0,1000}","offensive_tool_keyword","wifi-bruteforcer-fsecurity","Wifi bruteforcer","T1110 - T1114 - T1601 - T1602 - T1603","TA0003 - TA0008","N/A","N/A","Credential Access","https://github.com/faizann24/wifi-bruteforcer-fsecurify","1","1","N/A","network exploitation tool","N/A","10","1324","319","2022-04-16T02:59:36Z","2017-01-02T17:54:33Z","62592"
"*wifite --crack*",".{0,1000}wifite\s\-\-crack.{0,1000}","offensive_tool_keyword","wifite2","This repo is a complete re-write of wifite. a Python script for auditing wireless networks.Run wifite. select your targets. and Wifite will automatically start trying to capture or crack the password.","T1590 - T1170 - T1595","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/derv82/wifite2","1","0","N/A","network exploitation tool","N/A","10","6838","1403","2024-08-20T12:34:38Z","2015-05-30T06:09:52Z","62598"
"*wifite -e *",".{0,1000}wifite\s\-e\s.{0,1000}","offensive_tool_keyword","wifite2","This repo is a complete re-write of wifite. a Python script for auditing wireless networks.Run wifite. select your targets. and Wifite will automatically start trying to capture or crack the password.","T1590 - T1170 - T1595","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/derv82/wifite2","1","0","N/A","network exploitation tool","N/A","10","6838","1403","2024-08-20T12:34:38Z","2015-05-30T06:09:52Z","62600"
"*wifite --wep *",".{0,1000}wifite\s\-\-wep\s.{0,1000}","offensive_tool_keyword","wifite2","This repo is a complete re-write of wifite. a Python script for auditing wireless networks.Run wifite. select your targets. and Wifite will automatically start trying to capture or crack the password.","T1590 - T1170 - T1595","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/derv82/wifite2","1","0","N/A","network exploitation tool","N/A","10","6838","1403","2024-08-20T12:34:38Z","2015-05-30T06:09:52Z","62602"
"*Wifite.py*",".{0,1000}Wifite\.py.{0,1000}","offensive_tool_keyword","wifite2","This repo is a complete re-write of wifite. a Python script for auditing wireless networks.Run wifite. select your targets. and Wifite will automatically start trying to capture or crack the password.","T1590 - T1170 - T1595","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/derv82/wifite2","1","1","N/A","network exploitation tool","N/A","10","6838","1403","2024-08-20T12:34:38Z","2015-05-30T06:09:52Z","62603"
"*wifite2.git*",".{0,1000}wifite2\.git.{0,1000}","offensive_tool_keyword","wifite2","This repo is a complete re-write of wifite. a Python script for auditing wireless networks.Run wifite. select your targets. and Wifite will automatically start trying to capture or crack the password.","T1590 - T1170 - T1595","TA0002 - TA0003 - TA0007","N/A","N/A","Credential Access","https://github.com/derv82/wifite2","1","1","N/A","network exploitation tool","N/A","10","6838","1403","2024-08-20T12:34:38Z","2015-05-30T06:09:52Z","62604"
"*Will add the user to the administrator group (0x220)*",".{0,1000}Will\sadd\sthe\suser\sto\sthe\sadministrator\sgroup\s\(0x220\).{0,1000}","offensive_tool_keyword","chntpw","reset a password on your system","T1003 - T1078","TA0006","N/A","N/A","Credential Access","https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip","1","0","N/A","N/A","10","10","N/A","N/A","N/A","N/A","62606"
"*Win.Countermeasure.KeeFarce*",".{0,1000}Win\.Countermeasure\.KeeFarce.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","#Avsignature","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","62609"
"*Win.Tool.ADPassHunt-*",".{0,1000}Win\.Tool\.ADPassHunt\-.{0,1000}","offensive_tool_keyword","ADPassHunt","credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)","T1003.003 - T1552.006","TA0006 - TA0007","N/A","N/A","Credential Access","https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","62614"
"*Win.Tool.Sharpdump*",".{0,1000}Win\.Tool\.Sharpdump.{0,1000}","signature_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#Avsignature","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","62617"
"*Win32.LaZagne*",".{0,1000}Win32\.LaZagne.{0,1000}","signature_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","#Avsignature","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","62626"
"*Win32/PSWTool.Gsecdump*",".{0,1000}Win32\/PSWTool\.Gsecdump.{0,1000}","signature_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","62639"
"*Win32/PWDump*",".{0,1000}Win32\/PWDump.{0,1000}","signature_keyword","PwDump7","pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format.","T1003.001 - T1555.003 - T1077","TA0006 - TA0008","N/A","N/A","Credential Access","https://www.openwall.com/passwords/windows-pwdump","1","0","#Avsignature","N/A","10","8","N/A","N/A","N/A","N/A","62640"
"*Win32/Riskware.Mimikatz*",".{0,1000}Win32\/Riskware\.Mimikatz.{0,1000}","signature_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#Avsignature","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","62641"
"*Win32:Gsecdump*",".{0,1000}Win32\:Gsecdump.{0,1000}","signature_keyword","gsecdump","credential dumper used to obtain password hashes and LSA secrets from Windows operating systems","T1003.001 - T1003.002 - T1555.003 - T1555.001","TA0006 - TA0008","N/A","APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick","Credential Access","https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe","1","0","#Avsignature","N/A","10","10","N/A","N/A","N/A","N/A","62647"
"*Win32:KFarce-C*",".{0,1000}Win32\:KFarce\-C.{0,1000}","offensive_tool_keyword","KeeFarce","Extracts passwords from a KeePass 2.x database directly from memory","T1003 - T1055 - T1059","TA0006 ","N/A","N/A","Credential Access","https://github.com/denandz/KeeFarce","1","0","#Avsignature","N/A","10","10","1009","132","2015-11-17T04:12:25Z","2015-10-27T05:29:04Z","62648"
"*Win64.Lazagne*",".{0,1000}Win64\.Lazagne.{0,1000}","signature_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","#Avsignature","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","62656"
"*Win64.ShadowDumper*",".{0,1000}Win64\.ShadowDumper.{0,1000}","signature_keyword","ShadowDumper","dump LSASS memory","T1003.001 - T1055","TA0006 ","N/A","N/A","Credential Access","https://github.com/Offensive-Panda/ShadowDumper","1","0","#Avsignature","N/A","10","6","521","83","2025-04-05T08:32:28Z","2024-11-10T15:26:28Z","62658"
"*Win64/MozillaCookiesView*",".{0,1000}Win64\/MozillaCookiesView.{0,1000}","signature_keyword","MozillaCookiesView","nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors","T1070 - T1552.001 - T1125 - T1005","TA0009 - TA0005","N/A","MuddyWater","Credential Access","https://www.nirsoft.net/utils/mzcv.html","1","0","#Avsignature","N/A","7","10","N/A","N/A","N/A","N/A","62661"
"*Win64/Outflank*",".{0,1000}Win64\/Outflank.{0,1000}","signature_keyword","Dumpert","Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls.","T1055.011 - T1003 - T1562.001 - T1027","TA0005 - TA0006","N/A","Dispossessor","Credential Access","https://github.com/outflanknl/Dumpert","1","0","#Avsignature","N/A","10","10","1523","246","2021-01-05T08:58:26Z","2019-06-17T18:22:01Z","62662"
"*Win64/Riskware Mimikatz*",".{0,1000}Win64\/Riskware\sMimikatz.{0,1000}","signature_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#Avsignature","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","62665"
"*Win64/Riskware.Mimikatz*",".{0,1000}Win64\/Riskware\.Mimikatz.{0,1000}","signature_keyword","mimikatz","mimikatz strings","T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003","TA0004 - TA0006 - TA0003 - TA0008 - TA0009","N/A","Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx","Credential Access","https://github.com/gentilkiwi/mimikatz","1","0","#Avsignature","N/A","10","10","20094","3854","2024-07-05T17:42:58Z","2014-04-06T18:30:02Z","62666"
"*WinBruteLogon* -v -u*",".{0,1000}WinBruteLogon.{0,1000}\s\-v\s\-u.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","0","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62676"
"*WinBruteLogon.dpr*",".{0,1000}WinBruteLogon\.dpr.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62677"
"*WinBruteLogon.dproj*",".{0,1000}WinBruteLogon\.dproj.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62678"
"*WinBruteLogon.exe*",".{0,1000}WinBruteLogon\.exe.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62680"
"*WinBruteLogon.exe*",".{0,1000}WinBruteLogon\.exe.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","1","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62681"
"*WinBruteLogon.res*",".{0,1000}WinBruteLogon\.res.{0,1000}","offensive_tool_keyword","win-brute-logon","Bruteforce cracking tool for windows users","T1110 - T1110.001 - T1110.002","TA0008 - TA0006 - TA0005","N/A","N/A","Credential Access","https://github.com/DarkCoderSc/win-brute-logon","1","1","N/A","N/A","N/A","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62682"
"*win-brute-logon-master.zip*",".{0,1000}win\-brute\-logon\-master\.zip.{0,1000}","offensive_tool_keyword","win-brute-logon","Crack any Microsoft Windows users password without any privilege (Guest account included)","T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005","TA0006 - TA0008 - TA0005","N/A","N/A","Credential Access","https://github.com/PhrozenIO/win-brute-logon","1","1","N/A","N/A","7","10","1138","191","2023-11-09T10:37:58Z","2020-05-14T21:46:50Z","62683"
"*Windows Credentials Editor v1.3beta*",".{0,1000}Windows\sCredentials\sEditor\sv1\.3beta.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","0","#content","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","62696"
"*windows*lsa_secrets.py*",".{0,1000}windows.{0,1000}lsa_secrets\.py.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","62712"
"*Windows.Hacktool.SharpDump*",".{0,1000}Windows\.Hacktool\.SharpDump.{0,1000}","signature_keyword","SharpDump","SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.","T1003 - T1055 - T1070","TA0006 - TA0005 - TA0008","N/A","Avaddon","Credential Access","https://github.com/GhostPack/SharpDump","1","0","#Avsignature","N/A","10","7","664","130","2019-02-07T02:52:20Z","2018-07-24T17:42:19Z","62715"
"*Windows/lazagne.spec*",".{0,1000}Windows\/lazagne\.spec.{0,1000}","offensive_tool_keyword","LaZagne","The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.","T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001","TA0006 - TA0009","N/A","Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT","Credential Access","https://github.com/AlessandroZ/LaZagne","1","1","N/A","N/A","10","10","9941","2062","2025-04-10T14:24:35Z","2015-02-16T14:10:02Z","62721"
"*WinSCPPasswdExtractor*",".{0,1000}WinSCPPasswdExtractor.{0,1000}","offensive_tool_keyword","WinSCPPasswdExtractor","Extract WinSCP Credentials from any Windows System or winscp config file","T1003.001 - T1083 - T1145","TA0003 - TA0007 - TA0008","N/A","N/A","Credential Access","https://github.com/NeffIsBack/WinSCPPasswdExtractor","1","1","N/A","N/A","N/A","1","16","3","2025-03-19T15:26:16Z","2022-12-20T11:55:55Z","62828"
"*wireless/captures.py*",".{0,1000}wireless\/captures\.py.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","62841"
"*wireless/cracker.py*",".{0,1000}wireless\/cracker\.py.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","62842"
"*wireless/pmkid.py*",".{0,1000}wireless\/pmkid\.py.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","62843"
"*wireless/sniper.py*",".{0,1000}wireless\/sniper\.py.{0,1000}","offensive_tool_keyword","wifibroot","A Wireless (WPA/WPA2) Pentest/Cracking tool. Captures & Crack 4-way handshake and PMKID key. Also. supports a deauthentication/jammer mode for stress testing","T1018 - T1040 - T1095 - T1113 - T1210 - T1437 - T1499 - T1557 - T1562 - T1573","TA0001 - TA0002 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://github.com/hash3liZer/WiFiBroot","1","1","N/A","network exploitation tool","N/A","10","1008","182","2021-01-15T09:07:36Z","2018-07-30T10:57:22Z","62844"
"*wirelesskeyview.exe*",".{0,1000}wirelesskeyview\.exe.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","62846"
"*wirelesskeyview.exe*",".{0,1000}wirelesskeyview\.exe.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62847"
"*wirelesskeyview.zip*",".{0,1000}wirelesskeyview\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","62848"
"*wirelesskeyview.zip*",".{0,1000}wirelesskeyview\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62849"
"*WirelessKeyView_x64.exe*",".{0,1000}WirelessKeyView_x64\.exe.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","62850"
"*WirelessKeyView_x64.exe*",".{0,1000}WirelessKeyView_x64\.exe.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62851"
"*wirelesskeyview-no-command-line.zip*",".{0,1000}wirelesskeyview\-no\-command\-line\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","62852"
"*wirelesskeyview-no-command-line.zip*",".{0,1000}wirelesskeyview\-no\-command\-line\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62853"
"*wirelesskeyview-x64.zip*",".{0,1000}wirelesskeyview\-x64\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1083 - T1552","TA0006 ","N/A","GoGoogle","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","7","10","N/A","N/A","N/A","N/A","62854"
"*wirelesskeyview-x64.zip*",".{0,1000}wirelesskeyview\-x64\.zip.{0,1000}","offensive_tool_keyword","WirelessKeyView","WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer ","T1003 - T1016 - T1021 - T1056 - T1110 - T1212 - T1552 - T1557","TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0007 - TA0011","N/A","N/A","Credential Access","https://www.nirsoft.net/utils/wireless_key.html","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62855"
"*WithSecureLabs/physmem2profit*",".{0,1000}WithSecureLabs\/physmem2profit.{0,1000}","offensive_tool_keyword","physmem2profit","Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely","T1003.001","TA0006","N/A","N/A","Credential Access","https://github.com/WithSecureLabs/physmem2profit","1","1","N/A","N/A","10","5","415","74","2022-07-27T03:33:59Z","2020-02-14T08:34:27Z","62886"
"*WLAN-Windows-Passwords-Discord-Exfiltration*",".{0,1000}WLAN\-Windows\-Passwords\-Discord\-Exfiltration.{0,1000}","offensive_tool_keyword","WLAN-Windows-Passwords","Opens PowerShell hidden - grabs wlan passwords - saves as a cleartext in a variable and exfiltrates info via Discord Webhook.","T1056.005 - T1552.001 - T1119 - T1071.001","TA0004 - TA0006 - TA0010 - TA0040","N/A","N/A","Credential Access","https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/WLAN-Windows-Passwords","1","0","N/A","N/A","10","10","904","310","2024-09-14T02:34:26Z","2021-09-08T20:33:18Z","62897"
"*wmic process call create*ntdsutil *ac i ntds* ifm*create full*",".{0,1000}wmic\sprocess\scall\screate.{0,1000}ntdsutil\s.{0,1000}ac\si\sntds.{0,1000}\sifm.{0,1000}create\sfull.{0,1000}","greyware_tool_keyword","wmic","The actor has executed WMIC commands [T1047] to create a copy of the ntds.dit file and SYSTEM registry hive using ntdsutil.exe","T1047 - T1005 - T1567.001","TA0002 - TA0003 - TA0007","N/A","MAZE - Conti - Hive - Quantum - TargetCompany - PYSA - AvosLocker - COZY BEAR","Credential Access","https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62923"
"*wmic shadowcopy call create Volume='C:\'*",".{0,1000}wmic\sshadowcopy\scall\screate\sVolume\=\'C\:\\\'.{0,1000}","offensive_tool_keyword","AD exploitation cheat sheet","Dumping secrets from a Volume Shadow Copy We can also create a Volume Shadow Copy of the SAM and SYSTEM files (which are always locked on the current system) so we can still copy them over to our local system. An elevated prompt is required for this.","T1110","TA0006","N/A","Black Basta","Credential Access","https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference","1","0","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","62949"
"*word_gen_b_varlen.*",".{0,1000}word_gen_b_varlen\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","63004"
"*Wordlist/ftp_p.txt*",".{0,1000}Wordlist\/ftp_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63006"
"*Wordlist/ftp_u.txt*",".{0,1000}Wordlist\/ftp_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63007"
"*Wordlist/ftp_up.txt*",".{0,1000}Wordlist\/ftp_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63008"
"*Wordlist/mssql_up.txt*",".{0,1000}Wordlist\/mssql_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63009"
"*Wordlist/mysql_up.txt*",".{0,1000}Wordlist\/mysql_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63010"
"*Wordlist/oracle_up.txt*",".{0,1000}Wordlist\/oracle_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63011"
"*Wordlist/pass.txt*",".{0,1000}Wordlist\/pass\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63012"
"*Wordlist/pop_p.txt*",".{0,1000}Wordlist\/pop_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63013"
"*Wordlist/pop_u.txt*",".{0,1000}Wordlist\/pop_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63014"
"*Wordlist/postgres_up.txt*",".{0,1000}Wordlist\/postgres_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63015"
"*Wordlist/smtp_p.txt*",".{0,1000}Wordlist\/smtp_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63016"
"*Wordlist/smtp_u.txt*",".{0,1000}Wordlist\/smtp_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63017"
"*Wordlist/snmp.txt*",".{0,1000}Wordlist\/snmp\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63018"
"*Wordlist/sql_p.txt*",".{0,1000}Wordlist\/sql_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63019"
"*Wordlist/sql_u.txt*",".{0,1000}Wordlist\/sql_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63020"
"*Wordlist/ssh_p.txt*",".{0,1000}Wordlist\/ssh_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63021"
"*Wordlist/ssh_u.txt*",".{0,1000}Wordlist\/ssh_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63022"
"*Wordlist/ssh_up.txt*",".{0,1000}Wordlist\/ssh_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63023"
"*Wordlist/telnet_p.txt*",".{0,1000}Wordlist\/telnet_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63024"
"*Wordlist/telnet_u.txt*",".{0,1000}Wordlist\/telnet_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63025"
"*Wordlist/telnet_up.txt*",".{0,1000}Wordlist\/telnet_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63026"
"*Wordlist/user.txt*",".{0,1000}Wordlist\/user\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63027"
"*Wordlist/vnc_p.txt*",".{0,1000}Wordlist\/vnc_p\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63028"
"*Wordlist/windows_u.txt*",".{0,1000}Wordlist\/windows_u\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63029"
"*Wordlist/windows_up.txt*",".{0,1000}Wordlist\/windows_up\.txt.{0,1000}","offensive_tool_keyword","t14m4t","Automated brute-forcing attack tool.","T1110","N/A","N/A","N/A","Credential Access","https://github.com/MS-WEB-BN/t14m4t","1","1","N/A","N/A","N/A","5","402","81","2021-04-02T09:52:45Z","2019-10-16T14:39:33Z","63030"
"*wordlist_TLAs.txt*",".{0,1000}wordlist_TLAs\.txt.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","63031"
"*--wordlist=*-passwords.txt*",".{0,1000}\-\-wordlist\=.{0,1000}\-passwords\.txt.{0,1000}","offensive_tool_keyword","icebreaker","Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment","T1110.001 - T1110.003 - T1059.003","TA0006 - TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/DanMcInerney/icebreaker","1","0","N/A","N/A","10","10","1190","163","2018-10-24T18:14:53Z","2017-12-04T03:42:28Z","63032"
"*wordlist-nthash-reversed*",".{0,1000}wordlist\-nthash\-reversed.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","63033"
"*wordlist-probable.txt*",".{0,1000}wordlist\-probable\.txt.{0,1000}","offensive_tool_keyword","wordlists","package contains the rockyou.txt wordlist","T1110.001","TA0006","N/A","N/A","Credential Access","https://www.kali.org/tools/wordlists/","1","1","N/A","N/A","N/A","N/A","N/A","N/A","N/A","N/A","63034"
"*wordlists*all_in_one.7z*",".{0,1000}wordlists.{0,1000}all_in_one\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","63035"
"*wordlists/dynamic-all.txt*",".{0,1000}wordlists\/dynamic\-all\.txt.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","63038"
"*wordlists/fasttrack.txt*",".{0,1000}wordlists\/fasttrack\.txt.{0,1000}","offensive_tool_keyword","cerbrutus","Network brute force tool. written in Python. Faster than other existing solutions (including the main leader in the network brute force market).","T1110 - T1040 - T1496","TA0006 - TA0008 - TA0009","N/A","N/A","Credential Access","https://github.com/Cerbrutus-BruteForcer/cerbrutus","1","1","N/A","N/A","N/A","4","385","57","2021-08-22T19:05:45Z","2021-07-07T19:11:40Z","63039"
"*wordlists/rockyou.txt'*",".{0,1000}wordlists\/rockyou\.txt\'.{0,1000}","offensive_tool_keyword","hashview","A web front-end for password cracking and analytics","T1110 - T1201","TA0006 - TA0002","N/A","N/A","Credential Access","https://github.com/hashview/hashview","1","1","N/A","N/A","10","4","373","41","2025-02-20T18:23:25Z","2020-11-23T19:21:06Z","63040"
"*wpapcap2john.*",".{0,1000}wpapcap2john\..{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","63049"
"*Wr173F0rF113(*",".{0,1000}Wr173F0rF113\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","63055"
"*write_payload_dll_transacted*",".{0,1000}write_payload_dll_transacted.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","63068"
"*WwAhAF0AIABJAG4ALQBtAGUAbQBvAHIAeQAgAEwAUwBBAFMAUwAgAGQAdQBtAHAAIABtAGUAdABoAG8AZAAgAGYAYQBpAGwAZQBkADoAIAAkAF8A*",".{0,1000}WwAhAF0AIABJAG4ALQBtAGUAbQBvAHIAeQAgAEwAUwBBAFMAUwAgAGQAdQBtAHAAIABtAGUAdABoAG8AZAAgAGYAYQBpAGwAZQBkADoAIAAkAF8A.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","63128"
"*WwAhAF0AIABMAFMAQQBTAFMAIABkAHUAbQBwACAAZgBhAGkAbABlAGQAIAB1AHMAaQBuAGcAIABzAHQAZQBhAGwAdABoACAAbQBlAHQAaABvAGQALgA=*",".{0,1000}WwAhAF0AIABMAFMAQQBTAFMAIABkAHUAbQBwACAAZgBhAGkAbABlAGQAIAB1AHMAaQBuAGcAIABzAHQAZQBhAGwAdABoACAAbQBlAHQAaABvAGQALgA\=.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","63129"
"*WwAhAF0AIABMAFMAQQBTAFMAIABkAHUAbQBwACAAZgBhAGkAbABlAGQALgAgAEUAeABpAHQAaQBuAGcAIABzAGMAcgBpAHAAdAAuAA==*",".{0,1000}WwAhAF0AIABMAFMAQQBTAFMAIABkAHUAbQBwACAAZgBhAGkAbABlAGQALgAgAEUAeABpAHQAaQBuAGcAIABzAGMAcgBpAHAAdAAuAA\=\=.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","63130"
"*WwAqAF0AIABBAHQAdABlAG0AcAB0AGkAbgBnACAAcwB0AGUAYQBsAHQAaAB5ACAATABTAEEAUwBTACAAZAB1AG0AcAAgAHUAcwBpAG4AZwAgAFAAbwB3AGUAcgBTAGgAZQBsAGwAIAByAGUAZgBsAGUAYwB0AGkAbwBuAC4ALgAuAA==*",".{0,1000}WwAqAF0AIABBAHQAdABlAG0AcAB0AGkAbgBnACAAcwB0AGUAYQBsAHQAaAB5ACAATABTAEEAUwBTACAAZAB1AG0AcAAgAHUAcwBpAG4AZwAgAFAAbwB3AGUAcgBTAGgAZQBsAGwAIAByAGUAZgBsAGUAYwB0AGkAbwBuAC4ALgAuAA\=\=.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","63131"
"*WwAqAF0AIABEAG8AbgBlAC4AIABDAGgAZQBjAGsAIAAkAHsAXwAvAD0AXABfAC8AXABfAF8ALwBcAF8ALwA9AFwALwA9AH0AIABmAG8AcgAgAHQAaABlACAAZgBpAG4AYQBsACAAYQByAGMAaABpAHYAZQAgAGkAZgAgAHMAdQBjAGMAZQBzAHMAZgB1AGwALgA=*",".{0,1000}WwAqAF0AIABEAG8AbgBlAC4AIABDAGgAZQBjAGsAIAAkAHsAXwAvAD0AXABfAC8AXABfAF8ALwBcAF8ALwA9AFwALwA9AH0AIABmAG8AcgAgAHQAaABlACAAZgBpAG4AYQBsACAAYQByAGMAaABpAHYAZQAgAGkAZgAgAHMAdQBjAGMAZQBzAHMAZgB1AGwALgA\=.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","63132"
"*WwArAF0AIABDAG8AbQBwAHIAZQBzAHMAaQBvAG4AIABjAG8AbQBwAGwAZQB0AGUAZAA6ACAAJAB7AF8ALwA9AFwAXwAvAFwAXwBfAC8AXABfAC8APQBcAC8APQB9AA==*",".{0,1000}WwArAF0AIABDAG8AbQBwAHIAZQBzAHMAaQBvAG4AIABjAG8AbQBwAGwAZQB0AGUAZAA6ACAAJAB7AF8ALwA9AFwAXwAvAFwAXwBfAC8AXABfAC8APQBcAC8APQB9AA\=\=.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","63133"
"*WwArAF0AIABEAHUAbQBwACAAZgBpAGwAZQAgAGUAbgBjAHIAeQBwAHQAZQBkACAAcwB1AGMAYwBlAHMAcwBmAHUAbABsAHkALgA=*",".{0,1000}WwArAF0AIABEAHUAbQBwACAAZgBpAGwAZQAgAGUAbgBjAHIAeQBwAHQAZQBkACAAcwB1AGMAYwBlAHMAcwBmAHUAbABsAHkALgA\=.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","63134"
"*WwArAF0AIABMAFMAQQBTAFMAIABkAHUAbQBwACAAYwByAGUAYQB0AGUAZAAgAHMAdQBjAGMAZQBzAHMAZgB1AGwAbAB5AC4A*",".{0,1000}WwArAF0AIABMAFMAQQBTAFMAIABkAHUAbQBwACAAYwByAGUAYQB0AGUAZAAgAHMAdQBjAGMAZQBzAHMAZgB1AGwAbAB5AC4A.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","0","#base64","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","63135"
"*www.ampliasecurity.com/research/wce12*",".{0,1000}www\.ampliasecurity\.com\/research\/wce12.{0,1000}","offensive_tool_keyword","WCE","manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication","T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212","TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/returnvar/wce","1","1","N/A","N/A","10","2","109","21","2019-09-15T05:26:40Z","2019-01-10T04:10:48Z","63142"
"*www.crackmd5.ru*",".{0,1000}www\.crackmd5\.ru.{0,1000}","offensive_tool_keyword","crackmd5.ru","site to crack md5 hashes used by Dispossessor ransomware groups and many others","T1003.002 - T1027 - T1213","TA0006 - TA0008 - TA0040","N/A","Dispossessor","Credential Access","https://vx-underground.org/Archive/Dispossessor%20Leaks","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","63146"
"*www.nicerat.com*",".{0,1000}www\.nicerat\.com.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","1","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","63159"
"*x90skysn3k/brutespray*",".{0,1000}x90skysn3k\/brutespray.{0,1000}","offensive_tool_keyword","brutespray","BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.","T1110","TA0001 - TA0043","N/A","N/A","Credential Access","https://github.com/x90skysn3k/brutespray","1","1","N/A","N/A","10","10","2231","405","2025-04-21T03:17:20Z","2017-04-05T17:05:10Z","63191"
"*xaitax/Chrome-App-Bound-Encryption-Decryption*",".{0,1000}xaitax\/Chrome\-App\-Bound\-Encryption\-Decryption.{0,1000}","offensive_tool_keyword","Chrome-App-Bound-Encryption-Decryption","Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections","T1003 - T1081 - T1555.003","TA0006","N/A","N/A","Credential Access","https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption","1","1","N/A","N/A","9","5","401","73","2025-04-22T08:30:00Z","2024-10-27T11:28:35Z","63192"
"*xelroth/ShadowStealer*",".{0,1000}xelroth\/ShadowStealer.{0,1000}","offensive_tool_keyword","ShadowStealer","Google Chrome Passwords , Cookies and SystemInfo Dumper","T1555 - T1539 - T1125 - T1083 - T1056","TA0009 - TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/xelroth/ShadowStealer","1","1","N/A","N/A","10","","N/A","","","","63203"
"*xor*8200ab18b1a1965f1759c891e87bc32f208843331d83195c21ee03148b531a0e*",".{0,1000}xor.{0,1000}8200ab18b1a1965f1759c891e87bc32f208843331d83195c21ee03148b531a0e.{0,1000}","offensive_tool_keyword","SecretServerSecretStealer","Powershell script that decrypts the data stored within a Thycotic Secret Server","T1552 - T1027 - T1059","TA0006","N/A","EvilCorp*","Credential Access","https://github.com/denandz/SecretServerSecretStealer","1","0","N/A","N/A","10","1","78","14","2020-08-03T06:52:27Z","2017-04-21T04:06:24Z","63261"
"*Xre0uS/MultiDump*",".{0,1000}Xre0uS\/MultiDump.{0,1000}","offensive_tool_keyword","MultiDump","MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly","T1003 - T1564.002","TA0005 - TA0006","N/A","N/A","Credential Access","https://github.com/Xre0uS/MultiDump","1","1","N/A","N/A","10","6","510","66","2025-03-28T10:40:27Z","2024-02-02T05:56:29Z","63284"
"*xsukax-Wordlist-All.7z*",".{0,1000}xsukax\-Wordlist\-All\.7z.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","63315"
"*yanncam/ShuckNT*",".{0,1000}yanncam\/ShuckNT.{0,1000}","offensive_tool_keyword","ShuckNT","ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)","T1552.001 - T1555.003 - T1078.003","TA0006 - TA0002 - TA0040","N/A","N/A","Credential Access","https://github.com/yanncam/ShuckNT","1","1","N/A","N/A","10","1","69","9","2024-10-18T10:45:49Z","2023-01-27T07:52:47Z","63337"
"*yehia-mamdouh/Lsassx*",".{0,1000}yehia\-mamdouh\/Lsassx.{0,1000}","offensive_tool_keyword","Lsassx","Dumping LSASS Evaded Endpoint Security Solutions","T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001","TA0006 - TA0005 - TA0004","N/A","N/A","Credential Access","https://github.com/yehia-mamdouh/Lsassx","1","1","N/A","N/A","10","1","12","3","2025-02-15T16:41:38Z","2025-02-15T16:36:27Z","63351"
"*YOLOP0wn/POSTDump*",".{0,1000}YOLOP0wn\/POSTDump.{0,1000}","offensive_tool_keyword","POSTDump","perform minidump of LSASS process using few technics to avoid detection.","T1003.001 - T1055 - T1564.001","TA0005 - TA0006","N/A","Black Basta","Credential Access","https://github.com/YOLOP0wn/POSTDump","1","1","N/A","N/A","10","4","327","37","2025-02-05T15:24:52Z","2023-09-13T11:28:51Z","63365"
"*You finally broke through BlankOBF v2; Give yourself a pat on your back!*",".{0,1000}You\sfinally\sbroke\sthrough\sBlankOBF\sv2\;\sGive\syourself\sa\spat\son\syour\sback!.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","63371"
"*you'll need the system key of the DC that you pulled the NTDS.dit file*",".{0,1000}you\'ll\sneed\sthe\ssystem\skey\sof\sthe\sDC\sthat\syou\spulled\sthe\sNTDS\.dit\sfile.{0,1000}","offensive_tool_keyword","DitExplorer","Tool for viewing NTDS.dit","T1003.003","TA0006","N/A","N/A","Credential Access","https://github.com/trustedsec/DitExplorer","1","0","#content","N/A","10","2","155","13","2025-03-14T13:02:44Z","2025-02-12T15:54:04Z","63382"
"*Your Moms Smart Vibrator*",".{0,1000}Your\sMoms\sSmart\sVibrator.{0,1000}","offensive_tool_keyword","TREVORspray","TREVORspray is a modular password sprayer with threading - clever proxying - loot modules and more","T1110.003 - T1059.005 - T1071.001","TA0001 - TA0002","N/A","N/A","Credential Access","https://github.com/blacklanternsecurity/TREVORspray","1","0","#useragent","user-agent","10","10","1156","154","2025-03-11T13:58:24Z","2020-09-06T23:02:37Z","63389"
"*Your version of Luna Token Grabber is outdated!*",".{0,1000}Your\sversion\sof\sLuna\sToken\sGrabber\sis\soutdated!.{0,1000}","offensive_tool_keyword","Luna-Grabber","discord token grabber made in python","T1003 - T1056","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/Smug246/Luna-Grabber","1","0","N/A","N/A","10","","N/A","","","","63395"
"*Yuuup!! Pass Cracked*",".{0,1000}Yuuup!!\sPass\sCracked.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://raw.githubusercontent.com/Sup3r-Us3r/scripts/master/fb-brute.pl","1","0","N/A","N/A","7","10","N/A","N/A","N/A","N/A","63413"
"*Z1P73136r4M(*",".{0,1000}Z1P73136r4M\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","63415"
"*Z1P7H1N65(*",".{0,1000}Z1P7H1N65\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","63416"
"*Z1PF01D3r(*",".{0,1000}Z1PF01D3r\(.{0,1000}","offensive_tool_keyword","cstealer","NiceRAT stealer - clone of cstealer","T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002","TA0006 - TA0009 - TA0010","N/A","N/A","Credential Access","https://github.com/0x00G/NiceRAT","1","0","N/A","N/A","10","2","118","86","2024-10-20T18:38:53Z","2022-11-20T19:11:00Z","63417"
"*zblurx/certsync*",".{0,1000}zblurx\/certsync.{0,1000}","offensive_tool_keyword","certsync","Dump NTDS with golden certificates and UnPAC the hash","T1553.002 - T1003.001 - T1145 - T1649","TA0002 - TA0003 - TA0006","N/A","N/A","Credential Access","https://github.com/zblurx/certsync","1","1","N/A","N/A","10","7","633","66","2024-03-20T10:58:15Z","2023-01-31T15:37:12Z","63434"
"*zblurx/dploot*",".{0,1000}zblurx\/dploot.{0,1000}","offensive_tool_keyword","dploot","DPAPI looting remotely in Python","T1003.006 - T1027 - T1110.004","TA0006 - TA0007 - TA0010","N/A","N/A","Credential Access","https://github.com/zblurx/dploot","1","1","N/A","N/A","10","5","455","58","2025-04-09T08:17:14Z","2022-05-24T11:05:21Z","63435"
"*zed2john.py*",".{0,1000}zed2john\.py.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","1","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","63438"
"*ZephrFish/ADFSDump-PS*",".{0,1000}ZephrFish\/ADFSDump\-PS.{0,1000}","offensive_tool_keyword","ADFSDump-PS","ADFSDump to assist with GoldenSAML","T1078 - T1552.004 - T1558.004","TA0006 ","N/A","N/A","Credential Access","https://github.com/ZephrFish/ADFSDump-PS","1","1","N/A","N/A","10","1","31","8","2024-05-20T00:00:19Z","2024-05-19T00:46:28Z","63444"
"*zip2john *",".{0,1000}zip2john\s.{0,1000}","offensive_tool_keyword","JohnTheRipper","John the Ripper jumbo - advanced offline password cracker","T1110 - T1003.001","TA0006","N/A","Black Basta","Credential Access","https://github.com/openwall/john/","1","0","N/A","N/A","N/A","10","11216","2220","2025-04-22T11:24:06Z","2011-12-16T19:43:47Z","63471"
"*ztgrace*changeme*",".{0,1000}ztgrace.{0,1000}changeme.{0,1000}","offensive_tool_keyword","changeme","A default credential scanner.","T1110 - T1114 - T1112 - T1056","TA0001 - TA0006 - TA0008","N/A","N/A","Credential Access","https://github.com/ztgrace/changeme","1","1","N/A","N/A","N/A","10","1478","251","2021-12-26T10:20:11Z","2016-03-11T17:10:34Z","63513"
"*ZxKmz4hXp6XKmTPg9lzgYxXN4sFr2pzo*",".{0,1000}ZxKmz4hXp6XKmTPg9lzgYxXN4sFr2pzo.{0,1000}","offensive_tool_keyword","SocialBox-Termux","SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android","T1110.001 - T1110.003 - T1078.003","TA0001 - TA0006 - TA0040","N/A","N/A","Credential Access","https://github.com/samsesh/insta-bf","1","0","#base64","N/A","7","1","59","13","2024-04-23T02:47:28Z","2020-11-20T22:22:48Z","63514"
"*zzzteph/weakpass*",".{0,1000}zzzteph\/weakpass.{0,1000}","offensive_tool_keyword","weakpass","Weakpass collection of tools for bruteforce and hashcracking","T1110 - T1201","TA0006 - TA0002","N/A","Black Basta","Credential Access","https://github.com/zzzteph/weakpass","1","1","N/A","N/A","10","6","541","55","2025-04-08T19:50:48Z","2021-08-29T13:07:37Z","63519"
"cme smb *","cme\ssmb\s.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","63547"
"cme winrm *","cme\swinrm\s.{0,1000}","offensive_tool_keyword","crackmapexec","crackmapexec command lines. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks","T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047","TA0002 - TA0006 - TA0007","N/A","APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta","Credential Access","https://github.com/Porchetta-Industries/CrackMapExec","1","0","N/A","N/A","10","10","8690","1667","2023-12-06T17:09:42Z","2015-08-14T14:11:55Z","63549"
"hydra -*","hydra\s\-.{0,1000}","offensive_tool_keyword","thc-hydra","Parallelized login cracker which supports numerous protocols to attack.","T1110.001","TA0006","N/A","ALLANITE - BERSERK BEAR","Credential Access","https://github.com/vanhauser-thc/thc-hydra","1","0","#linux","N/A","N/A","10","10326","2137","2025-04-04T12:19:05Z","2014-04-24T14:45:37Z","63565"
"nanodump*","nanodump.{0,1000}","offensive_tool_keyword","nanodump","The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.","T1003.001 - T1003.003","TA0006","N/A","Dispossessor","Credential Access","https://github.com/fortra/nanodump","1","1","N/A","N/A","10","10","1918","249","2024-09-17T22:58:11Z","2021-11-10T18:28:15Z","63581"
"*aircrack-ng.org*",".{0,1000}aircrack\-ng\.org.{0,1000}","offensive_tool_keyword","aircrack","Wi-Fi password cracking tool used for capturing and cracking WEP and WPA-PSK keys","T1557.002 - T1040","TA0006 - TA0009","N/A","N/A","Credential Access","N/A","1","1","N/A","N/A","8","8","N/A","N/A","N/A","N/A","63716"
"*crackstation.net*",".{0,1000}crackstation\.net.{0,1000}","offensive_tool_keyword","crackstation","online password hash cracking tool that uses a large precomputed lookup table (rainbow table) to recover plaintext passwords from their hash values - commonly used to crack credentials after hash extraction.","T1110.002 - T1111 - T1555","TA0006 - TA0008","N/A","N/A","Credential Access","https://crackstation.net/","1","1","N/A","N/A","10","10","N/A","N/A","N/A","N/A","63726"
"*[Windows.ApplicationModel.DataTransfer.Clipboard]::GetHistoryItemsAsync*",".{0,1000}\[Windows\.ApplicationModel\.DataTransfer\.Clipboard\]\:\:GetHistoryItemsAsync.{0,1000}","greyware_tool_keyword","powershell","interacts with the Windows Clipboard API to retrieve clipboard history","T1115 - T1059.001","TA0009 - TA0002","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","8","9","N/A","N/A","N/A","N/A","63731"
"*ApplicationModel.DataTransfer.Clipboard*GetHistoryItemsAsync*",".{0,1000}ApplicationModel\.DataTransfer\.Clipboard.{0,1000}GetHistoryItemsAsync.{0,1000}","greyware_tool_keyword","powershell","interacts with the Windows Clipboard API to retrieve clipboard history","T1115 - T1059.001","TA0009 - TA0002","N/A","N/A","Credential Access","N/A","1","0","N/A","N/A","8","9","N/A","N/A","N/A","N/A","63732"
"*/SSH-Stealer.git*",".{0,1000}\/SSH\-Stealer\.git.{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","1","N/A","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63736"
"*DarkSpaceSecurity/SSH-Stealer*",".{0,1000}DarkSpaceSecurity\/SSH\-Stealer.{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","1","N/A","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63737"
"*\SSH-Stealer*",".{0,1000}\\SSH\-Stealer.{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","0","N/A","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63738"
"*sshKeylogger.*",".{0,1000}sshKeylogger\..{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","1","N/A","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63739"
"*/sshKeylogger/*",".{0,1000}\/sshKeylogger\/.{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","1","N/A","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63740"
"*aed15bd2e969003861e3389c83b8236b28d95ff77bbd0a190cd1a322cc349417*",".{0,1000}aed15bd2e969003861e3389c83b8236b28d95ff77bbd0a190cd1a322cc349417.{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","0","#filehash","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63741"
"*29766e882e55554b32f415da20cbbc3165ade2472cb0ffe6c281b0f68621bb98*",".{0,1000}29766e882e55554b32f415da20cbbc3165ade2472cb0ffe6c281b0f68621bb98.{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","0","#filehash","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63742"
"*86cfb31b-69ae-483e-8dd9-f8f5a82aef13*",".{0,1000}86cfb31b\-69ae\-483e\-8dd9\-f8f5a82aef13.{0,1000}","offensive_tool_keyword","SSH-Stealer","Smart keylogging capability to steal SSH Credentials including password & Private Key","T1056.001 - T1552.004 - T1556.004 - T1003","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/DarkSpaceSecurity/SSH-Stealer","1","0","#GUIDproject","N/A","2","2","125","22","2025-03-26T04:23:00Z","2025-03-16T01:24:58Z","63743"
"*/Chrome-Password-Recovery.git*",".{0,1000}\/Chrome\-Password\-Recovery\.git.{0,1000}","offensive_tool_keyword","Chrome-Password-Recovery","recover Google Chrome Logins","T1555.003 - T1005 - T1027","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/SaturnsVoid/Chrome-Password-Recovery","1","1","N/A","N/A","8","1","75","31","2021-02-05T00:36:39Z","2017-04-07T17:32:27Z","63758"
"*SaturnsVoid/Chrome-Password-Recovery*",".{0,1000}SaturnsVoid\/Chrome\-Password\-Recovery.{0,1000}","offensive_tool_keyword","Chrome-Password-Recovery","recover Google Chrome Logins","T1555.003 - T1005 - T1027","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/SaturnsVoid/Chrome-Password-Recovery","1","1","N/A","N/A","8","1","75","31","2021-02-05T00:36:39Z","2017-04-07T17:32:27Z","63759"
"*Chrome Password Recovery.go*",".{0,1000}Chrome\sPassword\sRecovery\.go.{0,1000}","offensive_tool_keyword","Chrome-Password-Recovery","recover Google Chrome Logins","T1555.003 - T1005 - T1027","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/SaturnsVoid/Chrome-Password-Recovery","1","1","N/A","N/A","8","1","75","31","2021-02-05T00:36:39Z","2017-04-07T17:32:27Z","63760"
"*7eb6b7bb1ae807bb1610715069bde4c790d698924926eb8e9a59ce41e2dc327f*",".{0,1000}7eb6b7bb1ae807bb1610715069bde4c790d698924926eb8e9a59ce41e2dc327f.{0,1000}","offensive_tool_keyword","Chrome-Password-Recovery","recover Google Chrome Logins","T1555.003 - T1005 - T1027","TA0006 - TA0009","N/A","N/A","Credential Access","https://github.com/SaturnsVoid/Chrome-Password-Recovery","1","0","#filehash","N/A","8","1","75","31","2021-02-05T00:36:39Z","2017-04-07T17:32:27Z","63761"
"*Aur3ns/lsassStealer*",".{0,1000}Aur3ns\/lsassStealer.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/lsassStealer","1","1","N/A","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63762"
"*Aur3ns/Morpheus*",".{0,1000}Aur3ns\/Morpheus.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","1","N/A","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63763"
"*[+] Decoded target process: lsass.exe*",".{0,1000}\[\+\]\sDecoded\starget\sprocess\:\slsass\.exe.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","#content","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63764"
"*Set-ExecutionPolicy Bypass -Scope Process -Force; ./run.ps1*",".{0,1000}Set\-ExecutionPolicy\sBypass\s\-Scope\sProcess\s\-Force\;\s\.\/run\.ps1.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","N/A","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63765"
"*\memdump.exe*",".{0,1000}\\memdump\.exe.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","N/A","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63766"
"*126e1149940a288389cee23653f889ad5edadc77c5944d6700229dfd573e5327*",".{0,1000}126e1149940a288389cee23653f889ad5edadc77c5944d6700229dfd573e5327.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","#filehash","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63767"
"*ad8d2c8c861bc21e5768c4509027b36ae269f30b38efaeb9a1f990c0257479b2*",".{0,1000}ad8d2c8c861bc21e5768c4509027b36ae269f30b38efaeb9a1f990c0257479b2.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","#filehash","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63768"
"*ec45956c13d4f7e2eb4af57ad7ccdb8ff8ac14d0e524e2f676fdec002cc8bf79*",".{0,1000}ec45956c13d4f7e2eb4af57ad7ccdb8ff8ac14d0e524e2f676fdec002cc8bf79.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","#filehash","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63769"
"*a05b50e5814778371a6e565e659997211603dcb723bffd14eae9027ca7f557c3*",".{0,1000}a05b50e5814778371a6e565e659997211603dcb723bffd14eae9027ca7f557c3.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","#filehash","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63770"
"*\temp\*\dumpfile_*.dmp*",".{0,1000}\\temp\\.{0,1000}\\dumpfile_.{0,1000}\.dmp.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","N/A","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63771"
"*--best memdump.exe*",".{0,1000}\-\-best\smemdump\.exe.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","N/A","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63772"
"*function Obfuscate-Executable*",".{0,1000}function\sObfuscate\-Executable.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","#content","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63773"
"*\dump_memory.bin*",".{0,1000}\\dump_memory\.bin.{0,1000}","offensive_tool_keyword","Morpheus","Morpheus is a memory dumper that extracts lsass.exe in RAM and exfiltrates it via forged NTP packets","T1003.001 - T1043 - T1041 - T1027","TA0006 - TA0010","N/A","N/A","Credential Access","https://github.com/Aur3ns/Morpheus","1","0","N/A","N/A","8","1","89","15","2025-04-05T17:35:13Z","2024-12-15T16:02:49Z","63774"