Files
mthcht-ThreatHunting-Keywords/Credential_Access_category_detection.csv
mthcht 755048bf5e Mars and April 2025 update
very few additions and some corrections
2025-04-24 05:55:50 +02:00

3.2 MiB

1keywordmetadata_keyword_regexmetadata_keyword_typemetadata_toolmetadata_descriptionmetadata_tool_techniquesmetadata_tool_tacticsmetadata_malwares_namemetadata_groups_namemetadata_categorymetadata_linkmetadata_enable_endpoint_detectionmetadata_enable_proxy_detectionmetadata_tagsmetadata_commentmetadata_severity_scoremetadata_popularity_scoremetadata_github_starsmetadata_github_forksmetadata_github_updated_atmetadata_github_created_atmetadata_entry_id
2* - Dump LSASS memory bypassing countermeasures*.{0,1000}\s\-\sDump\sLSASS\smemory\sbypassing\scountermeasures.{0,1000}offensive_tool_keywordblindsightRed teaming tool to dump LSASS memory, bypassing basic countermeasuresT1003.001TA0006N/AN/ACredential Accesshttps://github.com/0xdea/blindsight10#contentN/A103225262024-12-31T15:28:15Z2024-07-18T07:35:43Z6
3* - Remote lsass dump reader*.{0,1000}\s\-\sRemote\slsass\sdump\sreader.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10#contentN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z10
4* /altservice:ldap *.{0,1000}\s\/altservice\:ldap\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z36
5* /asrepkey*.{0,1000}\s\/asrepkey.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z37
6* /changentlm* /user:* /oldhash:*.{0,1000}\s\/changentlm.{0,1000}\s\/user\:.{0,1000}\s\/oldhash\:.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z46
7* /changentlm* /user:* /oldpwd:*.{0,1000}\s\/changentlm.{0,1000}\s\/user\:.{0,1000}\s\/oldpwd\:.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z47
8* /changentlm* /user:* /oldpwd:*.{0,1000}\s\/changentlm.{0,1000}\s\/user\:.{0,1000}\s\/oldpwd\:.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z48
9* /createnetonly:*cmd.exe*.{0,1000}\s\/createnetonly\:.{0,1000}cmd\.exe.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z57
10* /createnetonly:*cmd.exe*.{0,1000}\s\/createnetonly\:.{0,1000}cmd\.exe.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z58
11* /credpassword*.{0,1000}\s\/credpassword.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z59
12* /creduser:* /credpassword:*.{0,1000}\s\/creduser\:.{0,1000}\s\/credpassword\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z60
13* /decodemk /binary:* /password:*.{0,1000}\s\/decodemk\s\/binary\:.{0,1000}\s\/password\:.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z61
14* /domain:* /dc:* /getcredentials /nowrap*.{0,1000}\s\/domain\:.{0,1000}\s\/dc\:.{0,1000}\s\/getcredentials\s\/nowrap.{0,1000}offensive_tool_keywordKeyCredentialLinkAdd Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attributeT1098 - T1550TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/Leo4j/KeyCredentialLink10N/AN/A1012132024-06-05T13:44:39Z2024-06-05T13:19:49Z62
15* /dumpsecret /input:* /system*.{0,1000}\s\/dumpsecret\s\/input\:.{0,1000}\s\/system.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z63
16* /dumpsecret /input:defaultpassword*.{0,1000}\s\/dumpsecret\s\/input\:defaultpassword.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z64
17* /dumpsecret /input:dpapi_system /offline*.{0,1000}\s\/dumpsecret\s\/input\:dpapi_system\s\/offline.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z65
18* /gethmac /mode:hashid /input:* /key:*.{0,1000}\s\/gethmac\s\/mode\:hashid\s\/input\:.{0,1000}\s\/key\:.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z69
19* /GetKeys WirelessKeyView*.{0,1000}\s\/GetKeys\sWirelessKeyView.{0,1000}offensive_tool_keywordWirelessKeyViewWirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer T1003 - T1083 - T1552TA0006 N/AGoGoogleCredential Accesshttps://www.nirsoft.net/utils/wireless_key.html10N/AN/A710N/AN/AN/AN/A70
20* /getlsasecret /input:*.{0,1000}\s\/getlsasecret\s\/input\:.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z71
21* /getntlmhash /password:*.{0,1000}\s\/getntlmhash\s\/password\:.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z72
22* /getntlmhash | wtee *.ntlm*.{0,1000}\s\/getntlmhash\s\|\swtee\s.{0,1000}\.ntlm.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z73
23* /getsamkey /offline*.{0,1000}\s\/getsamkey\s\/offline.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z74
24* /impersonateuser:* /msdsspn:* /ptt*.{0,1000}\s\/impersonateuser\:.{0,1000}\s\/msdsspn\:.{0,1000}\s\/ptt.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z75
25* /ldap * /printcmd*.{0,1000}\s\/ldap\s.{0,1000}\s\/printcmd.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z76
26* /ldapfilter:'admincount=1'*.{0,1000}\s\/ldapfilter\:\'admincount\=1\'.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z77
27* /nofullpacsig *.{0,1000}\s\/nofullpacsig\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z83
28* /outfile:* /spn:*.{0,1000}\s\/outfile\:.{0,1000}\s\/spn\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z84
29* /outfile:* /spns:*.{0,1000}\s\/outfile\:.{0,1000}\s\/spns\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z85
30* /ptt /binary:*.kirbi*.{0,1000}\s\/ptt\s\/binary\:.{0,1000}\.kirbi.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z89
31* /pwdsetafter:*.{0,1000}\s\/pwdsetafter\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z90
32* /pwdsetbefore:*.{0,1000}\s\/pwdsetbefore\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z91
33* /rc4opsec *.{0,1000}\s\/rc4opsec\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z94
34* /s4uproxytarget*.{0,1000}\s\/s4uproxytarget.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z96
35* /s4utransitedservices*.{0,1000}\s\/s4utransitedservices.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z98
36* /service:krbtgt *.{0,1000}\s\/service\:krbtgt\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z99
37* /setntlm * /user:* /newhash:*.{0,1000}\s\/setntlm\s.{0,1000}\s\/user\:.{0,1000}\s\/newhash\:.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z100
38* /setntlm * /user:* /newpwd:*.{0,1000}\s\/setntlm\s.{0,1000}\s\/user\:.{0,1000}\s\/newpwd\:.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z101
39* /simple * /spn*.{0,1000}\s\/simple\s.{0,1000}\s\/spn.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z102
40* /ticket *.kirbi*.{0,1000}\s\/ticket\s.{0,1000}\.kirbi.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z104
41* /ticket:* /autoenterprise *.{0,1000}\s\/ticket\:.{0,1000}\s\/autoenterprise\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z105
42* /ticket:*.kirbi*.{0,1000}\s\/ticket\:.{0,1000}\.kirbi.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z107
43* /usetgtdeleg *.{0,1000}\s\/usetgtdeleg\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z113
44* | NTLMParse*.{0,1000}\s\|\sNTLMParse.{0,1000}offensive_tool_keywordADFSRelayNTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFST1140 - T1212 - T1557TA0007 - TA0008 - TA0006N/ABlack BastaCredential Accesshttps://github.com/praetorian-inc/ADFSRelay10N/AN/A102179152022-06-22T03:01:00Z2022-05-12T01:20:14Z136
45* > Wi-Fi-PASS*.{0,1000}\s\>\sWi\-Fi\-PASS.{0,1000}offensive_tool_keywordwifigrabbergrab wifi password and exfiltrate to a given siteT1056.005 - T1552.001 - T1119 - T1071.001TA0004 - TA0006 - TA0010 - TA0040N/AN/ACredential Accesshttps://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber10N/AN/A10109043102024-09-14T02:34:26Z2021-09-08T20:33:18Z149
46* 1$a$$.exe*.{0,1000}\s1\$a\$\$\.exe.{0,1000}offensive_tool_keywordDumpThatLSASSDumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the diskT1003 - T1055.011 - T1027 - T1564.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/peiga/DumpThatLSASS10N/AN/A10131792022-09-24T22:39:04Z2022-09-24T22:41:19Z153
47* 29ABE9Hy.log*.{0,1000}\s29ABE9Hy\.log.{0,1000}offensive_tool_keywordblindsightRed teaming tool to dump LSASS memory, bypassing basic countermeasuresT1003.001TA0006N/AN/ACredential Accesshttps://github.com/0xdea/blindsight10N/AN/A103225262024-12-31T15:28:15Z2024-07-18T07:35:43Z159
48* --action SPRAY_USERS *.{0,1000}\s\-\-action\sSPRAY_USERS\s.{0,1000}offensive_tool_keywordSharpHoseAsynchronous Password Spraying Tool in C# for Windows EnvironmentsT1110.003TA0006N/AN/ACredential Accesshttps://github.com/ustayready/SharpHose10N/AN/A104312622023-12-19T21:06:47Z2020-05-01T22:10:49Z186
49* adcsync.py*.{0,1000}\sadcsync\.py.{0,1000}offensive_tool_keywordadcsyncUse ESC1 to perform a makeshift DCSync and dump hashesT1003.006 - T1021TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/JPG0mez/ADCSync10N/AN/A93205222023-11-02T21:41:08Z2023-10-04T01:56:50Z207
50* add /target:* /altsecid:X509:*.{0,1000}\sadd\s\/target\:.{0,1000}\s\/altsecid\:X509\:.{0,1000}offensive_tool_keywordSharpAltSecIdsShadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificateT1098.003 - T1556.002 - T1078TA0003 - TA0004 - TA0006N/AN/ACredential Accesshttps://github.com/bugch3ck/SharpAltSecIds10N/AN/A911232022-05-30T13:50:05Z2022-05-30T13:40:17Z209
51* adfsbrute.py*.{0,1000}\sadfsbrute\.py.{0,1000}offensive_tool_keywordadfsbrutetest credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacksT1110.003 - T1110.001 - T1110TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/ricardojoserf/adfsbrute10N/AN/A82172332021-04-23T16:43:59Z2020-10-02T16:28:35Z225
52* --adfs-host * --krb-key * --krb-ticket *.{0,1000}\s\-\-adfs\-host\s.{0,1000}\s\-\-krb\-key\s.{0,1000}\s\-\-krb\-ticket\s.{0,1000}offensive_tool_keywordwhiskeysamlandfriendsGoldenSAML Attack Libraries and FrameworkT1606.002TA0006N/AN/ACredential Accesshttps://github.com/secureworks/whiskeysamlandfriends10N/AN/AN/A17292024-06-05T14:56:28Z2021-11-04T15:30:12Z226
53* adfs-spray.py*.{0,1000}\sadfs\-spray\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z228
54* ADPassHunt.GetGPPPassword*.{0,1000}\sADPassHunt\.GetGPPPassword.{0,1000}offensive_tool_keywordADPassHuntcredential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team)T1003.003 - T1552.006TA0006 - TA0007N/AN/ACredential Accesshttps://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f10N/AN/A1010N/AN/AN/AN/A234
55* Any passwords that were successfully sprayed have been output to*.{0,1000}\sAny\spasswords\sthat\swere\ssuccessfully\ssprayed\shave\sbeen\soutput\sto.{0,1000}offensive_tool_keywordInvoke-Pre2kSprayEnumerate domain machine accounts and perform pre2k password spraying.T1087.002 - T1110.003TA0007 - TA0006N/AN/ACredential Accesshttps://github.com/eversinc33/Invoke-Pre2kSpray10#contentN/A8169112023-07-14T06:50:22Z2023-07-05T10:07:38Z268
56* App-Bound Encryption Decryption process*.{0,1000}\sApp\-Bound\sEncryption\sDecryption\sprocess.{0,1000}offensive_tool_keywordChrome-App-Bound-Encryption-DecryptionTool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protectionsT1003 - T1081 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption10#contentN/A95401732025-04-22T08:30:00Z2024-10-27T11:28:35Z271
57* Ask4Creds.ps1*.{0,1000}\sAsk4Creds\.ps1.{0,1000}offensive_tool_keywordAsk4CredsPrompt User for credentialsT1056 - T1071TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Leo4j/Ask4Creds10N/AN/A81102024-03-20T17:09:21Z2023-11-12T15:21:40Z280
58* asktgs * /ticket:*.{0,1000}\sasktgs\s.{0,1000}\s\/ticket\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z281
59* asktgs *.kirbi*.{0,1000}\sasktgs\s.{0,1000}\.kirbi.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z282
60* asktgs /ticket:*.{0,1000}\sasktgs\s\/ticket\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z283
61* asktgt * /service:*.{0,1000}\sasktgt\s.{0,1000}\s\/service\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z284
62* asktgt /user *.{0,1000}\sasktgt\s\/user\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z285
63* asktht /user:*.{0,1000}\sasktht\s\/user\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z288
64* asreproast *.{0,1000}\sasreproast\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z292
65* atomizer.py *.{0,1000}\satomizer\.py\s.{0,1000}offensive_tool_keywordSprayingToolkitScripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficientT1110 - T1078 - T1133 - T1061 - T1621TA0001 - TA0002 - TA0003N/AN/ACredential Accesshttps://github.com/byt3bl33d3r/SprayingToolkit10N/AN/A91014912692022-10-17T01:01:57Z2018-09-13T09:52:11Z306
66* autoNTDS.py*.{0,1000}\sautoNTDS\.py.{0,1000}offensive_tool_keywordautoNTDSautoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcatT1003 - T1059 - T1021.002 - T1213TA0006 - TA0008 - TA0005 - TA0002N/AN/ACredential Accesshttps://github.com/hmaverickadams/autoNTDS10N/AN/A102109142023-10-31T22:03:58Z2023-10-30T23:10:58Z342
67* BabelStrike.py*.{0,1000}\sBabelStrike\.py.{0,1000}offensive_tool_keywordBabelStrikeThe purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)T1078 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/t3l3machus/BabelStrike10N/AN/A12132232024-07-19T07:02:42Z2023-01-10T07:59:00Z351
68* backupcreds.exe*.{0,1000}\sbackupcreds\.exe.{0,1000}offensive_tool_keywordBackupCredsA C# implementation of dumping credentials from Windows Credential ManagerT1003 - T1555TA0006 - TA0005N/ABlack BastaCredential Accesshttps://github.com/leftp/BackupCreds10N/AN/A9157102023-09-23T10:37:05Z2023-09-23T06:42:20Z364
69* backupkey* /server:* /file*.pvk*.{0,1000}\sbackupkey.{0,1000}\s\/server\:.{0,1000}\s\/file.{0,1000}\.pvk.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z365
70* --bf-hashes-file *.{0,1000}\s\-\-bf\-hashes\-file\s.{0,1000}offensive_tool_keywordsmartbrutePassword spraying and bruteforcing tool for Active Directory Domain ServicesT1110.001 - T1110.003TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/ShutdownRepo/smartbrute10N/AN/A104365542024-10-27T20:47:29Z2021-07-16T14:53:29Z386
71* --bf-passwords-file *.{0,1000}\s\-\-bf\-passwords\-file\s.{0,1000}offensive_tool_keywordsmartbrutePassword spraying and bruteforcing tool for Active Directory Domain ServicesT1110.001 - T1110.003TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/ShutdownRepo/smartbrute10N/AN/A104365542024-10-27T20:47:29Z2021-07-16T14:53:29Z387
72* BlankOBF.py*.{0,1000}\sBlankOBF\.py.{0,1000}offensive_tool_keywordBlank-GrabberStealer with multiple functionsT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Blank-c/Blank-Grabber10N/AN/A1098312202023-08-06T06:26:16Z2022-01-26T12:04:56Z403
73* bleeding-jumbo john*.{0,1000}\sbleeding\-jumbo\sjohn.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z405
74* blob /target:*.bin* /pvk:*.{0,1000}\sblob\s\/target\:.{0,1000}\.bin.{0,1000}\s\/pvk\:.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z407
75* blob /target:*.bin* /unprotect*.{0,1000}\sblob\s\/target\:.{0,1000}\.bin.{0,1000}\s\/unprotect.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z408
76* --bloodhound --import-data *.{0,1000}\s\-\-bloodhound\s\-\-import\-data\s.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z411
77* --bloodhound --mark-owned *.{0,1000}\s\-\-bloodhound\s\-\-mark\-owned\s.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z412
78* --bloodhound --sync *.{0,1000}\s\-\-bloodhound\s\-\-sync\s.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z414
79* bloodhoundsync.py*.{0,1000}\sbloodhoundsync\.py.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z416
80* brute * /password*.{0,1000}\sbrute\s.{0,1000}\s\/password.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z464
81* --bruteforce *.kdbx*.{0,1000}\s\-\-bruteforce\s.{0,1000}\.kdbx.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn10N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z465
82* bruteuser *.{0,1000}\sbruteuser\s.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute10N/AN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z472
83* bruteuser -d *.{0,1000}\sbruteuser\s\-d\s.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute10N/AN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z473
84* by @citronneur (v*.{0,1000}\sby\s\@citronneur\s\(v.{0,1000}offensive_tool_keywordpamspyCredentials Dumper for Linux using eBPFT1003.001TA0006N/AN/ACredential Accesshttps://github.com/citronneur/pamspy10#linuxN/A10101135632024-09-09T13:19:12Z2022-07-01T19:33:43Z479
85* by erwan2212@gmail.com*.{0,1000}\sby\serwan2212\@gmail\.com.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z482
86* BypassCredGuard.exe*.{0,1000}\sBypassCredGuard\.exe.{0,1000}offensive_tool_keywordBypassCredGuardCredential Guard Bypass Via Patching Wdigest MemoryT1003 - T1112 - T1555.002 - T1574TA0006 - TA0005 - TA0040N/AN/ACredential Accesshttps://github.com/wh0amitz/BypassCredGuard10N/AN/A104323522023-02-03T06:55:43Z2023-01-18T15:16:11Z485
87* -c "!mimikatz" *.{0,1000}\s\-c\s\"!mimikatz\"\s.{0,1000}offensive_tool_keywordForensikeRemotely dump NT hashes through Windows Crash dumpsT1003TA0006N/AN/ACredential Accesshttps://github.com/bmarchev/Forensike10N/AN/A1012732024-10-29T00:13:50Z2024-02-01T13:52:55Z490
88* cachedump.py*.{0,1000}\scachedump\.py.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump710N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z533
89* --ccache-ticket *.{0,1000}\s\-\-ccache\-ticket\s.{0,1000}offensive_tool_keywordsmartbrutePassword spraying and bruteforcing tool for Active Directory Domain ServicesT1110.001 - T1110.003TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/ShutdownRepo/smartbrute10N/AN/A104365542024-10-27T20:47:29Z2021-07-16T14:53:29Z551
90* changepw * /ticket:*.{0,1000}\schangepw\s.{0,1000}\s\/ticket\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z557
91* chrome_decrypt.cpp *.{0,1000}\schrome_decrypt\.cpp\s.{0,1000}offensive_tool_keywordChrome-App-Bound-Encryption-DecryptionTool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protectionsT1003 - T1081 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption10N/AN/A95401732025-04-22T08:30:00Z2024-10-27T11:28:35Z573
92* chrome_decrypt.cpp*.{0,1000}\schrome_decrypt\.cpp.{0,1000}offensive_tool_keywordChrome-App-Bound-Encryption-DecryptionTool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protectionsT1003 - T1081 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption10N/AN/A95401732025-04-22T08:30:00Z2024-10-27T11:28:35Z574
93* chrome_decrypt.exe*.{0,1000}\schrome_decrypt\.exe.{0,1000}offensive_tool_keywordChrome-App-Bound-Encryption-DecryptionTool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protectionsT1003 - T1081 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption10N/AN/A95401732025-04-22T08:30:00Z2024-10-27T11:28:35Z575
94* chromium_based_browsers.py*.{0,1000}\schromium_based_browsers\.py.{0,1000}offensive_tool_keywordBrowser-password-stealerThis python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!T1003.002 - T1056.001TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/henry-richard7/Browser-password-stealer10N/AN/A105423622024-07-12T10:30:42Z2020-09-15T09:23:56Z579
95* cmedb.{0,1000}\scmedboffensive_tool_keywordcrackmapexecwindows default compiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z617
96* comsvcs_stealth.py*.{0,1000}\scomsvcs_stealth\.py.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z667
97* --config *.json --debug --exfil --onedrive*.{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-debug\s\-\-exfil\s\-\-onedrive.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z670
98* --config *.json --enum --validate-msol --usernames *.{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-enum\s\-\-validate\-msol\s\-\-usernames\s.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z671
99* --config *.json --enum --validate-teams*.{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-enum\s\-\-validate\-teams.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z672
100* --config *.json --exfil --aad*.{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-exfil\s\-\-aad.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z673
101* --crack * --ntds*.{0,1000}\s\-\-crack\s.{0,1000}\s\-\-ntds.{0,1000}offensive_tool_keywordautoNTDSautoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcatT1003 - T1059 - T1021.002 - T1213TA0006 - TA0008 - TA0005 - TA0002N/AN/ACredential Accesshttps://github.com/hmaverickadams/autoNTDS10N/AN/A102109142023-10-31T22:03:58Z2023-10-30T23:10:58Z706
102* --crack-status*.{0,1000}\s\-\-crack\-status.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z711
103* credentials /pvk:*.{0,1000}\scredentials\s\/pvk\:.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z733
104* credmaster.py*.{0,1000}\scredmaster\.py.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z734
105* credmaster-success.txt*.{0,1000}\scredmaster\-success\.txt.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z735
106* credmaster-validusers.txt*.{0,1000}\scredmaster\-validusers\.txt.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z736
107* cstealer.py*.{0,1000}\scstealer\.py.{0,1000}offensive_tool_keywordcstealerstealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/can-kat/cstealer10N/AN/A1010N/AN/AN/AN/A747
108* --custom_user_agent*.{0,1000}\s\-\-custom_user_agent.{0,1000}offensive_tool_keywordSpray365Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).T1110.003TA0006N/AN/ACredential Accesshttps://github.com/MarkoH17/Spray36510N/AN/AN/A4348582022-07-14T14:45:57Z2021-11-04T18:20:39Z753
109* darkcodersc *.{0,1000}\sdarkcodersc\s.{0,1000}offensive_tool_keywordwin-brute-logonBruteforce cracking tool for windows usersT1110 - T1110.001 - T1110.002TA0008 - TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/DarkCoderSc/win-brute-logon10N/AN/AN/A1011381912023-11-09T10:37:58Z2020-05-14T21:46:50Z778
110* --dc-ip * -request * -format hashcat*.{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-request\s.{0,1000}\s\-format\shashcat.{0,1000}offensive_tool_keywordhashcatWorlds fastest and most advanced password recovery utility.T1110.001 - T1003.001 - T1021.001TA0006 - TA0009 - TA0010N/ABlack BastaCredential Accesshttps://github.com/hashcat/hashcat10#linuxN/A10102248130462024-08-16T23:50:35Z2015-12-04T14:46:51Z791
111* --debug --exfil --onedrive*.{0,1000}\s\-\-debug\s\-\-exfil\s\-\-onedrive.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z805
112* Decrypt-RDCMan.ps1*.{0,1000}\sDecrypt\-RDCMan\.ps1.{0,1000}offensive_tool_keywordDecrypt-RDCMandecrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPIT1003 - T1552 - T1081 - T1027TA0006 - TA0008 - TA0005N/AN/ACredential Accesshttps://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps110N/AN/A91112016-12-01T14:06:24Z2017-11-22T23:18:39Z807
113* default_logins.txt*.{0,1000}\sdefault_logins\.txt.{0,1000}offensive_tool_keywordthc-hydraParallelized login cracker which supports numerous protocols to attack.T1110.001TA0006N/AALLANITE - BERSERK BEARCredential Accesshttps://github.com/vanhauser-thc/thc-hydra10#linuxN/AN/A101032621372025-04-04T12:19:05Z2014-04-24T14:45:37Z809
114* DEL {}SQLDmpr*.mdmp & for /f *.{0,1000}\sDEL\s\{\}SQLDmpr.{0,1000}\.mdmp\s\&\sfor\s\/f\s.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z813
115* dementor.py*.{0,1000}\sdementor\.py.{0,1000}offensive_tool_keywordNetNTLMtoSilverTicketObtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.T1110.001 - T1558.003 - T1558.004TA0006 - TA0008 - TA0002N/AN/ACredential Accesshttps://github.com/NotMedic/NetNTLMtoSilverTicket10N/AN/A1098421132021-07-26T15:16:20Z2019-01-14T15:32:27Z820
116* diamond * /certificate:*.{0,1000}\sdiamond\s.{0,1000}\s\s\/certificate\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z834
117* diamond /tgtdeleg *.{0,1000}\sdiamond\s\/tgtdeleg\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z835
118* diamond /user:*.{0,1000}\sdiamond\s\/user\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z836
119* Disable_defender.py*.{0,1000}\sDisable_defender\.py.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber10N/AN/A1010N/AN/AN/AN/A853
120* dllinject.py*.{0,1000}\sdllinject\.py.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z870
121* domcachedump.py*.{0,1000}\sdomcachedump\.py.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump710N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z915
122* -Downgrade False -Restore False -Impersonate True * -challange *.{0,1000}\s\-Downgrade\sFalse\s\-Restore\sFalse\s\-Impersonate\sTrue\s.{0,1000}\s\-challange\s.{0,1000}offensive_tool_keywordInternal-MonologueInternal Monologue Attack: Retrieving NTLM Hashes without Touching LSASST1003 - T1051 - T1574 - T1110 - T1547TA0003 - TA0006N/AN/ACredential Accesshttps://github.com/eladshamir/Internal-Monologue10N/AN/AN/A1015122402018-10-11T12:13:08Z2017-12-09T05:59:01Z940
123* dpapi blob *.json *.dat*.{0,1000}\sdpapi\sblob\s.{0,1000}\.json\s.{0,1000}\.dat.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z948
124* dpapi credential *.json cred*.{0,1000}\sdpapi\scredential\s.{0,1000}\.json\scred.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z949
125* dpapi masterkey /root/*.{0,1000}\sdpapi\smasterkey\s\/root\/.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z950
126* dpapi minidump *.dmp*.{0,1000}\sdpapi\sminidump\s.{0,1000}\.dmp.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z951
127* dpapi prekey nt *S-1-5-21*.{0,1000}\sdpapi\sprekey\snt\s.{0,1000}S\-1\-5\-21.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z952
128* dpapi prekey password *.{0,1000}\sdpapi\sprekey\spassword\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z953
129* dpapi prekey registry *.reg*.{0,1000}\sdpapi\sprekey\sregistry\s.{0,1000}\.reg.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z954
130* dpapi securestring *.dat*.{0,1000}\sdpapi\ssecurestring\s.{0,1000}\.dat.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z955
131* dragoncastle.py*.{0,1000}\sdragoncastle\.py.{0,1000}offensive_tool_keywordDragonCastleA PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.T1003 - T1547.005 - T1055 - T1557TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/mdsecactivebreach/DragonCastle10N/AN/A103298382022-10-26T10:19:55Z2022-10-26T10:18:37Z961
132* dump * /service:*.{0,1000}\sdump\s.{0,1000}\s\/service\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z969
133* dump --usermode --kernelmode --driver *.{0,1000}\sdump\s\-\-usermode\s\-\-kernelmode\s\-\-driver\s.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z971
134* --dump_file Keepass.exe.dmp*.{0,1000}\s\-\-dump_file\sKeepass\.exe\.dmp.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn10N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z973
135* --dump_lsa*.{0,1000}\s\-\-dump_lsa.{0,1000}offensive_tool_keywordgsecdumpcredential dumper used to obtain password hashes and LSA secrets from Windows operating systemsT1003.001 - T1003.002 - T1555.003 - T1555.001TA0006 - TA0008N/AAPT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - TickCredential Accesshttps://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe10N/AN/A1010N/AN/AN/AN/A974
136* --dump_usedhashes*.{0,1000}\s\-\-dump_usedhashes.{0,1000}offensive_tool_keywordgsecdumpcredential dumper used to obtain password hashes and LSA secrets from Windows operating systemsT1003.001 - T1003.002 - T1555.003 - T1555.001TA0006 - TA0008N/AAPT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - TickCredential Accesshttps://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe10N/AN/A1010N/AN/AN/AN/A976
137* --dump_wireless*.{0,1000}\s\-\-dump_wireless.{0,1000}offensive_tool_keywordgsecdumpcredential dumper used to obtain password hashes and LSA secrets from Windows operating systemsT1003.001 - T1003.002 - T1555.003 - T1555.001TA0006 - TA0008N/AAPT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - TickCredential Accesshttps://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe10N/AN/A1010N/AN/AN/AN/A977
138* --dump-bitlocker *.{0,1000}\s\-\-dump\-bitlocker\s.{0,1000}offensive_tool_keywordquarkspwdumpQuarks PwDump is a native Win32 tool to extract credentials from Windows operating systemsT1003 - T1003.001 - T1059TA0006N/ALOTUS PANDA - PowerPool - CalypsoCredential Accesshttps://github.com/peterdocter/quarkspwdump10N/AN/A911282015-06-25T04:22:21Z2015-07-14T08:18:08Z979
139* --dump-bitlocker*.{0,1000}\s\-\-dump\-bitlocker.{0,1000}offensive_tool_keywordquarkspwdumpDump various types of Windows credentials without injecting in any processT1003 - T1555TA0006N/AN/ACredential Accesshttps://github.com/quarkslab/quarkspwdump10N/AN/A1054271422023-01-13T03:45:25Z2013-02-13T15:16:30Z980
140* -DumpCred -ComputerName @*.{0,1000}\s\-DumpCred\s\-ComputerName\s\@.{0,1000}offensive_tool_keywordmimidogzRewrite of Invoke-Mimikatz.ps1 to avoid AV detectionT1055 - T1560.001 - T1110.001 - T1003 - T1071TA0005 - TA0040 - TA0006N/ADispossessorCredential Accesshttps://github.com/projectb-temp/mimidogz10N/AN/A101002019-02-11T10:14:10Z2019-02-11T10:12:08Z982
141* -DumpCreds -ComputerName @*.{0,1000}\s\-DumpCreds\s\-ComputerName\s\@.{0,1000}offensive_tool_keywordmimidogzRewrite of Invoke-Mimikatz.ps1 to avoid AV detectionT1055 - T1560.001 - T1110.001 - T1003 - T1071TA0005 - TA0040 - TA0006N/ADispossessorCredential Accesshttps://github.com/projectb-temp/mimidogz10N/AN/A101002019-02-11T10:14:10Z2019-02-11T10:12:08Z985
142* dumpert.py*.{0,1000}\sdumpert\.py.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z989
143* --dump-hash-domain --with-history*.{0,1000}\s\-\-dump\-hash\-domain\s\-\-with\-history.{0,1000}offensive_tool_keywordquarkspwdumpDump various types of Windows credentials without injecting in any processT1003 - T1555TA0006N/AN/ACredential Accesshttps://github.com/quarkslab/quarkspwdump10N/AN/A1054271422023-01-13T03:45:25Z2013-02-13T15:16:30Z992
144* --dump-hash-domain*.{0,1000}\s\-\-dump\-hash\-domain.{0,1000}offensive_tool_keywordquarkspwdumpQuarks PwDump is a native Win32 tool to extract credentials from Windows operating systemsT1003 - T1003.001 - T1059TA0006N/ALOTUS PANDA - PowerPool - CalypsoCredential Accesshttps://github.com/peterdocter/quarkspwdump10N/AN/A911282015-06-25T04:22:21Z2015-07-14T08:18:08Z993
145* --dump-hash-domain-cached*.{0,1000}\s\-\-dump\-hash\-domain\-cached.{0,1000}offensive_tool_keywordquarkspwdumpQuarks PwDump is a native Win32 tool to extract credentials from Windows operating systemsT1003 - T1003.001 - T1059TA0006N/ALOTUS PANDA - PowerPool - CalypsoCredential Accesshttps://github.com/peterdocter/quarkspwdump10N/AN/A911282015-06-25T04:22:21Z2015-07-14T08:18:08Z994
146* --dump-hash-domain-cached*.{0,1000}\s\-\-dump\-hash\-domain\-cached.{0,1000}offensive_tool_keywordquarkspwdumpDump various types of Windows credentials without injecting in any processT1003 - T1555TA0006N/AN/ACredential Accesshttps://github.com/quarkslab/quarkspwdump10N/AN/A1054271422023-01-13T03:45:25Z2013-02-13T15:16:30Z995
147* --dump-hash-local*.{0,1000}\s\-\-dump\-hash\-local.{0,1000}offensive_tool_keywordquarkspwdumpQuarks PwDump is a native Win32 tool to extract credentials from Windows operating systemsT1003 - T1003.001 - T1059TA0006N/ALOTUS PANDA - PowerPool - CalypsoCredential Accesshttps://github.com/peterdocter/quarkspwdump10N/AN/A911282015-06-25T04:22:21Z2015-07-14T08:18:08Z996
148* dump-lsass.py*.{0,1000}\sdump\-lsass\.py.{0,1000}offensive_tool_keywordimpacketDump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems.T1021 - T1047 - T1055.011 - T1003TA0002 - TA0005 - TA0006N/AAkira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black BastaCredential Accesshttps://github.com/kaluche/Dump-Lsass10N/AN/A101102019-11-14T18:15:26Z2019-11-20T20:26:27Z999
149* --dumpmode network --network raw --ip * --port *.{0,1000}\s\-\-dumpmode\snetwork\s\-\-network\sraw\s\-\-ip\s.{0,1000}\s\-\-port\s.{0,1000}offensive_tool_keywordPPLBladeProtected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.T1003.001 - T1027.004 - T1560.001 - T1039 - T1570TA0006 - TA0005 - TA0010 - TA0003N/AN/ACredential Accesshttps://github.com/tastypepperoni/PPLBlade10N/AN/A106545592023-08-30T07:59:51Z2023-08-29T19:36:04Z1000
150* --dumpmode network --network smb *.{0,1000}\s\-\-dumpmode\snetwork\s\-\-network\ssmb\s.{0,1000}offensive_tool_keywordPPLBladeProtected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.T1003.001 - T1027.004 - T1560.001 - T1039 - T1570TA0006 - TA0005 - TA0010 - TA0003N/AN/ACredential Accesshttps://github.com/tastypepperoni/PPLBlade10N/AN/A106545592023-08-30T07:59:51Z2023-08-29T19:36:04Z1001
151* --dump-name *lsass*.{0,1000}\s\-\-dump\-name\s.{0,1000}lsass.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z1002
152* --dumpname lsass.dmp*.{0,1000}\s\-\-dumpname\slsass\.dmp.{0,1000}offensive_tool_keywordPPLBladeProtected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.T1003.001 - T1027.004 - T1560.001 - T1039 - T1570TA0006 - TA0005 - TA0010 - TA0003N/AN/ACredential Accesshttps://github.com/tastypepperoni/PPLBlade10N/AN/A106545592023-08-30T07:59:51Z2023-08-29T19:36:04Z1003
153* DumpS1.ps1*.{0,1000}\sDumpS1\.ps1.{0,1000}greyware_tool_keywordSentinelAgentdump a process with SentinelAgent.exeT1003 - T1055TA0006 - TA0005N/AN/ACredential Accesshttps://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e10N/AN/A87N/AN/AN/AN/A1004
154* DumpSvc.exe*.{0,1000}\sDumpSvc\.exe.{0,1000}offensive_tool_keywordPWDumpXPWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.T1003.001 - T1555.003 - T1077TA0006 - TA0008N/AN/ACredential Accesshttps://packetstormsecurity.com/files/download/52580/PWDumpX.zip10N/AN/A108N/AN/AN/AN/A1005
155* EASSniper.ps1*.{0,1000}\sEASSniper\.ps1.{0,1000}offensive_tool_keywordEASSniperEASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)T1110 - T1078.003 - T1087.002 - T1059.001TA0006 -TA0007 - TA0009 - TA0002 - TA0001N/AN/ACredential Accesshttps://github.com/fugawi/EASSniper10N/AN/A101542018-04-17T23:23:31Z2018-04-17T22:43:51Z1014
156* EASSniper.ps1*.{0,1000}\sEASSniper\.ps1.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z1015
157* eas-valid-users.txt*.{0,1000}\seas\-valid\-users\.txt.{0,1000}offensive_tool_keywordEASSniperEASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)T1110 - T1078.003 - T1087.002 - T1059.001TA0006 -TA0007 - TA0009 - TA0002 - TA0001N/AN/ACredential Accesshttps://github.com/fugawi/EASSniper10N/AN/A101542018-04-17T23:23:31Z2018-04-17T22:43:51Z1016
158* empire_exec*.{0,1000}\sempire_exec.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1036
159* empireadmin*.{0,1000}\sempireadmin.{0,1000}offensive_tool_keywordcrackmapexecA swiss army knife for pentesting networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1037
160* --enum --validate-msol *.{0,1000}\s\-\-enum\s\-\-validate\-msol\s.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z1056
161* --enum --validate-teams*.{0,1000}\s\-\-enum\s\-\-validate\-teams.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z1057
162* enum_avproducts*.{0,1000}\senum_avproducts.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1058
163* enum_chrome*.{0,1000}\senum_chrome.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1059
164* enum_dns*.{0,1000}\senum_dns.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1060
165* EtwHash*.{0,1000}\sEtwHash.{0,1000}offensive_tool_keywordETWHashC# POC to extract NetNTLMv1/v2 hashes from ETW providerT1556.001TA0009 N/AN/ACredential Accesshttps://github.com/nettitude/ETWHash10N/AN/AN/A3256292023-05-10T06:45:06Z2023-04-26T15:53:01Z1075
166* EvilTwinServer *.{0,1000}\sEvilTwinServer\s.{0,1000}offensive_tool_keywordEvilLsassTwinattempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.T1003.001 - T1055 - T1093TA0006 - TA0005 - TA0002N/AN/ACredential Accesshttps://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin10N/AN/A92151182024-12-23T05:06:31Z2022-09-13T12:42:13Z1094
167* -ExchHostname * -Password *.{0,1000}\s\-ExchHostname\s.{0,1000}\s\-Password\s.{0,1000}offensive_tool_keywordMailSniperMailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.T1087.003 - T1110.003 - T1114.002TA0006 -TA0009 -TA0007N/AN/ACredential Accesshttps://github.com/dafthack/MailSniper/blob/master/MailSniper.ps110N/AN/AN/A1030465802024-08-07T18:11:58Z2016-09-08T00:36:51Z1095
168* --exfil --cookie-dump * --all*.{0,1000}\s\-\-exfil\s\-\-cookie\-dump\s\s.{0,1000}\s\-\-all.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z1122
169* --exfil --cookie-dump *.{0,1000}\s\-\-exfil\s\-\-cookie\-dump\s.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z1123
170* --exfil --teams --owa --owa-limit*.{0,1000}\s\-\-exfil\s\-\-teams\s\-\-owa\s\-\-owa\-limit.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z1124
171* --exfil --teams --owa*.{0,1000}\s\-\-exfil\s\-\-teams\s\-\-owa.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z1125
172* --exfil --tokens * --onedrive --owa*.{0,1000}\s\-\-exfil\s\-\-tokens\s.{0,1000}\s\-\-onedrive\s\-\-owa.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z1126
173* --exfil --tokens * --onedrive*.{0,1000}\s\-\-exfil\s\-\-tokens\s.{0,1000}\s\-\-onedrive.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z1127
174* extract --secrets --zsh*.{0,1000}\sextract\s\-\-secrets\s\-\-zsh.{0,1000}offensive_tool_keywordPassDetectivePassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secretsT1059 - T1059.004 - T1552 - T1552.001TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/aydinnyunus/PassDetective10N/AN/A7212982024-06-19T10:39:39Z2023-07-22T12:31:57Z1141
175* -f nessus.nessus *.{0,1000}\s\-f\snessus\.nessus\s.{0,1000}offensive_tool_keywordbrutesprayBruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.T1110TA0001 - TA0043N/AN/ACredential Accesshttps://github.com/x90skysn3k/brutespray10N/AN/A101022314052025-04-21T03:17:20Z2017-04-05T17:05:10Z1172
176* --force-ps32.{0,1000}\s\-\-force\-ps32offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1211
177* Forensike.ps1*.{0,1000}\sForensike\.ps1.{0,1000}offensive_tool_keywordForensikeRemotely dump NT hashes through Windows Crash dumpsT1003TA0006N/AN/ACredential Accesshttps://github.com/bmarchev/Forensike10N/AN/A1012732024-10-29T00:13:50Z2024-02-01T13:52:55Z1215
178* --fork --write *.dmp*.{0,1000}\s\-\-fork\s\-\-write\s.{0,1000}\.dmp.{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump10N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z1217
179* --format=netntlmv2 *.txt*.{0,1000}\s\-\-format\=netntlmv2\s.{0,1000}\.txt.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1228
180* --format=NT -w=*_password.txt*.{0,1000}\s\-\-format\=NT\s\-w\=.{0,1000}_password\.txt.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper is a fast password cracker.T1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/magnumripper/JohnTheRipper10#linuxN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1229
181* -fullmemdmp -snap & ping 127.0.0.1 -n *.{0,1000}\s\-fullmemdmp\s\-snap\s\&\sping\s127\.0\.0\.1\s\-n\s.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z1258
182* generate audit -ep *--passwords_in_userfile*.{0,1000}\sgenerate\saudit\s\-ep\s.{0,1000}\-\-passwords_in_userfile.{0,1000}offensive_tool_keywordSpray365Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).T1110.003TA0006N/AN/ACredential Accesshttps://github.com/MarkoH17/Spray36510N/AN/AN/A4348582022-07-14T14:45:57Z2021-11-04T18:20:39Z1291
183* generate normal -ep * -d * -u * -pf *.{0,1000}\sgenerate\snormal\s\-ep\s.{0,1000}\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-pf\s.{0,1000}offensive_tool_keywordSpray365Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).T1110.003TA0006N/AN/ACredential Accesshttps://github.com/MarkoH17/Spray36510N/AN/AN/A4348582022-07-14T14:45:57Z2021-11-04T18:20:39Z1292
184* generate normal -ep ex-plan.s365 *.{0,1000}\sgenerate\snormal\s\-ep\sex\-plan\.s365\s.{0,1000}offensive_tool_keywordSpray365Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).T1110.003TA0006N/AN/ACredential Accesshttps://github.com/MarkoH17/Spray36510N/AN/AN/A4348582022-07-14T14:45:57Z2021-11-04T18:20:39Z1293
185* --gen-relay-list *.{0,1000}\s\-\-gen\-relay\-list\s.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1300
186* get_keystrokes*.{0,1000}\sget_keystrokes.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1308
187* get_netdomaincontroller*.{0,1000}\sget_netdomaincontroller.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1309
188* get_netrdpsession*.{0,1000}\sget_netrdpsession.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1310
189* get_timedscreenshot*.{0,1000}\sget_timedscreenshot.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1312
190* Get-NetNTLM.ps1*.{0,1000}\sGet\-NetNTLM\.ps1.{0,1000}offensive_tool_keywordGet-NetNTLMPowershell module to get the NetNTLMv2 hash of the current userT1110.003 - T1557.001 - T1040TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/elnerd/Get-NetNTLM10N/AN/A7193182022-07-05T20:55:33Z2019-02-11T23:09:54Z1323
191* Get-SpoolStatus.ps1*.{0,1000}\sGet\-SpoolStatus\.ps1.{0,1000}offensive_tool_keywordNetNTLMtoSilverTicketObtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.T1110.001 - T1558.003 - T1558.004TA0006 - TA0008 - TA0002N/AN/ACredential Accesshttps://github.com/NotMedic/NetNTLMtoSilverTicket10N/AN/A1098421132021-07-26T15:16:20Z2019-01-14T15:32:27Z1332
192* github repos list --org*.{0,1000}\sgithub\srepos\slist\s\-\-org.{0,1000}offensive_tool_keywordnoseyparkerNosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.T1583 - T1059.001 - T1059.003TA0002 - TA0003 - TA0040N/AN/ACredential Accesshttps://github.com/praetorian-inc/noseyparker10N/AN/A81019031002025-03-07T20:15:34Z2022-11-08T23:09:17Z1342
193* github repos list --user *.{0,1000}\sgithub\srepos\slist\s\-\-user\s.{0,1000}offensive_tool_keywordnoseyparkerNosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.T1583 - T1059.001 - T1059.003TA0002 - TA0003 - TA0040N/AN/ACredential Accesshttps://github.com/praetorian-inc/noseyparker10N/AN/A81019031002025-03-07T20:15:34Z2022-11-08T23:09:17Z1343
194* golden * /badpwdcount*.{0,1000}\sgolden\s.{0,1000}\s\/badpwdcount.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z1351
195* golden * /ldap *.{0,1000}\sgolden\s.{0,1000}\s\/ldap\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z1352
196* golden * /user:*.{0,1000}\sgolden\s.{0,1000}\s\/user\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z1353
197* gosecretsdump_linux*.{0,1000}\sgosecretsdump_linux.{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump10#linuxN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z1360
198* gosecretsdump_mac*.{0,1000}\sgosecretsdump_mac.{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump10N/AN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z1361
199* gosecretsdump_win*.{0,1000}\sgosecretsdump_win.{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump10N/AN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z1362
200* gpp_autologin*.{0,1000}\sgpp_autologin.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1375
201* gpp_password*.{0,1000}\sgpp_password.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1376
202* hack.py*.{0,1000}\shack\.py.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1399
203* harvest * /monitorinterval:*.{0,1000}\sharvest\s.{0,1000}\s\/monitorinterval\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z1410
204* hashview.py*.{0,1000}\shashview\.py.{0,1000}offensive_tool_keywordhashviewA web front-end for password cracking and analyticsT1110 - T1201TA0006 - TA0002N/AN/ACredential Accesshttps://github.com/hashview/hashview10N/AN/A104373412025-02-20T18:23:25Z2020-11-23T19:21:06Z1415
205* hashview-agent *.{0,1000}\shashview\-agent\s.{0,1000}offensive_tool_keywordhashviewA web front-end for password cracking and analyticsT1110 - T1201TA0006 - TA0002N/AN/ACredential Accesshttps://github.com/hashview/hashview10N/AN/A104373412025-02-20T18:23:25Z2020-11-23T19:21:06Z1416
206* httprelayserver.py*.{0,1000}\shttprelayserver\.py.{0,1000}offensive_tool_keywordNtlmRelayToEWSntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)T1212 - T1557 - T1040 - T1078TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/Arno0x/NtlmRelayToEWS10N/AN/A104331602018-01-15T12:48:02Z2017-10-13T18:00:50Z1528
207* icebreaker.py*.{0,1000}\sicebreaker\.py.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker10N/AN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z1607
208* -Identity * -Set @{serviceprincipalname='*'}*.{0,1000}\s\-Identity\s.{0,1000}\s\-Set\s\@\{serviceprincipalname\=\'.{0,1000}\'\}.{0,1000}offensive_tool_keywordAD exploitation cheat sheetTargeted kerberoasting by setting SPNT1110TA0006N/ABlack BastaCredential Accesshttps://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference10N/AN/AN/AN/AN/AN/AN/AN/A1613
209* -Identity * -XOR @{useraccountcontrol=4194304*.{0,1000}\s\-Identity\s.{0,1000}\s\-XOR\s\@\{useraccountcontrol\=4194304.{0,1000}offensive_tool_keywordAD exploitation cheat sheetTargeted kerberoasting we need ACL write permissions to set UserAccountControl flags for the target user. Using PowerViewT1110TA0006N/ABlack BastaCredential Accesshttps://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference10N/AN/AN/AN/AN/AN/AN/AN/A1614
210* impacketfile.py*.{0,1000}\simpacketfile\.py.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z1634
211* -inc -u=0 *.pwd*.{0,1000}\s\-inc\s\-u\=0\s.{0,1000}\.pwd.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1650
212* -inc=digits *.{0,1000}\s\-inc\=digits\s.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1651
213* -InFile Wi-Fi-PASS*.{0,1000}\s\-InFile\sWi\-Fi\-PASS.{0,1000}offensive_tool_keywordwifigrabbergrab wifi password and exfiltrate to a given siteT1056.005 - T1552.001 - T1119 - T1071.001TA0004 - TA0006 - TA0010 - TA0040N/AN/ACredential Accesshttps://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber10N/AN/A10109043102024-09-14T02:34:26Z2021-09-08T20:33:18Z1657
214* instabf.py*.{0,1000}\sinstabf\.py.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/samsesh/insta-bf10N/AN/A7159132024-04-23T02:47:28Z2020-11-20T22:22:48Z1670
215* instainsane.sh*.{0,1000}\sinstainsane\.sh.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/umeshshinde19/instainsane10N/AN/A776553712024-02-11T10:29:05Z2018-12-02T22:48:11Z1671
216* install chntpw*.{0,1000}\sinstall\schntpw.{0,1000}offensive_tool_keywordchntpwreset a password on your systemT1003 - T1078TA0006N/AN/ACredential Accesshttps://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip10N/AN/A1010N/AN/AN/AN/A1682
217* install creddump7*.{0,1000}\sinstall\screddump7.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump710N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z1684
218* install hekatomb*.{0,1000}\sinstall\shekatomb.{0,1000}offensive_tool_keywordHEKATOMBHekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt themT1003 - T1555.002 - T1482 - T1087TA0006 - TA0005 - TA0007N/AN/ACredential Accesshttps://github.com/Processus-Thief/HEKATOMB10N/AN/A106N/AN/AN/AN/A1690
219* install requests_ntlm*.{0,1000}\sinstall\srequests_ntlm.{0,1000}greyware_tool_keywordrequests-ntlmHTTP NTLM Authentication for Requests LibraryT1003 - T1547.005 - T1055 - T1557TA0008 - TA0006N/AN/ACredential Accesshttps://pypi.org/project/requests-ntlm/10N/AN/A89N/AN/AN/AN/A1699
220* install samdump2*.{0,1000}\sinstall\ssamdump2.{0,1000}offensive_tool_keywordwcreddumpFully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.T1003 - T1110.001TA0006N/AN/ACredential Accesshttps://github.com/truerustyy/wcreddump10#linux #windowsN/A1017552024-11-18T18:37:28Z2024-03-05T00:00:20Z1700
221* install spraycharles*.{0,1000}\sinstall\sspraycharles.{0,1000}offensive_tool_keywordspraycharlesLow and slow password spraying toolT1110.003 - T1110.001TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Tw1sm/spraycharles10N/AN/A102195322025-02-09T03:08:09Z2018-09-17T11:17:47Z1703
222* install wordlists*.{0,1000}\sinstall\swordlists.{0,1000}offensive_tool_keywordwordlistspackage contains the rockyou.txt wordlistT1110.001TA0006N/AN/ACredential Accesshttps://www.kali.org/tools/wordlists/10N/AN/AN/AN/AN/AN/AN/AN/A1714
223* install-sb.sh*.{0,1000}\sinstall\-sb\.sh.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/samsesh/SocialBox-Termux10N/AN/A71035813912024-09-02T19:15:22Z2019-03-28T18:07:05Z1717
224* insTof.py*.{0,1000}\sinsTof\.py.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/samsesh/insta-bf10N/AN/A7159132024-04-23T02:47:28Z2020-11-20T22:22:48Z1718
225* invoke_sessiongopher*.{0,1000}\sinvoke_sessiongopher.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1735
226* invoke_vnc*.{0,1000}\sinvoke_vnc.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1736
227* john_done*.{0,1000}\sjohn_done.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1806
228* john_fork*.{0,1000}\sjohn_fork.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1807
229* john_load*.{0,1000}\sjohn_load.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1808
230* john_load_conf*.{0,1000}\sjohn_load_conf.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1809
231* john_load_conf_db*.{0,1000}\sjohn_load_conf_db.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1810
232* john_log_format*.{0,1000}\sjohn_log_format.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1811
233* john_log_format2*.{0,1000}\sjohn_log_format2.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1812
234* john_mpi_wait*.{0,1000}\sjohn_mpi_wait.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1813
235* john_omp_fallback*.{0,1000}\sjohn_omp_fallback.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1814
236* john_omp_init*.{0,1000}\sjohn_omp_init.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1815
237* john_omp_maybe_adjust_or_fallback*.{0,1000}\sjohn_omp_maybe_adjust_or_fallback.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1816
238* john_omp_show_info*.{0,1000}\sjohn_omp_show_info.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1817
239* john_register_all*.{0,1000}\sjohn_register_all.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1818
240* john_register_one*.{0,1000}\sjohn_register_one.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1819
241* john_run*.{0,1000}\sjohn_run.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1820
242* john_set_mpi*.{0,1000}\sjohn_set_mpi.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1821
243* john_set_tristates*.{0,1000}\sjohn_set_tristates.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1822
244* john_wait*.{0,1000}\sjohn_wait.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1824
245* JohnTheRipper/*.{0,1000}\sJohnTheRipper\/.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1825
246* -just-dc-ntlm *.{0,1000}\s\-just\-dc\-ntlm\s.{0,1000}offensive_tool_keywordsecretsdumpsecretdump.py from impacket - https://github.com/fortra/impacketT1003.003TA0006Operation WocaoBlack Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITECredential Accesshttps://github.com/fortra/impacket10N/AN/A10101419836812025-04-22T13:40:55Z2015-04-15T14:04:07Z1833
247* -just-dc-user *.{0,1000}\s\-just\-dc\-user\s.{0,1000}offensive_tool_keywordsecretsdumpsecretdump.py from impacket - https://github.com/fortra/impacketT1003.003TA0006Operation WocaoBlack Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITECredential Accesshttps://github.com/fortra/impacket10N/AN/A10101419836812025-04-22T13:40:55Z2015-04-15T14:04:07Z1836
248* keepass /unprotect*.{0,1000}\skeepass\s\/unprotect.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z1848
249* KeePwn.py*.{0,1000}\sKeePwn\.py.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn10N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z1851
250* KeeTheft.exe*.{0,1000}\sKeeTheft\.exe.{0,1000}offensive_tool_keywordKeeThiefSyscallsPatch GhostPack/KeeThief for it to use DInvoke and syscallsT1003.001 - T1558.002TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/Metro-Holografix/KeeThiefSyscalls10N/Aprivate github repo101N/AN/AN/AN/A1852
251* KeeThief.ps1*.{0,1000}\sKeeThief\.ps1.{0,1000}offensive_tool_keywordKeethiefAllows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.T1003 - T1055 - T1059 - T1070TA0006 - TA0005 - TA0008N/AEvilCorp* - APT20Credential Accesshttps://github.com/GhostPack/KeeThief10N/AN/A10109441542020-11-18T18:35:21Z2016-07-10T19:11:23Z1853
252* kerberoast *.{0,1000}\skerberoast\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z1855
253* kerberoast *.{0,1000}\skerberoast\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z1856
254* kerberos asreproast *.{0,1000}\skerberos\sasreproast\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1863
255* kerberos brute * -d *.{0,1000}\skerberos\sbrute\s.{0,1000}\s\-d\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1864
256* kerberos brute *.txt*.{0,1000}\skerberos\sbrute\s.{0,1000}\.txt.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1865
257* kerberos ccache del *.ccache*.{0,1000}\skerberos\sccache\sdel\s.{0,1000}\.ccache.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1866
258* kerberos ccache exportkirbi *.{0,1000}\skerberos\sccache\sexportkirbi\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1867
259* kerberos ccache list *.ccache*.{0,1000}\skerberos\sccache\slist\s.{0,1000}\.ccache.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1868
260* kerberos ccache loadkirbi *.{0,1000}\skerberos\sccache\sloadkirbi\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1869
261* kerberos ccache roast *.{0,1000}\skerberos\sccache\sroast\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1870
262* kerberos keytab *.keytab*.{0,1000}\skerberos\skeytab\s.{0,1000}\.keytab.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1871
263* kerberos kirbi parse *.{0,1000}\skerberos\skirbi\sparse\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1872
264* kerberos spnroast *.{0,1000}\skerberos\sspnroast\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1873
265* kerberos.py*.{0,1000}\skerberos\.py.{0,1000}offensive_tool_keywordcrackmapexecprotocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z1875
266* kerbrute.py*.{0,1000}\skerbrute\.py.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute10N/AN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z1876
267* --key PPLBlade*.{0,1000}\s\-\-key\sPPLBlade.{0,1000}offensive_tool_keywordPPLBladeProtected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.T1003.001 - T1027.004 - T1560.001 - T1039 - T1570TA0006 - TA0005 - TA0010 - TA0003N/AN/ACredential Accesshttps://github.com/tastypepperoni/PPLBlade10N/AN/A106545592023-08-30T07:59:51Z2023-08-29T19:36:04Z1878
268* KeyCredentialLink.ps1*.{0,1000}\sKeyCredentialLink\.ps1.{0,1000}offensive_tool_keywordKeyCredentialLinkAdd Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attributeT1098 - T1550TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/Leo4j/KeyCredentialLink10N/AN/A1012132024-06-05T13:44:39Z2024-06-05T13:19:49Z1879
269* klist * /service:*.{0,1000}\sklist\s.{0,1000}\s\/service\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z1892
270* knowsmore.cmd.wordlist*.{0,1000}\sknowsmore\.cmd\.wordlist.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1893
271* knowsmore.cmdbase*.{0,1000}\sknowsmore\.cmdbase.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1894
272* knowsmore.config*.{0,1000}\sknowsmore\.config.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1895
273* knowsmore.knowsmore*.{0,1000}\sknowsmore\.knowsmore.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1896
274* knowsmore.libs.bloodhoundsync*.{0,1000}\sknowsmore\.libs\.bloodhoundsync.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1897
275* knowsmore.libs.exporterbase*.{0,1000}\sknowsmore\.libs\.exporterbase.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1898
276* knowsmore.libs.ntdsuseraccount*.{0,1000}\sknowsmore\.libs\.ntdsuseraccount.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1899
277* knowsmore.module*.{0,1000}\sknowsmore\.module.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1900
278* knowsmore.password*.{0,1000}\sknowsmore\.password.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1901
279* knowsmore.py*.{0,1000}\sknowsmore\.py.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1902
280* knowsmore.util.color*.{0,1000}\sknowsmore\.util\.color.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1903
281* knowsmore.util.database*.{0,1000}\sknowsmore\.util\.database.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1904
282* knowsmore.util.knowsmoredb*.{0,1000}\sknowsmore\.util\.knowsmoredb.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1905
283* knowsmore.util.logger*.{0,1000}\sknowsmore\.util\.logger.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1906
284* knowsmore.util.process*.{0,1000}\sknowsmore\.util\.process.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1907
285* knowsmore.util.tools*.{0,1000}\sknowsmore\.util\.tools.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z1908
286* l$a$$Pid *.{0,1000}\sl\$a\$\$Pid\s.{0,1000}offensive_tool_keywordDumpThatLSASSDumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the diskT1003 - T1055.011 - T1027 - T1564.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/peiga/DumpThatLSASS10N/AN/A10131792022-09-24T22:39:04Z2022-09-24T22:41:19Z1919
287* laps.py *--ldapserver*.{0,1000}\slaps\.py\s.{0,1000}\-\-ldapserver.{0,1000}offensive_tool_keywordLAPSDumperDumping LAPS from PythonT1136.001 - T1112 - T1078.001TA0002 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/n00py/LAPSDumper10N/AN/A103267352022-12-07T18:35:28Z2020-12-19T05:15:10Z1924
288* laps.py *-u * -p *.{0,1000}\slaps\.py\s.{0,1000}\-u\s.{0,1000}\s\-p\s.{0,1000}offensive_tool_keywordLAPSDumperDumping LAPS from PythonT1136.001 - T1112 - T1078.001TA0002 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/n00py/LAPSDumper10N/AN/A103267352022-12-07T18:35:28Z2020-12-19T05:15:10Z1925
289* laZagne.py*.{0,1000}\slaZagne\.py.{0,1000}offensive_tool_keywordLaZagneThe LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001TA0006 - TA0009N/AAkira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONTCredential Accesshttps://github.com/AlessandroZ/LaZagne10N/AN/A1010994120622025-04-10T14:24:35Z2015-02-16T14:10:02Z1930
290* --list=hidden-options*.{0,1000}\s\-\-list\=hidden\-options.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1959
291* live dpapi blobfile *.blob*.{0,1000}\slive\sdpapi\sblobfile\s.{0,1000}\.blob.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1964
292* live dpapi cred *.{0,1000}\slive\sdpapi\scred\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1965
293* live dpapi keys -o *.{0,1000}\slive\sdpapi\skeys\s\-o\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1966
294* live dpapi securestring *.{0,1000}\slive\sdpapi\ssecurestring\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1967
295* live dpapi vcred *.{0,1000}\slive\sdpapi\svcred\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1968
296* live dpapi vpol *.{0,1000}\slive\sdpapi\svpol\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1969
297* live dpapi wifi*.{0,1000}\slive\sdpapi\swifi.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1970
298* live kerberos apreq *.{0,1000}\slive\skerberos\sapreq\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1971
299* live kerberos dump*.{0,1000}\slive\skerberos\sdump.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1972
300* live kerberos purge*.{0,1000}\slive\skerberos\spurge.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1973
301* live kerberos roast*.{0,1000}\slive\skerberos\sroast.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1974
302* live kerberos sessions*.{0,1000}\slive\skerberos\ssessions.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1975
303* live kerberos tgt*.{0,1000}\slive\skerberos\stgt.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1976
304* live kerberos triage*.{0,1000}\slive\skerberos\striage.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1977
305* live lsa -o *.{0,1000}\slive\slsa\s\-o\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1978
306* live lsa -o *.{0,1000}\slive\slsa\s\-o\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1979
307* live process create -c regedit*.{0,1000}\slive\sprocess\screate\s\-c\sregedit.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1980
308* live smb client *.{0,1000}\slive\ssmb\sclient\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1981
309* live smb dcsync *.{0,1000}\slive\ssmb\sdcsync\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1982
310* live smb lsassdump *.{0,1000}\slive\ssmb\slsassdump\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1983
311* live smb regdump *.{0,1000}\slive\ssmb\sregdump\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1984
312* live smb secretsdump *.{0,1000}\slive\ssmb\ssecretsdump\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1985
313* live smbapi localgroup enum -t*.{0,1000}\slive\ssmbapi\slocalgroup\senum\s\-t.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1986
314* live smbapi session enum *.{0,1000}\slive\ssmbapi\ssession\senum\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1987
315* live smbapi share enum*.{0,1000}\slive\ssmbapi\sshare\senum.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1988
316* live users whoami*.{0,1000}\slive\susers\swhoami.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z1989
317* lnkbomb.py*.{0,1000}\slnkbomb\.py.{0,1000}offensive_tool_keywordlnkbombMalicious shortcut generator for collecting NTLM hashes from insecure file shares.T1023.003 - T1557.002 - T1046TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/dievus/lnkbomb10N/AN/A104327582024-10-22T17:51:10Z2022-01-03T04:17:11Z1996
318* load_extra_pots*.{0,1000}\sload_extra_pots.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z1998
319* --load-dll *ssp.dll*.{0,1000}\s\-\-load\-dll\s.{0,1000}ssp\.dll.{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump10N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z2000
320* Local:DPAPIDecrypt*.{0,1000}\sLocal\:DPAPIDecrypt.{0,1000}offensive_tool_keywordSecretServerSecretStealerPowershell script that decrypts the data stored within a Thycotic Secret ServerT1552 - T1027 - T1059TA0006N/AEvilCorp*Credential Accesshttps://github.com/denandz/SecretServerSecretStealer10N/AN/A10178142020-08-03T06:52:27Z2017-04-21T04:06:24Z2010
321* Local:LoadEncryptionDll*.{0,1000}\sLocal\:LoadEncryptionDll.{0,1000}offensive_tool_keywordSecretServerSecretStealerPowershell script that decrypts the data stored within a Thycotic Secret ServerT1552 - T1027 - T1059TA0006N/AEvilCorp*Credential Accesshttps://github.com/denandz/SecretServerSecretStealer10N/AN/A10178142020-08-03T06:52:27Z2017-04-21T04:06:24Z2011
322* --local-auth --shares*.{0,1000}\s\-\-local\-auth\s\-\-shares.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2017
323* --loggedon-users*.{0,1000}\s\-\-loggedon\-users.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2035
324* loginAAD.ps1*.{0,1000}\sloginAAD\.ps1.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z2037
325* lsa minidump * -o *.{0,1000}\slsa\sminidump\s.{0,1000}\s\-o\s.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z2042
326* lsa minidump *.dmp*.{0,1000}\slsa\sminidump\s.{0,1000}\.dmp.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z2044
327* lsa minidump /*.{0,1000}\slsa\sminidump\s\/.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z2045
328* lsadump.py*.{0,1000}\slsadump\.py.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump710N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z2046
329* lsasecrets.py*.{0,1000}\slsasecrets\.py.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump710N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z2047
330* lsass.dmp*.{0,1000}\slsass\.dmp.{0,1000}offensive_tool_keywordAD exploitation cheat sheetDump LSASS memory through a process snapshot (-r) avoiding interacting with it directlyT1110TA0006N/ABlack BastaCredential Accesshttps://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference10N/AN/AN/AN/AN/AN/AN/AN/A2048
331* Lsassx.ps1*.{0,1000}\sLsassx\.ps1.{0,1000}offensive_tool_keywordLsassxDumping LSASS Evaded Endpoint Security SolutionsT1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001TA0006 - TA0005 - TA0004N/AN/ACredential Accesshttps://github.com/yehia-mamdouh/Lsassx10N/AN/A1011232025-02-15T16:41:38Z2025-02-15T16:36:27Z2050
332* Lsassx-OBF.ps1*.{0,1000}\sLsassx\-OBF\.ps1.{0,1000}offensive_tool_keywordLsassxDumping LSASS Evaded Endpoint Security SolutionsT1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001TA0006 - TA0005 - TA0004N/AN/ACredential Accesshttps://github.com/yehia-mamdouh/Lsassx10N/AN/A1011232025-02-15T16:41:38Z2025-02-15T16:36:27Z2051
333* lsassy*.{0,1000}\slsassy.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z2053
334* Luna Grabber Builder*.{0,1000}\sLuna\sGrabber\sBuilder.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber10N/AN/A10N/A2056
335* LyncSniper.ps1*.{0,1000}\/LyncSniper\.ps1.{0,1000}offensive_tool_keywordSprayingToolkitScripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficientT1110 - T1078 - T1133 - T1061 - T1621TA0001 - TA0002 - TA0003N/AN/ACredential Accesshttps://github.com/byt3bl33d3r/SprayingToolkit10N/AN/A101014912692022-10-17T01:01:57Z2018-09-13T09:52:11Z2057
336* -M multirdp*.{0,1000}\s\-M\smultirdp.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2076
337* -M pe_inject*.{0,1000}\s\-M\spe_inject.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2079
338* -m rdrleakdiag -M masterkeys*.{0,1000}\s\-m\srdrleakdiag\s\-M\smasterkeys.{0,1000}offensive_tool_keyworddplootDPAPI looting remotely in PythonT1003.006 - T1027 - T1110.004TA0006 - TA0007 - TA0010N/AN/ACredential Accesshttps://github.com/zblurx/dploot10N/AN/A105455582025-04-09T08:17:14Z2022-05-24T11:05:21Z2085
339* -M scuffy*.{0,1000}\s\-M\sscuffy.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2089
340* -M shellcode_inject*.{0,1000}\s\-M\sshellcode_inject.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2092
341* -M slinky.{0,1000}\s\-M\sslinkyoffensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2094
342* -M tokens*.{0,1000}\s\-M\stokens.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2100
343* -M uac.{0,1000}\s\-M\suacoffensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2101
344* -M web_delivery*.{0,1000}\s\-M\sweb_delivery.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2105
345* m365-fatigue.py *.{0,1000}\sm365\-fatigue\.py\s.{0,1000}offensive_tool_keywordm365-fatigueautomates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.T1110.001 - T1078.001 - T1556.004TA0006 - TA0008 - TA0009N/AN/ACredential Accesshttps://github.com/0xB455/m365-fatigue10N/AN/A1017772024-04-08T14:53:44Z2023-11-30T13:33:03Z2107
346* -ma lssas.exe*.{0,1000}\s\-ma\slssas\.exe.{0,1000}greyware_tool_keywordProcdumpdump lsass process with procdumpT1003.001TA0006N/ALockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - DispossessorCredential Accesshttps://learn.microsoft.com/en-us/sysinternals/downloads/procdump10N/AN/A1010N/AN/AN/AN/A2109
347* mask?a?a?a?a?*.{0,1000}\smask\?a\?a\?a\?a\?.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z2118
348* --mask=?1?1?1* --min-len*.{0,1000}\s\-\-mask\=\?1\?1\?1.{0,1000}\s\-\-min\-len.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z2119
349* memorydump.py*.{0,1000}\smemorydump\.py.{0,1000}offensive_tool_keywordLaZagneThe LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001TA0006 - TA0009N/AAkira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONTCredential Accesshttps://github.com/AlessandroZ/LaZagne10N/AN/A1010994120622025-04-10T14:24:35Z2015-02-16T14:10:02Z2136
350* met_inject*.{0,1000}\smet_inject.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2142
351* mimikittenz*.{0,1000}\smimikittenz.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2159
352* mimipenguin.sh*.{0,1000}\smimipenguin\.sh.{0,1000}offensive_tool_keywordmimipyTool to dump passwords from various processes memoryT1003TA0006N/AN/ACredential Accesshttps://github.com/n1nj4sec/mimipy10N/AN/A103207362017-04-30T00:09:15Z2017-04-05T21:06:32Z2160
353* mimipy.py *.{0,1000}\smimipy\.py\s.{0,1000}offensive_tool_keywordmimipyTool to dump passwords from various processes memoryT1003TA0006N/AN/ACredential Accesshttps://github.com/n1nj4sec/mimipy10N/AN/A103207362017-04-30T00:09:15Z2017-04-05T21:06:32Z2161
354* MirrorDump.exe*.{0,1000}\sMirrorDump\.exe.{0,1000}offensive_tool_keywordMirrorDumpLSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memoryT1003 - T1055 - T1574TA0006 - TA0005 - TA0003N/AN/ACredential Accesshttps://github.com/CCob/MirrorDump10N/AN/A103265582021-03-18T18:19:00Z2021-03-18T18:18:56Z2164
355* --mobaxterm-poison-hkcr*.{0,1000}\s\-\-mobaxterm\-poison\-hkcr.{0,1000}offensive_tool_keywordThievingFoxcollection of post-exploitation tools to gather credentials from various password managersT1555 - T1003 - T1056 - T1070TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Slowerzs/ThievingFox10N/AN/A106535652024-03-28T19:58:03Z2024-01-20T23:22:52Z2169
356* --mode decrypt --dumpname *.dmp --key *.{0,1000}\s\-\-mode\sdecrypt\s\-\-dumpname\s.{0,1000}\.dmp\s\-\-key\s.{0,1000}offensive_tool_keywordPPLBladeProtected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.T1003.001 - T1027.004 - T1560.001 - T1039 - T1570TA0006 - TA0005 - TA0010 - TA0003N/AN/ACredential Accesshttps://github.com/tastypepperoni/PPLBlade10N/AN/A106545592023-08-30T07:59:51Z2023-08-29T19:36:04Z2171
357* --mode dump --name *.exe --handle procexp --obfuscate*.{0,1000}\s\-\-mode\sdump\s\-\-name\s.{0,1000}\.exe\s\-\-handle\sprocexp\s\-\-obfuscate.{0,1000}offensive_tool_keywordPPLBladeProtected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.T1003.001 - T1027.004 - T1560.001 - T1039 - T1570TA0006 - TA0005 - TA0010 - TA0003N/AN/ACredential Accesshttps://github.com/tastypepperoni/PPLBlade10N/AN/A106545592023-08-30T07:59:51Z2023-08-29T19:36:04Z2172
358* --mode dump --name lsass.exe*.{0,1000}\s\-\-mode\sdump\s\-\-name\slsass\.exe.{0,1000}offensive_tool_keywordPPLBladeProtected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.T1003.001 - T1027.004 - T1560.001 - T1039 - T1570TA0006 - TA0005 - TA0010 - TA0003N/AN/ACredential Accesshttps://github.com/tastypepperoni/PPLBlade10N/AN/A106545592023-08-30T07:59:51Z2023-08-29T19:36:04Z2173
359* --module o365_spray_activesync*.{0,1000}\s\-\-module\so365_spray_activesync.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2178
360* monitor /interval:* /filteruser:*.{0,1000}\smonitor\s\/interval\:.{0,1000}\s\/filteruser\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z2182
361* mssprinkler.ps1*.{0,1000}\smssprinkler\.ps1.{0,1000}offensive_tool_keywordMSSprinklerpassword spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approachT1110.003 - T1110.001TA0006 - TA0007 - TA0008N/AN/ACredential Accesshttps://github.com/TheresAFewConors/MSSprinkler10N/AN/A917472025-02-25T13:32:41Z2024-09-15T09:54:53Z2203
362* --mstsc-poison-hkcr*.{0,1000}\s\-\-mstsc\-poison\-hkcr.{0,1000}offensive_tool_keywordThievingFoxcollection of post-exploitation tools to gather credentials from various password managersT1555 - T1003 - T1056 - T1070TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Slowerzs/ThievingFox10N/AN/A106535652024-03-28T19:58:03Z2024-01-20T23:22:52Z2218
363* MultiDump.exe*.{0,1000}\sMultiDump\.exe.{0,1000}offensive_tool_keywordMultiDumpMultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetlyT1003 - T1564.002TA0005 - TA0006N/AN/ACredential Accesshttps://github.com/Xre0uS/MultiDump10N/AN/A106510662025-03-28T10:40:27Z2024-02-02T05:56:29Z2220
364* nanodump*.{0,1000}\snanodump.{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump10N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z2253
365* nanodump/*.{0,1000}\snanodump\/.{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump10N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z2254
366* NativeDump.exe*.{0,1000}\sNativeDump\.exe.{0,1000}offensive_tool_keywordNativeDumpDump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)T1003.001TA0006N/AN/ACredential Accesshttps://github.com/ricardojoserf/NativeDump10N/AN/A106586862024-12-17T15:36:57Z2024-02-22T15:16:16Z2255
367* nc_srv.bat*.{0,1000}\snc_srv\.bat.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z2268
368* needs High Integrity Privileges to dump the relevant process!*.{0,1000}\sneeds\sHigh\sIntegrity\sPrivileges\sto\sdump\sthe\srelevant\sprocess!.{0,1000}offensive_tool_keywordpandoraA red team tool that assists into extracting/dumping master credentials and/or entries from different password managersT1555 - T1003TA0006 - TA0003N/AN/ACredential Accesshttps://github.com/efchatz/pandora10#contentN/A108738882025-01-09T14:58:57Z2023-11-03T18:01:31Z2274
369* --neo4j-host *.{0,1000}\s\-\-neo4j\-host\s.{0,1000}offensive_tool_keywordsmartbrutePassword spraying and bruteforcing tool for Active Directory Domain ServicesT1110.001 - T1110.003TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/ShutdownRepo/smartbrute10N/AN/A104365542024-10-27T20:47:29Z2021-07-16T14:53:29Z2279
370* --neo4j-host *--neo4j-port*.{0,1000}\s\-\-neo4j\-host\s.{0,1000}\-\-neo4j\-port.{0,1000}offensive_tool_keywordsprayhoundPassword spraying tool and Bloodhound integrationT1110.003 - T1210.001 - T1069.002TA0006 - TA0007 - TA0003N/AN/ACredential Accesshttps://github.com/Hackndo/sprayhound10N/AN/AN/A3231192024-12-31T08:09:37Z2020-02-06T17:45:37Z2280
371* -neo4j-password *.{0,1000}\s\-neo4j\-password\s.{0,1000}offensive_tool_keywordsmartbrutePassword spraying and bruteforcing tool for Active Directory Domain ServicesT1110.001 - T1110.003TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/ShutdownRepo/smartbrute10N/AN/A104365542024-10-27T20:47:29Z2021-07-16T14:53:29Z2281
372* --neo4j-port *.{0,1000}\s\-\-neo4j\-port\s.{0,1000}offensive_tool_keywordsmartbrutePassword spraying and bruteforcing tool for Active Directory Domain ServicesT1110.001 - T1110.003TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/ShutdownRepo/smartbrute10N/AN/A104365542024-10-27T20:47:29Z2021-07-16T14:53:29Z2282
373* --neo4j-user *.{0,1000}\s\-\-neo4j\-user\s.{0,1000}offensive_tool_keywordsmartbrutePassword spraying and bruteforcing tool for Active Directory Domain ServicesT1110.001 - T1110.003TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/ShutdownRepo/smartbrute10N/AN/A104365542024-10-27T20:47:29Z2021-07-16T14:53:29Z2283
374* netripper*.{0,1000}\snetripper.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2299
375* NiceRAT.py*.{0,1000}\sNiceRAT\.py.{0,1000}offensive_tool_keywordcstealerNiceRAT stealer - clone of cstealerT1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/0x00G/NiceRAT10N/AN/A102118862024-10-20T18:38:53Z2022-11-20T19:11:00Z2312
376* --ntds * -crack *.{0,1000}\s\-\-ntds\s.{0,1000}\s\-crack\s.{0,1000}offensive_tool_keywordautoNTDSautoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcatT1003 - T1059 - T1021.002 - T1213TA0006 - TA0008 - TA0005 - TA0002N/AN/ACredential Accesshttps://github.com/hmaverickadams/autoNTDS10N/AN/A102109142023-10-31T22:03:58Z2023-10-30T23:10:58Z2381
377* -ntds NTDS.dit -filters*.{0,1000}\s\-ntds\sNTDS\.dit\s\s\-filters.{0,1000}offensive_tool_keywordntdissectorNtdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.T1003.003TA0006 N/AN/ACredential Accesshttps://github.com/synacktiv/ntdissector10N/AN/A92139172024-08-16T14:18:35Z2023-09-05T12:13:47Z2383
378* -ntds ntds.dit -system SYSTEM *.{0,1000}\s\-ntds\sntds\.dit\s\-system\sSYSTEM\s.{0,1000}offensive_tool_keywordimpacketImpacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itselfT1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011N/AAkira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black BastaCredential Accesshttps://github.com/fortra/impacket10N/AN/A10101419836812025-04-22T13:40:55Z2015-04-15T14:04:07Z2384
379* -ntds NTDS.dit -system SYSTEM -outputdir /*.{0,1000}\s\-ntds\sNTDS\.dit\s\-system\sSYSTEM\s\-outputdir\s\/.{0,1000}offensive_tool_keywordntdissectorNtdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.T1003.003TA0006 N/AN/ACredential Accesshttps://github.com/synacktiv/ntdissector10N/AN/A92139172024-08-16T14:18:35Z2023-09-05T12:13:47Z2385
380* --ntds-file *.{0,1000}\s\-\-ntds\-file\s.{0,1000}offensive_tool_keywordquarkspwdumpQuarks PwDump is a native Win32 tool to extract credentials from Windows operating systemsT1003 - T1003.001 - T1059TA0006N/ALOTUS PANDA - PowerPool - CalypsoCredential Accesshttps://github.com/peterdocter/quarkspwdump10N/AN/A911282015-06-25T04:22:21Z2015-07-14T08:18:08Z2387
381* --ntds-history*.{0,1000}\s\-\-ntds\-history.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2388
382* --ntds-pwdLastSet*.{0,1000}\s\-\-ntds\-pwdLastSet.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2389
383* ntdsuseraccount.py*.{0,1000}\sntdsuseraccount\.py.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z2390
384* ntlm.wordlist *--hex-wordlist*.{0,1000}\sntlm\.wordlist\s.{0,1000}\-\-hex\-wordlist.{0,1000}offensive_tool_keywordhashcatWorlds fastest and most advanced password recovery utility.T1110.001 - T1003.001 - T1021.001TA0006 - TA0009 - TA0010N/ABlack BastaCredential Accesshttps://github.com/hashcat/hashcat10#linuxN/A10102248130462024-08-16T23:50:35Z2015-12-04T14:46:51Z2395
385* ntlmdecoder.py*.{0,1000}\sntlmdecoder\.py.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z2396
386* ntlmdecoder.py*.{0,1000}\sntlmdecoder\.py.{0,1000}offensive_tool_keywordSprayingToolkitScripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficientT1110 - T1078 - T1133 - T1061 - T1621TA0001 - TA0002 - TA0003N/AN/ACredential Accesshttps://github.com/byt3bl33d3r/SprayingToolkit10N/AN/A101014912692022-10-17T01:01:57Z2018-09-13T09:52:11Z2397
387* --ntlm-hash --company * --import-cracked *.{0,1000}\s\-\-ntlm\-hash\s\-\-company\s.{0,1000}\s\-\-import\-cracked\s.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z2398
388* --ntlm-hash --export-hashes *.{0,1000}\s\-\-ntlm\-hash\s\-\-export\-hashes\s.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z2399
389* --ntlm-hash --import-ntds *.ntds*.{0,1000}\s\-\-ntlm\-hash\s\-\-import\-ntds\s.{0,1000}\.ntds.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z2400
390* -o sprayed.txt*.{0,1000}\s\-o\ssprayed\.txt.{0,1000}offensive_tool_keywordSharpSpraySharpSpray is a Windows domain password spraying tool written in .NET C#T1110TA0006N/AN/ACredential Accesshttps://github.com/iomoath/SharpSpray10N/AN/A102130212021-11-25T19:13:56Z2021-08-31T16:09:45Z2419
391* o365_enum_activesync.py*.{0,1000}\so365_enum_activesync\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2421
392* o365_enum_office.py*.{0,1000}\so365_enum_office\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2422
393* o365_enum_onedrive.py*.{0,1000}\so365_enum_onedrive\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2423
394* o365_spray_activesync.py*.{0,1000}\so365_spray_activesync\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2424
395* o365_spray_adfs.py*.{0,1000}\so365_spray_adfs\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2425
396* o365_spray_msol.py*.{0,1000}\so365_spray_msol\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2426
397* o365spray.py*.{0,1000}\so365spray\.py.{0,1000}offensive_tool_keywordo365sprayUsername enumeration and password spraying tool aimed at Microsoft O365T1110.003 - T1087.002TA0007 - TA0006N/AN/ACredential Accesshttps://github.com/0xZDH/o365spray10N/AN/A898461002024-11-06T00:49:23Z2019-08-07T14:47:45Z2427
398* -oA icebreaker-scan*.{0,1000}\s\-oA\sicebreaker\-scan.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker10N/AN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z2428
399* OfflineSamTool.h*.{0,1000}\sOfflineSamTool\.h.{0,1000}greyware_tool_keywordosetOffline SAM Editor Tool to access and edit SAM databases from offline OS diskT1078 - T1003.002 - T1547.001TA0003 - TA0006 - TA0007 - TA0005N/AN/ACredential Accesshttps://x.com/0gtweet/status/181785948344546140610N/AN/A1010N/AN/AN/AN/A2436
400* oh365userfinder.py*.{0,1000}\soh365userfinder\.py.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z2437
401* omnispray.py*.{0,1000}\somnispray\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2440
402* --outpath * --config *.json --backdoor*.{0,1000}\s\-\-outpath\s.{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-backdoor.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z2468
403* --outpath *.json --backdoor*.{0,1000}\s\-\-outpath\s.{0,1000}\.json\s\-\-backdoor.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z2469
404* owa * --user-as-pass *.{0,1000}\sowa\s.{0,1000}\s\-\-user\-as\-pass\s.{0,1000}offensive_tool_keywordSprayingToolkitScripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficientT1110 - T1078 - T1133 - T1061 - T1621TA0001 - TA0002 - TA0003N/AN/ACredential Accesshttps://github.com/byt3bl33d3r/SprayingToolkit10N/AN/A101014912692022-10-17T01:01:57Z2018-09-13T09:52:11Z2473
405* owa_enum_activesync.py*.{0,1000}\sowa_enum_activesync\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2474
406* owa_spray_activesync.py*.{0,1000}\sowa_spray_activesync\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2475
407* owa-sprayed-creds.txt*.{0,1000}\sowa\-sprayed\-creds\.txt.{0,1000}offensive_tool_keywordEASSniperEASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)T1110 - T1078.003 - T1087.002 - T1059.001TA0006 -TA0007 - TA0009 - TA0002 - TA0001N/AN/ACredential Accesshttps://github.com/fugawi/EASSniper10N/AN/A101542018-04-17T23:23:31Z2018-04-17T22:43:51Z2476
408* -p pwd1.list pwd2.list *.{0,1000}\s\-p\spwd1\.list\spwd2\.list\s.{0,1000}offensive_tool_keywordcheetaha very fast brute force webshell password toolT1110 - T1190 - T1505.003TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/shmilylty/cheetah10N/AN/A1076301502023-04-17T01:33:52Z2017-04-15T20:03:50Z2492
409* paloalto_enum_globalprotectportal.py*.{0,1000}\spaloalto_enum_globalprotectportal\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2508
410* paloalto_spray_globalprotectportal.py*.{0,1000}\spaloalto_spray_globalprotectportal\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z2509
411* pamspy_event.h*.{0,1000}\spamspy_event\.h.{0,1000}offensive_tool_keywordpamspyCredentials Dumper for Linux using eBPFT1003.001TA0006N/AN/ACredential Accesshttps://github.com/citronneur/pamspy10#linuxN/A10101135632024-09-09T13:19:12Z2022-07-01T19:33:43Z2510
412* PassSpray.ps1*.{0,1000}\sPassSpray\.ps1.{0,1000}offensive_tool_keywordPassSprayDomain Password SprayT1110.003 - T1078TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/Leo4j/PassSpray10N/AN/A101732025-02-20T10:07:43Z2023-11-16T13:35:49Z2526
413* --password wordlists/*.txt*.{0,1000}\s\-\-password\swordlists\/.{0,1000}\.txt.{0,1000}offensive_tool_keywordlegbaA multiprotocol credentials bruteforcer / password sprayer and enumeratorT1110 - T1110.003 - T1110.001TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/evilsocket/legba10N/AN/A10101577932025-03-01T15:42:29Z2023-10-23T15:44:06Z2528
414* password.lst*.{0,1000}\spassword\.lst.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z2529
415* --password-list *.{0,1000}\s\-\-password\-list\s.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker10N/AN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z2532
416* --passwordsperdelay *.{0,1000}\s\-\-passwordsperdelay\s.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z2535
417* passwordspray -d *.{0,1000}\spasswordspray\s\-d\s.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute10N/AN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z2537
418* --passwords-to-users *hash*.{0,1000}\s\-\-passwords\-to\-users\s.{0,1000}hash.{0,1000}offensive_tool_keywordautoNTDSautoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcatT1003 - T1059 - T1021.002 - T1213TA0006 - TA0008 - TA0005 - TA0002N/AN/ACredential Accesshttps://github.com/hmaverickadams/autoNTDS10N/AN/A102109142023-10-31T22:03:58Z2023-10-30T23:10:58Z2538
419* -PathToDMP *.dmp*.{0,1000}\s\-PathToDMP\s.{0,1000}\.dmp.{0,1000}offensive_tool_keywordpowerextractThis tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS processT1003 - T1055 - T1003.001 - T1055.012TA0007 - TA0002N/AN/ACredential Accesshttps://github.com/powerseb/PowerExtract10N/AN/AN/A2117142025-03-28T10:49:43Z2021-12-11T15:24:44Z2546
420* physmem2minidump.py*.{0,1000}\sphysmem2minidump\.py.{0,1000}offensive_tool_keywordphysmem2profitPhysmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotelyT1003.001TA0006N/AN/ACredential Accesshttps://github.com/WithSecureLabs/physmem2profit10N/AN/A105415742022-07-27T03:33:59Z2020-02-14T08:34:27Z2603
421* Pictures\Screenshots\loot.zip*.{0,1000}\sPictures\\Screenshots\\loot\.zip.{0,1000}offensive_tool_keywordHarvester_OF_SORROWThe payload opens firefox about:logins and tabs and arrows its way through options. It then takes a screen shot with the first set of log in credentials made visible. Finally it sends the screenshot to an email of your choosing.T1056.001 - T1113 - T1512 - T1566.001 - T1059.006TA0004 - TA0009 - TA0010 - TA0040N/AN/ACredential Accesshttps://github.com/hak5/omg-payloads/blob/master/payloads/library/credentials/Harvester_OF_SORROW/payload.txt10N/AN/A10109043102024-09-14T02:34:26Z2021-09-08T20:33:18Z2605
422* --plugin gmailenum*.{0,1000}\s\-\-plugin\sgmailenum.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z2616
423* --plugin httpbrute --url *.{0,1000}\s\-\-plugin\shttpbrute\s\-\-url\s.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z2617
424* --plugin httpbrute*.{0,1000}\s\-\-plugin\shttpbrute.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z2618
425* --plugin KeeFarceRebornPlugin.dll*.{0,1000}\s\-\-plugin\sKeeFarceRebornPlugin\.dll.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn10N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z2620
426* --plugin o365enum*.{0,1000}\s\-\-plugin\so365enum.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z2621
427* PostDump.exe*.{0,1000}\sPostDump\.exe.{0,1000}offensive_tool_keywordPOSTDumpperform minidump of LSASS process using few technics to avoid detectionT1003TA0006N/ABlack BastaCredential Accesshttps://github.com/YOLOP0wn/POSTDump10N/AN/A104327372025-02-05T15:24:52Z2023-09-13T11:28:51Z2645
428* PPLmedic.exe*.{0,1000}\sPPLmedic\.exe.{0,1000}offensive_tool_keywordPPLmedicDump the memory of any PPL with a Userland exploit chainT1003 - T1055 - T1564.001TA0005 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/itm4n/PPLmedic10N/AN/A84333362023-03-17T15:58:24Z2023-03-10T12:07:01Z2658
429* Pre2kSpray.ps1*.{0,1000}\sPre2kSpray\.ps1.{0,1000}offensive_tool_keywordInvoke-Pre2kSprayEnumerate domain machine accounts and perform pre2k password spraying.T1087.002 - T1110.003TA0007 - TA0006N/AN/ACredential Accesshttps://github.com/eversinc33/Invoke-Pre2kSpray10N/AN/A8169112023-07-14T06:50:22Z2023-07-05T10:07:38Z2660
430* preauthscan /users:*.{0,1000}\spreauthscan\s\/users\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z2661
431* PrintCreds.py*.{0,1000}\sPrintCreds\.py.{0,1000}offensive_tool_keywordspraykatzSpraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008TA0003 - TA0004 - TA0007N/AN/ACredential Accesshttps://github.com/aas-n/spraykatz10N/AN/A987631212020-06-20T12:14:00Z2019-09-09T14:38:28Z2667
432* ps /target:*.xml /unprotect*.{0,1000}\sps\s\/target\:.{0,1000}\.xml\s\/unprotect.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z2685
433* ptt /ticket:*.{0,1000}\sptt\s\/ticket\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z2698
434* pwcrack.sh*.{0,1000}\spwcrack\.sh.{0,1000}offensive_tool_keywordnsa-rulesPassword cracking rules and masks for hashcat that I generated from cracked passwords.T1110.002 - T1021.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/NSAKEY/nsa-rules10N/AN/A1065471252017-01-03T11:53:25Z2016-02-15T20:49:32Z2723
435* pwcrack-framework*.{0,1000}\spwcrack\-framework.{0,1000}offensive_tool_keywordpwcrack-frameworkPassword Crack FrameworkT1110 - T1003 - T1059TA0006N/AN/ACredential Accesshttps://github.com/L-codes/pwcrack-framework10N/AN/A106515592024-02-25T13:08:56Z2018-07-01T08:33:55Z2724
436* pwdump.py*.{0,1000}\spwdump\.py.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump710N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z2725
437* PWDumpX process *.{0,1000}\sPWDumpX\sprocess\s.{0,1000}offensive_tool_keywordPWDumpXPWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.T1003.001 - T1555.003 - T1077TA0006 - TA0008N/AN/ACredential Accesshttps://packetstormsecurity.com/files/download/52580/PWDumpX.zip10#contentN/A108N/AN/AN/AN/A2728
438* PWDumpX service *.{0,1000}\sPWDumpX\sservice\s.{0,1000}offensive_tool_keywordPWDumpXPWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.T1003.001 - T1555.003 - T1077TA0006 - TA0008N/AN/ACredential Accesshttps://packetstormsecurity.com/files/download/52580/PWDumpX.zip10#contentN/A108N/AN/AN/AN/A2729
439* Pwn3d!*.{0,1000}\sPwn3d!.{0,1000}offensive_tool_keywordcrackmapexecA swiss army knife for pentesting networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2733
440* pyLAPS.py*.{0,1000}\spyLAPS\.py.{0,1000}offensive_tool_keywordpyLAPSA simple way to read and write LAPS passwords from linux.T1136.001 - T1112 - T1078.001TA0002 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/p0dalirius/pyLAPS10#linuxN/A92105162024-10-28T08:36:38Z2021-10-05T18:35:21Z2739
441* -r airolib-db /root/wpa.cap*.{0,1000}\s\-r\sairolib\-db\s\/root\/wpa\.cap.{0,1000}offensive_tool_keywordaircrackcracking Wi-Fi security including WEP and WPA/WPA2-PSK encryptionT1078 - T1496 - T1040TA0006 - TA0008 - TA0005N/AN/ACredential Accesshttps://github.com/aircrack-ng/aircrack-ng10N/AN/A510596710322024-12-19T21:36:56Z2018-03-10T17:11:11Z2754
442* RagingRotator.go*.{0,1000}\sRagingRotator\.go.{0,1000}offensive_tool_keywordRagingRotatorA tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.T1110 - T1027 - T1071 - T1090 - T1621TA0006 - TA0005 - TA0001N/AN/ACredential Accesshttps://github.com/nickzer0/RagingRotator10N/AN/A1017972024-06-06T19:31:34Z2023-09-01T15:19:38Z2761
443* --random_user_agent*.{0,1000}\s\-\-random_user_agent.{0,1000}offensive_tool_keywordSpray365Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).T1110.003TA0006N/AN/ACredential Accesshttps://github.com/MarkoH17/Spray36510N/AN/AN/A4348582022-07-14T14:45:57Z2021-11-04T18:20:39Z2764
444* rawrpc_embedded.py*.{0,1000}\srawrpc_embedded\.py.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z2776
445* --rdcman-poison-hkcr*.{0,1000}\s\-\-rdcman\-poison\-hkcr.{0,1000}offensive_tool_keywordThievingFoxcollection of post-exploitation tools to gather credentials from various password managersT1555 - T1003 - T1056 - T1070TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Slowerzs/ThievingFox10N/AN/A106535652024-03-28T19:58:03Z2024-01-20T23:22:52Z2781
446* RDPHook.dll*.{0,1000}\sRDPHook\.dll.{0,1000}offensive_tool_keywordSharpRDPThiefA C# implementation of RDPThief to steal credentials from RDPT1056.004 - T1110 - T1563.002TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/passthehashbrowns/SharpRDPThief10N/AN/A102160282020-08-28T03:48:51Z2020-08-26T22:27:36Z2789
447* RdpThief.dll*.{0,1000}\sRdpThief\.dll.{0,1000}offensive_tool_keywordInvoke-RDPThiefperform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentialsT1055 - T1056 - T1071 - T1110TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/The-Viper-One/Invoke-RDPThief10N/AN/A1016282025-01-21T20:12:33Z2024-10-01T20:12:00Z2791
448* rdpv.exe*.{0,1000}\srdpv\.exe.{0,1000}offensive_tool_keywordrdpvRemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files.T1110 - T1560.001 - T1555.003 - T1212TA0006 - TA0007N/APhobos - GoGoogle - KimsukyCredential Accesshttps://www.nirsoft.net/utils/remote_desktop_password.html10N/AN/A810N/AN/AN/AN/A2792
449* -Remote -ExchHostname *.{0,1000}\s\-Remote\s\-ExchHostname\s.{0,1000}offensive_tool_keywordMailSniperMailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.T1087.003 - T1110.003 - T1114.002TA0006 -TA0009 -TA0007N/ALeafminerCredential Accesshttps://github.com/dafthack/MailSniper/blob/master/MailSniper.ps110N/AN/AN/A1030465802024-08-07T18:11:58Z2016-09-08T00:36:51Z2829
450* renew *.kirbi*.{0,1000}\srenew\s.{0,1000}\.kirbi.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z2858
451* renew */ticket:*.{0,1000}\srenew\s.{0,1000}\/ticket\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z2859
452* --RestoreShadowCred*.{0,1000}\s\-\-RestoreShadowCred.{0,1000}offensive_tool_keywordShadowSprayA tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.T1556.005 - T1098.001 - T1098TA0006 - TA0008 - TA0004N/ABlack BastaCredential Accesshttps://github.com/Dec0ne/ShadowSpray10N/AN/A105459802022-10-14T13:36:51Z2022-10-10T08:34:07Z2872
453* restoresig.py*.{0,1000}\srestoresig\.py.{0,1000}offensive_tool_keywordLetMeowInA sophisticated covert Windows-based credential dumper using C++ and MASM x64.T1003 - T1055.011 - T1148TA0006N/AN/ACredential Accesshttps://github.com/Meowmycks/LetMeowIn10N/AN/A105401702024-07-08T15:58:37Z2024-04-09T16:33:27Z2873
454* revshell32.bin*.{0,1000}\srevshell32\.bin.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z2889
455* revshell64.bin*.{0,1000}\srevshell64\.bin.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z2890
456* --rid-brute*.{0,1000}\s\-\-rid\-brute.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z2902
457* rockyou.txt *.{0,1000}\srockyou\.txt\s.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z2913
458* rpcdump.py*.{0,1000}\srpcdump\.py.{0,1000}offensive_tool_keywordNetNTLMtoSilverTicketObtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.T1110.001 - T1558.003 - T1558.004TA0006 - TA0008 - TA0002N/AN/ACredential Accesshttps://github.com/NotMedic/NetNTLMtoSilverTicket10N/AN/A1098421132021-07-26T15:16:20Z2019-01-14T15:32:27Z2924
459* Rubeus.dll*.{0,1000}\sRubeus\.dll.{0,1000}offensive_tool_keywordRubeusRun Rubeus via Rundll32 (potential application whitelisting bypass technique)T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004TA0005 - TA0002 - TA0006 - TA0008 - TA0009N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/rvrsh3ll/Rubeus-Rundll3210N/AN/A103200322020-04-25T19:55:27Z2020-04-24T20:35:38Z2942
460* Rubeus.ps1*.{0,1000}\sRubeus\.ps1.{0,1000}offensive_tool_keywordRubeusRun Rubeus via Rundll32 (potential application whitelisting bypass technique)T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004TA0005 - TA0002 - TA0006 - TA0008 - TA0009N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/rvrsh3ll/Rubeus-Rundll3210N/AN/A103200322020-04-25T19:55:27Z2020-04-24T20:35:38Z2943
461* --rules:Jumbo *.{0,1000}\s\-\-rules\:Jumbo\s.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z2945
462* run donpapi*.{0,1000}\srun\sdonpapi.{0,1000}offensive_tool_keyworddonpapiDumping DPAPI credentials remotelyT1003.006 - T1021.001TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/login-securite/DonPAPI10N/AN/AN/A1011101302025-03-24T10:23:58Z2021-09-27T09:12:51Z2946
463* s4u * /bronzebit*.{0,1000}\ss4u\s.{0,1000}\s\/bronzebit.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z2971
464* s4u * /nopac*.{0,1000}\ss4u\s.{0,1000}\s\/nopac.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z2972
465* s4u * /ticket:*.{0,1000}\ss4u\s.{0,1000}\s\/ticket\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z2973
466* s4u *.kirbi*.{0,1000}\ss4u\s.{0,1000}\.kirbi.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z2974
467* s4u */rc4:* .{0,1000}\ss4u\s.{0,1000}\/rc4\:.{0,1000}\soffensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z2975
468* sam_reset_all_pw(*.{0,1000}\ssam_reset_all_pw\(.{0,1000}offensive_tool_keywordchntpwreset a password on your systemT1003 - T1078TA0006N/AN/ACredential Accesshttps://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip10N/AN/A1010N/AN/AN/AN/A2978
469* scan --github-org*.{0,1000}\sscan\s\-\-github\-org.{0,1000}offensive_tool_keywordnoseyparkerNosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.T1583 - T1059.001 - T1059.003TA0002 - TA0003 - TA0040N/AN/ACredential Accesshttps://github.com/praetorian-inc/noseyparker10N/AN/A81019031002025-03-07T20:15:34Z2022-11-08T23:09:17Z2989
470* scan --github-user*.{0,1000}\sscan\s\-\-github\-user.{0,1000}offensive_tool_keywordnoseyparkerNosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.T1583 - T1059.001 - T1059.003TA0002 - TA0003 - TA0040N/AN/ACredential Accesshttps://github.com/praetorian-inc/noseyparker10N/AN/A81019031002025-03-07T20:15:34Z2022-11-08T23:09:17Z2990
471* --script smb-security-mode*smb-enum-shares *.{0,1000}\s\-\-script\ssmb\-security\-mode.{0,1000}smb\-enum\-shares\s.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker10N/AN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z3009
472* --seclogon-duplicate*.{0,1000}\s\-\-seclogon\-duplicate.{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump10N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z3028
473* --secrets-dump -target *.{0,1000}\s\-\-secrets\-dump\s\-target\s.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z3030
474* secretsdump.py*.{0,1000}\ssecretsdump\.py.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z3031
475* SecretStealer.ps1*.{0,1000}\sSecretStealer\.ps1.{0,1000}offensive_tool_keywordSecretServerSecretStealerPowershell script that decrypts the data stored within a Thycotic Secret ServerT1552 - T1027 - T1059TA0006N/AEvilCorp*Credential Accesshttps://github.com/denandz/SecretServerSecretStealer10N/AN/A10178142020-08-03T06:52:27Z2017-04-21T04:06:24Z3034
476* --session=allrules --wordlist*.{0,1000}\s\-\-session\=allrules\s\-\-wordlist.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z3054
477* SessionGopher.ps1*.{0,1000}\sSessionGopher\.ps1.{0,1000}offensive_tool_keywordSessionGopheruses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.T1047 - T1003.008 - T1552.004 - T1555.003TA0006N/APYSA - DarkSide - SphinxCredential Accesshttps://github.com/Arvanaghi/SessionGopher10N/AN/A101012551732022-11-22T21:33:23Z2017-03-08T02:49:32Z3056
478* SharpHose.exe*.{0,1000}\sSharpHose\.exe.{0,1000}offensive_tool_keywordSharpHoseAsynchronous Password Spraying Tool in C# for Windows EnvironmentsT1110.003TA0006N/AN/ACredential Accesshttps://github.com/ustayready/SharpHose10N/AN/A104312622023-12-19T21:06:47Z2020-05-01T22:10:49Z3089
479* sharpspray.exe*.{0,1000}\ssharpspray\.exe.{0,1000}offensive_tool_keywordSharpSpraySharpSpray is a Windows domain password spraying tool written in .NET C#T1110TA0006N/AN/ACredential Accesshttps://github.com/iomoath/SharpSpray10N/AN/A102130212021-11-25T19:13:56Z2021-08-31T16:09:45Z3099
480* --show passwd*.{0,1000}\s\-\-show\spasswd.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10#linuxN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z3120
481* --show_invalid_creds*.{0,1000}\s\-\-show_invalid_creds.{0,1000}offensive_tool_keywordSpray365Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).T1110.003TA0006N/AN/ACredential Accesshttps://github.com/MarkoH17/Spray36510N/AN/AN/A4348582022-07-14T14:45:57Z2021-11-04T18:20:39Z3121
482* --shtinkering*.{0,1000}\s\-\-shtinkering.{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump10N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z3122
483* --shuffle-users* --spray*.{0,1000}\s\-\-shuffle\-users.{0,1000}\s\-\-spray.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z3123
484* sigthief.py*.{0,1000}\ssigthief\.py.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber10N/AN/A10N/A3133
485* --silent-process-exit *.{0,1000}\s\-\-silent\-process\-exit\s.{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump10N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z3136
486* silver * /domain*.{0,1000}\ssilver\s.{0,1000}\s\/domain.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z3138
487* silver * /ldap *.{0,1000}\ssilver\s.{0,1000}\s\/ldap\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z3139
488* silver * /passlastset *.{0,1000}\ssilver\s.{0,1000}\s\/passlastset\s.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z3140
489* silver * /service:*.{0,1000}\ssilver\s.{0,1000}\s\/service\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z3141
490* --single shadow.hashes*.{0,1000}\s\-\-single\sshadow\.hashes.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z3143
491* smb client * shares *use c$*.{0,1000}\ssmb\sclient\s.{0,1000}\sshares\s.{0,1000}use\sc\$.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z3199
492* smb -M mimikatz --options*.{0,1000}\ssmb\s\-M\smimikatz\s\-\-options.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3200
493* smb shareenum *smb2+ntlm-password*.{0,1000}\ssmb\sshareenum\s.{0,1000}smb2\+ntlm\-password.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z3201
494* smb* -u '' -p ''*.{0,1000}\ssmb.{0,1000}\s\-u\s\'\'\s\-p\s\'\'.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3203
495* smb-cmds.txt*.{0,1000}\ssmb\-cmds\.txt.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker10N/AN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z3212
496* smbexec.py*.{0,1000}\ssmbexec\.py.{0,1000}offensive_tool_keywordcrackmapexecprotocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3221
497* smbrelayserver.py*.{0,1000}\ssmbrelayserver\.py.{0,1000}offensive_tool_keywordNtlmRelayToEWSntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)T1212 - T1557 - T1040 - T1078TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/Arno0x/NtlmRelayToEWS10N/AN/A104331602018-01-15T12:48:02Z2017-10-13T18:00:50Z3233
498* Snake.sh *.{0,1000}\/Snake\.sh.{0,1000}offensive_tool_keywordSSH-SnakeSSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discoveryT1021.004 - T1027 - T1552.004TA0002 - TA0005 - TA0006N/AN/ACredential Accesshttps://github.com/MegaManSec/SSH-Snake10#linuxN/A101020651982024-07-25T09:32:07Z2023-12-03T04:52:38Z3272
499* Snake.sh*.{0,1000}\sSnake\.sh.{0,1000}offensive_tool_keywordSSH-SnakeSSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discoveryT1021.004 - T1027 - T1552.004TA0002 - TA0005 - TA0006N/AN/ACredential Accesshttps://github.com/MegaManSec/SSH-Snake10N/AN/A101020651982024-07-25T09:32:07Z2023-12-03T04:52:38Z3273
500* SocialBox.sh*.{0,1000}\sSocialBox\.sh.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/samsesh/SocialBox-Termux10N/AN/A71035813912024-09-02T19:15:22Z2019-03-28T18:07:05Z3291
501* --spray *--shuffle-users*.{0,1000}\s\-\-spray\s.{0,1000}\-\-shuffle\-users.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z3320
502* spray -ep ex-plan.s365*.{0,1000}\sspray\s\-ep\sex\-plan\.s365.{0,1000}offensive_tool_keywordSpray365Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).T1110.003TA0006N/AN/ACredential Accesshttps://github.com/MarkoH17/Spray36510N/AN/AN/A4348582022-07-14T14:45:57Z2021-11-04T18:20:39Z3321
503* --spray --passwords *.{0,1000}\s\-\-spray\s\-\-passwords\s.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z3322
504* --spray --push-locked --months-only --exclude *.{0,1000}\s\-\-spray\s\-\-push\-locked\s\-\-months\-only\s\-\-exclude\s.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z3323
505* --spray --push-locked --months-only*.{0,1000}\s\-\-spray\s\-\-push\-locked\s\-\-months\-only.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z3324
506* spray -u * -H * -p * -m owa*.{0,1000}\sspray\s\-u\s.{0,1000}\s\-H\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sowa.{0,1000}offensive_tool_keywordspraycharlesLow and slow password spraying toolT1110.003 - T1110.001TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Tw1sm/spraycharles10N/AN/A102195322025-02-09T03:08:09Z2018-09-17T11:17:47Z3325
507* spray -u * -p * -m Office365*.{0,1000}\sspray\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sOffice365.{0,1000}offensive_tool_keywordspraycharlesLow and slow password spraying toolT1110.003 - T1110.001TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Tw1sm/spraycharles10N/AN/A102195322025-02-09T03:08:09Z2018-09-17T11:17:47Z3326
508* spray -u * -p * -m Smb -H *.{0,1000}\sspray\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sSmb\s\-H\s.{0,1000}offensive_tool_keywordspraycharlesLow and slow password spraying toolT1110.003 - T1110.001TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Tw1sm/spraycharles10N/AN/A102195322025-02-09T03:08:09Z2018-09-17T11:17:47Z3327
509* spraycharles.py*.{0,1000}\sspraycharles\.py.{0,1000}offensive_tool_keywordspraycharlesLow and slow password spraying toolT1110.003 - T1110.001TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Tw1sm/spraycharles10N/AN/A102195322025-02-09T03:08:09Z2018-09-17T11:17:47Z3328
510* SprayLove.py*.{0,1000}\sSprayLove\.py.{0,1000}offensive_tool_keywordspraykatzSpraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008TA0003 - TA0004 - TA0007N/AN/ACredential Accesshttps://github.com/aas-n/spraykatz10N/AN/A987631212020-06-20T12:14:00Z2019-09-09T14:38:28Z3329
511* --spraypassword *.{0,1000}\s\-\-spraypassword\s.{0,1000}offensive_tool_keywordSharpHoseAsynchronous Password Spraying Tool in C# for Windows EnvironmentsT1110.003TA0006N/AN/ACredential Accesshttps://github.com/ustayready/SharpHose10N/AN/A104312622023-12-19T21:06:47Z2020-05-01T22:10:49Z3330
512* SQLDmpr0001.mdmp*.{0,1000}\sSQLDmpr0001\.mdmp.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z3335
513* Starting pre2k spray against *.{0,1000}\sStarting\spre2k\sspray\sagainst\s.{0,1000}offensive_tool_keywordInvoke-Pre2kSprayEnumerate domain machine accounts and perform pre2k password spraying.T1087.002 - T1110.003TA0007 - TA0006N/AN/ACredential Accesshttps://github.com/eversinc33/Invoke-Pre2kSpray10#contentN/A8169112023-07-14T06:50:22Z2023-07-05T10:07:38Z3398
514* Successfully hijacked KeePassXC.exe*.{0,1000}\sSuccessfully\shijacked\sKeePassXC\.exe.{0,1000}offensive_tool_keywordThievingFoxcollection of post-exploitation tools to gather credentials from various password managersT1555 - T1003 - T1056 - T1070TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Slowerzs/ThievingFox10N/AN/A106535652024-03-28T19:58:03Z2024-01-20T23:22:52Z3428
515* SW2_HashSyscall*.{0,1000}\sSW2_HashSyscall.{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump10N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z3435
516* -system * -ntds *ntds.dit*.{0,1000}\s\-system\s.{0,1000}\s\-ntds\s.{0,1000}ntds\.dit.{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump10N/AN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z3441
517* -t *https://autodiscover.*/autodiscover/autodiscover.xml*autodiscover*.{0,1000}\s\-t\s.{0,1000}https\:\/\/autodiscover\..{0,1000}\/autodiscover\/autodiscover\.xml.{0,1000}autodiscover.{0,1000}offensive_tool_keywordadfsprayPython3 tool to perform password spraying against Microsoft Online service using various methodsT1110.003TA0006N/AN/ACredential Accesshttps://github.com/xFreed0m/ADFSpray10N/AN/AN/A187142023-03-12T00:21:34Z2020-04-23T08:56:51Z3447
518* -target-ip * -remote-dll *.dll* -local-dll *.{0,1000}\s\-target\-ip\s.{0,1000}\s\-remote\-dll\s.{0,1000}\.dll.{0,1000}\s\-local\-dll\s.{0,1000}offensive_tool_keywordDragonCastleA PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.T1003 - T1547.005 - T1055 - T1557TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/mdsecactivebreach/DragonCastle10N/AN/A103298382022-10-26T10:19:55Z2022-10-26T10:18:37Z3468
519* --target-user * --dc-ip * -command *.{0,1000}\s\-\-target\-user\s.{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-command\s.{0,1000}offensive_tool_keywordwhiskeysamlandfriendsGoldenSAML Attack Libraries and FrameworkT1606.002TA0006N/AN/ACredential Accesshttps://github.com/secureworks/whiskeysamlandfriends10N/AN/AN/A17292024-06-05T14:56:28Z2021-11-04T15:30:12Z3483
520* TeamFiltration.dll*.{0,1000}\sTeamFiltration\.dll.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z3490
521* TeamFiltration.exe*.{0,1000}\sTeamFiltration\.exe.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z3491
522* teams_dump.py*.{0,1000}\steams_dump\.py.{0,1000}offensive_tool_keywordteams_dumpPoC for dumping and decrypting cookies in the latest version of Microsoft TeamsT1560.001 - T1555.003 - T1113 - T1557TA0006 - TA0005 - TA0009N/AN/ACredential Accesshttps://github.com/byinarie/teams_dump10N/AN/A72132192023-11-12T18:47:55Z2023-09-18T18:33:32Z3492
523* teams_dump.py*.{0,1000}\steams_dump\.py.{0,1000}offensive_tool_keywordteams_dumpPoC for dumping and decrypting cookies in the latest version of Microsoft TeamsT1555 - T1003 - T1114TA0006 - TA0005 - TA0009N/AN/ACredential Accesshttps://github.com/byinarie/teams_dump10N/AN/A92132192023-11-12T18:47:55Z2023-09-18T18:33:32Z3493
524* tgssub * /ticket:*.{0,1000}\stgssub\s.{0,1000}\s\/ticket\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z3506
525* tgtdeleg /nowrap*.{0,1000}\stgtdeleg\s\/nowrap.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z3508
526* tgtdeleg /target:*.{0,1000}\stgtdeleg\s\/target\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z3510
527* thc-hidra*.{0,1000}\sthc\-hidra.{0,1000}offensive_tool_keywordthc-hydraParallelized login cracker which supports numerous protocols to attack.T1110.001TA0006N/AALLANITE - BERSERK BEARCredential Accesshttps://github.com/vanhauser-thc/thc-hydra10#linuxN/AN/A101032621372025-04-04T12:19:05Z2014-04-24T14:45:37Z3511
528* ThievingFox.py*.{0,1000}\sThievingFox\.py.{0,1000}offensive_tool_keywordThievingFoxcollection of post-exploitation tools to gather credentials from various password managersT1555 - T1003 - T1056 - T1070TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Slowerzs/ThievingFox10N/AN/A106535652024-03-28T19:58:03Z2024-01-20T23:22:52Z3517
529* ticket_converter.py*.{0,1000}\sticket_converter\.py.{0,1000}offensive_tool_keywordticket_converterA little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.T1558.003 - T1110.004TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/zer1t0/ticket_converter10N/AN/A102167312022-06-16T19:38:05Z2019-05-14T04:48:19Z3519
530* ticketsplease.*.{0,1000}\sticketsplease\..{0,1000}offensive_tool_keywordwhiskeysamlandfriendsGoldenSAML Attack Libraries and FrameworkT1606.002TA0006N/AN/ACredential Accesshttps://github.com/secureworks/whiskeysamlandfriends10N/AN/AN/A17292024-06-05T14:56:28Z2021-11-04T15:30:12Z3521
531* TokenFinder.py*.{0,1000}\sTokenFinder\.py.{0,1000}offensive_tool_keywordTokenFinderTool to extract powerful tokens from Office desktop apps memoryT1003 - T1081 - T1110TA0006 - TA0008 - TA0009N/AN/ACredential Accesshttps://github.com/doredry/TokenFinder10N/AN/A9171102024-03-01T14:27:34Z2022-09-21T14:21:07Z3533
532* TokenUniverse.zip*.{0,1000}\sTokenUniverse\.zip.{0,1000}offensive_tool_keywordTokenUniverseAn advanced tool for working with access tokens and Windows security policy.T1134 - T1055 - T1056 - T1222 - T1484TA0004 - TA0005 - TA0006N/AN/ACredential Accesshttps://github.com/diversenok/TokenUniverse10N/AN/A86597662024-07-20T03:18:21Z2018-06-22T21:02:16Z3537
533* --tor_password *.{0,1000}\s\-\-tor_password\s.{0,1000}offensive_tool_keywordadfsbrutetest credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacksT1110.003 - T1110.001 - T1110TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/ricardojoserf/adfsbrute10N/AN/A82172332021-04-23T16:43:59Z2020-10-02T16:28:35Z3543
534* tweetshell.sh*.{0,1000}\stweetshell\.sh.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/samsesh/SocialBox-Termux10N/AN/A71035813912024-09-02T19:15:22Z2019-03-28T18:07:05Z3575
535* --type enum -uf * --module o365_enum_office*.{0,1000}\s\-\-type\senum\s\-uf\s.{0,1000}\s\-\-module\so365_enum_office.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z3577
536* --type spray -uf * -pf *.{0,1000}\s\-\-type\sspray\s\-uf\s.{0,1000}\s\-pf\s.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z3582
537* -u * -d * --dc-ip * -k --no-pass --target * --action "list"*.{0,1000}\s\-u\s.{0,1000}\s\-d\s.{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-k\s\-\-no\-pass\s\-\-target\s.{0,1000}\s\-\-action\s\"list\".{0,1000}offensive_tool_keywordpywhiskerPython version of the C# tool for Shadow Credentials attacksT1552.001 - T1136 - T1098TA0003 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/ShutdownRepo/pywhisker10N/AN/A108712892025-04-21T16:53:22Z2021-07-21T19:20:00Z3586
538* -u * --local-auth*.{0,1000}\s\-u\s.{0,1000}\s\-\-local\-auth.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3587
539* -u * -p * --lusers*.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-lusers.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3588
540* -u * -p * --sam.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-samoffensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3592
541* -u * -p * --shares*.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-shares.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3593
542* -u * -p *--pass-pol*.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\-\-pass\-pol.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3594
543* -u wordlist * wordlist_uniq_sorted*.{0,1000}\s\-u\swordlist\s.{0,1000}\swordlist_uniq_sorted.{0,1000}offensive_tool_keywordwordlistsVarious wordlists FR & EN - Cracking French passwordsT1110.001TA0006N/AN/ACredential Accesshttps://github.com/clem9669/wordlists10N/AN/AN/A3280452025-04-22T14:34:10Z2020-10-21T14:37:53Z3602
544* -user * --passwordlist *.{0,1000}\s\-user\s.{0,1000}\s\-\-passwordlist\s.{0,1000}offensive_tool_keywordadfsprayPython3 tool to perform password spraying against Microsoft Online service using various methodsT1110.003TA0006N/AN/ACredential Accesshttps://github.com/xFreed0m/ADFSpray10N/AN/AN/A187142023-03-12T00:21:34Z2020-04-23T08:56:51Z3636
545* -user userlist.txt -pass passwordlist.txt *.{0,1000}\s\-user\suserlist\.txt\s\-pass\spasswordlist\.txt\s.{0,1000}offensive_tool_keywordMSSprinklerpassword spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approachT1110.003 - T1110.001TA0006 - TA0007 - TA0008N/AN/ACredential Accesshttps://github.com/TheresAFewConors/MSSprinkler10N/AN/A917472025-02-25T13:32:41Z2024-09-15T09:54:53Z3639
546* --user-as-pass*.{0,1000}\s\-\-user\-as\-pass.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute10N/AN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z3641
547* userenum -d * *.txt*.{0,1000}\suserenum\s\-d\s.{0,1000}\s.{0,1000}\.txt.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute10N/AN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z3643
548* -UserList * -Domain * -PasswordList * -OutFile *.{0,1000}\s\-UserList\s.{0,1000}\s\-Domain\s.{0,1000}\s\-PasswordList\s.{0,1000}\s\-OutFile\s.{0,1000}offensive_tool_keywordDomainPasswordSprayDomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.T1110.001 - T1110.003TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/dafthack/DomainPasswordSpray10N/AN/A101018653882024-07-11T18:18:57Z2016-10-04T23:37:37Z3645
549* -userpassfile ./userpass_file.txt*.{0,1000}\s\-userpassfile\s\.\/userpass_file\.txt.{0,1000}offensive_tool_keywordRagingRotatorA tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways.T1110 - T1027 - T1071 - T1090 - T1621TA0006 - TA0005 - TA0001N/AN/ACredential Accesshttps://github.com/nickzer0/RagingRotator10#linuxN/A1017972024-06-06T19:31:34Z2023-09-01T15:19:38Z3651
550* --userpassword_list *.{0,1000}\s\-\-userpassword_list\s.{0,1000}offensive_tool_keywordadfsbrutetest credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacksT1110.003 - T1110.001 - T1110TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/ricardojoserf/adfsbrute10N/AN/A82172332021-04-23T16:43:59Z2020-10-02T16:28:35Z3652
551* utils.ntlmdecode *.{0,1000}\sutils\.ntlmdecode\s.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z3656
552* vaporizer.py *.{0,1000}\svaporizer\.py\s.{0,1000}offensive_tool_keywordSprayingToolkitScripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficientT1110 - T1078 - T1133 - T1061 - T1621TA0001 - TA0002 - TA0003N/AN/ACredential Accesshttps://github.com/byt3bl33d3r/SprayingToolkit10N/AN/A101014912692022-10-17T01:01:57Z2018-09-13T09:52:11Z3658
553* vaults /target:* /pvk:*.{0,1000}\svaults\s\/target\:.{0,1000}\s\/pvk\:.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z3661
554* wcreddump (windows credentials dump)*.{0,1000}\swcreddump\s\(windows\scredentials\sdump\).{0,1000}offensive_tool_keywordwcreddumpFully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.T1003 - T1110.001TA0006N/AN/ACredential Accesshttps://github.com/truerustyy/wcreddump10#linux #windows #contentN/A1017552024-11-18T18:37:28Z2024-03-05T00:00:20Z3691
555* wcreddump.py*.{0,1000}\swcreddump\.py.{0,1000}offensive_tool_keywordwcreddumpFully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.T1003 - T1110.001TA0006N/AN/ACredential Accesshttps://github.com/truerustyy/wcreddump10#linux #windowsN/A1017552024-11-18T18:37:28Z2024-03-05T00:00:20Z3692
556* --wdigest disable*.{0,1000}\s\-\-wdigest\sdisable.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3694
557* --wdigest enable*.{0,1000}\s\-\-wdigest\senable.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3695
558* -WebRoot C:\inetpub\wwwroot\SecretServer*.{0,1000}\s\-WebRoot\sC\:\\inetpub\\wwwroot\\SecretServer.{0,1000}offensive_tool_keywordSecretServerSecretStealerPowershell script that decrypts the data stored within a Thycotic Secret ServerT1552 - T1027 - T1059TA0006N/AEvilCorp*Credential Accesshttps://github.com/denandz/SecretServerSecretStealer10N/AN/A10178142020-08-03T06:52:27Z2017-04-21T04:06:24Z3699
559* --weekday-warrior -*.{0,1000}\s\-\-weekday\-warrior\s\-.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z3701
560* --werfault *\temp\*.{0,1000}\s\-\-werfault\s.{0,1000}\\temp\\.{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump10N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z3702
561* Windows-Passwords.ps1*.{0,1000}\sWindows\-Passwords\.ps1.{0,1000}offensive_tool_keywordWLAN-Windows-PasswordsOpens PowerShell hidden - grabs wlan passwords - saves as a cleartext in a variable and exfiltrates info via Discord Webhook.T1056.005 - T1552.001 - T1119 - T1071.001TA0004 - TA0006 - TA0010 - TA0040N/AN/ACredential Accesshttps://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/WLAN-Windows-Passwords10N/AN/A10109043102024-09-14T02:34:26Z2021-09-08T20:33:18Z3723
562* WINHELLO2hashcat.py*.{0,1000}\sWINHELLO2hashcat\.py.{0,1000}offensive_tool_keywordwcreddumpFully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive.T1003 - T1110.001TA0006N/AN/ACredential Accesshttps://github.com/truerustyy/wcreddump10#linux #windowsN/A1017552024-11-18T18:37:28Z2024-03-05T00:00:20Z3725
563* winrm.py*.{0,1000}\swinrm\.py.{0,1000}offensive_tool_keywordcrackmapexecprotocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3734
564* --wmi *SELECT *.{0,1000}\s\-\-wmi\s.{0,1000}SELECT\s.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3740
565* wmiexec.py*.{0,1000}\swmiexec\.py.{0,1000}offensive_tool_keywordcrackmapexecprotocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3743
566* --wmi-namespace 'root\cimv2'*.{0,1000}\s\-\-wmi\-namespace\s\'root\\cimv2\'.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3747
567* --wordlist=*.lst*.{0,1000}\s\-\-wordlist\=.{0,1000}\.lst.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z3750
568* -X '$PSVersionTable' *.{0,1000}\s\-X\s\'\$PSVersionTable\'\s.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3769
569* -X '[System.Environment]::Is64BitProcess'*.{0,1000}\s\-X\s\'\[System\.Environment\]\:\:Is64BitProcess\'.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3771
570* -x -z --get-users-list*.{0,1000}\s\-x\s\-z\s\-\-get\-users\-list.{0,1000}offensive_tool_keywordSharpSpraySharpSpray is a Windows domain password spraying tool written in .NET C#T1110TA0006N/AN/ACredential Accesshttps://github.com/iomoath/SharpSpray10N/AN/A102130212021-11-25T19:13:56Z2021-08-31T16:09:45Z3774
571* -x -z -s 3 -j 1 -u *.txt*.{0,1000}\s\-x\s\-z\s\-s\s3\s\-j\s1\s\-u\s.{0,1000}\.txt.{0,1000}offensive_tool_keywordSharpSpraySharpSpray is a Windows domain password spraying tool written in .NET C#T1110TA0006N/AN/ACredential Accesshttps://github.com/iomoath/SharpSpray10N/AN/A102130212021-11-25T19:13:56Z2021-08-31T16:09:45Z3775
572*!!! Are you sure you are running as the AD FS service account?*.{0,1000}!!!\sAre\syou\ssure\syou\sare\srunning\sas\sthe\sAD\sFS\sservice\saccount\?.{0,1000}offensive_tool_keywordADFSDumpA C# tool to dump all sorts of goodies from AD FST1081 - T1003 - T1114 - T1212TA0006 - TA0005 - TA0009N/AN/ACredential Accesshttps://github.com/mandiant/ADFSDump10N/AN/A104349672023-08-07T16:58:37Z2019-03-20T22:31:16Z3796
573*!process 0 0 lsass.exe*.{0,1000}!process\s0\s0\slsass\.exe.{0,1000}offensive_tool_keywordmimikatzmimikatz stringsT1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003TA0004 - TA0006 - TA0003 - TA0008 - TA0009N/ABlack Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - SphinxCredential Accesshttps://github.com/gentilkiwi/mimikatz10N/AN/A10102009438542024-07-05T17:42:58Z2014-04-06T18:30:02Z3805
574*"A La Vie, A L'Amour" - Windows build *.{0,1000}\"A\sLa\sVie,\sA\sL\'Amour\"\s\-\sWindows\sbuild\s.{0,1000}offensive_tool_keywordmimikatzmimikatz stringsT1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003TA0004 - TA0006 - TA0003 - TA0008 - TA0009N/ABlack Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - SphinxCredential Accesshttps://github.com/gentilkiwi/mimikatz10N/AN/A10102009438542024-07-05T17:42:58Z2014-04-06T18:30:02Z3816
575*"author": "@_EthicalChaos_"*.{0,1000}\"author\"\:\s\"\@_EthicalChaos_\".{0,1000}offensive_tool_keywordShwmaeShwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentialsT1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002TA0006 - TA0005 - TA0003 - TA0004N/AN/ACredential Accesshttps://github.com/CCob/Shwmae10N/AN/A72149122025-01-27T14:36:07Z2024-03-21T15:05:03Z3821
576*"MSGraph token is CAE capable"*.{0,1000}\"MSGraph\stoken\sis\sCAE\scapable\".{0,1000}offensive_tool_keywordTokenTacticsV2fork of the great TokenTactics with support for CAE and token endpoint v2T1134.002 - T1078.004 - T1095TA0005 - TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/f-bader/TokenTacticsV210N/AN/A63282382025-02-25T14:14:25Z2022-08-16T17:00:45Z3854
577*"RdpStrike.cna"*.{0,1000}\"RdpStrike\.cna\".{0,1000}offensive_tool_keywordRdpStrikePositional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBPT1081 - T1055.011 - T1012 - T1113 - T1040 - T1185TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/0xEr3bus/RdpStrike10N/AN/A103238272024-06-11T19:40:05Z2024-06-11T19:31:50Z3862
578*"sacrificialO365Passwords": *.{0,1000}\"sacrificialO365Passwords\"\:\s.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z3864
579*"sacrificialO365Username": *.{0,1000}\"sacrificialO365Username\"\:\s.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z3865
580*"Saved in session, but master password prevents plaintext recovery"*.{0,1000}\"Saved\sin\ssession,\sbut\smaster\spassword\sprevents\splaintext\srecovery\".{0,1000}offensive_tool_keywordSessionGopheruses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.T1047 - T1003.008 - T1552.004 - T1555.003TA0006N/APYSA - DarkSide - SphinxCredential Accesshttps://github.com/Arvanaghi/SessionGopher10#contentN/A101012551732022-11-22T21:33:23Z2017-03-08T02:49:32Z3867
581*"The LaZagne project"*.{0,1000}\"The\sLaZagne\sproject\".{0,1000}offensive_tool_keywordLaZagneThe LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001TA0006 - TA0009N/AAkira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONTCredential Accesshttps://github.com/AlessandroZ/LaZagne10#contentN/A1010994120622025-04-10T14:24:35Z2015-02-16T14:10:02Z3876
582*"User32LogonProcesss"*.{0,1000}User32LogonProcesss.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://x.com/_RastaMouse/status/174763652961319775710N/Atypo in the process name used when calling LsaRegisterLogonProcess1010N/AN/AN/AN/A3879
583*"VeeamBackupCreds"*.{0,1000}\"VeeamBackupCreds\".{0,1000}offensive_tool_keywordSharpVeeamDecryptorDecrypt Veeam database passwordsT1555.005 - T1003 - T1059TA0006 - TA0005 - TA0008N/AN/ACredential Accesshttps://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor10N/Aused by EMBARGO Ransomware102158182023-11-07T14:00:47Z2023-11-07T14:00:45Z3881
584*# Minimalistic AD login bruteforcer *.{0,1000}\#\sMinimalistic\sAD\slogin\sbruteforcer\s.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorCredential Accesshttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools10N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z3899
585*# Minimalistic SMB login bruteforcer *.{0,1000}\#\sMinimalistic\sSMB\slogin\sbruteforcer\s.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorCredential Accesshttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools10N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z3900
586*# Using reflection to dump LSASS in-memory with stealth*.{0,1000}\#\sUsing\sreflection\sto\sdump\sLSASS\sin\-memory\swith\sstealth.{0,1000}offensive_tool_keywordLsassxDumping LSASS Evaded Endpoint Security SolutionsT1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001TA0006 - TA0005 - TA0004N/AN/ACredential Accesshttps://github.com/yehia-mamdouh/Lsassx10#contentN/A1011232025-02-15T16:41:38Z2025-02-15T16:36:27Z3910
587*## Extracting Private Key from Active Directory Store*.{0,1000}\#\#\sExtracting\sPrivate\sKey\sfrom\sActive\sDirectory\sStore.{0,1000}offensive_tool_keywordADFSDumpA C# tool to dump all sorts of goodies from AD FST1081 - T1003 - T1114 - T1212TA0006 - TA0005 - TA0009N/AN/ACredential Accesshttps://github.com/mandiant/ADFSDump10N/AN/A104349672023-08-07T16:58:37Z2019-03-20T22:31:16Z3914
588*$AllCurrentPwdDiscovered*.{0,1000}\$AllCurrentPwdDiscovered.{0,1000}offensive_tool_keywordInvoke-CleverSprayPassword Spraying Script detecting current and previous passwords of Active Directory UserT1110.003 - T1110.001TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/wavestone-cdt/Invoke-CleverSpray10N/AN/A10165112021-09-09T07:35:32Z2018-11-29T10:05:25Z3941
589*$DummyServiceName*.{0,1000}\$DummyServiceName.{0,1000}offensive_tool_keywordcrackmapexecVariable name from script RestartKeePass.ps1 from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3956
590*$dumpDir\lsass.txt*.{0,1000}\$dumpDir\\lsass\.txt.{0,1000}offensive_tool_keywordForensikeRemotely dump NT hashes through Windows Crash dumpsT1003TA0006N/AN/ACredential Accesshttps://github.com/bmarchev/Forensike10N/AN/A1012732024-10-29T00:13:50Z2024-02-01T13:52:55Z3957
591*$fct = Get-Content -Encoding byte -Path *.{0,1000}\$fct\s\=\sGet\-Content\s\-Encoding\sbyte\s\-Path\s.{0,1000}offensive_tool_keywordSessionGopheruses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally.T1047 - T1003.008 - T1552.004 - T1555.003TA0006N/APYSA - DarkSide - SphinxCredential Accesshttps://github.com/Arvanaghi/SessionGopher10#contentN/A101012551732022-11-22T21:33:23Z2017-03-08T02:49:32Z3974
592*$ForensikeFolder*.{0,1000}\$ForensikeFolder.{0,1000}offensive_tool_keywordForensikeRemotely dump NT hashes through Windows Crash dumpsT1003TA0006N/AN/ACredential Accesshttps://github.com/bmarchev/Forensike10N/AN/A1012732024-10-29T00:13:50Z2024-02-01T13:52:55Z3976
593*$KeePassBinaryPath*.{0,1000}\$KeePassBinaryPath.{0,1000}offensive_tool_keywordcrackmapexecVariable name from script RestartKeePass.ps1 from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3991
594*$KeePassUser*.{0,1000}\$KeePassUser.{0,1000}offensive_tool_keywordcrackmapexecVariable name from script RestartKeePass.ps1 from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z3992
595*$KeePassXMLPath backdoored*.{0,1000}\$KeePassXMLPath\sbackdoored.{0,1000}offensive_tool_keywordKeethiefAllows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.T1003 - T1055 - T1059 - T1070TA0006 - TA0005 - TA0008N/AEvilCorp* - APT20Credential Accesshttps://github.com/GhostPack/KeeThief10N/AN/A10109441542020-11-18T18:35:21Z2016-07-10T19:11:23Z3993
596*$KeePassXMLPath triggers removed*.{0,1000}\$KeePassXMLPath\striggers\sremoved.{0,1000}offensive_tool_keywordKeethiefAllows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.T1003 - T1055 - T1059 - T1070TA0006 - TA0005 - TA0008N/AEvilCorp* - APT20Credential Accesshttps://github.com/GhostPack/KeeThief10N/AN/A10109441542020-11-18T18:35:21Z2016-07-10T19:11:23Z3994
597*$ThisIsNotTheStringYouAreLookingFor*.{0,1000}\$ThisIsNotTheStringYouAreLookingFor.{0,1000}offensive_tool_keywordmimidogzRewrite of Invoke-Mimikatz.ps1 to avoid AV detectionT1055 - T1560.001 - T1110.001 - T1003 - T1071TA0005 - TA0040 - TA0006N/ADispossessorCredential Accesshttps://github.com/projectb-temp/mimidogz10N/AN/A101002019-02-11T10:14:10Z2019-02-11T10:12:08Z4022
598*$TotalNbCurrentPwdDiscovered*.{0,1000}\$TotalNbCurrentPwdDiscovered.{0,1000}offensive_tool_keywordInvoke-CleverSprayPassword Spraying Script detecting current and previous passwords of Active Directory UserT1110.003 - T1110.001TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/wavestone-cdt/Invoke-CleverSpray10N/AN/A10165112021-09-09T07:35:32Z2018-11-29T10:05:25Z4023
599*$VeaamRegPath*SqlDatabaseName*.{0,1000}\$VeaamRegPath.{0,1000}SqlDatabaseName.{0,1000}offensive_tool_keywordveeam-credsCollection of scripts to retrieve stored passwords from Veeam BackupT1003 - T1555.005 - T1552TA0006 - TA0007N/ADispossessor - Dagon LockerCredential Accesshttps://github.com/sadshade/veeam-creds10N/AN/A102126322024-12-12T10:23:54Z2021-02-05T03:13:08Z4025
600*$VeaamRegPath*SqlInstanceName*.{0,1000}\$VeaamRegPath.{0,1000}SqlInstanceName.{0,1000}offensive_tool_keywordveeam-credsCollection of scripts to retrieve stored passwords from Veeam BackupT1003 - T1555.005 - T1552TA0006 - TA0007N/ADispossessor - Dagon LockerCredential Accesshttps://github.com/sadshade/veeam-creds10N/AN/A102126322024-12-12T10:23:54Z2021-02-05T03:13:08Z4026
601*$VeaamRegPath*SqlServerName*.{0,1000}\$VeaamRegPath.{0,1000}SqlServerName.{0,1000}offensive_tool_keywordveeam-credsCollection of scripts to retrieve stored passwords from Veeam BackupT1003 - T1555.005 - T1552TA0006 - TA0007N/ADispossessor - Dagon LockerCredential Accesshttps://github.com/sadshade/veeam-creds10N/AN/A102126322024-12-12T10:23:54Z2021-02-05T03:13:08Z4027
602*%appdaedx765ta%/Binaedx765nce*.{0,1000}\%appdaedx765ta\%\/Binaedx765nce.{0,1000}offensive_tool_keywordLummaC2-Stealer-sampleartifacts from a specific sample of lumma stealer - source code on githubT1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539TA0006 - TA0010Lumma StealerN/ACredential Accesshttps://github.com/x86byte/LummaC2-Stealer10#contentcan be used for yara scans1013152025-02-18T00:38:59Z2025-02-15T12:28:05Z4030
603*%appdedx765ata%/Eledx765ectrum*.{0,1000}\%appdedx765ata\%\/Eledx765ectrum.{0,1000}offensive_tool_keywordLummaC2-Stealer-sampleartifacts from a specific sample of lumma stealer - source code on githubT1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539TA0006 - TA0010Lumma StealerN/ACredential Accesshttps://github.com/x86byte/LummaC2-Stealer10#contentcan be used for yara scans1013152025-02-18T00:38:59Z2025-02-15T12:28:05Z4034
604*%appdedx765ata%/Etheedx765reum*.{0,1000}\%appdedx765ata\%\/Etheedx765reum.{0,1000}offensive_tool_keywordLummaC2-Stealer-sampleartifacts from a specific sample of lumma stealer - source code on githubT1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539TA0006 - TA0010Lumma StealerN/ACredential Accesshttps://github.com/x86byte/LummaC2-Stealer10#contentcan be used for yara scans1013152025-02-18T00:38:59Z2025-02-15T12:28:05Z4035
605*%localaedx765ppdata%*.{0,1000}\%localaedx765ppdata\%.{0,1000}offensive_tool_keywordLummaC2-Stealer-sampleartifacts from a specific sample of lumma stealer - source code on githubT1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539TA0006 - TA0010Lumma StealerN/ACredential Accesshttps://github.com/x86byte/LummaC2-Stealer10#contentcan be used for yara scans1013152025-02-18T00:38:59Z2025-02-15T12:28:05Z4037
606*%loedx765calappedx765data*.{0,1000}\%loedx765calappedx765data.{0,1000}offensive_tool_keywordLummaC2-Stealer-sampleartifacts from a specific sample of lumma stealer - source code on githubT1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539TA0006 - TA0010Lumma StealerN/ACredential Accesshttps://github.com/x86byte/LummaC2-Stealer10#contentcan be used for yara scans1013152025-02-18T00:38:59Z2025-02-15T12:28:05Z4039
607*%userproedx765file%*.{0,1000}\%userproedx765file\%.{0,1000}offensive_tool_keywordLummaC2-Stealer-sampleartifacts from a specific sample of lumma stealer - source code on githubT1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539TA0006 - TA0010Lumma StealerN/ACredential Accesshttps://github.com/x86byte/LummaC2-Stealer10#contentcan be used for yara scans1013152025-02-18T00:38:59Z2025-02-15T12:28:05Z4045
608*&passwd=Winter2020&ok=Log+In*.{0,1000}\&passwd\=Winter2020\&ok\=Log\+In.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray10#linuxN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z4050
609*(msds-supportedencryptiontypes=0)(msds-supportedencryptiontypes:1.2.840.113556.1.4.803:=4)))*.{0,1000}\(msds\-supportedencryptiontypes\=0\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.803\:\=4\)\)\).{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z4082
610*(Program.MiniDump minidump*.{0,1000}\(Program\.MiniDump\sminidump.{0,1000}offensive_tool_keywordMiniDumpC# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumpsT1003.001TA0006N/AN/ACredential Accesshttps://github.com/cube0x0/MiniDump10#contentN/A103291482021-10-13T18:00:46Z2021-08-14T12:26:16Z4088
611*(SHADOW DUMPER v1.0)*.{0,1000}\(SHADOW\sDUMPER\sv1\.0\).{0,1000}offensive_tool_keywordShadowDumperdump LSASS memoryT1003.001 - T1055TA0006 N/AN/ACredential Accesshttps://github.com/Offensive-Panda/ShadowDumper10#contentN/A106521832025-04-05T08:32:28Z2024-11-10T15:26:28Z4089
612*./GoAWSConsoleSpray*.{0,1000}\.\/GoAWSConsoleSpray.{0,1000}offensive_tool_keywordGoAWSConsoleSpraybrute-force AWS IAM Console credentials to discover valid logins for user accountsT1078 - T1110 - T1187 - T1110.001TA0006 - TA0007 - TA0003 - TA0001N/AN/ACredential Accesshttps://github.com/WhiteOakSecurity/GoAWSConsoleSpray10#linuxN/A912952022-06-15T18:16:21Z2022-06-15T18:11:39Z4144
613*./go-secdump*.{0,1000}\.\/go\-secdump.{0,1000}offensive_tool_keywordgo-secdumpTool to remotely dump secrets from the Windows registryT1003.002 - T1012 - T1059.003TA0006 - TA0003 - TA0002N/AN/ACredential Accesshttps://github.com/jfjallid/go-secdump10#linuxN/A105457512025-02-21T19:16:11Z2023-02-23T17:02:50Z4145
614*./hashcat -*.{0,1000}\.\/hashcat\s\-.{0,1000}offensive_tool_keywordNetNTLMtoSilverTicketObtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.T1110.001 - T1558.003 - T1558.004TA0006 - TA0008 - TA0002N/AN/ACredential Accesshttps://github.com/NotMedic/NetNTLMtoSilverTicket10#linuxN/A1098421132021-07-26T15:16:20Z2019-01-14T15:32:27Z4147
615*./hashview/*.{0,1000}\.\/hashview\/.{0,1000}offensive_tool_keywordhashviewA web front-end for password cracking and analyticsT1110 - T1201TA0006 - TA0002N/AN/ACredential Accesshttps://github.com/hashview/hashview10#linuxN/A104373412025-02-20T18:23:25Z2020-11-23T19:21:06Z4148
616*./hydra *.{0,1000}\.\/hydra\s.{0,1000}offensive_tool_keywordthc-hydraParallelized login cracker which supports numerous protocols to attack.T1110.001TA0006N/AALLANITE - BERSERK BEARCredential Accesshttps://github.com/vanhauser-thc/thc-hydra10#linuxN/AN/A101032621372025-04-04T12:19:05Z2014-04-24T14:45:37Z4153
617*./kerbrute *.{0,1000}\.\/kerbrute\s.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute10#linuxN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z4159
618*./ntdissector*.{0,1000}\.\/ntdissector.{0,1000}offensive_tool_keywordntdissectorNtdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.T1003.003TA0006 N/AN/ACredential Accesshttps://github.com/synacktiv/ntdissector10#linuxN/A92139172024-08-16T14:18:35Z2023-09-05T12:13:47Z4175
619*./Obfuscated_*.py*.{0,1000}\.\/Obfuscated_.{0,1000}\.py.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber10#linuxN/A10N/A4177
620*./Passdetective*.{0,1000}\.\/Passdetective.{0,1000}offensive_tool_keywordPassDetectivePassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secretsT1059 - T1059.004 - T1552 - T1552.001TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/aydinnyunus/PassDetective10#linuxN/A7212982024-06-19T10:39:39Z2023-07-22T12:31:57Z4180
621*./Pcredz *.{0,1000}\.\/Pcredz\s.{0,1000}offensive_tool_keywordPcredzThis tool extracts Credit card numbers. NTLM(DCE-RPC. HTTP. SQL. LDAP. etc). Kerberos (AS-REQ Pre-Auth etype 23). HTTP Basic. SNMP. POP. SMTP. FTP. IMAP. etc from a pcap file or from a live interface.T1116 - T1003 - T1002 - T1001 - T1005 - T1552TA0003 - TA0002 - TA0011N/AN/ACredential Accesshttps://github.com/lgandx/Pcredz10#linuxN/AN/A1021004132025-01-27T10:34:00Z2014-04-07T02:03:33Z4181
622*./snake.{0,1000}\.\/snakeoffensive_tool_keyword3snakeTool for extracting information from newly spawned processesT1003 - T1110 - T1552 - T1505TA0001 - TA0002 - TA0003N/AN/ACredential Accesshttps://github.com/blendin/3snake10#linuxN/A787521092022-02-14T17:42:10Z2018-02-07T21:03:15Z4208
623*./t14m4t *.{0,1000}\.\/t14m4t\s.{0,1000}offensive_tool_keywordt14m4tAutomated brute-forcing attack tool.T1110N/AN/AN/ACredential Accesshttps://github.com/MS-WEB-BN/t14m4t10#linuxN/AN/A5402812021-04-02T09:52:45Z2019-10-16T14:39:33Z4213
624*./xhydra*.{0,1000}\.\/xhydra.{0,1000}offensive_tool_keywordthc-hydraParallelized login cracker which supports numerous protocols to attack.T1110.001TA0006N/AALLANITE - BERSERK BEARCredential Accesshttps://github.com/vanhauser-thc/thc-hydra10#linuxN/AN/A101032621372025-04-04T12:19:05Z2014-04-24T14:45:37Z4222
625*.asp --adcs --template Machine -smb2support*.{0,1000}\.asp\s\-\-adcs\s\-\-template\sMachine\s\-smb2support.{0,1000}offensive_tool_keywordADCSCoercePotatocoercing machine authentication but specific for ADCS serverT1187TA0006N/AN/ACredential Accesshttps://github.com/decoder-it/ADCSCoercePotato10N/AN/A103224312024-05-05T14:42:23Z2024-02-26T12:08:34Z4247
626*.dmp 1> \\127.0.0.1\C$\*.{0,1000}\.dmp\s1\>\s\\\\127\.0\.0\.1\\C\$\\.{0,1000}offensive_tool_keywordspraykatzSpraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008TA0003 - TA0004 - TA0007N/AN/ACredential Accesshttps://github.com/aas-n/spraykatz10N/AN/A987631212020-06-20T12:14:00Z2019-09-09T14:38:28Z4287
627*.edx765txt*.{0,1000}\.edx765txt.{0,1000}offensive_tool_keywordLummaC2-Stealer-sampleartifacts from a specific sample of lumma stealer - source code on githubT1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539TA0006 - TA0010Lumma StealerN/ACredential Accesshttps://github.com/x86byte/LummaC2-Stealer10#contentcan be used for yara scans1013152025-02-18T00:38:59Z2025-02-15T12:28:05Z4308
628*.exe /logonpasswords /symbol*.{0,1000}\.exe\s\s\/logonpasswords\s\/symbol.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z4318
629*.exe certificates /pvk:*.pvk*.{0,1000}\.exe\s\scertificates\s\/pvk\:.{0,1000}\.pvk.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4321
630*.exe keepass /unprotect*.{0,1000}\.exe\s\skeepass\s\/unprotect.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4323
631*.exe .\chrome.DMP*.{0,1000}\.exe\s\.\\chrome\.DMP.{0,1000}offensive_tool_keywordChromeKatzDump cookies directly from Chrome process memoryT1555.003 - T1003TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Meckazin/ChromeKatz10N/AN/A101011711152024-11-26T12:53:22Z2023-12-07T22:27:06Z4330
632*.exe .\msedge.DMP*.{0,1000}\.exe\s\.\\msedge\.DMP.{0,1000}offensive_tool_keywordChromeKatzDump cookies directly from Chrome process memoryT1555.003 - T1003TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Meckazin/ChromeKatz10N/AN/A101011711152024-11-26T12:53:22Z2023-12-07T22:27:06Z4331
633*.exe /gethmac /mode:SHA1 /key:*.{0,1000}\.exe\s\/gethmac\s\/mode\:SHA1\s\/key\:.{0,1000}offensive_tool_keywordNTHASH-FPCvarious tools for retrieving windows secrets - Lateral Movement and C2T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602TA0006 - TA0007 - TA0008 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/erwan2212/NTHASH-FPC10N/AN/A1013592023-08-13T16:38:53Z2019-08-09T11:49:55Z4333
634*.exe asktgt /user:* /aes256:* /opsec /ptt*.{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/aes256\:.{0,1000}\s\/opsec\s\/ptt.{0,1000}offensive_tool_keywordAD exploitation cheat sheetLateral Movement with Rubeus More stealthy variant but requires the AES256 key (see 'Dumping OS credentials with Mimikatz' section)T1110TA0006N/ABlack BastaCredential Accesshttps://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference10N/AN/AN/AN/AN/AN/AN/AN/A4380
635*.exe asktgt /user:* /certificate:* /password:*.{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/certificate\:.{0,1000}\s\/password\:.{0,1000}offensive_tool_keywordKeyCredentialLinkAdd Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attributeT1098 - T1550TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/Leo4j/KeyCredentialLink10N/AN/A1012132024-06-05T13:44:39Z2024-06-05T13:19:49Z4381
636*.exe asktgt /user:* /rc4:* /createnetonly:*cmd.exe*.{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/rc4\:.{0,1000}\s\/createnetonly\:.{0,1000}cmd\.exe.{0,1000}offensive_tool_keywordAD exploitation cheat sheetLateral Movement with Rubeus Pass the ticket to a sacrificial hidden process. allowing you to e.g. steal the token from this process (requires elevation)T1110TA0006N/ABlack BastaCredential Accesshttps://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference10N/AN/AN/AN/AN/AN/AN/AN/A4382
637*.exe asktgt /user:* /rc4:* /ptt*.{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/rc4\:.{0,1000}\s\/ptt.{0,1000}offensive_tool_keywordAD exploitation cheat sheetLateral Movement with Rubeus Request a TGT as the target user and pass it into the current sessionT1110TA0006N/ABlack BastaCredential Accesshttps://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference10N/AN/AN/AN/AN/AN/AN/AN/A4383
638*.exe -b chromium -p *\AppData\Local\Google\Chrome\*.{0,1000}\.exe\s\-b\schromium\s\-p\s.{0,1000}\\AppData\\Local\\Google\\Chrome\\.{0,1000}offensive_tool_keywordSharpWebSharpWeb - to export browser data including passwords - history - cookies - bookmarks and download recordsT1555.003 - T1539 - T1602 - T1074.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/StarfireLab/SharpWeb10N/AN/A108703792024-11-15T07:05:34Z2023-10-09T06:48:23Z4392
639*.exe backupkey /nowrap *.pvk*.{0,1000}\.exe\sbackupkey\s\/nowrap\s.{0,1000}\.pvk.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4393
640*.exe backupkey /server:*.{0,1000}\.exe\sbackupkey\s\/server\:.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4394
641*.exe blob /target:C:\Temp\*.{0,1000}\.exe\sblob\s\/target\:C\:\\Temp\\.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4395
642*.exe BOOKMARKS*.{0,1000}\.exe\sBOOKMARKS.{0,1000}offensive_tool_keywordAdamantium-ThiefDecrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.T1555 - T1003TA0006N/AN/ACredential Accesshttps://github.com/LimerBoy/Adamantium-Thief10N/AN/A1098182052025-01-12T15:11:50Z2020-03-01T06:50:15Z4397
643*.exe certificates /mkfile:*.txt*.{0,1000}\.exe\scertificates\s\/mkfile\:.{0,1000}\.txt.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4400
644*.exe certificates /unprotect*.{0,1000}\.exe\scertificates\s\/unprotect.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4401
645*.exe compute --sid * --kdskey *.{0,1000}\.exe\scompute\s\-\-sid\s.{0,1000}\s\-\-kdskey\s.{0,1000}offensive_tool_keywordGoldenGMSAGolenGMSA tool for working with GMSA passwordsT1003.004 - T1078.003 - T1059.006TA0006 - TA0004 - TA0002N/AN/ACredential Accesshttps://github.com/Semperis/GoldenGMSA10N/AN/A72144222024-04-11T07:51:57Z2022-02-03T10:32:05Z4407
646*.exe COOKIES*.{0,1000}\.exe\sCOOKIES.{0,1000}offensive_tool_keywordAdamantium-ThiefDecrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.T1555 - T1003TA0006N/AN/ACredential Accesshttps://github.com/LimerBoy/Adamantium-Thief10N/AN/A1098182052025-01-12T15:11:50Z2020-03-01T06:50:15Z4414
647*.exe credentials /pvk:*.pvk*.{0,1000}\.exe\scredentials\s\/pvk\:.{0,1000}\.pvk.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4417
648*.exe CREDIT_CARDS*.{0,1000}\.exe\sCREDIT_CARDS.{0,1000}offensive_tool_keywordAdamantium-ThiefDecrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.T1555 - T1003TA0006N/AN/ACredential Accesshttps://github.com/LimerBoy/Adamantium-Thief10N/AN/A1098182052025-01-12T15:11:50Z2020-03-01T06:50:15Z4418
649*.exe --dll * --dump * --pid *.{0,1000}\.exe\s\-\-dll\s.{0,1000}\s\-\-dump\s.{0,1000}\s\-\-pid\s.{0,1000}offensive_tool_keywordPPLSystemcreates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process.T1003.002TA0006N/AN/ACredential Accesshttps://github.com/Slowerzs/PPLSystem10N/AN/A102190232024-05-29T18:33:35Z2024-05-22T17:48:49Z4425
650*.exe dump /luid:* /service:krbtgt*.{0,1000}\.exe\sdump\s\/luid\:.{0,1000}\s\/service\:krbtgt.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z4429
651*.exe --dump -k * -u http*.{0,1000}\.exe\s\-\-dump\s\-k\s.{0,1000}\s\-u\shttp.{0,1000}offensive_tool_keywordDumpyReuse open handles to dynamically dump LSASST1003.001 - T1055.001 - T1083TA0006N/AN/ACredential Accesshttps://github.com/Kudaes/Dumpy10N/AN/A103243242024-04-04T07:42:26Z2021-10-13T21:54:59Z4431
652*.exe dump --key-name *.{0,1000}\.exe\sdump\s\-\-key\-name\s.{0,1000}offensive_tool_keywordShwmaeShwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentialsT1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002TA0006 - TA0005 - TA0003 - TA0004N/AN/ACredential Accesshttps://github.com/CCob/Shwmae10N/AN/A72149122025-01-27T14:36:07Z2024-03-21T15:05:03Z4432
653*.exe exec * cmd interactive*.{0,1000}\.exe\sexec\s.{0,1000}\scmd\sinteractive.{0,1000}offensive_tool_keywordBesoTokenA tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).T1134 - T1003.002TA0004 - TA0006N/AN/ACredential Accesshttps://github.com/OmriBaso/BesoToken10N/AN/A10193142022-11-23T10:45:07Z2022-11-21T01:07:51Z4439
654*.exe --get-users-list > *.{0,1000}\.exe\s\-\-get\-users\-list\s\>\s.{0,1000}offensive_tool_keywordSharpSpraySharpSpray is a Windows domain password spraying tool written in .NET C#T1110TA0006N/AN/ACredential Accesshttps://github.com/iomoath/SharpSpray10N/AN/A102130212021-11-25T19:13:56Z2021-08-31T16:09:45Z4456
655*.exe gmsainfo --sid *.{0,1000}\.exe\sgmsainfo\s\-\-sid\s.{0,1000}offensive_tool_keywordGoldenGMSAGolenGMSA tool for working with GMSA passwordsT1003.004 - T1078.003 - T1059.006TA0006 - TA0004 - TA0002N/AN/ACredential Accesshttps://github.com/Semperis/GoldenGMSA10N/AN/A72144222024-04-11T07:51:57Z2022-02-03T10:32:05Z4457
656*.exe hash /password:*.{0,1000}\.exe\shash\s\/password\:.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z4466
657*.exe kdsinfo --guid *.{0,1000}\.exe\skdsinfo\s\-\-guid\s.{0,1000}offensive_tool_keywordGoldenGMSAGolenGMSA tool for working with GMSA passwordsT1003.004 - T1078.003 - T1059.006TA0006 - TA0004 - TA0002N/AN/ACredential Accesshttps://github.com/Semperis/GoldenGMSA10N/AN/A72144222024-04-11T07:51:57Z2022-02-03T10:32:05Z4488
658*.exe machinemasterkeys*.{0,1000}\.exe\smachinemasterkeys.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4529
659*.exe machinetriage*.{0,1000}\.exe\smachinetriage.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4530
660*.exe machinevaults*.{0,1000}\.exe\smachinevaults.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4531
661*.exe masterkeys /hashes*.{0,1000}\.exe\smasterkeys\s\/hashes.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4532
662*.exe masterkeys /hashes*.{0,1000}\.exe\smasterkeys\s\/hashes.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4533
663*.exe masterkeys /pvk:*.{0,1000}\.exe\smasterkeys\s\/pvk\:.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4534
664*.exe --procdump -p *.{0,1000}\.exe\s\-\-procdump\s\-p\s.{0,1000}offensive_tool_keywordMultiDumpMultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetlyT1003 - T1564.002TA0005 - TA0006N/AN/ACredential Accesshttps://github.com/Xre0uS/MultiDump10N/AN/A106510662025-03-28T10:40:27Z2024-02-02T05:56:29Z4572
665*.exe ps /target:C:\Temp\* /unprotect*.{0,1000}\.exe\sps\s\/target\:C\:\\Temp\\.{0,1000}\s\/unprotect.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4574
666*.exe ptt /ticket:*.kirbi.{0,1000}\.exe\sptt\s\/ticket\:.{0,1000}\.kirbioffensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z4576
667*.exe rdg /unprotect*.{0,1000}\.exe\srdg\s\/unprotect.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4584
668*.exe --signature --driver*.{0,1000}\.exe\s\-\-signature\s\-\-driver.{0,1000}offensive_tool_keywordPOSTDumpAnother tool to perform minidump of LSASS process using few technics to avoid detection.T1003 - T1055 - T1562.001 - T1218TA0005 - TA0003 - TA0006N/ABlack BastaCredential Accesshttps://github.com/YOLOP0wn/POSTDump10N/AN/A104327372025-02-05T15:24:52Z2023-09-13T11:28:51Z4611
669*.exe spy --pid *.{0,1000}\.exe\sspy\s\-\-pid\s.{0,1000}offensive_tool_keywordSpyndicappedCOM ViewLogger - keyloggerT1574.001 - T1574.002 - T1574.009TA0006N/AN/ACredential Accesshttps://github.com/CICADA8-Research/Spyndicapped10N/AN/A104356502025-01-06T07:31:29Z2024-12-25T11:47:39Z4620
670*.exe spy --window *.{0,1000}\.exe\sspy\s\-\-window\s.{0,1000}offensive_tool_keywordSpyndicappedCOM ViewLogger - keyloggerT1574.001 - T1574.002 - T1574.009TA0006N/AN/ACredential Accesshttps://github.com/CICADA8-Research/Spyndicapped10N/AN/A104356502025-01-06T07:31:29Z2024-12-25T11:47:39Z4621
671*.exe triage /password:*.{0,1000}\.exe\striage\s\/password\:.{0,1000}offensive_tool_keywordSharpDPAPISharpDPAPI is a C# port of some Mimikatz DPAPI functionality.T1552.002 - T1059.001 - T1112 - T1649TA0006 - TA0002N/AContiCredential Accesshttps://github.com/GhostPack/SharpDPAPI10N/AN/A101012322152024-06-27T13:39:08Z2018-08-22T17:39:31Z4632
672*.exe -u * -s 2 -c cmd.exe*.{0,1000}\.exe\s\-u\s.{0,1000}\s\-s\s2\s\-c\scmd\.exe.{0,1000}offensive_tool_keywordTokenStealerstealing Windows tokensT1134 - T1055TA0003 - TA0004N/AN/ACredential Accesshttps://github.com/decoder-it/TokenStealer10N/AN/A102164292023-10-25T14:08:57Z2023-10-24T13:06:37Z4633
673*.exe -v -u * -w 10k-most-common.txt*.{0,1000}\.exe\s\-v\s\-u\s.{0,1000}\s\-w\s10k\-most\-common\.txt.{0,1000}offensive_tool_keywordwin-brute-logonCrack any Microsoft Windows users password without any privilege (Guest account included)T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005TA0006 - TA0008 - TA0005N/AN/ACredential Accesshttps://github.com/PhrozenIO/win-brute-logon10N/AN/A71011381912023-11-09T10:37:58Z2020-05-14T21:46:50Z4639
674*.exe Xmanager /user:* /sid:* /path:**.{0,1000}\.exe\sXmanager\s\/user\:.{0,1000}\s\/sid\:.{0,1000}\s\/path\:.{0,1000}.{0,1000}offensive_tool_keywordSharpDecryptPwdDecrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etcT1003.008 - T1555.004 - T1552.002TA0006N/AN/ACredential Accesshttps://github.com/RowTeam/SharpDecryptPwd10N/AN/A1087691172022-03-04T02:49:31Z2022-02-25T11:21:43Z4645
675*.exe -Xmangager -p *.{0,1000}\.exe\s\-Xmangager\s\-p\s.{0,1000}offensive_tool_keywordSharpDecryptPwdDecrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etcT1003.008 - T1555.004 - T1552.002TA0006N/AN/ACredential Accesshttps://github.com/RowTeam/SharpDecryptPwd10N/AN/A1087691172022-03-04T02:49:31Z2022-02-25T11:21:43Z4646
676*.exe* -d localhost * -u * -p */24*.{0,1000}\.exe.{0,1000}\s\-d\slocalhost\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\/24.{0,1000}offensive_tool_keywordcrackmapexecwindows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z4647
677*.exe* -u administrator -H :*--shares*.{0,1000}\.exe.{0,1000}\s\-u\sadministrator\s\-H\s\:.{0,1000}\-\-shares.{0,1000}offensive_tool_keywordcrackmapexecwindows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z4657
678*.local.kirbi*.{0,1000}\.local\.kirbi.{0,1000}offensive_tool_keywordkerberoastKerberoast is a series of tools for attacking MS Kerberos implementationsT1550 - T1555 - T1212 - T1558TA0001 - TA0004 - TA0006N/AAPT20Credential Accesshttps://github.com/nidem/kerberoast11N/AN/AN/A1014333172022-12-31T17:17:28Z2014-09-22T14:46:49Z4695
679*.ps1 -dcip * -Username * -Password* -ExportToCSV *.csv -ExportToJSON *.json*.{0,1000}\.ps1\s\-dcip\s.{0,1000}\s\-Username\s.{0,1000}\s\-Password.{0,1000}\s\-ExportToCSV\s.{0,1000}\.csv\s\-ExportToJSON\s.{0,1000}\.json.{0,1000}offensive_tool_keywordExtractBitlockerKeysA system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.T1003.002 - T1039 - T1087.002TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/p0dalirius/ExtractBitlockerKeys10N/AN/A104368542025-01-31T09:39:55Z2023-09-19T07:28:11Z4760
680*.py -credz *.txt * .{0,1000}\.py\s\s\-credz\s.{0,1000}\.txt\s.{0,1000}\soffensive_tool_keyworddonpapiDumping DPAPI credentials remotelyT1003.006 - T1021.001TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/login-securite/DonPAPI10N/AN/AN/A1011101302025-03-24T10:23:58Z2021-09-27T09:12:51Z4773
681*.py rekall *.dmp* -t 0.{0,1000}\.py\s\srekall\s.{0,1000}\.dmp.{0,1000}\s\-t\s0offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz10N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z4788
682*.py * --burp *.{0,1000}\.py\s.{0,1000}\s\-\-burp\s.{0,1000}offensive_tool_keywordsecretfinderSecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript filesT1083 - T1081 - T1113TA0003 - TA0002 - TA0007N/AN/ACredential Accesshttps://github.com/m4ll0k/SecretFinder10N/AN/AN/A1021534052024-05-26T09:36:41Z2020-06-08T10:50:12Z4793
683*.py * -debug -dnstcp*.{0,1000}\.py\s.{0,1000}\s\-debug\s\-dnstcp.{0,1000}offensive_tool_keywordHEKATOMBHekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt themT1003 - T1555.002 - T1482 - T1087TA0006 - TA0005 - TA0007N/AN/ACredential Accesshttps://github.com/Processus-Thief/HEKATOMB10N/AN/A10N/A4796
684*.py -d "test.local" -u "john" -p "password123" --target "user2" --action "list" --dc-ip "10.10.10.1"*.{0,1000}\.py\s\-d\s\"test\.local\"\s\-u\s\"john\"\s\-p\s\"password123\"\s\-\-target\s\"user2\"\s\-\-action\s\"list\"\s\-\-dc\-ip\s\"10\.10\.10\.1\".{0,1000}offensive_tool_keywordpywhiskerPython version of the C# tool for Shadow Credentials attacksT1552.001 - T1136 - T1098TA0003 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/ShutdownRepo/pywhisker10N/AN/A108712892025-04-21T16:53:22Z2021-07-21T19:20:00Z4822
685*.py -d * -u * -p * --target * --action * --export PEM*.{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\s.{0,1000}\s\-\-export\sPEM.{0,1000}offensive_tool_keywordpywhiskerPython version of the C# tool for Shadow Credentials attacksT1552.001 - T1136 - T1098TA0003 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/ShutdownRepo/pywhisker10N/AN/A108712892025-04-21T16:53:22Z2021-07-21T19:20:00Z4823
686*.py -d * -u * -p * --target * --action "add" --filename * .{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\"add\"\s\-\-filename\s.{0,1000}\soffensive_tool_keywordpywhiskerPython version of the C# tool for Shadow Credentials attacksT1552.001 - T1136 - T1098TA0003 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/ShutdownRepo/pywhisker10N/AN/A108712892025-04-21T16:53:22Z2021-07-21T19:20:00Z4824
687*.py -d * -u * -p * --target * --action "clear"* .{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\"clear\".{0,1000}\soffensive_tool_keywordpywhiskerPython version of the C# tool for Shadow Credentials attacksT1552.001 - T1136 - T1098TA0003 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/ShutdownRepo/pywhisker10N/AN/A108712892025-04-21T16:53:22Z2021-07-21T19:20:00Z4825
688*.py -d * -u * -p * --target * --action "info" --device-id *.{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\"info\"\s\-\-device\-id\s.{0,1000}offensive_tool_keywordpywhiskerPython version of the C# tool for Shadow Credentials attacksT1552.001 - T1136 - T1098TA0003 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/ShutdownRepo/pywhisker10N/AN/A108712892025-04-21T16:53:22Z2021-07-21T19:20:00Z4826
689*.py -d * -u * -p * --target * --action "list" *.{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\"list\"\s.{0,1000}offensive_tool_keywordpywhiskerPython version of the C# tool for Shadow Credentials attacksT1552.001 - T1136 - T1098TA0003 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/ShutdownRepo/pywhisker10N/AN/A108712892025-04-21T16:53:22Z2021-07-21T19:20:00Z4827
690*.py -d * -u * -p * --target * --action "remove" --device-id *.{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\"remove\"\s\-\-device\-id\s.{0,1000}offensive_tool_keywordpywhiskerPython version of the C# tool for Shadow Credentials attacksT1552.001 - T1136 - T1098TA0003 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/ShutdownRepo/pywhisker10N/AN/A108712892025-04-21T16:53:22Z2021-07-21T19:20:00Z4828
691*.py discover -H domain_list.txt*.{0,1000}\.py\sdiscover\s\-H\sdomain_list\.txt.{0,1000}offensive_tool_keywordlyncsmasha collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations T1190 - T1087 - T1110TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/nyxgeek/lyncsmash10N/AN/A84337632024-10-01T11:22:01Z2016-05-20T04:32:41Z4829
692*.py enum -H * -U *.txt -P *.txt -*.txt*.{0,1000}\.py\senum\s\-H\s.{0,1000}\s\-U\s.{0,1000}\.txt\s\-P\s.{0,1000}\.txt\s\-.{0,1000}\.txt.{0,1000}offensive_tool_keywordlyncsmasha collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations T1190 - T1087 - T1110TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/nyxgeek/lyncsmash10N/AN/A84337632024-10-01T11:22:01Z2016-05-20T04:32:41Z4831
693*.py lock -H * -u administrator -d *.{0,1000}\.py\slock\s\-H\s.{0,1000}\s\-u\sadministrator\s\-d\s.{0,1000}offensive_tool_keywordlyncsmasha collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations T1190 - T1087 - T1110TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/nyxgeek/lyncsmash10N/AN/A84337632024-10-01T11:22:01Z2016-05-20T04:32:41Z4836
694*.py spray -ep *.{0,1000}\.py\sspray\s\-ep\s.{0,1000}offensive_tool_keywordSpray365Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD).T1110.003TA0006N/AN/ACredential Accesshttps://github.com/MarkoH17/Spray36510N/AN/AN/A4348582022-07-14T14:45:57Z2021-11-04T18:20:39Z4842
695*.py teams --get*.{0,1000}\.py\steams\s\-\-get.{0,1000}offensive_tool_keywordteams_dumpPoC for dumping and decrypting cookies in the latest version of Microsoft TeamsT1560.001 - T1555.003 - T1113 - T1557TA0006 - TA0005 - TA0009N/AN/ACredential Accesshttps://github.com/byinarie/teams_dump10N/AN/A72132192023-11-12T18:47:55Z2023-09-18T18:33:32Z4845
696*.py teams --list*.{0,1000}\.py\steams\s\-\-list.{0,1000}offensive_tool_keywordteams_dumpPoC for dumping and decrypting cookies in the latest version of Microsoft TeamsT1560.001 - T1555.003 - T1113 - T1557TA0006 - TA0005 - TA0009N/AN/ACredential Accesshttps://github.com/byinarie/teams_dump10N/AN/A72132192023-11-12T18:47:55Z2023-09-18T18:33:32Z4846
697*.py*.ccache *.kirbi *.{0,1000}\.py.{0,1000}\.ccache\s.{0,1000}\.kirbi\s.{0,1000}offensive_tool_keywordticket_converterA little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.T1558.003 - T1110.004TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/zer1t0/ticket_converter10N/AN/A102167312022-06-16T19:38:05Z2019-05-14T04:48:19Z4855
698*.py*.kirbi *.ccache*.{0,1000}\.py.{0,1000}\.kirbi\s.{0,1000}\.ccache.{0,1000}offensive_tool_keywordticket_converterA little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.T1558.003 - T1110.004TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/zer1t0/ticket_converter10N/AN/A102167312022-06-16T19:38:05Z2019-05-14T04:48:19Z4856
699*.py*found-users.txt*.{0,1000}\.py.{0,1000}found\-users\.txt.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker10N/AN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z4857
700*/.config/lsassy*.{0,1000}\/\.config\/lsassy.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy10#linuxN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z5011
701*/.ntdissector*.{0,1000}\/\.ntdissector.{0,1000}offensive_tool_keywordntdissectorNtdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class.T1003.003TA0006 N/AN/ACredential Accesshttps://github.com/synacktiv/ntdissector10#linuxN/A92139172024-08-16T14:18:35Z2023-09-05T12:13:47Z5027
702*/.spraycharles/logs*.{0,1000}\/\.spraycharles\/logs.{0,1000}offensive_tool_keywordspraycharlesLow and slow password spraying toolT1110.003 - T1110.001TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Tw1sm/spraycharles10#linuxN/A102195322025-02-09T03:08:09Z2018-09-17T11:17:47Z5035
703*/.spraycharles/out*.{0,1000}\/\.spraycharles\/out.{0,1000}offensive_tool_keywordspraycharlesLow and slow password spraying toolT1110.003 - T1110.001TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Tw1sm/spraycharles10#linuxN/A102195322025-02-09T03:08:09Z2018-09-17T11:17:47Z5036
704*/.spraycharles:/root/.spraycharles*.{0,1000}\/\.spraycharles\:\/root\/\.spraycharles.{0,1000}offensive_tool_keywordspraycharlesLow and slow password spraying toolT1110.003 - T1110.001TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Tw1sm/spraycharles10#linuxN/A102195322025-02-09T03:08:09Z2018-09-17T11:17:47Z5037
705*//shuck.sh*.{0,1000}\/\/shuck\.sh.{0,1000}offensive_tool_keywordShuckNTShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)T1552.001 - T1555.003 - T1078.003TA0006 - TA0002 - TA0040N/AN/ACredential Accesshttps://github.com/yanncam/ShuckNT11N/AN/A1016992024-10-18T10:45:49Z2023-01-27T07:52:47Z5060
706*/1$a$$.exe*.{0,1000}\/1\$a\$\$\.exe.{0,1000}offensive_tool_keywordDumpThatLSASSDumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the diskT1003 - T1055.011 - T1027 - T1564.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/peiga/DumpThatLSASS11N/AN/A10131792022-09-24T22:39:04Z2022-09-24T22:41:19Z5075
707*/1/all_in_one.7z.torrent*.{0,1000}\/1\/all_in_one\.7z\.torrent.{0,1000}offensive_tool_keywordweakpassWeakpass collection of tools for bruteforce and hashcrackingT1110 - T1201TA0006 - TA0002N/ABlack BastaCredential Accesshttps://github.com/zzzteph/weakpass11N/AN/A106541552025-04-08T19:50:48Z2021-08-29T13:07:37Z5077
708*/1/all_in_one_p.7z*.{0,1000}\/1\/all_in_one_p\.7z.{0,1000}offensive_tool_keywordweakpassWeakpass collection of tools for bruteforce and hashcrackingT1110 - T1201TA0006 - TA0002N/ABlack BastaCredential Accesshttps://github.com/zzzteph/weakpass11N/AN/A106541552025-04-08T19:50:48Z2021-08-29T13:07:37Z5078
709*/1/all_in_one_w.7z*.{0,1000}\/1\/all_in_one_w\.7z.{0,1000}offensive_tool_keywordweakpassWeakpass collection of tools for bruteforce and hashcrackingT1110 - T1201TA0006 - TA0002N/ABlack BastaCredential Accesshttps://github.com/zzzteph/weakpass11N/AN/A106541552025-04-08T19:50:48Z2021-08-29T13:07:37Z5079
710*/3snake.git*.{0,1000}\/3snake\.git.{0,1000}offensive_tool_keyword3snakeTool for extracting information from newly spawned processesT1003 - T1110 - T1552 - T1505TA0001 - TA0002 - TA0003N/AN/ACredential Accesshttps://github.com/blendin/3snake11N/AN/A787521092022-02-14T17:42:10Z2018-02-07T21:03:15Z5094
711*/Adamantium-Thief.git*.{0,1000}\/Adamantium\-Thief\.git.{0,1000}offensive_tool_keywordAdamantium-ThiefDecrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill.T1555 - T1003TA0006N/AN/ACredential Accesshttps://github.com/LimerBoy/Adamantium-Thief11N/AN/A1098182052025-01-12T15:11:50Z2020-03-01T06:50:15Z5131
712*/adconnectdump.git*.{0,1000}\/adconnectdump\.git.{0,1000}offensive_tool_keywordadconnectdumpDump Azure AD Connect credentials for Azure AD and Active DirectoryT1003.004 - T1059.001 - T1082TA0006 - TA0002 - TA0007N/AN/ACredential Accesshttps://github.com/fox-it/adconnectdump11N/AN/A107668882024-11-10T22:00:16Z2019-04-09T07:41:42Z5148
713*/ADCSCoercePotato.git*.{0,1000}\/ADCSCoercePotato\.git.{0,1000}offensive_tool_keywordADCSCoercePotatocoercing machine authentication but specific for ADCS serverT1187TA0006N/AN/ACredential Accesshttps://github.com/decoder-it/ADCSCoercePotato11N/AN/A103224312024-05-05T14:42:23Z2024-02-26T12:08:34Z5156
714*/ADCSCoercePotato/*.{0,1000}\/ADCSCoercePotato\/.{0,1000}offensive_tool_keywordADCSCoercePotatocoercing machine authentication but specific for ADCS serverT1187TA0006N/AN/ACredential Accesshttps://github.com/decoder-it/ADCSCoercePotato11N/AN/A103224312024-05-05T14:42:23Z2024-02-26T12:08:34Z5157
715*/adcsync.git*.{0,1000}\/adcsync\.git.{0,1000}offensive_tool_keywordadcsyncUse ESC1 to perform a makeshift DCSync and dump hashesT1003.006 - T1021TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/JPG0mez/ADCSync11N/AN/A93205222023-11-02T21:41:08Z2023-10-04T01:56:50Z5164
716*/adcsync.py*.{0,1000}\/adcsync\.py.{0,1000}offensive_tool_keywordadcsyncUse ESC1 to perform a makeshift DCSync and dump hashesT1003.006 - T1021TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/JPG0mez/ADCSync11N/AN/A93205222023-11-02T21:41:08Z2023-10-04T01:56:50Z5165
717*/adfsbrute.git*.{0,1000}\/adfsbrute\.git.{0,1000}offensive_tool_keywordadfsbrutetest credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacksT1110.003 - T1110.001 - T1110TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/ricardojoserf/adfsbrute11N/AN/A82172332021-04-23T16:43:59Z2020-10-02T16:28:35Z5187
718*/adfsbrute.py*.{0,1000}\/adfsbrute\.py.{0,1000}offensive_tool_keywordadfsbrutetest credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacksT1110.003 - T1110.001 - T1110TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/ricardojoserf/adfsbrute11N/AN/A82172332021-04-23T16:43:59Z2020-10-02T16:28:35Z5188
719*/ADFSDump.git*.{0,1000}\/ADFSDump\.git.{0,1000}offensive_tool_keywordADFSDumpA C# tool to dump all sorts of goodies from AD FST1081 - T1003 - T1114 - T1212TA0006 - TA0005 - TA0009N/AN/ACredential Accesshttps://github.com/mandiant/ADFSDump11N/AN/A104349672023-08-07T16:58:37Z2019-03-20T22:31:16Z5191
720*/ADFSDump-PS.git*.{0,1000}\/ADFSDump\-PS\.git.{0,1000}offensive_tool_keywordADFSDump-PSADFSDump to assist with GoldenSAMLT1078 - T1552.004 - T1558.004TA0006 N/AN/ACredential Accesshttps://github.com/ZephrFish/ADFSDump-PS11N/AN/A1013182024-05-20T00:00:19Z2024-05-19T00:46:28Z5192
721*/ADFSpray*.{0,1000}\/ADFSpray.{0,1000}offensive_tool_keywordadfsprayPython3 tool to perform password spraying against Microsoft Online service using various methodsT1110.003TA0006N/AN/ACredential Accesshttps://github.com/xFreed0m/ADFSpray11N/AN/AN/A187142023-03-12T00:21:34Z2020-04-23T08:56:51Z5194
722*/ADFSRelay.git*.{0,1000}\/ADFSRelay\.git.{0,1000}offensive_tool_keywordADFSRelayNTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFST1140 - T1212 - T1557TA0007 - TA0008 - TA0006N/ABlack BastaCredential Accesshttps://github.com/praetorian-inc/ADFSRelay11N/AN/A102179152022-06-22T03:01:00Z2022-05-12T01:20:14Z5195
723*/ADFSRelay.go*.{0,1000}\/ADFSRelay\.go.{0,1000}offensive_tool_keywordADFSRelayNTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFST1140 - T1212 - T1557TA0007 - TA0008 - TA0006N/ABlack BastaCredential Accesshttps://github.com/praetorian-inc/ADFSRelay11N/AN/A102179152022-06-22T03:01:00Z2022-05-12T01:20:14Z5196
724*/adfs-spray.py*.{0,1000}\/adfs\-spray\.py.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray11N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z5197
725*/aerosol.py*.{0,1000}\/aerosol\.py.{0,1000}offensive_tool_keywordSprayingToolkitScripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficientT1110 - T1078 - T1133 - T1061 - T1621TA0001 - TA0002 - TA0003N/AN/ACredential Accesshttps://github.com/byt3bl33d3r/SprayingToolkit10#linuxN/A101014912692022-10-17T01:01:57Z2018-09-13T09:52:11Z5220
726*/amass/wordlists*.{0,1000}\/amass\/wordlists.{0,1000}offensive_tool_keywordwordlistspackage contains the rockyou.txt wordlistT1110.001TA0006N/AN/ACredential Accesshttps://www.kali.org/tools/wordlists/11N/AN/AN/AN/AN/AN/AN/AN/A5286
727*/amsiwala.exe*.{0,1000}\/amsiwala\.exe.{0,1000}offensive_tool_keywordShadowStealerGoogle Chrome Passwords , Cookies and SystemInfo DumperT1555 - T1539 - T1125 - T1083 - T1056TA0009 - TA0006 - TA0010N/AN/ACredential Accesshttps://github.com/xelroth/ShadowStealer11N/AN/A101N/AN/AN/AN/A5306
728*/AndrewSpecial.git*.{0,1000}\/AndrewSpecial\.git.{0,1000}offensive_tool_keywordAndrewSpecialAndrewSpecial - dumping lsass memory stealthilyT1003.001 - T1055.001TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/hoangprod/AndrewSpecial11N/AN/A104386982019-06-02T02:49:28Z2019-01-18T19:12:09Z5308
729*/apps/zxtm/wizard.fcgi?error=1&section=Access+Management%3ALocalUsers*.{0,1000}\/apps\/zxtm\/wizard\.fcgi\?error\=1\&section\=Access\+Management\%3ALocalUsers.{0,1000}offensive_tool_keywordPOCIvanti Authent Bypass CVE-2024-7593 - Successful exploitation could lead to authentication bypass and creation of an administrator userT1078 - T1136 - T1078.001TA0006 - TA0004 - TA0005N/AN/ACredential Accesshttps://x.com/mthcht/status/182346384245984890611N/AN/A1010N/AN/AN/AN/A5388
730*/Ask4Creds.git*.{0,1000}\/Ask4Creds\.git.{0,1000}offensive_tool_keywordAsk4CredsPrompt User for credentialsT1056 - T1071TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Leo4j/Ask4Creds11N/AN/A81102024-03-20T17:09:21Z2023-11-12T15:21:40Z5409
731*/Ask4Creds.ps1*.{0,1000}\/Ask4Creds\.ps1.{0,1000}offensive_tool_keywordAsk4CredsPrompt User for credentialsT1056 - T1071TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Leo4j/Ask4Creds11N/AN/A81102024-03-20T17:09:21Z2023-11-12T15:21:40Z5411
732*/ASREPRoast*.{0,1000}\/ASREPRoast.{0,1000}offensive_tool_keywordASREPRoastProject that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. T1558.003TA0006N/AN/ACredential Accesshttps://github.com/HarmJ0y/ASREPRoast11N/AN/AN/A3202582018-09-25T03:26:00Z2017-01-14T21:07:57Z5423
733*/atomizer.py*.{0,1000}\/atomizer\.py.{0,1000}offensive_tool_keywordSprayingToolkitScripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficientT1110 - T1078 - T1133 - T1061 - T1621TA0001 - TA0002 - TA0003N/AN/ACredential Accesshttps://github.com/byt3bl33d3r/SprayingToolkit10#linuxN/A91014912692022-10-17T01:01:57Z2018-09-13T09:52:11Z5456
734*/ATPMiniDump.git*.{0,1000}\/ATPMiniDump\.git.{0,1000}offensive_tool_keywordATPMiniDumpDumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @CneelisT1003 - T1005 - T1055 - T1218TA0006 - TA0008 - TA0011N/AN/ACredential Accesshttps://github.com/b4rtik/ATPMiniDump11N/AN/AN/A3255462019-12-02T15:01:22Z2019-11-29T19:49:54Z5460
735*/autoNTDS.git*.{0,1000}\/autoNTDS\.git.{0,1000}offensive_tool_keywordautoNTDSautoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcatT1003 - T1059 - T1021.002 - T1213TA0006 - TA0008 - TA0005 - TA0002N/AN/ACredential Accesshttps://github.com/hmaverickadams/autoNTDS11N/AN/A102109142023-10-31T22:03:58Z2023-10-30T23:10:58Z5486
736*/autoNTDS.py*.{0,1000}\/autoNTDS\.py.{0,1000}offensive_tool_keywordautoNTDSautoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcatT1003 - T1059 - T1021.002 - T1213TA0006 - TA0008 - TA0005 - TA0002N/AN/ACredential Accesshttps://github.com/hmaverickadams/autoNTDS11N/AN/A102109142023-10-31T22:03:58Z2023-10-30T23:10:58Z5487
737*/BabelStrike.git*.{0,1000}\/BabelStrike\.git.{0,1000}offensive_tool_keywordBabelStrikeThe purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)T1078 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/t3l3machus/BabelStrike11N/AN/A12132232024-07-19T07:02:42Z2023-01-10T07:59:00Z5518
738*/BabelStrike.py*.{0,1000}\/BabelStrike\.py.{0,1000}offensive_tool_keywordBabelStrikeThe purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin)T1078 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/t3l3machus/BabelStrike11N/AN/A12132232024-07-19T07:02:42Z2023-01-10T07:59:00Z5519
739*/backupcreds.exe*.{0,1000}\/backupcreds\.exe.{0,1000}offensive_tool_keywordBackupCredsA C# implementation of dumping credentials from Windows Credential ManagerT1003 - T1555TA0006 - TA0005N/ABlack BastaCredential Accesshttps://github.com/leftp/BackupCreds11N/AN/A9157102023-09-23T10:37:05Z2023-09-23T06:42:20Z5542
740*/BackupCreds.git*.{0,1000}\/BackupCreds\.git.{0,1000}offensive_tool_keywordBackupCredsA C# implementation of dumping credentials from Windows Credential ManagerT1003 - T1555TA0006 - TA0005N/ABlack BastaCredential Accesshttps://github.com/leftp/BackupCreds11N/AN/A9157102023-09-23T10:37:05Z2023-09-23T06:42:20Z5543
741*/badcert.pem*.{0,1000}\/badcert\.pem.{0,1000}offensive_tool_keywordSSH-SnakeSSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discoveryT1021.004 - T1027 - T1552.004TA0002 - TA0005 - TA0006N/AN/ACredential Accesshttps://github.com/MegaManSec/SSH-Snake10#linuxN/A101020651982024-07-25T09:32:07Z2023-12-03T04:52:38Z5548
742*/badkey.pem*.{0,1000}\/badkey\.pem.{0,1000}offensive_tool_keywordSSH-SnakeSSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discoveryT1021.004 - T1027 - T1552.004TA0002 - TA0005 - TA0006N/AN/ACredential Accesshttps://github.com/MegaManSec/SSH-Snake10#linuxN/A101020651982024-07-25T09:32:07Z2023-12-03T04:52:38Z5549
743*/BesoToken.cpp*.{0,1000}\/BesoToken\.cpp.{0,1000}offensive_tool_keywordBesoTokenA tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).T1134 - T1003.002TA0004 - TA0006N/AN/ACredential Accesshttps://github.com/OmriBaso/BesoToken11N/AN/A10193142022-11-23T10:45:07Z2022-11-21T01:07:51Z5606
744*/BesoToken.exe*.{0,1000}\/BesoToken\.exe.{0,1000}offensive_tool_keywordBesoTokenA tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).T1134 - T1003.002TA0004 - TA0006N/AN/ACredential Accesshttps://github.com/OmriBaso/BesoToken11N/AN/A10193142022-11-23T10:45:07Z2022-11-21T01:07:51Z5607
745*/BesoToken.git*.{0,1000}\/BesoToken\.git.{0,1000}offensive_tool_keywordBesoTokenA tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions).T1134 - T1003.002TA0004 - TA0006N/AN/ACredential Accesshttps://github.com/OmriBaso/BesoToken11N/AN/A10193142022-11-23T10:45:07Z2022-11-21T01:07:51Z5608
746*/big_shell_pwd.7z*.{0,1000}\/big_shell_pwd\.7z.{0,1000}offensive_tool_keywordcheetaha very fast brute force webshell password toolT1110 - T1190 - T1505.003TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/shmilylty/cheetah11N/AN/A1076301502023-04-17T01:33:52Z2017-04-15T20:03:50Z5618
747*/Blank%20Grabber/Extras/hash*.{0,1000}\/Blank\%20Grabber\/Extras\/hash.{0,1000}offensive_tool_keywordBlank-GrabberStealer with multiple functionsT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Blank-c/Blank-Grabber11N/AN/A1098312202023-08-06T06:26:16Z2022-01-26T12:04:56Z5692
748*/Blank.Grabber.zip*.{0,1000}\/Blank\.Grabber\.zip.{0,1000}offensive_tool_keywordBlank-GrabberStealer with multiple functionsT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Blank-c/Blank-Grabber11N/AN/A1098312202023-08-06T06:26:16Z2022-01-26T12:04:56Z5693
749*/Blank-Grabber#download*.{0,1000}\/Blank\-Grabber\#download.{0,1000}offensive_tool_keywordBlank-GrabberStealer with multiple functionsT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Blank-c/Blank-Grabber11N/AN/A1098312202023-08-06T06:26:16Z2022-01-26T12:04:56Z5694
750*/Blank-Grabber.git*.{0,1000}\/Blank\-Grabber\.git.{0,1000}offensive_tool_keywordBlank-GrabberStealer with multiple functionsT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Blank-c/Blank-Grabber11N/AN/A1098312202023-08-06T06:26:16Z2022-01-26T12:04:56Z5695
751*/BlankOBF.py*.{0,1000}\/BlankOBF\.py.{0,1000}offensive_tool_keywordBlank-GrabberStealer with multiple functionsT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Blank-c/Blank-Grabber11N/AN/A1098312202023-08-06T06:26:16Z2022-01-26T12:04:56Z5697
752*/blindsight.exe*.{0,1000}\/blindsight\.exe.{0,1000}offensive_tool_keywordblindsightRed teaming tool to dump LSASS memory, bypassing basic countermeasuresT1003.001TA0006N/AN/ACredential Accesshttps://github.com/0xdea/blindsight11N/AN/A103225262024-12-31T15:28:15Z2024-07-18T07:35:43Z5700
753*/blindsight.git*.{0,1000}\/blindsight\.git.{0,1000}offensive_tool_keywordblindsightRed teaming tool to dump LSASS memory, bypassing basic countermeasuresT1003.001TA0006N/AN/ACredential Accesshttps://github.com/0xdea/blindsight11N/AN/A103225262024-12-31T15:28:15Z2024-07-18T07:35:43Z5701
754*/bloodhound.py*.{0,1000}\/bloodhound\.py.{0,1000}offensive_tool_keywordcrackmapexecbloodhound integration with crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec11N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z5715
755*/bloodhoundsync.py*.{0,1000}\/bloodhoundsync\.py.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore11N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z5725
756*/BrowserDataGrabber.git*.{0,1000}\/BrowserDataGrabber\.git.{0,1000}offensive_tool_keywordBrowser Data Grabbercredential access tool used by the Dispossessor ransomware groupT1003 - T1555 - T1081 - T1552TA0006N/ADispossessorCredential Accesshttps://github.com/n37sn4k3/BrowserDataGrabber11N/AN/A101742018-05-28T15:49:03Z2018-05-04T12:33:32Z5817
757*/BrowserGhost.git*.{0,1000}\/BrowserGhost\.git.{0,1000}offensive_tool_keywordBrowserGhostThis is a tool for grabbing browser passwordsT1555.003 - T1555.013 - T1003.008TA0006N/AN/ACredential Accesshttps://github.com/QAX-A-Team/BrowserGhost11N/AN/A101014142062022-05-21T14:09:45Z2020-06-12T12:19:06Z5819
758*/BrowserGhost/releases/download/*.{0,1000}\/BrowserGhost\/releases\/download\/.{0,1000}offensive_tool_keywordBrowserGhostThis is a tool for grabbing browser passwordsT1555.003 - T1555.013 - T1003.008TA0006N/AN/ACredential Accesshttps://github.com/QAX-A-Team/BrowserGhost11N/AN/A101014142062022-05-21T14:09:45Z2020-06-12T12:19:06Z5820
759*/BrowserGhost/tarball/*.{0,1000}\/BrowserGhost\/tarball\/.{0,1000}offensive_tool_keywordBrowserGhostThis is a tool for grabbing browser passwordsT1555.003 - T1555.013 - T1003.008TA0006N/AN/ACredential Accesshttps://github.com/QAX-A-Team/BrowserGhost11N/AN/A101014142062022-05-21T14:09:45Z2020-06-12T12:19:06Z5821
760*/BrowserGhost/zipball/*.{0,1000}\/BrowserGhost\/zipball\/.{0,1000}offensive_tool_keywordBrowserGhostThis is a tool for grabbing browser passwordsT1555.003 - T1555.013 - T1003.008TA0006N/AN/ACredential Accesshttps://github.com/QAX-A-Team/BrowserGhost11N/AN/A101014142062022-05-21T14:09:45Z2020-06-12T12:19:06Z5822
761*/Bruteforcer.*.{0,1000}\/Bruteforcer\..{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus11N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z5833
762*/brutespray.git*.{0,1000}\/brutespray\.git.{0,1000}offensive_tool_keywordbrutesprayBruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.T1110TA0001 - TA0043N/AN/ACredential Accesshttps://github.com/x90skysn3k/brutespray11N/AN/A101022314052025-04-21T03:17:20Z2017-04-05T17:05:10Z5842
763*/brutespray/*.{0,1000}\/brutespray\/.{0,1000}offensive_tool_keywordbrutesprayBruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.T1110TA0001 - TA0043N/AN/ACredential Accesshttps://github.com/x90skysn3k/brutespray11N/AN/A101022314052025-04-21T03:17:20Z2017-04-05T17:05:10Z5843
764*/brutespray/*.{0,1000}\/brutespray\/.{0,1000}offensive_tool_keywordwordlistspackage contains the rockyou.txt wordlistT1110.001TA0006N/AN/ACredential Accesshttps://www.kali.org/tools/wordlists/11N/AN/AN/AN/AN/AN/AN/AN/A5844
765*/brutespray_*.{0,1000}\/brutespray_.{0,1000}offensive_tool_keywordbrutesprayBruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap.T1110TA0001 - TA0043N/AN/ACredential Accesshttps://github.com/x90skysn3k/brutespray11N/AN/A101022314052025-04-21T03:17:20Z2017-04-05T17:05:10Z5845
766*/BypassCredGuard.cpp*.{0,1000}\/BypassCredGuard\.cpp.{0,1000}offensive_tool_keywordBypassCredGuardCredential Guard Bypass Via Patching Wdigest MemoryT1003 - T1112 - T1555.002 - T1574TA0006 - TA0005 - TA0040N/AN/ACredential Accesshttps://github.com/wh0amitz/BypassCredGuard11N/AN/A104323522023-02-03T06:55:43Z2023-01-18T15:16:11Z5880
767*/BypassCredGuard.exe*.{0,1000}\/BypassCredGuard\.exe.{0,1000}offensive_tool_keywordBypassCredGuardCredential Guard Bypass Via Patching Wdigest MemoryT1003 - T1112 - T1555.002 - T1574TA0006 - TA0005 - TA0040N/AN/ACredential Accesshttps://github.com/wh0amitz/BypassCredGuard11N/AN/A104323522023-02-03T06:55:43Z2023-01-18T15:16:11Z5881
768*/BypassCredGuard.git*.{0,1000}\/BypassCredGuard\.git.{0,1000}offensive_tool_keywordBypassCredGuardCredential Guard Bypass Via Patching Wdigest MemoryT1003 - T1112 - T1555.002 - T1574TA0006 - TA0005 - TA0040N/AN/ACredential Accesshttps://github.com/wh0amitz/BypassCredGuard11N/AN/A104323522023-02-03T06:55:43Z2023-01-18T15:16:11Z5882
769*/c ping 127.0.0.1 && del \\*.{0,1000}\/c\sping\s127\.0\.0\.1\s\&\&\sdel\s\\\\.{0,1000}offensive_tool_keywordPredatorTheStealerC++ stealer (passwords - cookies - forms - cards - wallets) T1078 - T1114 - T1555 - T1539 - T1212 - T1132TA0006 - TA0010N/AN/ACredential Accesshttps://github.com/SecUser1/PredatorTheStealer10N/AN/A811122022-12-06T16:46:33Z2022-12-06T16:34:43Z5890
770*/cached-domain-credentials.html*.{0,1000}\/cached\-domain\-credentials\.html.{0,1000}offensive_tool_keywordsecretsdumpsecretdump.py from impacket - https://github.com/fortra/impacketT1003.003TA0006Operation WocaoBlack Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITECredential Accesshttps://github.com/fortra/impacket10N/AN/A10101419836812025-04-22T13:40:55Z2015-04-15T14:04:07Z5936
771*/cachedump.py*.{0,1000}\/cachedump\.py.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump711N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z5937
772*/cain.html*.{0,1000}\/cain\.html.{0,1000}offensive_tool_keywordCain&AbelCain & Able exploitation tool file T1075 - T1110 - T1071 - T1003 - T1555TA0003 - TA0008N/AFIN7 - Night DragonCredential Accesshttps://github.com/undergroundwires/CEH-in-bullet-points/blob/master/chapters/08-sniffing/sniffing-tools.md11N/AN/AN/A1010673102024-08-13T04:35:50Z2021-05-11T12:38:17Z5940
773*/CapBypass.ps1*.{0,1000}\/CapBypass\.ps1.{0,1000}offensive_tool_keywordTokenTacticsAzure JWT Token Manipulation ToolsetT1134.002 - T1078.004 - T1095TA0005 - TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/rvrsh3ll/TokenTactics10N/AN/A676521052024-12-06T15:51:42Z2021-07-08T02:28:12Z5952
774*/cerbrutus*.{0,1000}\/cerbrutus.{0,1000}offensive_tool_keywordcerbrutusNetwork brute force tool. written in Python. Faster than other existing solutions (including the main leader in the network brute force market).T1110 - T1040 - T1496TA0006 - TA0008 - TA0009N/AN/ACredential Accesshttps://github.com/Cerbrutus-BruteForcer/cerbrutus11N/AN/AN/A4385572021-08-22T19:05:45Z2021-07-07T19:11:40Z5972
775*/certsync.git*.{0,1000}\/certsync\.git.{0,1000}offensive_tool_keywordcertsyncDump NTDS with golden certificates and UnPAC the hashT1553.002 - T1003.001 - T1145 - T1649TA0002 - TA0003 - TA0006N/AN/ACredential Accesshttps://github.com/zblurx/certsync11N/AN/A107633662024-03-20T10:58:15Z2023-01-31T15:37:12Z5982
776*/cheetah.git*.{0,1000}\/cheetah\.git.{0,1000}offensive_tool_keywordcheetaha very fast brute force webshell password toolT1110 - T1190 - T1505.003TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/shmilylty/cheetah11N/AN/A1076301502023-04-17T01:33:52Z2017-04-15T20:03:50Z6004
777*/cheetah.py*.{0,1000}\/cheetah\.py.{0,1000}offensive_tool_keywordcheetaha very fast brute force webshell password toolT1110 - T1190 - T1505.003TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/shmilylty/cheetah10#linuxN/A1076301502023-04-17T01:33:52Z2017-04-15T20:03:50Z6005
778*/chntpw -*.{0,1000}\/chntpw\s\-.{0,1000}offensive_tool_keywordchntpwreset a password on your systemT1003 - T1078TA0006N/AN/ACredential Accesshttps://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip10#linuxN/A1010N/AN/AN/AN/A6021
779*/chntpw-140201*.{0,1000}\/chntpw\-140201.{0,1000}offensive_tool_keywordchntpwreset a password on your systemT1003 - T1078TA0006N/AN/ACredential Accesshttps://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip11N/AN/A1010N/AN/AN/AN/A6022
780*/chrome_creditcard.csv*.{0,1000}\/chrome_creditcard\.csv.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData10#linuxN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z6023
781*/chrome_creditcard.json*.{0,1000}\/chrome_creditcard\.json.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData10#linuxN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z6024
782*/chrome_decrypt.exe*.{0,1000}\/chrome_decrypt\.exe.{0,1000}offensive_tool_keywordChrome-App-Bound-Encryption-DecryptionTool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protectionsT1003 - T1081 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption11N/AN/A95401732025-04-22T08:30:00Z2024-10-27T11:28:35Z6025
783*/chrome_decrypt.py*.{0,1000}\/chrome_decrypt\.py.{0,1000}offensive_tool_keyworddonpapiDumping DPAPI credentials remotelyT1003.006 - T1021.001TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/login-securite/DonPAPI11N/AN/AN/A1011101302025-03-24T10:23:58Z2021-09-27T09:12:51Z6026
784*/chrome_password.csv*.{0,1000}\/chrome_password\.csv.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData10#linuxN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z6027
785*/chrome_password.json*.{0,1000}\/chrome_password\.json.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData10#linuxN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z6028
786*/Chrome-App-Bound-Encryption-Decryption.git*.{0,1000}\/Chrome\-App\-Bound\-Encryption\-Decryption\.git.{0,1000}offensive_tool_keywordChrome-App-Bound-Encryption-DecryptionTool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protectionsT1003 - T1081 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption11N/AN/A95401732025-04-22T08:30:00Z2024-10-27T11:28:35Z6029
787*/ChromeDump/*.{0,1000}\/ChromeDump\/.{0,1000}offensive_tool_keywordchromedumpChromeDump is a small tool to dump all JavaScript and other ressources going through the browserT1059.007 - T1114.001 - T1518.001 - T1552.002TA0005 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/g4l4drim/ChromeDump11N/AN/AN/A15512024-10-12T14:07:36Z2023-01-26T20:44:06Z6031
788*/ChromeKatz.git*.{0,1000}\/ChromeKatz\.git.{0,1000}offensive_tool_keywordChromeKatzDump cookies directly from Chrome process memoryT1555.003 - T1003TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Meckazin/ChromeKatz11N/AN/A101011711152024-11-26T12:53:22Z2023-12-07T22:27:06Z6032
789*/ChromeStealer.git*.{0,1000}\/ChromeStealer\.git.{0,1000}offensive_tool_keywordChromeStealerextract and decrypt stored passwords from Google ChromeT1555.003 - T1003.001 - T1552.001TA0006 N/AN/ACredential Accesshttps://github.com/BernKing/ChromeStealer11N/AN/A82145182024-07-25T08:27:10Z2024-07-14T13:27:30Z6035
790*/chromium_based_browsers.py*.{0,1000}\/chromium_based_browsers\.py.{0,1000}offensive_tool_keywordBrowser-password-stealerThis python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above!T1003.002 - T1056.001TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/henry-richard7/Browser-password-stealer11N/AN/A105423622024-07-12T10:30:42Z2020-09-15T09:23:56Z6036
791*/cme smb *.{0,1000}\/cme\ssmb\s.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10#linuxN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z6112
792*/cme winrm *.{0,1000}\/cme\swinrm\s.{0,1000}offensive_tool_keywordcrackmapexeccrackmapexec command lines. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec10#linuxN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z6113
793*/cmedb.{0,1000}\/cmedboffensive_tool_keywordcrackmapexecwindows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral moveT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec11N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z6117
794*/comsvcs_stealth.py*.{0,1000}\/comsvcs_stealth\.py.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy11N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z6177
795*/crack.sh/get-cracking/*.{0,1000}\/\/crack\.sh\/get\-cracking\/.{0,1000}offensive_tool_keywordcrack.shcrack.sh THE WORLD???S FASTEST DES CRACKER. Used by attackers to submit passwords to crackT1110.002 - T1021.002TA0006 - TA0008N/AN/ACredential Accesshttps://crack.sh/get-cracking/11N/AN/AN/AN/AN/AN/AN/AN/A6212
796*/cracked-users.txt*.{0,1000}\/cracked\-users\.txt.{0,1000}offensive_tool_keywordautoNTDSautoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcatT1003 - T1059 - T1021.002 - T1213TA0006 - TA0008 - TA0005 - TA0002N/AN/ACredential Accesshttps://github.com/hmaverickadams/autoNTDS10N/AN/A102109142023-10-31T22:03:58Z2023-10-30T23:10:58Z6219
797*/cracklord.git*.{0,1000}\/cracklord\.git.{0,1000}offensive_tool_keywordcracklordQueue and resource system for cracking passwordsT1110 - T1201TA0006 - TA0002N/AN/ACredential Accesshttps://github.com/jmmcatee/cracklord11N/AN/A104388702022-09-22T09:30:14Z2013-12-09T23:10:54Z6220
798*/cracklord/cmd/*.{0,1000}\/cracklord\/cmd\/.{0,1000}offensive_tool_keywordcracklordQueue and resource system for cracking passwordsT1110 - T1201TA0006 - TA0002N/AN/ACredential Accesshttps://github.com/jmmcatee/cracklord11N/AN/A104388702022-09-22T09:30:14Z2013-12-09T23:10:54Z6221
799*/creddump7*.py*.{0,1000}\/creddump7.{0,1000}\.py.{0,1000}offensive_tool_keywordLaZagneThe LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001TA0006 - TA0009N/AAkira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONTCredential Accesshttps://github.com/AlessandroZ/LaZagne11N/AN/A1010994120622025-04-10T14:24:35Z2015-02-16T14:10:02Z6239
800*/creddump7.git*.{0,1000}\/creddump7\.git.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump711N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z6240
801*/creddump7.git*.{0,1000}\/creddump7\.git.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump711N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z6241
802*/creddump7/*.{0,1000}\/creddump7\/.{0,1000}offensive_tool_keyworddonpapiDumping DPAPI credentials remotelyT1003.006 - T1021.001TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/login-securite/DonPAPI11N/AN/AN/A1011101302025-03-24T10:23:58Z2021-09-27T09:12:51Z6242
803*/creddump7/releases/*.{0,1000}\/creddump7\/releases\/.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump711N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z6244
804*/credentials/SudoSnatch*.{0,1000}\/credentials\/SudoSnatch.{0,1000}offensive_tool_keywordsudoSnatchsudoSnatch payload grabs sudo password in plain text and imediately after target uses sudo command and sends it back to attacker remotely/locally.T1552.001 - T1056.001 - T1071.001TA0006 - TA0004 - TA0010N/AN/ACredential Accesshttps://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SudoSnatch11#linuxN/A10109043102024-09-14T02:34:26Z2021-09-08T20:33:18Z6251
805*/credentials/wifigrabber*.{0,1000}\/credentials\/wifigrabber.{0,1000}offensive_tool_keywordwifigrabbergrab wifi password and exfiltrate to a given siteT1056.005 - T1552.001 - T1119 - T1071.001TA0004 - TA0006 - TA0010 - TA0040N/AN/ACredential Accesshttps://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber11N/AN/A10109043102024-09-14T02:34:26Z2021-09-08T20:33:18Z6252
806*/CredMaster.git*.{0,1000}\/CredMaster\.git.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster11N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z6257
807*/credmaster.py*.{0,1000}\/credmaster\.py.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster11N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z6258
808*/credmaster.txt*.{0,1000}\/credmaster\.txt.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10#linuxN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z6259
809*/CredMaster-master.zip*.{0,1000}\/CredMaster\-master\.zip.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster11N/AN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z6260
810*/credmaster-success.txt*.{0,1000}\/credmaster\-success\.txt.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10#linuxN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z6261
811*/credmaster-validusers.txt*.{0,1000}\/credmaster\-validusers\.txt.{0,1000}offensive_tool_keywordCredMasterCredKing password spraying tool - uses FireProx APIs to rotate IP addressesT1110.003 - T1596 - T1071.004 - T1621TA0006 - TA0043N/AN/ACredential Accesshttps://github.com/knavesec/CredMaster10#linuxN/A91010701422025-03-19T20:36:21Z2020-09-25T20:57:42Z6262
812*/CredPhisher.exe*.{0,1000}\/CredPhisher\.exe.{0,1000}offensive_tool_keywordCredphisherprompt a user for credentials using a Windows credential dialogT1056.002 - T1003 TA0006N/AN/ACredential Accesshttps://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher11N/AN/A72136342024-10-18T12:12:38Z2021-04-12T00:00:03Z6264
813*/creds-*/creds.zip*.{0,1000}\/creds\-.{0,1000}\/creds\.zip.{0,1000}offensive_tool_keywordDefaultCreds-cheat-sheetOne place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default passwordT1110.001 - T1110.003TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/ihebski/DefaultCreds-cheat-sheet11N/AN/AN/A1060487262025-04-15T13:13:19Z2021-01-01T19:02:36Z6268
814*/crunch-wordlist/*.{0,1000}\/crunch\-wordlist\/.{0,1000}offensive_tool_keywordcrunchGenerate a dictionary file containing words with a minimum and maximum lengthT1596 - T1596.001TA0043N/AN/ACredential Accesshttps://sourceforge.net/projects/crunch-wordlist/11N/AN/AN/AN/AN/AN/AN/AN/A6298
815*/cstealer.git*.{0,1000}\/cstealer\.git.{0,1000}offensive_tool_keywordcstealerstealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/can-kat/cstealer11N/AN/A10N/A6322
816*/cstealer.py*.{0,1000}\/cstealer\.py.{0,1000}offensive_tool_keywordcstealerstealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python.T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/can-kat/cstealer11N/AN/A10N/A6323
817*/dafthack/MSOLSpray*.{0,1000}\/dafthack\/MSOLSpray.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray11N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z6396
818*/DanMcInerney/ridenum*.{0,1000}\/DanMcInerney\/ridenum.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker10#linuxN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z6400
819*/DarkCoderSc/*.{0,1000}\/DarkCoderSc\/.{0,1000}offensive_tool_keywordwin-brute-logonBruteforce cracking tool for windows usersT1110 - T1110.001 - T1110.002TA0008 - TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/DarkCoderSc/win-brute-logon11N/AN/AN/A1011381912023-11-09T10:37:58Z2020-05-14T21:46:50Z6406
820*/DCSyncer.git*.{0,1000}\/DCSyncer\.git.{0,1000}offensive_tool_keywordDCSyncerPerform DCSync operationT1003.006TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/notsoshant/DCSyncer11N/AN/A102143222024-11-05T20:03:27Z2020-06-06T17:20:22Z6472
821*/DCSyncer/releases/download/*.{0,1000}\/DCSyncer\/releases\/download\/.{0,1000}offensive_tool_keywordDCSyncerPerform DCSync operationT1003.006TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/notsoshant/DCSyncer11N/AN/A102143222024-11-05T20:03:27Z2020-06-06T17:20:22Z6473
822*/DCSyncer/tarball/*.{0,1000}\/DCSyncer\/tarball\/.{0,1000}offensive_tool_keywordDCSyncerPerform DCSync operationT1003.006TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/notsoshant/DCSyncer11N/AN/A102143222024-11-05T20:03:27Z2020-06-06T17:20:22Z6474
823*/DCSyncer/zipball/*.{0,1000}\/DCSyncer\/zipball\/.{0,1000}offensive_tool_keywordDCSyncerPerform DCSync operationT1003.006TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/notsoshant/DCSyncer11N/AN/A102143222024-11-05T20:03:27Z2020-06-06T17:20:22Z6475
824*/DeathStar/DeathStar.py*.{0,1000}\/DeathStar\/DeathStar\.py.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker10#linuxN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z6484
825*/decipher_mremoteng.iml*.{0,1000}\/decipher_mremoteng\.iml.{0,1000}offensive_tool_keywordmRemoteNG-DecryptPython script to decrypt passwords stored by mRemoteNGT1555.003 - T1110.003 - T1003 - T1081TA0006 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/kmahyyg/mremoteng-decrypt11N/AN/A8183212022-10-29T16:02:26Z2019-05-11T09:09:49Z6488
826*/DecryptAutoLogon.exe*.{0,1000}\/DecryptAutoLogon\.exe.{0,1000}offensive_tool_keywordDecryptAutoLogonCommand line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogonT1003.001 - T1555.003 - T1003.006TA0006N/AN/ACredential Accesshttps://github.com/securesean/DecryptAutoLogon11N/AN/A103218322020-12-05T16:14:28Z2020-12-03T20:38:59Z6490
827*/DecryptAutoLogon.git*.{0,1000}\/DecryptAutoLogon\.git.{0,1000}offensive_tool_keywordDecryptAutoLogonCommand line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogonT1003.001 - T1555.003 - T1003.006TA0006N/AN/ACredential Accesshttps://github.com/securesean/DecryptAutoLogon11N/AN/A103218322020-12-05T16:14:28Z2020-12-03T20:38:59Z6491
828*/decrypt-chrome-passwords*.{0,1000}\/decrypt\-chrome\-passwords.{0,1000}offensive_tool_keyworddecrypt-chrome-passwordsA simple program to decrypt chrome password saved on your machine.T1555.003 - T1112 - T1056.001TA0006 - TA0009 - TA0040N/AN/ACredential Accesshttps://github.com/ohyicong/decrypt-chrome-passwords11N/AN/A10109662112024-07-31T14:08:55Z2020-12-28T15:11:12Z6492
829*/decrypted.dmp*.{0,1000}\/decrypted\.dmp.{0,1000}offensive_tool_keywordPPLBladeProtected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk.T1003.001 - T1027.004 - T1560.001 - T1039 - T1570TA0006 - TA0005 - TA0010 - TA0003N/AN/ACredential Accesshttps://github.com/tastypepperoni/PPLBlade10N/AN/A106545592023-08-30T07:59:51Z2023-08-29T19:36:04Z6493
830*/decrypting-lsa-secrets.html*.{0,1000}\/decrypting\-lsa\-secrets\.html.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore11N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z6494
831*/decrypting-lsa-secrets.html*.{0,1000}\/decrypting\-lsa\-secrets\.html.{0,1000}offensive_tool_keywordsecretsdumpsecretdump.py from impacket - https://github.com/fortra/impacketT1003.003TA0006Operation WocaoBlack Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITECredential Accesshttps://github.com/fortra/impacket10N/AN/A10101419836812025-04-22T13:40:55Z2015-04-15T14:04:07Z6496
832*/Decrypt-RDCMan.ps1*.{0,1000}\/Decrypt\-RDCMan\.ps1.{0,1000}offensive_tool_keywordDecrypt-RDCMandecrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPIT1003 - T1552 - T1081 - T1027TA0006 - TA0008 - TA0005N/AN/ACredential Accesshttps://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps111N/AN/A91112016-12-01T14:06:24Z2017-11-22T23:18:39Z6497
833*/DecryptRDCManager.git*.{0,1000}\/DecryptRDCManager\.git.{0,1000}offensive_tool_keywordDecryptRDCManagerdecrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPIT1003 - T1552 - T1081 - T1027TA0006 - TA0008 - TA0005N/AN/ACredential Accesshttps://github.com/mez-0/DecryptRDCManager11N/AN/A817372020-09-29T10:12:58Z2020-09-29T08:53:46Z6498
834*/DecryptTeamViewer.exe*.{0,1000}\/DecryptTeamViewer\.exe.{0,1000}offensive_tool_keywordDecryptTeamViewerEnumerate and decrypt TeamViewer credentials from Windows registryT1552.001 - T1003 - T1119 - T1012TA0006 - TA0007 - TA0008N/AN/ACredential Accesshttps://github.com/V1V1/DecryptTeamViewer11N/AN/A73241622021-12-05T09:19:56Z2020-02-07T07:50:47Z6500
835*/DecryptTeamViewer.git*.{0,1000}\/DecryptTeamViewer\.git.{0,1000}offensive_tool_keywordDecryptTeamViewerEnumerate and decrypt TeamViewer credentials from Windows registryT1552.001 - T1003 - T1119 - T1012TA0006 - TA0007 - TA0008N/AN/ACredential Accesshttps://github.com/V1V1/DecryptTeamViewer11N/AN/A73241622021-12-05T09:19:56Z2020-02-07T07:50:47Z6501
836*/DefaultCreds_db.json*.{0,1000}\/DefaultCreds_db\.json.{0,1000}offensive_tool_keywordDefaultCreds-cheat-sheetOne place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default passwordT1110.001 - T1110.003TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/ihebski/DefaultCreds-cheat-sheet11N/AN/AN/A1060487262025-04-15T13:13:19Z2021-01-01T19:02:36Z6508
837*/DelegationBOF/*.{0,1000}\/DelegationBOF\/.{0,1000}offensive_tool_keywordDelegationBOFThis tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks.T1098 - T1214 - T1552TA0006N/AN/ACredential Accesshttps://github.com/IcebreakerSecurity/DelegationBOF11N/AN/AN/A10141232022-05-04T14:00:36Z2022-03-28T20:14:24Z6521
838*/dementor.py*.{0,1000}\/dementor\.py.{0,1000}offensive_tool_keywordNetNTLMtoSilverTicketObtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket.T1110.001 - T1558.003 - T1558.004TA0006 - TA0008 - TA0002N/AN/ACredential Accesshttps://github.com/NotMedic/NetNTLMtoSilverTicket11N/AN/A1098421132021-07-26T15:16:20Z2019-01-14T15:32:27Z6525
839*/dicassassin.7z*.{0,1000}\/dicassassin\.7z.{0,1000}offensive_tool_keywordweakpassWeakpass collection of tools for bruteforce and hashcrackingT1110 - T1201TA0006 - TA0002N/ABlack BastaCredential Accesshttps://github.com/zzzteph/weakpass11N/AN/A106541552025-04-08T19:50:48Z2021-08-29T13:07:37Z6571
840*/dirbuster/*.{0,1000}\/dirbuster\/.{0,1000}offensive_tool_keywordwordlistspackage contains the rockyou.txt wordlistT1110.001TA0006N/AN/ACredential Accesshttps://www.kali.org/tools/wordlists/11N/AN/AN/AN/AN/AN/AN/AN/A6583
841*/Disable_defender.py*.{0,1000}\/Disable_defender\.py.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber11N/AN/A10N/A6603
842*/DitExplorer.git*.{0,1000}\/DitExplorer\.git.{0,1000}offensive_tool_keywordDitExplorerTool for viewing NTDS.ditT1003.003TA0006N/AN/ACredential Accesshttps://github.com/trustedsec/DitExplorer11N/AN/A102155132025-03-14T13:02:44Z2025-02-12T15:54:04Z6619
843*/DitExplorer/releases/download/*.{0,1000}\/DitExplorer\/releases\/download\/.{0,1000}offensive_tool_keywordDitExplorerTool for viewing NTDS.ditT1003.003TA0006N/AN/ACredential Accesshttps://github.com/trustedsec/DitExplorer11N/AN/A102155132025-03-14T13:02:44Z2025-02-12T15:54:04Z6620
844*/DitExplorer/releases/tag/v*.{0,1000}\/DitExplorer\/releases\/tag\/v.{0,1000}offensive_tool_keywordDitExplorerTool for viewing NTDS.ditT1003.003TA0006N/AN/ACredential Accesshttps://github.com/trustedsec/DitExplorer11N/AN/A102155132025-03-14T13:02:44Z2025-02-12T15:54:04Z6621
845*/DitExplorer/tarball/*.{0,1000}\/DitExplorer\/tarball\/.{0,1000}offensive_tool_keywordDitExplorerTool for viewing NTDS.ditT1003.003TA0006N/AN/ACredential Accesshttps://github.com/trustedsec/DitExplorer11N/AN/A102155132025-03-14T13:02:44Z2025-02-12T15:54:04Z6622
846*/DitExplorer/zipball/*.{0,1000}\/DitExplorer\/zipball\/.{0,1000}offensive_tool_keywordDitExplorerTool for viewing NTDS.ditT1003.003TA0006N/AN/ACredential Accesshttps://github.com/trustedsec/DitExplorer11N/AN/A102155132025-03-14T13:02:44Z2025-02-12T15:54:04Z6623
847*/dllinject.py*.{0,1000}\/dllinject\.py.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy11N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z6640
848*/dnsspoof.c*.{0,1000}\/dnsspoof\.c.{0,1000}offensive_tool_keyworddsniffpassword sniffer. handles FTP. Telnet. SMTP. HTTP. POP. poppass. NNTP. IMAP. SNMP. LDAP. Rlogin. RIP. OSPF. PPTP MS-CHAP. NFS. VRRP. YP/NIS. SOCKS. X11. CVS. IRC. AIM. ICQ. Napster. PostgreSQL. Meeting Maker. Citrix ICA. Symantec pcAnywhere. NAI Sniffer. Microsoft SMB. Oracle SQL*Net. Sybase and Microsoft SQL auth info. dsniff automatically detects and minimally parses each application protocol. only saving the interesting bits. and uses Berkeley DB as its output file format. only logging unique authentication attempts. full TCP/IP reassembly is provided by libnids(3) (likewise for the following tools as well).T1110 - T1040 - T1074.001 - T1555.002 - T1555.003TA0001 - TA0002 - TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/tecknicaltom/dsniff10#linuxN/AN/A3208472010-06-29T05:53:39Z2010-06-23T13:11:11Z6696
849*/DomainPasswordSpray.git*.{0,1000}\/DomainPasswordSpray\.git.{0,1000}offensive_tool_keywordDomainPasswordSprayDomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain.T1110.001 - T1110.003TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/dafthack/DomainPasswordSpray11N/AN/A101018653882024-07-11T18:18:57Z2016-10-04T23:37:37Z6724
850*/domcachedump.py*.{0,1000}\/domcachedump\.py.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump711N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z6727
851*/DonPAPI.git*.{0,1000}\/DonPAPI\.git.{0,1000}offensive_tool_keyworddonpapiDumping DPAPI credentials remotelyT1003.006 - T1021.001TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/login-securite/DonPAPI11N/AN/AN/A1011101302025-03-24T10:23:58Z2021-09-27T09:12:51Z6734
852*/DonPAPI.py*.{0,1000}\/DonPAPI\.py.{0,1000}offensive_tool_keyworddonpapiDumping DPAPI credentials remotelyT1003.006 - T1021.001TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/login-securite/DonPAPI11N/AN/AN/A1011101302025-03-24T10:23:58Z2021-09-27T09:12:51Z6735
853*/download/LsassDumping/*.{0,1000}\/download\/LsassDumping\/.{0,1000}offensive_tool_keywordShadowDumperdump LSASS memoryT1003.001 - T1055TA0006 N/AN/ACredential Accesshttps://github.com/Offensive-Panda/ShadowDumper11N/AN/A106521832025-04-05T08:32:28Z2024-11-10T15:26:28Z6753
854*/download/pcunlocker*.{0,1000}\/download\/pcunlocker.{0,1000}greyware_tool_keywordpcunlockerReset and unlock forgotten Windows login passwordT1078TA0005 - TA0006 - TA0009N/AN/ACredential Accesshttps://www.pcunlocker.com/11N/AN/A1010N/AN/AN/AN/A6754
855*/dpat.py*.{0,1000}\/dpat\.py.{0,1000}offensive_tool_keywordDPATDomain Password Audit Tool for PentestersT1003 - T1087 - T1110 - T1555TA0006 - TA0004 - TA0002 - TA0005N/AN/ACredential Accesshttps://github.com/clr2of8/DPAT10N/AN/A10109541562022-06-24T21:41:43Z2016-11-22T22:00:21Z6779
856*/dploot.git*.{0,1000}\/dploot\.git.{0,1000}offensive_tool_keyworddplootDPAPI looting remotely in PythonT1003.006 - T1027 - T1110.004TA0006 - TA0007 - TA0010N/AN/ACredential Accesshttps://github.com/zblurx/dploot11N/AN/A105455582025-04-09T08:17:14Z2022-05-24T11:05:21Z6782
857*/DragonCastle.git*.{0,1000}\/DragonCastle\.git.{0,1000}offensive_tool_keywordDragonCastleA PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.T1003 - T1547.005 - T1055 - T1557TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/mdsecactivebreach/DragonCastle11N/AN/A103298382022-10-26T10:19:55Z2022-10-26T10:18:37Z6783
858*/DragonCastle.pdb*.{0,1000}\/DragonCastle\.pdb.{0,1000}offensive_tool_keywordDragonCastleA PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.T1003 - T1547.005 - T1055 - T1557TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/mdsecactivebreach/DragonCastle11N/AN/A103298382022-10-26T10:19:55Z2022-10-26T10:18:37Z6784
859*/dragoncastle.py*.{0,1000}\/dragoncastle\.py.{0,1000}offensive_tool_keywordDragonCastleA PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process.T1003 - T1547.005 - T1055 - T1557TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/mdsecactivebreach/DragonCastle11N/AN/A103298382022-10-26T10:19:55Z2022-10-26T10:18:37Z6785
860*/DriverDump.exe*.{0,1000}\/DriverDump\.exe.{0,1000}offensive_tool_keywordDriverDumpabusing the old process explorer driver to grab a privledged handle to lsass and then dump itT1543 - T1548 - T1562 - T1003 - T1569TA0005 - TA0003 - TA0004 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/trustedsec/The_Shelf11N/AN/A103247142024-11-25T19:33:34Z2024-05-22T14:31:52Z6790
861*/dsniff.c*.{0,1000}\/dsniff\.c.{0,1000}offensive_tool_keyworddsniffpassword sniffer. handles FTP. Telnet. SMTP. HTTP. POP. poppass. NNTP. IMAP. SNMP. LDAP. Rlogin. RIP. OSPF. PPTP MS-CHAP. NFS. VRRP. YP/NIS. SOCKS. X11. CVS. IRC. AIM. ICQ. Napster. PostgreSQL. Meeting Maker. Citrix ICA. SymantecpcAnywhere. NAI Sniffer. Microsoft SMB. Oracle SQL*Net. Sybase and Microsoft SQL auth info. dsniff automatically detects and minimally parses each application protocol. only saving the interesting bits. and uses Berkeley DB as its output file format. only logging unique authentication attempts. full TCP/IP reassembly is provided by libnids(3) (likewise for the following tools as well).T1110 - T1040 - T1074.001 - T1555.002 - T1555.003TA0001 - TA0002 - TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/tecknicaltom/dsniff10#linuxN/AN/A3208472010-06-29T05:53:39Z2010-06-23T13:11:11Z6806
862*/dsniff.services*.{0,1000}\/dsniff\.services.{0,1000}offensive_tool_keyworddsniffpassword sniffer. handles FTP. Telnet. SMTP. HTTP. POP. poppass. NNTP. IMAP. SNMP. LDAP. Rlogin. RIP. OSPF. PPTP MS-CHAP. NFS. VRRP. YP/NIS. SOCKS. X11. CVS. IRC. AIM. ICQ. Napster. PostgreSQL. Meeting Maker. Citrix ICA. Symantec pcAnywhere. NAI Sniffer. Microsoft SMB. Oracle SQL*Net. Sybase and Microsoft SQL auth info. dsniff automatically detects and minimally parses each application protocol. only saving the interesting bits. and uses Berkeley DB as its output file format. only logging unique authentication attempts. full TCP/IP reassembly is provided by libnids(3) (likewise for the following tools as well).T1110 - T1040 - T1074.001 - T1555.002 - T1555.003TA0001 - TA0002 - TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/tecknicaltom/dsniff10#linuxN/AN/A3208472010-06-29T05:53:39Z2010-06-23T13:11:11Z6807
863*/DUBrute.git*.{0,1000}\/DUBrute\.git.{0,1000}offensive_tool_keywordDUBruteRDP BruteforcerT1110TA0006N/AN/ACredential Accesshttps://github.com/ch0sys/DUBrute11N/AN/A10137282018-02-19T13:03:14Z2017-06-15T08:55:46Z6808
864*/DumpAADSyncCreds.git*.{0,1000}\/DumpAADSyncCreds\.git.{0,1000}offensive_tool_keywordDumpAADSyncCredsC# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database.T1555 - T1110TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/Hagrid29/DumpAADSyncCreds11N/AN/A1013932023-06-24T16:17:36Z2022-03-27T18:43:44Z6822
865*/dumper2020.git*.{0,1000}\/dumper2020\.git.{0,1000}offensive_tool_keyworddumper2020Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASST1003.001TA0006N/AN/ACredential Accesshttps://github.com/gitjdm/dumper202011N/AN/A1017652020-12-29T03:55:21Z2020-10-04T17:25:21Z6827
866*/dumper2020_exe*.{0,1000}\/dumper2020_exe.{0,1000}offensive_tool_keyworddumper2020Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASST1003.001TA0006N/AN/ACredential Accesshttps://github.com/gitjdm/dumper202011N/AN/A1017652020-12-29T03:55:21Z2020-10-04T17:25:21Z6828
867*/dumpert.py*.{0,1000}\/dumpert\.py.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy11N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z6830
868*/DumpIt.exe*.{0,1000}\/DumpIt\.exe.{0,1000}offensive_tool_keywordForensikeRemotely dump NT hashes through Windows Crash dumpsT1003TA0006N/AN/ACredential Accesshttps://github.com/bmarchev/Forensike11N/AN/A1012732024-10-29T00:13:50Z2024-02-01T13:52:55Z6832
869*/DumpLSASS.git*.{0,1000}\/DumpLSASS\.git.{0,1000}offensive_tool_keywordDumpLSASSLsass dumping tool - 50 ways of dumping lsassT1003.001 - T1055.001 - T1620TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/elementalsouls/DumpLSASS11N/AN/A1013352024-02-27T11:25:11Z2023-04-09T12:11:10Z6833
870*/Dump-Lsass.git*.{0,1000}\/Dump\-Lsass\.git.{0,1000}offensive_tool_keywordimpacketDump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems.T1021 - T1047 - T1055.011 - T1003TA0002 - TA0005 - TA0006N/ADispossessor - Black BastaCredential Accesshttps://github.com/kaluche/Dump-Lsass11N/AN/A101102019-11-14T18:15:26Z2019-11-20T20:26:27Z6834
871*/dump-lsass.py*.{0,1000}\/dump\-lsass\.py.{0,1000}offensive_tool_keywordimpacketDump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems.T1021 - T1047 - T1055.011 - T1003TA0002 - TA0005 - TA0006N/ADispossessor - Black BastaCredential Accesshttps://github.com/kaluche/Dump-Lsass11N/AN/A101102019-11-14T18:15:26Z2019-11-20T20:26:27Z6836
872*/dumpmethod/*.py.{0,1000}\/dumpmethod\/.{0,1000}\.pyoffensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy11N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z6837
873*/DumpNParse.exe*.{0,1000}\/DumpNParse\.exe.{0,1000}offensive_tool_keywordDumpNParseA Combination LSASS Dumper and LSASS ParserT1003.001TA0006N/AN/ACredential Accesshttps://github.com/icyguider/DumpNParse11N/AN/A102150242021-11-21T14:25:24Z2021-11-21T14:18:42Z6838
874*/DumpNParse.git*.{0,1000}\/DumpNParse\.git.{0,1000}offensive_tool_keywordDumpNParseA Combination LSASS Dumper and LSASS ParserT1003.001TA0006N/AN/ACredential Accesshttps://github.com/icyguider/DumpNParse11N/AN/A102150242021-11-21T14:25:24Z2021-11-21T14:18:42Z6839
875*/DumpS1.ps1*.{0,1000}\/DumpS1\.ps1.{0,1000}greyware_tool_keywordSentinelAgentdump a process with SentinelAgent.exeT1003 - T1055TA0006 - TA0005N/AN/ACredential Accesshttps://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e10N/AN/A87N/AN/AN/AN/A6841
876*/dumpSecrets.go*.{0,1000}\/dumpSecrets\.go.{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump11N/AN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z6842
877*/dumpsecrets_test.go*.{0,1000}\/dumpsecrets_test\.go.{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump11N/AN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z6843
878*/DumpShellcode/*.{0,1000}\/DumpShellcode\/.{0,1000}offensive_tool_keywordPPLFaultExploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process.T1055 - T1078 - T1112 - T1553 - T1555TA0001 - TA0002 - TA0003 - TA0005 - TA0011N/AN/ACredential Accesshttps://github.com/gabriellandau/PPLFault11N/AN/A106525822024-02-22T17:23:53Z2022-09-22T19:39:24Z6844
879*/DumpSvc.exe*.{0,1000}\/DumpSvc\.exe.{0,1000}offensive_tool_keywordPWDumpXPWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems.T1003.001 - T1555.003 - T1077TA0006 - TA0008N/AN/ACredential Accesshttps://packetstormsecurity.com/files/download/52580/PWDumpX.zip11N/AN/A108N/AN/AN/AN/A6846
880*/DumpThatLSASS.*.{0,1000}\/DumpThatLSASS\..{0,1000}offensive_tool_keywordDumpThatLSASSDumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the diskT1003 - T1055.011 - T1027 - T1564.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/peiga/DumpThatLSASS11N/AN/A10131792022-09-24T22:39:04Z2022-09-24T22:41:19Z6847
881*/DumpThatLSASS.git*.{0,1000}\/DumpThatLSASS\.git.{0,1000}offensive_tool_keywordDumpThatLSASSDumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the diskT1003 - T1055.011 - T1027 - T1564.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/peiga/DumpThatLSASS11N/AN/A10131792022-09-24T22:39:04Z2022-09-24T22:41:19Z6848
882*/DumpThatLSASS/*.{0,1000}\/DumpThatLSASS\/.{0,1000}offensive_tool_keywordDumpThatLSASSDumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the diskT1003 - T1055.011 - T1027 - T1564.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/peiga/DumpThatLSASS11N/AN/A10131792022-09-24T22:39:04Z2022-09-24T22:41:19Z6849
883*/dumpweb.log*.{0,1000}\/dumpweb\.log.{0,1000}offensive_tool_keywordchromedumpChromeDump is a small tool to dump all JavaScript and other ressources going through the browserT1059.007 - T1114.001 - T1518.001 - T1552.002TA0005 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/g4l4drim/ChromeDump11#logfile #linuxN/AN/A15512024-10-12T14:07:36Z2023-01-26T20:44:06Z6850
884*/dumpy.exe*.{0,1000}\/dumpy\.exe.{0,1000}offensive_tool_keywordDumpyReuse open handles to dynamically dump LSASST1003.001 - T1055.001 - T1083TA0006N/AN/ACredential Accesshttps://github.com/Kudaes/Dumpy11N/AN/A103243242024-04-04T07:42:26Z2021-10-13T21:54:59Z6853
885*/Dumpy.git*.{0,1000}\/Dumpy\.git.{0,1000}offensive_tool_keywordDumpyReuse open handles to dynamically dump LSASST1003.001 - T1055.001 - T1083TA0006N/AN/ACredential Accesshttps://github.com/Kudaes/Dumpy11N/AN/A103243242024-04-04T07:42:26Z2021-10-13T21:54:59Z6854
886*/EASSniper.git*.{0,1000}\/EASSniper\.git.{0,1000}offensive_tool_keywordEASSniperEASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)T1110 - T1078.003 - T1087.002 - T1059.001TA0006 -TA0007 - TA0009 - TA0002 - TA0001N/AN/ACredential Accesshttps://github.com/fugawi/EASSniper11N/AN/A101542018-04-17T23:23:31Z2018-04-17T22:43:51Z6871
887*/EASSniper.ps1*.{0,1000}\/EASSniper\.ps1.{0,1000}offensive_tool_keywordEASSniperEASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)T1110 - T1078.003 - T1087.002 - T1059.001TA0006 -TA0007 - TA0009 - TA0002 - TA0001N/AN/ACredential Accesshttps://github.com/fugawi/EASSniper11N/AN/A101542018-04-17T23:23:31Z2018-04-17T22:43:51Z6872
888*/EASSniper.ps1*.{0,1000}\/EASSniper\.ps1.{0,1000}offensive_tool_keywordOmnisprayModular Enumeration and Password Spraying FrameworkT1110 - T1078.003 - T1087.002 - T1621TA0001 - TA0002 - TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/0xZDH/Omnispray11N/AN/A102118192024-04-10T20:05:46Z2021-02-25T07:28:06Z6873
889*/eas-valid-users.txt*.{0,1000}\/eas\-valid\-users\.txt.{0,1000}offensive_tool_keywordEASSniperEASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS)T1110 - T1078.003 - T1087.002 - T1059.001TA0006 -TA0007 - TA0009 - TA0002 - TA0001N/AN/ACredential Accesshttps://github.com/fugawi/EASSniper10#linuxN/A101542018-04-17T23:23:31Z2018-04-17T22:43:51Z6874
890*/enum_av.py*.{0,1000}\/enum_av\.py.{0,1000}offensive_tool_keywordcrackmapexecA swiss army knife for pentesting networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec11N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z6955
891*/ETWHash/*.{0,1000}\/ETWHash\/.{0,1000}offensive_tool_keywordETWHashC# POC to extract NetNTLMv1/v2 hashes from ETW providerT1556.001TA0009 N/AN/ACredential Accesshttps://github.com/nettitude/ETWHash11N/AN/AN/A3256292023-05-10T06:45:06Z2023-04-26T15:53:01Z7046
892*/EvilLsassTwin*.{0,1000}\/EvilLsassTwin.{0,1000}offensive_tool_keywordEvilLsassTwinDumping lsassT1003 - T1560.001 - T1022 - T1027.002TA0005 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin11N/AN/A102151182024-12-23T05:06:31Z2022-09-13T12:42:13Z7080
893*/EvilLsassTwin/*.{0,1000}\/EvilLsassTwin\/.{0,1000}offensive_tool_keywordEvilLsassTwinattempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.T1003.001 - T1055 - T1093TA0006 - TA0005 - TA0002N/AN/ACredential Accesshttps://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin11N/AN/A92151182024-12-23T05:06:31Z2022-09-13T12:42:13Z7081
894*/EvilTwinServer*.{0,1000}\/EvilTwinServer.{0,1000}offensive_tool_keywordEvilLsassTwinattempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess.T1003.001 - T1055 - T1093TA0006 - TA0005 - TA0002N/AN/ACredential Accesshttps://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin11N/AN/A92151182024-12-23T05:06:31Z2022-09-13T12:42:13Z7094
895*/exported_credentials.csv*.{0,1000}\/exported_credentials\.csv.{0,1000}offensive_tool_keywordHEKATOMBHekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt themT1003 - T1555.002 - T1482 - T1087TA0006 - TA0005 - TA0007N/AN/ACredential Accesshttps://github.com/ProcessusT/HEKATOMB10#linuxN/A106510592024-07-31T19:05:30Z2022-09-09T15:07:15Z7149
896*/extpassword.zip*.{0,1000}\/extpassword\.zip.{0,1000}offensive_tool_keywordExtPassword.exeNirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computerT1081 - T1003 - T1212TA0006 - TA0009N/ALockBitCredential Accesshttps://www.nirsoft.net/utils/external_drive_password_recovery.html11N/AN/A1010N/AN/AN/AN/A7159
897*/ExtractBitlockerKeys.git*.{0,1000}\/ExtractBitlockerKeys\.git.{0,1000}offensive_tool_keywordExtractBitlockerKeysA system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.T1003.002 - T1039 - T1087.002TA0006 - TA0007 - TA0009N/AN/ACredential Accesshttps://github.com/p0dalirius/ExtractBitlockerKeys11N/AN/A104368542025-01-31T09:39:55Z2023-09-19T07:28:11Z7161
898*/fakelogonscreen.exe*.{0,1000}\/fakelogonscreen.{0,1000}offensive_tool_keywordfakelogonscreenFake Windows logon screen to steal passwordsT1056.002 - T1078 - T1110 - T1555TA0006 - TA0003 - TA0009N/AN/ACredential Accesshttps://github.com/bitsadmin/fakelogonscreen11N/AN/A101013252362020-02-03T23:28:01Z2020-02-01T18:51:35Z7169
899*/fakelogonscreen.git*.{0,1000}\/fakelogonscreen\.git.{0,1000}offensive_tool_keywordfakelogonscreenFake Windows logon screen to steal passwordsT1056.002 - T1078 - T1110 - T1555TA0006 - TA0003 - TA0009N/AN/ACredential Accesshttps://github.com/bitsadmin/fakelogonscreen11N/AN/A101013252362020-02-03T23:28:01Z2020-02-01T18:51:35Z7170
900*/fakelogonscreen/releases/download/*.{0,1000}\/fakelogonscreen\/releases\/download\/.{0,1000}offensive_tool_keywordfakelogonscreenFake Windows logon screen to steal passwordsT1056.002 - T1078 - T1110 - T1555TA0006 - TA0003 - TA0009N/AN/ACredential Accesshttps://github.com/bitsadmin/fakelogonscreen11N/AN/A101013252362020-02-03T23:28:01Z2020-02-01T18:51:35Z7171
901*/fakelogonscreen/tarball/*.{0,1000}\/fakelogonscreen\/tarball\/.{0,1000}offensive_tool_keywordfakelogonscreenFake Windows logon screen to steal passwordsT1056.002 - T1078 - T1110 - T1555TA0006 - TA0003 - TA0009N/AN/ACredential Accesshttps://github.com/bitsadmin/fakelogonscreen11N/AN/A101013252362020-02-03T23:28:01Z2020-02-01T18:51:35Z7172
902*/fakelogonscreen/zipball/*.{0,1000}\/fakelogonscreen\/zipball\/.{0,1000}offensive_tool_keywordfakelogonscreenFake Windows logon screen to steal passwordsT1056.002 - T1078 - T1110 - T1555TA0006 - TA0003 - TA0009N/AN/ACredential Accesshttps://github.com/bitsadmin/fakelogonscreen11N/AN/A101013252362020-02-03T23:28:01Z2020-02-01T18:51:35Z7173
903*/Farmer.git*.{0,1000}\/Farmer\.git.{0,1000}offensive_tool_keywordFarmerFarmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.T1557.001 - T1056.004 - T1078.003TA0006 - TA0004 - TA0001N/AN/ACredential Accesshttps://github.com/mdsecactivebreach/Farmer11N/AN/A104379612021-04-28T15:27:24Z2021-02-22T14:32:29Z7176
904*/fb_firstlast.7z*.{0,1000}\/fb_firstlast\.7z.{0,1000}offensive_tool_keywordwordlistsVarious wordlists FR & EN - Cracking French passwordsT1110.001TA0006N/AN/ACredential Accesshttps://github.com/clem9669/wordlists11N/AN/AN/A3280452025-04-22T14:34:10Z2020-10-21T14:37:53Z7179
905*/fb-brute.pl*.{0,1000}\/fb\-brute\.pl.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://raw.githubusercontent.com/Sup3r-Us3r/scripts/master/fb-brute.pl11N/AN/A710N/AN/AN/AN/A7180
906*/fern-wifi-cracker/*.{0,1000}\/fern\-wifi\-cracker\/.{0,1000}offensive_tool_keywordwordlistspackage contains the rockyou.txt wordlistT1110.001TA0006N/AN/ACredential Accesshttps://www.kali.org/tools/wordlists/11N/AN/AN/AN/AN/AN/AN/AN/A7184
907*/fgdump.git*.{0,1000}\/fgdump\.git.{0,1000}offensive_tool_keywordfgdumpA utility for dumping passwords on Windows NT/2000/XP/2003 machinesT1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008N/AVolt TyphoonCredential Accesshttps://github.com/ihamburglar/fgdump11N/AN/A101842012-01-14T19:05:42Z2015-10-11T17:08:47Z7189
908*/find_domain.sh*.{0,1000}\/find_domain\.sh.{0,1000}offensive_tool_keywordlyncsmasha collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations T1190 - T1087 - T1110TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/nyxgeek/lyncsmash11N/AN/A84337632024-10-01T11:22:01Z2016-05-20T04:32:41Z7202
909*/firefox_decrypt.git*.{0,1000}\/firefox_decrypt\.git.{0,1000}offensive_tool_keywordfirefox_decryptFirefox Decrypt is a tool to extract passwords from MozillaT1555.003 - T1112 - T1056.001TA0006 - TA0009 - TA0040N/AN/ACredential Accesshttps://github.com/unode/firefox_decrypt11N/AN/A101021723172024-11-08T13:52:34Z2014-01-17T13:25:02Z7210
910*/firefox_decrypt.py*.{0,1000}\/firefox_decrypt\.py.{0,1000}offensive_tool_keyworddonpapiDumping DPAPI credentials remotelyT1003.006 - T1021.001TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/login-securite/DonPAPI11N/AN/AN/A1011101302025-03-24T10:23:58Z2021-09-27T09:12:51Z7211
911*/Forensike.git*.{0,1000}\/Forensike\.git.{0,1000}offensive_tool_keywordForensikeRemotely dump NT hashes through Windows Crash dumpsT1003TA0006N/AN/ACredential Accesshttps://github.com/bmarchev/Forensike11N/AN/A1012732024-10-29T00:13:50Z2024-02-01T13:52:55Z7228
912*/Forensike.ps1*.{0,1000}\/Forensike\.ps1.{0,1000}offensive_tool_keywordForensikeRemotely dump NT hashes through Windows Crash dumpsT1003TA0006N/AN/ACredential Accesshttps://github.com/bmarchev/Forensike11N/AN/A1012732024-10-29T00:13:50Z2024-02-01T13:52:55Z7229
913*/forkatz.filters*.{0,1000}\/forkatz\.filters.{0,1000}offensive_tool_keywordforkatzcredential dump using foreshaw technique using SeTrustedCredmanAccessPrivilegeT1003.002 - T1558.002 - T1055.001TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/Barbarisch/forkatz11N/AN/A102124162021-05-22T00:23:04Z2021-05-21T18:42:22Z7235
914*/forkatz.git*.{0,1000}\/forkatz\.git.{0,1000}offensive_tool_keywordforkatzcredential dump using foreshaw technique using SeTrustedCredmanAccessPrivilegeT1003.002 - T1558.002 - T1055.001TA0006 - TA0004N/AN/ACredential Accesshttps://github.com/Barbarisch/forkatz11N/AN/A102124162021-05-22T00:23:04Z2021-05-21T18:42:22Z7236
915*/format:hashcat*.{0,1000}\/format\:hashcat.{0,1000}offensive_tool_keywordRubeusRubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist.T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004TA0006N/ABlack Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEARCredential Accesshttps://github.com/GhostPack/Rubeus10N/AN/A101044098042025-04-17T10:11:57Z2018-09-23T23:59:03Z7240
916*/FormThief.git*.{0,1000}\/FormThief\.git.{0,1000}offensive_tool_keywordFormThiefSpoofing desktop login applications with WinForms and WPFT1204.002 - T1056.004 - T1071.001TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/mlcsec/FormThief11N/AN/A82173312024-02-19T22:40:09Z2024-02-19T22:34:07Z7241
917*/Gemail-Hack.git*.{0,1000}\/Gemail\-Hack\.git.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/Ha3MrX/Gemail-Hack11N/AN/A71010624002024-01-17T15:12:44Z2018-04-19T13:48:41Z7346
918*/getlsasrvaddr.exe*.{0,1000}\/getlsasrvaddr\.exe.{0,1000}offensive_tool_keywordWCEmanipulates and extracts credentials through NTLM - Kerberos and Digest AuthenticationT1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/returnvar/wce11N/AN/A102109212019-09-15T05:26:40Z2019-01-10T04:10:48Z7372
919*/Get-NetNTLM.git*.{0,1000}\/Get\-NetNTLM\.git.{0,1000}offensive_tool_keywordGet-NetNTLMPowershell module to get the NetNTLMv2 hash of the current userT1110.003 - T1557.001 - T1040TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/elnerd/Get-NetNTLM11N/AN/A7193182022-07-05T20:55:33Z2019-02-11T23:09:54Z7373
920*/Get-NetNTLM.ps1*.{0,1000}\/Get\-NetNTLM\.ps1.{0,1000}offensive_tool_keywordGet-NetNTLMPowershell module to get the NetNTLMv2 hash of the current userT1110.003 - T1557.001 - T1040TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/elnerd/Get-NetNTLM11N/AN/A7193182022-07-05T20:55:33Z2019-02-11T23:09:54Z7374
921*/get-shucking.php*.{0,1000}\/get\-shucking\.php.{0,1000}offensive_tool_keywordShuckNTShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES)T1552.001 - T1555.003 - T1078.003TA0006 - TA0002 - TA0040N/AN/ACredential Accesshttps://github.com/yanncam/ShuckNT11N/AN/A1016992024-10-18T10:45:49Z2023-01-27T07:52:47Z7384
922*/GlobalUnProtect.git*.{0,1000}\/GlobalUnProtect\.git.{0,1000}offensive_tool_keywordGlobalUnProtectDecrypt GlobalProtect configuration and cookie files.T1552 - T1003 - T1555TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/rotarydrone/GlobalUnProtect11N/AN/A92147192024-09-10T20:19:24Z2024-09-04T15:31:52Z7526
923*/gMSADumper*.{0,1000}\/gMSADumper.{0,1000}offensive_tool_keywordgMSADumperLists who can read any gMSA password blobs and parses them if the current user has access.T1552.001 - T1003.001TA0006N/AN/ACredential Accesshttps://github.com/micahvandeusen/gMSADumper11N/AN/AN/A3274512024-02-12T02:15:32Z2021-04-10T00:15:24Z7532
924*/GMSAPasswordReader.git*.{0,1000}\/GMSAPasswordReader\.git.{0,1000}offensive_tool_keywordGMSAPasswordReaderReads the password blob from a GMSA account using LDAP and parses the values into hashes for re-use.T1003.004 - T1078.003 - T1059.006TA0006 - TA0004 - TA0002N/AN/ACredential Accesshttps://github.com/rvazarkar/GMSAPasswordReader11N/AN/A73219342023-02-17T14:37:40Z2020-01-19T19:06:20Z7537
925*/GoAWSConsoleSpray.git*.{0,1000}\/GoAWSConsoleSpray\.git.{0,1000}offensive_tool_keywordGoAWSConsoleSpraybrute-force AWS IAM Console credentials to discover valid logins for user accountsT1078 - T1110 - T1187 - T1110.001TA0006 - TA0007 - TA0003 - TA0001N/AN/ACredential Accesshttps://github.com/WhiteOakSecurity/GoAWSConsoleSpray11N/AN/A912952022-06-15T18:16:21Z2022-06-15T18:11:39Z7538
926*/gocrack.git*.{0,1000}\/gocrack\.git.{0,1000}offensive_tool_keywordgocrackGoCrack is a management frontend for password cracking tools written in GoT1110 - T1021.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/mandiant/gocrack11N/AN/A91012332422025-04-14T16:20:05Z2017-10-23T14:43:59Z7544
927*/gocrack/.hashcat*.{0,1000}\/gocrack\/\.hashcat.{0,1000}offensive_tool_keywordgocrackGoCrack is a management frontend for password cracking tools written in GoT1110 - T1021.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/mandiant/gocrack10#linuxN/A91012332422025-04-14T16:20:05Z2017-10-23T14:43:59Z7545
928*/gocrack/server*.{0,1000}\/gocrack\/server.{0,1000}offensive_tool_keywordgocrackGoCrack is a management frontend for password cracking tools written in GoT1110 - T1021.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/mandiant/gocrack10#linuxN/A91012332422025-04-14T16:20:05Z2017-10-23T14:43:59Z7546
929*/gocrack_server*.{0,1000}\/gocrack_server.{0,1000}offensive_tool_keywordgocrackGoCrack is a management frontend for password cracking tools written in GoT1110 - T1021.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/mandiant/gocrack10#linuxN/A91012332422025-04-14T16:20:05Z2017-10-23T14:43:59Z7547
930*/gocrack_worker*.{0,1000}\/gocrack_worker.{0,1000}offensive_tool_keywordgocrackGoCrack is a management frontend for password cracking tools written in GoT1110 - T1021.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/mandiant/gocrack10#linuxN/A91012332422025-04-14T16:20:05Z2017-10-23T14:43:59Z7548
931*/gocrack-1.0.zip*.{0,1000}\/gocrack\-1\.0\.zip.{0,1000}offensive_tool_keywordgocrackGoCrack is a management frontend for password cracking tools written in GoT1110 - T1021.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/mandiant/gocrack10#linuxN/A91012332422025-04-14T16:20:05Z2017-10-23T14:43:59Z7549
932*/GoldenGMSA.git*.{0,1000}\/GoldenGMSA\.git.{0,1000}offensive_tool_keywordGoldenGMSAGolenGMSA tool for working with GMSA passwordsT1003.004 - T1078.003 - T1059.006TA0006 - TA0004 - TA0002N/AN/ACredential Accesshttps://github.com/Semperis/GoldenGMSA11N/AN/A72144222024-04-11T07:51:57Z2022-02-03T10:32:05Z7567
933*/go-lsass.exe*.{0,1000}\/go\-lsass\.exe.{0,1000}offensive_tool_keywordgo-lsassdumping LSASS process remotelyT1003 - T1055 - T1021.005TA0006 - TA0008 - TA0009N/AN/ACredential Accesshttps://github.com/jfjallid/go-lsass11N/AN/A913852024-07-27T10:35:12Z2023-11-30T18:45:51Z7571
934*/go-lsass.git*.{0,1000}\/go\-lsass\.git.{0,1000}offensive_tool_keywordgo-lsassdumping LSASS process remotelyT1003 - T1055 - T1021.005TA0006 - TA0008 - TA0009N/AN/ACredential Accesshttps://github.com/jfjallid/go-lsass11N/AN/A913852024-07-27T10:35:12Z2023-11-30T18:45:51Z7572
935*/go-lsass/releases*.{0,1000}\/go\-lsass\/releases.{0,1000}offensive_tool_keywordgo-lsassdumping LSASS process remotelyT1003 - T1055 - T1021.005TA0006 - TA0008 - TA0009N/AN/ACredential Accesshttps://github.com/jfjallid/go-lsass11N/AN/A913852024-07-27T10:35:12Z2023-11-30T18:45:51Z7573
936*/go-lsass-master.zip*.{0,1000}\/go\-lsass\-master\.zip.{0,1000}offensive_tool_keywordgo-lsassdumping LSASS process remotelyT1003 - T1055 - T1021.005TA0006 - TA0008 - TA0009N/AN/ACredential Accesshttps://github.com/jfjallid/go-lsass11N/AN/A913852024-07-27T10:35:12Z2023-11-30T18:45:51Z7574
937*/go-secdump.git*.{0,1000}\/go\-secdump\.git.{0,1000}offensive_tool_keywordgo-secdumpTool to remotely dump secrets from the Windows registryT1003.002 - T1012 - T1059.003TA0006 - TA0003 - TA0002N/AN/ACredential Accesshttps://github.com/jfjallid/go-secdump11N/AN/A105457512025-02-21T19:16:11Z2023-02-23T17:02:50Z7590
938*/gosecretsdump.*.{0,1000}\/gosecretsdump\..{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump11N/AN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z7592
939*/gosecretsdump/*.{0,1000}\/gosecretsdump\/.{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump11N/AN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z7593
940*/gosecretsdump_linux*.{0,1000}\/gosecretsdump_linux.{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump11#linuxN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z7594
941*/gosecretsdump_mac*.{0,1000}\/gosecretsdump_mac.{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump11N/AN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z7595
942*/gosecretsdump_win*.{0,1000}\/gosecretsdump_win.{0,1000}offensive_tool_keywordgosecretsdumpDump ntds.dit really fastT1003TA0006N/ALockbit - Black BastaCredential Accesshttps://github.com/C-Sto/gosecretsdump11N/AN/A104391502021-10-01T09:11:33Z2018-12-24T05:54:19Z7596
943*/gpp-decrypt*.{0,1000}\/gpp\-decrypt.{0,1000}offensive_tool_keywordgpp-decryptDecrypt the given Group Policy PreferencesT1552.002 - T1212TA0009 - TA0006N/AN/ACredential Accesshttps://gitlab.com/kalilinux/packages/gpp-decrypt11N/AN/A610N/AN/AN/AN/A7614
944*/grabchrome.exe*.{0,1000}\/grabchrome\.exe.{0,1000}offensive_tool_keywordGrabChromeHelloKitty Grabber used by Dispossessor ransomware groupT1003 - T1555 - T1081 - T1552TA0006N/ADispossessorCredential Accesshttps://vx-underground.org/Archive/Dispossessor%20Leaks11N/AN/A1010N/AN/AN/AN/A7616
945*/gsecdump-*.exe*.{0,1000}\/gsecdump\-.{0,1000}\.exe.{0,1000}offensive_tool_keywordgsecdumpcredential dumper used to obtain password hashes and LSA secrets from Windows operating systemsT1003.001 - T1003.002 - T1555.003 - T1555.001TA0006 - TA0008N/AAPT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - TickCredential Accesshttps://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe11N/AN/A1010N/AN/AN/AN/A7641
946*/gsecdump.exe*.{0,1000}\/gsecdump\.exe.{0,1000}offensive_tool_keywordgsecdumpcredential dumper used to obtain password hashes and LSA secrets from Windows operating systemsT1003.001 - T1003.002 - T1555.003 - T1555.001TA0006 - TA0008N/AAPT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - TickCredential Accesshttps://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe11N/AN/A1010N/AN/AN/AN/A7642
947*/HackBrowserData.git*.{0,1000}\/HackBrowserData\.git.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData11N/AN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z7692
948*/hack-browser-data-linux-386.zip*.{0,1000}\/hack\-browser\-data\-linux\-386\.zip.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData11#linuxN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z7693
949*/hack-browser-data-linux-amd64.zip*.{0,1000}\/hack\-browser\-data\-linux\-amd64\.zip.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData11#linuxN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z7694
950*/hack-browser-data-linux-arm.zip*.{0,1000}\/hack\-browser\-data\-linux\-arm\.zip.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData11#linuxN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z7695
951*/hack-browser-data-linux-arm64.zip*.{0,1000}\/hack\-browser\-data\-linux\-arm64\.zip.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData11#linuxN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z7696
952*/hack-browser-data-osx-64bit.zip*.{0,1000}\/hack\-browser\-data\-osx\-64bit\.zip.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData11N/AN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z7697
953*/hack-browser-data-windows-32bit.zip*.{0,1000}\/hack\-browser\-data\-windows\-32bit\.zip.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData11N/AN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z7698
954*/hack-browser-data-windows-64bit.zip*.{0,1000}\/hack\-browser\-data\-windows\-64bit\.zip.{0,1000}offensive_tool_keywordHackBrowserDataDecrypt passwords/cookies/history/bookmarks from the browserT1555.003 - T1552.001TA0006 - TA0009 - TA0010N/AN/ACredential Accesshttps://github.com/moonD4rk/HackBrowserData11N/AN/AN/A101221616562025-04-06T01:32:13Z2020-06-18T03:24:31Z7699
955*/hashcat-rule.git*.{0,1000}\/hashcat\-rule\.git.{0,1000}offensive_tool_keywordhashcat-ruleRule for hashcat or john. Aiming to crack how people generate their passwordT1110.002 - T1021.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/clem9669/hashcat-rule11#linuxN/A105435472024-09-02T20:14:15Z2020-03-06T17:20:40Z7727
956*/hashcrack_com.rb*.{0,1000}\/hashcrack_com\.rb.{0,1000}offensive_tool_keywordpwcrack-frameworkPassword Crack FrameworkT1110 - T1003 - T1059TA0006N/AN/ACredential Accesshttps://github.com/L-codes/pwcrack-framework11N/AN/A106515592024-02-25T13:08:56Z2018-07-01T08:33:55Z7728
957*/hashcracking.rb*.{0,1000}\/hashcracking\.rb.{0,1000}offensive_tool_keywordpwcrack-frameworkPassword Crack FrameworkT1110 - T1003 - T1059TA0006N/AN/ACredential Accesshttps://github.com/L-codes/pwcrack-framework11N/AN/A106515592024-02-25T13:08:56Z2018-07-01T08:33:55Z7729
958*/hashesorg2019.gz*.{0,1000}\/hashesorg2019\.gz.{0,1000}offensive_tool_keywordweakpassWeakpass collection of tools for bruteforce and hashcrackingT1110 - T1201TA0006 - TA0002N/ABlack BastaCredential Accesshttps://github.com/zzzteph/weakpass11N/AN/A106541552025-04-08T19:50:48Z2021-08-29T13:07:37Z7731
959*/hashview.py*.{0,1000}\/hashview\.py.{0,1000}offensive_tool_keywordhashviewA web front-end for password cracking and analyticsT1110 - T1201TA0006 - TA0002N/AN/ACredential Accesshttps://github.com/hashview/hashview11N/AN/A104373412025-02-20T18:23:25Z2020-11-23T19:21:06Z7733
960*/httprelayserver.py*.{0,1000}\/httprelayserver\.py.{0,1000}offensive_tool_keywordNtlmRelayToEWSntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS)T1212 - T1557 - T1040 - T1078TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/Arno0x/NtlmRelayToEWS11N/AN/A104331602018-01-15T12:48:02Z2017-10-13T18:00:50Z7917
961*/hydra -*.{0,1000}hydra\s\-.{0,1000}offensive_tool_keywordthc-hydraParallelized login cracker which supports numerous protocols to attack.T1110.001TA0006N/AALLANITE - BERSERK BEARCredential Accesshttps://github.com/vanhauser-thc/thc-hydra10#linuxN/AN/A101032621372025-04-04T12:19:05Z2014-04-24T14:45:37Z7990
962*/icebreaker.git*.{0,1000}\/icebreaker\.git.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker11N/AN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z8005
963*/icebreaker.py*.{0,1000}\/icebreaker\.py.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker11N/AN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z8006
964*/iepv.exe*.{0,1000}\/iepv\.exe.{0,1000}offensive_tool_keywordIEPassViewIE PassView scans all Internet Explorer passwords in your system and display them on the main window.T1555 - T1212TA0006N/ABlackSuit - Royal - GoGoogle - XDSpyCredential Accesshttps://www.nirsoft.net/utils/internet_explorer_password.html11N/AN/A1010N/AN/AN/AN/A8015
965*/ike-crack.*.{0,1000}\/ike\-crack\..{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/11N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z8023
966*/impacketfile.py*.{0,1000}\/impacketfile\.py.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy11N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z8038
967*/insta-bf.git*.{0,1000}\/insta\-bf\.git.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/samsesh/insta-bf11N/AN/A7159132024-04-23T02:47:28Z2020-11-20T22:22:48Z8094
968*/instabf.py*.{0,1000}\/instabf\.py.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/samsesh/insta-bf11N/AN/A7159132024-04-23T02:47:28Z2020-11-20T22:22:48Z8095
969*/instainsane.git*.{0,1000}\/instainsane\.git.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/umeshshinde19/instainsane11N/AN/A776553712024-02-11T10:29:05Z2018-12-02T22:48:11Z8097
970*/instainsane.sh*.{0,1000}\/instainsane\.sh.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/umeshshinde19/instainsane11N/AN/A776553712024-02-11T10:29:05Z2018-12-02T22:48:11Z8098
971*/install-sb.sh*.{0,1000}\/install\-sb\.sh.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/samsesh/SocialBox-Termux11N/AN/A71035813912024-09-02T19:15:22Z2019-03-28T18:07:05Z8102
972*/insTof.py*.{0,1000}\/insTof\.py.{0,1000}offensive_tool_keywordSocialBox-TermuxSocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on androidT1110.001 - T1110.003 - T1078.003TA0001 - TA0006 - TA0040N/AN/ACredential Accesshttps://github.com/samsesh/insta-bf11N/AN/A7159132024-04-23T02:47:28Z2020-11-20T22:22:48Z8104
973*/Invoke-CleverSpray.git*.{0,1000}\/Invoke\-CleverSpray\.git.{0,1000}offensive_tool_keywordInvoke-CleverSprayPassword Spraying Script detecting current and previous passwords of Active Directory UserT1110.003 - T1110.001TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/wavestone-cdt/Invoke-CleverSpray11N/AN/A10165112021-09-09T07:35:32Z2018-11-29T10:05:25Z8145
974*/Invoke-RDPThief.git*.{0,1000}\/Invoke\-RDPThief\.git.{0,1000}offensive_tool_keywordInvoke-RDPThiefperform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentialsT1055 - T1056 - T1071 - T1110TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/The-Viper-One/Invoke-RDPThief11N/AN/A1016282025-01-21T20:12:33Z2024-10-01T20:12:00Z8160
975*/john -*.{0,1000}\/john\s\-.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/10#linuxN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z8241
976*/john/run/*.pl*.{0,1000}\/john\/run\/.{0,1000}\.pl.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/11N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z8243
977*/john/run/*.py*.{0,1000}\/john\/run\/.{0,1000}\.py.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/11N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z8244
978*/JohnTheRipper*.{0,1000}\/JohnTheRipper.{0,1000}offensive_tool_keywordJohnTheRipperJohn the Ripper jumbo - advanced offline password crackerT1110 - T1003.001TA0006N/ABlack BastaCredential Accesshttps://github.com/openwall/john/11N/AN/AN/A101121622202025-04-22T11:24:06Z2011-12-16T19:43:47Z8246
979*/KeeFarce.exe*.{0,1000}\/KeeFarce\.exe.{0,1000}offensive_tool_keywordKeeFarceExtracts passwords from a KeePass 2.x database directly from memoryT1003 - T1055 - T1059TA0006 N/AN/ACredential Accesshttps://github.com/denandz/KeeFarce11N/AN/A101010091322015-11-17T04:12:25Z2015-10-27T05:29:04Z8297
980*/KeeFarce.git*.{0,1000}\/KeeFarce\.git.{0,1000}offensive_tool_keywordKeeFarceExtracts passwords from a KeePass 2.x database directly from memoryT1003 - T1055 - T1059TA0006 N/AN/ACredential Accesshttps://github.com/denandz/KeeFarce11N/AN/A101010091322015-11-17T04:12:25Z2015-10-27T05:29:04Z8298
981*/KeeFarceDLL.dll*.{0,1000}\/KeeFarceDLL\.dll.{0,1000}offensive_tool_keywordKeeFarceExtracts passwords from a KeePass 2.x database directly from memoryT1003 - T1055 - T1059TA0006 N/AN/ACredential Accesshttps://github.com/denandz/KeeFarce11N/AN/A101010091322015-11-17T04:12:25Z2015-10-27T05:29:04Z8299
982*/keepwn.core.*.{0,1000}\/keepwn\.core.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn10N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z8303
983*/KeePwn.git*.{0,1000}\/KeePwn\.git.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn11N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z8304
984*/KeePwn.py*.{0,1000}\/KeePwn\.py.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn11N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z8305
985*/keepwn.utils.*.{0,1000}\/keepwn\.utils.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn10N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z8306
986*/KeePwn/keepwn/*.{0,1000}\/KeePwn\/keepwn\/.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn11N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z8307
987*/KeePwn/tarball/*.{0,1000}\/KeePwn\/tarball\/.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn11N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z8308
988*/KeePwn/zipball/*.{0,1000}\/KeePwn\/zipball\/.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn11N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z8309
989*/KeePwn-0.3/*.{0,1000}\/KeePwn\-0\.3\/.{0,1000}offensive_tool_keywordKeePwnA python tool to automate KeePass discovery and secret extractionT1555 - T1003 - T1114TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Orange-Cyberdefense/KeePwn10N/AN/A105486472024-12-12T12:47:07Z2023-01-27T13:59:38Z8310
990*/KeeTheft.exe*.{0,1000}\/KeeTheft\.exe.{0,1000}offensive_tool_keywordKeethiefAllows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.T1003 - T1055 - T1059 - T1070TA0006 - TA0005 - TA0008N/AEvilCorp* - APT20Credential Accesshttps://github.com/GhostPack/KeeThief11N/AN/A10109441542020-11-18T18:35:21Z2016-07-10T19:11:23Z8312
991*/KeeThief.git*.{0,1000}\/KeeThief\.git.{0,1000}offensive_tool_keywordKeethiefAllows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.T1003 - T1055 - T1059 - T1070TA0006 - TA0005 - TA0008N/AEvilCorp* - APT20Credential Accesshttps://github.com/GhostPack/KeeThief11N/AN/A10109441542020-11-18T18:35:21Z2016-07-10T19:11:23Z8314
992*/KeeThief.git*.{0,1000}\/KeeThief\.git.{0,1000}offensive_tool_keywordKeeThiefSyscallsPatch GhostPack/KeeThief for it to use DInvoke and syscallsT1003.001 - T1558.002TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/Metro-Holografix/KeeThiefSyscalls11N/Aprivate github repo10N/A8315
993*/KeeThief.ps1*.{0,1000}\/KeeThief\.ps1.{0,1000}offensive_tool_keywordKeethiefAllows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system.T1003 - T1055 - T1059 - T1070TA0006 - TA0005 - TA0008N/AEvilCorp* - APT20Credential Accesshttps://github.com/GhostPack/KeeThief11N/AN/A10109441542020-11-18T18:35:21Z2016-07-10T19:11:23Z8316
994*/KerberOPSEC.git*.{0,1000}\/KerberOPSEC\.git.{0,1000}offensive_tool_keywordKerberOPSECOPSEC safe Kerberoasting in C#T1558.003TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/Luct0r/KerberOPSEC11N/AN/A102191212022-06-14T18:10:25Z2022-01-07T17:20:40Z8327
995*/kerberos.py*.{0,1000}\/kerberos\.py.{0,1000}offensive_tool_keywordcrackmapexecprotocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec11N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z8328
996*/kerberosticket.py*.{0,1000}\/kerberosticket\.py.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz11N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z8330
997*/kerbrute.git*.{0,1000}\/kerbrute\.git.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute11N/AN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z8333
998*/kerbrute.go*.{0,1000}\/kerbrute\.go.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute11N/AN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z8334
999*/kerbrute.py*.{0,1000}\/kerbrute\.py.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute11N/AN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z8335
1000*/kerbrute/*.{0,1000}\/kerbrute\/.{0,1000}offensive_tool_keywordkerbruteA tool to perform Kerberos pre-auth bruteforcingT1110.003 - T1558.001TA0006 - TA0001N/AN/ACredential Accesshttps://github.com/ropnop/kerbrute11N/AN/A101028724382024-08-20T10:56:06Z2019-02-03T18:21:17Z8336
1001*/KeyCredentialLink.git*.{0,1000}\/KeyCredentialLink\.git.{0,1000}offensive_tool_keywordKeyCredentialLinkAdd Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attributeT1098 - T1550TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/Leo4j/KeyCredentialLink11N/AN/A1012132024-06-05T13:44:39Z2024-06-05T13:19:49Z8339
1002*/KeyCredentialLink.ps1*.{0,1000}\/KeyCredentialLink\.ps1.{0,1000}offensive_tool_keywordKeyCredentialLinkAdd Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attributeT1098 - T1550TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/Leo4j/KeyCredentialLink11N/AN/A1012132024-06-05T13:44:39Z2024-06-05T13:19:49Z8340
1003*/Kill_protector.py*.{0,1000}\/Kill_protector\.py.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber11N/AN/A10N/A8357
1004*/knowsmore.cmd*.{0,1000}\/knowsmore\.cmd.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z8382
1005*/knowsmore.db*.{0,1000}\/knowsmore\.db.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore10N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z8383
1006*/knowsmore.git*.{0,1000}\/knowsmore\.git.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore11N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z8384
1007*/knowsmore.py*.{0,1000}\/knowsmore\.py.{0,1000}offensive_tool_keywordknowsmoreKnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync).T1003 - T1098 - T1134 - T1484 - T1178 - T1078TA0006 - TA0008 - TA0003 - TA0011 - TA0005N/ABlack BastaCredential Accesshttps://github.com/helviojunior/knowsmore11N/AN/A103223322025-04-14T14:52:09Z2023-01-09T14:02:37Z8385
1008*/label-date-lsass.dmp*.{0,1000}\/label\-date\-lsass\.dmp.{0,1000}offensive_tool_keywordphysmem2profitPhysmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotelyT1003.001TA0006N/AN/ACredential Accesshttps://github.com/WithSecureLabs/physmem2profit10#contentN/A105415742022-07-27T03:33:59Z2020-02-14T08:34:27Z8419
1009*/laps.py *--ldapserver*.{0,1000}\/laps\.py\s.{0,1000}\-\-ldapserver.{0,1000}offensive_tool_keywordLAPSDumperDumping LAPS from PythonT1136.001 - T1112 - T1078.001TA0002 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/n00py/LAPSDumper10N/AN/A103267352022-12-07T18:35:28Z2020-12-19T05:15:10Z8437
1010*/laps.py *-u * -p *.{0,1000}\/laps\.py\s.{0,1000}\-u\s.{0,1000}\s\-p\s.{0,1000}offensive_tool_keywordLAPSDumperDumping LAPS from PythonT1136.001 - T1112 - T1078.001TA0002 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/n00py/LAPSDumper10N/AN/A103267352022-12-07T18:35:28Z2020-12-19T05:15:10Z8438
1011*/LAPSDumper.git*.{0,1000}\/LAPSDumper\.git.{0,1000}offensive_tool_keywordLAPSDumperDumping LAPS from PythonT1136.001 - T1112 - T1078.001TA0002 - TA0004 - TA0005N/AN/ACredential Accesshttps://github.com/n00py/LAPSDumper11N/AN/A103267352022-12-07T18:35:28Z2020-12-19T05:15:10Z8441
1012*/lastpass.py*.{0,1000}\/lastpass\.py.{0,1000}offensive_tool_keyworddonpapiDumping DPAPI credentials remotelyT1003.006 - T1021.001TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/login-securite/DonPAPI11N/AN/AN/A1011101302025-03-24T10:23:58Z2021-09-27T09:12:51Z8447
1013*/LaZagne.git*.{0,1000}\/LaZagne\.git.{0,1000}offensive_tool_keywordLaZagneThe LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001TA0006 - TA0009N/AAkira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONTCredential Accesshttps://github.com/AlessandroZ/LaZagne11N/AN/A1010994120622025-04-10T14:24:35Z2015-02-16T14:10:02Z8458
1014*/laZagne.py*.{0,1000}\/laZagne\.py.{0,1000}offensive_tool_keywordLaZagneThe LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001TA0006 - TA0009N/AAkira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONTCredential Accesshttps://github.com/AlessandroZ/LaZagne11N/AN/A1010994120622025-04-10T14:24:35Z2015-02-16T14:10:02Z8459
1015*/LDAPWordlistHarvester.git*.{0,1000}\/LDAPWordlistHarvester\.git.{0,1000}offensive_tool_keywordLDAPWordlistHarvesterA tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts.T1210.001 - T1087.003 - T1110TA0001 - TA0006 - TA0007N/ABlack BastaCredential Accesshttps://github.com/p0dalirius/LDAPWordlistHarvester11N/AN/A54N/AN/AN/AN/A8483
1016*/legba.git*.{0,1000}\/legba\.git.{0,1000}offensive_tool_keywordlegbaA multiprotocol credentials bruteforcer / password sprayer and enumeratorT1110 - T1110.003 - T1110.001TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/evilsocket/legba11N/AN/A10101577932025-03-01T15:42:29Z2023-10-23T15:44:06Z8487
1017*/legba/target/release/legba*.{0,1000}\/legba\/target\/release\/legba.{0,1000}offensive_tool_keywordlegbaA multiprotocol credentials bruteforcer / password sprayer and enumeratorT1110 - T1110.003 - T1110.001TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/evilsocket/legba10#linuxN/A10101577932025-03-01T15:42:29Z2023-10-23T15:44:06Z8488
1018*/LetMeowIn.git*.{0,1000}\/LetMeowIn\.git.{0,1000}offensive_tool_keywordLetMeowInA sophisticated covert Windows-based credential dumper using C++ and MASM x64.T1003 - T1055.011 - T1148TA0006N/AN/ACredential Accesshttps://github.com/Meowmycks/LetMeowIn11N/AN/A105401702024-07-08T15:58:37Z2024-04-09T16:33:27Z8491
1019*/lgandx/Responder*.{0,1000}\/lgandx\/Responder.{0,1000}offensive_tool_keywordicebreakerGets plaintext Active Directory credentials if you're on the internal network but outside the AD environmentT1110.001 - T1110.003 - T1059.003TA0006 - TA0001 - TA0002N/AN/ACredential Accesshttps://github.com/DanMcInerney/icebreaker10#linuxN/A101011901632018-10-24T18:14:53Z2017-12-04T03:42:28Z8496
1020*/lnkbomb.git*.{0,1000}\/lnkbomb\.git.{0,1000}offensive_tool_keywordlnkbombMalicious shortcut generator for collecting NTLM hashes from insecure file shares.T1023.003 - T1557.002 - T1046TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/dievus/lnkbomb11N/AN/A104327582024-10-22T17:51:10Z2022-01-03T04:17:11Z8562
1021*/lnkbomb.py*.{0,1000}\/lnkbomb\.py.{0,1000}offensive_tool_keywordlnkbombMalicious shortcut generator for collecting NTLM hashes from insecure file shares.T1023.003 - T1557.002 - T1046TA0008 - TA0006N/AN/ACredential Accesshttps://github.com/dievus/lnkbomb11N/AN/A104327582024-10-22T17:51:10Z2022-01-03T04:17:11Z8563
1022*/load_ssp.x64.exe*.{0,1000}\/load_ssp\.x64\.exe.{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump11N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z8566
1023*/localbrute-extra-mini.ps1*.{0,1000}\/localbrute\-extra\-mini\.ps1.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorCredential Accesshttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools11N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z8583
1024*/loginAAD.ps1*.{0,1000}\/loginAAD\.ps1.{0,1000}offensive_tool_keywordTeamFiltrationTeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accountsT1110 - T1087 - T1560.001 - T1592 - T1071TA0001 - TA0003 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Flangvik/TeamFiltration10N/AN/A101011321282025-04-10T13:48:00Z2022-06-28T00:00:28Z8613
1025*/login-securite/DonPAPI*.{0,1000}\/login\-securite\/DonPAPI.{0,1000}offensive_tool_keyworddonpapiDumping DPAPI credentials remotelyT1003.006 - T1021.001TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/login-securite/DonPAPI11N/AN/AN/A1011101302025-03-24T10:23:58Z2021-09-27T09:12:51Z8614
1026*/logonuifox.dll*.{0,1000}\/logonuifox\.dll.{0,1000}offensive_tool_keywordThievingFoxcollection of post-exploitation tools to gather credentials from various password managersT1555 - T1003 - T1056 - T1070TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Slowerzs/ThievingFox11N/AN/A106535652024-03-28T19:58:03Z2024-01-20T23:22:52Z8616
1027*/lsadump.py*.{0,1000}\/lsadump\.py.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump711N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z8638
1028*/lsarelayx.git*.{0,1000}\/lsarelayx\.git.{0,1000}offensive_tool_keywordlsarelayxlsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running onT1557.001 - T1187 - T1558TA0001 - TA0006 - TA0008N/AN/ACredential Accesshttps://github.com/CCob/lsarelayx11N/AN/A106562692023-04-25T23:15:33Z2021-11-12T18:55:01Z8639
1029*/lsasecrets.py*.{0,1000}\/lsasecrets\.py.{0,1000}offensive_tool_keywordcreddump7extracts various forms of credentials from Windows systemsT1003 - T1081 - T1040 - T1110 - T1555TA0006 - TA0009N/ASandwormCredential Accesshttps://github.com/CiscoCXSecurity/creddump711N/AN/A1043941062020-10-02T13:25:16Z2014-06-24T13:18:38Z8640
1030*/lsass.DMP*.{0,1000}\/lsass\.DMP.{0,1000}offensive_tool_keywordpypykatzMimikatz implementation in pure PythonT1003.002 - T1055 - T1078TA0003 - TA0002 - TA0004N/ABlack BastaCredential Accesshttps://github.com/skelsec/pypykatz11N/AN/AN/A1029893942025-02-27T20:37:07Z2018-05-25T22:21:20Z8641
1031*/lsass.rar*.{0,1000}\/lsass\.rar.{0,1000}offensive_tool_keywordMirrorDumpLSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memoryT1003 - T1055 - T1574TA0006 - TA0005 - TA0003N/AN/ACredential Accesshttps://github.com/CCob/MirrorDump11N/AN/A103265582021-03-18T18:19:00Z2021-03-18T18:18:56Z8642
1032*/lsass.zip*.{0,1000}\/lsass\.zip.{0,1000}offensive_tool_keywordMirrorDumpLSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memoryT1003 - T1055 - T1574TA0006 - TA0005 - TA0003N/AN/ACredential Accesshttps://github.com/CCob/MirrorDump11N/AN/A103265582021-03-18T18:19:00Z2021-03-18T18:18:56Z8643
1033*/Lsass_Shtinkering.cpp*.{0,1000}\/Lsass_Shtinkering\.cpp.{0,1000}offensive_tool_keywordNativeDumpDump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)T1003.001TA0006N/AN/ACredential Accesshttps://github.com/ricardojoserf/NativeDump11N/AN/A106586862024-12-17T15:36:57Z2024-02-22T15:16:16Z8645
1034*/Lsass_Shtinkering.exe*.{0,1000}\/Lsass_Shtinkering\.exe.{0,1000}offensive_tool_keywordNativeDumpDump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)T1003.001TA0006N/AN/ACredential Accesshttps://github.com/ricardojoserf/NativeDump11N/AN/A106586862024-12-17T15:36:57Z2024-02-22T15:16:16Z8646
1035*/lsass64.exe*.{0,1000}\/lsass64\.exe.{0,1000}offensive_tool_keywordlslsassdump active logon session password hashes from the lsass process (old tool for vista and older)T1003.001TA0006N/AAPT1Credential Accesshttps://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details11N/AN/A1010N/AN/AN/AN/A8647
1036*/LsassReflectDumping.git*.{0,1000}\/LsassReflectDumping\.git.{0,1000}offensive_tool_keywordLsassReflectDumpingleverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned processT1003.001 - T1555.003 - T1077TA0006N/AN/ACredential Accesshttps://github.com/Offensive-Panda/LsassReflectDumping11N/AN/A102198272024-10-19T08:16:13Z2024-10-17T14:57:30Z8649
1037*/Lsass-Shtinkering.git*.{0,1000}\/Lsass\-Shtinkering\.git.{0,1000}offensive_tool_keywordNativeDumpDump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!)T1003.001TA0006N/AN/ACredential Accesshttps://github.com/ricardojoserf/NativeDump11N/AN/A106586862024-12-17T15:36:57Z2024-02-22T15:16:16Z8650
1038*/LsassSilentProcessExit.git*.{0,1000}\/LsassSilentProcessExit\.git.{0,1000}offensive_tool_keywordLsassSilentProcessExitCommand line interface to dump LSASS memory to disk via SilentProcessExitT1003.001 - T1059.003TA0006 - TA0002N/AN/ACredential Accesshttps://github.com/deepinstinct/LsassSilentProcessExit11N/AN/A105445612020-12-23T11:51:21Z2020-11-29T08:49:42Z8651
1039*/Lsassx.git*.{0,1000}\/Lsassx\.git.{0,1000}offensive_tool_keywordLsassxDumping LSASS Evaded Endpoint Security SolutionsT1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001TA0006 - TA0005 - TA0004N/AN/ACredential Accesshttps://github.com/yehia-mamdouh/Lsassx11N/AN/A1011232025-02-15T16:41:38Z2025-02-15T16:36:27Z8652
1040*/Lsassx.ps1*.{0,1000}\/Lsassx\.ps1.{0,1000}offensive_tool_keywordLsassxDumping LSASS Evaded Endpoint Security SolutionsT1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001TA0006 - TA0005 - TA0004N/AN/ACredential Accesshttps://github.com/yehia-mamdouh/Lsassx11N/AN/A1011232025-02-15T16:41:38Z2025-02-15T16:36:27Z8653
1041*/Lsassx-OBF.ps1*.{0,1000}\/Lsassx\-OBF\.ps1.{0,1000}offensive_tool_keywordLsassxDumping LSASS Evaded Endpoint Security SolutionsT1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001TA0006 - TA0005 - TA0004N/AN/ACredential Accesshttps://github.com/yehia-mamdouh/Lsassx11N/AN/A1011232025-02-15T16:41:38Z2025-02-15T16:36:27Z8654
1042*/lsassy*.{0,1000}\/lsassy.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy11N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z8655
1043*/lsassy/releases/download/*.{0,1000}\/lsassy\/releases\/download\/.{0,1000}offensive_tool_keywordlsassyExtract credentials from lsass remotelyT1003.001 - T1021.001 - T1021.002 - T1555.003TA0006N/AN/ACredential Accesshttps://github.com/login-securite/lsassy11N/AN/A101021052512024-12-31T11:56:19Z2019-12-03T14:03:41Z8656
1044*/lsa-whisperer-*.zip*.{0,1000}\/lsa\-whisperer\-.{0,1000}\.zip.{0,1000}greyware_tool_keywordlsa-whispererTools for interacting with authentication packages using their individual message protocolsT1556.002 - T1003.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/EvanMcBroom/lsa-whisperer11N/AN/A64316292025-04-01T13:54:17Z2022-08-04T14:35:45Z8658
1045*/lsa-whisperer.git*.{0,1000}\/lsa\-whisperer\.git.{0,1000}greyware_tool_keywordlsa-whispererTools for interacting with authentication packages using their individual message protocolsT1556.002 - T1003.001TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/EvanMcBroom/lsa-whisperer11N/AN/A64316292025-04-01T13:54:17Z2022-08-04T14:35:45Z8659
1046*/luna.log*.{0,1000}\/luna\.log.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber10#linuxN/A10N/A8664
1047*/Luna-Grabber.git*.{0,1000}\/Luna\-Grabber\.git.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber11N/AN/A10N/A8665
1048*/Luna-Grabber/releases/download/*.{0,1000}\/Luna\-Grabber\/releases\/download\/.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber11N/AN/A10N/A8666
1049*/Luna-Grabber/tarball/*.{0,1000}\/Luna\-Grabber\/tarball\/.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber11N/AN/A10N/A8667
1050*/Luna-Grabber/zipball*.{0,1000}\/Luna\-Grabber\/zipball.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber11N/AN/A10N/A8668
1051*/Luna-Grabber-Injection/main*.{0,1000}\/Luna\-Grabber\-Injection\/main.{0,1000}offensive_tool_keywordLuna-Grabberdiscord token grabber made in pythonT1003 - T1056TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Smug246/Luna-Grabber11N/AN/A10N/A8669
1052*/lyncsmash/*.{0,1000}\/lyncsmash\/.{0,1000}offensive_tool_keywordlyncsmasha collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations T1190 - T1087 - T1110TA0006 - TA0007N/AN/ACredential Accesshttps://github.com/nyxgeek/lyncsmash11N/AN/A84337632024-10-01T11:22:01Z2016-05-20T04:32:41Z8671
1053*/LyncSniper.ps1*.{0,1000}\/LyncSniper\.ps1.{0,1000}offensive_tool_keywordSprayingToolkitScripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficientT1110 - T1078 - T1133 - T1061 - T1621TA0001 - TA0002 - TA0003N/AN/ACredential Accesshttps://github.com/byt3bl33d3r/SprayingToolkit11N/AN/A101014912692022-10-17T01:01:57Z2018-09-13T09:52:11Z8672
1054*/m365-fatigue.git*.{0,1000}\/m365\-fatigue\.git.{0,1000}offensive_tool_keywordm365-fatigueautomates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.T1110.001 - T1078.001 - T1556.004TA0006 - TA0008 - TA0009N/AN/ACredential Accesshttps://github.com/0xB455/m365-fatigue11N/AN/A1017772024-04-08T14:53:44Z2023-11-30T13:33:03Z8674
1055*/m365-fatigue.py*.{0,1000}\/m365\-fatigue\.py.{0,1000}offensive_tool_keywordm365-fatigueautomates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved.T1110.001 - T1078.001 - T1556.004TA0006 - TA0008 - TA0009N/AN/ACredential Accesshttps://github.com/0xB455/m365-fatigue11N/AN/A1017772024-04-08T14:53:44Z2023-11-30T13:33:03Z8675
1056*/mailpv.exe*.{0,1000}\/mailpv\.exe.{0,1000}offensive_tool_keywordMailPassViewMail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clientsT1003 - T1081 - T1110TA0006 - TA0009N/ABlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpyCredential Accesshttps://www.nirsoft.net/utils/mailpv.html11N/AN/A1010N/AN/AN/AN/A8691
1057*/MailSniper/*.{0,1000}\/MailSniper\/.{0,1000}offensive_tool_keywordMailSniperMailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain.T1087.003 - T1110.003 - T1114.002TA0006 -TA0009 -TA0007N/ALeafminerCredential Accesshttps://github.com/dafthack/MailSniper/blob/master/MailSniper.ps111N/AN/AN/A1030465802024-08-07T18:11:58Z2016-09-08T00:36:51Z8694
1058*/malDll.dll*.{0,1000}\/malDll\.dll.{0,1000}offensive_tool_keywordEvilLsassTwinDumping lsassT1003 - T1560.001 - T1022 - T1027.002TA0005 - TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin11N/AN/A102151182024-12-23T05:06:31Z2022-09-13T12:42:13Z8707
1059*/malseclogon.*.{0,1000}\/malseclogon\..{0,1000}offensive_tool_keywordnanodumpThe swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process.T1003.001 - T1003.003TA0006N/ADispossessorCredential Accesshttps://github.com/fortra/nanodump11N/AN/A101019182492024-09-17T22:58:11Z2021-11-10T18:28:15Z8712
1060*/md5cracker.rb*.{0,1000}\/md5cracker\.rb.{0,1000}offensive_tool_keywordpwcrack-frameworkPassword Crack FrameworkT1110 - T1003 - T1059TA0006N/AN/ACredential Accesshttps://github.com/L-codes/pwcrack-framework11N/AN/A106515592024-02-25T13:08:56Z2018-07-01T08:33:55Z8731
1061*/memorydump.py*.{0,1000}\/memorydump\.py.{0,1000}offensive_tool_keywordLaZagneThe LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software.T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001TA0006 - TA0009N/AAkira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONTCredential Accesshttps://github.com/AlessandroZ/LaZagne10N/AN/A1010994120622025-04-10T14:24:35Z2015-02-16T14:10:02Z8755
1062*/mimidogz.git*.{0,1000}\/mimidogz\.git.{0,1000}offensive_tool_keywordmimidogzRewrite of Invoke-Mimikatz.ps1 to avoid AV detectionT1055 - T1560.001 - T1110.001 - T1003 - T1071TA0005 - TA0040 - TA0006N/ADispossessorCredential Accesshttps://github.com/projectb-temp/mimidogz11N/AN/A101002019-02-11T10:14:10Z2019-02-11T10:12:08Z8818
1063*/mimikatz.git*.{0,1000}\/mimikatz\.git.{0,1000}offensive_tool_keywordmimikatzmimikatz github linkT1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003TA0004 - TA0006 - TA0003 - TA0008 - TA0009N/ABlack Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - SphinxCredential Accesshttps://github.com/gentilkiwi/mimikatz11N/AN/A10102009438542024-07-05T17:42:58Z2014-04-06T18:30:02Z8825
1064*/mimikatz/archive/master.zip*.{0,1000}\/mimikatz\/archive\/master\.zip.{0,1000}offensive_tool_keywordmimikatzmimikatz archive linkT1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003TA0004 - TA0006 - TA0003 - TA0008 - TA0009N/ABlack Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - SphinxCredential Accesshttps://github.com/gentilkiwi/mimikatz11N/AN/A10102009438542024-07-05T17:42:58Z2014-04-06T18:30:02Z8829
1065*/mimikatz/releases/*.{0,1000}\/mimikatz\/releases\/.{0,1000}offensive_tool_keywordmimikatzmimikatz archive linkT1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003TA0004 - TA0006 - TA0003 - TA0008 - TA0009N/ABlack Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - SphinxCredential Accesshttps://github.com/gentilkiwi/mimikatz11N/AN/A10102009438542024-07-05T17:42:58Z2014-04-06T18:30:02Z8830
1066*/mimikatz/zipball/*.{0,1000}\/mimikatz\/zipball\/.{0,1000}offensive_tool_keywordmimikatzmimikatz archive linkT1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003TA0004 - TA0006 - TA0003 - TA0008 - TA0009N/ABlack Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - SphinxCredential Accesshttps://github.com/gentilkiwi/mimikatz11N/AN/A10102009438542024-07-05T17:42:58Z2014-04-06T18:30:02Z8831
1067*/mimilib.dll*.{0,1000}\/mimilib\.dll.{0,1000}offensive_tool_keywordForensikeRemotely dump NT hashes through Windows Crash dumpsT1003TA0006N/AN/ACredential Accesshttps://github.com/bmarchev/Forensike11N/AN/A1012732024-10-29T00:13:50Z2024-02-01T13:52:55Z8838
1068*/mimipenguin.sh*.{0,1000}\/mimipenguin\.sh.{0,1000}offensive_tool_keywordmimipyTool to dump passwords from various processes memoryT1003TA0006N/AN/ACredential Accesshttps://github.com/n1nj4sec/mimipy11N/AN/A103207362017-04-30T00:09:15Z2017-04-05T21:06:32Z8845
1069*/mimipenguin/releases/download/*.{0,1000}\/mimipenguin\/releases\/download\/.{0,1000}offensive_tool_keywordmimipenguinA tool to dump the login password from the current linux userT1003.007TA0006 - TA0002 N/ATeamTNTCredential Accesshttps://github.com/huntergregal/mimipenguin11#linuxN/A101039406442023-05-17T13:20:46Z2017-03-28T21:24:28Z8848
1070*/mimipy.git*.{0,1000}\/mimipy\.git.{0,1000}offensive_tool_keywordmimipyTool to dump passwords from various processes memoryT1003TA0006N/AN/ACredential Accesshttps://github.com/n1nj4sec/mimipy11N/AN/A103207362017-04-30T00:09:15Z2017-04-05T21:06:32Z8849
1071*/MiniDump.git*.{0,1000}\/MiniDump\.git.{0,1000}offensive_tool_keywordMiniDumpC# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumpsT1003.001TA0006N/AN/ACredential Accesshttps://github.com/cube0x0/MiniDump11N/AN/A103291482021-10-13T18:00:46Z2021-08-14T12:26:16Z8852
1072*/MiniDump-main.zip*.{0,1000}\/MiniDump\-main\.zip.{0,1000}offensive_tool_keywordMiniDumpC# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumpsT1003.001TA0006N/AN/ACredential Accesshttps://github.com/cube0x0/MiniDump11N/AN/A103291482021-10-13T18:00:46Z2021-08-14T12:26:16Z8855
1073*/MirrorDump.exe*.{0,1000}\/MirrorDump\.exe.{0,1000}offensive_tool_keywordMirrorDumpLSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memoryT1003 - T1055 - T1574TA0006 - TA0005 - TA0003N/AN/ACredential Accesshttps://github.com/CCob/MirrorDump11N/AN/A103265582021-03-18T18:19:00Z2021-03-18T18:18:56Z8860
1074*/MirrorDump.git*.{0,1000}\/MirrorDump\.git.{0,1000}offensive_tool_keywordMirrorDumpLSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memoryT1003 - T1055 - T1574TA0006 - TA0005 - TA0003N/AN/ACredential Accesshttps://github.com/CCob/MirrorDump11N/AN/A103265582021-03-18T18:19:00Z2021-03-18T18:18:56Z8861
1075*/mobaxterm.rb*.{0,1000}\/mobaxterm\.rb.{0,1000}offensive_tool_keywordpwcrack-frameworkPassword Crack FrameworkT1110 - T1003 - T1059TA0006N/AN/ACredential Accesshttps://github.com/L-codes/pwcrack-framework10#linuxN/A106515592024-02-25T13:08:56Z2018-07-01T08:33:55Z8872
1076*/mRemoteNG-Decrypt*.{0,1000}\/mRemoteNG\-Decrypt.{0,1000}offensive_tool_keywordmRemoteNG-DecryptPython script to decrypt passwords stored by mRemoteNGT1555.003 - T1110.003 - T1003 - T1081TA0006 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/haseebT/mRemoteNG-Decrypt11N/AN/A82146422023-07-06T16:15:20Z2019-05-27T05:25:57Z8909
1077*/mremoteng-decrypt.git*.{0,1000}\/mremoteng\-decrypt\.git.{0,1000}offensive_tool_keywordmRemoteNG-DecryptPython script to decrypt passwords stored by mRemoteNGT1555.003 - T1110.003 - T1003 - T1081TA0006 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/kmahyyg/mremoteng-decrypt11N/AN/A8183212022-10-29T16:02:26Z2019-05-11T09:09:49Z8910
1078*/mremoteng-decrypt/releases/download/*.{0,1000}\/mremoteng\-decrypt\/releases\/download\/.{0,1000}offensive_tool_keywordmRemoteNG-DecryptPython script to decrypt passwords stored by mRemoteNGT1555.003 - T1110.003 - T1003 - T1081TA0006 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/kmahyyg/mremoteng-decrypt11N/AN/A8183212022-10-29T16:02:26Z2019-05-11T09:09:49Z8911
1079*/mremoteng-decrypt/tarball/*.{0,1000}\/mremoteng\-decrypt\/tarball\/.{0,1000}offensive_tool_keywordmRemoteNG-DecryptPython script to decrypt passwords stored by mRemoteNGT1555.003 - T1110.003 - T1003 - T1081TA0006 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/kmahyyg/mremoteng-decrypt11N/AN/A8183212022-10-29T16:02:26Z2019-05-11T09:09:49Z8912
1080*/mremoteng-decrypt/zipball/*.{0,1000}\/mremoteng\-decrypt\/zipball\/.{0,1000}offensive_tool_keywordmRemoteNG-DecryptPython script to decrypt passwords stored by mRemoteNGT1555.003 - T1110.003 - T1003 - T1081TA0006 - TA0009 - TA0011N/AN/ACredential Accesshttps://github.com/kmahyyg/mremoteng-decrypt11N/AN/A8183212022-10-29T16:02:26Z2019-05-11T09:09:49Z8913
1081*/MSOLSpray*.{0,1000}\/MSOLSpray.{0,1000}offensive_tool_keywordMSOLSprayThis module will perform password spraying against Microsoft Online accounts (Azure/O365)T1110.003 - T1553.003 - T1621TA0001 - TA0006N/AN/ACredential Accesshttps://github.com/dafthack/MSOLSpray11N/Anetwork exploitation tool10109641742024-03-19T11:03:06Z2020-03-16T13:38:22Z8941
1082*/MSSprinkler.git*.{0,1000}\/MSSprinkler\.git.{0,1000}offensive_tool_keywordMSSprinklerpassword spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approachT1110.003 - T1110.001TA0006 - TA0007 - TA0008N/AN/ACredential Accesshttps://github.com/TheresAFewConors/MSSprinkler11N/AN/A917472025-02-25T13:32:41Z2024-09-15T09:54:53Z8943
1083*/mssprinkler.ps1*.{0,1000}\/mssprinkler\.ps1.{0,1000}offensive_tool_keywordMSSprinklerpassword spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approachT1110.003 - T1110.001TA0006 - TA0007 - TA0008N/AN/ACredential Accesshttps://github.com/TheresAFewConors/MSSprinkler11N/AN/A917472025-02-25T13:32:41Z2024-09-15T09:54:53Z8944
1084*/mssqlexec.py*.{0,1000}\/mssqlexec\.py.{0,1000}offensive_tool_keywordcrackmapexecprotocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networksT1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047TA0002 - TA0006 - TA0007N/AAPT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black BastaCredential Accesshttps://github.com/Porchetta-Industries/CrackMapExec11N/AN/A1010869016672023-12-06T17:09:42Z2015-08-14T14:11:55Z8952
1085*/mstscfox.dll*.{0,1000}\/mstscfox\.dll.{0,1000}offensive_tool_keywordThievingFoxcollection of post-exploitation tools to gather credentials from various password managersT1555 - T1003 - T1056 - T1070TA0006 - TA0009N/AN/ACredential Accesshttps://github.com/Slowerzs/ThievingFox11N/AN/A106535652024-03-28T19:58:03Z2024-01-20T23:22:52Z8961
1086*/MultiDump.exe*.{0,1000}\/MultiDump\.exe.{0,1000}offensive_tool_keywordDumpLSASSLsass dumping tool - 50 ways of dumping lsassT1003.001 - T1055.001 - T1620TA0006 - TA0005N/AN/ACredential Accesshttps://github.com/elementalsouls/DumpLSASS11N/AN/A1013352024-02-27T11:25:11Z2023-04-09T12:11:10Z8964
1087*/MultiDump.exe*.{0,1000}\/MultiDump\.exe.{0,1000}offensive_tool_keywordMultiDumpMultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetlyT1003 - T1564.002TA0005 - TA0006N/AN/ACredential Accesshttps://github.com/Xre0uS/MultiDump11N/AN/A106510662025-03-28T10:40:27Z2024-02-02T05:56:29Z8965
The file is too large to be shown. View Raw