mirror of
https://github.com/mthcht/ThreatHunting-Keywords
synced 2026-06-08 16:12:28 +00:00
755048bf5e
very few additions and some corrections
3.2 MiB
3.2 MiB
| 1 | keyword | metadata_keyword_regex | metadata_keyword_type | metadata_tool | metadata_description | metadata_tool_techniques | metadata_tool_tactics | metadata_malwares_name | metadata_groups_name | metadata_category | metadata_link | metadata_enable_endpoint_detection | metadata_enable_proxy_detection | metadata_tags | metadata_comment | metadata_severity_score | metadata_popularity_score | metadata_github_stars | metadata_github_forks | metadata_github_updated_at | metadata_github_created_at | metadata_entry_id |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2 | * - Dump LSASS memory bypassing countermeasures* | .{0,1000}\s\-\sDump\sLSASS\smemory\sbypassing\scountermeasures.{0,1000} | offensive_tool_keyword | blindsight | Red teaming tool to dump LSASS memory, bypassing basic countermeasures | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/0xdea/blindsight | 1 | 0 | #content | N/A | 10 | 3 | 225 | 26 | 2024-12-31T15:28:15Z | 2024-07-18T07:35:43Z | 6 |
| 3 | * - Remote lsass dump reader* | .{0,1000}\s\-\sRemote\slsass\sdump\sreader.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | #content | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 10 |
| 4 | * /altservice:ldap * | .{0,1000}\s\/altservice\:ldap\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 36 |
| 5 | * /asrepkey* | .{0,1000}\s\/asrepkey.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 37 |
| 6 | * /changentlm* /user:* /oldhash:* | .{0,1000}\s\/changentlm.{0,1000}\s\/user\:.{0,1000}\s\/oldhash\:.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 46 |
| 7 | * /changentlm* /user:* /oldpwd:* | .{0,1000}\s\/changentlm.{0,1000}\s\/user\:.{0,1000}\s\/oldpwd\:.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 47 |
| 8 | * /changentlm* /user:* /oldpwd:* | .{0,1000}\s\/changentlm.{0,1000}\s\/user\:.{0,1000}\s\/oldpwd\:.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 48 |
| 9 | * /createnetonly:*cmd.exe* | .{0,1000}\s\/createnetonly\:.{0,1000}cmd\.exe.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 57 |
| 10 | * /createnetonly:*cmd.exe* | .{0,1000}\s\/createnetonly\:.{0,1000}cmd\.exe.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 58 |
| 11 | * /credpassword* | .{0,1000}\s\/credpassword.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 59 |
| 12 | * /creduser:* /credpassword:* | .{0,1000}\s\/creduser\:.{0,1000}\s\/credpassword\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 60 |
| 13 | * /decodemk /binary:* /password:* | .{0,1000}\s\/decodemk\s\/binary\:.{0,1000}\s\/password\:.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 61 |
| 14 | * /domain:* /dc:* /getcredentials /nowrap* | .{0,1000}\s\/domain\:.{0,1000}\s\/dc\:.{0,1000}\s\/getcredentials\s\/nowrap.{0,1000} | offensive_tool_keyword | KeyCredentialLink | Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute | T1098 - T1550 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/Leo4j/KeyCredentialLink | 1 | 0 | N/A | N/A | 10 | 1 | 21 | 3 | 2024-06-05T13:44:39Z | 2024-06-05T13:19:49Z | 62 |
| 15 | * /dumpsecret /input:* /system* | .{0,1000}\s\/dumpsecret\s\/input\:.{0,1000}\s\/system.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 63 |
| 16 | * /dumpsecret /input:defaultpassword* | .{0,1000}\s\/dumpsecret\s\/input\:defaultpassword.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 64 |
| 17 | * /dumpsecret /input:dpapi_system /offline* | .{0,1000}\s\/dumpsecret\s\/input\:dpapi_system\s\/offline.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 65 |
| 18 | * /gethmac /mode:hashid /input:* /key:* | .{0,1000}\s\/gethmac\s\/mode\:hashid\s\/input\:.{0,1000}\s\/key\:.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 69 |
| 19 | * /GetKeys WirelessKeyView* | .{0,1000}\s\/GetKeys\sWirelessKeyView.{0,1000} | offensive_tool_keyword | WirelessKeyView | WirelessKeyView recovers all wireless network security keys/passwords (WEP/WPA) stored in your computer | T1003 - T1083 - T1552 | TA0006 | N/A | GoGoogle | Credential Access | https://www.nirsoft.net/utils/wireless_key.html | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 70 |
| 20 | * /getlsasecret /input:* | .{0,1000}\s\/getlsasecret\s\/input\:.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 71 |
| 21 | * /getntlmhash /password:* | .{0,1000}\s\/getntlmhash\s\/password\:.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 72 |
| 22 | * /getntlmhash | wtee *.ntlm* | .{0,1000}\s\/getntlmhash\s\|\swtee\s.{0,1000}\.ntlm.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 73 |
| 23 | * /getsamkey /offline* | .{0,1000}\s\/getsamkey\s\/offline.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 74 |
| 24 | * /impersonateuser:* /msdsspn:* /ptt* | .{0,1000}\s\/impersonateuser\:.{0,1000}\s\/msdsspn\:.{0,1000}\s\/ptt.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 75 |
| 25 | * /ldap * /printcmd* | .{0,1000}\s\/ldap\s.{0,1000}\s\/printcmd.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 76 |
| 26 | * /ldapfilter:'admincount=1'* | .{0,1000}\s\/ldapfilter\:\'admincount\=1\'.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 77 |
| 27 | * /nofullpacsig * | .{0,1000}\s\/nofullpacsig\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 83 |
| 28 | * /outfile:* /spn:* | .{0,1000}\s\/outfile\:.{0,1000}\s\/spn\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 84 |
| 29 | * /outfile:* /spns:* | .{0,1000}\s\/outfile\:.{0,1000}\s\/spns\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 85 |
| 30 | * /ptt /binary:*.kirbi* | .{0,1000}\s\/ptt\s\/binary\:.{0,1000}\.kirbi.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 89 |
| 31 | * /pwdsetafter:* | .{0,1000}\s\/pwdsetafter\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 90 |
| 32 | * /pwdsetbefore:* | .{0,1000}\s\/pwdsetbefore\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 91 |
| 33 | * /rc4opsec * | .{0,1000}\s\/rc4opsec\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 94 |
| 34 | * /s4uproxytarget* | .{0,1000}\s\/s4uproxytarget.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 96 |
| 35 | * /s4utransitedservices* | .{0,1000}\s\/s4utransitedservices.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 98 |
| 36 | * /service:krbtgt * | .{0,1000}\s\/service\:krbtgt\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 99 |
| 37 | * /setntlm * /user:* /newhash:* | .{0,1000}\s\/setntlm\s.{0,1000}\s\/user\:.{0,1000}\s\/newhash\:.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 100 |
| 38 | * /setntlm * /user:* /newpwd:* | .{0,1000}\s\/setntlm\s.{0,1000}\s\/user\:.{0,1000}\s\/newpwd\:.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 101 |
| 39 | * /simple * /spn* | .{0,1000}\s\/simple\s.{0,1000}\s\/spn.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 102 |
| 40 | * /ticket *.kirbi* | .{0,1000}\s\/ticket\s.{0,1000}\.kirbi.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 104 |
| 41 | * /ticket:* /autoenterprise * | .{0,1000}\s\/ticket\:.{0,1000}\s\/autoenterprise\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 105 |
| 42 | * /ticket:*.kirbi* | .{0,1000}\s\/ticket\:.{0,1000}\.kirbi.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 107 |
| 43 | * /usetgtdeleg * | .{0,1000}\s\/usetgtdeleg\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 113 |
| 44 | * | NTLMParse* | .{0,1000}\s\|\sNTLMParse.{0,1000} | offensive_tool_keyword | ADFSRelay | NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS | T1140 - T1212 - T1557 | TA0007 - TA0008 - TA0006 | N/A | Black Basta | Credential Access | https://github.com/praetorian-inc/ADFSRelay | 1 | 0 | N/A | N/A | 10 | 2 | 179 | 15 | 2022-06-22T03:01:00Z | 2022-05-12T01:20:14Z | 136 |
| 45 | * > Wi-Fi-PASS* | .{0,1000}\s\>\sWi\-Fi\-PASS.{0,1000} | offensive_tool_keyword | wifigrabber | grab wifi password and exfiltrate to a given site | T1056.005 - T1552.001 - T1119 - T1071.001 | TA0004 - TA0006 - TA0010 - TA0040 | N/A | N/A | Credential Access | https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber | 1 | 0 | N/A | N/A | 10 | 10 | 904 | 310 | 2024-09-14T02:34:26Z | 2021-09-08T20:33:18Z | 149 |
| 46 | * 1$a$$.exe* | .{0,1000}\s1\$a\$\$\.exe.{0,1000} | offensive_tool_keyword | DumpThatLSASS | Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk | T1003 - T1055.011 - T1027 - T1564.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/peiga/DumpThatLSASS | 1 | 0 | N/A | N/A | 10 | 1 | 31 | 79 | 2022-09-24T22:39:04Z | 2022-09-24T22:41:19Z | 153 |
| 47 | * 29ABE9Hy.log* | .{0,1000}\s29ABE9Hy\.log.{0,1000} | offensive_tool_keyword | blindsight | Red teaming tool to dump LSASS memory, bypassing basic countermeasures | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/0xdea/blindsight | 1 | 0 | N/A | N/A | 10 | 3 | 225 | 26 | 2024-12-31T15:28:15Z | 2024-07-18T07:35:43Z | 159 |
| 48 | * --action SPRAY_USERS * | .{0,1000}\s\-\-action\sSPRAY_USERS\s.{0,1000} | offensive_tool_keyword | SharpHose | Asynchronous Password Spraying Tool in C# for Windows Environments | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/ustayready/SharpHose | 1 | 0 | N/A | N/A | 10 | 4 | 312 | 62 | 2023-12-19T21:06:47Z | 2020-05-01T22:10:49Z | 186 |
| 49 | * adcsync.py* | .{0,1000}\sadcsync\.py.{0,1000} | offensive_tool_keyword | adcsync | Use ESC1 to perform a makeshift DCSync and dump hashes | T1003.006 - T1021 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/JPG0mez/ADCSync | 1 | 0 | N/A | N/A | 9 | 3 | 205 | 22 | 2023-11-02T21:41:08Z | 2023-10-04T01:56:50Z | 207 |
| 50 | * add /target:* /altsecid:X509:* | .{0,1000}\sadd\s\/target\:.{0,1000}\s\/altsecid\:X509\:.{0,1000} | offensive_tool_keyword | SharpAltSecIds | Shadow Credentials via altSecurityIdentities - Enables attackers to add altSecurityIdentities entries to an account - linking it to an X.509 certificate for authentication. This allows them to impersonate the targeted account and authenticate using the associated certificate | T1098.003 - T1556.002 - T1078 | TA0003 - TA0004 - TA0006 | N/A | N/A | Credential Access | https://github.com/bugch3ck/SharpAltSecIds | 1 | 0 | N/A | N/A | 9 | 1 | 12 | 3 | 2022-05-30T13:50:05Z | 2022-05-30T13:40:17Z | 209 |
| 51 | * adfsbrute.py* | .{0,1000}\sadfsbrute\.py.{0,1000} | offensive_tool_keyword | adfsbrute | test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks | T1110.003 - T1110.001 - T1110 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/ricardojoserf/adfsbrute | 1 | 0 | N/A | N/A | 8 | 2 | 172 | 33 | 2021-04-23T16:43:59Z | 2020-10-02T16:28:35Z | 225 |
| 52 | * --adfs-host * --krb-key * --krb-ticket * | .{0,1000}\s\-\-adfs\-host\s.{0,1000}\s\-\-krb\-key\s.{0,1000}\s\-\-krb\-ticket\s.{0,1000} | offensive_tool_keyword | whiskeysamlandfriends | GoldenSAML Attack Libraries and Framework | T1606.002 | TA0006 | N/A | N/A | Credential Access | https://github.com/secureworks/whiskeysamlandfriends | 1 | 0 | N/A | N/A | N/A | 1 | 72 | 9 | 2024-06-05T14:56:28Z | 2021-11-04T15:30:12Z | 226 |
| 53 | * adfs-spray.py* | .{0,1000}\sadfs\-spray\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 228 |
| 54 | * ADPassHunt.GetGPPPassword* | .{0,1000}\sADPassHunt\.GetGPPPassword.{0,1000} | offensive_tool_keyword | ADPassHunt | credential stealer tool that hunts Active Directory credentials (leaked tool Developed In-house for Fireeyes Red Team) | T1003.003 - T1552.006 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://www.virustotal.com/gui/file/73233ca7230fb5848e220723caa06d795a14c0f1f42c6a59482e812bfb8c217f | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 234 |
| 55 | * Any passwords that were successfully sprayed have been output to* | .{0,1000}\sAny\spasswords\sthat\swere\ssuccessfully\ssprayed\shave\sbeen\soutput\sto.{0,1000} | offensive_tool_keyword | Invoke-Pre2kSpray | Enumerate domain machine accounts and perform pre2k password spraying. | T1087.002 - T1110.003 | TA0007 - TA0006 | N/A | N/A | Credential Access | https://github.com/eversinc33/Invoke-Pre2kSpray | 1 | 0 | #content | N/A | 8 | 1 | 69 | 11 | 2023-07-14T06:50:22Z | 2023-07-05T10:07:38Z | 268 |
| 56 | * App-Bound Encryption Decryption process* | .{0,1000}\sApp\-Bound\sEncryption\sDecryption\sprocess.{0,1000} | offensive_tool_keyword | Chrome-App-Bound-Encryption-Decryption | Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections | T1003 - T1081 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption | 1 | 0 | #content | N/A | 9 | 5 | 401 | 73 | 2025-04-22T08:30:00Z | 2024-10-27T11:28:35Z | 271 |
| 57 | * Ask4Creds.ps1* | .{0,1000}\sAsk4Creds\.ps1.{0,1000} | offensive_tool_keyword | Ask4Creds | Prompt User for credentials | T1056 - T1071 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Leo4j/Ask4Creds | 1 | 0 | N/A | N/A | 8 | 1 | 1 | 0 | 2024-03-20T17:09:21Z | 2023-11-12T15:21:40Z | 280 |
| 58 | * asktgs * /ticket:* | .{0,1000}\sasktgs\s.{0,1000}\s\/ticket\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 281 |
| 59 | * asktgs *.kirbi* | .{0,1000}\sasktgs\s.{0,1000}\.kirbi.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 282 |
| 60 | * asktgs /ticket:* | .{0,1000}\sasktgs\s\/ticket\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 283 |
| 61 | * asktgt * /service:* | .{0,1000}\sasktgt\s.{0,1000}\s\/service\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 284 |
| 62 | * asktgt /user * | .{0,1000}\sasktgt\s\/user\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 285 |
| 63 | * asktht /user:* | .{0,1000}\sasktht\s\/user\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 288 |
| 64 | * asreproast * | .{0,1000}\sasreproast\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 292 |
| 65 | * atomizer.py * | .{0,1000}\satomizer\.py\s.{0,1000} | offensive_tool_keyword | SprayingToolkit | Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient | T1110 - T1078 - T1133 - T1061 - T1621 | TA0001 - TA0002 - TA0003 | N/A | N/A | Credential Access | https://github.com/byt3bl33d3r/SprayingToolkit | 1 | 0 | N/A | N/A | 9 | 10 | 1491 | 269 | 2022-10-17T01:01:57Z | 2018-09-13T09:52:11Z | 306 |
| 66 | * autoNTDS.py* | .{0,1000}\sautoNTDS\.py.{0,1000} | offensive_tool_keyword | autoNTDS | autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat | T1003 - T1059 - T1021.002 - T1213 | TA0006 - TA0008 - TA0005 - TA0002 | N/A | N/A | Credential Access | https://github.com/hmaverickadams/autoNTDS | 1 | 0 | N/A | N/A | 10 | 2 | 109 | 14 | 2023-10-31T22:03:58Z | 2023-10-30T23:10:58Z | 342 |
| 67 | * BabelStrike.py* | .{0,1000}\sBabelStrike\.py.{0,1000} | offensive_tool_keyword | BabelStrike | The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin) | T1078 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/t3l3machus/BabelStrike | 1 | 0 | N/A | N/A | 1 | 2 | 132 | 23 | 2024-07-19T07:02:42Z | 2023-01-10T07:59:00Z | 351 |
| 68 | * backupcreds.exe* | .{0,1000}\sbackupcreds\.exe.{0,1000} | offensive_tool_keyword | BackupCreds | A C# implementation of dumping credentials from Windows Credential Manager | T1003 - T1555 | TA0006 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/leftp/BackupCreds | 1 | 0 | N/A | N/A | 9 | 1 | 57 | 10 | 2023-09-23T10:37:05Z | 2023-09-23T06:42:20Z | 364 |
| 69 | * backupkey* /server:* /file*.pvk* | .{0,1000}\sbackupkey.{0,1000}\s\/server\:.{0,1000}\s\/file.{0,1000}\.pvk.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 365 |
| 70 | * --bf-hashes-file * | .{0,1000}\s\-\-bf\-hashes\-file\s.{0,1000} | offensive_tool_keyword | smartbrute | Password spraying and bruteforcing tool for Active Directory Domain Services | T1110.001 - T1110.003 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/smartbrute | 1 | 0 | N/A | N/A | 10 | 4 | 365 | 54 | 2024-10-27T20:47:29Z | 2021-07-16T14:53:29Z | 386 |
| 71 | * --bf-passwords-file * | .{0,1000}\s\-\-bf\-passwords\-file\s.{0,1000} | offensive_tool_keyword | smartbrute | Password spraying and bruteforcing tool for Active Directory Domain Services | T1110.001 - T1110.003 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/smartbrute | 1 | 0 | N/A | N/A | 10 | 4 | 365 | 54 | 2024-10-27T20:47:29Z | 2021-07-16T14:53:29Z | 387 |
| 72 | * BlankOBF.py* | .{0,1000}\sBlankOBF\.py.{0,1000} | offensive_tool_keyword | Blank-Grabber | Stealer with multiple functions | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Blank-c/Blank-Grabber | 1 | 0 | N/A | N/A | 10 | 9 | 831 | 220 | 2023-08-06T06:26:16Z | 2022-01-26T12:04:56Z | 403 |
| 73 | * bleeding-jumbo john* | .{0,1000}\sbleeding\-jumbo\sjohn.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 405 |
| 74 | * blob /target:*.bin* /pvk:* | .{0,1000}\sblob\s\/target\:.{0,1000}\.bin.{0,1000}\s\/pvk\:.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 407 |
| 75 | * blob /target:*.bin* /unprotect* | .{0,1000}\sblob\s\/target\:.{0,1000}\.bin.{0,1000}\s\/unprotect.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 408 |
| 76 | * --bloodhound --import-data * | .{0,1000}\s\-\-bloodhound\s\-\-import\-data\s.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 411 |
| 77 | * --bloodhound --mark-owned * | .{0,1000}\s\-\-bloodhound\s\-\-mark\-owned\s.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 412 |
| 78 | * --bloodhound --sync * | .{0,1000}\s\-\-bloodhound\s\-\-sync\s.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 414 |
| 79 | * bloodhoundsync.py* | .{0,1000}\sbloodhoundsync\.py.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 416 |
| 80 | * brute * /password* | .{0,1000}\sbrute\s.{0,1000}\s\/password.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 464 |
| 81 | * --bruteforce *.kdbx* | .{0,1000}\s\-\-bruteforce\s.{0,1000}\.kdbx.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 0 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 465 |
| 82 | * bruteuser * | .{0,1000}\sbruteuser\s.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 0 | N/A | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 472 |
| 83 | * bruteuser -d * | .{0,1000}\sbruteuser\s\-d\s.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 0 | N/A | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 473 |
| 84 | * by @citronneur (v* | .{0,1000}\sby\s\@citronneur\s\(v.{0,1000} | offensive_tool_keyword | pamspy | Credentials Dumper for Linux using eBPF | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/citronneur/pamspy | 1 | 0 | #linux | N/A | 10 | 10 | 1135 | 63 | 2024-09-09T13:19:12Z | 2022-07-01T19:33:43Z | 479 |
| 85 | * by erwan2212@gmail.com* | .{0,1000}\sby\serwan2212\@gmail\.com.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 482 |
| 86 | * BypassCredGuard.exe* | .{0,1000}\sBypassCredGuard\.exe.{0,1000} | offensive_tool_keyword | BypassCredGuard | Credential Guard Bypass Via Patching Wdigest Memory | T1003 - T1112 - T1555.002 - T1574 | TA0006 - TA0005 - TA0040 | N/A | N/A | Credential Access | https://github.com/wh0amitz/BypassCredGuard | 1 | 0 | N/A | N/A | 10 | 4 | 323 | 52 | 2023-02-03T06:55:43Z | 2023-01-18T15:16:11Z | 485 |
| 87 | * -c "!mimikatz" * | .{0,1000}\s\-c\s\"!mimikatz\"\s.{0,1000} | offensive_tool_keyword | Forensike | Remotely dump NT hashes through Windows Crash dumps | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/bmarchev/Forensike | 1 | 0 | N/A | N/A | 10 | 1 | 27 | 3 | 2024-10-29T00:13:50Z | 2024-02-01T13:52:55Z | 490 |
| 88 | * cachedump.py* | .{0,1000}\scachedump\.py.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 533 |
| 89 | * --ccache-ticket * | .{0,1000}\s\-\-ccache\-ticket\s.{0,1000} | offensive_tool_keyword | smartbrute | Password spraying and bruteforcing tool for Active Directory Domain Services | T1110.001 - T1110.003 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/smartbrute | 1 | 0 | N/A | N/A | 10 | 4 | 365 | 54 | 2024-10-27T20:47:29Z | 2021-07-16T14:53:29Z | 551 |
| 90 | * changepw * /ticket:* | .{0,1000}\schangepw\s.{0,1000}\s\/ticket\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 557 |
| 91 | * chrome_decrypt.cpp * | .{0,1000}\schrome_decrypt\.cpp\s.{0,1000} | offensive_tool_keyword | Chrome-App-Bound-Encryption-Decryption | Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections | T1003 - T1081 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption | 1 | 0 | N/A | N/A | 9 | 5 | 401 | 73 | 2025-04-22T08:30:00Z | 2024-10-27T11:28:35Z | 573 |
| 92 | * chrome_decrypt.cpp* | .{0,1000}\schrome_decrypt\.cpp.{0,1000} | offensive_tool_keyword | Chrome-App-Bound-Encryption-Decryption | Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections | T1003 - T1081 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption | 1 | 0 | N/A | N/A | 9 | 5 | 401 | 73 | 2025-04-22T08:30:00Z | 2024-10-27T11:28:35Z | 574 |
| 93 | * chrome_decrypt.exe* | .{0,1000}\schrome_decrypt\.exe.{0,1000} | offensive_tool_keyword | Chrome-App-Bound-Encryption-Decryption | Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections | T1003 - T1081 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption | 1 | 0 | N/A | N/A | 9 | 5 | 401 | 73 | 2025-04-22T08:30:00Z | 2024-10-27T11:28:35Z | 575 |
| 94 | * chromium_based_browsers.py* | .{0,1000}\schromium_based_browsers\.py.{0,1000} | offensive_tool_keyword | Browser-password-stealer | This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above! | T1003.002 - T1056.001 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/henry-richard7/Browser-password-stealer | 1 | 0 | N/A | N/A | 10 | 5 | 423 | 62 | 2024-07-12T10:30:42Z | 2020-09-15T09:23:56Z | 579 |
| 95 | * cmedb | .{0,1000}\scmedb | offensive_tool_keyword | crackmapexec | windows default compiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 617 |
| 96 | * comsvcs_stealth.py* | .{0,1000}\scomsvcs_stealth\.py.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 667 |
| 97 | * --config *.json --debug --exfil --onedrive* | .{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-debug\s\-\-exfil\s\-\-onedrive.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 670 |
| 98 | * --config *.json --enum --validate-msol --usernames * | .{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-enum\s\-\-validate\-msol\s\-\-usernames\s.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 671 |
| 99 | * --config *.json --enum --validate-teams* | .{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-enum\s\-\-validate\-teams.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 672 |
| 100 | * --config *.json --exfil --aad* | .{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-exfil\s\-\-aad.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 673 |
| 101 | * --crack * --ntds* | .{0,1000}\s\-\-crack\s.{0,1000}\s\-\-ntds.{0,1000} | offensive_tool_keyword | autoNTDS | autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat | T1003 - T1059 - T1021.002 - T1213 | TA0006 - TA0008 - TA0005 - TA0002 | N/A | N/A | Credential Access | https://github.com/hmaverickadams/autoNTDS | 1 | 0 | N/A | N/A | 10 | 2 | 109 | 14 | 2023-10-31T22:03:58Z | 2023-10-30T23:10:58Z | 706 |
| 102 | * --crack-status* | .{0,1000}\s\-\-crack\-status.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 711 |
| 103 | * credentials /pvk:* | .{0,1000}\scredentials\s\/pvk\:.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 733 |
| 104 | * credmaster.py* | .{0,1000}\scredmaster\.py.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 734 |
| 105 | * credmaster-success.txt* | .{0,1000}\scredmaster\-success\.txt.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 735 |
| 106 | * credmaster-validusers.txt* | .{0,1000}\scredmaster\-validusers\.txt.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 736 |
| 107 | * cstealer.py* | .{0,1000}\scstealer\.py.{0,1000} | offensive_tool_keyword | cstealer | stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python. | T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/can-kat/cstealer | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 747 |
| 108 | * --custom_user_agent* | .{0,1000}\s\-\-custom_user_agent.{0,1000} | offensive_tool_keyword | Spray365 | Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/MarkoH17/Spray365 | 1 | 0 | N/A | N/A | N/A | 4 | 348 | 58 | 2022-07-14T14:45:57Z | 2021-11-04T18:20:39Z | 753 |
| 109 | * darkcodersc * | .{0,1000}\sdarkcodersc\s.{0,1000} | offensive_tool_keyword | win-brute-logon | Bruteforce cracking tool for windows users | T1110 - T1110.001 - T1110.002 | TA0008 - TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/DarkCoderSc/win-brute-logon | 1 | 0 | N/A | N/A | N/A | 10 | 1138 | 191 | 2023-11-09T10:37:58Z | 2020-05-14T21:46:50Z | 778 |
| 110 | * --dc-ip * -request * -format hashcat* | .{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-request\s.{0,1000}\s\-format\shashcat.{0,1000} | offensive_tool_keyword | hashcat | Worlds fastest and most advanced password recovery utility. | T1110.001 - T1003.001 - T1021.001 | TA0006 - TA0009 - TA0010 | N/A | Black Basta | Credential Access | https://github.com/hashcat/hashcat | 1 | 0 | #linux | N/A | 10 | 10 | 22481 | 3046 | 2024-08-16T23:50:35Z | 2015-12-04T14:46:51Z | 791 |
| 111 | * --debug --exfil --onedrive* | .{0,1000}\s\-\-debug\s\-\-exfil\s\-\-onedrive.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 805 |
| 112 | * Decrypt-RDCMan.ps1* | .{0,1000}\sDecrypt\-RDCMan\.ps1.{0,1000} | offensive_tool_keyword | Decrypt-RDCMan | decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI | T1003 - T1552 - T1081 - T1027 | TA0006 - TA0008 - TA0005 | N/A | N/A | Credential Access | https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1 | 1 | 0 | N/A | N/A | 9 | 1 | 1 | 1 | 2016-12-01T14:06:24Z | 2017-11-22T23:18:39Z | 807 |
| 113 | * default_logins.txt* | .{0,1000}\sdefault_logins\.txt.{0,1000} | offensive_tool_keyword | thc-hydra | Parallelized login cracker which supports numerous protocols to attack. | T1110.001 | TA0006 | N/A | ALLANITE - BERSERK BEAR | Credential Access | https://github.com/vanhauser-thc/thc-hydra | 1 | 0 | #linux | N/A | N/A | 10 | 10326 | 2137 | 2025-04-04T12:19:05Z | 2014-04-24T14:45:37Z | 809 |
| 114 | * DEL {}SQLDmpr*.mdmp & for /f * | .{0,1000}\sDEL\s\{\}SQLDmpr.{0,1000}\.mdmp\s\&\sfor\s\/f\s.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 813 |
| 115 | * dementor.py* | .{0,1000}\sdementor\.py.{0,1000} | offensive_tool_keyword | NetNTLMtoSilverTicket | Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket. | T1110.001 - T1558.003 - T1558.004 | TA0006 - TA0008 - TA0002 | N/A | N/A | Credential Access | https://github.com/NotMedic/NetNTLMtoSilverTicket | 1 | 0 | N/A | N/A | 10 | 9 | 842 | 113 | 2021-07-26T15:16:20Z | 2019-01-14T15:32:27Z | 820 |
| 116 | * diamond * /certificate:* | .{0,1000}\sdiamond\s.{0,1000}\s\s\/certificate\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 834 |
| 117 | * diamond /tgtdeleg * | .{0,1000}\sdiamond\s\/tgtdeleg\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 835 |
| 118 | * diamond /user:* | .{0,1000}\sdiamond\s\/user\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 836 |
| 119 | * Disable_defender.py* | .{0,1000}\sDisable_defender\.py.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 853 |
| 120 | * dllinject.py* | .{0,1000}\sdllinject\.py.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 870 |
| 121 | * domcachedump.py* | .{0,1000}\sdomcachedump\.py.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 915 |
| 122 | * -Downgrade False -Restore False -Impersonate True * -challange * | .{0,1000}\s\-Downgrade\sFalse\s\-Restore\sFalse\s\-Impersonate\sTrue\s.{0,1000}\s\-challange\s.{0,1000} | offensive_tool_keyword | Internal-Monologue | Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS | T1003 - T1051 - T1574 - T1110 - T1547 | TA0003 - TA0006 | N/A | N/A | Credential Access | https://github.com/eladshamir/Internal-Monologue | 1 | 0 | N/A | N/A | N/A | 10 | 1512 | 240 | 2018-10-11T12:13:08Z | 2017-12-09T05:59:01Z | 940 |
| 123 | * dpapi blob *.json *.dat* | .{0,1000}\sdpapi\sblob\s.{0,1000}\.json\s.{0,1000}\.dat.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 948 |
| 124 | * dpapi credential *.json cred* | .{0,1000}\sdpapi\scredential\s.{0,1000}\.json\scred.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 949 |
| 125 | * dpapi masterkey /root/* | .{0,1000}\sdpapi\smasterkey\s\/root\/.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 950 |
| 126 | * dpapi minidump *.dmp* | .{0,1000}\sdpapi\sminidump\s.{0,1000}\.dmp.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 951 |
| 127 | * dpapi prekey nt *S-1-5-21* | .{0,1000}\sdpapi\sprekey\snt\s.{0,1000}S\-1\-5\-21.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 952 |
| 128 | * dpapi prekey password * | .{0,1000}\sdpapi\sprekey\spassword\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 953 |
| 129 | * dpapi prekey registry *.reg* | .{0,1000}\sdpapi\sprekey\sregistry\s.{0,1000}\.reg.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 954 |
| 130 | * dpapi securestring *.dat* | .{0,1000}\sdpapi\ssecurestring\s.{0,1000}\.dat.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 955 |
| 131 | * dragoncastle.py* | .{0,1000}\sdragoncastle\.py.{0,1000} | offensive_tool_keyword | DragonCastle | A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process. | T1003 - T1547.005 - T1055 - T1557 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/mdsecactivebreach/DragonCastle | 1 | 0 | N/A | N/A | 10 | 3 | 298 | 38 | 2022-10-26T10:19:55Z | 2022-10-26T10:18:37Z | 961 |
| 132 | * dump * /service:* | .{0,1000}\sdump\s.{0,1000}\s\/service\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 969 |
| 133 | * dump --usermode --kernelmode --driver * | .{0,1000}\sdump\s\-\-usermode\s\-\-kernelmode\s\-\-driver\s.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 971 |
| 134 | * --dump_file Keepass.exe.dmp* | .{0,1000}\s\-\-dump_file\sKeepass\.exe\.dmp.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 0 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 973 |
| 135 | * --dump_lsa* | .{0,1000}\s\-\-dump_lsa.{0,1000} | offensive_tool_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 974 |
| 136 | * --dump_usedhashes* | .{0,1000}\s\-\-dump_usedhashes.{0,1000} | offensive_tool_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 976 |
| 137 | * --dump_wireless* | .{0,1000}\s\-\-dump_wireless.{0,1000} | offensive_tool_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 977 |
| 138 | * --dump-bitlocker * | .{0,1000}\s\-\-dump\-bitlocker\s.{0,1000} | offensive_tool_keyword | quarkspwdump | Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems | T1003 - T1003.001 - T1059 | TA0006 | N/A | LOTUS PANDA - PowerPool - Calypso | Credential Access | https://github.com/peterdocter/quarkspwdump | 1 | 0 | N/A | N/A | 9 | 1 | 12 | 8 | 2015-06-25T04:22:21Z | 2015-07-14T08:18:08Z | 979 |
| 139 | * --dump-bitlocker* | .{0,1000}\s\-\-dump\-bitlocker.{0,1000} | offensive_tool_keyword | quarkspwdump | Dump various types of Windows credentials without injecting in any process | T1003 - T1555 | TA0006 | N/A | N/A | Credential Access | https://github.com/quarkslab/quarkspwdump | 1 | 0 | N/A | N/A | 10 | 5 | 427 | 142 | 2023-01-13T03:45:25Z | 2013-02-13T15:16:30Z | 980 |
| 140 | * -DumpCred -ComputerName @* | .{0,1000}\s\-DumpCred\s\-ComputerName\s\@.{0,1000} | offensive_tool_keyword | mimidogz | Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection | T1055 - T1560.001 - T1110.001 - T1003 - T1071 | TA0005 - TA0040 - TA0006 | N/A | Dispossessor | Credential Access | https://github.com/projectb-temp/mimidogz | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2019-02-11T10:14:10Z | 2019-02-11T10:12:08Z | 982 |
| 141 | * -DumpCreds -ComputerName @* | .{0,1000}\s\-DumpCreds\s\-ComputerName\s\@.{0,1000} | offensive_tool_keyword | mimidogz | Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection | T1055 - T1560.001 - T1110.001 - T1003 - T1071 | TA0005 - TA0040 - TA0006 | N/A | Dispossessor | Credential Access | https://github.com/projectb-temp/mimidogz | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2019-02-11T10:14:10Z | 2019-02-11T10:12:08Z | 985 |
| 142 | * dumpert.py* | .{0,1000}\sdumpert\.py.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 989 |
| 143 | * --dump-hash-domain --with-history* | .{0,1000}\s\-\-dump\-hash\-domain\s\-\-with\-history.{0,1000} | offensive_tool_keyword | quarkspwdump | Dump various types of Windows credentials without injecting in any process | T1003 - T1555 | TA0006 | N/A | N/A | Credential Access | https://github.com/quarkslab/quarkspwdump | 1 | 0 | N/A | N/A | 10 | 5 | 427 | 142 | 2023-01-13T03:45:25Z | 2013-02-13T15:16:30Z | 992 |
| 144 | * --dump-hash-domain* | .{0,1000}\s\-\-dump\-hash\-domain.{0,1000} | offensive_tool_keyword | quarkspwdump | Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems | T1003 - T1003.001 - T1059 | TA0006 | N/A | LOTUS PANDA - PowerPool - Calypso | Credential Access | https://github.com/peterdocter/quarkspwdump | 1 | 0 | N/A | N/A | 9 | 1 | 12 | 8 | 2015-06-25T04:22:21Z | 2015-07-14T08:18:08Z | 993 |
| 145 | * --dump-hash-domain-cached* | .{0,1000}\s\-\-dump\-hash\-domain\-cached.{0,1000} | offensive_tool_keyword | quarkspwdump | Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems | T1003 - T1003.001 - T1059 | TA0006 | N/A | LOTUS PANDA - PowerPool - Calypso | Credential Access | https://github.com/peterdocter/quarkspwdump | 1 | 0 | N/A | N/A | 9 | 1 | 12 | 8 | 2015-06-25T04:22:21Z | 2015-07-14T08:18:08Z | 994 |
| 146 | * --dump-hash-domain-cached* | .{0,1000}\s\-\-dump\-hash\-domain\-cached.{0,1000} | offensive_tool_keyword | quarkspwdump | Dump various types of Windows credentials without injecting in any process | T1003 - T1555 | TA0006 | N/A | N/A | Credential Access | https://github.com/quarkslab/quarkspwdump | 1 | 0 | N/A | N/A | 10 | 5 | 427 | 142 | 2023-01-13T03:45:25Z | 2013-02-13T15:16:30Z | 995 |
| 147 | * --dump-hash-local* | .{0,1000}\s\-\-dump\-hash\-local.{0,1000} | offensive_tool_keyword | quarkspwdump | Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems | T1003 - T1003.001 - T1059 | TA0006 | N/A | LOTUS PANDA - PowerPool - Calypso | Credential Access | https://github.com/peterdocter/quarkspwdump | 1 | 0 | N/A | N/A | 9 | 1 | 12 | 8 | 2015-06-25T04:22:21Z | 2015-07-14T08:18:08Z | 996 |
| 148 | * dump-lsass.py* | .{0,1000}\sdump\-lsass\.py.{0,1000} | offensive_tool_keyword | impacket | Dump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems. | T1021 - T1047 - T1055.011 - T1003 | TA0002 - TA0005 - TA0006 | N/A | Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta | Credential Access | https://github.com/kaluche/Dump-Lsass | 1 | 0 | N/A | N/A | 10 | 1 | 1 | 0 | 2019-11-14T18:15:26Z | 2019-11-20T20:26:27Z | 999 |
| 149 | * --dumpmode network --network raw --ip * --port * | .{0,1000}\s\-\-dumpmode\snetwork\s\-\-network\sraw\s\-\-ip\s.{0,1000}\s\-\-port\s.{0,1000} | offensive_tool_keyword | PPLBlade | Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk. | T1003.001 - T1027.004 - T1560.001 - T1039 - T1570 | TA0006 - TA0005 - TA0010 - TA0003 | N/A | N/A | Credential Access | https://github.com/tastypepperoni/PPLBlade | 1 | 0 | N/A | N/A | 10 | 6 | 545 | 59 | 2023-08-30T07:59:51Z | 2023-08-29T19:36:04Z | 1000 |
| 150 | * --dumpmode network --network smb * | .{0,1000}\s\-\-dumpmode\snetwork\s\-\-network\ssmb\s.{0,1000} | offensive_tool_keyword | PPLBlade | Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk. | T1003.001 - T1027.004 - T1560.001 - T1039 - T1570 | TA0006 - TA0005 - TA0010 - TA0003 | N/A | N/A | Credential Access | https://github.com/tastypepperoni/PPLBlade | 1 | 0 | N/A | N/A | 10 | 6 | 545 | 59 | 2023-08-30T07:59:51Z | 2023-08-29T19:36:04Z | 1001 |
| 151 | * --dump-name *lsass* | .{0,1000}\s\-\-dump\-name\s.{0,1000}lsass.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 1002 |
| 152 | * --dumpname lsass.dmp* | .{0,1000}\s\-\-dumpname\slsass\.dmp.{0,1000} | offensive_tool_keyword | PPLBlade | Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk. | T1003.001 - T1027.004 - T1560.001 - T1039 - T1570 | TA0006 - TA0005 - TA0010 - TA0003 | N/A | N/A | Credential Access | https://github.com/tastypepperoni/PPLBlade | 1 | 0 | N/A | N/A | 10 | 6 | 545 | 59 | 2023-08-30T07:59:51Z | 2023-08-29T19:36:04Z | 1003 |
| 153 | * DumpS1.ps1* | .{0,1000}\sDumpS1\.ps1.{0,1000} | greyware_tool_keyword | SentinelAgent | dump a process with SentinelAgent.exe | T1003 - T1055 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e | 1 | 0 | N/A | N/A | 8 | 7 | N/A | N/A | N/A | N/A | 1004 |
| 154 | * DumpSvc.exe* | .{0,1000}\sDumpSvc\.exe.{0,1000} | offensive_tool_keyword | PWDumpX | PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://packetstormsecurity.com/files/download/52580/PWDumpX.zip | 1 | 0 | N/A | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 1005 |
| 155 | * EASSniper.ps1* | .{0,1000}\sEASSniper\.ps1.{0,1000} | offensive_tool_keyword | EASSniper | EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS) | T1110 - T1078.003 - T1087.002 - T1059.001 | TA0006 -TA0007 - TA0009 - TA0002 - TA0001 | N/A | N/A | Credential Access | https://github.com/fugawi/EASSniper | 1 | 0 | N/A | N/A | 10 | 1 | 5 | 4 | 2018-04-17T23:23:31Z | 2018-04-17T22:43:51Z | 1014 |
| 156 | * EASSniper.ps1* | .{0,1000}\sEASSniper\.ps1.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 1015 |
| 157 | * eas-valid-users.txt* | .{0,1000}\seas\-valid\-users\.txt.{0,1000} | offensive_tool_keyword | EASSniper | EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS) | T1110 - T1078.003 - T1087.002 - T1059.001 | TA0006 -TA0007 - TA0009 - TA0002 - TA0001 | N/A | N/A | Credential Access | https://github.com/fugawi/EASSniper | 1 | 0 | N/A | N/A | 10 | 1 | 5 | 4 | 2018-04-17T23:23:31Z | 2018-04-17T22:43:51Z | 1016 |
| 158 | * empire_exec* | .{0,1000}\sempire_exec.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1036 |
| 159 | * empireadmin* | .{0,1000}\sempireadmin.{0,1000} | offensive_tool_keyword | crackmapexec | A swiss army knife for pentesting networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1037 |
| 160 | * --enum --validate-msol * | .{0,1000}\s\-\-enum\s\-\-validate\-msol\s.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 1056 |
| 161 | * --enum --validate-teams* | .{0,1000}\s\-\-enum\s\-\-validate\-teams.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 1057 |
| 162 | * enum_avproducts* | .{0,1000}\senum_avproducts.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1058 |
| 163 | * enum_chrome* | .{0,1000}\senum_chrome.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1059 |
| 164 | * enum_dns* | .{0,1000}\senum_dns.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1060 |
| 165 | * EtwHash* | .{0,1000}\sEtwHash.{0,1000} | offensive_tool_keyword | ETWHash | C# POC to extract NetNTLMv1/v2 hashes from ETW provider | T1556.001 | TA0009 | N/A | N/A | Credential Access | https://github.com/nettitude/ETWHash | 1 | 0 | N/A | N/A | N/A | 3 | 256 | 29 | 2023-05-10T06:45:06Z | 2023-04-26T15:53:01Z | 1075 |
| 166 | * EvilTwinServer * | .{0,1000}\sEvilTwinServer\s.{0,1000} | offensive_tool_keyword | EvilLsassTwin | attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess. | T1003.001 - T1055 - T1093 | TA0006 - TA0005 - TA0002 | N/A | N/A | Credential Access | https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin | 1 | 0 | N/A | N/A | 9 | 2 | 151 | 18 | 2024-12-23T05:06:31Z | 2022-09-13T12:42:13Z | 1094 |
| 167 | * -ExchHostname * -Password * | .{0,1000}\s\-ExchHostname\s.{0,1000}\s\-Password\s.{0,1000} | offensive_tool_keyword | MailSniper | MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain. | T1087.003 - T1110.003 - T1114.002 | TA0006 -TA0009 -TA0007 | N/A | N/A | Credential Access | https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1 | 1 | 0 | N/A | N/A | N/A | 10 | 3046 | 580 | 2024-08-07T18:11:58Z | 2016-09-08T00:36:51Z | 1095 |
| 168 | * --exfil --cookie-dump * --all* | .{0,1000}\s\-\-exfil\s\-\-cookie\-dump\s\s.{0,1000}\s\-\-all.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 1122 |
| 169 | * --exfil --cookie-dump * | .{0,1000}\s\-\-exfil\s\-\-cookie\-dump\s.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 1123 |
| 170 | * --exfil --teams --owa --owa-limit* | .{0,1000}\s\-\-exfil\s\-\-teams\s\-\-owa\s\-\-owa\-limit.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 1124 |
| 171 | * --exfil --teams --owa* | .{0,1000}\s\-\-exfil\s\-\-teams\s\-\-owa.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 1125 |
| 172 | * --exfil --tokens * --onedrive --owa* | .{0,1000}\s\-\-exfil\s\-\-tokens\s.{0,1000}\s\-\-onedrive\s\-\-owa.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 1126 |
| 173 | * --exfil --tokens * --onedrive* | .{0,1000}\s\-\-exfil\s\-\-tokens\s.{0,1000}\s\-\-onedrive.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 1127 |
| 174 | * extract --secrets --zsh* | .{0,1000}\sextract\s\-\-secrets\s\-\-zsh.{0,1000} | offensive_tool_keyword | PassDetective | PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets | T1059 - T1059.004 - T1552 - T1552.001 | TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/aydinnyunus/PassDetective | 1 | 0 | N/A | N/A | 7 | 2 | 129 | 8 | 2024-06-19T10:39:39Z | 2023-07-22T12:31:57Z | 1141 |
| 175 | * -f nessus.nessus * | .{0,1000}\s\-f\snessus\.nessus\s.{0,1000} | offensive_tool_keyword | brutespray | BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap. | T1110 | TA0001 - TA0043 | N/A | N/A | Credential Access | https://github.com/x90skysn3k/brutespray | 1 | 0 | N/A | N/A | 10 | 10 | 2231 | 405 | 2025-04-21T03:17:20Z | 2017-04-05T17:05:10Z | 1172 |
| 176 | * --force-ps32 | .{0,1000}\s\-\-force\-ps32 | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1211 |
| 177 | * Forensike.ps1* | .{0,1000}\sForensike\.ps1.{0,1000} | offensive_tool_keyword | Forensike | Remotely dump NT hashes through Windows Crash dumps | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/bmarchev/Forensike | 1 | 0 | N/A | N/A | 10 | 1 | 27 | 3 | 2024-10-29T00:13:50Z | 2024-02-01T13:52:55Z | 1215 |
| 178 | * --fork --write *.dmp* | .{0,1000}\s\-\-fork\s\-\-write\s.{0,1000}\.dmp.{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 0 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 1217 |
| 179 | * --format=netntlmv2 *.txt* | .{0,1000}\s\-\-format\=netntlmv2\s.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1228 |
| 180 | * --format=NT -w=*_password.txt* | .{0,1000}\s\-\-format\=NT\s\-w\=.{0,1000}_password\.txt.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper is a fast password cracker. | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/magnumripper/JohnTheRipper | 1 | 0 | #linux | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1229 |
| 181 | * -fullmemdmp -snap & ping 127.0.0.1 -n * | .{0,1000}\s\-fullmemdmp\s\-snap\s\&\sping\s127\.0\.0\.1\s\-n\s.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 1258 |
| 182 | * generate audit -ep *--passwords_in_userfile* | .{0,1000}\sgenerate\saudit\s\-ep\s.{0,1000}\-\-passwords_in_userfile.{0,1000} | offensive_tool_keyword | Spray365 | Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/MarkoH17/Spray365 | 1 | 0 | N/A | N/A | N/A | 4 | 348 | 58 | 2022-07-14T14:45:57Z | 2021-11-04T18:20:39Z | 1291 |
| 183 | * generate normal -ep * -d * -u * -pf * | .{0,1000}\sgenerate\snormal\s\-ep\s.{0,1000}\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-pf\s.{0,1000} | offensive_tool_keyword | Spray365 | Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/MarkoH17/Spray365 | 1 | 0 | N/A | N/A | N/A | 4 | 348 | 58 | 2022-07-14T14:45:57Z | 2021-11-04T18:20:39Z | 1292 |
| 184 | * generate normal -ep ex-plan.s365 * | .{0,1000}\sgenerate\snormal\s\-ep\sex\-plan\.s365\s.{0,1000} | offensive_tool_keyword | Spray365 | Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/MarkoH17/Spray365 | 1 | 0 | N/A | N/A | N/A | 4 | 348 | 58 | 2022-07-14T14:45:57Z | 2021-11-04T18:20:39Z | 1293 |
| 185 | * --gen-relay-list * | .{0,1000}\s\-\-gen\-relay\-list\s.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1300 |
| 186 | * get_keystrokes* | .{0,1000}\sget_keystrokes.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1308 |
| 187 | * get_netdomaincontroller* | .{0,1000}\sget_netdomaincontroller.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1309 |
| 188 | * get_netrdpsession* | .{0,1000}\sget_netrdpsession.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1310 |
| 189 | * get_timedscreenshot* | .{0,1000}\sget_timedscreenshot.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1312 |
| 190 | * Get-NetNTLM.ps1* | .{0,1000}\sGet\-NetNTLM\.ps1.{0,1000} | offensive_tool_keyword | Get-NetNTLM | Powershell module to get the NetNTLMv2 hash of the current user | T1110.003 - T1557.001 - T1040 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/elnerd/Get-NetNTLM | 1 | 0 | N/A | N/A | 7 | 1 | 93 | 18 | 2022-07-05T20:55:33Z | 2019-02-11T23:09:54Z | 1323 |
| 191 | * Get-SpoolStatus.ps1* | .{0,1000}\sGet\-SpoolStatus\.ps1.{0,1000} | offensive_tool_keyword | NetNTLMtoSilverTicket | Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket. | T1110.001 - T1558.003 - T1558.004 | TA0006 - TA0008 - TA0002 | N/A | N/A | Credential Access | https://github.com/NotMedic/NetNTLMtoSilverTicket | 1 | 0 | N/A | N/A | 10 | 9 | 842 | 113 | 2021-07-26T15:16:20Z | 2019-01-14T15:32:27Z | 1332 |
| 192 | * github repos list --org* | .{0,1000}\sgithub\srepos\slist\s\-\-org.{0,1000} | offensive_tool_keyword | noseyparker | Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history. | T1583 - T1059.001 - T1059.003 | TA0002 - TA0003 - TA0040 | N/A | N/A | Credential Access | https://github.com/praetorian-inc/noseyparker | 1 | 0 | N/A | N/A | 8 | 10 | 1903 | 100 | 2025-03-07T20:15:34Z | 2022-11-08T23:09:17Z | 1342 |
| 193 | * github repos list --user * | .{0,1000}\sgithub\srepos\slist\s\-\-user\s.{0,1000} | offensive_tool_keyword | noseyparker | Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history. | T1583 - T1059.001 - T1059.003 | TA0002 - TA0003 - TA0040 | N/A | N/A | Credential Access | https://github.com/praetorian-inc/noseyparker | 1 | 0 | N/A | N/A | 8 | 10 | 1903 | 100 | 2025-03-07T20:15:34Z | 2022-11-08T23:09:17Z | 1343 |
| 194 | * golden * /badpwdcount* | .{0,1000}\sgolden\s.{0,1000}\s\/badpwdcount.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 1351 |
| 195 | * golden * /ldap * | .{0,1000}\sgolden\s.{0,1000}\s\/ldap\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 1352 |
| 196 | * golden * /user:* | .{0,1000}\sgolden\s.{0,1000}\s\/user\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 1353 |
| 197 | * gosecretsdump_linux* | .{0,1000}\sgosecretsdump_linux.{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 0 | #linux | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 1360 |
| 198 | * gosecretsdump_mac* | .{0,1000}\sgosecretsdump_mac.{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 0 | N/A | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 1361 |
| 199 | * gosecretsdump_win* | .{0,1000}\sgosecretsdump_win.{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 0 | N/A | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 1362 |
| 200 | * gpp_autologin* | .{0,1000}\sgpp_autologin.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1375 |
| 201 | * gpp_password* | .{0,1000}\sgpp_password.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1376 |
| 202 | * hack.py* | .{0,1000}\shack\.py.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1399 |
| 203 | * harvest * /monitorinterval:* | .{0,1000}\sharvest\s.{0,1000}\s\/monitorinterval\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 1410 |
| 204 | * hashview.py* | .{0,1000}\shashview\.py.{0,1000} | offensive_tool_keyword | hashview | A web front-end for password cracking and analytics | T1110 - T1201 | TA0006 - TA0002 | N/A | N/A | Credential Access | https://github.com/hashview/hashview | 1 | 0 | N/A | N/A | 10 | 4 | 373 | 41 | 2025-02-20T18:23:25Z | 2020-11-23T19:21:06Z | 1415 |
| 205 | * hashview-agent * | .{0,1000}\shashview\-agent\s.{0,1000} | offensive_tool_keyword | hashview | A web front-end for password cracking and analytics | T1110 - T1201 | TA0006 - TA0002 | N/A | N/A | Credential Access | https://github.com/hashview/hashview | 1 | 0 | N/A | N/A | 10 | 4 | 373 | 41 | 2025-02-20T18:23:25Z | 2020-11-23T19:21:06Z | 1416 |
| 206 | * httprelayserver.py* | .{0,1000}\shttprelayserver\.py.{0,1000} | offensive_tool_keyword | NtlmRelayToEWS | ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS) | T1212 - T1557 - T1040 - T1078 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/Arno0x/NtlmRelayToEWS | 1 | 0 | N/A | N/A | 10 | 4 | 331 | 60 | 2018-01-15T12:48:02Z | 2017-10-13T18:00:50Z | 1528 |
| 207 | * icebreaker.py* | .{0,1000}\sicebreaker\.py.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 0 | N/A | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 1607 |
| 208 | * -Identity * -Set @{serviceprincipalname='*'}* | .{0,1000}\s\-Identity\s.{0,1000}\s\-Set\s\@\{serviceprincipalname\=\'.{0,1000}\'\}.{0,1000} | offensive_tool_keyword | AD exploitation cheat sheet | Targeted kerberoasting by setting SPN | T1110 | TA0006 | N/A | Black Basta | Credential Access | https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 1613 |
| 209 | * -Identity * -XOR @{useraccountcontrol=4194304* | .{0,1000}\s\-Identity\s.{0,1000}\s\-XOR\s\@\{useraccountcontrol\=4194304.{0,1000} | offensive_tool_keyword | AD exploitation cheat sheet | Targeted kerberoasting we need ACL write permissions to set UserAccountControl flags for the target user. Using PowerView | T1110 | TA0006 | N/A | Black Basta | Credential Access | https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 1614 |
| 210 | * impacketfile.py* | .{0,1000}\simpacketfile\.py.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 1634 |
| 211 | * -inc -u=0 *.pwd* | .{0,1000}\s\-inc\s\-u\=0\s.{0,1000}\.pwd.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1650 |
| 212 | * -inc=digits * | .{0,1000}\s\-inc\=digits\s.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1651 |
| 213 | * -InFile Wi-Fi-PASS* | .{0,1000}\s\-InFile\sWi\-Fi\-PASS.{0,1000} | offensive_tool_keyword | wifigrabber | grab wifi password and exfiltrate to a given site | T1056.005 - T1552.001 - T1119 - T1071.001 | TA0004 - TA0006 - TA0010 - TA0040 | N/A | N/A | Credential Access | https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber | 1 | 0 | N/A | N/A | 10 | 10 | 904 | 310 | 2024-09-14T02:34:26Z | 2021-09-08T20:33:18Z | 1657 |
| 214 | * instabf.py* | .{0,1000}\sinstabf\.py.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/samsesh/insta-bf | 1 | 0 | N/A | N/A | 7 | 1 | 59 | 13 | 2024-04-23T02:47:28Z | 2020-11-20T22:22:48Z | 1670 |
| 215 | * instainsane.sh* | .{0,1000}\sinstainsane\.sh.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/umeshshinde19/instainsane | 1 | 0 | N/A | N/A | 7 | 7 | 655 | 371 | 2024-02-11T10:29:05Z | 2018-12-02T22:48:11Z | 1671 |
| 216 | * install chntpw* | .{0,1000}\sinstall\schntpw.{0,1000} | offensive_tool_keyword | chntpw | reset a password on your system | T1003 - T1078 | TA0006 | N/A | N/A | Credential Access | https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1682 |
| 217 | * install creddump7* | .{0,1000}\sinstall\screddump7.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 1684 |
| 218 | * install hekatomb* | .{0,1000}\sinstall\shekatomb.{0,1000} | offensive_tool_keyword | HEKATOMB | Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them | T1003 - T1555.002 - T1482 - T1087 | TA0006 - TA0005 - TA0007 | N/A | N/A | Credential Access | https://github.com/Processus-Thief/HEKATOMB | 1 | 0 | N/A | N/A | 10 | 6 | N/A | N/A | N/A | N/A | 1690 |
| 219 | * install requests_ntlm* | .{0,1000}\sinstall\srequests_ntlm.{0,1000} | greyware_tool_keyword | requests-ntlm | HTTP NTLM Authentication for Requests Library | T1003 - T1547.005 - T1055 - T1557 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://pypi.org/project/requests-ntlm/ | 1 | 0 | N/A | N/A | 8 | 9 | N/A | N/A | N/A | N/A | 1699 |
| 220 | * install samdump2* | .{0,1000}\sinstall\ssamdump2.{0,1000} | offensive_tool_keyword | wcreddump | Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive. | T1003 - T1110.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/truerustyy/wcreddump | 1 | 0 | #linux #windows | N/A | 10 | 1 | 75 | 5 | 2024-11-18T18:37:28Z | 2024-03-05T00:00:20Z | 1700 |
| 221 | * install spraycharles* | .{0,1000}\sinstall\sspraycharles.{0,1000} | offensive_tool_keyword | spraycharles | Low and slow password spraying tool | T1110.003 - T1110.001 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Tw1sm/spraycharles | 1 | 0 | N/A | N/A | 10 | 2 | 195 | 32 | 2025-02-09T03:08:09Z | 2018-09-17T11:17:47Z | 1703 |
| 222 | * install wordlists* | .{0,1000}\sinstall\swordlists.{0,1000} | offensive_tool_keyword | wordlists | package contains the rockyou.txt wordlist | T1110.001 | TA0006 | N/A | N/A | Credential Access | https://www.kali.org/tools/wordlists/ | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 1714 |
| 223 | * install-sb.sh* | .{0,1000}\sinstall\-sb\.sh.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/samsesh/SocialBox-Termux | 1 | 0 | N/A | N/A | 7 | 10 | 3581 | 391 | 2024-09-02T19:15:22Z | 2019-03-28T18:07:05Z | 1717 |
| 224 | * insTof.py* | .{0,1000}\sinsTof\.py.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/samsesh/insta-bf | 1 | 0 | N/A | N/A | 7 | 1 | 59 | 13 | 2024-04-23T02:47:28Z | 2020-11-20T22:22:48Z | 1718 |
| 225 | * invoke_sessiongopher* | .{0,1000}\sinvoke_sessiongopher.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1735 |
| 226 | * invoke_vnc* | .{0,1000}\sinvoke_vnc.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1736 |
| 227 | * john_done* | .{0,1000}\sjohn_done.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1806 |
| 228 | * john_fork* | .{0,1000}\sjohn_fork.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1807 |
| 229 | * john_load* | .{0,1000}\sjohn_load.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1808 |
| 230 | * john_load_conf* | .{0,1000}\sjohn_load_conf.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1809 |
| 231 | * john_load_conf_db* | .{0,1000}\sjohn_load_conf_db.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1810 |
| 232 | * john_log_format* | .{0,1000}\sjohn_log_format.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1811 |
| 233 | * john_log_format2* | .{0,1000}\sjohn_log_format2.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1812 |
| 234 | * john_mpi_wait* | .{0,1000}\sjohn_mpi_wait.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1813 |
| 235 | * john_omp_fallback* | .{0,1000}\sjohn_omp_fallback.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1814 |
| 236 | * john_omp_init* | .{0,1000}\sjohn_omp_init.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1815 |
| 237 | * john_omp_maybe_adjust_or_fallback* | .{0,1000}\sjohn_omp_maybe_adjust_or_fallback.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1816 |
| 238 | * john_omp_show_info* | .{0,1000}\sjohn_omp_show_info.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1817 |
| 239 | * john_register_all* | .{0,1000}\sjohn_register_all.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1818 |
| 240 | * john_register_one* | .{0,1000}\sjohn_register_one.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1819 |
| 241 | * john_run* | .{0,1000}\sjohn_run.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1820 |
| 242 | * john_set_mpi* | .{0,1000}\sjohn_set_mpi.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1821 |
| 243 | * john_set_tristates* | .{0,1000}\sjohn_set_tristates.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1822 |
| 244 | * john_wait* | .{0,1000}\sjohn_wait.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1824 |
| 245 | * JohnTheRipper/* | .{0,1000}\sJohnTheRipper\/.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1825 |
| 246 | * -just-dc-ntlm * | .{0,1000}\s\-just\-dc\-ntlm\s.{0,1000} | offensive_tool_keyword | secretsdump | secretdump.py from impacket - https://github.com/fortra/impacket | T1003.003 | TA0006 | Operation Wocao | Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE | Credential Access | https://github.com/fortra/impacket | 1 | 0 | N/A | N/A | 10 | 10 | 14198 | 3681 | 2025-04-22T13:40:55Z | 2015-04-15T14:04:07Z | 1833 |
| 247 | * -just-dc-user * | .{0,1000}\s\-just\-dc\-user\s.{0,1000} | offensive_tool_keyword | secretsdump | secretdump.py from impacket - https://github.com/fortra/impacket | T1003.003 | TA0006 | Operation Wocao | Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE | Credential Access | https://github.com/fortra/impacket | 1 | 0 | N/A | N/A | 10 | 10 | 14198 | 3681 | 2025-04-22T13:40:55Z | 2015-04-15T14:04:07Z | 1836 |
| 248 | * keepass /unprotect* | .{0,1000}\skeepass\s\/unprotect.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 1848 |
| 249 | * KeePwn.py* | .{0,1000}\sKeePwn\.py.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 0 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 1851 |
| 250 | * KeeTheft.exe* | .{0,1000}\sKeeTheft\.exe.{0,1000} | offensive_tool_keyword | KeeThiefSyscalls | Patch GhostPack/KeeThief for it to use DInvoke and syscalls | T1003.001 - T1558.002 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/Metro-Holografix/KeeThiefSyscalls | 1 | 0 | N/A | private github repo | 10 | 1 | N/A | N/A | N/A | N/A | 1852 |
| 251 | * KeeThief.ps1* | .{0,1000}\sKeeThief\.ps1.{0,1000} | offensive_tool_keyword | Keethief | Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system. | T1003 - T1055 - T1059 - T1070 | TA0006 - TA0005 - TA0008 | N/A | EvilCorp* - APT20 | Credential Access | https://github.com/GhostPack/KeeThief | 1 | 0 | N/A | N/A | 10 | 10 | 944 | 154 | 2020-11-18T18:35:21Z | 2016-07-10T19:11:23Z | 1853 |
| 252 | * kerberoast * | .{0,1000}\skerberoast\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 1855 |
| 253 | * kerberoast * | .{0,1000}\skerberoast\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 1856 |
| 254 | * kerberos asreproast * | .{0,1000}\skerberos\sasreproast\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1863 |
| 255 | * kerberos brute * -d * | .{0,1000}\skerberos\sbrute\s.{0,1000}\s\-d\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1864 |
| 256 | * kerberos brute *.txt* | .{0,1000}\skerberos\sbrute\s.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1865 |
| 257 | * kerberos ccache del *.ccache* | .{0,1000}\skerberos\sccache\sdel\s.{0,1000}\.ccache.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1866 |
| 258 | * kerberos ccache exportkirbi * | .{0,1000}\skerberos\sccache\sexportkirbi\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1867 |
| 259 | * kerberos ccache list *.ccache* | .{0,1000}\skerberos\sccache\slist\s.{0,1000}\.ccache.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1868 |
| 260 | * kerberos ccache loadkirbi * | .{0,1000}\skerberos\sccache\sloadkirbi\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1869 |
| 261 | * kerberos ccache roast * | .{0,1000}\skerberos\sccache\sroast\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1870 |
| 262 | * kerberos keytab *.keytab* | .{0,1000}\skerberos\skeytab\s.{0,1000}\.keytab.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1871 |
| 263 | * kerberos kirbi parse * | .{0,1000}\skerberos\skirbi\sparse\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1872 |
| 264 | * kerberos spnroast * | .{0,1000}\skerberos\sspnroast\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1873 |
| 265 | * kerberos.py* | .{0,1000}\skerberos\.py.{0,1000} | offensive_tool_keyword | crackmapexec | protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 1875 |
| 266 | * kerbrute.py* | .{0,1000}\skerbrute\.py.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 0 | N/A | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 1876 |
| 267 | * --key PPLBlade* | .{0,1000}\s\-\-key\sPPLBlade.{0,1000} | offensive_tool_keyword | PPLBlade | Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk. | T1003.001 - T1027.004 - T1560.001 - T1039 - T1570 | TA0006 - TA0005 - TA0010 - TA0003 | N/A | N/A | Credential Access | https://github.com/tastypepperoni/PPLBlade | 1 | 0 | N/A | N/A | 10 | 6 | 545 | 59 | 2023-08-30T07:59:51Z | 2023-08-29T19:36:04Z | 1878 |
| 268 | * KeyCredentialLink.ps1* | .{0,1000}\sKeyCredentialLink\.ps1.{0,1000} | offensive_tool_keyword | KeyCredentialLink | Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute | T1098 - T1550 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/Leo4j/KeyCredentialLink | 1 | 0 | N/A | N/A | 10 | 1 | 21 | 3 | 2024-06-05T13:44:39Z | 2024-06-05T13:19:49Z | 1879 |
| 269 | * klist * /service:* | .{0,1000}\sklist\s.{0,1000}\s\/service\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 1892 |
| 270 | * knowsmore.cmd.wordlist* | .{0,1000}\sknowsmore\.cmd\.wordlist.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1893 |
| 271 | * knowsmore.cmdbase* | .{0,1000}\sknowsmore\.cmdbase.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1894 |
| 272 | * knowsmore.config* | .{0,1000}\sknowsmore\.config.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1895 |
| 273 | * knowsmore.knowsmore* | .{0,1000}\sknowsmore\.knowsmore.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1896 |
| 274 | * knowsmore.libs.bloodhoundsync* | .{0,1000}\sknowsmore\.libs\.bloodhoundsync.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1897 |
| 275 | * knowsmore.libs.exporterbase* | .{0,1000}\sknowsmore\.libs\.exporterbase.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1898 |
| 276 | * knowsmore.libs.ntdsuseraccount* | .{0,1000}\sknowsmore\.libs\.ntdsuseraccount.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1899 |
| 277 | * knowsmore.module* | .{0,1000}\sknowsmore\.module.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1900 |
| 278 | * knowsmore.password* | .{0,1000}\sknowsmore\.password.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1901 |
| 279 | * knowsmore.py* | .{0,1000}\sknowsmore\.py.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1902 |
| 280 | * knowsmore.util.color* | .{0,1000}\sknowsmore\.util\.color.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1903 |
| 281 | * knowsmore.util.database* | .{0,1000}\sknowsmore\.util\.database.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1904 |
| 282 | * knowsmore.util.knowsmoredb* | .{0,1000}\sknowsmore\.util\.knowsmoredb.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1905 |
| 283 | * knowsmore.util.logger* | .{0,1000}\sknowsmore\.util\.logger.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1906 |
| 284 | * knowsmore.util.process* | .{0,1000}\sknowsmore\.util\.process.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1907 |
| 285 | * knowsmore.util.tools* | .{0,1000}\sknowsmore\.util\.tools.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 1908 |
| 286 | * l$a$$Pid * | .{0,1000}\sl\$a\$\$Pid\s.{0,1000} | offensive_tool_keyword | DumpThatLSASS | Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk | T1003 - T1055.011 - T1027 - T1564.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/peiga/DumpThatLSASS | 1 | 0 | N/A | N/A | 10 | 1 | 31 | 79 | 2022-09-24T22:39:04Z | 2022-09-24T22:41:19Z | 1919 |
| 287 | * laps.py *--ldapserver* | .{0,1000}\slaps\.py\s.{0,1000}\-\-ldapserver.{0,1000} | offensive_tool_keyword | LAPSDumper | Dumping LAPS from Python | T1136.001 - T1112 - T1078.001 | TA0002 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/n00py/LAPSDumper | 1 | 0 | N/A | N/A | 10 | 3 | 267 | 35 | 2022-12-07T18:35:28Z | 2020-12-19T05:15:10Z | 1924 |
| 288 | * laps.py *-u * -p * | .{0,1000}\slaps\.py\s.{0,1000}\-u\s.{0,1000}\s\-p\s.{0,1000} | offensive_tool_keyword | LAPSDumper | Dumping LAPS from Python | T1136.001 - T1112 - T1078.001 | TA0002 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/n00py/LAPSDumper | 1 | 0 | N/A | N/A | 10 | 3 | 267 | 35 | 2022-12-07T18:35:28Z | 2020-12-19T05:15:10Z | 1925 |
| 289 | * laZagne.py* | .{0,1000}\slaZagne\.py.{0,1000} | offensive_tool_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 0 | N/A | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 1930 |
| 290 | * --list=hidden-options* | .{0,1000}\s\-\-list\=hidden\-options.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1959 |
| 291 | * live dpapi blobfile *.blob* | .{0,1000}\slive\sdpapi\sblobfile\s.{0,1000}\.blob.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1964 |
| 292 | * live dpapi cred * | .{0,1000}\slive\sdpapi\scred\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1965 |
| 293 | * live dpapi keys -o * | .{0,1000}\slive\sdpapi\skeys\s\-o\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1966 |
| 294 | * live dpapi securestring * | .{0,1000}\slive\sdpapi\ssecurestring\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1967 |
| 295 | * live dpapi vcred * | .{0,1000}\slive\sdpapi\svcred\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1968 |
| 296 | * live dpapi vpol * | .{0,1000}\slive\sdpapi\svpol\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1969 |
| 297 | * live dpapi wifi* | .{0,1000}\slive\sdpapi\swifi.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1970 |
| 298 | * live kerberos apreq * | .{0,1000}\slive\skerberos\sapreq\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1971 |
| 299 | * live kerberos dump* | .{0,1000}\slive\skerberos\sdump.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1972 |
| 300 | * live kerberos purge* | .{0,1000}\slive\skerberos\spurge.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1973 |
| 301 | * live kerberos roast* | .{0,1000}\slive\skerberos\sroast.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1974 |
| 302 | * live kerberos sessions* | .{0,1000}\slive\skerberos\ssessions.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1975 |
| 303 | * live kerberos tgt* | .{0,1000}\slive\skerberos\stgt.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1976 |
| 304 | * live kerberos triage* | .{0,1000}\slive\skerberos\striage.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1977 |
| 305 | * live lsa -o * | .{0,1000}\slive\slsa\s\-o\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1978 |
| 306 | * live lsa -o * | .{0,1000}\slive\slsa\s\-o\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1979 |
| 307 | * live process create -c regedit* | .{0,1000}\slive\sprocess\screate\s\-c\sregedit.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1980 |
| 308 | * live smb client * | .{0,1000}\slive\ssmb\sclient\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1981 |
| 309 | * live smb dcsync * | .{0,1000}\slive\ssmb\sdcsync\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1982 |
| 310 | * live smb lsassdump * | .{0,1000}\slive\ssmb\slsassdump\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1983 |
| 311 | * live smb regdump * | .{0,1000}\slive\ssmb\sregdump\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1984 |
| 312 | * live smb secretsdump * | .{0,1000}\slive\ssmb\ssecretsdump\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1985 |
| 313 | * live smbapi localgroup enum -t* | .{0,1000}\slive\ssmbapi\slocalgroup\senum\s\-t.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1986 |
| 314 | * live smbapi session enum * | .{0,1000}\slive\ssmbapi\ssession\senum\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1987 |
| 315 | * live smbapi share enum* | .{0,1000}\slive\ssmbapi\sshare\senum.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1988 |
| 316 | * live users whoami* | .{0,1000}\slive\susers\swhoami.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 1989 |
| 317 | * lnkbomb.py* | .{0,1000}\slnkbomb\.py.{0,1000} | offensive_tool_keyword | lnkbomb | Malicious shortcut generator for collecting NTLM hashes from insecure file shares. | T1023.003 - T1557.002 - T1046 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/dievus/lnkbomb | 1 | 0 | N/A | N/A | 10 | 4 | 327 | 58 | 2024-10-22T17:51:10Z | 2022-01-03T04:17:11Z | 1996 |
| 318 | * load_extra_pots* | .{0,1000}\sload_extra_pots.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 1998 |
| 319 | * --load-dll *ssp.dll* | .{0,1000}\s\-\-load\-dll\s.{0,1000}ssp\.dll.{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 0 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 2000 |
| 320 | * Local:DPAPIDecrypt* | .{0,1000}\sLocal\:DPAPIDecrypt.{0,1000} | offensive_tool_keyword | SecretServerSecretStealer | Powershell script that decrypts the data stored within a Thycotic Secret Server | T1552 - T1027 - T1059 | TA0006 | N/A | EvilCorp* | Credential Access | https://github.com/denandz/SecretServerSecretStealer | 1 | 0 | N/A | N/A | 10 | 1 | 78 | 14 | 2020-08-03T06:52:27Z | 2017-04-21T04:06:24Z | 2010 |
| 321 | * Local:LoadEncryptionDll* | .{0,1000}\sLocal\:LoadEncryptionDll.{0,1000} | offensive_tool_keyword | SecretServerSecretStealer | Powershell script that decrypts the data stored within a Thycotic Secret Server | T1552 - T1027 - T1059 | TA0006 | N/A | EvilCorp* | Credential Access | https://github.com/denandz/SecretServerSecretStealer | 1 | 0 | N/A | N/A | 10 | 1 | 78 | 14 | 2020-08-03T06:52:27Z | 2017-04-21T04:06:24Z | 2011 |
| 322 | * --local-auth --shares* | .{0,1000}\s\-\-local\-auth\s\-\-shares.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2017 |
| 323 | * --loggedon-users* | .{0,1000}\s\-\-loggedon\-users.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2035 |
| 324 | * loginAAD.ps1* | .{0,1000}\sloginAAD\.ps1.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 2037 |
| 325 | * lsa minidump * -o * | .{0,1000}\slsa\sminidump\s.{0,1000}\s\-o\s.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 2042 |
| 326 | * lsa minidump *.dmp* | .{0,1000}\slsa\sminidump\s.{0,1000}\.dmp.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 2044 |
| 327 | * lsa minidump /* | .{0,1000}\slsa\sminidump\s\/.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 2045 |
| 328 | * lsadump.py* | .{0,1000}\slsadump\.py.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 2046 |
| 329 | * lsasecrets.py* | .{0,1000}\slsasecrets\.py.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 2047 |
| 330 | * lsass.dmp* | .{0,1000}\slsass\.dmp.{0,1000} | offensive_tool_keyword | AD exploitation cheat sheet | Dump LSASS memory through a process snapshot (-r) avoiding interacting with it directly | T1110 | TA0006 | N/A | Black Basta | Credential Access | https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 2048 |
| 331 | * Lsassx.ps1* | .{0,1000}\sLsassx\.ps1.{0,1000} | offensive_tool_keyword | Lsassx | Dumping LSASS Evaded Endpoint Security Solutions | T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001 | TA0006 - TA0005 - TA0004 | N/A | N/A | Credential Access | https://github.com/yehia-mamdouh/Lsassx | 1 | 0 | N/A | N/A | 10 | 1 | 12 | 3 | 2025-02-15T16:41:38Z | 2025-02-15T16:36:27Z | 2050 |
| 332 | * Lsassx-OBF.ps1* | .{0,1000}\sLsassx\-OBF\.ps1.{0,1000} | offensive_tool_keyword | Lsassx | Dumping LSASS Evaded Endpoint Security Solutions | T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001 | TA0006 - TA0005 - TA0004 | N/A | N/A | Credential Access | https://github.com/yehia-mamdouh/Lsassx | 1 | 0 | N/A | N/A | 10 | 1 | 12 | 3 | 2025-02-15T16:41:38Z | 2025-02-15T16:36:27Z | 2051 |
| 333 | * lsassy* | .{0,1000}\slsassy.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 2053 |
| 334 | * Luna Grabber Builder* | .{0,1000}\sLuna\sGrabber\sBuilder.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 0 | N/A | N/A | 10 | N/A | 2056 | ||||
| 335 | * LyncSniper.ps1* | .{0,1000}\/LyncSniper\.ps1.{0,1000} | offensive_tool_keyword | SprayingToolkit | Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient | T1110 - T1078 - T1133 - T1061 - T1621 | TA0001 - TA0002 - TA0003 | N/A | N/A | Credential Access | https://github.com/byt3bl33d3r/SprayingToolkit | 1 | 0 | N/A | N/A | 10 | 10 | 1491 | 269 | 2022-10-17T01:01:57Z | 2018-09-13T09:52:11Z | 2057 |
| 336 | * -M multirdp* | .{0,1000}\s\-M\smultirdp.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2076 |
| 337 | * -M pe_inject* | .{0,1000}\s\-M\spe_inject.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2079 |
| 338 | * -m rdrleakdiag -M masterkeys* | .{0,1000}\s\-m\srdrleakdiag\s\-M\smasterkeys.{0,1000} | offensive_tool_keyword | dploot | DPAPI looting remotely in Python | T1003.006 - T1027 - T1110.004 | TA0006 - TA0007 - TA0010 | N/A | N/A | Credential Access | https://github.com/zblurx/dploot | 1 | 0 | N/A | N/A | 10 | 5 | 455 | 58 | 2025-04-09T08:17:14Z | 2022-05-24T11:05:21Z | 2085 |
| 339 | * -M scuffy* | .{0,1000}\s\-M\sscuffy.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2089 |
| 340 | * -M shellcode_inject* | .{0,1000}\s\-M\sshellcode_inject.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2092 |
| 341 | * -M slinky | .{0,1000}\s\-M\sslinky | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2094 |
| 342 | * -M tokens* | .{0,1000}\s\-M\stokens.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2100 |
| 343 | * -M uac | .{0,1000}\s\-M\suac | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2101 |
| 344 | * -M web_delivery* | .{0,1000}\s\-M\sweb_delivery.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2105 |
| 345 | * m365-fatigue.py * | .{0,1000}\sm365\-fatigue\.py\s.{0,1000} | offensive_tool_keyword | m365-fatigue | automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved. | T1110.001 - T1078.001 - T1556.004 | TA0006 - TA0008 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xB455/m365-fatigue | 1 | 0 | N/A | N/A | 10 | 1 | 77 | 7 | 2024-04-08T14:53:44Z | 2023-11-30T13:33:03Z | 2107 |
| 346 | * -ma lssas.exe* | .{0,1000}\s\-ma\slssas\.exe.{0,1000} | greyware_tool_keyword | Procdump | dump lsass process with procdump | T1003.001 | TA0006 | N/A | LockBit - Kimsuky - Conti - Quantum - PYSA - NetWalker - 8BASE - APT1 - APT15 - APT20 - APT27 - APT28 - Antlion - FIN13 - GOBLIN PANDA - Lazarus Group - PowerPool - PARINACOTA - Scattered Spider - BERSERK BEAR - Dispossessor | Credential Access | https://learn.microsoft.com/en-us/sysinternals/downloads/procdump | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2109 |
| 347 | * mask?a?a?a?a?* | .{0,1000}\smask\?a\?a\?a\?a\?.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 2118 |
| 348 | * --mask=?1?1?1* --min-len* | .{0,1000}\s\-\-mask\=\?1\?1\?1.{0,1000}\s\-\-min\-len.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 2119 |
| 349 | * memorydump.py* | .{0,1000}\smemorydump\.py.{0,1000} | offensive_tool_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 0 | N/A | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 2136 |
| 350 | * met_inject* | .{0,1000}\smet_inject.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2142 |
| 351 | * mimikittenz* | .{0,1000}\smimikittenz.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2159 |
| 352 | * mimipenguin.sh* | .{0,1000}\smimipenguin\.sh.{0,1000} | offensive_tool_keyword | mimipy | Tool to dump passwords from various processes memory | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/n1nj4sec/mimipy | 1 | 0 | N/A | N/A | 10 | 3 | 207 | 36 | 2017-04-30T00:09:15Z | 2017-04-05T21:06:32Z | 2160 |
| 353 | * mimipy.py * | .{0,1000}\smimipy\.py\s.{0,1000} | offensive_tool_keyword | mimipy | Tool to dump passwords from various processes memory | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/n1nj4sec/mimipy | 1 | 0 | N/A | N/A | 10 | 3 | 207 | 36 | 2017-04-30T00:09:15Z | 2017-04-05T21:06:32Z | 2161 |
| 354 | * MirrorDump.exe* | .{0,1000}\sMirrorDump\.exe.{0,1000} | offensive_tool_keyword | MirrorDump | LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory | T1003 - T1055 - T1574 | TA0006 - TA0005 - TA0003 | N/A | N/A | Credential Access | https://github.com/CCob/MirrorDump | 1 | 0 | N/A | N/A | 10 | 3 | 265 | 58 | 2021-03-18T18:19:00Z | 2021-03-18T18:18:56Z | 2164 |
| 355 | * --mobaxterm-poison-hkcr* | .{0,1000}\s\-\-mobaxterm\-poison\-hkcr.{0,1000} | offensive_tool_keyword | ThievingFox | collection of post-exploitation tools to gather credentials from various password managers | T1555 - T1003 - T1056 - T1070 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Slowerzs/ThievingFox | 1 | 0 | N/A | N/A | 10 | 6 | 535 | 65 | 2024-03-28T19:58:03Z | 2024-01-20T23:22:52Z | 2169 |
| 356 | * --mode decrypt --dumpname *.dmp --key * | .{0,1000}\s\-\-mode\sdecrypt\s\-\-dumpname\s.{0,1000}\.dmp\s\-\-key\s.{0,1000} | offensive_tool_keyword | PPLBlade | Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk. | T1003.001 - T1027.004 - T1560.001 - T1039 - T1570 | TA0006 - TA0005 - TA0010 - TA0003 | N/A | N/A | Credential Access | https://github.com/tastypepperoni/PPLBlade | 1 | 0 | N/A | N/A | 10 | 6 | 545 | 59 | 2023-08-30T07:59:51Z | 2023-08-29T19:36:04Z | 2171 |
| 357 | * --mode dump --name *.exe --handle procexp --obfuscate* | .{0,1000}\s\-\-mode\sdump\s\-\-name\s.{0,1000}\.exe\s\-\-handle\sprocexp\s\-\-obfuscate.{0,1000} | offensive_tool_keyword | PPLBlade | Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk. | T1003.001 - T1027.004 - T1560.001 - T1039 - T1570 | TA0006 - TA0005 - TA0010 - TA0003 | N/A | N/A | Credential Access | https://github.com/tastypepperoni/PPLBlade | 1 | 0 | N/A | N/A | 10 | 6 | 545 | 59 | 2023-08-30T07:59:51Z | 2023-08-29T19:36:04Z | 2172 |
| 358 | * --mode dump --name lsass.exe* | .{0,1000}\s\-\-mode\sdump\s\-\-name\slsass\.exe.{0,1000} | offensive_tool_keyword | PPLBlade | Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk. | T1003.001 - T1027.004 - T1560.001 - T1039 - T1570 | TA0006 - TA0005 - TA0010 - TA0003 | N/A | N/A | Credential Access | https://github.com/tastypepperoni/PPLBlade | 1 | 0 | N/A | N/A | 10 | 6 | 545 | 59 | 2023-08-30T07:59:51Z | 2023-08-29T19:36:04Z | 2173 |
| 359 | * --module o365_spray_activesync* | .{0,1000}\s\-\-module\so365_spray_activesync.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2178 |
| 360 | * monitor /interval:* /filteruser:* | .{0,1000}\smonitor\s\/interval\:.{0,1000}\s\/filteruser\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 2182 |
| 361 | * mssprinkler.ps1* | .{0,1000}\smssprinkler\.ps1.{0,1000} | offensive_tool_keyword | MSSprinkler | password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach | T1110.003 - T1110.001 | TA0006 - TA0007 - TA0008 | N/A | N/A | Credential Access | https://github.com/TheresAFewConors/MSSprinkler | 1 | 0 | N/A | N/A | 9 | 1 | 74 | 7 | 2025-02-25T13:32:41Z | 2024-09-15T09:54:53Z | 2203 |
| 362 | * --mstsc-poison-hkcr* | .{0,1000}\s\-\-mstsc\-poison\-hkcr.{0,1000} | offensive_tool_keyword | ThievingFox | collection of post-exploitation tools to gather credentials from various password managers | T1555 - T1003 - T1056 - T1070 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Slowerzs/ThievingFox | 1 | 0 | N/A | N/A | 10 | 6 | 535 | 65 | 2024-03-28T19:58:03Z | 2024-01-20T23:22:52Z | 2218 |
| 363 | * MultiDump.exe* | .{0,1000}\sMultiDump\.exe.{0,1000} | offensive_tool_keyword | MultiDump | MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly | T1003 - T1564.002 | TA0005 - TA0006 | N/A | N/A | Credential Access | https://github.com/Xre0uS/MultiDump | 1 | 0 | N/A | N/A | 10 | 6 | 510 | 66 | 2025-03-28T10:40:27Z | 2024-02-02T05:56:29Z | 2220 |
| 364 | * nanodump* | .{0,1000}\snanodump.{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 0 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 2253 |
| 365 | * nanodump/* | .{0,1000}\snanodump\/.{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 0 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 2254 |
| 366 | * NativeDump.exe* | .{0,1000}\sNativeDump\.exe.{0,1000} | offensive_tool_keyword | NativeDump | Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!) | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/ricardojoserf/NativeDump | 1 | 0 | N/A | N/A | 10 | 6 | 586 | 86 | 2024-12-17T15:36:57Z | 2024-02-22T15:16:16Z | 2255 |
| 367 | * nc_srv.bat* | .{0,1000}\snc_srv\.bat.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 2268 |
| 368 | * needs High Integrity Privileges to dump the relevant process!* | .{0,1000}\sneeds\sHigh\sIntegrity\sPrivileges\sto\sdump\sthe\srelevant\sprocess!.{0,1000} | offensive_tool_keyword | pandora | A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers | T1555 - T1003 | TA0006 - TA0003 | N/A | N/A | Credential Access | https://github.com/efchatz/pandora | 1 | 0 | #content | N/A | 10 | 8 | 738 | 88 | 2025-01-09T14:58:57Z | 2023-11-03T18:01:31Z | 2274 |
| 369 | * --neo4j-host * | .{0,1000}\s\-\-neo4j\-host\s.{0,1000} | offensive_tool_keyword | smartbrute | Password spraying and bruteforcing tool for Active Directory Domain Services | T1110.001 - T1110.003 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/smartbrute | 1 | 0 | N/A | N/A | 10 | 4 | 365 | 54 | 2024-10-27T20:47:29Z | 2021-07-16T14:53:29Z | 2279 |
| 370 | * --neo4j-host *--neo4j-port* | .{0,1000}\s\-\-neo4j\-host\s.{0,1000}\-\-neo4j\-port.{0,1000} | offensive_tool_keyword | sprayhound | Password spraying tool and Bloodhound integration | T1110.003 - T1210.001 - T1069.002 | TA0006 - TA0007 - TA0003 | N/A | N/A | Credential Access | https://github.com/Hackndo/sprayhound | 1 | 0 | N/A | N/A | N/A | 3 | 231 | 19 | 2024-12-31T08:09:37Z | 2020-02-06T17:45:37Z | 2280 |
| 371 | * -neo4j-password * | .{0,1000}\s\-neo4j\-password\s.{0,1000} | offensive_tool_keyword | smartbrute | Password spraying and bruteforcing tool for Active Directory Domain Services | T1110.001 - T1110.003 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/smartbrute | 1 | 0 | N/A | N/A | 10 | 4 | 365 | 54 | 2024-10-27T20:47:29Z | 2021-07-16T14:53:29Z | 2281 |
| 372 | * --neo4j-port * | .{0,1000}\s\-\-neo4j\-port\s.{0,1000} | offensive_tool_keyword | smartbrute | Password spraying and bruteforcing tool for Active Directory Domain Services | T1110.001 - T1110.003 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/smartbrute | 1 | 0 | N/A | N/A | 10 | 4 | 365 | 54 | 2024-10-27T20:47:29Z | 2021-07-16T14:53:29Z | 2282 |
| 373 | * --neo4j-user * | .{0,1000}\s\-\-neo4j\-user\s.{0,1000} | offensive_tool_keyword | smartbrute | Password spraying and bruteforcing tool for Active Directory Domain Services | T1110.001 - T1110.003 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/smartbrute | 1 | 0 | N/A | N/A | 10 | 4 | 365 | 54 | 2024-10-27T20:47:29Z | 2021-07-16T14:53:29Z | 2283 |
| 374 | * netripper* | .{0,1000}\snetripper.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2299 |
| 375 | * NiceRAT.py* | .{0,1000}\sNiceRAT\.py.{0,1000} | offensive_tool_keyword | cstealer | NiceRAT stealer - clone of cstealer | T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/0x00G/NiceRAT | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 86 | 2024-10-20T18:38:53Z | 2022-11-20T19:11:00Z | 2312 |
| 376 | * --ntds * -crack * | .{0,1000}\s\-\-ntds\s.{0,1000}\s\-crack\s.{0,1000} | offensive_tool_keyword | autoNTDS | autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat | T1003 - T1059 - T1021.002 - T1213 | TA0006 - TA0008 - TA0005 - TA0002 | N/A | N/A | Credential Access | https://github.com/hmaverickadams/autoNTDS | 1 | 0 | N/A | N/A | 10 | 2 | 109 | 14 | 2023-10-31T22:03:58Z | 2023-10-30T23:10:58Z | 2381 |
| 377 | * -ntds NTDS.dit -filters* | .{0,1000}\s\-ntds\sNTDS\.dit\s\s\-filters.{0,1000} | offensive_tool_keyword | ntdissector | Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class. | T1003.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/synacktiv/ntdissector | 1 | 0 | N/A | N/A | 9 | 2 | 139 | 17 | 2024-08-16T14:18:35Z | 2023-09-05T12:13:47Z | 2383 |
| 378 | * -ntds ntds.dit -system SYSTEM * | .{0,1000}\s\-ntds\sntds\.dit\s\-system\sSYSTEM\s.{0,1000} | offensive_tool_keyword | impacket | Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself | T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047 | TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011 | N/A | Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta | Credential Access | https://github.com/fortra/impacket | 1 | 0 | N/A | N/A | 10 | 10 | 14198 | 3681 | 2025-04-22T13:40:55Z | 2015-04-15T14:04:07Z | 2384 |
| 379 | * -ntds NTDS.dit -system SYSTEM -outputdir /* | .{0,1000}\s\-ntds\sNTDS\.dit\s\-system\sSYSTEM\s\-outputdir\s\/.{0,1000} | offensive_tool_keyword | ntdissector | Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class. | T1003.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/synacktiv/ntdissector | 1 | 0 | N/A | N/A | 9 | 2 | 139 | 17 | 2024-08-16T14:18:35Z | 2023-09-05T12:13:47Z | 2385 |
| 380 | * --ntds-file * | .{0,1000}\s\-\-ntds\-file\s.{0,1000} | offensive_tool_keyword | quarkspwdump | Quarks PwDump is a native Win32 tool to extract credentials from Windows operating systems | T1003 - T1003.001 - T1059 | TA0006 | N/A | LOTUS PANDA - PowerPool - Calypso | Credential Access | https://github.com/peterdocter/quarkspwdump | 1 | 0 | N/A | N/A | 9 | 1 | 12 | 8 | 2015-06-25T04:22:21Z | 2015-07-14T08:18:08Z | 2387 |
| 381 | * --ntds-history* | .{0,1000}\s\-\-ntds\-history.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2388 |
| 382 | * --ntds-pwdLastSet* | .{0,1000}\s\-\-ntds\-pwdLastSet.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2389 |
| 383 | * ntdsuseraccount.py* | .{0,1000}\sntdsuseraccount\.py.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 2390 |
| 384 | * ntlm.wordlist *--hex-wordlist* | .{0,1000}\sntlm\.wordlist\s.{0,1000}\-\-hex\-wordlist.{0,1000} | offensive_tool_keyword | hashcat | Worlds fastest and most advanced password recovery utility. | T1110.001 - T1003.001 - T1021.001 | TA0006 - TA0009 - TA0010 | N/A | Black Basta | Credential Access | https://github.com/hashcat/hashcat | 1 | 0 | #linux | N/A | 10 | 10 | 22481 | 3046 | 2024-08-16T23:50:35Z | 2015-12-04T14:46:51Z | 2395 |
| 385 | * ntlmdecoder.py* | .{0,1000}\sntlmdecoder\.py.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 2396 |
| 386 | * ntlmdecoder.py* | .{0,1000}\sntlmdecoder\.py.{0,1000} | offensive_tool_keyword | SprayingToolkit | Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient | T1110 - T1078 - T1133 - T1061 - T1621 | TA0001 - TA0002 - TA0003 | N/A | N/A | Credential Access | https://github.com/byt3bl33d3r/SprayingToolkit | 1 | 0 | N/A | N/A | 10 | 10 | 1491 | 269 | 2022-10-17T01:01:57Z | 2018-09-13T09:52:11Z | 2397 |
| 387 | * --ntlm-hash --company * --import-cracked * | .{0,1000}\s\-\-ntlm\-hash\s\-\-company\s.{0,1000}\s\-\-import\-cracked\s.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 2398 |
| 388 | * --ntlm-hash --export-hashes * | .{0,1000}\s\-\-ntlm\-hash\s\-\-export\-hashes\s.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 2399 |
| 389 | * --ntlm-hash --import-ntds *.ntds* | .{0,1000}\s\-\-ntlm\-hash\s\-\-import\-ntds\s.{0,1000}\.ntds.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 2400 |
| 390 | * -o sprayed.txt* | .{0,1000}\s\-o\ssprayed\.txt.{0,1000} | offensive_tool_keyword | SharpSpray | SharpSpray is a Windows domain password spraying tool written in .NET C# | T1110 | TA0006 | N/A | N/A | Credential Access | https://github.com/iomoath/SharpSpray | 1 | 0 | N/A | N/A | 10 | 2 | 130 | 21 | 2021-11-25T19:13:56Z | 2021-08-31T16:09:45Z | 2419 |
| 391 | * o365_enum_activesync.py* | .{0,1000}\so365_enum_activesync\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2421 |
| 392 | * o365_enum_office.py* | .{0,1000}\so365_enum_office\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2422 |
| 393 | * o365_enum_onedrive.py* | .{0,1000}\so365_enum_onedrive\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2423 |
| 394 | * o365_spray_activesync.py* | .{0,1000}\so365_spray_activesync\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2424 |
| 395 | * o365_spray_adfs.py* | .{0,1000}\so365_spray_adfs\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2425 |
| 396 | * o365_spray_msol.py* | .{0,1000}\so365_spray_msol\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2426 |
| 397 | * o365spray.py* | .{0,1000}\so365spray\.py.{0,1000} | offensive_tool_keyword | o365spray | Username enumeration and password spraying tool aimed at Microsoft O365 | T1110.003 - T1087.002 | TA0007 - TA0006 | N/A | N/A | Credential Access | https://github.com/0xZDH/o365spray | 1 | 0 | N/A | N/A | 8 | 9 | 846 | 100 | 2024-11-06T00:49:23Z | 2019-08-07T14:47:45Z | 2427 |
| 398 | * -oA icebreaker-scan* | .{0,1000}\s\-oA\sicebreaker\-scan.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 0 | N/A | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 2428 |
| 399 | * OfflineSamTool.h* | .{0,1000}\sOfflineSamTool\.h.{0,1000} | greyware_tool_keyword | oset | Offline SAM Editor Tool to access and edit SAM databases from offline OS disk | T1078 - T1003.002 - T1547.001 | TA0003 - TA0006 - TA0007 - TA0005 | N/A | N/A | Credential Access | https://x.com/0gtweet/status/1817859483445461406 | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2436 |
| 400 | * oh365userfinder.py* | .{0,1000}\soh365userfinder\.py.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 2437 |
| 401 | * omnispray.py* | .{0,1000}\somnispray\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2440 |
| 402 | * --outpath * --config *.json --backdoor* | .{0,1000}\s\-\-outpath\s.{0,1000}\s\-\-config\s.{0,1000}\.json\s\-\-backdoor.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 2468 |
| 403 | * --outpath *.json --backdoor* | .{0,1000}\s\-\-outpath\s.{0,1000}\.json\s\-\-backdoor.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 2469 |
| 404 | * owa * --user-as-pass * | .{0,1000}\sowa\s.{0,1000}\s\-\-user\-as\-pass\s.{0,1000} | offensive_tool_keyword | SprayingToolkit | Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient | T1110 - T1078 - T1133 - T1061 - T1621 | TA0001 - TA0002 - TA0003 | N/A | N/A | Credential Access | https://github.com/byt3bl33d3r/SprayingToolkit | 1 | 0 | N/A | N/A | 10 | 10 | 1491 | 269 | 2022-10-17T01:01:57Z | 2018-09-13T09:52:11Z | 2473 |
| 405 | * owa_enum_activesync.py* | .{0,1000}\sowa_enum_activesync\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2474 |
| 406 | * owa_spray_activesync.py* | .{0,1000}\sowa_spray_activesync\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2475 |
| 407 | * owa-sprayed-creds.txt* | .{0,1000}\sowa\-sprayed\-creds\.txt.{0,1000} | offensive_tool_keyword | EASSniper | EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS) | T1110 - T1078.003 - T1087.002 - T1059.001 | TA0006 -TA0007 - TA0009 - TA0002 - TA0001 | N/A | N/A | Credential Access | https://github.com/fugawi/EASSniper | 1 | 0 | N/A | N/A | 10 | 1 | 5 | 4 | 2018-04-17T23:23:31Z | 2018-04-17T22:43:51Z | 2476 |
| 408 | * -p pwd1.list pwd2.list * | .{0,1000}\s\-p\spwd1\.list\spwd2\.list\s.{0,1000} | offensive_tool_keyword | cheetah | a very fast brute force webshell password tool | T1110 - T1190 - T1505.003 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/shmilylty/cheetah | 1 | 0 | N/A | N/A | 10 | 7 | 630 | 150 | 2023-04-17T01:33:52Z | 2017-04-15T20:03:50Z | 2492 |
| 409 | * paloalto_enum_globalprotectportal.py* | .{0,1000}\spaloalto_enum_globalprotectportal\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2508 |
| 410 | * paloalto_spray_globalprotectportal.py* | .{0,1000}\spaloalto_spray_globalprotectportal\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 2509 |
| 411 | * pamspy_event.h* | .{0,1000}\spamspy_event\.h.{0,1000} | offensive_tool_keyword | pamspy | Credentials Dumper for Linux using eBPF | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/citronneur/pamspy | 1 | 0 | #linux | N/A | 10 | 10 | 1135 | 63 | 2024-09-09T13:19:12Z | 2022-07-01T19:33:43Z | 2510 |
| 412 | * PassSpray.ps1* | .{0,1000}\sPassSpray\.ps1.{0,1000} | offensive_tool_keyword | PassSpray | Domain Password Spray | T1110.003 - T1078 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/Leo4j/PassSpray | 1 | 0 | N/A | N/A | 10 | 1 | 7 | 3 | 2025-02-20T10:07:43Z | 2023-11-16T13:35:49Z | 2526 |
| 413 | * --password wordlists/*.txt* | .{0,1000}\s\-\-password\swordlists\/.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | legba | A multiprotocol credentials bruteforcer / password sprayer and enumerator | T1110 - T1110.003 - T1110.001 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/evilsocket/legba | 1 | 0 | N/A | N/A | 10 | 10 | 1577 | 93 | 2025-03-01T15:42:29Z | 2023-10-23T15:44:06Z | 2528 |
| 414 | * password.lst* | .{0,1000}\spassword\.lst.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 2529 |
| 415 | * --password-list * | .{0,1000}\s\-\-password\-list\s.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 0 | N/A | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 2532 |
| 416 | * --passwordsperdelay * | .{0,1000}\s\-\-passwordsperdelay\s.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 2535 |
| 417 | * passwordspray -d * | .{0,1000}\spasswordspray\s\-d\s.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 0 | N/A | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 2537 |
| 418 | * --passwords-to-users *hash* | .{0,1000}\s\-\-passwords\-to\-users\s.{0,1000}hash.{0,1000} | offensive_tool_keyword | autoNTDS | autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat | T1003 - T1059 - T1021.002 - T1213 | TA0006 - TA0008 - TA0005 - TA0002 | N/A | N/A | Credential Access | https://github.com/hmaverickadams/autoNTDS | 1 | 0 | N/A | N/A | 10 | 2 | 109 | 14 | 2023-10-31T22:03:58Z | 2023-10-30T23:10:58Z | 2538 |
| 419 | * -PathToDMP *.dmp* | .{0,1000}\s\-PathToDMP\s.{0,1000}\.dmp.{0,1000} | offensive_tool_keyword | powerextract | This tool is able to parse memory dumps of the LSASS process without any additional tools (e.g. Debuggers) or additional sideloading of mimikatz. It is a pure PowerShell implementation for parsing and extracting secrets (LSA / MSV and Kerberos) of the LSASS process | T1003 - T1055 - T1003.001 - T1055.012 | TA0007 - TA0002 | N/A | N/A | Credential Access | https://github.com/powerseb/PowerExtract | 1 | 0 | N/A | N/A | N/A | 2 | 117 | 14 | 2025-03-28T10:49:43Z | 2021-12-11T15:24:44Z | 2546 |
| 420 | * physmem2minidump.py* | .{0,1000}\sphysmem2minidump\.py.{0,1000} | offensive_tool_keyword | physmem2profit | Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/WithSecureLabs/physmem2profit | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 74 | 2022-07-27T03:33:59Z | 2020-02-14T08:34:27Z | 2603 |
| 421 | * Pictures\Screenshots\loot.zip* | .{0,1000}\sPictures\\Screenshots\\loot\.zip.{0,1000} | offensive_tool_keyword | Harvester_OF_SORROW | The payload opens firefox about:logins and tabs and arrows its way through options. It then takes a screen shot with the first set of log in credentials made visible. Finally it sends the screenshot to an email of your choosing. | T1056.001 - T1113 - T1512 - T1566.001 - T1059.006 | TA0004 - TA0009 - TA0010 - TA0040 | N/A | N/A | Credential Access | https://github.com/hak5/omg-payloads/blob/master/payloads/library/credentials/Harvester_OF_SORROW/payload.txt | 1 | 0 | N/A | N/A | 10 | 10 | 904 | 310 | 2024-09-14T02:34:26Z | 2021-09-08T20:33:18Z | 2605 |
| 422 | * --plugin gmailenum* | .{0,1000}\s\-\-plugin\sgmailenum.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 2616 |
| 423 | * --plugin httpbrute --url * | .{0,1000}\s\-\-plugin\shttpbrute\s\-\-url\s.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 2617 |
| 424 | * --plugin httpbrute* | .{0,1000}\s\-\-plugin\shttpbrute.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 2618 |
| 425 | * --plugin KeeFarceRebornPlugin.dll* | .{0,1000}\s\-\-plugin\sKeeFarceRebornPlugin\.dll.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 0 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 2620 |
| 426 | * --plugin o365enum* | .{0,1000}\s\-\-plugin\so365enum.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 2621 |
| 427 | * PostDump.exe* | .{0,1000}\sPostDump\.exe.{0,1000} | offensive_tool_keyword | POSTDump | perform minidump of LSASS process using few technics to avoid detection | T1003 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/YOLOP0wn/POSTDump | 1 | 0 | N/A | N/A | 10 | 4 | 327 | 37 | 2025-02-05T15:24:52Z | 2023-09-13T11:28:51Z | 2645 |
| 428 | * PPLmedic.exe* | .{0,1000}\sPPLmedic\.exe.{0,1000} | offensive_tool_keyword | PPLmedic | Dump the memory of any PPL with a Userland exploit chain | T1003 - T1055 - T1564.001 | TA0005 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/itm4n/PPLmedic | 1 | 0 | N/A | N/A | 8 | 4 | 333 | 36 | 2023-03-17T15:58:24Z | 2023-03-10T12:07:01Z | 2658 |
| 429 | * Pre2kSpray.ps1* | .{0,1000}\sPre2kSpray\.ps1.{0,1000} | offensive_tool_keyword | Invoke-Pre2kSpray | Enumerate domain machine accounts and perform pre2k password spraying. | T1087.002 - T1110.003 | TA0007 - TA0006 | N/A | N/A | Credential Access | https://github.com/eversinc33/Invoke-Pre2kSpray | 1 | 0 | N/A | N/A | 8 | 1 | 69 | 11 | 2023-07-14T06:50:22Z | 2023-07-05T10:07:38Z | 2660 |
| 430 | * preauthscan /users:* | .{0,1000}\spreauthscan\s\/users\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 2661 |
| 431 | * PrintCreds.py* | .{0,1000}\sPrintCreds\.py.{0,1000} | offensive_tool_keyword | spraykatz | Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments. | T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 | TA0003 - TA0004 - TA0007 | N/A | N/A | Credential Access | https://github.com/aas-n/spraykatz | 1 | 0 | N/A | N/A | 9 | 8 | 763 | 121 | 2020-06-20T12:14:00Z | 2019-09-09T14:38:28Z | 2667 |
| 432 | * ps /target:*.xml /unprotect* | .{0,1000}\sps\s\/target\:.{0,1000}\.xml\s\/unprotect.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 2685 |
| 433 | * ptt /ticket:* | .{0,1000}\sptt\s\/ticket\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 2698 |
| 434 | * pwcrack.sh* | .{0,1000}\spwcrack\.sh.{0,1000} | offensive_tool_keyword | nsa-rules | Password cracking rules and masks for hashcat that I generated from cracked passwords. | T1110.002 - T1021.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/NSAKEY/nsa-rules | 1 | 0 | N/A | N/A | 10 | 6 | 547 | 125 | 2017-01-03T11:53:25Z | 2016-02-15T20:49:32Z | 2723 |
| 435 | * pwcrack-framework* | .{0,1000}\spwcrack\-framework.{0,1000} | offensive_tool_keyword | pwcrack-framework | Password Crack Framework | T1110 - T1003 - T1059 | TA0006 | N/A | N/A | Credential Access | https://github.com/L-codes/pwcrack-framework | 1 | 0 | N/A | N/A | 10 | 6 | 515 | 59 | 2024-02-25T13:08:56Z | 2018-07-01T08:33:55Z | 2724 |
| 436 | * pwdump.py* | .{0,1000}\spwdump\.py.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 0 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 2725 |
| 437 | * PWDumpX process * | .{0,1000}\sPWDumpX\sprocess\s.{0,1000} | offensive_tool_keyword | PWDumpX | PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://packetstormsecurity.com/files/download/52580/PWDumpX.zip | 1 | 0 | #content | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 2728 |
| 438 | * PWDumpX service * | .{0,1000}\sPWDumpX\sservice\s.{0,1000} | offensive_tool_keyword | PWDumpX | PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://packetstormsecurity.com/files/download/52580/PWDumpX.zip | 1 | 0 | #content | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 2729 |
| 439 | * Pwn3d!* | .{0,1000}\sPwn3d!.{0,1000} | offensive_tool_keyword | crackmapexec | A swiss army knife for pentesting networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2733 |
| 440 | * pyLAPS.py* | .{0,1000}\spyLAPS\.py.{0,1000} | offensive_tool_keyword | pyLAPS | A simple way to read and write LAPS passwords from linux. | T1136.001 - T1112 - T1078.001 | TA0002 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/p0dalirius/pyLAPS | 1 | 0 | #linux | N/A | 9 | 2 | 105 | 16 | 2024-10-28T08:36:38Z | 2021-10-05T18:35:21Z | 2739 |
| 441 | * -r airolib-db /root/wpa.cap* | .{0,1000}\s\-r\sairolib\-db\s\/root\/wpa\.cap.{0,1000} | offensive_tool_keyword | aircrack | cracking Wi-Fi security including WEP and WPA/WPA2-PSK encryption | T1078 - T1496 - T1040 | TA0006 - TA0008 - TA0005 | N/A | N/A | Credential Access | https://github.com/aircrack-ng/aircrack-ng | 1 | 0 | N/A | N/A | 5 | 10 | 5967 | 1032 | 2024-12-19T21:36:56Z | 2018-03-10T17:11:11Z | 2754 |
| 442 | * RagingRotator.go* | .{0,1000}\sRagingRotator\.go.{0,1000} | offensive_tool_keyword | RagingRotator | A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways. | T1110 - T1027 - T1071 - T1090 - T1621 | TA0006 - TA0005 - TA0001 | N/A | N/A | Credential Access | https://github.com/nickzer0/RagingRotator | 1 | 0 | N/A | N/A | 10 | 1 | 79 | 7 | 2024-06-06T19:31:34Z | 2023-09-01T15:19:38Z | 2761 |
| 443 | * --random_user_agent* | .{0,1000}\s\-\-random_user_agent.{0,1000} | offensive_tool_keyword | Spray365 | Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/MarkoH17/Spray365 | 1 | 0 | N/A | N/A | N/A | 4 | 348 | 58 | 2022-07-14T14:45:57Z | 2021-11-04T18:20:39Z | 2764 |
| 444 | * rawrpc_embedded.py* | .{0,1000}\srawrpc_embedded\.py.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 2776 |
| 445 | * --rdcman-poison-hkcr* | .{0,1000}\s\-\-rdcman\-poison\-hkcr.{0,1000} | offensive_tool_keyword | ThievingFox | collection of post-exploitation tools to gather credentials from various password managers | T1555 - T1003 - T1056 - T1070 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Slowerzs/ThievingFox | 1 | 0 | N/A | N/A | 10 | 6 | 535 | 65 | 2024-03-28T19:58:03Z | 2024-01-20T23:22:52Z | 2781 |
| 446 | * RDPHook.dll* | .{0,1000}\sRDPHook\.dll.{0,1000} | offensive_tool_keyword | SharpRDPThief | A C# implementation of RDPThief to steal credentials from RDP | T1056.004 - T1110 - T1563.002 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/passthehashbrowns/SharpRDPThief | 1 | 0 | N/A | N/A | 10 | 2 | 160 | 28 | 2020-08-28T03:48:51Z | 2020-08-26T22:27:36Z | 2789 |
| 447 | * RdpThief.dll* | .{0,1000}\sRdpThief\.dll.{0,1000} | offensive_tool_keyword | Invoke-RDPThief | perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials | T1055 - T1056 - T1071 - T1110 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/The-Viper-One/Invoke-RDPThief | 1 | 0 | N/A | N/A | 10 | 1 | 62 | 8 | 2025-01-21T20:12:33Z | 2024-10-01T20:12:00Z | 2791 |
| 448 | * rdpv.exe* | .{0,1000}\srdpv\.exe.{0,1000} | offensive_tool_keyword | rdpv | RemoteDesktopPassView is a small utility that reveals the password stored by Microsoft Remote Desktop Connection utility inside the .rdp files. | T1110 - T1560.001 - T1555.003 - T1212 | TA0006 - TA0007 | N/A | Phobos - GoGoogle - Kimsuky | Credential Access | https://www.nirsoft.net/utils/remote_desktop_password.html | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 2792 |
| 449 | * -Remote -ExchHostname * | .{0,1000}\s\-Remote\s\-ExchHostname\s.{0,1000} | offensive_tool_keyword | MailSniper | MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain. | T1087.003 - T1110.003 - T1114.002 | TA0006 -TA0009 -TA0007 | N/A | Leafminer | Credential Access | https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1 | 1 | 0 | N/A | N/A | N/A | 10 | 3046 | 580 | 2024-08-07T18:11:58Z | 2016-09-08T00:36:51Z | 2829 |
| 450 | * renew *.kirbi* | .{0,1000}\srenew\s.{0,1000}\.kirbi.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 2858 |
| 451 | * renew */ticket:* | .{0,1000}\srenew\s.{0,1000}\/ticket\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 2859 |
| 452 | * --RestoreShadowCred* | .{0,1000}\s\-\-RestoreShadowCred.{0,1000} | offensive_tool_keyword | ShadowSpray | A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain. | T1556.005 - T1098.001 - T1098 | TA0006 - TA0008 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/Dec0ne/ShadowSpray | 1 | 0 | N/A | N/A | 10 | 5 | 459 | 80 | 2022-10-14T13:36:51Z | 2022-10-10T08:34:07Z | 2872 |
| 453 | * restoresig.py* | .{0,1000}\srestoresig\.py.{0,1000} | offensive_tool_keyword | LetMeowIn | A sophisticated covert Windows-based credential dumper using C++ and MASM x64. | T1003 - T1055.011 - T1148 | TA0006 | N/A | N/A | Credential Access | https://github.com/Meowmycks/LetMeowIn | 1 | 0 | N/A | N/A | 10 | 5 | 401 | 70 | 2024-07-08T15:58:37Z | 2024-04-09T16:33:27Z | 2873 |
| 454 | * revshell32.bin* | .{0,1000}\srevshell32\.bin.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 2889 |
| 455 | * revshell64.bin* | .{0,1000}\srevshell64\.bin.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 2890 |
| 456 | * --rid-brute* | .{0,1000}\s\-\-rid\-brute.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 2902 |
| 457 | * rockyou.txt * | .{0,1000}\srockyou\.txt\s.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 2913 |
| 458 | * rpcdump.py* | .{0,1000}\srpcdump\.py.{0,1000} | offensive_tool_keyword | NetNTLMtoSilverTicket | Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket. | T1110.001 - T1558.003 - T1558.004 | TA0006 - TA0008 - TA0002 | N/A | N/A | Credential Access | https://github.com/NotMedic/NetNTLMtoSilverTicket | 1 | 0 | N/A | N/A | 10 | 9 | 842 | 113 | 2021-07-26T15:16:20Z | 2019-01-14T15:32:27Z | 2924 |
| 459 | * Rubeus.dll* | .{0,1000}\sRubeus\.dll.{0,1000} | offensive_tool_keyword | Rubeus | Run Rubeus via Rundll32 (potential application whitelisting bypass technique) | T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004 | TA0005 - TA0002 - TA0006 - TA0008 - TA0009 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/rvrsh3ll/Rubeus-Rundll32 | 1 | 0 | N/A | N/A | 10 | 3 | 200 | 32 | 2020-04-25T19:55:27Z | 2020-04-24T20:35:38Z | 2942 |
| 460 | * Rubeus.ps1* | .{0,1000}\sRubeus\.ps1.{0,1000} | offensive_tool_keyword | Rubeus | Run Rubeus via Rundll32 (potential application whitelisting bypass technique) | T1558.004 - T1098 - T1110.001 - T1555.003 - T1218.011 - T1085 - T1070.004 | TA0005 - TA0002 - TA0006 - TA0008 - TA0009 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/rvrsh3ll/Rubeus-Rundll32 | 1 | 0 | N/A | N/A | 10 | 3 | 200 | 32 | 2020-04-25T19:55:27Z | 2020-04-24T20:35:38Z | 2943 |
| 461 | * --rules:Jumbo * | .{0,1000}\s\-\-rules\:Jumbo\s.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 2945 |
| 462 | * run donpapi* | .{0,1000}\srun\sdonpapi.{0,1000} | offensive_tool_keyword | donpapi | Dumping DPAPI credentials remotely | T1003.006 - T1021.001 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/login-securite/DonPAPI | 1 | 0 | N/A | N/A | N/A | 10 | 1110 | 130 | 2025-03-24T10:23:58Z | 2021-09-27T09:12:51Z | 2946 |
| 463 | * s4u * /bronzebit* | .{0,1000}\ss4u\s.{0,1000}\s\/bronzebit.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 2971 |
| 464 | * s4u * /nopac* | .{0,1000}\ss4u\s.{0,1000}\s\/nopac.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 2972 |
| 465 | * s4u * /ticket:* | .{0,1000}\ss4u\s.{0,1000}\s\/ticket\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 2973 |
| 466 | * s4u *.kirbi* | .{0,1000}\ss4u\s.{0,1000}\.kirbi.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 2974 |
| 467 | * s4u */rc4:* | .{0,1000}\ss4u\s.{0,1000}\/rc4\:.{0,1000}\s | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 2975 |
| 468 | * sam_reset_all_pw(* | .{0,1000}\ssam_reset_all_pw\(.{0,1000} | offensive_tool_keyword | chntpw | reset a password on your system | T1003 - T1078 | TA0006 | N/A | N/A | Credential Access | https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2978 |
| 469 | * scan --github-org* | .{0,1000}\sscan\s\-\-github\-org.{0,1000} | offensive_tool_keyword | noseyparker | Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history. | T1583 - T1059.001 - T1059.003 | TA0002 - TA0003 - TA0040 | N/A | N/A | Credential Access | https://github.com/praetorian-inc/noseyparker | 1 | 0 | N/A | N/A | 8 | 10 | 1903 | 100 | 2025-03-07T20:15:34Z | 2022-11-08T23:09:17Z | 2989 |
| 470 | * scan --github-user* | .{0,1000}\sscan\s\-\-github\-user.{0,1000} | offensive_tool_keyword | noseyparker | Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history. | T1583 - T1059.001 - T1059.003 | TA0002 - TA0003 - TA0040 | N/A | N/A | Credential Access | https://github.com/praetorian-inc/noseyparker | 1 | 0 | N/A | N/A | 8 | 10 | 1903 | 100 | 2025-03-07T20:15:34Z | 2022-11-08T23:09:17Z | 2990 |
| 471 | * --script smb-security-mode*smb-enum-shares * | .{0,1000}\s\-\-script\ssmb\-security\-mode.{0,1000}smb\-enum\-shares\s.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 0 | N/A | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 3009 |
| 472 | * --seclogon-duplicate* | .{0,1000}\s\-\-seclogon\-duplicate.{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 0 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 3028 |
| 473 | * --secrets-dump -target * | .{0,1000}\s\-\-secrets\-dump\s\-target\s.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 3030 |
| 474 | * secretsdump.py* | .{0,1000}\ssecretsdump\.py.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 3031 |
| 475 | * SecretStealer.ps1* | .{0,1000}\sSecretStealer\.ps1.{0,1000} | offensive_tool_keyword | SecretServerSecretStealer | Powershell script that decrypts the data stored within a Thycotic Secret Server | T1552 - T1027 - T1059 | TA0006 | N/A | EvilCorp* | Credential Access | https://github.com/denandz/SecretServerSecretStealer | 1 | 0 | N/A | N/A | 10 | 1 | 78 | 14 | 2020-08-03T06:52:27Z | 2017-04-21T04:06:24Z | 3034 |
| 476 | * --session=allrules --wordlist* | .{0,1000}\s\-\-session\=allrules\s\-\-wordlist.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 3054 |
| 477 | * SessionGopher.ps1* | .{0,1000}\sSessionGopher\.ps1.{0,1000} | offensive_tool_keyword | SessionGopher | uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally. | T1047 - T1003.008 - T1552.004 - T1555.003 | TA0006 | N/A | PYSA - DarkSide - Sphinx | Credential Access | https://github.com/Arvanaghi/SessionGopher | 1 | 0 | N/A | N/A | 10 | 10 | 1255 | 173 | 2022-11-22T21:33:23Z | 2017-03-08T02:49:32Z | 3056 |
| 478 | * SharpHose.exe* | .{0,1000}\sSharpHose\.exe.{0,1000} | offensive_tool_keyword | SharpHose | Asynchronous Password Spraying Tool in C# for Windows Environments | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/ustayready/SharpHose | 1 | 0 | N/A | N/A | 10 | 4 | 312 | 62 | 2023-12-19T21:06:47Z | 2020-05-01T22:10:49Z | 3089 |
| 479 | * sharpspray.exe* | .{0,1000}\ssharpspray\.exe.{0,1000} | offensive_tool_keyword | SharpSpray | SharpSpray is a Windows domain password spraying tool written in .NET C# | T1110 | TA0006 | N/A | N/A | Credential Access | https://github.com/iomoath/SharpSpray | 1 | 0 | N/A | N/A | 10 | 2 | 130 | 21 | 2021-11-25T19:13:56Z | 2021-08-31T16:09:45Z | 3099 |
| 480 | * --show passwd* | .{0,1000}\s\-\-show\spasswd.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | #linux | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 3120 |
| 481 | * --show_invalid_creds* | .{0,1000}\s\-\-show_invalid_creds.{0,1000} | offensive_tool_keyword | Spray365 | Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/MarkoH17/Spray365 | 1 | 0 | N/A | N/A | N/A | 4 | 348 | 58 | 2022-07-14T14:45:57Z | 2021-11-04T18:20:39Z | 3121 |
| 482 | * --shtinkering* | .{0,1000}\s\-\-shtinkering.{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 0 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 3122 |
| 483 | * --shuffle-users* --spray* | .{0,1000}\s\-\-shuffle\-users.{0,1000}\s\-\-spray.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 3123 |
| 484 | * sigthief.py* | .{0,1000}\ssigthief\.py.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 0 | N/A | N/A | 10 | N/A | 3133 | ||||
| 485 | * --silent-process-exit * | .{0,1000}\s\-\-silent\-process\-exit\s.{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 0 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 3136 |
| 486 | * silver * /domain* | .{0,1000}\ssilver\s.{0,1000}\s\/domain.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 3138 |
| 487 | * silver * /ldap * | .{0,1000}\ssilver\s.{0,1000}\s\/ldap\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 3139 |
| 488 | * silver * /passlastset * | .{0,1000}\ssilver\s.{0,1000}\s\/passlastset\s.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 3140 |
| 489 | * silver * /service:* | .{0,1000}\ssilver\s.{0,1000}\s\/service\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 3141 |
| 490 | * --single shadow.hashes* | .{0,1000}\s\-\-single\sshadow\.hashes.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 3143 |
| 491 | * smb client * shares *use c$* | .{0,1000}\ssmb\sclient\s.{0,1000}\sshares\s.{0,1000}use\sc\$.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 3199 |
| 492 | * smb -M mimikatz --options* | .{0,1000}\ssmb\s\-M\smimikatz\s\-\-options.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3200 |
| 493 | * smb shareenum *smb2+ntlm-password* | .{0,1000}\ssmb\sshareenum\s.{0,1000}smb2\+ntlm\-password.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 3201 |
| 494 | * smb* -u '' -p ''* | .{0,1000}\ssmb.{0,1000}\s\-u\s\'\'\s\-p\s\'\'.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3203 |
| 495 | * smb-cmds.txt* | .{0,1000}\ssmb\-cmds\.txt.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 0 | N/A | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 3212 |
| 496 | * smbexec.py* | .{0,1000}\ssmbexec\.py.{0,1000} | offensive_tool_keyword | crackmapexec | protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3221 |
| 497 | * smbrelayserver.py* | .{0,1000}\ssmbrelayserver\.py.{0,1000} | offensive_tool_keyword | NtlmRelayToEWS | ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS) | T1212 - T1557 - T1040 - T1078 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/Arno0x/NtlmRelayToEWS | 1 | 0 | N/A | N/A | 10 | 4 | 331 | 60 | 2018-01-15T12:48:02Z | 2017-10-13T18:00:50Z | 3233 |
| 498 | * Snake.sh * | .{0,1000}\/Snake\.sh.{0,1000} | offensive_tool_keyword | SSH-Snake | SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery | T1021.004 - T1027 - T1552.004 | TA0002 - TA0005 - TA0006 | N/A | N/A | Credential Access | https://github.com/MegaManSec/SSH-Snake | 1 | 0 | #linux | N/A | 10 | 10 | 2065 | 198 | 2024-07-25T09:32:07Z | 2023-12-03T04:52:38Z | 3272 |
| 499 | * Snake.sh* | .{0,1000}\sSnake\.sh.{0,1000} | offensive_tool_keyword | SSH-Snake | SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery | T1021.004 - T1027 - T1552.004 | TA0002 - TA0005 - TA0006 | N/A | N/A | Credential Access | https://github.com/MegaManSec/SSH-Snake | 1 | 0 | N/A | N/A | 10 | 10 | 2065 | 198 | 2024-07-25T09:32:07Z | 2023-12-03T04:52:38Z | 3273 |
| 500 | * SocialBox.sh* | .{0,1000}\sSocialBox\.sh.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/samsesh/SocialBox-Termux | 1 | 0 | N/A | N/A | 7 | 10 | 3581 | 391 | 2024-09-02T19:15:22Z | 2019-03-28T18:07:05Z | 3291 |
| 501 | * --spray *--shuffle-users* | .{0,1000}\s\-\-spray\s.{0,1000}\-\-shuffle\-users.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 3320 |
| 502 | * spray -ep ex-plan.s365* | .{0,1000}\sspray\s\-ep\sex\-plan\.s365.{0,1000} | offensive_tool_keyword | Spray365 | Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/MarkoH17/Spray365 | 1 | 0 | N/A | N/A | N/A | 4 | 348 | 58 | 2022-07-14T14:45:57Z | 2021-11-04T18:20:39Z | 3321 |
| 503 | * --spray --passwords * | .{0,1000}\s\-\-spray\s\-\-passwords\s.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 3322 |
| 504 | * --spray --push-locked --months-only --exclude * | .{0,1000}\s\-\-spray\s\-\-push\-locked\s\-\-months\-only\s\-\-exclude\s.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 3323 |
| 505 | * --spray --push-locked --months-only* | .{0,1000}\s\-\-spray\s\-\-push\-locked\s\-\-months\-only.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 3324 |
| 506 | * spray -u * -H * -p * -m owa* | .{0,1000}\sspray\s\-u\s.{0,1000}\s\-H\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sowa.{0,1000} | offensive_tool_keyword | spraycharles | Low and slow password spraying tool | T1110.003 - T1110.001 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Tw1sm/spraycharles | 1 | 0 | N/A | N/A | 10 | 2 | 195 | 32 | 2025-02-09T03:08:09Z | 2018-09-17T11:17:47Z | 3325 |
| 507 | * spray -u * -p * -m Office365* | .{0,1000}\sspray\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sOffice365.{0,1000} | offensive_tool_keyword | spraycharles | Low and slow password spraying tool | T1110.003 - T1110.001 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Tw1sm/spraycharles | 1 | 0 | N/A | N/A | 10 | 2 | 195 | 32 | 2025-02-09T03:08:09Z | 2018-09-17T11:17:47Z | 3326 |
| 508 | * spray -u * -p * -m Smb -H * | .{0,1000}\sspray\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sSmb\s\-H\s.{0,1000} | offensive_tool_keyword | spraycharles | Low and slow password spraying tool | T1110.003 - T1110.001 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Tw1sm/spraycharles | 1 | 0 | N/A | N/A | 10 | 2 | 195 | 32 | 2025-02-09T03:08:09Z | 2018-09-17T11:17:47Z | 3327 |
| 509 | * spraycharles.py* | .{0,1000}\sspraycharles\.py.{0,1000} | offensive_tool_keyword | spraycharles | Low and slow password spraying tool | T1110.003 - T1110.001 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Tw1sm/spraycharles | 1 | 0 | N/A | N/A | 10 | 2 | 195 | 32 | 2025-02-09T03:08:09Z | 2018-09-17T11:17:47Z | 3328 |
| 510 | * SprayLove.py* | .{0,1000}\sSprayLove\.py.{0,1000} | offensive_tool_keyword | spraykatz | Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments. | T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 | TA0003 - TA0004 - TA0007 | N/A | N/A | Credential Access | https://github.com/aas-n/spraykatz | 1 | 0 | N/A | N/A | 9 | 8 | 763 | 121 | 2020-06-20T12:14:00Z | 2019-09-09T14:38:28Z | 3329 |
| 511 | * --spraypassword * | .{0,1000}\s\-\-spraypassword\s.{0,1000} | offensive_tool_keyword | SharpHose | Asynchronous Password Spraying Tool in C# for Windows Environments | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/ustayready/SharpHose | 1 | 0 | N/A | N/A | 10 | 4 | 312 | 62 | 2023-12-19T21:06:47Z | 2020-05-01T22:10:49Z | 3330 |
| 512 | * SQLDmpr0001.mdmp* | .{0,1000}\sSQLDmpr0001\.mdmp.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 3335 |
| 513 | * Starting pre2k spray against * | .{0,1000}\sStarting\spre2k\sspray\sagainst\s.{0,1000} | offensive_tool_keyword | Invoke-Pre2kSpray | Enumerate domain machine accounts and perform pre2k password spraying. | T1087.002 - T1110.003 | TA0007 - TA0006 | N/A | N/A | Credential Access | https://github.com/eversinc33/Invoke-Pre2kSpray | 1 | 0 | #content | N/A | 8 | 1 | 69 | 11 | 2023-07-14T06:50:22Z | 2023-07-05T10:07:38Z | 3398 |
| 514 | * Successfully hijacked KeePassXC.exe* | .{0,1000}\sSuccessfully\shijacked\sKeePassXC\.exe.{0,1000} | offensive_tool_keyword | ThievingFox | collection of post-exploitation tools to gather credentials from various password managers | T1555 - T1003 - T1056 - T1070 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Slowerzs/ThievingFox | 1 | 0 | N/A | N/A | 10 | 6 | 535 | 65 | 2024-03-28T19:58:03Z | 2024-01-20T23:22:52Z | 3428 |
| 515 | * SW2_HashSyscall* | .{0,1000}\sSW2_HashSyscall.{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 0 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 3435 |
| 516 | * -system * -ntds *ntds.dit* | .{0,1000}\s\-system\s.{0,1000}\s\-ntds\s.{0,1000}ntds\.dit.{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 0 | N/A | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 3441 |
| 517 | * -t *https://autodiscover.*/autodiscover/autodiscover.xml*autodiscover* | .{0,1000}\s\-t\s.{0,1000}https\:\/\/autodiscover\..{0,1000}\/autodiscover\/autodiscover\.xml.{0,1000}autodiscover.{0,1000} | offensive_tool_keyword | adfspray | Python3 tool to perform password spraying against Microsoft Online service using various methods | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/xFreed0m/ADFSpray | 1 | 0 | N/A | N/A | N/A | 1 | 87 | 14 | 2023-03-12T00:21:34Z | 2020-04-23T08:56:51Z | 3447 |
| 518 | * -target-ip * -remote-dll *.dll* -local-dll * | .{0,1000}\s\-target\-ip\s.{0,1000}\s\-remote\-dll\s.{0,1000}\.dll.{0,1000}\s\-local\-dll\s.{0,1000} | offensive_tool_keyword | DragonCastle | A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process. | T1003 - T1547.005 - T1055 - T1557 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/mdsecactivebreach/DragonCastle | 1 | 0 | N/A | N/A | 10 | 3 | 298 | 38 | 2022-10-26T10:19:55Z | 2022-10-26T10:18:37Z | 3468 |
| 519 | * --target-user * --dc-ip * -command * | .{0,1000}\s\-\-target\-user\s.{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-command\s.{0,1000} | offensive_tool_keyword | whiskeysamlandfriends | GoldenSAML Attack Libraries and Framework | T1606.002 | TA0006 | N/A | N/A | Credential Access | https://github.com/secureworks/whiskeysamlandfriends | 1 | 0 | N/A | N/A | N/A | 1 | 72 | 9 | 2024-06-05T14:56:28Z | 2021-11-04T15:30:12Z | 3483 |
| 520 | * TeamFiltration.dll* | .{0,1000}\sTeamFiltration\.dll.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 3490 |
| 521 | * TeamFiltration.exe* | .{0,1000}\sTeamFiltration\.exe.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 3491 |
| 522 | * teams_dump.py* | .{0,1000}\steams_dump\.py.{0,1000} | offensive_tool_keyword | teams_dump | PoC for dumping and decrypting cookies in the latest version of Microsoft Teams | T1560.001 - T1555.003 - T1113 - T1557 | TA0006 - TA0005 - TA0009 | N/A | N/A | Credential Access | https://github.com/byinarie/teams_dump | 1 | 0 | N/A | N/A | 7 | 2 | 132 | 19 | 2023-11-12T18:47:55Z | 2023-09-18T18:33:32Z | 3492 |
| 523 | * teams_dump.py* | .{0,1000}\steams_dump\.py.{0,1000} | offensive_tool_keyword | teams_dump | PoC for dumping and decrypting cookies in the latest version of Microsoft Teams | T1555 - T1003 - T1114 | TA0006 - TA0005 - TA0009 | N/A | N/A | Credential Access | https://github.com/byinarie/teams_dump | 1 | 0 | N/A | N/A | 9 | 2 | 132 | 19 | 2023-11-12T18:47:55Z | 2023-09-18T18:33:32Z | 3493 |
| 524 | * tgssub * /ticket:* | .{0,1000}\stgssub\s.{0,1000}\s\/ticket\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 3506 |
| 525 | * tgtdeleg /nowrap* | .{0,1000}\stgtdeleg\s\/nowrap.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 3508 |
| 526 | * tgtdeleg /target:* | .{0,1000}\stgtdeleg\s\/target\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 3510 |
| 527 | * thc-hidra* | .{0,1000}\sthc\-hidra.{0,1000} | offensive_tool_keyword | thc-hydra | Parallelized login cracker which supports numerous protocols to attack. | T1110.001 | TA0006 | N/A | ALLANITE - BERSERK BEAR | Credential Access | https://github.com/vanhauser-thc/thc-hydra | 1 | 0 | #linux | N/A | N/A | 10 | 10326 | 2137 | 2025-04-04T12:19:05Z | 2014-04-24T14:45:37Z | 3511 |
| 528 | * ThievingFox.py* | .{0,1000}\sThievingFox\.py.{0,1000} | offensive_tool_keyword | ThievingFox | collection of post-exploitation tools to gather credentials from various password managers | T1555 - T1003 - T1056 - T1070 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Slowerzs/ThievingFox | 1 | 0 | N/A | N/A | 10 | 6 | 535 | 65 | 2024-03-28T19:58:03Z | 2024-01-20T23:22:52Z | 3517 |
| 529 | * ticket_converter.py* | .{0,1000}\sticket_converter\.py.{0,1000} | offensive_tool_keyword | ticket_converter | A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket. | T1558.003 - T1110.004 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/zer1t0/ticket_converter | 1 | 0 | N/A | N/A | 10 | 2 | 167 | 31 | 2022-06-16T19:38:05Z | 2019-05-14T04:48:19Z | 3519 |
| 530 | * ticketsplease.* | .{0,1000}\sticketsplease\..{0,1000} | offensive_tool_keyword | whiskeysamlandfriends | GoldenSAML Attack Libraries and Framework | T1606.002 | TA0006 | N/A | N/A | Credential Access | https://github.com/secureworks/whiskeysamlandfriends | 1 | 0 | N/A | N/A | N/A | 1 | 72 | 9 | 2024-06-05T14:56:28Z | 2021-11-04T15:30:12Z | 3521 |
| 531 | * TokenFinder.py* | .{0,1000}\sTokenFinder\.py.{0,1000} | offensive_tool_keyword | TokenFinder | Tool to extract powerful tokens from Office desktop apps memory | T1003 - T1081 - T1110 | TA0006 - TA0008 - TA0009 | N/A | N/A | Credential Access | https://github.com/doredry/TokenFinder | 1 | 0 | N/A | N/A | 9 | 1 | 71 | 10 | 2024-03-01T14:27:34Z | 2022-09-21T14:21:07Z | 3533 |
| 532 | * TokenUniverse.zip* | .{0,1000}\sTokenUniverse\.zip.{0,1000} | offensive_tool_keyword | TokenUniverse | An advanced tool for working with access tokens and Windows security policy. | T1134 - T1055 - T1056 - T1222 - T1484 | TA0004 - TA0005 - TA0006 | N/A | N/A | Credential Access | https://github.com/diversenok/TokenUniverse | 1 | 0 | N/A | N/A | 8 | 6 | 597 | 66 | 2024-07-20T03:18:21Z | 2018-06-22T21:02:16Z | 3537 |
| 533 | * --tor_password * | .{0,1000}\s\-\-tor_password\s.{0,1000} | offensive_tool_keyword | adfsbrute | test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks | T1110.003 - T1110.001 - T1110 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/ricardojoserf/adfsbrute | 1 | 0 | N/A | N/A | 8 | 2 | 172 | 33 | 2021-04-23T16:43:59Z | 2020-10-02T16:28:35Z | 3543 |
| 534 | * tweetshell.sh* | .{0,1000}\stweetshell\.sh.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/samsesh/SocialBox-Termux | 1 | 0 | N/A | N/A | 7 | 10 | 3581 | 391 | 2024-09-02T19:15:22Z | 2019-03-28T18:07:05Z | 3575 |
| 535 | * --type enum -uf * --module o365_enum_office* | .{0,1000}\s\-\-type\senum\s\-uf\s.{0,1000}\s\-\-module\so365_enum_office.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 3577 |
| 536 | * --type spray -uf * -pf * | .{0,1000}\s\-\-type\sspray\s\-uf\s.{0,1000}\s\-pf\s.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 3582 |
| 537 | * -u * -d * --dc-ip * -k --no-pass --target * --action "list"* | .{0,1000}\s\-u\s.{0,1000}\s\-d\s.{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-k\s\-\-no\-pass\s\-\-target\s.{0,1000}\s\-\-action\s\"list\".{0,1000} | offensive_tool_keyword | pywhisker | Python version of the C# tool for Shadow Credentials attacks | T1552.001 - T1136 - T1098 | TA0003 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/pywhisker | 1 | 0 | N/A | N/A | 10 | 8 | 712 | 89 | 2025-04-21T16:53:22Z | 2021-07-21T19:20:00Z | 3586 |
| 538 | * -u * --local-auth* | .{0,1000}\s\-u\s.{0,1000}\s\-\-local\-auth.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3587 |
| 539 | * -u * -p * --lusers* | .{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-lusers.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3588 |
| 540 | * -u * -p * --sam | .{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-sam | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3592 |
| 541 | * -u * -p * --shares* | .{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-shares.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3593 |
| 542 | * -u * -p *--pass-pol* | .{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\-\-pass\-pol.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3594 |
| 543 | * -u wordlist * wordlist_uniq_sorted* | .{0,1000}\s\-u\swordlist\s.{0,1000}\swordlist_uniq_sorted.{0,1000} | offensive_tool_keyword | wordlists | Various wordlists FR & EN - Cracking French passwords | T1110.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/clem9669/wordlists | 1 | 0 | N/A | N/A | N/A | 3 | 280 | 45 | 2025-04-22T14:34:10Z | 2020-10-21T14:37:53Z | 3602 |
| 544 | * -user * --passwordlist * | .{0,1000}\s\-user\s.{0,1000}\s\-\-passwordlist\s.{0,1000} | offensive_tool_keyword | adfspray | Python3 tool to perform password spraying against Microsoft Online service using various methods | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/xFreed0m/ADFSpray | 1 | 0 | N/A | N/A | N/A | 1 | 87 | 14 | 2023-03-12T00:21:34Z | 2020-04-23T08:56:51Z | 3636 |
| 545 | * -user userlist.txt -pass passwordlist.txt * | .{0,1000}\s\-user\suserlist\.txt\s\-pass\spasswordlist\.txt\s.{0,1000} | offensive_tool_keyword | MSSprinkler | password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach | T1110.003 - T1110.001 | TA0006 - TA0007 - TA0008 | N/A | N/A | Credential Access | https://github.com/TheresAFewConors/MSSprinkler | 1 | 0 | N/A | N/A | 9 | 1 | 74 | 7 | 2025-02-25T13:32:41Z | 2024-09-15T09:54:53Z | 3639 |
| 546 | * --user-as-pass* | .{0,1000}\s\-\-user\-as\-pass.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 0 | N/A | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 3641 |
| 547 | * userenum -d * *.txt* | .{0,1000}\suserenum\s\-d\s.{0,1000}\s.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 0 | N/A | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 3643 |
| 548 | * -UserList * -Domain * -PasswordList * -OutFile * | .{0,1000}\s\-UserList\s.{0,1000}\s\-Domain\s.{0,1000}\s\-PasswordList\s.{0,1000}\s\-OutFile\s.{0,1000} | offensive_tool_keyword | DomainPasswordSpray | DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. | T1110.001 - T1110.003 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/dafthack/DomainPasswordSpray | 1 | 0 | N/A | N/A | 10 | 10 | 1865 | 388 | 2024-07-11T18:18:57Z | 2016-10-04T23:37:37Z | 3645 |
| 549 | * -userpassfile ./userpass_file.txt* | .{0,1000}\s\-userpassfile\s\.\/userpass_file\.txt.{0,1000} | offensive_tool_keyword | RagingRotator | A tool for carrying out brute force attacks against Office 365 with built in IP rotation use AWS gateways. | T1110 - T1027 - T1071 - T1090 - T1621 | TA0006 - TA0005 - TA0001 | N/A | N/A | Credential Access | https://github.com/nickzer0/RagingRotator | 1 | 0 | #linux | N/A | 10 | 1 | 79 | 7 | 2024-06-06T19:31:34Z | 2023-09-01T15:19:38Z | 3651 |
| 550 | * --userpassword_list * | .{0,1000}\s\-\-userpassword_list\s.{0,1000} | offensive_tool_keyword | adfsbrute | test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks | T1110.003 - T1110.001 - T1110 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/ricardojoserf/adfsbrute | 1 | 0 | N/A | N/A | 8 | 2 | 172 | 33 | 2021-04-23T16:43:59Z | 2020-10-02T16:28:35Z | 3652 |
| 551 | * utils.ntlmdecode * | .{0,1000}\sutils\.ntlmdecode\s.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 3656 |
| 552 | * vaporizer.py * | .{0,1000}\svaporizer\.py\s.{0,1000} | offensive_tool_keyword | SprayingToolkit | Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient | T1110 - T1078 - T1133 - T1061 - T1621 | TA0001 - TA0002 - TA0003 | N/A | N/A | Credential Access | https://github.com/byt3bl33d3r/SprayingToolkit | 1 | 0 | N/A | N/A | 10 | 10 | 1491 | 269 | 2022-10-17T01:01:57Z | 2018-09-13T09:52:11Z | 3658 |
| 553 | * vaults /target:* /pvk:* | .{0,1000}\svaults\s\/target\:.{0,1000}\s\/pvk\:.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 3661 |
| 554 | * wcreddump (windows credentials dump)* | .{0,1000}\swcreddump\s\(windows\scredentials\sdump\).{0,1000} | offensive_tool_keyword | wcreddump | Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive. | T1003 - T1110.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/truerustyy/wcreddump | 1 | 0 | #linux #windows #content | N/A | 10 | 1 | 75 | 5 | 2024-11-18T18:37:28Z | 2024-03-05T00:00:20Z | 3691 |
| 555 | * wcreddump.py* | .{0,1000}\swcreddump\.py.{0,1000} | offensive_tool_keyword | wcreddump | Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive. | T1003 - T1110.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/truerustyy/wcreddump | 1 | 0 | #linux #windows | N/A | 10 | 1 | 75 | 5 | 2024-11-18T18:37:28Z | 2024-03-05T00:00:20Z | 3692 |
| 556 | * --wdigest disable* | .{0,1000}\s\-\-wdigest\sdisable.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3694 |
| 557 | * --wdigest enable* | .{0,1000}\s\-\-wdigest\senable.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3695 |
| 558 | * -WebRoot C:\inetpub\wwwroot\SecretServer* | .{0,1000}\s\-WebRoot\sC\:\\inetpub\\wwwroot\\SecretServer.{0,1000} | offensive_tool_keyword | SecretServerSecretStealer | Powershell script that decrypts the data stored within a Thycotic Secret Server | T1552 - T1027 - T1059 | TA0006 | N/A | EvilCorp* | Credential Access | https://github.com/denandz/SecretServerSecretStealer | 1 | 0 | N/A | N/A | 10 | 1 | 78 | 14 | 2020-08-03T06:52:27Z | 2017-04-21T04:06:24Z | 3699 |
| 559 | * --weekday-warrior -* | .{0,1000}\s\-\-weekday\-warrior\s\-.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 3701 |
| 560 | * --werfault *\temp\* | .{0,1000}\s\-\-werfault\s.{0,1000}\\temp\\.{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 0 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 3702 |
| 561 | * Windows-Passwords.ps1* | .{0,1000}\sWindows\-Passwords\.ps1.{0,1000} | offensive_tool_keyword | WLAN-Windows-Passwords | Opens PowerShell hidden - grabs wlan passwords - saves as a cleartext in a variable and exfiltrates info via Discord Webhook. | T1056.005 - T1552.001 - T1119 - T1071.001 | TA0004 - TA0006 - TA0010 - TA0040 | N/A | N/A | Credential Access | https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/WLAN-Windows-Passwords | 1 | 0 | N/A | N/A | 10 | 10 | 904 | 310 | 2024-09-14T02:34:26Z | 2021-09-08T20:33:18Z | 3723 |
| 562 | * WINHELLO2hashcat.py* | .{0,1000}\sWINHELLO2hashcat\.py.{0,1000} | offensive_tool_keyword | wcreddump | Fully automated windows credentials dumper from SAM (classic passwords) and WINHELLO (pins). Requires to be run from a linux machine with a mounted windows drive. | T1003 - T1110.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/truerustyy/wcreddump | 1 | 0 | #linux #windows | N/A | 10 | 1 | 75 | 5 | 2024-11-18T18:37:28Z | 2024-03-05T00:00:20Z | 3725 |
| 563 | * winrm.py* | .{0,1000}\swinrm\.py.{0,1000} | offensive_tool_keyword | crackmapexec | protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3734 |
| 564 | * --wmi *SELECT * | .{0,1000}\s\-\-wmi\s.{0,1000}SELECT\s.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3740 |
| 565 | * wmiexec.py* | .{0,1000}\swmiexec\.py.{0,1000} | offensive_tool_keyword | crackmapexec | protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3743 |
| 566 | * --wmi-namespace 'root\cimv2'* | .{0,1000}\s\-\-wmi\-namespace\s\'root\\cimv2\'.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3747 |
| 567 | * --wordlist=*.lst* | .{0,1000}\s\-\-wordlist\=.{0,1000}\.lst.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 3750 |
| 568 | * -X '$PSVersionTable' * | .{0,1000}\s\-X\s\'\$PSVersionTable\'\s.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3769 |
| 569 | * -X '[System.Environment]::Is64BitProcess'* | .{0,1000}\s\-X\s\'\[System\.Environment\]\:\:Is64BitProcess\'.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines patterns. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3771 |
| 570 | * -x -z --get-users-list* | .{0,1000}\s\-x\s\-z\s\-\-get\-users\-list.{0,1000} | offensive_tool_keyword | SharpSpray | SharpSpray is a Windows domain password spraying tool written in .NET C# | T1110 | TA0006 | N/A | N/A | Credential Access | https://github.com/iomoath/SharpSpray | 1 | 0 | N/A | N/A | 10 | 2 | 130 | 21 | 2021-11-25T19:13:56Z | 2021-08-31T16:09:45Z | 3774 |
| 571 | * -x -z -s 3 -j 1 -u *.txt* | .{0,1000}\s\-x\s\-z\s\-s\s3\s\-j\s1\s\-u\s.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | SharpSpray | SharpSpray is a Windows domain password spraying tool written in .NET C# | T1110 | TA0006 | N/A | N/A | Credential Access | https://github.com/iomoath/SharpSpray | 1 | 0 | N/A | N/A | 10 | 2 | 130 | 21 | 2021-11-25T19:13:56Z | 2021-08-31T16:09:45Z | 3775 |
| 572 | *!!! Are you sure you are running as the AD FS service account?* | .{0,1000}!!!\sAre\syou\ssure\syou\sare\srunning\sas\sthe\sAD\sFS\sservice\saccount\?.{0,1000} | offensive_tool_keyword | ADFSDump | A C# tool to dump all sorts of goodies from AD FS | T1081 - T1003 - T1114 - T1212 | TA0006 - TA0005 - TA0009 | N/A | N/A | Credential Access | https://github.com/mandiant/ADFSDump | 1 | 0 | N/A | N/A | 10 | 4 | 349 | 67 | 2023-08-07T16:58:37Z | 2019-03-20T22:31:16Z | 3796 |
| 573 | *!process 0 0 lsass.exe* | .{0,1000}!process\s0\s0\slsass\.exe.{0,1000} | offensive_tool_keyword | mimikatz | mimikatz strings | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Credential Access | https://github.com/gentilkiwi/mimikatz | 1 | 0 | N/A | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 3805 |
| 574 | *"A La Vie, A L'Amour" - Windows build * | .{0,1000}\"A\sLa\sVie,\sA\sL\'Amour\"\s\-\sWindows\sbuild\s.{0,1000} | offensive_tool_keyword | mimikatz | mimikatz strings | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Credential Access | https://github.com/gentilkiwi/mimikatz | 1 | 0 | N/A | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 3816 |
| 575 | *"author": "@_EthicalChaos_"* | .{0,1000}\"author\"\:\s\"\@_EthicalChaos_\".{0,1000} | offensive_tool_keyword | Shwmae | Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials | T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002 | TA0006 - TA0005 - TA0003 - TA0004 | N/A | N/A | Credential Access | https://github.com/CCob/Shwmae | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 12 | 2025-01-27T14:36:07Z | 2024-03-21T15:05:03Z | 3821 |
| 576 | *"MSGraph token is CAE capable"* | .{0,1000}\"MSGraph\stoken\sis\sCAE\scapable\".{0,1000} | offensive_tool_keyword | TokenTacticsV2 | fork of the great TokenTactics with support for CAE and token endpoint v2 | T1134.002 - T1078.004 - T1095 | TA0005 - TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/f-bader/TokenTacticsV2 | 1 | 0 | N/A | N/A | 6 | 3 | 282 | 38 | 2025-02-25T14:14:25Z | 2022-08-16T17:00:45Z | 3854 |
| 577 | *"RdpStrike.cna"* | .{0,1000}\"RdpStrike\.cna\".{0,1000} | offensive_tool_keyword | RdpStrike | Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP | T1081 - T1055.011 - T1012 - T1113 - T1040 - T1185 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xEr3bus/RdpStrike | 1 | 0 | N/A | N/A | 10 | 3 | 238 | 27 | 2024-06-11T19:40:05Z | 2024-06-11T19:31:50Z | 3862 |
| 578 | *"sacrificialO365Passwords": * | .{0,1000}\"sacrificialO365Passwords\"\:\s.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 3864 |
| 579 | *"sacrificialO365Username": * | .{0,1000}\"sacrificialO365Username\"\:\s.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 3865 |
| 580 | *"Saved in session, but master password prevents plaintext recovery"* | .{0,1000}\"Saved\sin\ssession,\sbut\smaster\spassword\sprevents\splaintext\srecovery\".{0,1000} | offensive_tool_keyword | SessionGopher | uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally. | T1047 - T1003.008 - T1552.004 - T1555.003 | TA0006 | N/A | PYSA - DarkSide - Sphinx | Credential Access | https://github.com/Arvanaghi/SessionGopher | 1 | 0 | #content | N/A | 10 | 10 | 1255 | 173 | 2022-11-22T21:33:23Z | 2017-03-08T02:49:32Z | 3867 |
| 581 | *"The LaZagne project"* | .{0,1000}\"The\sLaZagne\sproject\".{0,1000} | offensive_tool_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 0 | #content | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 3876 |
| 582 | *"User32LogonProcesss"* | .{0,1000}User32LogonProcesss.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://x.com/_RastaMouse/status/1747636529613197757 | 1 | 0 | N/A | typo in the process name used when calling LsaRegisterLogonProcess | 10 | 10 | N/A | N/A | N/A | N/A | 3879 |
| 583 | *"VeeamBackupCreds"* | .{0,1000}\"VeeamBackupCreds\".{0,1000} | offensive_tool_keyword | SharpVeeamDecryptor | Decrypt Veeam database passwords | T1555.005 - T1003 - T1059 | TA0006 - TA0005 - TA0008 | N/A | N/A | Credential Access | https://github.com/S3cur3Th1sSh1t/SharpVeeamDecryptor | 1 | 0 | N/A | used by EMBARGO Ransomware | 10 | 2 | 158 | 18 | 2023-11-07T14:00:47Z | 2023-11-07T14:00:45Z | 3881 |
| 584 | *# Minimalistic AD login bruteforcer * | .{0,1000}\#\sMinimalistic\sAD\slogin\sbruteforcer\s.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Credential Access | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 0 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 3899 |
| 585 | *# Minimalistic SMB login bruteforcer * | .{0,1000}\#\sMinimalistic\sSMB\slogin\sbruteforcer\s.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Credential Access | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 0 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 3900 |
| 586 | *# Using reflection to dump LSASS in-memory with stealth* | .{0,1000}\#\sUsing\sreflection\sto\sdump\sLSASS\sin\-memory\swith\sstealth.{0,1000} | offensive_tool_keyword | Lsassx | Dumping LSASS Evaded Endpoint Security Solutions | T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001 | TA0006 - TA0005 - TA0004 | N/A | N/A | Credential Access | https://github.com/yehia-mamdouh/Lsassx | 1 | 0 | #content | N/A | 10 | 1 | 12 | 3 | 2025-02-15T16:41:38Z | 2025-02-15T16:36:27Z | 3910 |
| 587 | *## Extracting Private Key from Active Directory Store* | .{0,1000}\#\#\sExtracting\sPrivate\sKey\sfrom\sActive\sDirectory\sStore.{0,1000} | offensive_tool_keyword | ADFSDump | A C# tool to dump all sorts of goodies from AD FS | T1081 - T1003 - T1114 - T1212 | TA0006 - TA0005 - TA0009 | N/A | N/A | Credential Access | https://github.com/mandiant/ADFSDump | 1 | 0 | N/A | N/A | 10 | 4 | 349 | 67 | 2023-08-07T16:58:37Z | 2019-03-20T22:31:16Z | 3914 |
| 588 | *$AllCurrentPwdDiscovered* | .{0,1000}\$AllCurrentPwdDiscovered.{0,1000} | offensive_tool_keyword | Invoke-CleverSpray | Password Spraying Script detecting current and previous passwords of Active Directory User | T1110.003 - T1110.001 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/wavestone-cdt/Invoke-CleverSpray | 1 | 0 | N/A | N/A | 10 | 1 | 65 | 11 | 2021-09-09T07:35:32Z | 2018-11-29T10:05:25Z | 3941 |
| 589 | *$DummyServiceName* | .{0,1000}\$DummyServiceName.{0,1000} | offensive_tool_keyword | crackmapexec | Variable name from script RestartKeePass.ps1 from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3956 |
| 590 | *$dumpDir\lsass.txt* | .{0,1000}\$dumpDir\\lsass\.txt.{0,1000} | offensive_tool_keyword | Forensike | Remotely dump NT hashes through Windows Crash dumps | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/bmarchev/Forensike | 1 | 0 | N/A | N/A | 10 | 1 | 27 | 3 | 2024-10-29T00:13:50Z | 2024-02-01T13:52:55Z | 3957 |
| 591 | *$fct = Get-Content -Encoding byte -Path * | .{0,1000}\$fct\s\=\sGet\-Content\s\-Encoding\sbyte\s\-Path\s.{0,1000} | offensive_tool_keyword | SessionGopher | uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally. | T1047 - T1003.008 - T1552.004 - T1555.003 | TA0006 | N/A | PYSA - DarkSide - Sphinx | Credential Access | https://github.com/Arvanaghi/SessionGopher | 1 | 0 | #content | N/A | 10 | 10 | 1255 | 173 | 2022-11-22T21:33:23Z | 2017-03-08T02:49:32Z | 3974 |
| 592 | *$ForensikeFolder* | .{0,1000}\$ForensikeFolder.{0,1000} | offensive_tool_keyword | Forensike | Remotely dump NT hashes through Windows Crash dumps | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/bmarchev/Forensike | 1 | 0 | N/A | N/A | 10 | 1 | 27 | 3 | 2024-10-29T00:13:50Z | 2024-02-01T13:52:55Z | 3976 |
| 593 | *$KeePassBinaryPath* | .{0,1000}\$KeePassBinaryPath.{0,1000} | offensive_tool_keyword | crackmapexec | Variable name from script RestartKeePass.ps1 from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3991 |
| 594 | *$KeePassUser* | .{0,1000}\$KeePassUser.{0,1000} | offensive_tool_keyword | crackmapexec | Variable name from script RestartKeePass.ps1 from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 3992 |
| 595 | *$KeePassXMLPath backdoored* | .{0,1000}\$KeePassXMLPath\sbackdoored.{0,1000} | offensive_tool_keyword | Keethief | Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system. | T1003 - T1055 - T1059 - T1070 | TA0006 - TA0005 - TA0008 | N/A | EvilCorp* - APT20 | Credential Access | https://github.com/GhostPack/KeeThief | 1 | 0 | N/A | N/A | 10 | 10 | 944 | 154 | 2020-11-18T18:35:21Z | 2016-07-10T19:11:23Z | 3993 |
| 596 | *$KeePassXMLPath triggers removed* | .{0,1000}\$KeePassXMLPath\striggers\sremoved.{0,1000} | offensive_tool_keyword | Keethief | Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system. | T1003 - T1055 - T1059 - T1070 | TA0006 - TA0005 - TA0008 | N/A | EvilCorp* - APT20 | Credential Access | https://github.com/GhostPack/KeeThief | 1 | 0 | N/A | N/A | 10 | 10 | 944 | 154 | 2020-11-18T18:35:21Z | 2016-07-10T19:11:23Z | 3994 |
| 597 | *$ThisIsNotTheStringYouAreLookingFor* | .{0,1000}\$ThisIsNotTheStringYouAreLookingFor.{0,1000} | offensive_tool_keyword | mimidogz | Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection | T1055 - T1560.001 - T1110.001 - T1003 - T1071 | TA0005 - TA0040 - TA0006 | N/A | Dispossessor | Credential Access | https://github.com/projectb-temp/mimidogz | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2019-02-11T10:14:10Z | 2019-02-11T10:12:08Z | 4022 |
| 598 | *$TotalNbCurrentPwdDiscovered* | .{0,1000}\$TotalNbCurrentPwdDiscovered.{0,1000} | offensive_tool_keyword | Invoke-CleverSpray | Password Spraying Script detecting current and previous passwords of Active Directory User | T1110.003 - T1110.001 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/wavestone-cdt/Invoke-CleverSpray | 1 | 0 | N/A | N/A | 10 | 1 | 65 | 11 | 2021-09-09T07:35:32Z | 2018-11-29T10:05:25Z | 4023 |
| 599 | *$VeaamRegPath*SqlDatabaseName* | .{0,1000}\$VeaamRegPath.{0,1000}SqlDatabaseName.{0,1000} | offensive_tool_keyword | veeam-creds | Collection of scripts to retrieve stored passwords from Veeam Backup | T1003 - T1555.005 - T1552 | TA0006 - TA0007 | N/A | Dispossessor - Dagon Locker | Credential Access | https://github.com/sadshade/veeam-creds | 1 | 0 | N/A | N/A | 10 | 2 | 126 | 32 | 2024-12-12T10:23:54Z | 2021-02-05T03:13:08Z | 4025 |
| 600 | *$VeaamRegPath*SqlInstanceName* | .{0,1000}\$VeaamRegPath.{0,1000}SqlInstanceName.{0,1000} | offensive_tool_keyword | veeam-creds | Collection of scripts to retrieve stored passwords from Veeam Backup | T1003 - T1555.005 - T1552 | TA0006 - TA0007 | N/A | Dispossessor - Dagon Locker | Credential Access | https://github.com/sadshade/veeam-creds | 1 | 0 | N/A | N/A | 10 | 2 | 126 | 32 | 2024-12-12T10:23:54Z | 2021-02-05T03:13:08Z | 4026 |
| 601 | *$VeaamRegPath*SqlServerName* | .{0,1000}\$VeaamRegPath.{0,1000}SqlServerName.{0,1000} | offensive_tool_keyword | veeam-creds | Collection of scripts to retrieve stored passwords from Veeam Backup | T1003 - T1555.005 - T1552 | TA0006 - TA0007 | N/A | Dispossessor - Dagon Locker | Credential Access | https://github.com/sadshade/veeam-creds | 1 | 0 | N/A | N/A | 10 | 2 | 126 | 32 | 2024-12-12T10:23:54Z | 2021-02-05T03:13:08Z | 4027 |
| 602 | *%appdaedx765ta%/Binaedx765nce* | .{0,1000}\%appdaedx765ta\%\/Binaedx765nce.{0,1000} | offensive_tool_keyword | LummaC2-Stealer-sample | artifacts from a specific sample of lumma stealer - source code on github | T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539 | TA0006 - TA0010 | Lumma Stealer | N/A | Credential Access | https://github.com/x86byte/LummaC2-Stealer | 1 | 0 | #content | can be used for yara scans | 10 | 1 | 31 | 5 | 2025-02-18T00:38:59Z | 2025-02-15T12:28:05Z | 4030 |
| 603 | *%appdedx765ata%/Eledx765ectrum* | .{0,1000}\%appdedx765ata\%\/Eledx765ectrum.{0,1000} | offensive_tool_keyword | LummaC2-Stealer-sample | artifacts from a specific sample of lumma stealer - source code on github | T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539 | TA0006 - TA0010 | Lumma Stealer | N/A | Credential Access | https://github.com/x86byte/LummaC2-Stealer | 1 | 0 | #content | can be used for yara scans | 10 | 1 | 31 | 5 | 2025-02-18T00:38:59Z | 2025-02-15T12:28:05Z | 4034 |
| 604 | *%appdedx765ata%/Etheedx765reum* | .{0,1000}\%appdedx765ata\%\/Etheedx765reum.{0,1000} | offensive_tool_keyword | LummaC2-Stealer-sample | artifacts from a specific sample of lumma stealer - source code on github | T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539 | TA0006 - TA0010 | Lumma Stealer | N/A | Credential Access | https://github.com/x86byte/LummaC2-Stealer | 1 | 0 | #content | can be used for yara scans | 10 | 1 | 31 | 5 | 2025-02-18T00:38:59Z | 2025-02-15T12:28:05Z | 4035 |
| 605 | *%localaedx765ppdata%* | .{0,1000}\%localaedx765ppdata\%.{0,1000} | offensive_tool_keyword | LummaC2-Stealer-sample | artifacts from a specific sample of lumma stealer - source code on github | T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539 | TA0006 - TA0010 | Lumma Stealer | N/A | Credential Access | https://github.com/x86byte/LummaC2-Stealer | 1 | 0 | #content | can be used for yara scans | 10 | 1 | 31 | 5 | 2025-02-18T00:38:59Z | 2025-02-15T12:28:05Z | 4037 |
| 606 | *%loedx765calappedx765data* | .{0,1000}\%loedx765calappedx765data.{0,1000} | offensive_tool_keyword | LummaC2-Stealer-sample | artifacts from a specific sample of lumma stealer - source code on github | T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539 | TA0006 - TA0010 | Lumma Stealer | N/A | Credential Access | https://github.com/x86byte/LummaC2-Stealer | 1 | 0 | #content | can be used for yara scans | 10 | 1 | 31 | 5 | 2025-02-18T00:38:59Z | 2025-02-15T12:28:05Z | 4039 |
| 607 | *%userproedx765file%* | .{0,1000}\%userproedx765file\%.{0,1000} | offensive_tool_keyword | LummaC2-Stealer-sample | artifacts from a specific sample of lumma stealer - source code on github | T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539 | TA0006 - TA0010 | Lumma Stealer | N/A | Credential Access | https://github.com/x86byte/LummaC2-Stealer | 1 | 0 | #content | can be used for yara scans | 10 | 1 | 31 | 5 | 2025-02-18T00:38:59Z | 2025-02-15T12:28:05Z | 4045 |
| 608 | *&passwd=Winter2020&ok=Log+In* | .{0,1000}\&passwd\=Winter2020\&ok\=Log\+In.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 0 | #linux | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 4050 |
| 609 | *(msds-supportedencryptiontypes=0)(msds-supportedencryptiontypes:1.2.840.113556.1.4.803:=4)))* | .{0,1000}\(msds\-supportedencryptiontypes\=0\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.803\:\=4\)\)\).{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 4082 |
| 610 | *(Program.MiniDump minidump* | .{0,1000}\(Program\.MiniDump\sminidump.{0,1000} | offensive_tool_keyword | MiniDump | C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/cube0x0/MiniDump | 1 | 0 | #content | N/A | 10 | 3 | 291 | 48 | 2021-10-13T18:00:46Z | 2021-08-14T12:26:16Z | 4088 |
| 611 | *(SHADOW DUMPER v1.0)* | .{0,1000}\(SHADOW\sDUMPER\sv1\.0\).{0,1000} | offensive_tool_keyword | ShadowDumper | dump LSASS memory | T1003.001 - T1055 | TA0006 | N/A | N/A | Credential Access | https://github.com/Offensive-Panda/ShadowDumper | 1 | 0 | #content | N/A | 10 | 6 | 521 | 83 | 2025-04-05T08:32:28Z | 2024-11-10T15:26:28Z | 4089 |
| 612 | *./GoAWSConsoleSpray* | .{0,1000}\.\/GoAWSConsoleSpray.{0,1000} | offensive_tool_keyword | GoAWSConsoleSpray | brute-force AWS IAM Console credentials to discover valid logins for user accounts | T1078 - T1110 - T1187 - T1110.001 | TA0006 - TA0007 - TA0003 - TA0001 | N/A | N/A | Credential Access | https://github.com/WhiteOakSecurity/GoAWSConsoleSpray | 1 | 0 | #linux | N/A | 9 | 1 | 29 | 5 | 2022-06-15T18:16:21Z | 2022-06-15T18:11:39Z | 4144 |
| 613 | *./go-secdump* | .{0,1000}\.\/go\-secdump.{0,1000} | offensive_tool_keyword | go-secdump | Tool to remotely dump secrets from the Windows registry | T1003.002 - T1012 - T1059.003 | TA0006 - TA0003 - TA0002 | N/A | N/A | Credential Access | https://github.com/jfjallid/go-secdump | 1 | 0 | #linux | N/A | 10 | 5 | 457 | 51 | 2025-02-21T19:16:11Z | 2023-02-23T17:02:50Z | 4145 |
| 614 | *./hashcat -* | .{0,1000}\.\/hashcat\s\-.{0,1000} | offensive_tool_keyword | NetNTLMtoSilverTicket | Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket. | T1110.001 - T1558.003 - T1558.004 | TA0006 - TA0008 - TA0002 | N/A | N/A | Credential Access | https://github.com/NotMedic/NetNTLMtoSilverTicket | 1 | 0 | #linux | N/A | 10 | 9 | 842 | 113 | 2021-07-26T15:16:20Z | 2019-01-14T15:32:27Z | 4147 |
| 615 | *./hashview/* | .{0,1000}\.\/hashview\/.{0,1000} | offensive_tool_keyword | hashview | A web front-end for password cracking and analytics | T1110 - T1201 | TA0006 - TA0002 | N/A | N/A | Credential Access | https://github.com/hashview/hashview | 1 | 0 | #linux | N/A | 10 | 4 | 373 | 41 | 2025-02-20T18:23:25Z | 2020-11-23T19:21:06Z | 4148 |
| 616 | *./hydra * | .{0,1000}\.\/hydra\s.{0,1000} | offensive_tool_keyword | thc-hydra | Parallelized login cracker which supports numerous protocols to attack. | T1110.001 | TA0006 | N/A | ALLANITE - BERSERK BEAR | Credential Access | https://github.com/vanhauser-thc/thc-hydra | 1 | 0 | #linux | N/A | N/A | 10 | 10326 | 2137 | 2025-04-04T12:19:05Z | 2014-04-24T14:45:37Z | 4153 |
| 617 | *./kerbrute * | .{0,1000}\.\/kerbrute\s.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 0 | #linux | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 4159 |
| 618 | *./ntdissector* | .{0,1000}\.\/ntdissector.{0,1000} | offensive_tool_keyword | ntdissector | Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class. | T1003.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/synacktiv/ntdissector | 1 | 0 | #linux | N/A | 9 | 2 | 139 | 17 | 2024-08-16T14:18:35Z | 2023-09-05T12:13:47Z | 4175 |
| 619 | *./Obfuscated_*.py* | .{0,1000}\.\/Obfuscated_.{0,1000}\.py.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 0 | #linux | N/A | 10 | N/A | 4177 | ||||
| 620 | *./Passdetective* | .{0,1000}\.\/Passdetective.{0,1000} | offensive_tool_keyword | PassDetective | PassDetective is a command-line tool that scans shell command history to detect mistakenly written passwords - API keys and secrets | T1059 - T1059.004 - T1552 - T1552.001 | TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/aydinnyunus/PassDetective | 1 | 0 | #linux | N/A | 7 | 2 | 129 | 8 | 2024-06-19T10:39:39Z | 2023-07-22T12:31:57Z | 4180 |
| 621 | *./Pcredz * | .{0,1000}\.\/Pcredz\s.{0,1000} | offensive_tool_keyword | Pcredz | This tool extracts Credit card numbers. NTLM(DCE-RPC. HTTP. SQL. LDAP. etc). Kerberos (AS-REQ Pre-Auth etype 23). HTTP Basic. SNMP. POP. SMTP. FTP. IMAP. etc from a pcap file or from a live interface. | T1116 - T1003 - T1002 - T1001 - T1005 - T1552 | TA0003 - TA0002 - TA0011 | N/A | N/A | Credential Access | https://github.com/lgandx/Pcredz | 1 | 0 | #linux | N/A | N/A | 10 | 2100 | 413 | 2025-01-27T10:34:00Z | 2014-04-07T02:03:33Z | 4181 |
| 622 | *./snake | .{0,1000}\.\/snake | offensive_tool_keyword | 3snake | Tool for extracting information from newly spawned processes | T1003 - T1110 - T1552 - T1505 | TA0001 - TA0002 - TA0003 | N/A | N/A | Credential Access | https://github.com/blendin/3snake | 1 | 0 | #linux | N/A | 7 | 8 | 752 | 109 | 2022-02-14T17:42:10Z | 2018-02-07T21:03:15Z | 4208 |
| 623 | *./t14m4t * | .{0,1000}\.\/t14m4t\s.{0,1000} | offensive_tool_keyword | t14m4t | Automated brute-forcing attack tool. | T1110 | N/A | N/A | N/A | Credential Access | https://github.com/MS-WEB-BN/t14m4t | 1 | 0 | #linux | N/A | N/A | 5 | 402 | 81 | 2021-04-02T09:52:45Z | 2019-10-16T14:39:33Z | 4213 |
| 624 | *./xhydra* | .{0,1000}\.\/xhydra.{0,1000} | offensive_tool_keyword | thc-hydra | Parallelized login cracker which supports numerous protocols to attack. | T1110.001 | TA0006 | N/A | ALLANITE - BERSERK BEAR | Credential Access | https://github.com/vanhauser-thc/thc-hydra | 1 | 0 | #linux | N/A | N/A | 10 | 10326 | 2137 | 2025-04-04T12:19:05Z | 2014-04-24T14:45:37Z | 4222 |
| 625 | *.asp --adcs --template Machine -smb2support* | .{0,1000}\.asp\s\-\-adcs\s\-\-template\sMachine\s\-smb2support.{0,1000} | offensive_tool_keyword | ADCSCoercePotato | coercing machine authentication but specific for ADCS server | T1187 | TA0006 | N/A | N/A | Credential Access | https://github.com/decoder-it/ADCSCoercePotato | 1 | 0 | N/A | N/A | 10 | 3 | 224 | 31 | 2024-05-05T14:42:23Z | 2024-02-26T12:08:34Z | 4247 |
| 626 | *.dmp 1> \\127.0.0.1\C$\* | .{0,1000}\.dmp\s1\>\s\\\\127\.0\.0\.1\\C\$\\.{0,1000} | offensive_tool_keyword | spraykatz | Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments. | T1003 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1003.005 - T1003.006 - T1003.007 - T1003.008 | TA0003 - TA0004 - TA0007 | N/A | N/A | Credential Access | https://github.com/aas-n/spraykatz | 1 | 0 | N/A | N/A | 9 | 8 | 763 | 121 | 2020-06-20T12:14:00Z | 2019-09-09T14:38:28Z | 4287 |
| 627 | *.edx765txt* | .{0,1000}\.edx765txt.{0,1000} | offensive_tool_keyword | LummaC2-Stealer-sample | artifacts from a specific sample of lumma stealer - source code on github | T1204.002 - T1566.001 - T1059.003 - T1027 - T1140 - T1555.003 - T1557.001 - T1083 - T1560.001 - T1041 - T1567 - T1071.001 - T1105 - T1539 | TA0006 - TA0010 | Lumma Stealer | N/A | Credential Access | https://github.com/x86byte/LummaC2-Stealer | 1 | 0 | #content | can be used for yara scans | 10 | 1 | 31 | 5 | 2025-02-18T00:38:59Z | 2025-02-15T12:28:05Z | 4308 |
| 628 | *.exe /logonpasswords /symbol* | .{0,1000}\.exe\s\s\/logonpasswords\s\/symbol.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 4318 |
| 629 | *.exe certificates /pvk:*.pvk* | .{0,1000}\.exe\s\scertificates\s\/pvk\:.{0,1000}\.pvk.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4321 |
| 630 | *.exe keepass /unprotect* | .{0,1000}\.exe\s\skeepass\s\/unprotect.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4323 |
| 631 | *.exe .\chrome.DMP* | .{0,1000}\.exe\s\.\\chrome\.DMP.{0,1000} | offensive_tool_keyword | ChromeKatz | Dump cookies directly from Chrome process memory | T1555.003 - T1003 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Meckazin/ChromeKatz | 1 | 0 | N/A | N/A | 10 | 10 | 1171 | 115 | 2024-11-26T12:53:22Z | 2023-12-07T22:27:06Z | 4330 |
| 632 | *.exe .\msedge.DMP* | .{0,1000}\.exe\s\.\\msedge\.DMP.{0,1000} | offensive_tool_keyword | ChromeKatz | Dump cookies directly from Chrome process memory | T1555.003 - T1003 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Meckazin/ChromeKatz | 1 | 0 | N/A | N/A | 10 | 10 | 1171 | 115 | 2024-11-26T12:53:22Z | 2023-12-07T22:27:06Z | 4331 |
| 633 | *.exe /gethmac /mode:SHA1 /key:* | .{0,1000}\.exe\s\/gethmac\s\/mode\:SHA1\s\/key\:.{0,1000} | offensive_tool_keyword | NTHASH-FPC | various tools for retrieving windows secrets - Lateral Movement and C2 | T1552.002 - T1552.005 - T1555.003 - T1555.005 - T1558 - T1558.003 - T1111 - T1552.001 - T1539 - T1606 - T1602 | TA0006 - TA0007 - TA0008 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/erwan2212/NTHASH-FPC | 1 | 0 | N/A | N/A | 10 | 1 | 35 | 9 | 2023-08-13T16:38:53Z | 2019-08-09T11:49:55Z | 4333 |
| 634 | *.exe asktgt /user:* /aes256:* /opsec /ptt* | .{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/aes256\:.{0,1000}\s\/opsec\s\/ptt.{0,1000} | offensive_tool_keyword | AD exploitation cheat sheet | Lateral Movement with Rubeus More stealthy variant but requires the AES256 key (see 'Dumping OS credentials with Mimikatz' section) | T1110 | TA0006 | N/A | Black Basta | Credential Access | https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 4380 |
| 635 | *.exe asktgt /user:* /certificate:* /password:* | .{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/certificate\:.{0,1000}\s\/password\:.{0,1000} | offensive_tool_keyword | KeyCredentialLink | Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute | T1098 - T1550 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/Leo4j/KeyCredentialLink | 1 | 0 | N/A | N/A | 10 | 1 | 21 | 3 | 2024-06-05T13:44:39Z | 2024-06-05T13:19:49Z | 4381 |
| 636 | *.exe asktgt /user:* /rc4:* /createnetonly:*cmd.exe* | .{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/rc4\:.{0,1000}\s\/createnetonly\:.{0,1000}cmd\.exe.{0,1000} | offensive_tool_keyword | AD exploitation cheat sheet | Lateral Movement with Rubeus Pass the ticket to a sacrificial hidden process. allowing you to e.g. steal the token from this process (requires elevation) | T1110 | TA0006 | N/A | Black Basta | Credential Access | https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 4382 |
| 637 | *.exe asktgt /user:* /rc4:* /ptt* | .{0,1000}\.exe\sasktgt\s\/user\:.{0,1000}\s\/rc4\:.{0,1000}\s\/ptt.{0,1000} | offensive_tool_keyword | AD exploitation cheat sheet | Lateral Movement with Rubeus Request a TGT as the target user and pass it into the current session | T1110 | TA0006 | N/A | Black Basta | Credential Access | https://casvancooten.com/posts/2020/11/windows-active-directory-exploitation-cheat-sheet-and-command-reference | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 4383 |
| 638 | *.exe -b chromium -p *\AppData\Local\Google\Chrome\* | .{0,1000}\.exe\s\-b\schromium\s\-p\s.{0,1000}\\AppData\\Local\\Google\\Chrome\\.{0,1000} | offensive_tool_keyword | SharpWeb | SharpWeb - to export browser data including passwords - history - cookies - bookmarks and download records | T1555.003 - T1539 - T1602 - T1074.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/StarfireLab/SharpWeb | 1 | 0 | N/A | N/A | 10 | 8 | 703 | 79 | 2024-11-15T07:05:34Z | 2023-10-09T06:48:23Z | 4392 |
| 639 | *.exe backupkey /nowrap *.pvk* | .{0,1000}\.exe\sbackupkey\s\/nowrap\s.{0,1000}\.pvk.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4393 |
| 640 | *.exe backupkey /server:* | .{0,1000}\.exe\sbackupkey\s\/server\:.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4394 |
| 641 | *.exe blob /target:C:\Temp\* | .{0,1000}\.exe\sblob\s\/target\:C\:\\Temp\\.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4395 |
| 642 | *.exe BOOKMARKS* | .{0,1000}\.exe\sBOOKMARKS.{0,1000} | offensive_tool_keyword | Adamantium-Thief | Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill. | T1555 - T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/LimerBoy/Adamantium-Thief | 1 | 0 | N/A | N/A | 10 | 9 | 818 | 205 | 2025-01-12T15:11:50Z | 2020-03-01T06:50:15Z | 4397 |
| 643 | *.exe certificates /mkfile:*.txt* | .{0,1000}\.exe\scertificates\s\/mkfile\:.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4400 |
| 644 | *.exe certificates /unprotect* | .{0,1000}\.exe\scertificates\s\/unprotect.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4401 |
| 645 | *.exe compute --sid * --kdskey * | .{0,1000}\.exe\scompute\s\-\-sid\s.{0,1000}\s\-\-kdskey\s.{0,1000} | offensive_tool_keyword | GoldenGMSA | GolenGMSA tool for working with GMSA passwords | T1003.004 - T1078.003 - T1059.006 | TA0006 - TA0004 - TA0002 | N/A | N/A | Credential Access | https://github.com/Semperis/GoldenGMSA | 1 | 0 | N/A | N/A | 7 | 2 | 144 | 22 | 2024-04-11T07:51:57Z | 2022-02-03T10:32:05Z | 4407 |
| 646 | *.exe COOKIES* | .{0,1000}\.exe\sCOOKIES.{0,1000} | offensive_tool_keyword | Adamantium-Thief | Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill. | T1555 - T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/LimerBoy/Adamantium-Thief | 1 | 0 | N/A | N/A | 10 | 9 | 818 | 205 | 2025-01-12T15:11:50Z | 2020-03-01T06:50:15Z | 4414 |
| 647 | *.exe credentials /pvk:*.pvk* | .{0,1000}\.exe\scredentials\s\/pvk\:.{0,1000}\.pvk.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4417 |
| 648 | *.exe CREDIT_CARDS* | .{0,1000}\.exe\sCREDIT_CARDS.{0,1000} | offensive_tool_keyword | Adamantium-Thief | Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill. | T1555 - T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/LimerBoy/Adamantium-Thief | 1 | 0 | N/A | N/A | 10 | 9 | 818 | 205 | 2025-01-12T15:11:50Z | 2020-03-01T06:50:15Z | 4418 |
| 649 | *.exe --dll * --dump * --pid * | .{0,1000}\.exe\s\-\-dll\s.{0,1000}\s\-\-dump\s.{0,1000}\s\-\-pid\s.{0,1000} | offensive_tool_keyword | PPLSystem | creates a livedump of the machine through NtDebugSystemControl to extract the COM secret and context, to then inject inside this process. | T1003.002 | TA0006 | N/A | N/A | Credential Access | https://github.com/Slowerzs/PPLSystem | 1 | 0 | N/A | N/A | 10 | 2 | 190 | 23 | 2024-05-29T18:33:35Z | 2024-05-22T17:48:49Z | 4425 |
| 650 | *.exe dump /luid:* /service:krbtgt* | .{0,1000}\.exe\sdump\s\/luid\:.{0,1000}\s\/service\:krbtgt.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 4429 |
| 651 | *.exe --dump -k * -u http* | .{0,1000}\.exe\s\-\-dump\s\-k\s.{0,1000}\s\-u\shttp.{0,1000} | offensive_tool_keyword | Dumpy | Reuse open handles to dynamically dump LSASS | T1003.001 - T1055.001 - T1083 | TA0006 | N/A | N/A | Credential Access | https://github.com/Kudaes/Dumpy | 1 | 0 | N/A | N/A | 10 | 3 | 243 | 24 | 2024-04-04T07:42:26Z | 2021-10-13T21:54:59Z | 4431 |
| 652 | *.exe dump --key-name * | .{0,1000}\.exe\sdump\s\-\-key\-name\s.{0,1000} | offensive_tool_keyword | Shwmae | Shwmae is a tool focused on Windows Hello and DPAPI exploitation. It enables the enumeration - extraction and manipulation of Windows Hello keys and credentials | T1068 - T1078 - T1211 - T1003.004 - T1003.005 - T1003.002 | TA0006 - TA0005 - TA0003 - TA0004 | N/A | N/A | Credential Access | https://github.com/CCob/Shwmae | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 12 | 2025-01-27T14:36:07Z | 2024-03-21T15:05:03Z | 4432 |
| 653 | *.exe exec * cmd interactive* | .{0,1000}\.exe\sexec\s.{0,1000}\scmd\sinteractive.{0,1000} | offensive_tool_keyword | BesoToken | A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions). | T1134 - T1003.002 | TA0004 - TA0006 | N/A | N/A | Credential Access | https://github.com/OmriBaso/BesoToken | 1 | 0 | N/A | N/A | 10 | 1 | 93 | 14 | 2022-11-23T10:45:07Z | 2022-11-21T01:07:51Z | 4439 |
| 654 | *.exe --get-users-list > * | .{0,1000}\.exe\s\-\-get\-users\-list\s\>\s.{0,1000} | offensive_tool_keyword | SharpSpray | SharpSpray is a Windows domain password spraying tool written in .NET C# | T1110 | TA0006 | N/A | N/A | Credential Access | https://github.com/iomoath/SharpSpray | 1 | 0 | N/A | N/A | 10 | 2 | 130 | 21 | 2021-11-25T19:13:56Z | 2021-08-31T16:09:45Z | 4456 |
| 655 | *.exe gmsainfo --sid * | .{0,1000}\.exe\sgmsainfo\s\-\-sid\s.{0,1000} | offensive_tool_keyword | GoldenGMSA | GolenGMSA tool for working with GMSA passwords | T1003.004 - T1078.003 - T1059.006 | TA0006 - TA0004 - TA0002 | N/A | N/A | Credential Access | https://github.com/Semperis/GoldenGMSA | 1 | 0 | N/A | N/A | 7 | 2 | 144 | 22 | 2024-04-11T07:51:57Z | 2022-02-03T10:32:05Z | 4457 |
| 656 | *.exe hash /password:* | .{0,1000}\.exe\shash\s\/password\:.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 4466 |
| 657 | *.exe kdsinfo --guid * | .{0,1000}\.exe\skdsinfo\s\-\-guid\s.{0,1000} | offensive_tool_keyword | GoldenGMSA | GolenGMSA tool for working with GMSA passwords | T1003.004 - T1078.003 - T1059.006 | TA0006 - TA0004 - TA0002 | N/A | N/A | Credential Access | https://github.com/Semperis/GoldenGMSA | 1 | 0 | N/A | N/A | 7 | 2 | 144 | 22 | 2024-04-11T07:51:57Z | 2022-02-03T10:32:05Z | 4488 |
| 658 | *.exe machinemasterkeys* | .{0,1000}\.exe\smachinemasterkeys.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4529 |
| 659 | *.exe machinetriage* | .{0,1000}\.exe\smachinetriage.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4530 |
| 660 | *.exe machinevaults* | .{0,1000}\.exe\smachinevaults.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4531 |
| 661 | *.exe masterkeys /hashes* | .{0,1000}\.exe\smasterkeys\s\/hashes.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4532 |
| 662 | *.exe masterkeys /hashes* | .{0,1000}\.exe\smasterkeys\s\/hashes.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4533 |
| 663 | *.exe masterkeys /pvk:* | .{0,1000}\.exe\smasterkeys\s\/pvk\:.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4534 |
| 664 | *.exe --procdump -p * | .{0,1000}\.exe\s\-\-procdump\s\-p\s.{0,1000} | offensive_tool_keyword | MultiDump | MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly | T1003 - T1564.002 | TA0005 - TA0006 | N/A | N/A | Credential Access | https://github.com/Xre0uS/MultiDump | 1 | 0 | N/A | N/A | 10 | 6 | 510 | 66 | 2025-03-28T10:40:27Z | 2024-02-02T05:56:29Z | 4572 |
| 665 | *.exe ps /target:C:\Temp\* /unprotect* | .{0,1000}\.exe\sps\s\/target\:C\:\\Temp\\.{0,1000}\s\/unprotect.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4574 |
| 666 | *.exe ptt /ticket:*.kirbi | .{0,1000}\.exe\sptt\s\/ticket\:.{0,1000}\.kirbi | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 4576 |
| 667 | *.exe rdg /unprotect* | .{0,1000}\.exe\srdg\s\/unprotect.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4584 |
| 668 | *.exe --signature --driver* | .{0,1000}\.exe\s\-\-signature\s\-\-driver.{0,1000} | offensive_tool_keyword | POSTDump | Another tool to perform minidump of LSASS process using few technics to avoid detection. | T1003 - T1055 - T1562.001 - T1218 | TA0005 - TA0003 - TA0006 | N/A | Black Basta | Credential Access | https://github.com/YOLOP0wn/POSTDump | 1 | 0 | N/A | N/A | 10 | 4 | 327 | 37 | 2025-02-05T15:24:52Z | 2023-09-13T11:28:51Z | 4611 |
| 669 | *.exe spy --pid * | .{0,1000}\.exe\sspy\s\-\-pid\s.{0,1000} | offensive_tool_keyword | Spyndicapped | COM ViewLogger - keylogger | T1574.001 - T1574.002 - T1574.009 | TA0006 | N/A | N/A | Credential Access | https://github.com/CICADA8-Research/Spyndicapped | 1 | 0 | N/A | N/A | 10 | 4 | 356 | 50 | 2025-01-06T07:31:29Z | 2024-12-25T11:47:39Z | 4620 |
| 670 | *.exe spy --window * | .{0,1000}\.exe\sspy\s\-\-window\s.{0,1000} | offensive_tool_keyword | Spyndicapped | COM ViewLogger - keylogger | T1574.001 - T1574.002 - T1574.009 | TA0006 | N/A | N/A | Credential Access | https://github.com/CICADA8-Research/Spyndicapped | 1 | 0 | N/A | N/A | 10 | 4 | 356 | 50 | 2025-01-06T07:31:29Z | 2024-12-25T11:47:39Z | 4621 |
| 671 | *.exe triage /password:* | .{0,1000}\.exe\striage\s\/password\:.{0,1000} | offensive_tool_keyword | SharpDPAPI | SharpDPAPI is a C# port of some Mimikatz DPAPI functionality. | T1552.002 - T1059.001 - T1112 - T1649 | TA0006 - TA0002 | N/A | Conti | Credential Access | https://github.com/GhostPack/SharpDPAPI | 1 | 0 | N/A | N/A | 10 | 10 | 1232 | 215 | 2024-06-27T13:39:08Z | 2018-08-22T17:39:31Z | 4632 |
| 672 | *.exe -u * -s 2 -c cmd.exe* | .{0,1000}\.exe\s\-u\s.{0,1000}\s\-s\s2\s\-c\scmd\.exe.{0,1000} | offensive_tool_keyword | TokenStealer | stealing Windows tokens | T1134 - T1055 | TA0003 - TA0004 | N/A | N/A | Credential Access | https://github.com/decoder-it/TokenStealer | 1 | 0 | N/A | N/A | 10 | 2 | 164 | 29 | 2023-10-25T14:08:57Z | 2023-10-24T13:06:37Z | 4633 |
| 673 | *.exe -v -u * -w 10k-most-common.txt* | .{0,1000}\.exe\s\-v\s\-u\s.{0,1000}\s\-w\s10k\-most\-common\.txt.{0,1000} | offensive_tool_keyword | win-brute-logon | Crack any Microsoft Windows users password without any privilege (Guest account included) | T1110.001 - T1078.001 - T1187 - T1055 - T1547 - T1003.005 | TA0006 - TA0008 - TA0005 | N/A | N/A | Credential Access | https://github.com/PhrozenIO/win-brute-logon | 1 | 0 | N/A | N/A | 7 | 10 | 1138 | 191 | 2023-11-09T10:37:58Z | 2020-05-14T21:46:50Z | 4639 |
| 674 | *.exe Xmanager /user:* /sid:* /path:** | .{0,1000}\.exe\sXmanager\s\/user\:.{0,1000}\s\/sid\:.{0,1000}\s\/path\:.{0,1000}.{0,1000} | offensive_tool_keyword | SharpDecryptPwd | Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc | T1003.008 - T1555.004 - T1552.002 | TA0006 | N/A | N/A | Credential Access | https://github.com/RowTeam/SharpDecryptPwd | 1 | 0 | N/A | N/A | 10 | 8 | 769 | 117 | 2022-03-04T02:49:31Z | 2022-02-25T11:21:43Z | 4645 |
| 675 | *.exe -Xmangager -p * | .{0,1000}\.exe\s\-Xmangager\s\-p\s.{0,1000} | offensive_tool_keyword | SharpDecryptPwd | Decrypt Navicat,Xmanager,Filezilla,Foxmail,WinSCP,etc | T1003.008 - T1555.004 - T1552.002 | TA0006 | N/A | N/A | Credential Access | https://github.com/RowTeam/SharpDecryptPwd | 1 | 0 | N/A | N/A | 10 | 8 | 769 | 117 | 2022-03-04T02:49:31Z | 2022-02-25T11:21:43Z | 4646 |
| 676 | *.exe* -d localhost * -u * -p */24* | .{0,1000}\.exe.{0,1000}\s\-d\slocalhost\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\/24.{0,1000} | offensive_tool_keyword | crackmapexec | windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 4647 |
| 677 | *.exe* -u administrator -H :*--shares* | .{0,1000}\.exe.{0,1000}\s\-u\sadministrator\s\-H\s\:.{0,1000}\-\-shares.{0,1000} | offensive_tool_keyword | crackmapexec | windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 4657 |
| 678 | *.local.kirbi* | .{0,1000}\.local\.kirbi.{0,1000} | offensive_tool_keyword | kerberoast | Kerberoast is a series of tools for attacking MS Kerberos implementations | T1550 - T1555 - T1212 - T1558 | TA0001 - TA0004 - TA0006 | N/A | APT20 | Credential Access | https://github.com/nidem/kerberoast | 1 | 1 | N/A | N/A | N/A | 10 | 1433 | 317 | 2022-12-31T17:17:28Z | 2014-09-22T14:46:49Z | 4695 |
| 679 | *.ps1 -dcip * -Username * -Password* -ExportToCSV *.csv -ExportToJSON *.json* | .{0,1000}\.ps1\s\-dcip\s.{0,1000}\s\-Username\s.{0,1000}\s\-Password.{0,1000}\s\-ExportToCSV\s.{0,1000}\.csv\s\-ExportToJSON\s.{0,1000}\.json.{0,1000} | offensive_tool_keyword | ExtractBitlockerKeys | A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain. | T1003.002 - T1039 - T1087.002 | TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/p0dalirius/ExtractBitlockerKeys | 1 | 0 | N/A | N/A | 10 | 4 | 368 | 54 | 2025-01-31T09:39:55Z | 2023-09-19T07:28:11Z | 4760 |
| 680 | *.py -credz *.txt * | .{0,1000}\.py\s\s\-credz\s.{0,1000}\.txt\s.{0,1000}\s | offensive_tool_keyword | donpapi | Dumping DPAPI credentials remotely | T1003.006 - T1021.001 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/login-securite/DonPAPI | 1 | 0 | N/A | N/A | N/A | 10 | 1110 | 130 | 2025-03-24T10:23:58Z | 2021-09-27T09:12:51Z | 4773 |
| 681 | *.py rekall *.dmp* -t 0 | .{0,1000}\.py\s\srekall\s.{0,1000}\.dmp.{0,1000}\s\-t\s0 | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 0 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 4788 |
| 682 | *.py * --burp * | .{0,1000}\.py\s.{0,1000}\s\-\-burp\s.{0,1000} | offensive_tool_keyword | secretfinder | SecretFinder is a python script based on LinkFinder written to discover sensitive data like apikeys - accesstoken - authorizations - jwt..etc in JavaScript files | T1083 - T1081 - T1113 | TA0003 - TA0002 - TA0007 | N/A | N/A | Credential Access | https://github.com/m4ll0k/SecretFinder | 1 | 0 | N/A | N/A | N/A | 10 | 2153 | 405 | 2024-05-26T09:36:41Z | 2020-06-08T10:50:12Z | 4793 |
| 683 | *.py * -debug -dnstcp* | .{0,1000}\.py\s.{0,1000}\s\-debug\s\-dnstcp.{0,1000} | offensive_tool_keyword | HEKATOMB | Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them | T1003 - T1555.002 - T1482 - T1087 | TA0006 - TA0005 - TA0007 | N/A | N/A | Credential Access | https://github.com/Processus-Thief/HEKATOMB | 1 | 0 | N/A | N/A | 10 | N/A | 4796 | ||||
| 684 | *.py -d "test.local" -u "john" -p "password123" --target "user2" --action "list" --dc-ip "10.10.10.1"* | .{0,1000}\.py\s\-d\s\"test\.local\"\s\-u\s\"john\"\s\-p\s\"password123\"\s\-\-target\s\"user2\"\s\-\-action\s\"list\"\s\-\-dc\-ip\s\"10\.10\.10\.1\".{0,1000} | offensive_tool_keyword | pywhisker | Python version of the C# tool for Shadow Credentials attacks | T1552.001 - T1136 - T1098 | TA0003 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/pywhisker | 1 | 0 | N/A | N/A | 10 | 8 | 712 | 89 | 2025-04-21T16:53:22Z | 2021-07-21T19:20:00Z | 4822 |
| 685 | *.py -d * -u * -p * --target * --action * --export PEM* | .{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\s.{0,1000}\s\-\-export\sPEM.{0,1000} | offensive_tool_keyword | pywhisker | Python version of the C# tool for Shadow Credentials attacks | T1552.001 - T1136 - T1098 | TA0003 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/pywhisker | 1 | 0 | N/A | N/A | 10 | 8 | 712 | 89 | 2025-04-21T16:53:22Z | 2021-07-21T19:20:00Z | 4823 |
| 686 | *.py -d * -u * -p * --target * --action "add" --filename * | .{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\"add\"\s\-\-filename\s.{0,1000}\s | offensive_tool_keyword | pywhisker | Python version of the C# tool for Shadow Credentials attacks | T1552.001 - T1136 - T1098 | TA0003 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/pywhisker | 1 | 0 | N/A | N/A | 10 | 8 | 712 | 89 | 2025-04-21T16:53:22Z | 2021-07-21T19:20:00Z | 4824 |
| 687 | *.py -d * -u * -p * --target * --action "clear"* | .{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\"clear\".{0,1000}\s | offensive_tool_keyword | pywhisker | Python version of the C# tool for Shadow Credentials attacks | T1552.001 - T1136 - T1098 | TA0003 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/pywhisker | 1 | 0 | N/A | N/A | 10 | 8 | 712 | 89 | 2025-04-21T16:53:22Z | 2021-07-21T19:20:00Z | 4825 |
| 688 | *.py -d * -u * -p * --target * --action "info" --device-id * | .{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\"info\"\s\-\-device\-id\s.{0,1000} | offensive_tool_keyword | pywhisker | Python version of the C# tool for Shadow Credentials attacks | T1552.001 - T1136 - T1098 | TA0003 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/pywhisker | 1 | 0 | N/A | N/A | 10 | 8 | 712 | 89 | 2025-04-21T16:53:22Z | 2021-07-21T19:20:00Z | 4826 |
| 689 | *.py -d * -u * -p * --target * --action "list" * | .{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\"list\"\s.{0,1000} | offensive_tool_keyword | pywhisker | Python version of the C# tool for Shadow Credentials attacks | T1552.001 - T1136 - T1098 | TA0003 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/pywhisker | 1 | 0 | N/A | N/A | 10 | 8 | 712 | 89 | 2025-04-21T16:53:22Z | 2021-07-21T19:20:00Z | 4827 |
| 690 | *.py -d * -u * -p * --target * --action "remove" --device-id * | .{0,1000}\.py\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-\-target\s.{0,1000}\s\-\-action\s\"remove\"\s\-\-device\-id\s.{0,1000} | offensive_tool_keyword | pywhisker | Python version of the C# tool for Shadow Credentials attacks | T1552.001 - T1136 - T1098 | TA0003 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/ShutdownRepo/pywhisker | 1 | 0 | N/A | N/A | 10 | 8 | 712 | 89 | 2025-04-21T16:53:22Z | 2021-07-21T19:20:00Z | 4828 |
| 691 | *.py discover -H domain_list.txt* | .{0,1000}\.py\sdiscover\s\-H\sdomain_list\.txt.{0,1000} | offensive_tool_keyword | lyncsmash | a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations | T1190 - T1087 - T1110 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/nyxgeek/lyncsmash | 1 | 0 | N/A | N/A | 8 | 4 | 337 | 63 | 2024-10-01T11:22:01Z | 2016-05-20T04:32:41Z | 4829 |
| 692 | *.py enum -H * -U *.txt -P *.txt -*.txt* | .{0,1000}\.py\senum\s\-H\s.{0,1000}\s\-U\s.{0,1000}\.txt\s\-P\s.{0,1000}\.txt\s\-.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | lyncsmash | a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations | T1190 - T1087 - T1110 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/nyxgeek/lyncsmash | 1 | 0 | N/A | N/A | 8 | 4 | 337 | 63 | 2024-10-01T11:22:01Z | 2016-05-20T04:32:41Z | 4831 |
| 693 | *.py lock -H * -u administrator -d * | .{0,1000}\.py\slock\s\-H\s.{0,1000}\s\-u\sadministrator\s\-d\s.{0,1000} | offensive_tool_keyword | lyncsmash | a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations | T1190 - T1087 - T1110 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/nyxgeek/lyncsmash | 1 | 0 | N/A | N/A | 8 | 4 | 337 | 63 | 2024-10-01T11:22:01Z | 2016-05-20T04:32:41Z | 4836 |
| 694 | *.py spray -ep * | .{0,1000}\.py\sspray\s\-ep\s.{0,1000} | offensive_tool_keyword | Spray365 | Spray365 is a password spraying tool that identifies valid credentials for Microsoft accounts (Office 365 / Azure AD). | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/MarkoH17/Spray365 | 1 | 0 | N/A | N/A | N/A | 4 | 348 | 58 | 2022-07-14T14:45:57Z | 2021-11-04T18:20:39Z | 4842 |
| 695 | *.py teams --get* | .{0,1000}\.py\steams\s\-\-get.{0,1000} | offensive_tool_keyword | teams_dump | PoC for dumping and decrypting cookies in the latest version of Microsoft Teams | T1560.001 - T1555.003 - T1113 - T1557 | TA0006 - TA0005 - TA0009 | N/A | N/A | Credential Access | https://github.com/byinarie/teams_dump | 1 | 0 | N/A | N/A | 7 | 2 | 132 | 19 | 2023-11-12T18:47:55Z | 2023-09-18T18:33:32Z | 4845 |
| 696 | *.py teams --list* | .{0,1000}\.py\steams\s\-\-list.{0,1000} | offensive_tool_keyword | teams_dump | PoC for dumping and decrypting cookies in the latest version of Microsoft Teams | T1560.001 - T1555.003 - T1113 - T1557 | TA0006 - TA0005 - TA0009 | N/A | N/A | Credential Access | https://github.com/byinarie/teams_dump | 1 | 0 | N/A | N/A | 7 | 2 | 132 | 19 | 2023-11-12T18:47:55Z | 2023-09-18T18:33:32Z | 4846 |
| 697 | *.py*.ccache *.kirbi * | .{0,1000}\.py.{0,1000}\.ccache\s.{0,1000}\.kirbi\s.{0,1000} | offensive_tool_keyword | ticket_converter | A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket. | T1558.003 - T1110.004 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/zer1t0/ticket_converter | 1 | 0 | N/A | N/A | 10 | 2 | 167 | 31 | 2022-06-16T19:38:05Z | 2019-05-14T04:48:19Z | 4855 |
| 698 | *.py*.kirbi *.ccache* | .{0,1000}\.py.{0,1000}\.kirbi\s.{0,1000}\.ccache.{0,1000} | offensive_tool_keyword | ticket_converter | A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket. | T1558.003 - T1110.004 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/zer1t0/ticket_converter | 1 | 0 | N/A | N/A | 10 | 2 | 167 | 31 | 2022-06-16T19:38:05Z | 2019-05-14T04:48:19Z | 4856 |
| 699 | *.py*found-users.txt* | .{0,1000}\.py.{0,1000}found\-users\.txt.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 0 | N/A | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 4857 |
| 700 | */.config/lsassy* | .{0,1000}\/\.config\/lsassy.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 0 | #linux | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 5011 |
| 701 | */.ntdissector* | .{0,1000}\/\.ntdissector.{0,1000} | offensive_tool_keyword | ntdissector | Ntdissector is a tool for parsing records of an NTDS database. Records are dumped in JSON format and can be filtered by object class. | T1003.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/synacktiv/ntdissector | 1 | 0 | #linux | N/A | 9 | 2 | 139 | 17 | 2024-08-16T14:18:35Z | 2023-09-05T12:13:47Z | 5027 |
| 702 | */.spraycharles/logs* | .{0,1000}\/\.spraycharles\/logs.{0,1000} | offensive_tool_keyword | spraycharles | Low and slow password spraying tool | T1110.003 - T1110.001 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Tw1sm/spraycharles | 1 | 0 | #linux | N/A | 10 | 2 | 195 | 32 | 2025-02-09T03:08:09Z | 2018-09-17T11:17:47Z | 5035 |
| 703 | */.spraycharles/out* | .{0,1000}\/\.spraycharles\/out.{0,1000} | offensive_tool_keyword | spraycharles | Low and slow password spraying tool | T1110.003 - T1110.001 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Tw1sm/spraycharles | 1 | 0 | #linux | N/A | 10 | 2 | 195 | 32 | 2025-02-09T03:08:09Z | 2018-09-17T11:17:47Z | 5036 |
| 704 | */.spraycharles:/root/.spraycharles* | .{0,1000}\/\.spraycharles\:\/root\/\.spraycharles.{0,1000} | offensive_tool_keyword | spraycharles | Low and slow password spraying tool | T1110.003 - T1110.001 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Tw1sm/spraycharles | 1 | 0 | #linux | N/A | 10 | 2 | 195 | 32 | 2025-02-09T03:08:09Z | 2018-09-17T11:17:47Z | 5037 |
| 705 | *//shuck.sh* | .{0,1000}\/\/shuck\.sh.{0,1000} | offensive_tool_keyword | ShuckNT | ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES) | T1552.001 - T1555.003 - T1078.003 | TA0006 - TA0002 - TA0040 | N/A | N/A | Credential Access | https://github.com/yanncam/ShuckNT | 1 | 1 | N/A | N/A | 10 | 1 | 69 | 9 | 2024-10-18T10:45:49Z | 2023-01-27T07:52:47Z | 5060 |
| 706 | */1$a$$.exe* | .{0,1000}\/1\$a\$\$\.exe.{0,1000} | offensive_tool_keyword | DumpThatLSASS | Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk | T1003 - T1055.011 - T1027 - T1564.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/peiga/DumpThatLSASS | 1 | 1 | N/A | N/A | 10 | 1 | 31 | 79 | 2022-09-24T22:39:04Z | 2022-09-24T22:41:19Z | 5075 |
| 707 | */1/all_in_one.7z.torrent* | .{0,1000}\/1\/all_in_one\.7z\.torrent.{0,1000} | offensive_tool_keyword | weakpass | Weakpass collection of tools for bruteforce and hashcracking | T1110 - T1201 | TA0006 - TA0002 | N/A | Black Basta | Credential Access | https://github.com/zzzteph/weakpass | 1 | 1 | N/A | N/A | 10 | 6 | 541 | 55 | 2025-04-08T19:50:48Z | 2021-08-29T13:07:37Z | 5077 |
| 708 | */1/all_in_one_p.7z* | .{0,1000}\/1\/all_in_one_p\.7z.{0,1000} | offensive_tool_keyword | weakpass | Weakpass collection of tools for bruteforce and hashcracking | T1110 - T1201 | TA0006 - TA0002 | N/A | Black Basta | Credential Access | https://github.com/zzzteph/weakpass | 1 | 1 | N/A | N/A | 10 | 6 | 541 | 55 | 2025-04-08T19:50:48Z | 2021-08-29T13:07:37Z | 5078 |
| 709 | */1/all_in_one_w.7z* | .{0,1000}\/1\/all_in_one_w\.7z.{0,1000} | offensive_tool_keyword | weakpass | Weakpass collection of tools for bruteforce and hashcracking | T1110 - T1201 | TA0006 - TA0002 | N/A | Black Basta | Credential Access | https://github.com/zzzteph/weakpass | 1 | 1 | N/A | N/A | 10 | 6 | 541 | 55 | 2025-04-08T19:50:48Z | 2021-08-29T13:07:37Z | 5079 |
| 710 | */3snake.git* | .{0,1000}\/3snake\.git.{0,1000} | offensive_tool_keyword | 3snake | Tool for extracting information from newly spawned processes | T1003 - T1110 - T1552 - T1505 | TA0001 - TA0002 - TA0003 | N/A | N/A | Credential Access | https://github.com/blendin/3snake | 1 | 1 | N/A | N/A | 7 | 8 | 752 | 109 | 2022-02-14T17:42:10Z | 2018-02-07T21:03:15Z | 5094 |
| 711 | */Adamantium-Thief.git* | .{0,1000}\/Adamantium\-Thief\.git.{0,1000} | offensive_tool_keyword | Adamantium-Thief | Decrypt chromium based browsers passwords - cookies - credit cards - history - bookmarks and autofill. | T1555 - T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/LimerBoy/Adamantium-Thief | 1 | 1 | N/A | N/A | 10 | 9 | 818 | 205 | 2025-01-12T15:11:50Z | 2020-03-01T06:50:15Z | 5131 |
| 712 | */adconnectdump.git* | .{0,1000}\/adconnectdump\.git.{0,1000} | offensive_tool_keyword | adconnectdump | Dump Azure AD Connect credentials for Azure AD and Active Directory | T1003.004 - T1059.001 - T1082 | TA0006 - TA0002 - TA0007 | N/A | N/A | Credential Access | https://github.com/fox-it/adconnectdump | 1 | 1 | N/A | N/A | 10 | 7 | 668 | 88 | 2024-11-10T22:00:16Z | 2019-04-09T07:41:42Z | 5148 |
| 713 | */ADCSCoercePotato.git* | .{0,1000}\/ADCSCoercePotato\.git.{0,1000} | offensive_tool_keyword | ADCSCoercePotato | coercing machine authentication but specific for ADCS server | T1187 | TA0006 | N/A | N/A | Credential Access | https://github.com/decoder-it/ADCSCoercePotato | 1 | 1 | N/A | N/A | 10 | 3 | 224 | 31 | 2024-05-05T14:42:23Z | 2024-02-26T12:08:34Z | 5156 |
| 714 | */ADCSCoercePotato/* | .{0,1000}\/ADCSCoercePotato\/.{0,1000} | offensive_tool_keyword | ADCSCoercePotato | coercing machine authentication but specific for ADCS server | T1187 | TA0006 | N/A | N/A | Credential Access | https://github.com/decoder-it/ADCSCoercePotato | 1 | 1 | N/A | N/A | 10 | 3 | 224 | 31 | 2024-05-05T14:42:23Z | 2024-02-26T12:08:34Z | 5157 |
| 715 | */adcsync.git* | .{0,1000}\/adcsync\.git.{0,1000} | offensive_tool_keyword | adcsync | Use ESC1 to perform a makeshift DCSync and dump hashes | T1003.006 - T1021 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/JPG0mez/ADCSync | 1 | 1 | N/A | N/A | 9 | 3 | 205 | 22 | 2023-11-02T21:41:08Z | 2023-10-04T01:56:50Z | 5164 |
| 716 | */adcsync.py* | .{0,1000}\/adcsync\.py.{0,1000} | offensive_tool_keyword | adcsync | Use ESC1 to perform a makeshift DCSync and dump hashes | T1003.006 - T1021 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/JPG0mez/ADCSync | 1 | 1 | N/A | N/A | 9 | 3 | 205 | 22 | 2023-11-02T21:41:08Z | 2023-10-04T01:56:50Z | 5165 |
| 717 | */adfsbrute.git* | .{0,1000}\/adfsbrute\.git.{0,1000} | offensive_tool_keyword | adfsbrute | test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks | T1110.003 - T1110.001 - T1110 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/ricardojoserf/adfsbrute | 1 | 1 | N/A | N/A | 8 | 2 | 172 | 33 | 2021-04-23T16:43:59Z | 2020-10-02T16:28:35Z | 5187 |
| 718 | */adfsbrute.py* | .{0,1000}\/adfsbrute\.py.{0,1000} | offensive_tool_keyword | adfsbrute | test credentials against Active Directory Federation Services (ADFS) allowing password spraying or bruteforce attacks | T1110.003 - T1110.001 - T1110 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/ricardojoserf/adfsbrute | 1 | 1 | N/A | N/A | 8 | 2 | 172 | 33 | 2021-04-23T16:43:59Z | 2020-10-02T16:28:35Z | 5188 |
| 719 | */ADFSDump.git* | .{0,1000}\/ADFSDump\.git.{0,1000} | offensive_tool_keyword | ADFSDump | A C# tool to dump all sorts of goodies from AD FS | T1081 - T1003 - T1114 - T1212 | TA0006 - TA0005 - TA0009 | N/A | N/A | Credential Access | https://github.com/mandiant/ADFSDump | 1 | 1 | N/A | N/A | 10 | 4 | 349 | 67 | 2023-08-07T16:58:37Z | 2019-03-20T22:31:16Z | 5191 |
| 720 | */ADFSDump-PS.git* | .{0,1000}\/ADFSDump\-PS\.git.{0,1000} | offensive_tool_keyword | ADFSDump-PS | ADFSDump to assist with GoldenSAML | T1078 - T1552.004 - T1558.004 | TA0006 | N/A | N/A | Credential Access | https://github.com/ZephrFish/ADFSDump-PS | 1 | 1 | N/A | N/A | 10 | 1 | 31 | 8 | 2024-05-20T00:00:19Z | 2024-05-19T00:46:28Z | 5192 |
| 721 | */ADFSpray* | .{0,1000}\/ADFSpray.{0,1000} | offensive_tool_keyword | adfspray | Python3 tool to perform password spraying against Microsoft Online service using various methods | T1110.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/xFreed0m/ADFSpray | 1 | 1 | N/A | N/A | N/A | 1 | 87 | 14 | 2023-03-12T00:21:34Z | 2020-04-23T08:56:51Z | 5194 |
| 722 | */ADFSRelay.git* | .{0,1000}\/ADFSRelay\.git.{0,1000} | offensive_tool_keyword | ADFSRelay | NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS | T1140 - T1212 - T1557 | TA0007 - TA0008 - TA0006 | N/A | Black Basta | Credential Access | https://github.com/praetorian-inc/ADFSRelay | 1 | 1 | N/A | N/A | 10 | 2 | 179 | 15 | 2022-06-22T03:01:00Z | 2022-05-12T01:20:14Z | 5195 |
| 723 | */ADFSRelay.go* | .{0,1000}\/ADFSRelay\.go.{0,1000} | offensive_tool_keyword | ADFSRelay | NTLMParse is a utility for decoding base64-encoded NTLM messages and printing information about the underlying properties and fields within the message. Examining these NTLM messages is helpful when researching the behavior of a particular NTLM implementation. ADFSRelay is a proof of concept utility developed while researching the feasibility of NTLM relaying attacks targeting the ADFS service. This utility can be leveraged to perform NTLM relaying attacks targeting ADFS | T1140 - T1212 - T1557 | TA0007 - TA0008 - TA0006 | N/A | Black Basta | Credential Access | https://github.com/praetorian-inc/ADFSRelay | 1 | 1 | N/A | N/A | 10 | 2 | 179 | 15 | 2022-06-22T03:01:00Z | 2022-05-12T01:20:14Z | 5196 |
| 724 | */adfs-spray.py* | .{0,1000}\/adfs\-spray\.py.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 1 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 5197 |
| 725 | */aerosol.py* | .{0,1000}\/aerosol\.py.{0,1000} | offensive_tool_keyword | SprayingToolkit | Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient | T1110 - T1078 - T1133 - T1061 - T1621 | TA0001 - TA0002 - TA0003 | N/A | N/A | Credential Access | https://github.com/byt3bl33d3r/SprayingToolkit | 1 | 0 | #linux | N/A | 10 | 10 | 1491 | 269 | 2022-10-17T01:01:57Z | 2018-09-13T09:52:11Z | 5220 |
| 726 | */amass/wordlists* | .{0,1000}\/amass\/wordlists.{0,1000} | offensive_tool_keyword | wordlists | package contains the rockyou.txt wordlist | T1110.001 | TA0006 | N/A | N/A | Credential Access | https://www.kali.org/tools/wordlists/ | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 5286 |
| 727 | */amsiwala.exe* | .{0,1000}\/amsiwala\.exe.{0,1000} | offensive_tool_keyword | ShadowStealer | Google Chrome Passwords , Cookies and SystemInfo Dumper | T1555 - T1539 - T1125 - T1083 - T1056 | TA0009 - TA0006 - TA0010 | N/A | N/A | Credential Access | https://github.com/xelroth/ShadowStealer | 1 | 1 | N/A | N/A | 10 | 1 | N/A | N/A | N/A | N/A | 5306 |
| 728 | */AndrewSpecial.git* | .{0,1000}\/AndrewSpecial\.git.{0,1000} | offensive_tool_keyword | AndrewSpecial | AndrewSpecial - dumping lsass memory stealthily | T1003.001 - T1055.001 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/hoangprod/AndrewSpecial | 1 | 1 | N/A | N/A | 10 | 4 | 386 | 98 | 2019-06-02T02:49:28Z | 2019-01-18T19:12:09Z | 5308 |
| 729 | */apps/zxtm/wizard.fcgi?error=1§ion=Access+Management%3ALocalUsers* | .{0,1000}\/apps\/zxtm\/wizard\.fcgi\?error\=1\§ion\=Access\+Management\%3ALocalUsers.{0,1000} | offensive_tool_keyword | POC | Ivanti Authent Bypass CVE-2024-7593 - Successful exploitation could lead to authentication bypass and creation of an administrator user | T1078 - T1136 - T1078.001 | TA0006 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://x.com/mthcht/status/1823463842459848906 | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5388 |
| 730 | */Ask4Creds.git* | .{0,1000}\/Ask4Creds\.git.{0,1000} | offensive_tool_keyword | Ask4Creds | Prompt User for credentials | T1056 - T1071 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Leo4j/Ask4Creds | 1 | 1 | N/A | N/A | 8 | 1 | 1 | 0 | 2024-03-20T17:09:21Z | 2023-11-12T15:21:40Z | 5409 |
| 731 | */Ask4Creds.ps1* | .{0,1000}\/Ask4Creds\.ps1.{0,1000} | offensive_tool_keyword | Ask4Creds | Prompt User for credentials | T1056 - T1071 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Leo4j/Ask4Creds | 1 | 1 | N/A | N/A | 8 | 1 | 1 | 0 | 2024-03-20T17:09:21Z | 2023-11-12T15:21:40Z | 5411 |
| 732 | */ASREPRoast* | .{0,1000}\/ASREPRoast.{0,1000} | offensive_tool_keyword | ASREPRoast | Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled. | T1558.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/HarmJ0y/ASREPRoast | 1 | 1 | N/A | N/A | N/A | 3 | 202 | 58 | 2018-09-25T03:26:00Z | 2017-01-14T21:07:57Z | 5423 |
| 733 | */atomizer.py* | .{0,1000}\/atomizer\.py.{0,1000} | offensive_tool_keyword | SprayingToolkit | Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient | T1110 - T1078 - T1133 - T1061 - T1621 | TA0001 - TA0002 - TA0003 | N/A | N/A | Credential Access | https://github.com/byt3bl33d3r/SprayingToolkit | 1 | 0 | #linux | N/A | 9 | 10 | 1491 | 269 | 2022-10-17T01:01:57Z | 2018-09-13T09:52:11Z | 5456 |
| 734 | */ATPMiniDump.git* | .{0,1000}\/ATPMiniDump\.git.{0,1000} | offensive_tool_keyword | ATPMiniDump | Dumping LSASS memory with MiniDumpWriteDump on PssCaptureSnapShot to evade WinDefender ATP credential-theft. Take a look at this blog post for details. ATPMiniDump was created starting from Outflank-Dumpert then big credits to @Cneelis | T1003 - T1005 - T1055 - T1218 | TA0006 - TA0008 - TA0011 | N/A | N/A | Credential Access | https://github.com/b4rtik/ATPMiniDump | 1 | 1 | N/A | N/A | N/A | 3 | 255 | 46 | 2019-12-02T15:01:22Z | 2019-11-29T19:49:54Z | 5460 |
| 735 | */autoNTDS.git* | .{0,1000}\/autoNTDS\.git.{0,1000} | offensive_tool_keyword | autoNTDS | autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat | T1003 - T1059 - T1021.002 - T1213 | TA0006 - TA0008 - TA0005 - TA0002 | N/A | N/A | Credential Access | https://github.com/hmaverickadams/autoNTDS | 1 | 1 | N/A | N/A | 10 | 2 | 109 | 14 | 2023-10-31T22:03:58Z | 2023-10-30T23:10:58Z | 5486 |
| 736 | */autoNTDS.py* | .{0,1000}\/autoNTDS\.py.{0,1000} | offensive_tool_keyword | autoNTDS | autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat | T1003 - T1059 - T1021.002 - T1213 | TA0006 - TA0008 - TA0005 - TA0002 | N/A | N/A | Credential Access | https://github.com/hmaverickadams/autoNTDS | 1 | 1 | N/A | N/A | 10 | 2 | 109 | 14 | 2023-10-31T22:03:58Z | 2023-10-30T23:10:58Z | 5487 |
| 737 | */BabelStrike.git* | .{0,1000}\/BabelStrike\.git.{0,1000} | offensive_tool_keyword | BabelStrike | The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin) | T1078 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/t3l3machus/BabelStrike | 1 | 1 | N/A | N/A | 1 | 2 | 132 | 23 | 2024-07-19T07:02:42Z | 2023-01-10T07:59:00Z | 5518 |
| 738 | */BabelStrike.py* | .{0,1000}\/BabelStrike\.py.{0,1000} | offensive_tool_keyword | BabelStrike | The purpose of this tool is to normalize and generate possible usernames out of a full names list that may include names written in multiple (non-English) languages. common problem occurring from scraped employee names lists (e.g. from Linkedin) | T1078 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/t3l3machus/BabelStrike | 1 | 1 | N/A | N/A | 1 | 2 | 132 | 23 | 2024-07-19T07:02:42Z | 2023-01-10T07:59:00Z | 5519 |
| 739 | */backupcreds.exe* | .{0,1000}\/backupcreds\.exe.{0,1000} | offensive_tool_keyword | BackupCreds | A C# implementation of dumping credentials from Windows Credential Manager | T1003 - T1555 | TA0006 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/leftp/BackupCreds | 1 | 1 | N/A | N/A | 9 | 1 | 57 | 10 | 2023-09-23T10:37:05Z | 2023-09-23T06:42:20Z | 5542 |
| 740 | */BackupCreds.git* | .{0,1000}\/BackupCreds\.git.{0,1000} | offensive_tool_keyword | BackupCreds | A C# implementation of dumping credentials from Windows Credential Manager | T1003 - T1555 | TA0006 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/leftp/BackupCreds | 1 | 1 | N/A | N/A | 9 | 1 | 57 | 10 | 2023-09-23T10:37:05Z | 2023-09-23T06:42:20Z | 5543 |
| 741 | */badcert.pem* | .{0,1000}\/badcert\.pem.{0,1000} | offensive_tool_keyword | SSH-Snake | SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery | T1021.004 - T1027 - T1552.004 | TA0002 - TA0005 - TA0006 | N/A | N/A | Credential Access | https://github.com/MegaManSec/SSH-Snake | 1 | 0 | #linux | N/A | 10 | 10 | 2065 | 198 | 2024-07-25T09:32:07Z | 2023-12-03T04:52:38Z | 5548 |
| 742 | */badkey.pem* | .{0,1000}\/badkey\.pem.{0,1000} | offensive_tool_keyword | SSH-Snake | SSH-Snake is a self-propagating - self-replicating - file-less script that automates the post-exploitation task of SSH private key and host discovery | T1021.004 - T1027 - T1552.004 | TA0002 - TA0005 - TA0006 | N/A | N/A | Credential Access | https://github.com/MegaManSec/SSH-Snake | 1 | 0 | #linux | N/A | 10 | 10 | 2065 | 198 | 2024-07-25T09:32:07Z | 2023-12-03T04:52:38Z | 5549 |
| 743 | */BesoToken.cpp* | .{0,1000}\/BesoToken\.cpp.{0,1000} | offensive_tool_keyword | BesoToken | A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions). | T1134 - T1003.002 | TA0004 - TA0006 | N/A | N/A | Credential Access | https://github.com/OmriBaso/BesoToken | 1 | 1 | N/A | N/A | 10 | 1 | 93 | 14 | 2022-11-23T10:45:07Z | 2022-11-21T01:07:51Z | 5606 |
| 744 | */BesoToken.exe* | .{0,1000}\/BesoToken\.exe.{0,1000} | offensive_tool_keyword | BesoToken | A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions). | T1134 - T1003.002 | TA0004 - TA0006 | N/A | N/A | Credential Access | https://github.com/OmriBaso/BesoToken | 1 | 1 | N/A | N/A | 10 | 1 | 93 | 14 | 2022-11-23T10:45:07Z | 2022-11-21T01:07:51Z | 5607 |
| 745 | */BesoToken.git* | .{0,1000}\/BesoToken\.git.{0,1000} | offensive_tool_keyword | BesoToken | A tool to Impersonate logged on users without touching LSASS (Including non-Interactive sessions). | T1134 - T1003.002 | TA0004 - TA0006 | N/A | N/A | Credential Access | https://github.com/OmriBaso/BesoToken | 1 | 1 | N/A | N/A | 10 | 1 | 93 | 14 | 2022-11-23T10:45:07Z | 2022-11-21T01:07:51Z | 5608 |
| 746 | */big_shell_pwd.7z* | .{0,1000}\/big_shell_pwd\.7z.{0,1000} | offensive_tool_keyword | cheetah | a very fast brute force webshell password tool | T1110 - T1190 - T1505.003 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/shmilylty/cheetah | 1 | 1 | N/A | N/A | 10 | 7 | 630 | 150 | 2023-04-17T01:33:52Z | 2017-04-15T20:03:50Z | 5618 |
| 747 | */Blank%20Grabber/Extras/hash* | .{0,1000}\/Blank\%20Grabber\/Extras\/hash.{0,1000} | offensive_tool_keyword | Blank-Grabber | Stealer with multiple functions | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Blank-c/Blank-Grabber | 1 | 1 | N/A | N/A | 10 | 9 | 831 | 220 | 2023-08-06T06:26:16Z | 2022-01-26T12:04:56Z | 5692 |
| 748 | */Blank.Grabber.zip* | .{0,1000}\/Blank\.Grabber\.zip.{0,1000} | offensive_tool_keyword | Blank-Grabber | Stealer with multiple functions | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Blank-c/Blank-Grabber | 1 | 1 | N/A | N/A | 10 | 9 | 831 | 220 | 2023-08-06T06:26:16Z | 2022-01-26T12:04:56Z | 5693 |
| 749 | */Blank-Grabber#download* | .{0,1000}\/Blank\-Grabber\#download.{0,1000} | offensive_tool_keyword | Blank-Grabber | Stealer with multiple functions | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Blank-c/Blank-Grabber | 1 | 1 | N/A | N/A | 10 | 9 | 831 | 220 | 2023-08-06T06:26:16Z | 2022-01-26T12:04:56Z | 5694 |
| 750 | */Blank-Grabber.git* | .{0,1000}\/Blank\-Grabber\.git.{0,1000} | offensive_tool_keyword | Blank-Grabber | Stealer with multiple functions | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Blank-c/Blank-Grabber | 1 | 1 | N/A | N/A | 10 | 9 | 831 | 220 | 2023-08-06T06:26:16Z | 2022-01-26T12:04:56Z | 5695 |
| 751 | */BlankOBF.py* | .{0,1000}\/BlankOBF\.py.{0,1000} | offensive_tool_keyword | Blank-Grabber | Stealer with multiple functions | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Blank-c/Blank-Grabber | 1 | 1 | N/A | N/A | 10 | 9 | 831 | 220 | 2023-08-06T06:26:16Z | 2022-01-26T12:04:56Z | 5697 |
| 752 | */blindsight.exe* | .{0,1000}\/blindsight\.exe.{0,1000} | offensive_tool_keyword | blindsight | Red teaming tool to dump LSASS memory, bypassing basic countermeasures | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/0xdea/blindsight | 1 | 1 | N/A | N/A | 10 | 3 | 225 | 26 | 2024-12-31T15:28:15Z | 2024-07-18T07:35:43Z | 5700 |
| 753 | */blindsight.git* | .{0,1000}\/blindsight\.git.{0,1000} | offensive_tool_keyword | blindsight | Red teaming tool to dump LSASS memory, bypassing basic countermeasures | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/0xdea/blindsight | 1 | 1 | N/A | N/A | 10 | 3 | 225 | 26 | 2024-12-31T15:28:15Z | 2024-07-18T07:35:43Z | 5701 |
| 754 | */bloodhound.py* | .{0,1000}\/bloodhound\.py.{0,1000} | offensive_tool_keyword | crackmapexec | bloodhound integration with crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 1 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 5715 |
| 755 | */bloodhoundsync.py* | .{0,1000}\/bloodhoundsync\.py.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 1 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 5725 |
| 756 | */BrowserDataGrabber.git* | .{0,1000}\/BrowserDataGrabber\.git.{0,1000} | offensive_tool_keyword | Browser Data Grabber | credential access tool used by the Dispossessor ransomware group | T1003 - T1555 - T1081 - T1552 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/n37sn4k3/BrowserDataGrabber | 1 | 1 | N/A | N/A | 10 | 1 | 7 | 4 | 2018-05-28T15:49:03Z | 2018-05-04T12:33:32Z | 5817 |
| 757 | */BrowserGhost.git* | .{0,1000}\/BrowserGhost\.git.{0,1000} | offensive_tool_keyword | BrowserGhost | This is a tool for grabbing browser passwords | T1555.003 - T1555.013 - T1003.008 | TA0006 | N/A | N/A | Credential Access | https://github.com/QAX-A-Team/BrowserGhost | 1 | 1 | N/A | N/A | 10 | 10 | 1414 | 206 | 2022-05-21T14:09:45Z | 2020-06-12T12:19:06Z | 5819 |
| 758 | */BrowserGhost/releases/download/* | .{0,1000}\/BrowserGhost\/releases\/download\/.{0,1000} | offensive_tool_keyword | BrowserGhost | This is a tool for grabbing browser passwords | T1555.003 - T1555.013 - T1003.008 | TA0006 | N/A | N/A | Credential Access | https://github.com/QAX-A-Team/BrowserGhost | 1 | 1 | N/A | N/A | 10 | 10 | 1414 | 206 | 2022-05-21T14:09:45Z | 2020-06-12T12:19:06Z | 5820 |
| 759 | */BrowserGhost/tarball/* | .{0,1000}\/BrowserGhost\/tarball\/.{0,1000} | offensive_tool_keyword | BrowserGhost | This is a tool for grabbing browser passwords | T1555.003 - T1555.013 - T1003.008 | TA0006 | N/A | N/A | Credential Access | https://github.com/QAX-A-Team/BrowserGhost | 1 | 1 | N/A | N/A | 10 | 10 | 1414 | 206 | 2022-05-21T14:09:45Z | 2020-06-12T12:19:06Z | 5821 |
| 760 | */BrowserGhost/zipball/* | .{0,1000}\/BrowserGhost\/zipball\/.{0,1000} | offensive_tool_keyword | BrowserGhost | This is a tool for grabbing browser passwords | T1555.003 - T1555.013 - T1003.008 | TA0006 | N/A | N/A | Credential Access | https://github.com/QAX-A-Team/BrowserGhost | 1 | 1 | N/A | N/A | 10 | 10 | 1414 | 206 | 2022-05-21T14:09:45Z | 2020-06-12T12:19:06Z | 5822 |
| 761 | */Bruteforcer.* | .{0,1000}\/Bruteforcer\..{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 1 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 5833 |
| 762 | */brutespray.git* | .{0,1000}\/brutespray\.git.{0,1000} | offensive_tool_keyword | brutespray | BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap. | T1110 | TA0001 - TA0043 | N/A | N/A | Credential Access | https://github.com/x90skysn3k/brutespray | 1 | 1 | N/A | N/A | 10 | 10 | 2231 | 405 | 2025-04-21T03:17:20Z | 2017-04-05T17:05:10Z | 5842 |
| 763 | */brutespray/* | .{0,1000}\/brutespray\/.{0,1000} | offensive_tool_keyword | brutespray | BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap. | T1110 | TA0001 - TA0043 | N/A | N/A | Credential Access | https://github.com/x90skysn3k/brutespray | 1 | 1 | N/A | N/A | 10 | 10 | 2231 | 405 | 2025-04-21T03:17:20Z | 2017-04-05T17:05:10Z | 5843 |
| 764 | */brutespray/* | .{0,1000}\/brutespray\/.{0,1000} | offensive_tool_keyword | wordlists | package contains the rockyou.txt wordlist | T1110.001 | TA0006 | N/A | N/A | Credential Access | https://www.kali.org/tools/wordlists/ | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 5844 |
| 765 | */brutespray_* | .{0,1000}\/brutespray_.{0,1000} | offensive_tool_keyword | brutespray | BruteSpray takes nmap GNMAP/XML output or newline seperated JSONS and automatically brute-forces services with default credentials using Medusa. BruteSpray can even find non-standard ports by using the -sV inside Nmap. | T1110 | TA0001 - TA0043 | N/A | N/A | Credential Access | https://github.com/x90skysn3k/brutespray | 1 | 1 | N/A | N/A | 10 | 10 | 2231 | 405 | 2025-04-21T03:17:20Z | 2017-04-05T17:05:10Z | 5845 |
| 766 | */BypassCredGuard.cpp* | .{0,1000}\/BypassCredGuard\.cpp.{0,1000} | offensive_tool_keyword | BypassCredGuard | Credential Guard Bypass Via Patching Wdigest Memory | T1003 - T1112 - T1555.002 - T1574 | TA0006 - TA0005 - TA0040 | N/A | N/A | Credential Access | https://github.com/wh0amitz/BypassCredGuard | 1 | 1 | N/A | N/A | 10 | 4 | 323 | 52 | 2023-02-03T06:55:43Z | 2023-01-18T15:16:11Z | 5880 |
| 767 | */BypassCredGuard.exe* | .{0,1000}\/BypassCredGuard\.exe.{0,1000} | offensive_tool_keyword | BypassCredGuard | Credential Guard Bypass Via Patching Wdigest Memory | T1003 - T1112 - T1555.002 - T1574 | TA0006 - TA0005 - TA0040 | N/A | N/A | Credential Access | https://github.com/wh0amitz/BypassCredGuard | 1 | 1 | N/A | N/A | 10 | 4 | 323 | 52 | 2023-02-03T06:55:43Z | 2023-01-18T15:16:11Z | 5881 |
| 768 | */BypassCredGuard.git* | .{0,1000}\/BypassCredGuard\.git.{0,1000} | offensive_tool_keyword | BypassCredGuard | Credential Guard Bypass Via Patching Wdigest Memory | T1003 - T1112 - T1555.002 - T1574 | TA0006 - TA0005 - TA0040 | N/A | N/A | Credential Access | https://github.com/wh0amitz/BypassCredGuard | 1 | 1 | N/A | N/A | 10 | 4 | 323 | 52 | 2023-02-03T06:55:43Z | 2023-01-18T15:16:11Z | 5882 |
| 769 | */c ping 127.0.0.1 && del \\* | .{0,1000}\/c\sping\s127\.0\.0\.1\s\&\&\sdel\s\\\\.{0,1000} | offensive_tool_keyword | PredatorTheStealer | C++ stealer (passwords - cookies - forms - cards - wallets) | T1078 - T1114 - T1555 - T1539 - T1212 - T1132 | TA0006 - TA0010 | N/A | N/A | Credential Access | https://github.com/SecUser1/PredatorTheStealer | 1 | 0 | N/A | N/A | 8 | 1 | 11 | 2 | 2022-12-06T16:46:33Z | 2022-12-06T16:34:43Z | 5890 |
| 770 | */cached-domain-credentials.html* | .{0,1000}\/cached\-domain\-credentials\.html.{0,1000} | offensive_tool_keyword | secretsdump | secretdump.py from impacket - https://github.com/fortra/impacket | T1003.003 | TA0006 | Operation Wocao | Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE | Credential Access | https://github.com/fortra/impacket | 1 | 0 | N/A | N/A | 10 | 10 | 14198 | 3681 | 2025-04-22T13:40:55Z | 2015-04-15T14:04:07Z | 5936 |
| 771 | */cachedump.py* | .{0,1000}\/cachedump\.py.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 1 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 5937 |
| 772 | */cain.html* | .{0,1000}\/cain\.html.{0,1000} | offensive_tool_keyword | Cain&Abel | Cain & Able exploitation tool file | T1075 - T1110 - T1071 - T1003 - T1555 | TA0003 - TA0008 | N/A | FIN7 - Night Dragon | Credential Access | https://github.com/undergroundwires/CEH-in-bullet-points/blob/master/chapters/08-sniffing/sniffing-tools.md | 1 | 1 | N/A | N/A | N/A | 10 | 1067 | 310 | 2024-08-13T04:35:50Z | 2021-05-11T12:38:17Z | 5940 |
| 773 | */CapBypass.ps1* | .{0,1000}\/CapBypass\.ps1.{0,1000} | offensive_tool_keyword | TokenTactics | Azure JWT Token Manipulation Toolset | T1134.002 - T1078.004 - T1095 | TA0005 - TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/rvrsh3ll/TokenTactics | 1 | 0 | N/A | N/A | 6 | 7 | 652 | 105 | 2024-12-06T15:51:42Z | 2021-07-08T02:28:12Z | 5952 |
| 774 | */cerbrutus* | .{0,1000}\/cerbrutus.{0,1000} | offensive_tool_keyword | cerbrutus | Network brute force tool. written in Python. Faster than other existing solutions (including the main leader in the network brute force market). | T1110 - T1040 - T1496 | TA0006 - TA0008 - TA0009 | N/A | N/A | Credential Access | https://github.com/Cerbrutus-BruteForcer/cerbrutus | 1 | 1 | N/A | N/A | N/A | 4 | 385 | 57 | 2021-08-22T19:05:45Z | 2021-07-07T19:11:40Z | 5972 |
| 775 | */certsync.git* | .{0,1000}\/certsync\.git.{0,1000} | offensive_tool_keyword | certsync | Dump NTDS with golden certificates and UnPAC the hash | T1553.002 - T1003.001 - T1145 - T1649 | TA0002 - TA0003 - TA0006 | N/A | N/A | Credential Access | https://github.com/zblurx/certsync | 1 | 1 | N/A | N/A | 10 | 7 | 633 | 66 | 2024-03-20T10:58:15Z | 2023-01-31T15:37:12Z | 5982 |
| 776 | */cheetah.git* | .{0,1000}\/cheetah\.git.{0,1000} | offensive_tool_keyword | cheetah | a very fast brute force webshell password tool | T1110 - T1190 - T1505.003 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/shmilylty/cheetah | 1 | 1 | N/A | N/A | 10 | 7 | 630 | 150 | 2023-04-17T01:33:52Z | 2017-04-15T20:03:50Z | 6004 |
| 777 | */cheetah.py* | .{0,1000}\/cheetah\.py.{0,1000} | offensive_tool_keyword | cheetah | a very fast brute force webshell password tool | T1110 - T1190 - T1505.003 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/shmilylty/cheetah | 1 | 0 | #linux | N/A | 10 | 7 | 630 | 150 | 2023-04-17T01:33:52Z | 2017-04-15T20:03:50Z | 6005 |
| 778 | */chntpw -* | .{0,1000}\/chntpw\s\-.{0,1000} | offensive_tool_keyword | chntpw | reset a password on your system | T1003 - T1078 | TA0006 | N/A | N/A | Credential Access | https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6021 |
| 779 | */chntpw-140201* | .{0,1000}\/chntpw\-140201.{0,1000} | offensive_tool_keyword | chntpw | reset a password on your system | T1003 - T1078 | TA0006 | N/A | N/A | Credential Access | https://pogostick.net/~pnh/ntpasswd/chntpw-source-140201.zip | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6022 |
| 780 | */chrome_creditcard.csv* | .{0,1000}\/chrome_creditcard\.csv.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 0 | #linux | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 6023 |
| 781 | */chrome_creditcard.json* | .{0,1000}\/chrome_creditcard\.json.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 0 | #linux | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 6024 |
| 782 | */chrome_decrypt.exe* | .{0,1000}\/chrome_decrypt\.exe.{0,1000} | offensive_tool_keyword | Chrome-App-Bound-Encryption-Decryption | Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections | T1003 - T1081 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption | 1 | 1 | N/A | N/A | 9 | 5 | 401 | 73 | 2025-04-22T08:30:00Z | 2024-10-27T11:28:35Z | 6025 |
| 783 | */chrome_decrypt.py* | .{0,1000}\/chrome_decrypt\.py.{0,1000} | offensive_tool_keyword | donpapi | Dumping DPAPI credentials remotely | T1003.006 - T1021.001 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/login-securite/DonPAPI | 1 | 1 | N/A | N/A | N/A | 10 | 1110 | 130 | 2025-03-24T10:23:58Z | 2021-09-27T09:12:51Z | 6026 |
| 784 | */chrome_password.csv* | .{0,1000}\/chrome_password\.csv.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 0 | #linux | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 6027 |
| 785 | */chrome_password.json* | .{0,1000}\/chrome_password\.json.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 0 | #linux | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 6028 |
| 786 | */Chrome-App-Bound-Encryption-Decryption.git* | .{0,1000}\/Chrome\-App\-Bound\-Encryption\-Decryption\.git.{0,1000} | offensive_tool_keyword | Chrome-App-Bound-Encryption-Decryption | Tool to decrypt App-Bound encrypted keys in Chrome using the IElevator COM interface with path validation and encryption protections | T1003 - T1081 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption | 1 | 1 | N/A | N/A | 9 | 5 | 401 | 73 | 2025-04-22T08:30:00Z | 2024-10-27T11:28:35Z | 6029 |
| 787 | */ChromeDump/* | .{0,1000}\/ChromeDump\/.{0,1000} | offensive_tool_keyword | chromedump | ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser | T1059.007 - T1114.001 - T1518.001 - T1552.002 | TA0005 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/g4l4drim/ChromeDump | 1 | 1 | N/A | N/A | N/A | 1 | 55 | 1 | 2024-10-12T14:07:36Z | 2023-01-26T20:44:06Z | 6031 |
| 788 | */ChromeKatz.git* | .{0,1000}\/ChromeKatz\.git.{0,1000} | offensive_tool_keyword | ChromeKatz | Dump cookies directly from Chrome process memory | T1555.003 - T1003 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Meckazin/ChromeKatz | 1 | 1 | N/A | N/A | 10 | 10 | 1171 | 115 | 2024-11-26T12:53:22Z | 2023-12-07T22:27:06Z | 6032 |
| 789 | */ChromeStealer.git* | .{0,1000}\/ChromeStealer\.git.{0,1000} | offensive_tool_keyword | ChromeStealer | extract and decrypt stored passwords from Google Chrome | T1555.003 - T1003.001 - T1552.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/BernKing/ChromeStealer | 1 | 1 | N/A | N/A | 8 | 2 | 145 | 18 | 2024-07-25T08:27:10Z | 2024-07-14T13:27:30Z | 6035 |
| 790 | */chromium_based_browsers.py* | .{0,1000}\/chromium_based_browsers\.py.{0,1000} | offensive_tool_keyword | Browser-password-stealer | This python program gets all the saved passwords + credit cards and bookmarks from chromium based browsers supports chromium 80 and above! | T1003.002 - T1056.001 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/henry-richard7/Browser-password-stealer | 1 | 1 | N/A | N/A | 10 | 5 | 423 | 62 | 2024-07-12T10:30:42Z | 2020-09-15T09:23:56Z | 6036 |
| 791 | */cme smb * | .{0,1000}\/cme\ssmb\s.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | #linux | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 6112 |
| 792 | */cme winrm * | .{0,1000}\/cme\swinrm\s.{0,1000} | offensive_tool_keyword | crackmapexec | crackmapexec command lines. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 0 | #linux | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 6113 |
| 793 | */cmedb | .{0,1000}\/cmedb | offensive_tool_keyword | crackmapexec | windows default copiled executable name for crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral move | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 1 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 6117 |
| 794 | */comsvcs_stealth.py* | .{0,1000}\/comsvcs_stealth\.py.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 1 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 6177 |
| 795 | */crack.sh/get-cracking/* | .{0,1000}\/\/crack\.sh\/get\-cracking\/.{0,1000} | offensive_tool_keyword | crack.sh | crack.sh THE WORLD???S FASTEST DES CRACKER. Used by attackers to submit passwords to crack | T1110.002 - T1021.002 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://crack.sh/get-cracking/ | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 6212 |
| 796 | */cracked-users.txt* | .{0,1000}\/cracked\-users\.txt.{0,1000} | offensive_tool_keyword | autoNTDS | autoNTDS is an automation script designed to simplify the process of dumping and cracking NTDS hashes using secretsdump.py and hashcat | T1003 - T1059 - T1021.002 - T1213 | TA0006 - TA0008 - TA0005 - TA0002 | N/A | N/A | Credential Access | https://github.com/hmaverickadams/autoNTDS | 1 | 0 | N/A | N/A | 10 | 2 | 109 | 14 | 2023-10-31T22:03:58Z | 2023-10-30T23:10:58Z | 6219 |
| 797 | */cracklord.git* | .{0,1000}\/cracklord\.git.{0,1000} | offensive_tool_keyword | cracklord | Queue and resource system for cracking passwords | T1110 - T1201 | TA0006 - TA0002 | N/A | N/A | Credential Access | https://github.com/jmmcatee/cracklord | 1 | 1 | N/A | N/A | 10 | 4 | 388 | 70 | 2022-09-22T09:30:14Z | 2013-12-09T23:10:54Z | 6220 |
| 798 | */cracklord/cmd/* | .{0,1000}\/cracklord\/cmd\/.{0,1000} | offensive_tool_keyword | cracklord | Queue and resource system for cracking passwords | T1110 - T1201 | TA0006 - TA0002 | N/A | N/A | Credential Access | https://github.com/jmmcatee/cracklord | 1 | 1 | N/A | N/A | 10 | 4 | 388 | 70 | 2022-09-22T09:30:14Z | 2013-12-09T23:10:54Z | 6221 |
| 799 | */creddump7*.py* | .{0,1000}\/creddump7.{0,1000}\.py.{0,1000} | offensive_tool_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 1 | N/A | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 6239 |
| 800 | */creddump7.git* | .{0,1000}\/creddump7\.git.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 1 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 6240 |
| 801 | */creddump7.git* | .{0,1000}\/creddump7\.git.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 1 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 6241 |
| 802 | */creddump7/* | .{0,1000}\/creddump7\/.{0,1000} | offensive_tool_keyword | donpapi | Dumping DPAPI credentials remotely | T1003.006 - T1021.001 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/login-securite/DonPAPI | 1 | 1 | N/A | N/A | N/A | 10 | 1110 | 130 | 2025-03-24T10:23:58Z | 2021-09-27T09:12:51Z | 6242 |
| 803 | */creddump7/releases/* | .{0,1000}\/creddump7\/releases\/.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 1 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 6244 |
| 804 | */credentials/SudoSnatch* | .{0,1000}\/credentials\/SudoSnatch.{0,1000} | offensive_tool_keyword | sudoSnatch | sudoSnatch payload grabs sudo password in plain text and imediately after target uses sudo command and sends it back to attacker remotely/locally. | T1552.001 - T1056.001 - T1071.001 | TA0006 - TA0004 - TA0010 | N/A | N/A | Credential Access | https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/SudoSnatch | 1 | 1 | #linux | N/A | 10 | 10 | 904 | 310 | 2024-09-14T02:34:26Z | 2021-09-08T20:33:18Z | 6251 |
| 805 | */credentials/wifigrabber* | .{0,1000}\/credentials\/wifigrabber.{0,1000} | offensive_tool_keyword | wifigrabber | grab wifi password and exfiltrate to a given site | T1056.005 - T1552.001 - T1119 - T1071.001 | TA0004 - TA0006 - TA0010 - TA0040 | N/A | N/A | Credential Access | https://github.com/hak5/omg-payloads/tree/master/payloads/library/credentials/wifigrabber | 1 | 1 | N/A | N/A | 10 | 10 | 904 | 310 | 2024-09-14T02:34:26Z | 2021-09-08T20:33:18Z | 6252 |
| 806 | */CredMaster.git* | .{0,1000}\/CredMaster\.git.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 1 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 6257 |
| 807 | */credmaster.py* | .{0,1000}\/credmaster\.py.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 1 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 6258 |
| 808 | */credmaster.txt* | .{0,1000}\/credmaster\.txt.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | #linux | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 6259 |
| 809 | */CredMaster-master.zip* | .{0,1000}\/CredMaster\-master\.zip.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 1 | N/A | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 6260 |
| 810 | */credmaster-success.txt* | .{0,1000}\/credmaster\-success\.txt.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | #linux | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 6261 |
| 811 | */credmaster-validusers.txt* | .{0,1000}\/credmaster\-validusers\.txt.{0,1000} | offensive_tool_keyword | CredMaster | CredKing password spraying tool - uses FireProx APIs to rotate IP addresses | T1110.003 - T1596 - T1071.004 - T1621 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/knavesec/CredMaster | 1 | 0 | #linux | N/A | 9 | 10 | 1070 | 142 | 2025-03-19T20:36:21Z | 2020-09-25T20:57:42Z | 6262 |
| 812 | */CredPhisher.exe* | .{0,1000}\/CredPhisher\.exe.{0,1000} | offensive_tool_keyword | Credphisher | prompt a user for credentials using a Windows credential dialog | T1056.002 - T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/ryanmrestivo/red-team/blob/1e53b7aa77717a22c9bd54facc64155a9a4c49fc/Exploitation-Tools/OffensiveCSharp/CredPhisher | 1 | 1 | N/A | N/A | 7 | 2 | 136 | 34 | 2024-10-18T12:12:38Z | 2021-04-12T00:00:03Z | 6264 |
| 813 | */creds-*/creds.zip* | .{0,1000}\/creds\-.{0,1000}\/creds\.zip.{0,1000} | offensive_tool_keyword | DefaultCreds-cheat-sheet | One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password | T1110.001 - T1110.003 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/ihebski/DefaultCreds-cheat-sheet | 1 | 1 | N/A | N/A | N/A | 10 | 6048 | 726 | 2025-04-15T13:13:19Z | 2021-01-01T19:02:36Z | 6268 |
| 814 | */crunch-wordlist/* | .{0,1000}\/crunch\-wordlist\/.{0,1000} | offensive_tool_keyword | crunch | Generate a dictionary file containing words with a minimum and maximum length | T1596 - T1596.001 | TA0043 | N/A | N/A | Credential Access | https://sourceforge.net/projects/crunch-wordlist/ | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 6298 |
| 815 | */cstealer.git* | .{0,1000}\/cstealer\.git.{0,1000} | offensive_tool_keyword | cstealer | stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python. | T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/can-kat/cstealer | 1 | 1 | N/A | N/A | 10 | N/A | 6322 | ||||
| 816 | */cstealer.py* | .{0,1000}\/cstealer\.py.{0,1000} | offensive_tool_keyword | cstealer | stealer discord token grabber, crypto wallet stealer, cookie stealer, password stealer, file stealer etc. app written in Python. | T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/can-kat/cstealer | 1 | 1 | N/A | N/A | 10 | N/A | 6323 | ||||
| 817 | */dafthack/MSOLSpray* | .{0,1000}\/dafthack\/MSOLSpray.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 1 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 6396 |
| 818 | */DanMcInerney/ridenum* | .{0,1000}\/DanMcInerney\/ridenum.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 0 | #linux | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 6400 |
| 819 | */DarkCoderSc/* | .{0,1000}\/DarkCoderSc\/.{0,1000} | offensive_tool_keyword | win-brute-logon | Bruteforce cracking tool for windows users | T1110 - T1110.001 - T1110.002 | TA0008 - TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/DarkCoderSc/win-brute-logon | 1 | 1 | N/A | N/A | N/A | 10 | 1138 | 191 | 2023-11-09T10:37:58Z | 2020-05-14T21:46:50Z | 6406 |
| 820 | */DCSyncer.git* | .{0,1000}\/DCSyncer\.git.{0,1000} | offensive_tool_keyword | DCSyncer | Perform DCSync operation | T1003.006 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/notsoshant/DCSyncer | 1 | 1 | N/A | N/A | 10 | 2 | 143 | 22 | 2024-11-05T20:03:27Z | 2020-06-06T17:20:22Z | 6472 |
| 821 | */DCSyncer/releases/download/* | .{0,1000}\/DCSyncer\/releases\/download\/.{0,1000} | offensive_tool_keyword | DCSyncer | Perform DCSync operation | T1003.006 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/notsoshant/DCSyncer | 1 | 1 | N/A | N/A | 10 | 2 | 143 | 22 | 2024-11-05T20:03:27Z | 2020-06-06T17:20:22Z | 6473 |
| 822 | */DCSyncer/tarball/* | .{0,1000}\/DCSyncer\/tarball\/.{0,1000} | offensive_tool_keyword | DCSyncer | Perform DCSync operation | T1003.006 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/notsoshant/DCSyncer | 1 | 1 | N/A | N/A | 10 | 2 | 143 | 22 | 2024-11-05T20:03:27Z | 2020-06-06T17:20:22Z | 6474 |
| 823 | */DCSyncer/zipball/* | .{0,1000}\/DCSyncer\/zipball\/.{0,1000} | offensive_tool_keyword | DCSyncer | Perform DCSync operation | T1003.006 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/notsoshant/DCSyncer | 1 | 1 | N/A | N/A | 10 | 2 | 143 | 22 | 2024-11-05T20:03:27Z | 2020-06-06T17:20:22Z | 6475 |
| 824 | */DeathStar/DeathStar.py* | .{0,1000}\/DeathStar\/DeathStar\.py.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 0 | #linux | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 6484 |
| 825 | */decipher_mremoteng.iml* | .{0,1000}\/decipher_mremoteng\.iml.{0,1000} | offensive_tool_keyword | mRemoteNG-Decrypt | Python script to decrypt passwords stored by mRemoteNG | T1555.003 - T1110.003 - T1003 - T1081 | TA0006 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/kmahyyg/mremoteng-decrypt | 1 | 1 | N/A | N/A | 8 | 1 | 83 | 21 | 2022-10-29T16:02:26Z | 2019-05-11T09:09:49Z | 6488 |
| 826 | */DecryptAutoLogon.exe* | .{0,1000}\/DecryptAutoLogon\.exe.{0,1000} | offensive_tool_keyword | DecryptAutoLogon | Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon | T1003.001 - T1555.003 - T1003.006 | TA0006 | N/A | N/A | Credential Access | https://github.com/securesean/DecryptAutoLogon | 1 | 1 | N/A | N/A | 10 | 3 | 218 | 32 | 2020-12-05T16:14:28Z | 2020-12-03T20:38:59Z | 6490 |
| 827 | */DecryptAutoLogon.git* | .{0,1000}\/DecryptAutoLogon\.git.{0,1000} | offensive_tool_keyword | DecryptAutoLogon | Command line tool to extract/decrypt the password that was stored in the LSA by SysInternals AutoLogon | T1003.001 - T1555.003 - T1003.006 | TA0006 | N/A | N/A | Credential Access | https://github.com/securesean/DecryptAutoLogon | 1 | 1 | N/A | N/A | 10 | 3 | 218 | 32 | 2020-12-05T16:14:28Z | 2020-12-03T20:38:59Z | 6491 |
| 828 | */decrypt-chrome-passwords* | .{0,1000}\/decrypt\-chrome\-passwords.{0,1000} | offensive_tool_keyword | decrypt-chrome-passwords | A simple program to decrypt chrome password saved on your machine. | T1555.003 - T1112 - T1056.001 | TA0006 - TA0009 - TA0040 | N/A | N/A | Credential Access | https://github.com/ohyicong/decrypt-chrome-passwords | 1 | 1 | N/A | N/A | 10 | 10 | 966 | 211 | 2024-07-31T14:08:55Z | 2020-12-28T15:11:12Z | 6492 |
| 829 | */decrypted.dmp* | .{0,1000}\/decrypted\.dmp.{0,1000} | offensive_tool_keyword | PPLBlade | Protected Process Dumper Tool that support obfuscating memory dump and transferring it on remote workstations without dropping it onto the disk. | T1003.001 - T1027.004 - T1560.001 - T1039 - T1570 | TA0006 - TA0005 - TA0010 - TA0003 | N/A | N/A | Credential Access | https://github.com/tastypepperoni/PPLBlade | 1 | 0 | N/A | N/A | 10 | 6 | 545 | 59 | 2023-08-30T07:59:51Z | 2023-08-29T19:36:04Z | 6493 |
| 830 | */decrypting-lsa-secrets.html* | .{0,1000}\/decrypting\-lsa\-secrets\.html.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 1 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 6494 |
| 831 | */decrypting-lsa-secrets.html* | .{0,1000}\/decrypting\-lsa\-secrets\.html.{0,1000} | offensive_tool_keyword | secretsdump | secretdump.py from impacket - https://github.com/fortra/impacket | T1003.003 | TA0006 | Operation Wocao | Black Basta - Rhysida - HAFNIUM - Threat Group-3390 - Dragonfly - FIN8 - Sandworm Team - menuPass - Magic Hound - ALLANITE | Credential Access | https://github.com/fortra/impacket | 1 | 0 | N/A | N/A | 10 | 10 | 14198 | 3681 | 2025-04-22T13:40:55Z | 2015-04-15T14:04:07Z | 6496 |
| 832 | */Decrypt-RDCMan.ps1* | .{0,1000}\/Decrypt\-RDCMan\.ps1.{0,1000} | offensive_tool_keyword | Decrypt-RDCMan | decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI | T1003 - T1552 - T1081 - T1027 | TA0006 - TA0008 - TA0005 | N/A | N/A | Credential Access | https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1 | 1 | 1 | N/A | N/A | 9 | 1 | 1 | 1 | 2016-12-01T14:06:24Z | 2017-11-22T23:18:39Z | 6497 |
| 833 | */DecryptRDCManager.git* | .{0,1000}\/DecryptRDCManager\.git.{0,1000} | offensive_tool_keyword | DecryptRDCManager | decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI | T1003 - T1552 - T1081 - T1027 | TA0006 - TA0008 - TA0005 | N/A | N/A | Credential Access | https://github.com/mez-0/DecryptRDCManager | 1 | 1 | N/A | N/A | 8 | 1 | 73 | 7 | 2020-09-29T10:12:58Z | 2020-09-29T08:53:46Z | 6498 |
| 834 | */DecryptTeamViewer.exe* | .{0,1000}\/DecryptTeamViewer\.exe.{0,1000} | offensive_tool_keyword | DecryptTeamViewer | Enumerate and decrypt TeamViewer credentials from Windows registry | T1552.001 - T1003 - T1119 - T1012 | TA0006 - TA0007 - TA0008 | N/A | N/A | Credential Access | https://github.com/V1V1/DecryptTeamViewer | 1 | 1 | N/A | N/A | 7 | 3 | 241 | 62 | 2021-12-05T09:19:56Z | 2020-02-07T07:50:47Z | 6500 |
| 835 | */DecryptTeamViewer.git* | .{0,1000}\/DecryptTeamViewer\.git.{0,1000} | offensive_tool_keyword | DecryptTeamViewer | Enumerate and decrypt TeamViewer credentials from Windows registry | T1552.001 - T1003 - T1119 - T1012 | TA0006 - TA0007 - TA0008 | N/A | N/A | Credential Access | https://github.com/V1V1/DecryptTeamViewer | 1 | 1 | N/A | N/A | 7 | 3 | 241 | 62 | 2021-12-05T09:19:56Z | 2020-02-07T07:50:47Z | 6501 |
| 836 | */DefaultCreds_db.json* | .{0,1000}\/DefaultCreds_db\.json.{0,1000} | offensive_tool_keyword | DefaultCreds-cheat-sheet | One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password | T1110.001 - T1110.003 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/ihebski/DefaultCreds-cheat-sheet | 1 | 1 | N/A | N/A | N/A | 10 | 6048 | 726 | 2025-04-15T13:13:19Z | 2021-01-01T19:02:36Z | 6508 |
| 837 | */DelegationBOF/* | .{0,1000}\/DelegationBOF\/.{0,1000} | offensive_tool_keyword | DelegationBOF | This tool uses LDAP to check a domain for known abusable Kerberos delegation settings. Currently. it supports RBCD. Constrained. Constrained w/Protocol Transition. and Unconstrained Delegation checks. | T1098 - T1214 - T1552 | TA0006 | N/A | N/A | Credential Access | https://github.com/IcebreakerSecurity/DelegationBOF | 1 | 1 | N/A | N/A | N/A | 10 | 141 | 23 | 2022-05-04T14:00:36Z | 2022-03-28T20:14:24Z | 6521 |
| 838 | */dementor.py* | .{0,1000}\/dementor\.py.{0,1000} | offensive_tool_keyword | NetNTLMtoSilverTicket | Obtaining NetNTLMv1 Challenge/Response authentication - cracking those to NTLM Hashes and using that NTLM Hash to sign a Kerberos Silver ticket. | T1110.001 - T1558.003 - T1558.004 | TA0006 - TA0008 - TA0002 | N/A | N/A | Credential Access | https://github.com/NotMedic/NetNTLMtoSilverTicket | 1 | 1 | N/A | N/A | 10 | 9 | 842 | 113 | 2021-07-26T15:16:20Z | 2019-01-14T15:32:27Z | 6525 |
| 839 | */dicassassin.7z* | .{0,1000}\/dicassassin\.7z.{0,1000} | offensive_tool_keyword | weakpass | Weakpass collection of tools for bruteforce and hashcracking | T1110 - T1201 | TA0006 - TA0002 | N/A | Black Basta | Credential Access | https://github.com/zzzteph/weakpass | 1 | 1 | N/A | N/A | 10 | 6 | 541 | 55 | 2025-04-08T19:50:48Z | 2021-08-29T13:07:37Z | 6571 |
| 840 | */dirbuster/* | .{0,1000}\/dirbuster\/.{0,1000} | offensive_tool_keyword | wordlists | package contains the rockyou.txt wordlist | T1110.001 | TA0006 | N/A | N/A | Credential Access | https://www.kali.org/tools/wordlists/ | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 6583 |
| 841 | */Disable_defender.py* | .{0,1000}\/Disable_defender\.py.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 1 | N/A | N/A | 10 | N/A | 6603 | ||||
| 842 | */DitExplorer.git* | .{0,1000}\/DitExplorer\.git.{0,1000} | offensive_tool_keyword | DitExplorer | Tool for viewing NTDS.dit | T1003.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/trustedsec/DitExplorer | 1 | 1 | N/A | N/A | 10 | 2 | 155 | 13 | 2025-03-14T13:02:44Z | 2025-02-12T15:54:04Z | 6619 |
| 843 | */DitExplorer/releases/download/* | .{0,1000}\/DitExplorer\/releases\/download\/.{0,1000} | offensive_tool_keyword | DitExplorer | Tool for viewing NTDS.dit | T1003.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/trustedsec/DitExplorer | 1 | 1 | N/A | N/A | 10 | 2 | 155 | 13 | 2025-03-14T13:02:44Z | 2025-02-12T15:54:04Z | 6620 |
| 844 | */DitExplorer/releases/tag/v* | .{0,1000}\/DitExplorer\/releases\/tag\/v.{0,1000} | offensive_tool_keyword | DitExplorer | Tool for viewing NTDS.dit | T1003.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/trustedsec/DitExplorer | 1 | 1 | N/A | N/A | 10 | 2 | 155 | 13 | 2025-03-14T13:02:44Z | 2025-02-12T15:54:04Z | 6621 |
| 845 | */DitExplorer/tarball/* | .{0,1000}\/DitExplorer\/tarball\/.{0,1000} | offensive_tool_keyword | DitExplorer | Tool for viewing NTDS.dit | T1003.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/trustedsec/DitExplorer | 1 | 1 | N/A | N/A | 10 | 2 | 155 | 13 | 2025-03-14T13:02:44Z | 2025-02-12T15:54:04Z | 6622 |
| 846 | */DitExplorer/zipball/* | .{0,1000}\/DitExplorer\/zipball\/.{0,1000} | offensive_tool_keyword | DitExplorer | Tool for viewing NTDS.dit | T1003.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/trustedsec/DitExplorer | 1 | 1 | N/A | N/A | 10 | 2 | 155 | 13 | 2025-03-14T13:02:44Z | 2025-02-12T15:54:04Z | 6623 |
| 847 | */dllinject.py* | .{0,1000}\/dllinject\.py.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 1 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 6640 |
| 848 | */dnsspoof.c* | .{0,1000}\/dnsspoof\.c.{0,1000} | offensive_tool_keyword | dsniff | password sniffer. handles FTP. Telnet. SMTP. HTTP. POP. poppass. NNTP. IMAP. SNMP. LDAP. Rlogin. RIP. OSPF. PPTP MS-CHAP. NFS. VRRP. YP/NIS. SOCKS. X11. CVS. IRC. AIM. ICQ. Napster. PostgreSQL. Meeting Maker. Citrix ICA. Symantec pcAnywhere. NAI Sniffer. Microsoft SMB. Oracle SQL*Net. Sybase and Microsoft SQL auth info. dsniff automatically detects and minimally parses each application protocol. only saving the interesting bits. and uses Berkeley DB as its output file format. only logging unique authentication attempts. full TCP/IP reassembly is provided by libnids(3) (likewise for the following tools as well). | T1110 - T1040 - T1074.001 - T1555.002 - T1555.003 | TA0001 - TA0002 - TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/tecknicaltom/dsniff | 1 | 0 | #linux | N/A | N/A | 3 | 208 | 47 | 2010-06-29T05:53:39Z | 2010-06-23T13:11:11Z | 6696 |
| 849 | */DomainPasswordSpray.git* | .{0,1000}\/DomainPasswordSpray\.git.{0,1000} | offensive_tool_keyword | DomainPasswordSpray | DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. | T1110.001 - T1110.003 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/dafthack/DomainPasswordSpray | 1 | 1 | N/A | N/A | 10 | 10 | 1865 | 388 | 2024-07-11T18:18:57Z | 2016-10-04T23:37:37Z | 6724 |
| 850 | */domcachedump.py* | .{0,1000}\/domcachedump\.py.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 1 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 6727 |
| 851 | */DonPAPI.git* | .{0,1000}\/DonPAPI\.git.{0,1000} | offensive_tool_keyword | donpapi | Dumping DPAPI credentials remotely | T1003.006 - T1021.001 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/login-securite/DonPAPI | 1 | 1 | N/A | N/A | N/A | 10 | 1110 | 130 | 2025-03-24T10:23:58Z | 2021-09-27T09:12:51Z | 6734 |
| 852 | */DonPAPI.py* | .{0,1000}\/DonPAPI\.py.{0,1000} | offensive_tool_keyword | donpapi | Dumping DPAPI credentials remotely | T1003.006 - T1021.001 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/login-securite/DonPAPI | 1 | 1 | N/A | N/A | N/A | 10 | 1110 | 130 | 2025-03-24T10:23:58Z | 2021-09-27T09:12:51Z | 6735 |
| 853 | */download/LsassDumping/* | .{0,1000}\/download\/LsassDumping\/.{0,1000} | offensive_tool_keyword | ShadowDumper | dump LSASS memory | T1003.001 - T1055 | TA0006 | N/A | N/A | Credential Access | https://github.com/Offensive-Panda/ShadowDumper | 1 | 1 | N/A | N/A | 10 | 6 | 521 | 83 | 2025-04-05T08:32:28Z | 2024-11-10T15:26:28Z | 6753 |
| 854 | */download/pcunlocker* | .{0,1000}\/download\/pcunlocker.{0,1000} | greyware_tool_keyword | pcunlocker | Reset and unlock forgotten Windows login password | T1078 | TA0005 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://www.pcunlocker.com/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 6754 |
| 855 | */dpat.py* | .{0,1000}\/dpat\.py.{0,1000} | offensive_tool_keyword | DPAT | Domain Password Audit Tool for Pentesters | T1003 - T1087 - T1110 - T1555 | TA0006 - TA0004 - TA0002 - TA0005 | N/A | N/A | Credential Access | https://github.com/clr2of8/DPAT | 1 | 0 | N/A | N/A | 10 | 10 | 954 | 156 | 2022-06-24T21:41:43Z | 2016-11-22T22:00:21Z | 6779 |
| 856 | */dploot.git* | .{0,1000}\/dploot\.git.{0,1000} | offensive_tool_keyword | dploot | DPAPI looting remotely in Python | T1003.006 - T1027 - T1110.004 | TA0006 - TA0007 - TA0010 | N/A | N/A | Credential Access | https://github.com/zblurx/dploot | 1 | 1 | N/A | N/A | 10 | 5 | 455 | 58 | 2025-04-09T08:17:14Z | 2022-05-24T11:05:21Z | 6782 |
| 857 | */DragonCastle.git* | .{0,1000}\/DragonCastle\.git.{0,1000} | offensive_tool_keyword | DragonCastle | A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process. | T1003 - T1547.005 - T1055 - T1557 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/mdsecactivebreach/DragonCastle | 1 | 1 | N/A | N/A | 10 | 3 | 298 | 38 | 2022-10-26T10:19:55Z | 2022-10-26T10:18:37Z | 6783 |
| 858 | */DragonCastle.pdb* | .{0,1000}\/DragonCastle\.pdb.{0,1000} | offensive_tool_keyword | DragonCastle | A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process. | T1003 - T1547.005 - T1055 - T1557 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/mdsecactivebreach/DragonCastle | 1 | 1 | N/A | N/A | 10 | 3 | 298 | 38 | 2022-10-26T10:19:55Z | 2022-10-26T10:18:37Z | 6784 |
| 859 | */dragoncastle.py* | .{0,1000}\/dragoncastle\.py.{0,1000} | offensive_tool_keyword | DragonCastle | A PoC that combines AutodialDLL Lateral Movement technique and SSP to scrape NTLM hashes from LSASS process. | T1003 - T1547.005 - T1055 - T1557 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/mdsecactivebreach/DragonCastle | 1 | 1 | N/A | N/A | 10 | 3 | 298 | 38 | 2022-10-26T10:19:55Z | 2022-10-26T10:18:37Z | 6785 |
| 860 | */DriverDump.exe* | .{0,1000}\/DriverDump\.exe.{0,1000} | offensive_tool_keyword | DriverDump | abusing the old process explorer driver to grab a privledged handle to lsass and then dump it | T1543 - T1548 - T1562 - T1003 - T1569 | TA0005 - TA0003 - TA0004 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/trustedsec/The_Shelf | 1 | 1 | N/A | N/A | 10 | 3 | 247 | 14 | 2024-11-25T19:33:34Z | 2024-05-22T14:31:52Z | 6790 |
| 861 | */dsniff.c* | .{0,1000}\/dsniff\.c.{0,1000} | offensive_tool_keyword | dsniff | password sniffer. handles FTP. Telnet. SMTP. HTTP. POP. poppass. NNTP. IMAP. SNMP. LDAP. Rlogin. RIP. OSPF. PPTP MS-CHAP. NFS. VRRP. YP/NIS. SOCKS. X11. CVS. IRC. AIM. ICQ. Napster. PostgreSQL. Meeting Maker. Citrix ICA. SymantecpcAnywhere. NAI Sniffer. Microsoft SMB. Oracle SQL*Net. Sybase and Microsoft SQL auth info. dsniff automatically detects and minimally parses each application protocol. only saving the interesting bits. and uses Berkeley DB as its output file format. only logging unique authentication attempts. full TCP/IP reassembly is provided by libnids(3) (likewise for the following tools as well). | T1110 - T1040 - T1074.001 - T1555.002 - T1555.003 | TA0001 - TA0002 - TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/tecknicaltom/dsniff | 1 | 0 | #linux | N/A | N/A | 3 | 208 | 47 | 2010-06-29T05:53:39Z | 2010-06-23T13:11:11Z | 6806 |
| 862 | */dsniff.services* | .{0,1000}\/dsniff\.services.{0,1000} | offensive_tool_keyword | dsniff | password sniffer. handles FTP. Telnet. SMTP. HTTP. POP. poppass. NNTP. IMAP. SNMP. LDAP. Rlogin. RIP. OSPF. PPTP MS-CHAP. NFS. VRRP. YP/NIS. SOCKS. X11. CVS. IRC. AIM. ICQ. Napster. PostgreSQL. Meeting Maker. Citrix ICA. Symantec pcAnywhere. NAI Sniffer. Microsoft SMB. Oracle SQL*Net. Sybase and Microsoft SQL auth info. dsniff automatically detects and minimally parses each application protocol. only saving the interesting bits. and uses Berkeley DB as its output file format. only logging unique authentication attempts. full TCP/IP reassembly is provided by libnids(3) (likewise for the following tools as well). | T1110 - T1040 - T1074.001 - T1555.002 - T1555.003 | TA0001 - TA0002 - TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/tecknicaltom/dsniff | 1 | 0 | #linux | N/A | N/A | 3 | 208 | 47 | 2010-06-29T05:53:39Z | 2010-06-23T13:11:11Z | 6807 |
| 863 | */DUBrute.git* | .{0,1000}\/DUBrute\.git.{0,1000} | offensive_tool_keyword | DUBrute | RDP Bruteforcer | T1110 | TA0006 | N/A | N/A | Credential Access | https://github.com/ch0sys/DUBrute | 1 | 1 | N/A | N/A | 10 | 1 | 37 | 28 | 2018-02-19T13:03:14Z | 2017-06-15T08:55:46Z | 6808 |
| 864 | */DumpAADSyncCreds.git* | .{0,1000}\/DumpAADSyncCreds\.git.{0,1000} | offensive_tool_keyword | DumpAADSyncCreds | C# implementation of Get-AADIntSyncCredentials from AADInternals which extracts Azure AD Connect credentials to AD and Azure AD from AAD connect database. | T1555 - T1110 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/Hagrid29/DumpAADSyncCreds | 1 | 1 | N/A | N/A | 10 | 1 | 39 | 3 | 2023-06-24T16:17:36Z | 2022-03-27T18:43:44Z | 6822 |
| 865 | */dumper2020.git* | .{0,1000}\/dumper2020\.git.{0,1000} | offensive_tool_keyword | dumper2020 | Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/gitjdm/dumper2020 | 1 | 1 | N/A | N/A | 10 | 1 | 76 | 5 | 2020-12-29T03:55:21Z | 2020-10-04T17:25:21Z | 6827 |
| 866 | */dumper2020_exe* | .{0,1000}\/dumper2020_exe.{0,1000} | offensive_tool_keyword | dumper2020 | Create a minidump of the LSASS process - attempts to neutralize all user-land API hooks before dumping LSASS | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/gitjdm/dumper2020 | 1 | 1 | N/A | N/A | 10 | 1 | 76 | 5 | 2020-12-29T03:55:21Z | 2020-10-04T17:25:21Z | 6828 |
| 867 | */dumpert.py* | .{0,1000}\/dumpert\.py.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 1 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 6830 |
| 868 | */DumpIt.exe* | .{0,1000}\/DumpIt\.exe.{0,1000} | offensive_tool_keyword | Forensike | Remotely dump NT hashes through Windows Crash dumps | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/bmarchev/Forensike | 1 | 1 | N/A | N/A | 10 | 1 | 27 | 3 | 2024-10-29T00:13:50Z | 2024-02-01T13:52:55Z | 6832 |
| 869 | */DumpLSASS.git* | .{0,1000}\/DumpLSASS\.git.{0,1000} | offensive_tool_keyword | DumpLSASS | Lsass dumping tool - 50 ways of dumping lsass | T1003.001 - T1055.001 - T1620 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/elementalsouls/DumpLSASS | 1 | 1 | N/A | N/A | 10 | 1 | 33 | 5 | 2024-02-27T11:25:11Z | 2023-04-09T12:11:10Z | 6833 |
| 870 | */Dump-Lsass.git* | .{0,1000}\/Dump\-Lsass\.git.{0,1000} | offensive_tool_keyword | impacket | Dump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems. | T1021 - T1047 - T1055.011 - T1003 | TA0002 - TA0005 - TA0006 | N/A | Dispossessor - Black Basta | Credential Access | https://github.com/kaluche/Dump-Lsass | 1 | 1 | N/A | N/A | 10 | 1 | 1 | 0 | 2019-11-14T18:15:26Z | 2019-11-20T20:26:27Z | 6834 |
| 871 | */dump-lsass.py* | .{0,1000}\/dump\-lsass\.py.{0,1000} | offensive_tool_keyword | impacket | Dump-lsass script using impacket - Automates the manual process of using wmiexec and procdump to dump Lsass and plaintext creds or hashes across a large number of systems. | T1021 - T1047 - T1055.011 - T1003 | TA0002 - TA0005 - TA0006 | N/A | Dispossessor - Black Basta | Credential Access | https://github.com/kaluche/Dump-Lsass | 1 | 1 | N/A | N/A | 10 | 1 | 1 | 0 | 2019-11-14T18:15:26Z | 2019-11-20T20:26:27Z | 6836 |
| 872 | */dumpmethod/*.py | .{0,1000}\/dumpmethod\/.{0,1000}\.py | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 1 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 6837 |
| 873 | */DumpNParse.exe* | .{0,1000}\/DumpNParse\.exe.{0,1000} | offensive_tool_keyword | DumpNParse | A Combination LSASS Dumper and LSASS Parser | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/icyguider/DumpNParse | 1 | 1 | N/A | N/A | 10 | 2 | 150 | 24 | 2021-11-21T14:25:24Z | 2021-11-21T14:18:42Z | 6838 |
| 874 | */DumpNParse.git* | .{0,1000}\/DumpNParse\.git.{0,1000} | offensive_tool_keyword | DumpNParse | A Combination LSASS Dumper and LSASS Parser | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/icyguider/DumpNParse | 1 | 1 | N/A | N/A | 10 | 2 | 150 | 24 | 2021-11-21T14:25:24Z | 2021-11-21T14:18:42Z | 6839 |
| 875 | */DumpS1.ps1* | .{0,1000}\/DumpS1\.ps1.{0,1000} | greyware_tool_keyword | SentinelAgent | dump a process with SentinelAgent.exe | T1003 - T1055 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://gist.github.com/adamsvoboda/8e248c6b7fb812af5d04daba141c867e | 1 | 0 | N/A | N/A | 8 | 7 | N/A | N/A | N/A | N/A | 6841 |
| 876 | */dumpSecrets.go* | .{0,1000}\/dumpSecrets\.go.{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 1 | N/A | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 6842 |
| 877 | */dumpsecrets_test.go* | .{0,1000}\/dumpsecrets_test\.go.{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 1 | N/A | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 6843 |
| 878 | */DumpShellcode/* | .{0,1000}\/DumpShellcode\/.{0,1000} | offensive_tool_keyword | PPLFault | Exploits a TOCTOU in Windows Code Integrity to achieve arbitrary code execution as WinTcb-Light then dump a specified process. | T1055 - T1078 - T1112 - T1553 - T1555 | TA0001 - TA0002 - TA0003 - TA0005 - TA0011 | N/A | N/A | Credential Access | https://github.com/gabriellandau/PPLFault | 1 | 1 | N/A | N/A | 10 | 6 | 525 | 82 | 2024-02-22T17:23:53Z | 2022-09-22T19:39:24Z | 6844 |
| 879 | */DumpSvc.exe* | .{0,1000}\/DumpSvc\.exe.{0,1000} | offensive_tool_keyword | PWDumpX | PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://packetstormsecurity.com/files/download/52580/PWDumpX.zip | 1 | 1 | N/A | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 6846 |
| 880 | */DumpThatLSASS.* | .{0,1000}\/DumpThatLSASS\..{0,1000} | offensive_tool_keyword | DumpThatLSASS | Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk | T1003 - T1055.011 - T1027 - T1564.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/peiga/DumpThatLSASS | 1 | 1 | N/A | N/A | 10 | 1 | 31 | 79 | 2022-09-24T22:39:04Z | 2022-09-24T22:41:19Z | 6847 |
| 881 | */DumpThatLSASS.git* | .{0,1000}\/DumpThatLSASS\.git.{0,1000} | offensive_tool_keyword | DumpThatLSASS | Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk | T1003 - T1055.011 - T1027 - T1564.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/peiga/DumpThatLSASS | 1 | 1 | N/A | N/A | 10 | 1 | 31 | 79 | 2022-09-24T22:39:04Z | 2022-09-24T22:41:19Z | 6848 |
| 882 | */DumpThatLSASS/* | .{0,1000}\/DumpThatLSASS\/.{0,1000} | offensive_tool_keyword | DumpThatLSASS | Dumping LSASS by Unhooking MiniDumpWriteDump by getting a fresh DbgHelp.dll copy from the disk | T1003 - T1055.011 - T1027 - T1564.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/peiga/DumpThatLSASS | 1 | 1 | N/A | N/A | 10 | 1 | 31 | 79 | 2022-09-24T22:39:04Z | 2022-09-24T22:41:19Z | 6849 |
| 883 | */dumpweb.log* | .{0,1000}\/dumpweb\.log.{0,1000} | offensive_tool_keyword | chromedump | ChromeDump is a small tool to dump all JavaScript and other ressources going through the browser | T1059.007 - T1114.001 - T1518.001 - T1552.002 | TA0005 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/g4l4drim/ChromeDump | 1 | 1 | #logfile #linux | N/A | N/A | 1 | 55 | 1 | 2024-10-12T14:07:36Z | 2023-01-26T20:44:06Z | 6850 |
| 884 | */dumpy.exe* | .{0,1000}\/dumpy\.exe.{0,1000} | offensive_tool_keyword | Dumpy | Reuse open handles to dynamically dump LSASS | T1003.001 - T1055.001 - T1083 | TA0006 | N/A | N/A | Credential Access | https://github.com/Kudaes/Dumpy | 1 | 1 | N/A | N/A | 10 | 3 | 243 | 24 | 2024-04-04T07:42:26Z | 2021-10-13T21:54:59Z | 6853 |
| 885 | */Dumpy.git* | .{0,1000}\/Dumpy\.git.{0,1000} | offensive_tool_keyword | Dumpy | Reuse open handles to dynamically dump LSASS | T1003.001 - T1055.001 - T1083 | TA0006 | N/A | N/A | Credential Access | https://github.com/Kudaes/Dumpy | 1 | 1 | N/A | N/A | 10 | 3 | 243 | 24 | 2024-04-04T07:42:26Z | 2021-10-13T21:54:59Z | 6854 |
| 886 | */EASSniper.git* | .{0,1000}\/EASSniper\.git.{0,1000} | offensive_tool_keyword | EASSniper | EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS) | T1110 - T1078.003 - T1087.002 - T1059.001 | TA0006 -TA0007 - TA0009 - TA0002 - TA0001 | N/A | N/A | Credential Access | https://github.com/fugawi/EASSniper | 1 | 1 | N/A | N/A | 10 | 1 | 5 | 4 | 2018-04-17T23:23:31Z | 2018-04-17T22:43:51Z | 6871 |
| 887 | */EASSniper.ps1* | .{0,1000}\/EASSniper\.ps1.{0,1000} | offensive_tool_keyword | EASSniper | EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS) | T1110 - T1078.003 - T1087.002 - T1059.001 | TA0006 -TA0007 - TA0009 - TA0002 - TA0001 | N/A | N/A | Credential Access | https://github.com/fugawi/EASSniper | 1 | 1 | N/A | N/A | 10 | 1 | 5 | 4 | 2018-04-17T23:23:31Z | 2018-04-17T22:43:51Z | 6872 |
| 888 | */EASSniper.ps1* | .{0,1000}\/EASSniper\.ps1.{0,1000} | offensive_tool_keyword | Omnispray | Modular Enumeration and Password Spraying Framework | T1110 - T1078.003 - T1087.002 - T1621 | TA0001 - TA0002 - TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xZDH/Omnispray | 1 | 1 | N/A | N/A | 10 | 2 | 118 | 19 | 2024-04-10T20:05:46Z | 2021-02-25T07:28:06Z | 6873 |
| 889 | */eas-valid-users.txt* | .{0,1000}\/eas\-valid\-users\.txt.{0,1000} | offensive_tool_keyword | EASSniper | EASSniper is a penetration testing tool for account enumeration and brute force attacks against Exchange Active Sync (EAS) | T1110 - T1078.003 - T1087.002 - T1059.001 | TA0006 -TA0007 - TA0009 - TA0002 - TA0001 | N/A | N/A | Credential Access | https://github.com/fugawi/EASSniper | 1 | 0 | #linux | N/A | 10 | 1 | 5 | 4 | 2018-04-17T23:23:31Z | 2018-04-17T22:43:51Z | 6874 |
| 890 | */enum_av.py* | .{0,1000}\/enum_av\.py.{0,1000} | offensive_tool_keyword | crackmapexec | A swiss army knife for pentesting networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 1 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 6955 |
| 891 | */ETWHash/* | .{0,1000}\/ETWHash\/.{0,1000} | offensive_tool_keyword | ETWHash | C# POC to extract NetNTLMv1/v2 hashes from ETW provider | T1556.001 | TA0009 | N/A | N/A | Credential Access | https://github.com/nettitude/ETWHash | 1 | 1 | N/A | N/A | N/A | 3 | 256 | 29 | 2023-05-10T06:45:06Z | 2023-04-26T15:53:01Z | 7046 |
| 892 | */EvilLsassTwin* | .{0,1000}\/EvilLsassTwin.{0,1000} | offensive_tool_keyword | EvilLsassTwin | Dumping lsass | T1003 - T1560.001 - T1022 - T1027.002 | TA0005 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin | 1 | 1 | N/A | N/A | 10 | 2 | 151 | 18 | 2024-12-23T05:06:31Z | 2022-09-13T12:42:13Z | 7080 |
| 893 | */EvilLsassTwin/* | .{0,1000}\/EvilLsassTwin\/.{0,1000} | offensive_tool_keyword | EvilLsassTwin | attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess. | T1003.001 - T1055 - T1093 | TA0006 - TA0005 - TA0002 | N/A | N/A | Credential Access | https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin | 1 | 1 | N/A | N/A | 9 | 2 | 151 | 18 | 2024-12-23T05:06:31Z | 2022-09-13T12:42:13Z | 7081 |
| 894 | */EvilTwinServer* | .{0,1000}\/EvilTwinServer.{0,1000} | offensive_tool_keyword | EvilLsassTwin | attempt to duplicate open handles to LSASS. If this fails it will obtain a handle to LSASS through the NtGetNextProcess function instead of OpenProcess/NtOpenProcess. | T1003.001 - T1055 - T1093 | TA0006 - TA0005 - TA0002 | N/A | N/A | Credential Access | https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin | 1 | 1 | N/A | N/A | 9 | 2 | 151 | 18 | 2024-12-23T05:06:31Z | 2022-09-13T12:42:13Z | 7094 |
| 895 | */exported_credentials.csv* | .{0,1000}\/exported_credentials\.csv.{0,1000} | offensive_tool_keyword | HEKATOMB | Hekatomb is a python script that connects to LDAP directory to retrieve all computers and users informations. Then it will download all DPAPI blob of all users from all computers and uses Domain backup keys to decrypt them | T1003 - T1555.002 - T1482 - T1087 | TA0006 - TA0005 - TA0007 | N/A | N/A | Credential Access | https://github.com/ProcessusT/HEKATOMB | 1 | 0 | #linux | N/A | 10 | 6 | 510 | 59 | 2024-07-31T19:05:30Z | 2022-09-09T15:07:15Z | 7149 |
| 896 | */extpassword.zip* | .{0,1000}\/extpassword\.zip.{0,1000} | offensive_tool_keyword | ExtPassword.exe | Nirsoft tool for Windows that allows you to recover passwords stored on external drive plugged to your computer | T1081 - T1003 - T1212 | TA0006 - TA0009 | N/A | LockBit | Credential Access | https://www.nirsoft.net/utils/external_drive_password_recovery.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7159 |
| 897 | */ExtractBitlockerKeys.git* | .{0,1000}\/ExtractBitlockerKeys\.git.{0,1000} | offensive_tool_keyword | ExtractBitlockerKeys | A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain. | T1003.002 - T1039 - T1087.002 | TA0006 - TA0007 - TA0009 | N/A | N/A | Credential Access | https://github.com/p0dalirius/ExtractBitlockerKeys | 1 | 1 | N/A | N/A | 10 | 4 | 368 | 54 | 2025-01-31T09:39:55Z | 2023-09-19T07:28:11Z | 7161 |
| 898 | */fakelogonscreen.exe* | .{0,1000}\/fakelogonscreen.{0,1000} | offensive_tool_keyword | fakelogonscreen | Fake Windows logon screen to steal passwords | T1056.002 - T1078 - T1110 - T1555 | TA0006 - TA0003 - TA0009 | N/A | N/A | Credential Access | https://github.com/bitsadmin/fakelogonscreen | 1 | 1 | N/A | N/A | 10 | 10 | 1325 | 236 | 2020-02-03T23:28:01Z | 2020-02-01T18:51:35Z | 7169 |
| 899 | */fakelogonscreen.git* | .{0,1000}\/fakelogonscreen\.git.{0,1000} | offensive_tool_keyword | fakelogonscreen | Fake Windows logon screen to steal passwords | T1056.002 - T1078 - T1110 - T1555 | TA0006 - TA0003 - TA0009 | N/A | N/A | Credential Access | https://github.com/bitsadmin/fakelogonscreen | 1 | 1 | N/A | N/A | 10 | 10 | 1325 | 236 | 2020-02-03T23:28:01Z | 2020-02-01T18:51:35Z | 7170 |
| 900 | */fakelogonscreen/releases/download/* | .{0,1000}\/fakelogonscreen\/releases\/download\/.{0,1000} | offensive_tool_keyword | fakelogonscreen | Fake Windows logon screen to steal passwords | T1056.002 - T1078 - T1110 - T1555 | TA0006 - TA0003 - TA0009 | N/A | N/A | Credential Access | https://github.com/bitsadmin/fakelogonscreen | 1 | 1 | N/A | N/A | 10 | 10 | 1325 | 236 | 2020-02-03T23:28:01Z | 2020-02-01T18:51:35Z | 7171 |
| 901 | */fakelogonscreen/tarball/* | .{0,1000}\/fakelogonscreen\/tarball\/.{0,1000} | offensive_tool_keyword | fakelogonscreen | Fake Windows logon screen to steal passwords | T1056.002 - T1078 - T1110 - T1555 | TA0006 - TA0003 - TA0009 | N/A | N/A | Credential Access | https://github.com/bitsadmin/fakelogonscreen | 1 | 1 | N/A | N/A | 10 | 10 | 1325 | 236 | 2020-02-03T23:28:01Z | 2020-02-01T18:51:35Z | 7172 |
| 902 | */fakelogonscreen/zipball/* | .{0,1000}\/fakelogonscreen\/zipball\/.{0,1000} | offensive_tool_keyword | fakelogonscreen | Fake Windows logon screen to steal passwords | T1056.002 - T1078 - T1110 - T1555 | TA0006 - TA0003 - TA0009 | N/A | N/A | Credential Access | https://github.com/bitsadmin/fakelogonscreen | 1 | 1 | N/A | N/A | 10 | 10 | 1325 | 236 | 2020-02-03T23:28:01Z | 2020-02-01T18:51:35Z | 7173 |
| 903 | */Farmer.git* | .{0,1000}\/Farmer\.git.{0,1000} | offensive_tool_keyword | Farmer | Farmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients. | T1557.001 - T1056.004 - T1078.003 | TA0006 - TA0004 - TA0001 | N/A | N/A | Credential Access | https://github.com/mdsecactivebreach/Farmer | 1 | 1 | N/A | N/A | 10 | 4 | 379 | 61 | 2021-04-28T15:27:24Z | 2021-02-22T14:32:29Z | 7176 |
| 904 | */fb_firstlast.7z* | .{0,1000}\/fb_firstlast\.7z.{0,1000} | offensive_tool_keyword | wordlists | Various wordlists FR & EN - Cracking French passwords | T1110.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/clem9669/wordlists | 1 | 1 | N/A | N/A | N/A | 3 | 280 | 45 | 2025-04-22T14:34:10Z | 2020-10-21T14:37:53Z | 7179 |
| 905 | */fb-brute.pl* | .{0,1000}\/fb\-brute\.pl.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://raw.githubusercontent.com/Sup3r-Us3r/scripts/master/fb-brute.pl | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 7180 |
| 906 | */fern-wifi-cracker/* | .{0,1000}\/fern\-wifi\-cracker\/.{0,1000} | offensive_tool_keyword | wordlists | package contains the rockyou.txt wordlist | T1110.001 | TA0006 | N/A | N/A | Credential Access | https://www.kali.org/tools/wordlists/ | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 7184 |
| 907 | */fgdump.git* | .{0,1000}\/fgdump\.git.{0,1000} | offensive_tool_keyword | fgdump | A utility for dumping passwords on Windows NT/2000/XP/2003 machines | T1003.001 - T1003.002 - T1077 - T1059 - T1035 - T1021.002 - T1562.001 | TA0002 - TA0003 - TA0004 - TA0005 - TA0007 - TA0008 | N/A | Volt Typhoon | Credential Access | https://github.com/ihamburglar/fgdump | 1 | 1 | N/A | N/A | 10 | 1 | 8 | 4 | 2012-01-14T19:05:42Z | 2015-10-11T17:08:47Z | 7189 |
| 908 | */find_domain.sh* | .{0,1000}\/find_domain\.sh.{0,1000} | offensive_tool_keyword | lyncsmash | a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations | T1190 - T1087 - T1110 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/nyxgeek/lyncsmash | 1 | 1 | N/A | N/A | 8 | 4 | 337 | 63 | 2024-10-01T11:22:01Z | 2016-05-20T04:32:41Z | 7202 |
| 909 | */firefox_decrypt.git* | .{0,1000}\/firefox_decrypt\.git.{0,1000} | offensive_tool_keyword | firefox_decrypt | Firefox Decrypt is a tool to extract passwords from Mozilla | T1555.003 - T1112 - T1056.001 | TA0006 - TA0009 - TA0040 | N/A | N/A | Credential Access | https://github.com/unode/firefox_decrypt | 1 | 1 | N/A | N/A | 10 | 10 | 2172 | 317 | 2024-11-08T13:52:34Z | 2014-01-17T13:25:02Z | 7210 |
| 910 | */firefox_decrypt.py* | .{0,1000}\/firefox_decrypt\.py.{0,1000} | offensive_tool_keyword | donpapi | Dumping DPAPI credentials remotely | T1003.006 - T1021.001 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/login-securite/DonPAPI | 1 | 1 | N/A | N/A | N/A | 10 | 1110 | 130 | 2025-03-24T10:23:58Z | 2021-09-27T09:12:51Z | 7211 |
| 911 | */Forensike.git* | .{0,1000}\/Forensike\.git.{0,1000} | offensive_tool_keyword | Forensike | Remotely dump NT hashes through Windows Crash dumps | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/bmarchev/Forensike | 1 | 1 | N/A | N/A | 10 | 1 | 27 | 3 | 2024-10-29T00:13:50Z | 2024-02-01T13:52:55Z | 7228 |
| 912 | */Forensike.ps1* | .{0,1000}\/Forensike\.ps1.{0,1000} | offensive_tool_keyword | Forensike | Remotely dump NT hashes through Windows Crash dumps | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/bmarchev/Forensike | 1 | 1 | N/A | N/A | 10 | 1 | 27 | 3 | 2024-10-29T00:13:50Z | 2024-02-01T13:52:55Z | 7229 |
| 913 | */forkatz.filters* | .{0,1000}\/forkatz\.filters.{0,1000} | offensive_tool_keyword | forkatz | credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege | T1003.002 - T1558.002 - T1055.001 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/Barbarisch/forkatz | 1 | 1 | N/A | N/A | 10 | 2 | 124 | 16 | 2021-05-22T00:23:04Z | 2021-05-21T18:42:22Z | 7235 |
| 914 | */forkatz.git* | .{0,1000}\/forkatz\.git.{0,1000} | offensive_tool_keyword | forkatz | credential dump using foreshaw technique using SeTrustedCredmanAccessPrivilege | T1003.002 - T1558.002 - T1055.001 | TA0006 - TA0004 | N/A | N/A | Credential Access | https://github.com/Barbarisch/forkatz | 1 | 1 | N/A | N/A | 10 | 2 | 124 | 16 | 2021-05-22T00:23:04Z | 2021-05-21T18:42:22Z | 7236 |
| 915 | */format:hashcat* | .{0,1000}\/format\:hashcat.{0,1000} | offensive_tool_keyword | Rubeus | Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpys Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUXs MakeMeEnterpriseAdmin project (GPL v3.0 license). Full credit goes to Benjamin and Vincent for working out the hard components of weaponization- without their prior work this project would not exist. | T1482 - T1558.001 - T1558.002 - T1558.003 - T1558.004 | TA0006 | N/A | Black Basta - Dispossessor - Conti - Diavol - Ryuk - Wizard Spider - APT29 - COZY BEAR | Credential Access | https://github.com/GhostPack/Rubeus | 1 | 0 | N/A | N/A | 10 | 10 | 4409 | 804 | 2025-04-17T10:11:57Z | 2018-09-23T23:59:03Z | 7240 |
| 916 | */FormThief.git* | .{0,1000}\/FormThief\.git.{0,1000} | offensive_tool_keyword | FormThief | Spoofing desktop login applications with WinForms and WPF | T1204.002 - T1056.004 - T1071.001 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/mlcsec/FormThief | 1 | 1 | N/A | N/A | 8 | 2 | 173 | 31 | 2024-02-19T22:40:09Z | 2024-02-19T22:34:07Z | 7241 |
| 917 | */Gemail-Hack.git* | .{0,1000}\/Gemail\-Hack\.git.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/Ha3MrX/Gemail-Hack | 1 | 1 | N/A | N/A | 7 | 10 | 1062 | 400 | 2024-01-17T15:12:44Z | 2018-04-19T13:48:41Z | 7346 |
| 918 | */getlsasrvaddr.exe* | .{0,1000}\/getlsasrvaddr\.exe.{0,1000} | offensive_tool_keyword | WCE | manipulates and extracts credentials through NTLM - Kerberos and Digest Authentication | T1003 - T1550.003 - T1555.003 - T1557.001 - T1557.002 - T1078 - T1212 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/returnvar/wce | 1 | 1 | N/A | N/A | 10 | 2 | 109 | 21 | 2019-09-15T05:26:40Z | 2019-01-10T04:10:48Z | 7372 |
| 919 | */Get-NetNTLM.git* | .{0,1000}\/Get\-NetNTLM\.git.{0,1000} | offensive_tool_keyword | Get-NetNTLM | Powershell module to get the NetNTLMv2 hash of the current user | T1110.003 - T1557.001 - T1040 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/elnerd/Get-NetNTLM | 1 | 1 | N/A | N/A | 7 | 1 | 93 | 18 | 2022-07-05T20:55:33Z | 2019-02-11T23:09:54Z | 7373 |
| 920 | */Get-NetNTLM.ps1* | .{0,1000}\/Get\-NetNTLM\.ps1.{0,1000} | offensive_tool_keyword | Get-NetNTLM | Powershell module to get the NetNTLMv2 hash of the current user | T1110.003 - T1557.001 - T1040 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/elnerd/Get-NetNTLM | 1 | 1 | N/A | N/A | 7 | 1 | 93 | 18 | 2022-07-05T20:55:33Z | 2019-02-11T23:09:54Z | 7374 |
| 921 | */get-shucking.php* | .{0,1000}\/get\-shucking\.php.{0,1000} | offensive_tool_keyword | ShuckNT | ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade - convert - dissect and shuck authentication token based on Data Encryption Standard (DES) | T1552.001 - T1555.003 - T1078.003 | TA0006 - TA0002 - TA0040 | N/A | N/A | Credential Access | https://github.com/yanncam/ShuckNT | 1 | 1 | N/A | N/A | 10 | 1 | 69 | 9 | 2024-10-18T10:45:49Z | 2023-01-27T07:52:47Z | 7384 |
| 922 | */GlobalUnProtect.git* | .{0,1000}\/GlobalUnProtect\.git.{0,1000} | offensive_tool_keyword | GlobalUnProtect | Decrypt GlobalProtect configuration and cookie files. | T1552 - T1003 - T1555 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/rotarydrone/GlobalUnProtect | 1 | 1 | N/A | N/A | 9 | 2 | 147 | 19 | 2024-09-10T20:19:24Z | 2024-09-04T15:31:52Z | 7526 |
| 923 | */gMSADumper* | .{0,1000}\/gMSADumper.{0,1000} | offensive_tool_keyword | gMSADumper | Lists who can read any gMSA password blobs and parses them if the current user has access. | T1552.001 - T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/micahvandeusen/gMSADumper | 1 | 1 | N/A | N/A | N/A | 3 | 274 | 51 | 2024-02-12T02:15:32Z | 2021-04-10T00:15:24Z | 7532 |
| 924 | */GMSAPasswordReader.git* | .{0,1000}\/GMSAPasswordReader\.git.{0,1000} | offensive_tool_keyword | GMSAPasswordReader | Reads the password blob from a GMSA account using LDAP and parses the values into hashes for re-use. | T1003.004 - T1078.003 - T1059.006 | TA0006 - TA0004 - TA0002 | N/A | N/A | Credential Access | https://github.com/rvazarkar/GMSAPasswordReader | 1 | 1 | N/A | N/A | 7 | 3 | 219 | 34 | 2023-02-17T14:37:40Z | 2020-01-19T19:06:20Z | 7537 |
| 925 | */GoAWSConsoleSpray.git* | .{0,1000}\/GoAWSConsoleSpray\.git.{0,1000} | offensive_tool_keyword | GoAWSConsoleSpray | brute-force AWS IAM Console credentials to discover valid logins for user accounts | T1078 - T1110 - T1187 - T1110.001 | TA0006 - TA0007 - TA0003 - TA0001 | N/A | N/A | Credential Access | https://github.com/WhiteOakSecurity/GoAWSConsoleSpray | 1 | 1 | N/A | N/A | 9 | 1 | 29 | 5 | 2022-06-15T18:16:21Z | 2022-06-15T18:11:39Z | 7538 |
| 926 | */gocrack.git* | .{0,1000}\/gocrack\.git.{0,1000} | offensive_tool_keyword | gocrack | GoCrack is a management frontend for password cracking tools written in Go | T1110 - T1021.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/mandiant/gocrack | 1 | 1 | N/A | N/A | 9 | 10 | 1233 | 242 | 2025-04-14T16:20:05Z | 2017-10-23T14:43:59Z | 7544 |
| 927 | */gocrack/.hashcat* | .{0,1000}\/gocrack\/\.hashcat.{0,1000} | offensive_tool_keyword | gocrack | GoCrack is a management frontend for password cracking tools written in Go | T1110 - T1021.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/mandiant/gocrack | 1 | 0 | #linux | N/A | 9 | 10 | 1233 | 242 | 2025-04-14T16:20:05Z | 2017-10-23T14:43:59Z | 7545 |
| 928 | */gocrack/server* | .{0,1000}\/gocrack\/server.{0,1000} | offensive_tool_keyword | gocrack | GoCrack is a management frontend for password cracking tools written in Go | T1110 - T1021.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/mandiant/gocrack | 1 | 0 | #linux | N/A | 9 | 10 | 1233 | 242 | 2025-04-14T16:20:05Z | 2017-10-23T14:43:59Z | 7546 |
| 929 | */gocrack_server* | .{0,1000}\/gocrack_server.{0,1000} | offensive_tool_keyword | gocrack | GoCrack is a management frontend for password cracking tools written in Go | T1110 - T1021.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/mandiant/gocrack | 1 | 0 | #linux | N/A | 9 | 10 | 1233 | 242 | 2025-04-14T16:20:05Z | 2017-10-23T14:43:59Z | 7547 |
| 930 | */gocrack_worker* | .{0,1000}\/gocrack_worker.{0,1000} | offensive_tool_keyword | gocrack | GoCrack is a management frontend for password cracking tools written in Go | T1110 - T1021.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/mandiant/gocrack | 1 | 0 | #linux | N/A | 9 | 10 | 1233 | 242 | 2025-04-14T16:20:05Z | 2017-10-23T14:43:59Z | 7548 |
| 931 | */gocrack-1.0.zip* | .{0,1000}\/gocrack\-1\.0\.zip.{0,1000} | offensive_tool_keyword | gocrack | GoCrack is a management frontend for password cracking tools written in Go | T1110 - T1021.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/mandiant/gocrack | 1 | 0 | #linux | N/A | 9 | 10 | 1233 | 242 | 2025-04-14T16:20:05Z | 2017-10-23T14:43:59Z | 7549 |
| 932 | */GoldenGMSA.git* | .{0,1000}\/GoldenGMSA\.git.{0,1000} | offensive_tool_keyword | GoldenGMSA | GolenGMSA tool for working with GMSA passwords | T1003.004 - T1078.003 - T1059.006 | TA0006 - TA0004 - TA0002 | N/A | N/A | Credential Access | https://github.com/Semperis/GoldenGMSA | 1 | 1 | N/A | N/A | 7 | 2 | 144 | 22 | 2024-04-11T07:51:57Z | 2022-02-03T10:32:05Z | 7567 |
| 933 | */go-lsass.exe* | .{0,1000}\/go\-lsass\.exe.{0,1000} | offensive_tool_keyword | go-lsass | dumping LSASS process remotely | T1003 - T1055 - T1021.005 | TA0006 - TA0008 - TA0009 | N/A | N/A | Credential Access | https://github.com/jfjallid/go-lsass | 1 | 1 | N/A | N/A | 9 | 1 | 38 | 5 | 2024-07-27T10:35:12Z | 2023-11-30T18:45:51Z | 7571 |
| 934 | */go-lsass.git* | .{0,1000}\/go\-lsass\.git.{0,1000} | offensive_tool_keyword | go-lsass | dumping LSASS process remotely | T1003 - T1055 - T1021.005 | TA0006 - TA0008 - TA0009 | N/A | N/A | Credential Access | https://github.com/jfjallid/go-lsass | 1 | 1 | N/A | N/A | 9 | 1 | 38 | 5 | 2024-07-27T10:35:12Z | 2023-11-30T18:45:51Z | 7572 |
| 935 | */go-lsass/releases* | .{0,1000}\/go\-lsass\/releases.{0,1000} | offensive_tool_keyword | go-lsass | dumping LSASS process remotely | T1003 - T1055 - T1021.005 | TA0006 - TA0008 - TA0009 | N/A | N/A | Credential Access | https://github.com/jfjallid/go-lsass | 1 | 1 | N/A | N/A | 9 | 1 | 38 | 5 | 2024-07-27T10:35:12Z | 2023-11-30T18:45:51Z | 7573 |
| 936 | */go-lsass-master.zip* | .{0,1000}\/go\-lsass\-master\.zip.{0,1000} | offensive_tool_keyword | go-lsass | dumping LSASS process remotely | T1003 - T1055 - T1021.005 | TA0006 - TA0008 - TA0009 | N/A | N/A | Credential Access | https://github.com/jfjallid/go-lsass | 1 | 1 | N/A | N/A | 9 | 1 | 38 | 5 | 2024-07-27T10:35:12Z | 2023-11-30T18:45:51Z | 7574 |
| 937 | */go-secdump.git* | .{0,1000}\/go\-secdump\.git.{0,1000} | offensive_tool_keyword | go-secdump | Tool to remotely dump secrets from the Windows registry | T1003.002 - T1012 - T1059.003 | TA0006 - TA0003 - TA0002 | N/A | N/A | Credential Access | https://github.com/jfjallid/go-secdump | 1 | 1 | N/A | N/A | 10 | 5 | 457 | 51 | 2025-02-21T19:16:11Z | 2023-02-23T17:02:50Z | 7590 |
| 938 | */gosecretsdump.* | .{0,1000}\/gosecretsdump\..{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 1 | N/A | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 7592 |
| 939 | */gosecretsdump/* | .{0,1000}\/gosecretsdump\/.{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 1 | N/A | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 7593 |
| 940 | */gosecretsdump_linux* | .{0,1000}\/gosecretsdump_linux.{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 1 | #linux | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 7594 |
| 941 | */gosecretsdump_mac* | .{0,1000}\/gosecretsdump_mac.{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 1 | N/A | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 7595 |
| 942 | */gosecretsdump_win* | .{0,1000}\/gosecretsdump_win.{0,1000} | offensive_tool_keyword | gosecretsdump | Dump ntds.dit really fast | T1003 | TA0006 | N/A | Lockbit - Black Basta | Credential Access | https://github.com/C-Sto/gosecretsdump | 1 | 1 | N/A | N/A | 10 | 4 | 391 | 50 | 2021-10-01T09:11:33Z | 2018-12-24T05:54:19Z | 7596 |
| 943 | */gpp-decrypt* | .{0,1000}\/gpp\-decrypt.{0,1000} | offensive_tool_keyword | gpp-decrypt | Decrypt the given Group Policy Preferences | T1552.002 - T1212 | TA0009 - TA0006 | N/A | N/A | Credential Access | https://gitlab.com/kalilinux/packages/gpp-decrypt | 1 | 1 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 7614 |
| 944 | */grabchrome.exe* | .{0,1000}\/grabchrome\.exe.{0,1000} | offensive_tool_keyword | GrabChrome | HelloKitty Grabber used by Dispossessor ransomware group | T1003 - T1555 - T1081 - T1552 | TA0006 | N/A | Dispossessor | Credential Access | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7616 |
| 945 | */gsecdump-*.exe* | .{0,1000}\/gsecdump\-.{0,1000}\.exe.{0,1000} | offensive_tool_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7641 |
| 946 | */gsecdump.exe* | .{0,1000}\/gsecdump\.exe.{0,1000} | offensive_tool_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 7642 |
| 947 | */HackBrowserData.git* | .{0,1000}\/HackBrowserData\.git.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 1 | N/A | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 7692 |
| 948 | */hack-browser-data-linux-386.zip* | .{0,1000}\/hack\-browser\-data\-linux\-386\.zip.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 1 | #linux | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 7693 |
| 949 | */hack-browser-data-linux-amd64.zip* | .{0,1000}\/hack\-browser\-data\-linux\-amd64\.zip.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 1 | #linux | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 7694 |
| 950 | */hack-browser-data-linux-arm.zip* | .{0,1000}\/hack\-browser\-data\-linux\-arm\.zip.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 1 | #linux | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 7695 |
| 951 | */hack-browser-data-linux-arm64.zip* | .{0,1000}\/hack\-browser\-data\-linux\-arm64\.zip.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 1 | #linux | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 7696 |
| 952 | */hack-browser-data-osx-64bit.zip* | .{0,1000}\/hack\-browser\-data\-osx\-64bit\.zip.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 1 | N/A | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 7697 |
| 953 | */hack-browser-data-windows-32bit.zip* | .{0,1000}\/hack\-browser\-data\-windows\-32bit\.zip.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 1 | N/A | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 7698 |
| 954 | */hack-browser-data-windows-64bit.zip* | .{0,1000}\/hack\-browser\-data\-windows\-64bit\.zip.{0,1000} | offensive_tool_keyword | HackBrowserData | Decrypt passwords/cookies/history/bookmarks from the browser | T1555.003 - T1552.001 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/moonD4rk/HackBrowserData | 1 | 1 | N/A | N/A | N/A | 10 | 12216 | 1656 | 2025-04-06T01:32:13Z | 2020-06-18T03:24:31Z | 7699 |
| 955 | */hashcat-rule.git* | .{0,1000}\/hashcat\-rule\.git.{0,1000} | offensive_tool_keyword | hashcat-rule | Rule for hashcat or john. Aiming to crack how people generate their password | T1110.002 - T1021.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/clem9669/hashcat-rule | 1 | 1 | #linux | N/A | 10 | 5 | 435 | 47 | 2024-09-02T20:14:15Z | 2020-03-06T17:20:40Z | 7727 |
| 956 | */hashcrack_com.rb* | .{0,1000}\/hashcrack_com\.rb.{0,1000} | offensive_tool_keyword | pwcrack-framework | Password Crack Framework | T1110 - T1003 - T1059 | TA0006 | N/A | N/A | Credential Access | https://github.com/L-codes/pwcrack-framework | 1 | 1 | N/A | N/A | 10 | 6 | 515 | 59 | 2024-02-25T13:08:56Z | 2018-07-01T08:33:55Z | 7728 |
| 957 | */hashcracking.rb* | .{0,1000}\/hashcracking\.rb.{0,1000} | offensive_tool_keyword | pwcrack-framework | Password Crack Framework | T1110 - T1003 - T1059 | TA0006 | N/A | N/A | Credential Access | https://github.com/L-codes/pwcrack-framework | 1 | 1 | N/A | N/A | 10 | 6 | 515 | 59 | 2024-02-25T13:08:56Z | 2018-07-01T08:33:55Z | 7729 |
| 958 | */hashesorg2019.gz* | .{0,1000}\/hashesorg2019\.gz.{0,1000} | offensive_tool_keyword | weakpass | Weakpass collection of tools for bruteforce and hashcracking | T1110 - T1201 | TA0006 - TA0002 | N/A | Black Basta | Credential Access | https://github.com/zzzteph/weakpass | 1 | 1 | N/A | N/A | 10 | 6 | 541 | 55 | 2025-04-08T19:50:48Z | 2021-08-29T13:07:37Z | 7731 |
| 959 | */hashview.py* | .{0,1000}\/hashview\.py.{0,1000} | offensive_tool_keyword | hashview | A web front-end for password cracking and analytics | T1110 - T1201 | TA0006 - TA0002 | N/A | N/A | Credential Access | https://github.com/hashview/hashview | 1 | 1 | N/A | N/A | 10 | 4 | 373 | 41 | 2025-02-20T18:23:25Z | 2020-11-23T19:21:06Z | 7733 |
| 960 | */httprelayserver.py* | .{0,1000}\/httprelayserver\.py.{0,1000} | offensive_tool_keyword | NtlmRelayToEWS | ntlmRelayToEWS is a tool for performing ntlm relay attacks on Exchange Web Services (EWS) | T1212 - T1557 - T1040 - T1078 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/Arno0x/NtlmRelayToEWS | 1 | 1 | N/A | N/A | 10 | 4 | 331 | 60 | 2018-01-15T12:48:02Z | 2017-10-13T18:00:50Z | 7917 |
| 961 | */hydra -* | .{0,1000}hydra\s\-.{0,1000} | offensive_tool_keyword | thc-hydra | Parallelized login cracker which supports numerous protocols to attack. | T1110.001 | TA0006 | N/A | ALLANITE - BERSERK BEAR | Credential Access | https://github.com/vanhauser-thc/thc-hydra | 1 | 0 | #linux | N/A | N/A | 10 | 10326 | 2137 | 2025-04-04T12:19:05Z | 2014-04-24T14:45:37Z | 7990 |
| 962 | */icebreaker.git* | .{0,1000}\/icebreaker\.git.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 1 | N/A | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 8005 |
| 963 | */icebreaker.py* | .{0,1000}\/icebreaker\.py.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 1 | N/A | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 8006 |
| 964 | */iepv.exe* | .{0,1000}\/iepv\.exe.{0,1000} | offensive_tool_keyword | IEPassView | IE PassView scans all Internet Explorer passwords in your system and display them on the main window. | T1555 - T1212 | TA0006 | N/A | BlackSuit - Royal - GoGoogle - XDSpy | Credential Access | https://www.nirsoft.net/utils/internet_explorer_password.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8015 |
| 965 | */ike-crack.* | .{0,1000}\/ike\-crack\..{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 1 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 8023 |
| 966 | */impacketfile.py* | .{0,1000}\/impacketfile\.py.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 1 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 8038 |
| 967 | */insta-bf.git* | .{0,1000}\/insta\-bf\.git.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/samsesh/insta-bf | 1 | 1 | N/A | N/A | 7 | 1 | 59 | 13 | 2024-04-23T02:47:28Z | 2020-11-20T22:22:48Z | 8094 |
| 968 | */instabf.py* | .{0,1000}\/instabf\.py.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/samsesh/insta-bf | 1 | 1 | N/A | N/A | 7 | 1 | 59 | 13 | 2024-04-23T02:47:28Z | 2020-11-20T22:22:48Z | 8095 |
| 969 | */instainsane.git* | .{0,1000}\/instainsane\.git.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/umeshshinde19/instainsane | 1 | 1 | N/A | N/A | 7 | 7 | 655 | 371 | 2024-02-11T10:29:05Z | 2018-12-02T22:48:11Z | 8097 |
| 970 | */instainsane.sh* | .{0,1000}\/instainsane\.sh.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/umeshshinde19/instainsane | 1 | 1 | N/A | N/A | 7 | 7 | 655 | 371 | 2024-02-11T10:29:05Z | 2018-12-02T22:48:11Z | 8098 |
| 971 | */install-sb.sh* | .{0,1000}\/install\-sb\.sh.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/samsesh/SocialBox-Termux | 1 | 1 | N/A | N/A | 7 | 10 | 3581 | 391 | 2024-09-02T19:15:22Z | 2019-03-28T18:07:05Z | 8102 |
| 972 | */insTof.py* | .{0,1000}\/insTof\.py.{0,1000} | offensive_tool_keyword | SocialBox-Termux | SocialBox is a Bruteforce Attack Framework Facebook - Gmail - Instagram - Twitter for termux on android | T1110.001 - T1110.003 - T1078.003 | TA0001 - TA0006 - TA0040 | N/A | N/A | Credential Access | https://github.com/samsesh/insta-bf | 1 | 1 | N/A | N/A | 7 | 1 | 59 | 13 | 2024-04-23T02:47:28Z | 2020-11-20T22:22:48Z | 8104 |
| 973 | */Invoke-CleverSpray.git* | .{0,1000}\/Invoke\-CleverSpray\.git.{0,1000} | offensive_tool_keyword | Invoke-CleverSpray | Password Spraying Script detecting current and previous passwords of Active Directory User | T1110.003 - T1110.001 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/wavestone-cdt/Invoke-CleverSpray | 1 | 1 | N/A | N/A | 10 | 1 | 65 | 11 | 2021-09-09T07:35:32Z | 2018-11-29T10:05:25Z | 8145 |
| 974 | */Invoke-RDPThief.git* | .{0,1000}\/Invoke\-RDPThief\.git.{0,1000} | offensive_tool_keyword | Invoke-RDPThief | perform process injection on the target process and inject RDPthief into the process in order to capture cleartext credentials | T1055 - T1056 - T1071 - T1110 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/The-Viper-One/Invoke-RDPThief | 1 | 1 | N/A | N/A | 10 | 1 | 62 | 8 | 2025-01-21T20:12:33Z | 2024-10-01T20:12:00Z | 8160 |
| 975 | */john -* | .{0,1000}\/john\s\-.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 0 | #linux | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 8241 |
| 976 | */john/run/*.pl* | .{0,1000}\/john\/run\/.{0,1000}\.pl.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 1 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 8243 |
| 977 | */john/run/*.py* | .{0,1000}\/john\/run\/.{0,1000}\.py.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 1 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 8244 |
| 978 | */JohnTheRipper* | .{0,1000}\/JohnTheRipper.{0,1000} | offensive_tool_keyword | JohnTheRipper | John the Ripper jumbo - advanced offline password cracker | T1110 - T1003.001 | TA0006 | N/A | Black Basta | Credential Access | https://github.com/openwall/john/ | 1 | 1 | N/A | N/A | N/A | 10 | 11216 | 2220 | 2025-04-22T11:24:06Z | 2011-12-16T19:43:47Z | 8246 |
| 979 | */KeeFarce.exe* | .{0,1000}\/KeeFarce\.exe.{0,1000} | offensive_tool_keyword | KeeFarce | Extracts passwords from a KeePass 2.x database directly from memory | T1003 - T1055 - T1059 | TA0006 | N/A | N/A | Credential Access | https://github.com/denandz/KeeFarce | 1 | 1 | N/A | N/A | 10 | 10 | 1009 | 132 | 2015-11-17T04:12:25Z | 2015-10-27T05:29:04Z | 8297 |
| 980 | */KeeFarce.git* | .{0,1000}\/KeeFarce\.git.{0,1000} | offensive_tool_keyword | KeeFarce | Extracts passwords from a KeePass 2.x database directly from memory | T1003 - T1055 - T1059 | TA0006 | N/A | N/A | Credential Access | https://github.com/denandz/KeeFarce | 1 | 1 | N/A | N/A | 10 | 10 | 1009 | 132 | 2015-11-17T04:12:25Z | 2015-10-27T05:29:04Z | 8298 |
| 981 | */KeeFarceDLL.dll* | .{0,1000}\/KeeFarceDLL\.dll.{0,1000} | offensive_tool_keyword | KeeFarce | Extracts passwords from a KeePass 2.x database directly from memory | T1003 - T1055 - T1059 | TA0006 | N/A | N/A | Credential Access | https://github.com/denandz/KeeFarce | 1 | 1 | N/A | N/A | 10 | 10 | 1009 | 132 | 2015-11-17T04:12:25Z | 2015-10-27T05:29:04Z | 8299 |
| 982 | */keepwn.core.* | .{0,1000}\/keepwn\.core.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 0 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 8303 |
| 983 | */KeePwn.git* | .{0,1000}\/KeePwn\.git.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 1 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 8304 |
| 984 | */KeePwn.py* | .{0,1000}\/KeePwn\.py.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 1 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 8305 |
| 985 | */keepwn.utils.* | .{0,1000}\/keepwn\.utils.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 0 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 8306 |
| 986 | */KeePwn/keepwn/* | .{0,1000}\/KeePwn\/keepwn\/.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 1 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 8307 |
| 987 | */KeePwn/tarball/* | .{0,1000}\/KeePwn\/tarball\/.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 1 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 8308 |
| 988 | */KeePwn/zipball/* | .{0,1000}\/KeePwn\/zipball\/.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 1 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 8309 |
| 989 | */KeePwn-0.3/* | .{0,1000}\/KeePwn\-0\.3\/.{0,1000} | offensive_tool_keyword | KeePwn | A python tool to automate KeePass discovery and secret extraction | T1555 - T1003 - T1114 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Orange-Cyberdefense/KeePwn | 1 | 0 | N/A | N/A | 10 | 5 | 486 | 47 | 2024-12-12T12:47:07Z | 2023-01-27T13:59:38Z | 8310 |
| 990 | */KeeTheft.exe* | .{0,1000}\/KeeTheft\.exe.{0,1000} | offensive_tool_keyword | Keethief | Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system. | T1003 - T1055 - T1059 - T1070 | TA0006 - TA0005 - TA0008 | N/A | EvilCorp* - APT20 | Credential Access | https://github.com/GhostPack/KeeThief | 1 | 1 | N/A | N/A | 10 | 10 | 944 | 154 | 2020-11-18T18:35:21Z | 2016-07-10T19:11:23Z | 8312 |
| 991 | */KeeThief.git* | .{0,1000}\/KeeThief\.git.{0,1000} | offensive_tool_keyword | Keethief | Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system. | T1003 - T1055 - T1059 - T1070 | TA0006 - TA0005 - TA0008 | N/A | EvilCorp* - APT20 | Credential Access | https://github.com/GhostPack/KeeThief | 1 | 1 | N/A | N/A | 10 | 10 | 944 | 154 | 2020-11-18T18:35:21Z | 2016-07-10T19:11:23Z | 8314 |
| 992 | */KeeThief.git* | .{0,1000}\/KeeThief\.git.{0,1000} | offensive_tool_keyword | KeeThiefSyscalls | Patch GhostPack/KeeThief for it to use DInvoke and syscalls | T1003.001 - T1558.002 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/Metro-Holografix/KeeThiefSyscalls | 1 | 1 | N/A | private github repo | 10 | N/A | 8315 | ||||
| 993 | */KeeThief.ps1* | .{0,1000}\/KeeThief\.ps1.{0,1000} | offensive_tool_keyword | Keethief | Allows for the extraction of KeePass 2.X key material from memory as well as the backdooring and enumeration of the KeePass trigger system. | T1003 - T1055 - T1059 - T1070 | TA0006 - TA0005 - TA0008 | N/A | EvilCorp* - APT20 | Credential Access | https://github.com/GhostPack/KeeThief | 1 | 1 | N/A | N/A | 10 | 10 | 944 | 154 | 2020-11-18T18:35:21Z | 2016-07-10T19:11:23Z | 8316 |
| 994 | */KerberOPSEC.git* | .{0,1000}\/KerberOPSEC\.git.{0,1000} | offensive_tool_keyword | KerberOPSEC | OPSEC safe Kerberoasting in C# | T1558.003 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/Luct0r/KerberOPSEC | 1 | 1 | N/A | N/A | 10 | 2 | 191 | 21 | 2022-06-14T18:10:25Z | 2022-01-07T17:20:40Z | 8327 |
| 995 | */kerberos.py* | .{0,1000}\/kerberos\.py.{0,1000} | offensive_tool_keyword | crackmapexec | protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 1 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 8328 |
| 996 | */kerberosticket.py* | .{0,1000}\/kerberosticket\.py.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 1 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 8330 |
| 997 | */kerbrute.git* | .{0,1000}\/kerbrute\.git.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 1 | N/A | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 8333 |
| 998 | */kerbrute.go* | .{0,1000}\/kerbrute\.go.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 1 | N/A | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 8334 |
| 999 | */kerbrute.py* | .{0,1000}\/kerbrute\.py.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 1 | N/A | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 8335 |
| 1000 | */kerbrute/* | .{0,1000}\/kerbrute\/.{0,1000} | offensive_tool_keyword | kerbrute | A tool to perform Kerberos pre-auth bruteforcing | T1110.003 - T1558.001 | TA0006 - TA0001 | N/A | N/A | Credential Access | https://github.com/ropnop/kerbrute | 1 | 1 | N/A | N/A | 10 | 10 | 2872 | 438 | 2024-08-20T10:56:06Z | 2019-02-03T18:21:17Z | 8336 |
| 1001 | */KeyCredentialLink.git* | .{0,1000}\/KeyCredentialLink\.git.{0,1000} | offensive_tool_keyword | KeyCredentialLink | Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute | T1098 - T1550 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/Leo4j/KeyCredentialLink | 1 | 1 | N/A | N/A | 10 | 1 | 21 | 3 | 2024-06-05T13:44:39Z | 2024-06-05T13:19:49Z | 8339 |
| 1002 | */KeyCredentialLink.ps1* | .{0,1000}\/KeyCredentialLink\.ps1.{0,1000} | offensive_tool_keyword | KeyCredentialLink | Add Shadow Credentials to a target object by editing their msDS-KeyCredentialLink attribute | T1098 - T1550 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/Leo4j/KeyCredentialLink | 1 | 1 | N/A | N/A | 10 | 1 | 21 | 3 | 2024-06-05T13:44:39Z | 2024-06-05T13:19:49Z | 8340 |
| 1003 | */Kill_protector.py* | .{0,1000}\/Kill_protector\.py.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 1 | N/A | N/A | 10 | N/A | 8357 | ||||
| 1004 | */knowsmore.cmd* | .{0,1000}\/knowsmore\.cmd.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 8382 |
| 1005 | */knowsmore.db* | .{0,1000}\/knowsmore\.db.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 0 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 8383 |
| 1006 | */knowsmore.git* | .{0,1000}\/knowsmore\.git.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 1 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 8384 |
| 1007 | */knowsmore.py* | .{0,1000}\/knowsmore\.py.{0,1000} | offensive_tool_keyword | knowsmore | KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes - BloodHound - NTDS and DCSync). | T1003 - T1098 - T1134 - T1484 - T1178 - T1078 | TA0006 - TA0008 - TA0003 - TA0011 - TA0005 | N/A | Black Basta | Credential Access | https://github.com/helviojunior/knowsmore | 1 | 1 | N/A | N/A | 10 | 3 | 223 | 32 | 2025-04-14T14:52:09Z | 2023-01-09T14:02:37Z | 8385 |
| 1008 | */label-date-lsass.dmp* | .{0,1000}\/label\-date\-lsass\.dmp.{0,1000} | offensive_tool_keyword | physmem2profit | Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/WithSecureLabs/physmem2profit | 1 | 0 | #content | N/A | 10 | 5 | 415 | 74 | 2022-07-27T03:33:59Z | 2020-02-14T08:34:27Z | 8419 |
| 1009 | */laps.py *--ldapserver* | .{0,1000}\/laps\.py\s.{0,1000}\-\-ldapserver.{0,1000} | offensive_tool_keyword | LAPSDumper | Dumping LAPS from Python | T1136.001 - T1112 - T1078.001 | TA0002 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/n00py/LAPSDumper | 1 | 0 | N/A | N/A | 10 | 3 | 267 | 35 | 2022-12-07T18:35:28Z | 2020-12-19T05:15:10Z | 8437 |
| 1010 | */laps.py *-u * -p * | .{0,1000}\/laps\.py\s.{0,1000}\-u\s.{0,1000}\s\-p\s.{0,1000} | offensive_tool_keyword | LAPSDumper | Dumping LAPS from Python | T1136.001 - T1112 - T1078.001 | TA0002 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/n00py/LAPSDumper | 1 | 0 | N/A | N/A | 10 | 3 | 267 | 35 | 2022-12-07T18:35:28Z | 2020-12-19T05:15:10Z | 8438 |
| 1011 | */LAPSDumper.git* | .{0,1000}\/LAPSDumper\.git.{0,1000} | offensive_tool_keyword | LAPSDumper | Dumping LAPS from Python | T1136.001 - T1112 - T1078.001 | TA0002 - TA0004 - TA0005 | N/A | N/A | Credential Access | https://github.com/n00py/LAPSDumper | 1 | 1 | N/A | N/A | 10 | 3 | 267 | 35 | 2022-12-07T18:35:28Z | 2020-12-19T05:15:10Z | 8441 |
| 1012 | */lastpass.py* | .{0,1000}\/lastpass\.py.{0,1000} | offensive_tool_keyword | donpapi | Dumping DPAPI credentials remotely | T1003.006 - T1021.001 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/login-securite/DonPAPI | 1 | 1 | N/A | N/A | N/A | 10 | 1110 | 130 | 2025-03-24T10:23:58Z | 2021-09-27T09:12:51Z | 8447 |
| 1013 | */LaZagne.git* | .{0,1000}\/LaZagne\.git.{0,1000} | offensive_tool_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 1 | N/A | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 8458 |
| 1014 | */laZagne.py* | .{0,1000}\/laZagne\.py.{0,1000} | offensive_tool_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 1 | N/A | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 8459 |
| 1015 | */LDAPWordlistHarvester.git* | .{0,1000}\/LDAPWordlistHarvester\.git.{0,1000} | offensive_tool_keyword | LDAPWordlistHarvester | A tool to generate a wordlist from the information present in LDAP in order to crack passwords of domain accounts. | T1210.001 - T1087.003 - T1110 | TA0001 - TA0006 - TA0007 | N/A | Black Basta | Credential Access | https://github.com/p0dalirius/LDAPWordlistHarvester | 1 | 1 | N/A | N/A | 5 | 4 | N/A | N/A | N/A | N/A | 8483 |
| 1016 | */legba.git* | .{0,1000}\/legba\.git.{0,1000} | offensive_tool_keyword | legba | A multiprotocol credentials bruteforcer / password sprayer and enumerator | T1110 - T1110.003 - T1110.001 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/evilsocket/legba | 1 | 1 | N/A | N/A | 10 | 10 | 1577 | 93 | 2025-03-01T15:42:29Z | 2023-10-23T15:44:06Z | 8487 |
| 1017 | */legba/target/release/legba* | .{0,1000}\/legba\/target\/release\/legba.{0,1000} | offensive_tool_keyword | legba | A multiprotocol credentials bruteforcer / password sprayer and enumerator | T1110 - T1110.003 - T1110.001 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/evilsocket/legba | 1 | 0 | #linux | N/A | 10 | 10 | 1577 | 93 | 2025-03-01T15:42:29Z | 2023-10-23T15:44:06Z | 8488 |
| 1018 | */LetMeowIn.git* | .{0,1000}\/LetMeowIn\.git.{0,1000} | offensive_tool_keyword | LetMeowIn | A sophisticated covert Windows-based credential dumper using C++ and MASM x64. | T1003 - T1055.011 - T1148 | TA0006 | N/A | N/A | Credential Access | https://github.com/Meowmycks/LetMeowIn | 1 | 1 | N/A | N/A | 10 | 5 | 401 | 70 | 2024-07-08T15:58:37Z | 2024-04-09T16:33:27Z | 8491 |
| 1019 | */lgandx/Responder* | .{0,1000}\/lgandx\/Responder.{0,1000} | offensive_tool_keyword | icebreaker | Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment | T1110.001 - T1110.003 - T1059.003 | TA0006 - TA0001 - TA0002 | N/A | N/A | Credential Access | https://github.com/DanMcInerney/icebreaker | 1 | 0 | #linux | N/A | 10 | 10 | 1190 | 163 | 2018-10-24T18:14:53Z | 2017-12-04T03:42:28Z | 8496 |
| 1020 | */lnkbomb.git* | .{0,1000}\/lnkbomb\.git.{0,1000} | offensive_tool_keyword | lnkbomb | Malicious shortcut generator for collecting NTLM hashes from insecure file shares. | T1023.003 - T1557.002 - T1046 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/dievus/lnkbomb | 1 | 1 | N/A | N/A | 10 | 4 | 327 | 58 | 2024-10-22T17:51:10Z | 2022-01-03T04:17:11Z | 8562 |
| 1021 | */lnkbomb.py* | .{0,1000}\/lnkbomb\.py.{0,1000} | offensive_tool_keyword | lnkbomb | Malicious shortcut generator for collecting NTLM hashes from insecure file shares. | T1023.003 - T1557.002 - T1046 | TA0008 - TA0006 | N/A | N/A | Credential Access | https://github.com/dievus/lnkbomb | 1 | 1 | N/A | N/A | 10 | 4 | 327 | 58 | 2024-10-22T17:51:10Z | 2022-01-03T04:17:11Z | 8563 |
| 1022 | */load_ssp.x64.exe* | .{0,1000}\/load_ssp\.x64\.exe.{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 1 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 8566 |
| 1023 | */localbrute-extra-mini.ps1* | .{0,1000}\/localbrute\-extra\-mini\.ps1.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Credential Access | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 1 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 8583 |
| 1024 | */loginAAD.ps1* | .{0,1000}\/loginAAD\.ps1.{0,1000} | offensive_tool_keyword | TeamFiltration | TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts | T1110 - T1087 - T1560.001 - T1592 - T1071 | TA0001 - TA0003 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Flangvik/TeamFiltration | 1 | 0 | N/A | N/A | 10 | 10 | 1132 | 128 | 2025-04-10T13:48:00Z | 2022-06-28T00:00:28Z | 8613 |
| 1025 | */login-securite/DonPAPI* | .{0,1000}\/login\-securite\/DonPAPI.{0,1000} | offensive_tool_keyword | donpapi | Dumping DPAPI credentials remotely | T1003.006 - T1021.001 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/login-securite/DonPAPI | 1 | 1 | N/A | N/A | N/A | 10 | 1110 | 130 | 2025-03-24T10:23:58Z | 2021-09-27T09:12:51Z | 8614 |
| 1026 | */logonuifox.dll* | .{0,1000}\/logonuifox\.dll.{0,1000} | offensive_tool_keyword | ThievingFox | collection of post-exploitation tools to gather credentials from various password managers | T1555 - T1003 - T1056 - T1070 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Slowerzs/ThievingFox | 1 | 1 | N/A | N/A | 10 | 6 | 535 | 65 | 2024-03-28T19:58:03Z | 2024-01-20T23:22:52Z | 8616 |
| 1027 | */lsadump.py* | .{0,1000}\/lsadump\.py.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 1 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 8638 |
| 1028 | */lsarelayx.git* | .{0,1000}\/lsarelayx\.git.{0,1000} | offensive_tool_keyword | lsarelayx | lsarelayx is system wide NTLM relay tool designed to relay incoming NTLM based authentication to the host it is running on | T1557.001 - T1187 - T1558 | TA0001 - TA0006 - TA0008 | N/A | N/A | Credential Access | https://github.com/CCob/lsarelayx | 1 | 1 | N/A | N/A | 10 | 6 | 562 | 69 | 2023-04-25T23:15:33Z | 2021-11-12T18:55:01Z | 8639 |
| 1029 | */lsasecrets.py* | .{0,1000}\/lsasecrets\.py.{0,1000} | offensive_tool_keyword | creddump7 | extracts various forms of credentials from Windows systems | T1003 - T1081 - T1040 - T1110 - T1555 | TA0006 - TA0009 | N/A | Sandworm | Credential Access | https://github.com/CiscoCXSecurity/creddump7 | 1 | 1 | N/A | N/A | 10 | 4 | 394 | 106 | 2020-10-02T13:25:16Z | 2014-06-24T13:18:38Z | 8640 |
| 1030 | */lsass.DMP* | .{0,1000}\/lsass\.DMP.{0,1000} | offensive_tool_keyword | pypykatz | Mimikatz implementation in pure Python | T1003.002 - T1055 - T1078 | TA0003 - TA0002 - TA0004 | N/A | Black Basta | Credential Access | https://github.com/skelsec/pypykatz | 1 | 1 | N/A | N/A | N/A | 10 | 2989 | 394 | 2025-02-27T20:37:07Z | 2018-05-25T22:21:20Z | 8641 |
| 1031 | */lsass.rar* | .{0,1000}\/lsass\.rar.{0,1000} | offensive_tool_keyword | MirrorDump | LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory | T1003 - T1055 - T1574 | TA0006 - TA0005 - TA0003 | N/A | N/A | Credential Access | https://github.com/CCob/MirrorDump | 1 | 1 | N/A | N/A | 10 | 3 | 265 | 58 | 2021-03-18T18:19:00Z | 2021-03-18T18:18:56Z | 8642 |
| 1032 | */lsass.zip* | .{0,1000}\/lsass\.zip.{0,1000} | offensive_tool_keyword | MirrorDump | LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory | T1003 - T1055 - T1574 | TA0006 - TA0005 - TA0003 | N/A | N/A | Credential Access | https://github.com/CCob/MirrorDump | 1 | 1 | N/A | N/A | 10 | 3 | 265 | 58 | 2021-03-18T18:19:00Z | 2021-03-18T18:18:56Z | 8643 |
| 1033 | */Lsass_Shtinkering.cpp* | .{0,1000}\/Lsass_Shtinkering\.cpp.{0,1000} | offensive_tool_keyword | NativeDump | Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!) | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/ricardojoserf/NativeDump | 1 | 1 | N/A | N/A | 10 | 6 | 586 | 86 | 2024-12-17T15:36:57Z | 2024-02-22T15:16:16Z | 8645 |
| 1034 | */Lsass_Shtinkering.exe* | .{0,1000}\/Lsass_Shtinkering\.exe.{0,1000} | offensive_tool_keyword | NativeDump | Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!) | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/ricardojoserf/NativeDump | 1 | 1 | N/A | N/A | 10 | 6 | 586 | 86 | 2024-12-17T15:36:57Z | 2024-02-22T15:16:16Z | 8646 |
| 1035 | */lsass64.exe* | .{0,1000}\/lsass64\.exe.{0,1000} | offensive_tool_keyword | lslsass | dump active logon session password hashes from the lsass process (old tool for vista and older) | T1003.001 | TA0006 | N/A | APT1 | Credential Access | https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8647 |
| 1036 | */LsassReflectDumping.git* | .{0,1000}\/LsassReflectDumping\.git.{0,1000} | offensive_tool_keyword | LsassReflectDumping | leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created - it utilizes MINIDUMP_CALLBACK_INFORMATION callbacks to generate a memory dump of the cloned process | T1003.001 - T1555.003 - T1077 | TA0006 | N/A | N/A | Credential Access | https://github.com/Offensive-Panda/LsassReflectDumping | 1 | 1 | N/A | N/A | 10 | 2 | 198 | 27 | 2024-10-19T08:16:13Z | 2024-10-17T14:57:30Z | 8649 |
| 1037 | */Lsass-Shtinkering.git* | .{0,1000}\/Lsass\-Shtinkering\.git.{0,1000} | offensive_tool_keyword | NativeDump | Dump lsass using only Native APIs by hand-crafting Minidump files (without MinidumpWriteDump!) | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/ricardojoserf/NativeDump | 1 | 1 | N/A | N/A | 10 | 6 | 586 | 86 | 2024-12-17T15:36:57Z | 2024-02-22T15:16:16Z | 8650 |
| 1038 | */LsassSilentProcessExit.git* | .{0,1000}\/LsassSilentProcessExit\.git.{0,1000} | offensive_tool_keyword | LsassSilentProcessExit | Command line interface to dump LSASS memory to disk via SilentProcessExit | T1003.001 - T1059.003 | TA0006 - TA0002 | N/A | N/A | Credential Access | https://github.com/deepinstinct/LsassSilentProcessExit | 1 | 1 | N/A | N/A | 10 | 5 | 445 | 61 | 2020-12-23T11:51:21Z | 2020-11-29T08:49:42Z | 8651 |
| 1039 | */Lsassx.git* | .{0,1000}\/Lsassx\.git.{0,1000} | offensive_tool_keyword | Lsassx | Dumping LSASS Evaded Endpoint Security Solutions | T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001 | TA0006 - TA0005 - TA0004 | N/A | N/A | Credential Access | https://github.com/yehia-mamdouh/Lsassx | 1 | 1 | N/A | N/A | 10 | 1 | 12 | 3 | 2025-02-15T16:41:38Z | 2025-02-15T16:36:27Z | 8652 |
| 1040 | */Lsassx.ps1* | .{0,1000}\/Lsassx\.ps1.{0,1000} | offensive_tool_keyword | Lsassx | Dumping LSASS Evaded Endpoint Security Solutions | T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001 | TA0006 - TA0005 - TA0004 | N/A | N/A | Credential Access | https://github.com/yehia-mamdouh/Lsassx | 1 | 1 | N/A | N/A | 10 | 1 | 12 | 3 | 2025-02-15T16:41:38Z | 2025-02-15T16:36:27Z | 8653 |
| 1041 | */Lsassx-OBF.ps1* | .{0,1000}\/Lsassx\-OBF\.ps1.{0,1000} | offensive_tool_keyword | Lsassx | Dumping LSASS Evaded Endpoint Security Solutions | T1003.001 - T1055.001 - T1203 - T1027 - T1070.004 - T1140 - T1564.001 | TA0006 - TA0005 - TA0004 | N/A | N/A | Credential Access | https://github.com/yehia-mamdouh/Lsassx | 1 | 1 | N/A | N/A | 10 | 1 | 12 | 3 | 2025-02-15T16:41:38Z | 2025-02-15T16:36:27Z | 8654 |
| 1042 | */lsassy* | .{0,1000}\/lsassy.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 1 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 8655 |
| 1043 | */lsassy/releases/download/* | .{0,1000}\/lsassy\/releases\/download\/.{0,1000} | offensive_tool_keyword | lsassy | Extract credentials from lsass remotely | T1003.001 - T1021.001 - T1021.002 - T1555.003 | TA0006 | N/A | N/A | Credential Access | https://github.com/login-securite/lsassy | 1 | 1 | N/A | N/A | 10 | 10 | 2105 | 251 | 2024-12-31T11:56:19Z | 2019-12-03T14:03:41Z | 8656 |
| 1044 | */lsa-whisperer-*.zip* | .{0,1000}\/lsa\-whisperer\-.{0,1000}\.zip.{0,1000} | greyware_tool_keyword | lsa-whisperer | Tools for interacting with authentication packages using their individual message protocols | T1556.002 - T1003.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/EvanMcBroom/lsa-whisperer | 1 | 1 | N/A | N/A | 6 | 4 | 316 | 29 | 2025-04-01T13:54:17Z | 2022-08-04T14:35:45Z | 8658 |
| 1045 | */lsa-whisperer.git* | .{0,1000}\/lsa\-whisperer\.git.{0,1000} | greyware_tool_keyword | lsa-whisperer | Tools for interacting with authentication packages using their individual message protocols | T1556.002 - T1003.001 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/EvanMcBroom/lsa-whisperer | 1 | 1 | N/A | N/A | 6 | 4 | 316 | 29 | 2025-04-01T13:54:17Z | 2022-08-04T14:35:45Z | 8659 |
| 1046 | */luna.log* | .{0,1000}\/luna\.log.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 0 | #linux | N/A | 10 | N/A | 8664 | ||||
| 1047 | */Luna-Grabber.git* | .{0,1000}\/Luna\-Grabber\.git.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 1 | N/A | N/A | 10 | N/A | 8665 | ||||
| 1048 | */Luna-Grabber/releases/download/* | .{0,1000}\/Luna\-Grabber\/releases\/download\/.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 1 | N/A | N/A | 10 | N/A | 8666 | ||||
| 1049 | */Luna-Grabber/tarball/* | .{0,1000}\/Luna\-Grabber\/tarball\/.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 1 | N/A | N/A | 10 | N/A | 8667 | ||||
| 1050 | */Luna-Grabber/zipball* | .{0,1000}\/Luna\-Grabber\/zipball.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 1 | N/A | N/A | 10 | N/A | 8668 | ||||
| 1051 | */Luna-Grabber-Injection/main* | .{0,1000}\/Luna\-Grabber\-Injection\/main.{0,1000} | offensive_tool_keyword | Luna-Grabber | discord token grabber made in python | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Smug246/Luna-Grabber | 1 | 1 | N/A | N/A | 10 | N/A | 8669 | ||||
| 1052 | */lyncsmash/* | .{0,1000}\/lyncsmash\/.{0,1000} | offensive_tool_keyword | lyncsmash | a collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations | T1190 - T1087 - T1110 | TA0006 - TA0007 | N/A | N/A | Credential Access | https://github.com/nyxgeek/lyncsmash | 1 | 1 | N/A | N/A | 8 | 4 | 337 | 63 | 2024-10-01T11:22:01Z | 2016-05-20T04:32:41Z | 8671 |
| 1053 | */LyncSniper.ps1* | .{0,1000}\/LyncSniper\.ps1.{0,1000} | offensive_tool_keyword | SprayingToolkit | Scripts to make password spraying attacks against Lync/S4B. OWA & O365 a lot quicker. less painful and more efficient | T1110 - T1078 - T1133 - T1061 - T1621 | TA0001 - TA0002 - TA0003 | N/A | N/A | Credential Access | https://github.com/byt3bl33d3r/SprayingToolkit | 1 | 1 | N/A | N/A | 10 | 10 | 1491 | 269 | 2022-10-17T01:01:57Z | 2018-09-13T09:52:11Z | 8672 |
| 1054 | */m365-fatigue.git* | .{0,1000}\/m365\-fatigue\.git.{0,1000} | offensive_tool_keyword | m365-fatigue | automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved. | T1110.001 - T1078.001 - T1556.004 | TA0006 - TA0008 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xB455/m365-fatigue | 1 | 1 | N/A | N/A | 10 | 1 | 77 | 7 | 2024-04-08T14:53:44Z | 2023-11-30T13:33:03Z | 8674 |
| 1055 | */m365-fatigue.py* | .{0,1000}\/m365\-fatigue\.py.{0,1000} | offensive_tool_keyword | m365-fatigue | automates the authentication process for Microsoft 365 by using the device code flow and Selenium for automated login. It keeps bombing the user with MFA requests and stores the access_token once the MFA was approved. | T1110.001 - T1078.001 - T1556.004 | TA0006 - TA0008 - TA0009 | N/A | N/A | Credential Access | https://github.com/0xB455/m365-fatigue | 1 | 1 | N/A | N/A | 10 | 1 | 77 | 7 | 2024-04-08T14:53:44Z | 2023-11-30T13:33:03Z | 8675 |
| 1056 | */mailpv.exe* | .{0,1000}\/mailpv\.exe.{0,1000} | offensive_tool_keyword | MailPassView | Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients | T1003 - T1081 - T1110 | TA0006 - TA0009 | N/A | BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy | Credential Access | https://www.nirsoft.net/utils/mailpv.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 8691 |
| 1057 | */MailSniper/* | .{0,1000}\/MailSniper\/.{0,1000} | offensive_tool_keyword | MailSniper | MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords. insider intel. network architecture information. etc.). It can be used as a non-administrative user to search their own email. or by an administrator to search the mailboxes of every user in a domain. | T1087.003 - T1110.003 - T1114.002 | TA0006 -TA0009 -TA0007 | N/A | Leafminer | Credential Access | https://github.com/dafthack/MailSniper/blob/master/MailSniper.ps1 | 1 | 1 | N/A | N/A | N/A | 10 | 3046 | 580 | 2024-08-07T18:11:58Z | 2016-09-08T00:36:51Z | 8694 |
| 1058 | */malDll.dll* | .{0,1000}\/malDll\.dll.{0,1000} | offensive_tool_keyword | EvilLsassTwin | Dumping lsass | T1003 - T1560.001 - T1022 - T1027.002 | TA0005 - TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/RePRGM/Nimperiments/tree/main/EvilLsassTwin | 1 | 1 | N/A | N/A | 10 | 2 | 151 | 18 | 2024-12-23T05:06:31Z | 2022-09-13T12:42:13Z | 8707 |
| 1059 | */malseclogon.* | .{0,1000}\/malseclogon\..{0,1000} | offensive_tool_keyword | nanodump | The swiss army knife of LSASS dumping. A flexible tool that creates a minidump of the LSASS process. | T1003.001 - T1003.003 | TA0006 | N/A | Dispossessor | Credential Access | https://github.com/fortra/nanodump | 1 | 1 | N/A | N/A | 10 | 10 | 1918 | 249 | 2024-09-17T22:58:11Z | 2021-11-10T18:28:15Z | 8712 |
| 1060 | */md5cracker.rb* | .{0,1000}\/md5cracker\.rb.{0,1000} | offensive_tool_keyword | pwcrack-framework | Password Crack Framework | T1110 - T1003 - T1059 | TA0006 | N/A | N/A | Credential Access | https://github.com/L-codes/pwcrack-framework | 1 | 1 | N/A | N/A | 10 | 6 | 515 | 59 | 2024-02-25T13:08:56Z | 2018-07-01T08:33:55Z | 8731 |
| 1061 | */memorydump.py* | .{0,1000}\/memorydump\.py.{0,1000} | offensive_tool_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 0 | N/A | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 8755 |
| 1062 | */mimidogz.git* | .{0,1000}\/mimidogz\.git.{0,1000} | offensive_tool_keyword | mimidogz | Rewrite of Invoke-Mimikatz.ps1 to avoid AV detection | T1055 - T1560.001 - T1110.001 - T1003 - T1071 | TA0005 - TA0040 - TA0006 | N/A | Dispossessor | Credential Access | https://github.com/projectb-temp/mimidogz | 1 | 1 | N/A | N/A | 10 | 1 | 0 | 0 | 2019-02-11T10:14:10Z | 2019-02-11T10:12:08Z | 8818 |
| 1063 | */mimikatz.git* | .{0,1000}\/mimikatz\.git.{0,1000} | offensive_tool_keyword | mimikatz | mimikatz github link | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Credential Access | https://github.com/gentilkiwi/mimikatz | 1 | 1 | N/A | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 8825 |
| 1064 | */mimikatz/archive/master.zip* | .{0,1000}\/mimikatz\/archive\/master\.zip.{0,1000} | offensive_tool_keyword | mimikatz | mimikatz archive link | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Credential Access | https://github.com/gentilkiwi/mimikatz | 1 | 1 | N/A | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 8829 |
| 1065 | */mimikatz/releases/* | .{0,1000}\/mimikatz\/releases\/.{0,1000} | offensive_tool_keyword | mimikatz | mimikatz archive link | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Credential Access | https://github.com/gentilkiwi/mimikatz | 1 | 1 | N/A | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 8830 |
| 1066 | */mimikatz/zipball/* | .{0,1000}\/mimikatz\/zipball\/.{0,1000} | offensive_tool_keyword | mimikatz | mimikatz archive link | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Credential Access | https://github.com/gentilkiwi/mimikatz | 1 | 1 | N/A | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 8831 |
| 1067 | */mimilib.dll* | .{0,1000}\/mimilib\.dll.{0,1000} | offensive_tool_keyword | Forensike | Remotely dump NT hashes through Windows Crash dumps | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/bmarchev/Forensike | 1 | 1 | N/A | N/A | 10 | 1 | 27 | 3 | 2024-10-29T00:13:50Z | 2024-02-01T13:52:55Z | 8838 |
| 1068 | */mimipenguin.sh* | .{0,1000}\/mimipenguin\.sh.{0,1000} | offensive_tool_keyword | mimipy | Tool to dump passwords from various processes memory | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/n1nj4sec/mimipy | 1 | 1 | N/A | N/A | 10 | 3 | 207 | 36 | 2017-04-30T00:09:15Z | 2017-04-05T21:06:32Z | 8845 |
| 1069 | */mimipenguin/releases/download/* | .{0,1000}\/mimipenguin\/releases\/download\/.{0,1000} | offensive_tool_keyword | mimipenguin | A tool to dump the login password from the current linux user | T1003.007 | TA0006 - TA0002 | N/A | TeamTNT | Credential Access | https://github.com/huntergregal/mimipenguin | 1 | 1 | #linux | N/A | 10 | 10 | 3940 | 644 | 2023-05-17T13:20:46Z | 2017-03-28T21:24:28Z | 8848 |
| 1070 | */mimipy.git* | .{0,1000}\/mimipy\.git.{0,1000} | offensive_tool_keyword | mimipy | Tool to dump passwords from various processes memory | T1003 | TA0006 | N/A | N/A | Credential Access | https://github.com/n1nj4sec/mimipy | 1 | 1 | N/A | N/A | 10 | 3 | 207 | 36 | 2017-04-30T00:09:15Z | 2017-04-05T21:06:32Z | 8849 |
| 1071 | */MiniDump.git* | .{0,1000}\/MiniDump\.git.{0,1000} | offensive_tool_keyword | MiniDump | C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/cube0x0/MiniDump | 1 | 1 | N/A | N/A | 10 | 3 | 291 | 48 | 2021-10-13T18:00:46Z | 2021-08-14T12:26:16Z | 8852 |
| 1072 | */MiniDump-main.zip* | .{0,1000}\/MiniDump\-main\.zip.{0,1000} | offensive_tool_keyword | MiniDump | C# implementation of mimikatz/pypykatz minidump functionality to get credentials from LSASS dumps | T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/cube0x0/MiniDump | 1 | 1 | N/A | N/A | 10 | 3 | 291 | 48 | 2021-10-13T18:00:46Z | 2021-08-14T12:26:16Z | 8855 |
| 1073 | */MirrorDump.exe* | .{0,1000}\/MirrorDump\.exe.{0,1000} | offensive_tool_keyword | MirrorDump | LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory | T1003 - T1055 - T1574 | TA0006 - TA0005 - TA0003 | N/A | N/A | Credential Access | https://github.com/CCob/MirrorDump | 1 | 1 | N/A | N/A | 10 | 3 | 265 | 58 | 2021-03-18T18:19:00Z | 2021-03-18T18:18:56Z | 8860 |
| 1074 | */MirrorDump.git* | .{0,1000}\/MirrorDump\.git.{0,1000} | offensive_tool_keyword | MirrorDump | LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory | T1003 - T1055 - T1574 | TA0006 - TA0005 - TA0003 | N/A | N/A | Credential Access | https://github.com/CCob/MirrorDump | 1 | 1 | N/A | N/A | 10 | 3 | 265 | 58 | 2021-03-18T18:19:00Z | 2021-03-18T18:18:56Z | 8861 |
| 1075 | */mobaxterm.rb* | .{0,1000}\/mobaxterm\.rb.{0,1000} | offensive_tool_keyword | pwcrack-framework | Password Crack Framework | T1110 - T1003 - T1059 | TA0006 | N/A | N/A | Credential Access | https://github.com/L-codes/pwcrack-framework | 1 | 0 | #linux | N/A | 10 | 6 | 515 | 59 | 2024-02-25T13:08:56Z | 2018-07-01T08:33:55Z | 8872 |
| 1076 | */mRemoteNG-Decrypt* | .{0,1000}\/mRemoteNG\-Decrypt.{0,1000} | offensive_tool_keyword | mRemoteNG-Decrypt | Python script to decrypt passwords stored by mRemoteNG | T1555.003 - T1110.003 - T1003 - T1081 | TA0006 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/haseebT/mRemoteNG-Decrypt | 1 | 1 | N/A | N/A | 8 | 2 | 146 | 42 | 2023-07-06T16:15:20Z | 2019-05-27T05:25:57Z | 8909 |
| 1077 | */mremoteng-decrypt.git* | .{0,1000}\/mremoteng\-decrypt\.git.{0,1000} | offensive_tool_keyword | mRemoteNG-Decrypt | Python script to decrypt passwords stored by mRemoteNG | T1555.003 - T1110.003 - T1003 - T1081 | TA0006 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/kmahyyg/mremoteng-decrypt | 1 | 1 | N/A | N/A | 8 | 1 | 83 | 21 | 2022-10-29T16:02:26Z | 2019-05-11T09:09:49Z | 8910 |
| 1078 | */mremoteng-decrypt/releases/download/* | .{0,1000}\/mremoteng\-decrypt\/releases\/download\/.{0,1000} | offensive_tool_keyword | mRemoteNG-Decrypt | Python script to decrypt passwords stored by mRemoteNG | T1555.003 - T1110.003 - T1003 - T1081 | TA0006 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/kmahyyg/mremoteng-decrypt | 1 | 1 | N/A | N/A | 8 | 1 | 83 | 21 | 2022-10-29T16:02:26Z | 2019-05-11T09:09:49Z | 8911 |
| 1079 | */mremoteng-decrypt/tarball/* | .{0,1000}\/mremoteng\-decrypt\/tarball\/.{0,1000} | offensive_tool_keyword | mRemoteNG-Decrypt | Python script to decrypt passwords stored by mRemoteNG | T1555.003 - T1110.003 - T1003 - T1081 | TA0006 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/kmahyyg/mremoteng-decrypt | 1 | 1 | N/A | N/A | 8 | 1 | 83 | 21 | 2022-10-29T16:02:26Z | 2019-05-11T09:09:49Z | 8912 |
| 1080 | */mremoteng-decrypt/zipball/* | .{0,1000}\/mremoteng\-decrypt\/zipball\/.{0,1000} | offensive_tool_keyword | mRemoteNG-Decrypt | Python script to decrypt passwords stored by mRemoteNG | T1555.003 - T1110.003 - T1003 - T1081 | TA0006 - TA0009 - TA0011 | N/A | N/A | Credential Access | https://github.com/kmahyyg/mremoteng-decrypt | 1 | 1 | N/A | N/A | 8 | 1 | 83 | 21 | 2022-10-29T16:02:26Z | 2019-05-11T09:09:49Z | 8913 |
| 1081 | */MSOLSpray* | .{0,1000}\/MSOLSpray.{0,1000} | offensive_tool_keyword | MSOLSpray | This module will perform password spraying against Microsoft Online accounts (Azure/O365) | T1110.003 - T1553.003 - T1621 | TA0001 - TA0006 | N/A | N/A | Credential Access | https://github.com/dafthack/MSOLSpray | 1 | 1 | N/A | network exploitation tool | 10 | 10 | 964 | 174 | 2024-03-19T11:03:06Z | 2020-03-16T13:38:22Z | 8941 |
| 1082 | */MSSprinkler.git* | .{0,1000}\/MSSprinkler\.git.{0,1000} | offensive_tool_keyword | MSSprinkler | password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach | T1110.003 - T1110.001 | TA0006 - TA0007 - TA0008 | N/A | N/A | Credential Access | https://github.com/TheresAFewConors/MSSprinkler | 1 | 1 | N/A | N/A | 9 | 1 | 74 | 7 | 2025-02-25T13:32:41Z | 2024-09-15T09:54:53Z | 8943 |
| 1083 | */mssprinkler.ps1* | .{0,1000}\/mssprinkler\.ps1.{0,1000} | offensive_tool_keyword | MSSprinkler | password spraying utility for organizations to test their M365 accounts from an external perspective. It employs a 'low-and-slow' approach | T1110.003 - T1110.001 | TA0006 - TA0007 - TA0008 | N/A | N/A | Credential Access | https://github.com/TheresAFewConors/MSSprinkler | 1 | 1 | N/A | N/A | 9 | 1 | 74 | 7 | 2025-02-25T13:32:41Z | 2024-09-15T09:54:53Z | 8944 |
| 1084 | */mssqlexec.py* | .{0,1000}\/mssqlexec\.py.{0,1000} | offensive_tool_keyword | crackmapexec | protocol scripts from crackmapexec. CrackMapExec or CME is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct Lateral Movement through targeted networks | T1087.002 - T1110 - T1110.001 - T1110.003 - T1059.001 - T1083 - T1112 - T1135 - T1003.002 - T1003.003 - T1003.004 - T1201 - T1069.002 - T1018 - T1053.002 - T1082 - T1016 - T1049 - T1550.002 - T1047 | TA0002 - TA0006 - TA0007 | N/A | APT39 - Dragonfly - FIN7 - MuddyWater - ENERGETIC BEAR - EMBER BEAR - BERSERK BEAR - Black Basta | Credential Access | https://github.com/Porchetta-Industries/CrackMapExec | 1 | 1 | N/A | N/A | 10 | 10 | 8690 | 1667 | 2023-12-06T17:09:42Z | 2015-08-14T14:11:55Z | 8952 |
| 1085 | */mstscfox.dll* | .{0,1000}\/mstscfox\.dll.{0,1000} | offensive_tool_keyword | ThievingFox | collection of post-exploitation tools to gather credentials from various password managers | T1555 - T1003 - T1056 - T1070 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Slowerzs/ThievingFox | 1 | 1 | N/A | N/A | 10 | 6 | 535 | 65 | 2024-03-28T19:58:03Z | 2024-01-20T23:22:52Z | 8961 |
| 1086 | */MultiDump.exe* | .{0,1000}\/MultiDump\.exe.{0,1000} | offensive_tool_keyword | DumpLSASS | Lsass dumping tool - 50 ways of dumping lsass | T1003.001 - T1055.001 - T1620 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/elementalsouls/DumpLSASS | 1 | 1 | N/A | N/A | 10 | 1 | 33 | 5 | 2024-02-27T11:25:11Z | 2023-04-09T12:11:10Z | 8964 |
| 1087 | */MultiDump.exe* | .{0,1000}\/MultiDump\.exe.{0,1000} | offensive_tool_keyword | MultiDump | MultiDump is a post-exploitation tool for dumping and extracting LSASS memory discreetly | T1003 - T1564.002 | TA0005 - TA0006 | N/A | N/A | Credential Access | https://github.com/Xre0uS/MultiDump | 1 | 1 | N/A | N/A | 10 | 6 | 510 | 66 | 2025-03-28T10:40:27Z | 2024-02-02T05:56:29Z | 8965 |
| The file is too large to be shown. View Raw |