mirror of
https://github.com/mthcht/ThreatHunting-Keywords
synced 2026-06-08 16:12:28 +00:00
755048bf5e
very few additions and some corrections
1.8 MiB
1.8 MiB
| 1 | keyword | metadata_keyword_regex | metadata_keyword_type | metadata_tool | metadata_description | metadata_tool_techniques | metadata_tool_tactics | metadata_malwares_name | metadata_groups_name | metadata_category | metadata_link | metadata_enable_endpoint_detection | metadata_enable_proxy_detection | metadata_tags | metadata_comment | metadata_severity_score | metadata_popularity_score | metadata_github_stars | metadata_github_forks | metadata_github_updated_at | metadata_github_created_at | metadata_entry_id |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2 | * - Sensitive Accounts.csv* | .{0,1000}\s\-\sSensitive\sAccounts\.csv.{0,1000} | offensive_tool_keyword | ACLight | A tool for advanced discovery of Privileged Accounts - including Shadow Admins. | T1087 - T1003 - T1208 | TA0001 - TA0006 - TA0008 | N/A | N/A | Discovery | https://github.com/cyberark/ACLight | 1 | 0 | N/A | AD Enumeration | 7 | 9 | 801 | 146 | 2019-09-09T06:48:45Z | 2017-05-17T09:29:41Z | 12 |
| 3 | * - ShadowSpray* | .{0,1000}\s\-\sShadowSpray.{0,1000} | offensive_tool_keyword | ShadowSpray | A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain. | T1110.003 - T1098 - T1059 - T1075 | TA0001 - TA0008 - TA0009 | N/A | Black Basta | Discovery | https://github.com/ShorSec/ShadowSpray | 1 | 0 | N/A | N/A | 7 | 5 | 459 | 80 | 2022-10-14T13:36:51Z | 2022-10-10T08:34:07Z | 13 |
| 4 | * /c sc query WinDefend* | .{0,1000}\s\/c\ssc\squery\sWinDefend.{0,1000} | greyware_tool_keyword | sc | Get information about Windows Defender service | T1518.001 - T1049 | TA0007 - TA0009 | N/A | Snatch | Discovery | https://thedfirreport.com/2023/02/06/collect-exfiltrate-sleep-repeat/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 44 |
| 5 | * /config:netscan.xml * | .{0,1000}\s\/config\:netscan\.xml\s.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 51 |
| 6 | * --> GetWindowsAnti-VirusSoftware* | .{0,1000}\s\-\-\>\sGetWindowsAnti\-VirusSoftware.{0,1000} | offensive_tool_keyword | SharpAVKB | Windows Antivirus Comparison and Patch Number Comparison | T1082 - T1518 - T1083 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpAVKB | 1 | 0 | #content | N/A | 4 | 1 | 58 | 24 | 2019-10-28T06:50:30Z | 2019-10-14T12:44:22Z | 147 |
| 7 | * --> GetWindowsKernelExploitsKB* | .{0,1000}\s\-\-\>\sGetWindowsKernelExploitsKB.{0,1000} | offensive_tool_keyword | SharpAVKB | Windows Antivirus Comparison and Patch Number Comparison | T1082 - T1518 - T1083 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpAVKB | 1 | 0 | #content | N/A | 4 | 1 | 58 | 24 | 2019-10-28T06:50:30Z | 2019-10-14T12:44:22Z | 148 |
| 8 | * aad3b435b51404eeaad3b435b51404ee* | .{0,1000}\saad3b435b51404eeaad3b435b51404ee.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 176 |
| 9 | * ADAudit.ps1* | .{0,1000}\sADAudit\.ps1.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 200 |
| 10 | * adaudit.ps1* | .{0,1000}\sadaudit\.ps1.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 201 |
| 11 | * ADcheck.py* | .{0,1000}\sADcheck\.py.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 0 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 202 |
| 12 | * ADCollector.exe* | .{0,1000}\sADCollector\.exe.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 0 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 203 |
| 13 | * --adcs --filter * --ntaccount * --enroll * | .{0,1000}\s\-\-adcs\s\-\-filter\s.{0,1000}\s\-\-ntaccount\s.{0,1000}\s\-\-enroll\s.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 204 |
| 14 | * --adcs --old-bloodhound * | .{0,1000}\s\-\-adcs\s\-\-old\-bloodhound\s.{0,1000} | offensive_tool_keyword | RustHound | Active Directory data collector for BloodHound written in Rust | T1087.002 - T1018 - T1059.003 | TA0007 - TA0001 - TA0002 | N/A | N/A | Discovery | https://github.com/OPENCYBER-FR/RustHound | 1 | 0 | N/A | AD Enumeration | 9 | 10 | 1013 | 98 | 2024-10-21T18:58:20Z | 2022-10-12T05:54:35Z | 205 |
| 15 | * ADeleg.exe* | .{0,1000}\sADeleg\.exe.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 224 |
| 16 | * adhunt.py * | .{0,1000}\sadhunt\.py\s.{0,1000} | offensive_tool_keyword | adhunt | Tool for exploiting Active Directory Enviroments - enumeration | T1018 - T1087 - T1087.002 - T1069 - T1069.002 | TA0007 - TA0003 - TA0001 | N/A | N/A | Discovery | https://github.com/karendm/ADHunt | 1 | 0 | N/A | AD Enumeration | 7 | 1 | 46 | 10 | 2023-08-10T18:55:39Z | 2023-06-20T13:24:10Z | 229 |
| 17 | * adPEAS.ps1* | .{0,1000}\sadPEAS\.ps1.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 235 |
| 18 | * adPEAS_DomainPolicy.Sys* | .{0,1000}\sadPEAS_DomainPolicy\.Sys.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 236 |
| 19 | * adPEAS_out.txt* | .{0,1000}\sadPEAS_out\.txt.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 237 |
| 20 | * adPEAS-Light.ps1* | .{0,1000}\sadPEAS\-Light\.ps1.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 238 |
| 21 | * ADRecon.ps1* | .{0,1000}\sADRecon\.ps1.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 239 |
| 22 | * --asrep --domain * --user * --pass * | .{0,1000}\s\-\-asrep\s\-\-domain\s.{0,1000}\s\-\-user\s.{0,1000}\s\-\-pass\s.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 291 |
| 23 | * --asreproast * | .{0,1000}\s\-\-asreproast\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 293 |
| 24 | * --authmode ntlm --username * --password * | .{0,1000}\s\-\-authmode\sntlm\s\-\-username\s.{0,1000}\s\-\-password\s.{0,1000} | offensive_tool_keyword | adalanche | Active Directory ACL Visualizer and Explorer - who's really Domain Admin? | T1484 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/lkarlslund/Adalanche | 1 | 0 | N/A | AD Enumeration | 10 | 10 | 1908 | 184 | 2025-03-25T13:01:45Z | 2020-10-07T10:07:22Z | 336 |
| 25 | * AutoSUID.sh* | .{0,1000}\sAutoSUID\.sh.{0,1000} | offensive_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | N/A | N/A | 7 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 344 |
| 26 | * AzureHound.ps1* | .{0,1000}\sAzureHound\.ps1.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 348 |
| 27 | * backdoored-script.ps1* | .{0,1000}\sbackdoored\-script\.ps1.{0,1000} | offensive_tool_keyword | Graphpython | Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/Graphpython | 1 | 0 | N/A | N/A | 7 | 2 | 145 | 13 | 2024-12-07T21:54:00Z | 2024-07-10T00:04:48Z | 356 |
| 28 | * --bhdump * | .{0,1000}\s\-\-bhdump\s.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 388 |
| 29 | * bhqc.py -* | .{0,1000}\sbhqc\.py\s\-.{0,1000} | offensive_tool_keyword | bloodhound-quickwin | Simple script to extract useful informations from the combo BloodHound + Neo4j | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/kaluche/bloodhound-quickwin | 1 | 0 | N/A | AD Enumeration | 6 | 3 | 239 | 26 | 2025-04-04T05:11:46Z | 2021-02-16T16:04:16Z | 389 |
| 30 | * --bloodhound-file * | .{0,1000}\s\-\-bloodhound\-file\s.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 0 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 415 |
| 31 | * bofhound.py* | .{0,1000}\sbofhound\.py.{0,1000} | offensive_tool_keyword | ShadowHound | set of PowerShell scripts for Active Directory enumeration | T1087 - T1018 - T1482 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Friends-Security/ShadowHound | 1 | 0 | N/A | N/A | 8 | 4 | 345 | 36 | 2024-12-01T08:06:02Z | 2024-11-21T15:01:14Z | 421 |
| 32 | * Brc4LdapSentinelParser* | .{0,1000}\sBrc4LdapSentinelParser.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 0 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 427 |
| 33 | * --brute-ratel* | .{0,1000}\s\-\-brute\-ratel.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 0 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 470 |
| 34 | * -c all -d * --domaincontroller * | .{0,1000}\s\-c\sall\s\-d\s.{0,1000}\s\-\-domaincontroller\s.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 499 |
| 35 | * -c DCOnly -d * -u * -p * -o /tmp* | .{0,1000}\s\-c\sDCOnly\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-o\s\/tmp.{0,1000} | offensive_tool_keyword | RustHound | Active Directory data collector for BloodHound written in Rust | T1087.002 - T1018 - T1059.003 | TA0007 - TA0001 - TA0002 | N/A | N/A | Discovery | https://github.com/OPENCYBER-FR/RustHound | 1 | 0 | N/A | AD Enumeration | 9 | 10 | 1013 | 98 | 2024-10-21T18:58:20Z | 2022-10-12T05:54:35Z | 503 |
| 36 | * can now impersonate users on * via S4U2Proxy* | .{0,1000}\scan\snow\simpersonate\susers\son\s.{0,1000}\svia\sS4U2Proxy.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 542 |
| 37 | * --certdump * | .{0,1000}\s\-\-certdump\s.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 555 |
| 38 | * CheckSMBSigning.ps1* | .{0,1000}\sCheckSMBSigning\.ps1.{0,1000} | offensive_tool_keyword | CheckSMBSigning | Checks for SMB signing disabled on all hosts in the network | T1018 - T1550 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Leo4j/CheckSMBSigning | 1 | 0 | N/A | N/A | 6 | 1 | 8 | 1 | 2023-10-13T11:55:33Z | 2023-05-17T11:47:52Z | 564 |
| 39 | * CMLoot.ps1* | .{0,1000}\sCMLoot\.ps1.{0,1000} | offensive_tool_keyword | CMLoot | Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares | T1083 - T1039 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/1njected/CMLoot | 1 | 0 | N/A | N/A | 8 | 2 | 175 | 22 | 2023-02-05T00:24:31Z | 2022-06-02T10:59:21Z | 618 |
| 40 | * coerce * --dc-ip * | .{0,1000}\scoerce\s.{0,1000}\s\-\-dc\-ip\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 626 |
| 41 | * collect activedirectory --* | .{0,1000}\scollect\sactivedirectory\s\-\-.{0,1000} | offensive_tool_keyword | adalanche | Active Directory ACL Visualizer and Explorer - who's really Domain Admin? | T1484 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/lkarlslund/Adalanche | 1 | 0 | N/A | AD Enumeration | 10 | 10 | 1908 | 184 | 2025-03-25T13:01:45Z | 2020-10-07T10:07:22Z | 635 |
| 42 | * --collectallproperties* | .{0,1000}\s\-\-collectallproperties.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 636 |
| 43 | * --CollectionMethod All *ldap* | .{0,1000}\s\-\-CollectionMethod\sAll\s.{0,1000}ldap.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 637 |
| 44 | * --CollectionMethod All *--ZipFileName *.zip* | .{0,1000}\s\-\-CollectionMethod\sAll\s.{0,1000}\-\-ZipFileName\s.{0,1000}\.zip.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 638 |
| 45 | * -CollectionMethod All*loggedon* | .{0,1000}\s\-CollectionMethod\sAll.{0,1000}loggedon.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1552 - T1027 - T1059 - T1087 | TA0003 - TA0002 - TA0007 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 639 |
| 46 | * -CollectionMethod LoggedOn -Verbose* | .{0,1000}\s\-CollectionMethod\sLoggedOn\s\-Verbose.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 640 |
| 47 | * --collectionmethods ACL* | .{0,1000}\s\-\-collectionmethods\sACL.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 642 |
| 48 | * --collectionmethods ComputerOnly* | .{0,1000}\s\-\-collectionmethods\sComputerOnly.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 643 |
| 49 | * --collectionmethods Container* | .{0,1000}\s\-\-collectionmethods\sContainer.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 644 |
| 50 | * --collectionmethods DCOM | .{0,1000}\s\-\-collectionmethods\sDCOM | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 645 |
| 51 | * --collectionmethods DCOnly* | .{0,1000}\s\-\-collectionmethods\sDCOnly.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 646 |
| 52 | * --collectionmethods GPOLocalGroup* | .{0,1000}\s\-\-collectionmethods\sGPOLocalGroup.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 647 |
| 53 | * --collectionmethods Group* | .{0,1000}\s\-\-collectionmethods\sGroup.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 648 |
| 54 | * --collectionmethods LocalGroup* | .{0,1000}\s\-\-collectionmethods\sLocalGroup.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 649 |
| 55 | * --collectionmethods LoggedOn* | .{0,1000}\s\-\-collectionmethods\sLoggedOn.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 650 |
| 56 | * --collectionmethods ObjectProps* | .{0,1000}\s\-\-collectionmethods\sObjectProps.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 651 |
| 57 | * --collectionmethods PSRemote* | .{0,1000}\s\-\-collectionmethods\sPSRemote.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 652 |
| 58 | * --collectionmethods RDP* | .{0,1000}\s\-\-collectionmethods\sRDP.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 653 |
| 59 | * --collectionmethods Session* | .{0,1000}\s\-\-collectionmethods\sSession.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 654 |
| 60 | * --collectionmethods Trusts* | .{0,1000}\s\-\-collectionmethods\sTrusts.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 655 |
| 61 | * COMHijackToolkit.ps1* | .{0,1000}\sCOMHijackToolkit\.ps1.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 659 |
| 62 | * CRITICAL] Suspicous file: \\* | .{0,1000}\sCRITICAL\]\sSuspicous\sfile\:\s\\\\.{0,1000} | offensive_tool_keyword | smbscan | SMBScan is a tool to enumerate file shares on an internal network. | T1135 - T1046 - T1021 | TA0007 - TA0043 - TA0008 | N/A | APT22 | Discovery | https://github.com/jeffhacks/smbscan | 1 | 0 | N/A | N/A | 8 | 1 | 44 | 6 | 2025-03-24T01:55:30Z | 2021-10-26T02:28:34Z | 738 |
| 63 | * -d * -u *\* -p * --da* | .{0,1000}\s\-d\s.{0,1000}\s\-u\s.{0,1000}\\.{0,1000}\s\-p\s.{0,1000}\s\-\-da.{0,1000} | offensive_tool_keyword | windapsearch | Python script to enumerate users - groups and computers from a Windows domain through LDAP queries | T1087.002 - T1018 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/ropnop/windapsearch | 1 | 0 | N/A | AD Enumeration | 7 | 9 | 866 | 154 | 2022-04-20T07:40:42Z | 2016-08-10T21:43:30Z | 770 |
| 64 | * --dc * -m custom --filter *objectCategory* | .{0,1000}\s\-\-dc\s.{0,1000}\s\-m\scustom\s\-\-filter\s.{0,1000}objectCategory.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 786 |
| 65 | * -dc-ip * -dump * | .{0,1000}\s\-dc\-ip\s.{0,1000}\s\-dump\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 789 |
| 66 | * --dc-ip * --vuln --enabled* | .{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-\-vuln\s\-\-enabled.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 794 |
| 67 | * -dc-ip *SAMDump* | .{0,1000}\s\-dc\-ip\s.{0,1000}SAMDump.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 795 |
| 68 | * dclist * | .{0,1000}\sdclist\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 796 |
| 69 | * dir /s */ Microsoft.ActiveDirectory.Management.dll* | .{0,1000}\sdir\s\/s\s.{0,1000}\/\sMicrosoft\.ActiveDirectory\.Management\.dll.{0,1000} | greyware_tool_keyword | dir | threat actors searched for Active Directory related DLLs in directories | T1059 - T1083 - T1018 | TA0002 - TA0009 - TA0040 | N/A | N/A | Discovery | https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/ | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 844 |
| 70 | * --dirnames bank financ payable payment reconcil remit voucher vendor eft swift * | .{0,1000}\s\-\-dirnames\sbank\sfinanc\spayable\spayment\sreconcil\sremit\svoucher\svendor\seft\sswift\s.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | N/A | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 848 |
| 71 | * DLLHound.ps1* | .{0,1000}\sDLLHound\.ps1.{0,1000} | offensive_tool_keyword | DLLHound | Find potential DLL Sideloads on your windows computer | T1574.001 - T1574.002 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/ajm4n/DLLHound | 1 | 0 | N/A | N/A | 7 | 3 | 201 | 22 | 2025-01-12T02:28:22Z | 2024-12-20T02:26:16Z | 869 |
| 72 | * --dnsdump * | .{0,1000}\s\-\-dnsdump\s.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 887 |
| 73 | * dnsdump.py* | .{0,1000}\sdnsdump\.py.{0,1000} | offensive_tool_keyword | adidnsdump | By default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks. | T1018 - T1087 - T1201 - T1056 - T1039 | TA0005 - TA0009 | N/A | N/A | Discovery | https://github.com/dirkjanm/adidnsdump | 1 | 0 | N/A | N/A | N/A | 10 | 997 | 118 | 2025-04-04T09:28:20Z | 2019-04-24T17:18:46Z | 888 |
| 74 | * --doLocalAdminSessionEnum* | .{0,1000}\s\-\-doLocalAdminSessionEnum.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 908 |
| 75 | * domainDumper* | .{0,1000}\sdomainDumper.{0,1000} | offensive_tool_keyword | ldapdomaindump | Active Directory information dumper via LDAP | T1087 - T1005 - T1016 | TA0007 | N/A | EMBER BEAR | Discovery | https://github.com/dirkjanm/ldapdomaindump | 1 | 0 | N/A | N/A | 10 | 10 | 1242 | 201 | 2025-04-06T13:31:57Z | 2016-05-24T18:46:56Z | 911 |
| 76 | * --dont-enumerate-acls * | .{0,1000}\s\-\-dont\-enumerate\-acls\s.{0,1000} | offensive_tool_keyword | SMBeagle | SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host. | T1087.002 - T1021.002 - T1210 | TA0007 - TA0008 - TA0003 | N/A | N/A | Discovery | https://github.com/punk-security/SMBeagle | 1 | 0 | N/A | N/A | 9 | 8 | 712 | 80 | 2025-01-21T22:34:00Z | 2021-05-31T19:46:57Z | 925 |
| 77 | * --dont-enumerate-acls * -e * | .{0,1000}\s\-\-dont\-enumerate\-acls\s.{0,1000}\s\-e\s.{0,1000} | offensive_tool_keyword | SMBeagle | SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host. | T1087.002 - T1021.002 - T1210 | TA0007 - TA0008 - TA0003 | N/A | N/A | Discovery | https://github.com/punk-security/SMBeagle | 1 | 0 | N/A | N/A | 9 | 8 | 712 | 80 | 2025-01-21T22:34:00Z | 2021-05-31T19:46:57Z | 926 |
| 78 | * DSInternals.psd1* | .{0,1000}\sDSInternals\.psd1.{0,1000} | offensive_tool_keyword | DSInternals | Directory Services Internals (DSInternals) PowerShell Module and Framework - abused by attackers | T1003 - T1087 - T1018 - T1110 - T1558 | TA0003 - TA0006 - TA0007 | N/A | COZY BEAR | Discovery | https://github.com/MichaelGrafnetter/DSInternals | 1 | 0 | N/A | AD Enumeration | 10 | 10 | 1760 | 265 | 2025-04-16T18:12:55Z | 2015-12-25T13:23:05Z | 968 |
| 79 | * -e bat com vbs ps1 psd1 psm1 pem key rsa pub reg txt cfg conf config * | .{0,1000}\s\-e\sbat\scom\svbs\sps1\spsd1\spsm1\spem\skey\srsa\spub\sreg\stxt\scfg\sconf\sconfig\s.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | N/A | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 1008 |
| 80 | * -e pfx p12 pkcs12 pem key crt cer csr jks keystore key keys der * | .{0,1000}\s\-e\spfx\sp12\spkcs12\spem\skey\scrt\scer\scsr\sjks\skeystore\skey\skeys\sder\s.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | N/A | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 1009 |
| 81 | * -e ppk rsa pem ssh rsa* | .{0,1000}\s\-e\sppk\srsa\spem\sssh\srsa.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | N/A | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 1010 |
| 82 | * ecrprivenum.py* | .{0,1000}\secrprivenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 1020 |
| 83 | * ecrpubenum.py* | .{0,1000}\secrpubenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 1021 |
| 84 | * --excludedcs* | .{0,1000}\s\-\-excludedcs.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 1096 |
| 85 | * -exec bypass -nop -c whoami* | .{0,1000}\s\-exec\sbypass\s\-nop\s\-c\swhoami.{0,1000} | greyware_tool_keyword | whoami | whoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network. | T1003.001 - T1087 - T1057 | TA0007 | N/A | Black Basta | Discovery | N/A | 1 | 0 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 1101 |
| 86 | * -f "(objectcategory=computer)" -s subtree dn operatingSystem* | .{0,1000}\s\-f\s\"\(objectcategory\=computer\)\"\s\-s\ssubtree\sdn\soperatingSystem.{0,1000} | greyware_tool_keyword | adfind | Enumerate All Computers in the Domain | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1143 |
| 87 | * -f "(objectcategory=person)" -s subtree samaccountname userPrincipalName* | .{0,1000}\s\-f\s\"\(objectcategory\=person\)\"\s\-s\ssubtree\ssamaccountname\suserPrincipalName.{0,1000} | greyware_tool_keyword | adfind | Enumerate All Users in the Domain | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1144 |
| 88 | * -f "(objectcategory=trustedDomain)" -s subtree name trustAttributes trustDirection trustType* | .{0,1000}\s\-f\s\"\(objectcategory\=trustedDomain\)\"\s\-s\ssubtree\sname\strustAttributes\strustDirection\strustType.{0,1000} | greyware_tool_keyword | adfind | Dump All Domain Trusts | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 1145 |
| 89 | * -f passw -e xlsx csv * | .{0,1000}\s\-f\spassw\s\-e\sxlsx\scsv\s.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | N/A | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 1173 |
| 90 | * -f passw user admin account network login logon cred * | .{0,1000}\s\-f\spassw\suser\sadmin\saccount\snetwork\slogin\slogon\scred\s.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | N/A | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 1174 |
| 91 | * -fake-hostname * | .{0,1000}\s\-fake\-hostname\s.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 1186 |
| 92 | * --force-kerb * | .{0,1000}\s\-\-force\-kerb\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 1210 |
| 93 | * --format=krb5asrep* --wordlist=* | .{0,1000}\s\-\-format\=krb5asrep.{0,1000}\s\-\-wordlist\=.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 1227 |
| 94 | * FROM LDAPHUNTERFINDINGS* | .{0,1000}\sFROM\sLDAPHUNTERFINDINGS.{0,1000} | offensive_tool_keyword | LDAP-Password-Hunter | Password Hunter in Active Directory | T1087.002 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/LDAP-Password-Hunter | 1 | 0 | N/A | N/A | 7 | 2 | 198 | 25 | 2023-01-06T15:32:34Z | 2021-07-26T14:27:01Z | 1240 |
| 95 | * -g -n --kerberoast* | .{0,1000}\s\-g\s\-n\s\-\-kerberoast.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 1279 |
| 96 | * Get-ADReplAccount -SamAccountName 'AZUREADSSOACC$' * | .{0,1000}\sGet\-ADReplAccount\s\-SamAccountName\s\'AZUREADSSOACC\$\'\s.{0,1000} | offensive_tool_keyword | DSInternals | Directory Services Internals (DSInternals) PowerShell Module and Framework - abused by attackers | T1003 - T1087 - T1018 - T1110 - T1558 | TA0003 - TA0006 - TA0007 | N/A | COZY BEAR | Discovery | https://github.com/MichaelGrafnetter/DSInternals | 1 | 0 | N/A | AD Enumeration | 10 | 10 | 1760 | 265 | 2025-04-16T18:12:55Z | 2015-12-25T13:23:05Z | 1313 |
| 97 | * Get-DomainController | select Name,OSversion,IPAddress |fl* | .{0,1000}\sGet\-DomainController\s\|\sselect\sName,OSversion,IPAddress\s\|fl.{0,1000} | offensive_tool_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | N/A | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 1317 |
| 98 | * Get-DomainGPO -Identity "{AB306569-220D-43FF-B03B-83E8F4EF8081}"* | .{0,1000}\sGet\-DomainGPO\s\-Identity\s\"\{AB306569\-220D\-43FF\-B03B\-83E8F4EF8081\}\".{0,1000} | offensive_tool_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | N/A | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 1318 |
| 99 | * Get-SMBSigning.ps1* | .{0,1000}\sGet\-SMBSigning\.ps1.{0,1000} | offensive_tool_keyword | CheckSMBSigning | Checks for SMB signing disabled on all hosts in the network | T1018 - T1550 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Leo4j/CheckSMBSigning | 1 | 0 | N/A | N/A | 6 | 1 | 8 | 1 | 2023-10-13T11:55:33Z | 2023-05-17T11:47:52Z | 1331 |
| 100 | * GPOBrowser.py* | .{0,1000}\sGPOBrowser\.py.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 0 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 1370 |
| 101 | * Graphpython.py* | .{0,1000}\sGraphpython\.py.{0,1000} | offensive_tool_keyword | Graphpython | Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/Graphpython | 1 | 0 | N/A | N/A | 7 | 2 | 145 | 13 | 2024-12-07T21:54:00Z | 2024-07-10T00:04:48Z | 1378 |
| 102 | * -H * -u * -p * -r *C$/Users* | .{0,1000}\s\-H\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-r\s.{0,1000}C\$\/Users.{0,1000} | offensive_tool_keyword | smbmap | SMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks. | T1210.001 - T1083 - T1213 - T1021 | TA0007 - TA0003 - TA0002 - TA0001 | N/A | MuddyWater - Dispossessor | Discovery | https://github.com/ShawnDEvans/smbmap | 1 | 0 | N/A | N/A | 10 | 10 | 1890 | 359 | 2025-02-28T18:09:10Z | 2015-03-16T13:15:00Z | 1397 |
| 103 | * HijackDLL-Threads.dll* | .{0,1000}\sHijackDLL\-Threads\.dll.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 1423 |
| 104 | * --host-file *.txt -u * --prompt --admin --no-banner* | .{0,1000}\s\-\-host\-file\s.{0,1000}\.txt\s\-u\s.{0,1000}\s\-\-prompt\s\-\-admin\s\-\-no\-banner.{0,1000} | offensive_tool_keyword | smbmap | SMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks. | T1210.001 - T1083 - T1213 - T1021 | TA0007 - TA0003 - TA0002 - TA0001 | N/A | MuddyWater - Dispossessor | Discovery | https://github.com/ShawnDEvans/smbmap | 1 | 0 | N/A | N/A | 10 | 10 | 1890 | 359 | 2025-02-28T18:09:10Z | 2015-03-16T13:15:00Z | 1436 |
| 105 | * iamassumeroleenum.py* | .{0,1000}\siamassumeroleenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 1602 |
| 106 | * --impersonate Administrator -shell * | .{0,1000}\s\-\-impersonate\sAdministrator\s\-shell\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 1635 |
| 107 | * --input 10m_usernames.txt* | .{0,1000}\s\-\-input\s10m_usernames\.txt.{0,1000} | offensive_tool_keyword | ldapnomnom | Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP) | T1110.003 - T1205 | TA0007 | N/A | N/A | Discovery | https://github.com/lkarlslund/ldapnomnom | 1 | 0 | N/A | N/A | 6 | 10 | 1030 | 80 | 2024-11-09T10:15:13Z | 2022-09-18T10:35:09Z | 1665 |
| 108 | * -InputPath .\TrustedForests.txt* | .{0,1000}\s\-InputPath\s\.\\TrustedForests\.txt.{0,1000} | offensive_tool_keyword | Locksmith | A tiny tool to identify and remediate common misconfigurations in Active Directory Certificate Services | T1552.006 - T1222 - T1046 | TA0007 - TA0040 - TA0043 | N/A | N/A | Discovery | https://github.com/TrimarcJake/Locksmith | 1 | 0 | N/A | N/A | 8 | 10 | 1086 | 100 | 2025-04-21T12:43:50Z | 2022-04-28T01:37:32Z | 1667 |
| 109 | * INTO LDAPHUNTERFINDINGS* | .{0,1000}\sINTO\sLDAPHUNTERFINDINGS.{0,1000} | offensive_tool_keyword | LDAP-Password-Hunter | Password Hunter in Active Directory | T1087.002 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/LDAP-Password-Hunter | 1 | 0 | N/A | N/A | 7 | 2 | 198 | 25 | 2023-01-06T15:32:34Z | 2021-07-26T14:27:01Z | 1725 |
| 110 | * Invoke-CertToAccessToken -tenant * | .{0,1000}\sInvoke\-CertToAccessToken\s\-tenant\s.{0,1000} | offensive_tool_keyword | SharpGraphView | Microsoft Graph API post-exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/SharpGraphView | 1 | 0 | N/A | N/A | 6 | 1 | 94 | 9 | 2024-07-13T12:27:38Z | 2024-05-04T11:23:42Z | 1738 |
| 111 | * Invoke-DCOM.ps1* | .{0,1000}\sInvoke\-DCOM\.ps1.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 1739 |
| 112 | * Invoke-ShareFinder -CheckShareAccess* | .{0,1000}\sInvoke\-ShareFinder\s\-CheckShareAccess.{0,1000} | offensive_tool_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | N/A | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 1751 |
| 113 | * -ip * -smb2support *lwpshare* | .{0,1000}\s\-ip\s.{0,1000}\s\-smb2support\s.{0,1000}lwpshare.{0,1000}\s | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 1758 |
| 114 | * -it bloodhound* | .{0,1000}\s\-it\sbloodhound.{0,1000} | offensive_tool_keyword | BloodHound | A Python based ingestor for BloodHound | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/fox-it/BloodHound.py | 1 | 0 | N/A | N/A | 10 | 10 | 2088 | 343 | 2025-03-28T11:19:13Z | 2018-02-26T14:44:20Z | 1790 |
| 115 | * -jar ipscan.exe* | .{0,1000}\s\-jar\sipscan\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | network exploitation tool | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 1798 |
| 116 | * jecretz.py* | .{0,1000}\sjecretz\.py.{0,1000} | offensive_tool_keyword | jecretz | Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets | T1552 - T1114 - T1119 - T1070 | TA0006 - TA0009 - TA0005 | N/A | Scattered Spider* | Discovery | https://github.com/sahadnk72/jecretz | 1 | 0 | N/A | N/A | 7 | 1 | 43 | 9 | 2022-12-08T10:00:11Z | 2020-05-25T14:40:28Z | 1804 |
| 117 | * -k --kerberoast* | .{0,1000}\s\-k\s\-\-kerberoast.{0,1000} | offensive_tool_keyword | SilentHound | Quietly enumerate an Active Directory Domain via LDAP parsing users + admins + groups... | T1087.002 - T1018 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/layer8secure/SilentHound | 1 | 0 | N/A | AD Enumeration | 7 | 5 | 489 | 47 | 2023-01-23T20:41:55Z | 2022-07-01T13:49:24Z | 1840 |
| 118 | * Kerberoastable -action list* | .{0,1000}\sKerberoastable\s\-action\slist.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 1858 |
| 119 | * Kerberoastable -action write -target * | .{0,1000}\sKerberoastable\s\-action\swrite\s\-target\s.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 1859 |
| 120 | * Killchain.ps1* | .{0,1000}\sKillchain\.ps1.{0,1000} | offensive_tool_keyword | Graphpython | Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/Graphpython | 1 | 0 | N/A | N/A | 7 | 2 | 145 | 13 | 2024-12-07T21:54:00Z | 2024-07-10T00:04:48Z | 1883 |
| 121 | * lambdaenum.py* | .{0,1000}\slambdaenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 1923 |
| 122 | * ldap * --gmsa *dump* | .{0,1000}\sldap\s.{0,1000}\s\-\-gmsa\s.{0,1000}dump.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 1932 |
| 123 | * --ldap servicePrincipalName=* --domain * --user * --pass * | .{0,1000}\s\-\-ldap\sservicePrincipalName\=.{0,1000}\s\-\-domain\s.{0,1000}\s\-\-user\s.{0,1000}\s\-\-pass\s.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 1936 |
| 124 | * ldapper.py* | .{0,1000}\sldapper\.py.{0,1000} | offensive_tool_keyword | LDAPPER | LDAP Querying without the Suck | T1087 - T1069 - T1018 | TA0007 | N/A | N/A | Discovery | https://github.com/shellster/LDAPPER | 1 | 0 | N/A | N/A | 7 | 1 | 99 | 11 | 2024-11-09T03:53:26Z | 2020-06-17T16:53:35Z | 1939 |
| 125 | * ldapph.db* | .{0,1000}\sldapph\.db.{0,1000} | offensive_tool_keyword | LDAP-Password-Hunter | Password Hunter in Active Directory | T1087.002 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/LDAP-Password-Hunter | 1 | 0 | N/A | N/A | 7 | 2 | 198 | 25 | 2023-01-06T15:32:34Z | 2021-07-26T14:27:01Z | 1940 |
| 126 | * --ldapusername * --ldappassword * | .{0,1000}\s\-\-ldapusername\s\s.{0,1000}\s\-\-ldappassword\s.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 1944 |
| 127 | * linWinPwn* | .{0,1000}\slinWinPwn.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 1958 |
| 128 | * loadbalancer.py* | .{0,1000}\sloadbalancer\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 1999 |
| 129 | * --localadminsessionenum * | .{0,1000}\s\-\-localadminsessionenum\s.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 2016 |
| 130 | * --LocalGMEnum --Host * | .{0,1000}\s\s\-\-LocalGMEnum\s\-\-Host\s.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 0 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 2019 |
| 131 | * LocalShellExtParse.py* | .{0,1000}\sLocalShellExtParse\.py.{0,1000} | offensive_tool_keyword | LocalShellExtParse | Script to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User. | T1547.009 - T1129 | TA0003 - TA0007 | N/A | N/A | Discovery | https://github.com/herrcore/LocalShellExtParse | 1 | 0 | N/A | N/A | 9 | 1 | 20 | 4 | 2015-06-08T16:55:38Z | 2015-06-05T03:23:13Z | 2025 |
| 132 | * -M dfscoerce * | .{0,1000}\s\-M\sdfscoerce\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2059 |
| 133 | * -M handlekatz * | .{0,1000}\s\-M\shandlekatz\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2063 |
| 134 | * -M keepass_discover * | .{0,1000}\s\-M\skeepass_discover\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2064 |
| 135 | * -M laps --kdcHost * | .{0,1000}\s\-M\slaps\s\-\-kdcHost\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2068 |
| 136 | * -M ldap-checker * | .{0,1000}\s\-M\sldap\-checker\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2069 |
| 137 | * -M lsassy * | .{0,1000}\s\-M\slsassy\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2071 |
| 138 | * -M MAQ --kdcHost * | .{0,1000}\s\-M\sMAQ\s\-\-kdcHost\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2072 |
| 139 | * -M masky *CA=* | .{0,1000}\s\-M\smasky\s.{0,1000}CA\=.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2073 |
| 140 | * -M ms17-010 * | .{0,1000}\s\-M\sms17\-010\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2074 |
| 141 | * -M mssql_priv * | .{0,1000}\s\-M\smssql_priv\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2075 |
| 142 | * -M nanodump * | .{0,1000}\s\-M\snanodump\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2077 |
| 143 | * -M petitpotam * | .{0,1000}\s\-M\spetitpotam\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2080 |
| 144 | * -M printnightmare * | .{0,1000}\s\-M\sprintnightmare\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2082 |
| 145 | * -m privileged-users --full * | .{0,1000}\s\-m\sprivileged\-users\s\-\-full\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2083 |
| 146 | * -M procdump | .{0,1000}\s\-M\sprocdump\s | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2084 |
| 147 | * -M runasppl * | .{0,1000}\s\-M\srunasppl\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2087 |
| 148 | * -M shadowcoerce * | .{0,1000}\s\-M\sshadowcoerce\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2090 |
| 149 | * -M spider_plus * | .{0,1000}\s\-M\sspider_plus\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2096 |
| 150 | * -M teams_localdb * | .{0,1000}\s\-M\steams_localdb\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2099 |
| 151 | * -M zerologon * | .{0,1000}\s\-M\szerologon\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2106 |
| 152 | * -Module Bloodhound -Method All* | .{0,1000}\s\-Module\sBloodhound\s\-Method\sAll.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 2175 |
| 153 | * -Module Bloodhound -Scope All* | .{0,1000}\s\-Module\sBloodhound\s\-Scope\sAll.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 2176 |
| 154 | * netscan.exe * | .{0,1000}\snetscan\.exe\s.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 2301 |
| 155 | * netscan64.exe * | .{0,1000}\snetscan64\.exe\s.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 2302 |
| 156 | * NimScan.exe* | .{0,1000}\sNimScan\.exe.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 0 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 2317 |
| 157 | * NimScan.nim* | .{0,1000}\sNimScan\.nim.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 0 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 2318 |
| 158 | * -no-pass -just-dc-user * | .{0,1000}\s\-no\-pass\s\-just\-dc\-user\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2358 |
| 159 | * -no-preauth * -dc-ip * | .{0,1000}\s\-no\-preauth\s.{0,1000}\s\-dc\-ip\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2364 |
| 160 | * ntlmrecon* | .{0,1000}\sntlmrecon.{0,1000} | offensive_tool_keyword | NTMLRecon | A fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains | T1595 | TA0009 | N/A | N/A | Discovery | https://github.com/pwnfoo/NTLMRecon | 1 | 0 | N/A | N/A | N/A | 5 | 481 | 70 | 2024-06-24T18:11:12Z | 2019-12-01T06:06:30Z | 2402 |
| 161 | * nullinux.py* | .{0,1000}\snullinux\.py.{0,1000} | offensive_tool_keyword | nullinux | Internal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB. | T1087 - T1016 - T1077 - T1018 | TA0007 - TA0006 | N/A | N/A | Discovery | https://github.com/m8sec/nullinux | 1 | 0 | #linux | N/A | 7 | 6 | 575 | 101 | 2024-06-19T14:29:09Z | 2016-04-28T16:45:02Z | 2411 |
| 162 | * --only-abuse --dc-host * | .{0,1000}\s\-\-only\-abuse\s\-\-dc\-host\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2448 |
| 163 | * options.fake_hostname* | .{0,1000}\soptions\.fake_hostname.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 2454 |
| 164 | * --output rootDSEs.json --dump* | .{0,1000}\s\-\-output\srootDSEs\.json\s\-\-dump.{0,1000} | offensive_tool_keyword | ldapnomnom | Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP) | T1110.003 - T1205 | TA0007 | N/A | N/A | Discovery | https://github.com/lkarlslund/ldapnomnom | 1 | 0 | N/A | N/A | 6 | 10 | 1030 | 80 | 2024-11-09T10:15:13Z | 2022-09-18T10:35:09Z | 2470 |
| 165 | * -p 'aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0'* | .{0,1000}\s\-p\s\'aad3b435b51404eeaad3b435b51404ee\:31d6cfe0d16ae931b73c59d7e0c089c0\'.{0,1000} | offensive_tool_keyword | ad-ldap-enum | An LDAP based Active Directory user and group enumeration tool | T1087 - T1087.001 - T1018 - T1069 - T1069.002 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/CroweCybersecurity/ad-ldap-enum | 1 | 0 | N/A | AD Enumeration | 6 | 4 | 308 | 66 | 2023-02-10T19:07:34Z | 2015-08-25T19:38:39Z | 2485 |
| 166 | * --passnotreq --domain * --user * --pass * | .{0,1000}\s\-\-passnotreq\s\-\-domain\s.{0,1000}\s\-\-user\s.{0,1000}\s\-\-pass\s.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 2524 |
| 167 | * --password-not-required --kdcHost *cme* | .{0,1000}\s\-\-password\-not\-required\s\-\-kdcHost\s.{0,1000}cme.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2533 |
| 168 | * -pathToBloodHoundGraph * -pathToOutputGoFetchPath * -pathToAdditionalPayload * | .{0,1000}\s\-pathToBloodHoundGraph\s.{0,1000}\s\-pathToOutputGoFetchPath\s.{0,1000}\s\s\-pathToAdditionalPayload\s.{0,1000} | offensive_tool_keyword | GoFetch | GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application. | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | Dispossessor | Discovery | https://github.com/GoFetchAD/GoFetch | 1 | 0 | N/A | N/A | 10 | 7 | 633 | 99 | 2017-06-20T14:15:10Z | 2017-04-11T10:45:23Z | 2545 |
| 169 | * -PathToGraph *.json -PathToPayload *.exe* | .{0,1000}\s\-PathToGraph\s.{0,1000}\.json\s\-PathToPayload\s.{0,1000}\.exe.{0,1000} | offensive_tool_keyword | GoFetch | GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application. | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | Dispossessor | Discovery | https://github.com/GoFetchAD/GoFetch | 1 | 0 | N/A | N/A | 10 | 7 | 633 | 99 | 2017-06-20T14:15:10Z | 2017-04-11T10:45:23Z | 2547 |
| 170 | * -perm -4000 -o -perm -2000* | .{0,1000}\s\-perm\s\-4000\s\-o\s\-perm\s\-2000.{0,1000} | greyware_tool_keyword | find | Look for files with the SGID (Set Group ID) bit set | T1083 - T1069 - T1202 | TA0004 - TA0007 | N/A | N/A | Discovery | N/A | 1 | 0 | #linux | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 2584 |
| 171 | * -pfx *.pfx -dc-ip * | .{0,1000}\s\-pfx\s.{0,1000}\.pfx\s\-dc\-ip\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2598 |
| 172 | * polenum.py* | .{0,1000}\spolenum\.py.{0,1000} | offensive_tool_keyword | polenum | Uses Impacket Library to get the password policy from a windows machine | T1012 - T1596 | TA0009 - TA0007 | N/A | N/A | Discovery | https://salsa.debian.org/pkg-security-team/polenum | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 2625 |
| 173 | * powerview.py* | .{0,1000}\spowerview\.py.{0,1000} | offensive_tool_keyword | powerview | PowerView.py is an alternative for the awesome original PowerView.ps1 | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/aniqfakhrul/powerview.py | 1 | 0 | N/A | N/A | 10 | 7 | 622 | 66 | 2025-04-22T09:01:39Z | 2022-06-19T16:13:04Z | 2656 |
| 174 | * PSnmap.ps1* | .{0,1000}\sPSnmap\.ps1.{0,1000} | offensive_tool_keyword | Psnmap | Powershell scanner (nmap like) | T1086 - T1046 - T1059 | TA0007 | N/A | Black Basta | Discovery | https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1 | 1 | 0 | N/A | N/A | 7 | 2 | 178 | 64 | 2024-08-23T18:24:20Z | 2015-01-24T10:46:41Z | 2696 |
| 175 | * pwn_php.me* | .{0,1000}\spwn_php\.me.{0,1000} | offensive_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | N/A | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 2730 |
| 176 | * pwn_python.me* | .{0,1000}\spwn_python\.me.{0,1000} | offensive_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | N/A | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 2731 |
| 177 | * pwn_tclsh.me* | .{0,1000}\spwn_tclsh\.me.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | N/A | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 2732 |
| 178 | * Rattler.exe* | .{0,1000}\sRattler\.exe.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 2773 |
| 179 | * Rattler_32.exe* | .{0,1000}\sRattler_32\.exe.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 2774 |
| 180 | * Rattler_x64.exe* | .{0,1000}\sRattler_x64\.exe.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 2775 |
| 181 | * RBCD -action write -delegate-to * -delegate-from * | .{0,1000}\sRBCD\s\-action\swrite\s\-delegate\-to\s.{0,1000}\s\-delegate\-from\s.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 2778 |
| 182 | * -Recommended -SprayEmptyPasswords* | .{0,1000}\s\-Recommended\s\-SprayEmptyPasswords.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 0 | N/A | N/A | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 2806 |
| 183 | * -request -dc-ip * | .{0,1000}\s\-request\s\-dc\-ip\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2864 |
| 184 | * --rid-brute 2>&1 *.txt* | .{0,1000}\s\-\-rid\-brute\s2\>\&1\s.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2901 |
| 185 | * rusthound.exe* | .{0,1000}\srusthound\.exe.{0,1000} | offensive_tool_keyword | RustHound | Active Directory data collector for BloodHound written in Rust | T1087.002 - T1018 - T1059.003 | TA0007 - TA0001 - TA0002 | N/A | N/A | Discovery | https://github.com/OPENCYBER-FR/RustHound | 1 | 0 | N/A | AD Enumeration | 9 | 10 | 1013 | 98 | 2024-10-21T18:58:20Z | 2022-10-12T05:54:35Z | 2954 |
| 186 | * s3aclenum.py* | .{0,1000}\ss3aclenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 2969 |
| 187 | * s3enum.py* | .{0,1000}\ss3enum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 2970 |
| 188 | * -save-old -dc-ip * | .{0,1000}\s\-save\-old\s\-dc\-ip\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2982 |
| 189 | * -sc getacls -sddlfilter * | .{0,1000}\s\-sc\sgetacls\s\-sddlfilter\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2984 |
| 190 | * -sc trustdump* | .{0,1000}\s\-sc\strustdump.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 2987 |
| 191 | * scan * --dc-ip * | .{0,1000}\sscan\s.{0,1000}\s\-\-dc\-ip\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 2988 |
| 192 | * --scan-local-shares * -e * | .{0,1000}\s\-\-scan\-local\-shares\s.{0,1000}\s\-e\s.{0,1000} | offensive_tool_keyword | SMBeagle | SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host. | T1087.002 - T1021.002 - T1210 | TA0007 - TA0008 - TA0003 | N/A | N/A | Discovery | https://github.com/punk-security/SMBeagle | 1 | 0 | N/A | N/A | 9 | 8 | 712 | 80 | 2025-01-21T22:34:00Z | 2021-05-31T19:46:57Z | 2992 |
| 193 | * -SCCMHost * -Outfile * | .{0,1000}\s\-SCCMHost\s.{0,1000}\s\-Outfile\s.{0,1000} | offensive_tool_keyword | CMLoot | Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares | T1083 - T1039 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/1njected/CMLoot | 1 | 0 | N/A | N/A | 8 | 2 | 175 | 22 | 2023-02-05T00:24:31Z | 2022-06-02T10:59:21Z | 3002 |
| 194 | * --script smb-vuln-ms08-067,smb-vuln-ms17-010* | .{0,1000}\s\-\-script\ssmb\-vuln\-ms08\-067,smb\-vuln\-ms17\-010.{0,1000} | greyware_tool_keyword | nmap | nmap vuln scan of most used vulnerabilities | T1046 - T1203 - T1210 | TA0007 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 3011 |
| 195 | * SearchShares.ps1* | .{0,1000}\sSearchShares\.ps1.{0,1000} | offensive_tool_keyword | SearchOpenFileShares | Searches open files shares for password files or database backups - Extend as you see fit | T1083 - T1135 - T1005 - T1025 | TA0007 - TA0009 | N/A | Dispossessor | Discovery | https://github.com/fashionproof/SearchOpenFileShares | 1 | 0 | N/A | N/A | 7 | 1 | 29 | 6 | 2019-12-13T12:37:42Z | 2019-09-21T13:50:26Z | 3023 |
| 196 | * secretsmanagerenum.py* | .{0,1000}\ssecretsmanagerenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 3033 |
| 197 | * --SessionEnum --Host * | .{0,1000}\s\-\-SessionEnum\s\-\-Host\s.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 0 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 3055 |
| 198 | * SharpBuster.dll* | .{0,1000}\sSharpBuster\.dll.{0,1000} | offensive_tool_keyword | SharpBuster | This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution | T1087 - T1112 - T1048.003 - T1105 | TA0007 - TA0040 - TA0002 | N/A | N/A | Discovery | https://github.com/passthehashbrowns/SharpBuster | 1 | 0 | N/A | N/A | 7 | 1 | 62 | 7 | 2020-09-02T15:46:03Z | 2020-08-31T00:33:02Z | 3078 |
| 199 | * SharpBuster.exe* | .{0,1000}\sSharpBuster\.exe.{0,1000} | offensive_tool_keyword | SharpBuster | This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution | T1087 - T1112 - T1048.003 - T1105 | TA0007 - TA0040 - TA0002 | N/A | N/A | Discovery | https://github.com/passthehashbrowns/SharpBuster | 1 | 0 | N/A | N/A | 7 | 1 | 62 | 7 | 2020-09-02T15:46:03Z | 2020-08-31T00:33:02Z | 3079 |
| 200 | * SharpEDRChecker* | .{0,1000}\sSharpEDRChecker.{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | N/A | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 3085 |
| 201 | * SharpHound.ps1* | .{0,1000}\sSharpHound\.ps1.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 3091 |
| 202 | *- --skippasswordcheck* | .{0,1000}\-\s\-\-skippasswordcheck.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 3157 |
| 203 | * --skipregistryloggedon* | .{0,1000}\s\-\-skipregistryloggedon.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 3158 |
| 204 | * SmallSecretsDump.py* | .{0,1000}\sSmallSecretsDump\.py.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 0 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 3172 |
| 205 | * smb * --dpapi *password* | .{0,1000}\ssmb\s.{0,1000}\s\-\-dpapi\s.{0,1000}password.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 3176 |
| 206 | * smb * --gen-relay-list *.txt* | .{0,1000}\ssmb\s.{0,1000}\s\-\-gen\-relay\-list\s.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 3177 |
| 207 | * smb * --lsa --log * | .{0,1000}\ssmb\s.{0,1000}\s\-\-lsa\s\-\-log\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 3178 |
| 208 | * smb * -M msol * | .{0,1000}\ssmb\s.{0,1000}\s\-M\smsol\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 3181 |
| 209 | * smb * -M ntlmv1 * | .{0,1000}\ssmb\s.{0,1000}\s\-M\sntlmv1\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 3182 |
| 210 | * smb * --ntds --log * | .{0,1000}\ssmb\s.{0,1000}\s\-\-ntds\s\-\-log\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 3187 |
| 211 | * smb * --sam --log * | .{0,1000}\ssmb\s.{0,1000}\s\-\-sam\s\-\-log\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 3188 |
| 212 | * smbscan.py * | .{0,1000}\ssmbscan\.py\s.{0,1000} | offensive_tool_keyword | smbscan | SMBScan is a tool to enumerate file shares on an internal network. | T1135 - T1046 - T1021 | TA0007 - TA0043 - TA0008 | N/A | APT22 | Discovery | https://github.com/jeffhacks/smbscan | 1 | 0 | N/A | N/A | 8 | 1 | 44 | 6 | 2025-03-24T01:55:30Z | 2021-10-26T02:28:34Z | 3234 |
| 213 | * smbsr.log* | .{0,1000}\ssmbsr\.log.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 3238 |
| 214 | * smbsr.py* | .{0,1000}\ssmbsr\.py.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 3240 |
| 215 | * smbsr_results.csv* | .{0,1000}\ssmbsr_results\.csv.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 3241 |
| 216 | * snsenum.py* | .{0,1000}\ssnsenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 3289 |
| 217 | * SOAPHound.ADWS* | .{0,1000}\sSOAPHound\.ADWS.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | #content | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 3290 |
| 218 | * -sS -p- --min-rate=* -Pn* | .{0,1000}\s\-sS\s\-p\-\s\-\-min\-rate\=.{0,1000}\s\-Pn.{0,1000} | offensive_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing (stealphy mode) | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://nmap.org/book/nse-usage.html | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 3352 |
| 219 | * --stealth --secureldap* | .{0,1000}\s\-\-stealth\s\-\-secureldap.{0,1000} | signature_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 3406 |
| 220 | * -sV --script vulners * | .{0,1000}\s\-sV\s\-\-script\svulners\s.{0,1000} | offensive_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://nmap.org/book/nse-usage.html | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 3433 |
| 221 | * teamsenum.py* | .{0,1000}\steamsenum\.py.{0,1000} | offensive_tool_keyword | TeamsEnum | User Enumeration of Microsoft Teams users via API | T1589.002 - T1590 | TA0007 - TA0001 | N/A | Black Basta | Discovery | https://github.com/sse-secure-systems/TeamsEnum | 1 | 0 | N/A | N/A | 6 | 2 | 153 | 21 | 2024-03-27T18:14:25Z | 2023-04-03T18:35:15Z | 3494 |
| 222 | * thief.py* | .{0,1000}\sthief\.py.{0,1000} | offensive_tool_keyword | SeeYouCM-Thief | Simple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentials | T1110.001 - T1005 - T1071.001 | TA0001 - TA0011 - TA0005 | N/A | N/A | Discovery | https://github.com/trustedsec/SeeYouCM-Thief | 1 | 0 | N/A | N/A | 9 | 2 | 189 | 35 | 2023-05-11T01:04:36Z | 2022-01-14T20:12:25Z | 3516 |
| 223 | * -u http* --wordlisturl * -e php,aspx --recursion true* | .{0,1000}\s\-u\shttp.{0,1000}\s\-\-wordlisturl\s.{0,1000}\s\-e\sphp,aspx\s\-\-recursion\strue.{0,1000} | offensive_tool_keyword | SharpBuster | This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution | T1087 - T1112 - T1048.003 - T1105 | TA0007 - TA0040 - TA0002 | N/A | N/A | Discovery | https://github.com/passthehashbrowns/SharpBuster | 1 | 0 | N/A | N/A | 7 | 1 | 62 | 7 | 2020-09-02T15:46:03Z | 2020-08-31T00:33:02Z | 3599 |
| 224 | * --unconstrained-users* | .{0,1000}\s\-\-unconstrained\-users.{0,1000} | offensive_tool_keyword | windapsearch | Python script to enumerate users - groups and computers from a Windows domain through LDAP queries | T1087.002 - T1018 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/ropnop/windapsearch | 1 | 0 | N/A | AD Enumeration | 7 | 9 | 866 | 154 | 2022-04-20T07:40:42Z | 2016-08-10T21:43:30Z | 3613 |
| 225 | * userenum * --dc * | .{0,1000}\suserenum\s.{0,1000}\s\-\-dc\s.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 3642 |
| 226 | * --UserEnum --Host * | .{0,1000}\s\-\-UserEnum\s\-\-Host\s.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 0 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 3644 |
| 227 | * --user-spns* | .{0,1000}\s\-\-user\-spns.{0,1000} | offensive_tool_keyword | windapsearch | Python script to enumerate users - groups and computers from a Windows domain through LDAP queries | T1087.002 - T1018 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/ropnop/windapsearch | 1 | 0 | N/A | AD Enumeration | 7 | 9 | 866 | 154 | 2022-04-20T07:40:42Z | 2016-08-10T21:43:30Z | 3654 |
| 228 | * -vulnerable -stdout -hide-admins* | .{0,1000}\s\-vulnerable\s\-stdout\s\-hide\-admins.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 3681 |
| 229 | * We have found at least * potential SUID exploitable file(s)* | .{0,1000}\sWe\shave\sfound\sat\sleast\s.{0,1000}\spotential\sSUID\sexploitable\sfile\(s\).{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | N/A | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 3696 |
| 230 | * where /r C:\Windows\WinSxS\ *Microsoft.ActiveDirectory.Management.dll* | .{0,1000}\swhere\s\/r\sC\:\\Windows\\WinSxS\\\s.{0,1000}Microsoft\.ActiveDirectory\.Management\.dll.{0,1000} | greyware_tool_keyword | where | threat actors searched for Active Directory related DLLs in directories | T1059 - T1083 - T1018 | TA0002 - TA0009 - TA0040 | N/A | N/A | Discovery | https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/ | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 3704 |
| 231 | * Win64/NetTool.SoftPerfectNetscan* | .{0,1000}\sWin64\/NetTool\.SoftPerfectNetscan.{0,1000} | signature_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | #Avsignature | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 3712 |
| 232 | * windapsearch.py* | .{0,1000}\swindapsearch\.py.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 3714 |
| 233 | * -word-list-path tomatch.txt* | .{0,1000}\s\-word\-list\-path\stomatch\.txt.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 3752 |
| 234 | *"ADWS request with ldapbase (* | .{0,1000}\"ADWS\srequest\swith\sldapbase\s\(.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | #content | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 3819 |
| 235 | *"C:\Windows\system32\ARP.EXE" /a* | .{0,1000}\"C\:\\Windows\\system32\\ARP\.EXE\"\s\/a.{0,1000} | greyware_tool_keyword | arp | Arp displays and modifies information about a system's Address Resolution Protocol (ARP) cache | T1018 | TA0007 | N/A | Turla - APT32 - Orangeworm | Discovery | N/A | 1 | 0 | N/A | N/A | 5 | 7 | N/A | N/A | N/A | N/A | 3825 |
| 236 | *"Dump BH data"* | .{0,1000}\"Dump\sBH\sdata\".{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | #content | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 3836 |
| 237 | *"samaccounttype=268435456)(samaccounttype=268435457)(samaccounttype=536870912)(samaccounttype=536870913)* | .{0,1000}\"samaccounttype\=268435456\)\(samaccounttype\=268435457\)\(samaccounttype\=536870912\)\(samaccounttype\=536870913\).{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://thedfirreport.com/2024/08/26/blacksuit-ransomware/ | 1 | 0 | N/A | N/A | N/A | 7 | N/A | N/A | N/A | N/A | 3866 |
| 238 | *# @oldboy21* | .{0,1000}\#\s\s\@oldboy21.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 3883 |
| 239 | *# Minimalistic TCP and UDP port scanners* | .{0,1000}\#\sMinimalistic\sTCP\sand\sUDP\sport\sscanners.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 0 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 3901 |
| 240 | *$ADelegReport* | .{0,1000}\$ADelegReport.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 3939 |
| 241 | *$adPEAS_* | .{0,1000}\$adPEAS_.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | #content | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 3940 |
| 242 | *$attacker_IPlist* | .{0,1000}\$attacker_IPlist.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 0 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 3942 |
| 243 | *$base64adrecon* | .{0,1000}\$base64adrecon.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | #content | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 3945 |
| 244 | *$EmptyPasswordUsers* | .{0,1000}\$EmptyPasswordUsers.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 0 | N/A | N/A | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 3960 |
| 245 | *$InsecureResourceDelegations* | .{0,1000}\$InsecureResourceDelegations.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 3986 |
| 246 | *$InsecureTrusteeDelegations* | .{0,1000}\$InsecureTrusteeDelegations.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 3987 |
| 247 | *$PotentialComputersWithEmptyPassword* | .{0,1000}\$PotentialComputersWithEmptyPassword.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 0 | N/A | simple backdoor with anydesk | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 4007 |
| 248 | *$PotentialUsersWithEmptyPassword* | .{0,1000}\$PotentialUsersWithEmptyPassword.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 0 | N/A | simple backdoor with anydesk | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 4008 |
| 249 | *$SprayEmptyPasswords* | .{0,1000}\$SprayEmptyPasswords.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 0 | N/A | N/A | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 4017 |
| 250 | *(!soaphound=* | .{0,1000}\(!soaphound\=.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | #ldap | ioc in ldap query https://github.com/FalconForceTeam/SOAPHound/blob/818a0b5add9d70c3d210f0ddcde781a85cd0cba2/ADWSUtils.cs#L42C21-L42C30 | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 4052 |
| 251 | *(&(&(objectCategory=person)(objectClass=user))(|(description=*pass*)(comment=*pass*)))* | .{0,1000}\(\&\(\&\(objectCategory\=person\)\(objectClass\=user\)\)\(\|\(description\=.{0,1000}pass.{0,1000}\)\(comment\=.{0,1000}pass.{0,1000}\)\)\).{0,1000} | greyware_tool_keyword | ldap queries | metasploit enum_ad_user_comments | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/hunting-for-reconnaissance-activities-using-ldap-search-filters/ba-p/824726 | 1 | 0 | N/A | N/A | 8 | 4 | N/A | N/A | N/A | N/A | 4053 |
| 252 | *(&(objectCategory=computer)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(!(userAccountControl:1.2.840.113556.1.4.803:=8192))(!(userAccountControl:1.2.840.113556.1.4.803:=67100867)))* | .{0,1000}\(\&\(objectCategory\=computer\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=8192\)\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=67100867\)\)\).{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/mitchmoser/SharpShares | 1 | 0 | N/A | N/A | 10 | 4 | 351 | 49 | 2021-09-21T08:14:27Z | 2020-09-25T22:35:57Z | 4054 |
| 253 | *(&(objectCategory=computer)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(operatingSystem=*server*)(!(userAccountControl:1.2.840.113556.1.4.803:=8192))(!(userAccountControl:1.2.840.113556.1.4.803:=67100867)))* | .{0,1000}\(\&\(objectCategory\=computer\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(operatingSystem\=.{0,1000}server.{0,1000}\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=8192\)\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=67100867\)\)\).{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/mitchmoser/SharpShares | 1 | 0 | N/A | N/A | 10 | 4 | 351 | 49 | 2021-09-21T08:14:27Z | 2020-09-25T22:35:57Z | 4055 |
| 254 | *(&(objectCategory=computer)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(userAccountControl:1.2.840.113556.1.4.803:=8192))* | .{0,1000}\(\&\(objectCategory\=computer\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=8192\)\).{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/mitchmoser/SharpShares | 1 | 0 | N/A | N/A | 10 | 4 | 351 | 49 | 2021-09-21T08:14:27Z | 2020-09-25T22:35:57Z | 4056 |
| 255 | *(&(objectCategory=computer)(msDS-isRODC=TRUE))* | .{0,1000}\(\&\(objectCategory\=computer\)\(msDS\-isRODC\=TRUE\)\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate Read-Only Domain Controllers (RODC) | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/mthcht/ThreatHunting-Keywords | 1 | 0 | N/A | N/A | 8 | 6 | 563 | 61 | 2025-03-03T15:48:41Z | 2023-05-16T15:38:26Z | 4057 |
| 256 | *(&(objectCategory=computer)(ms-MCS-AdmPwd=*)(sAMAccountName=" + target + "))* | .{0,1000}\(\&\(objectCategory\=computer\)\(ms\-MCS\-AdmPwd\=.{0,1000}\)\(sAMAccountName\=\"\s\+\starget\s\+\s\"\)\).{0,1000} | greyware_tool_keyword | ldap queries | LAPS passwords (from SharpLAPS) | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4058 |
| 257 | *(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=65536)(memberOf=CN=Administrators* | .{0,1000}\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=65536\)\(memberOf\=CN\=Administrators.{0,1000} | greyware_tool_keyword | ldap queries | Enumerate Accounts with Non-Expiring Passwords and Administrative Privileges | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/mthcht/ThreatHunting-Keywords | 1 | 0 | N/A | N/A | 8 | 6 | 563 | 61 | 2025-03-03T15:48:41Z | 2023-05-16T15:38:26Z | 4059 |
| 258 | *(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=65536)* | .{0,1000}\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=65536\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate all users with the account configuration 'Password never expires' | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4060 |
| 259 | *(&(objectClass=group)(managedBy=*)(groupType:1.2.840.113556.1.4.803:=2147483648))* | .{0,1000}\(\&\(objectClass\=group\)\(managedBy\=.{0,1000}\)\(groupType\:1\.2\.840\.113556\.1\.4\.803\:\=2147483648\)\).{0,1000} | greyware_tool_keyword | ldap queries | metasploit enum_ad_managedby_groups.rb | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/rapid7/metasploit-framework/blob/d37a82500d1d08f9d8ab3da9b194653835748fae/modules/post/windows/gather/enum_ad_managedby_groups.rb#L59 | 1 | 0 | N/A | N/A | 8 | 10 | 35400 | 14272 | 2025-04-22T20:14:59Z | 2011-08-30T06:13:20Z | 4061 |
| 260 | *(&(objectclass=group)(samaccountname=*domain admins*))* | .{0,1000}\(\&\(objectclass\=group\)\(samaccountname\=.{0,1000}domain\sadmins.{0,1000}\)\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate Domain Administrators Group | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca384 | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4062 |
| 261 | *(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))(!msds-supportedencryptiontypes:1.2.840.113556.1.4.804:=24))* | .{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(!msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.804\:\=24\)\).{0,1000} | greyware_tool_keyword | ldap queries | Kerberoasting | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4063 |
| 262 | *(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))(msds-supportedencryptiontypes:1.2.840.113556.1.4.804:=24))* | .{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.804\:\=24\)\).{0,1000} | greyware_tool_keyword | ldap queries | Kerberoasting | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4064 |
| 263 | *(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))* | .{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\).{0,1000} | greyware_tool_keyword | ldap queries | Kerberoasting | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4065 |
| 264 | *([adsisearcher]'(&(objectCategory=computer)(!(primaryGroupID=516)(userAccountControl:1.2.840.113556.1.4.803:=524288)))').FindAll()* | .{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=computer\)\(!\(primaryGroupID\=516\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=524288\)\)\)\'\)\.FindAll\(\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate all servers configured for Unconstrained Delegation | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | N/A | 1 | 0 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 4067 |
| 265 | *([adsisearcher]'(&(objectCategory=computer)(userAccountControl:1.2.840.113556.1.4.803:=8192))').FindAll()* | .{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=computer\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=8192\)\)\'\)\.FindAll\(\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate all Domain Controllers | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://web.archive.org/web/20240109000256/https://cyberdom.blog/2024/01/07/defender-for-identity-hunting-for-ldap/ | 1 | 0 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 4068 |
| 266 | *([adsisearcher]'(&(objectCategory=user)(!(samAccountName=krbtgt)(servicePrincipalName=*)))').FindAll()* | .{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=user\)\(!\(samAccountName\=krbtgt\)\(servicePrincipalName\=.{0,1000}\)\)\)\'\)\.FindAll\(\).{0,1000} | greyware_tool_keyword | ldap queries | Search for user accounts with SPN but not TGT accounts | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca384 | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4069 |
| 267 | *([adsisearcher]'(adminCount=1)').FindAll()* | .{0,1000}\(\[adsisearcher\]\'\(adminCount\=1\)\'\)\.FindAll\(\).{0,1000} | greyware_tool_keyword | ldap queries | Search for all objects with AdminSHHolder | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca384 | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4070 |
| 268 | *([DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest()).Domains* | .{0,1000}\(\[DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\)\.Domains.{0,1000} | greyware_tool_keyword | ldap queries | Queries for domain level and mode information | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 4071 |
| 269 | *([DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest()).Sites | * | .{0,1000}\(\[DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\)\.Sites\s\|\s.{0,1000} | greyware_tool_keyword | ldap queries | enumeration of AD Forest Sites | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 4072 |
| 270 | *([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).FindAllDomainControllers() | Select-Object -Property * | .{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.FindAllDomainControllers\(\)\s\|\sSelect\-Object\s\-Property\s.{0,1000} | greyware_tool_keyword | ldap queries | querying all domain controllers with detailed properties | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 4073 |
| 271 | *([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()* | .{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.GetAllTrustRelationships\(\).{0,1000} | greyware_tool_keyword | ldap queries | get all trust relationships in the current domain | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 4074 |
| 272 | *([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()* | .{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.GetAllTrustRelationships\(\).{0,1000} | greyware_tool_keyword | powershell | Powershell enumerate domains and forests | T1482 - T1069.002 | TA0007 - TA0008 | N/A | Black Basta | Discovery | https://medium.com/@simone.kraus/black-basta-playbook-chat-leak-d5036936166d | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4075 |
| 273 | *(Get-ADForest).Domains | %{ Get-ADDomainController -Filter * -Server $_ }* | .{0,1000}\(Get\-ADForest\)\.Domains\s\|\s\%\{\sGet\-ADDomainController\s\-Filter\s.{0,1000}\s\-Server\s\$_\s\}.{0,1000} | greyware_tool_keyword | ldap queries | Enumerate all of the domain controllers for all domains in a forest | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | N/A | 1 | 0 | N/A | N/A | 6 | 6 | N/A | N/A | N/A | N/A | 4077 |
| 274 | *(msds-supportedencryptiontypes=0)(msds-supportedencryptiontypes:1.2.840.113556.1.4.803:=4)))* | .{0,1000}\(msds\-supportedencryptiontypes\=0\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.803\:\=4\)\)\).{0,1000} | greyware_tool_keyword | ldap queries | used by Rubeus and S4UTomato tools | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4081 |
| 275 | *(objectCategory=person)(objectClass=user)(serviceAccount=TRUE)* | .{0,1000}\(objectCategory\=person\)\(objectClass\=user\)\(serviceAccount\=TRUE\).{0,1000} | greyware_tool_keyword | ldap queries | Query to find service accounts which are typically high-privileged and targeted for privilege escalation | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/mthcht/ThreatHunting-Keywords | 1 | 0 | N/A | N/A | 8 | 6 | 563 | 61 | 2025-03-03T15:48:41Z | 2023-05-16T15:38:26Z | 4085 |
| 276 | *(objectclass=group)(samaccountname=domain admins)* | .{0,1000}\(objectclass\=group\)\(samaccountname\=domain\sadmins\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate Domain Admins | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4086 |
| 277 | *(userAccountControl:1.2.840.113556.1.4.803:=524288)* | .{0,1000}\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=524288\).{0,1000} | greyware_tool_keyword | ldap queries | Accounts Trusted for Delegation | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4091 |
| 278 | *./AutoSUID.sh* | .{0,1000}\.\/AutoSUID\.sh.{0,1000} | offensive_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 7 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4105 |
| 279 | *./capsh --gid=0 --uid=0 --* | .{0,1000}\.\/capsh\s\-\-gid\=0\s\-\-uid\=0\s\-\-.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4112 |
| 280 | *./chroot / /bin/sh -p* | .{0,1000}\.\/chroot\s\/\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4115 |
| 281 | *./env /bin/sh -p* | .{0,1000}\.\/env\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4131 |
| 282 | *./expect -c 'spawn /bin/sh -p;interact'* | .{0,1000}\.\/expect\s\-c\s\'spawn\s\/bin\/sh\s\-p\;interact\'.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4134 |
| 283 | *./flock -u / /bin/sh -p* | .{0,1000}\.\/flock\s\-u\s\/\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4139 |
| 284 | *./nice /bin/sh -p* | .{0,1000}\.\/nice\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4171 |
| 285 | *./nmap* | .{0,1000}\.\/nmap.{0,1000} | greyware_tool_keyword | nmap | A very common tool. Network host vuln and port detector. | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap | 1 | 1 | #linux | greyware tool - risks of False positive ! | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 4173 |
| 286 | *./rview -c ':py3 import os*os.execl(\"/bin/sh\* | .{0,1000}\.\/rview\s\-c\s\'\:py3\simport\sos.{0,1000}os\.execl\(\\\"\/bin\/sh\\.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 4195 |
| 287 | *.exe /HistorySource 1 /SaveDirect /scomma * | .{0,1000}\.exe\s\s\/HistorySource\s1\s\/SaveDirect\s\/scomma\s.{0,1000} | offensive_tool_keyword | BrowsingHistoryView | BrowsingHistoryView is a utility that reads the history data of different Web browsers | T1217 - T1070 - T1113 | TA0009 - TA0005 - TA0007 | N/A | GOBLIN PANDA | Discovery | https://www.nirsoft.net/utils/browsing_history_view.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4317 |
| 288 | *.exe --buildcache -c *\cache.txt* | .{0,1000}\.exe\s\s\-\-buildcache\s\-c\s.{0,1000}\\cache\.txt.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 4320 |
| 289 | *.exe * /hide * /range:* /auto:*.* | .{0,1000}\.exe\s.{0,1000}\s\/hide\s.{0,1000}\s\/range\:.{0,1000}\s\/auto\:.{0,1000}\..{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4325 |
| 290 | *.exe /hide /range:all* | .{0,1000}\.exe\s\/hide\s\/range\:all.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4334 |
| 291 | *.exe /HistorySource 1 /LoadChrome 1 /shtml * | .{0,1000}\.exe\s\/HistorySource\s1\s\/LoadChrome\s1\s\/shtml\s.{0,1000} | offensive_tool_keyword | BrowsingHistoryView | BrowsingHistoryView is a utility that reads the history data of different Web browsers | T1217 - T1070 - T1113 | TA0009 - TA0005 - TA0007 | N/A | GOBLIN PANDA | Discovery | https://www.nirsoft.net/utils/browsing_history_view.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4335 |
| 292 | *.exe /s:ip_ranges.txt /f:scan_results.txt* | .{0,1000}\.exe\s\/s\:ip_ranges\.txt\s\/f\:scan_results\.txt.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 4347 |
| 293 | *.exe /wakeall* | .{0,1000}\.exe\s\/wakeall.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 4348 |
| 294 | *.exe acl -dn * -scope * -trustee * | .{0,1000}\.exe\sacl\s\-dn\s.{0,1000}\s\-scope\s.{0,1000}\s\-trustee\s.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 4350 |
| 295 | *.exe --ACLScan * --OU * | .{0,1000}\.exe\s\-\-ACLScan\s.{0,1000}\s\-\-OU\s.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 0 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 4351 |
| 296 | *.exe --asrep | .{0,1000}\.exe\s\-\-asrep | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 4384 |
| 297 | *.exe Certify -action find -enrolleeSuppliesSubject -clientAuth* | .{0,1000}\.exe\sCertify\s\-action\sfind\s\-enrolleeSuppliesSubject\s\-clientAuth.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 4402 |
| 298 | *.exe Certify -action find* | .{0,1000}\.exe\sCertify\s\-action\sfind.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 4403 |
| 299 | *.exe --CollectionMethods Session --Loop* | .{0,1000}\.exe\s\-\-CollectionMethods\sSession\s\-\-Loop.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 4406 |
| 300 | *.exe -d * -u * -p * -m LDAPS* | .{0,1000}\.exe\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sLDAPS.{0,1000} | offensive_tool_keyword | SharpLdapRelayScan | SharLdapRealyScan is a tool to check Domain Controllers for LDAP server protections regarding the relay of NTLM authenticationvand it's a C# port of?LdapRelayScan | T1557.001 - T1078.003 - T1046 | TA0002 - TA0007 - TA0040 | N/A | N/A | Discovery | https://github.com/klezVirus/SharpLdapRelayScan | 1 | 0 | N/A | network exploitation tool | 7 | 1 | 81 | 18 | 2022-02-26T22:03:11Z | 2022-02-12T08:16:59Z | 4419 |
| 301 | *.exe DCSync -action list* | .{0,1000}\.exe\sDCSync\s\-action\slist.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 4422 |
| 302 | *.exe DCSync -action write -target * | .{0,1000}\.exe\sDCSync\s\-action\swrite\s\-target\s.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 4423 |
| 303 | *.exe DontReqPreAuth -action list* | .{0,1000}\.exe\sDontReqPreAuth\s\-action\slist.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 4427 |
| 304 | *.exe DontReqPreAuth -action write -target * | .{0,1000}\.exe\sDontReqPreAuth\s\-action\swrite\s\-target\s.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 4428 |
| 305 | *.exe -gcb -sc trustdmp > * | .{0,1000}\.exe\s\-gcb\s\-sc\strustdmp\s\>\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 4443 |
| 306 | *.exe Get-DomainController -Domain * -Server * -Credential * | .{0,1000}\.exe\sGet\-DomainController\s\-Domain\s.{0,1000}\s\-Server\s.{0,1000}\s\-Credential\s.{0,1000} | offensive_tool_keyword | SharpView | C# implementation of harmj0y's PowerView | T1018 - T1482 - T1087.002 - T1069.002 | TA0007 - TA0003 - TA0001 | N/A | Conti - APT29 | Discovery | https://github.com/tevora-threat/SharpView/ | 1 | 0 | N/A | N/A | 10 | 10 | 1032 | 196 | 2024-03-22T16:34:09Z | 2018-07-24T21:15:04Z | 4444 |
| 307 | *.exe --gpo --filter admin --domain* | .{0,1000}\.exe\s\-\-gpo\s\-\-filter\sadmin\s\-\-domain.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 4459 |
| 308 | *.exe --LDAPs --DisableSigning* | .{0,1000}\.exe\s\-\-LDAPs\s\-\-DisableSigning.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 0 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 4515 |
| 309 | *.exe --list-vulns* | .{0,1000}\.exe\s\-\-list\-vulns.{0,1000} | offensive_tool_keyword | Moriarty | Moriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments. | T1068 - T1083 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/BC-SECURITY/Moriarty | 1 | 0 | N/A | N/A | 7 | 6 | 510 | 67 | 2024-08-07T15:06:31Z | 2023-12-11T14:15:33Z | 4518 |
| 310 | *.exe RBCD -action read -delegate-to * | .{0,1000}\.exe\sRBCD\s\-action\sread\s\-delegate\-to\s.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 4582 |
| 311 | *.exe -sc adinfo > * | .{0,1000}\.exe\s\-sc\sadinfo\s\>\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 4598 |
| 312 | *.exe -sc dclist > * | .{0,1000}\.exe\s\-sc\sdclist\s\>\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 4599 |
| 313 | *.exe -sc getacls -sddlfilter * | .{0,1000}\.exe\s\-sc\sgetacls\s\-sddlfilter\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 4600 |
| 314 | *.exe -sc trustdmp > * | .{0,1000}\.exe\s\-sc\strustdmp\s\>\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 4601 |
| 315 | *.exe --showstats -c *\cache.txt* | .{0,1000}\.exe\s\-\-showstats\s\-c\s.{0,1000}\\cache\.txt.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 4610 |
| 316 | *.exe --spn --domain * --user * --pass * | .{0,1000}\.exe\s\-\-spn\s\-\-domain\s.{0,1000}\s\-\-user\s.{0,1000}\s\-\-pass\s.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 4619 |
| 317 | *.exe -subnets -f (objectCategory=subnet) > * | .{0,1000}\.exe\s\-subnets\s\-f\s\(objectCategory\=subnet\)\s\>\s.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 4623 |
| 318 | *.exe Whisker -action add -target * -cert-pass * | .{0,1000}\.exe\sWhisker\s\-action\sadd\s\-target\s.{0,1000}\s\-cert\-pass\s.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 4641 |
| 319 | *.exe Whisker -action list -target * | .{0,1000}\.exe\sWhisker\s\-action\slist\s\-target\s.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 4642 |
| 320 | *.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation * | .{0,1000}\.NET\spost\-exploitation\stoolkit\sfor\sActive\sDirectory\sreconnaissance\sand\sexploitation\s.{0,1000} | offensive_tool_keyword | Cable | *.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation* | T1087 - T1016 - T1059 - T1482 - T1078 | TA0007 - TA0002 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/logangoins/Cable | 1 | 0 | #content | N/A | 7 | 4 | 361 | 40 | 2025-04-09T01:12:47Z | 2024-08-10T19:47:08Z | 4707 |
| 321 | *.powerview.ldap_session* | .{0,1000}\.powerview\.ldap_session.{0,1000} | offensive_tool_keyword | powerview | PowerView.py is an alternative for the awesome original PowerView.ps1 | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/aniqfakhrul/powerview.py | 1 | 0 | #content | N/A | 10 | 7 | 622 | 66 | 2025-04-22T09:01:39Z | 2022-06-19T16:13:04Z | 4738 |
| 322 | *.ps1 -Base *OU=*DC=* -Credentials * -Server * | .{0,1000}\.ps1\s\-Base\s.{0,1000}OU\=.{0,1000}DC\=.{0,1000}\s\-Credentials\s.{0,1000}\s\-Server\s.{0,1000} | offensive_tool_keyword | ADACLScanner | A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory . | T1222 - T1069 - T1018 | TA0002 - TA0007 - TA0043 | N/A | N/A | Discovery | https://github.com/canix1/ADACLScanner | 1 | 0 | N/A | AD Enumeration | 7 | 10 | 1015 | 173 | 2025-04-11T14:35:08Z | 2017-04-06T12:28:37Z | 4759 |
| 323 | *.py --cached --ntuser NTUSER.DAT* | .{0,1000}\.py\s\-\-cached\s\-\-ntuser\sNTUSER\.DAT.{0,1000} | offensive_tool_keyword | LocalShellExtParse | Script to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User. | T1547.009 - T1129 | TA0003 - TA0007 | N/A | N/A | Discovery | https://github.com/herrcore/LocalShellExtParse | 1 | 0 | N/A | N/A | 9 | 1 | 20 | 4 | 2015-06-08T16:55:38Z | 2015-06-05T03:23:13Z | 4816 |
| 324 | *.py --ntuser NTUSER.DAT --usrclass UsrClass.dat* | .{0,1000}\.py\s\-\-ntuser\sNTUSER\.DAT\s\-\-usrclass\sUsrClass\.dat.{0,1000} | offensive_tool_keyword | LocalShellExtParse | Script to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User. | T1547.009 - T1129 | TA0003 - TA0007 | N/A | N/A | Discovery | https://github.com/herrcore/LocalShellExtParse | 1 | 0 | N/A | N/A | 9 | 1 | 20 | 4 | 2015-06-08T16:55:38Z | 2015-06-05T03:23:13Z | 4840 |
| 325 | *.py -u * ?print-zones * | .{0,1000}\.py\s\-u\s.{0,1000}\s\?print\-zones\s.{0,1000} | offensive_tool_keyword | adidnsdump | By default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks. | T1018 - T1087 - T1201 - T1056 - T1039 | TA0005 - TA0009 | N/A | N/A | Discovery | https://github.com/dirkjanm/adidnsdump | 1 | 0 | N/A | N/A | N/A | 10 | 997 | 118 | 2025-04-04T09:28:20Z | 2019-04-24T17:18:46Z | 4847 |
| 326 | */.manspider/logs* | .{0,1000}\/\.manspider\/logs.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | #linux | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 5023 |
| 327 | */.manspider/loot* | .{0,1000}\/\.manspider\/loot.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | #linux | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 5024 |
| 328 | */.powerview/.powerview_history* | .{0,1000}\/\.powerview\/\.powerview_history.{0,1000} | offensive_tool_keyword | powerview | PowerView.py is an alternative for the awesome original PowerView.ps1 | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/aniqfakhrul/powerview.py | 1 | 0 | #linux | N/A | 10 | 7 | 622 | 66 | 2025-04-22T09:01:39Z | 2022-06-19T16:13:04Z | 5029 |
| 329 | */.powerview/logs* | .{0,1000}\/\.powerview\/logs.{0,1000} | offensive_tool_keyword | powerview | PowerView.py is an alternative for the awesome original PowerView.ps1 | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/aniqfakhrul/powerview.py | 1 | 0 | #linux | N/A | 10 | 7 | 622 | 66 | 2025-04-22T09:01:39Z | 2022-06-19T16:13:04Z | 5030 |
| 330 | */10m_usernames.txt* | .{0,1000}\/10m_usernames\.txt.{0,1000} | offensive_tool_keyword | ldapnomnom | Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP) | T1110.003 - T1205 | TA0007 | N/A | N/A | Discovery | https://github.com/lkarlslund/ldapnomnom | 1 | 0 | N/A | N/A | 6 | 10 | 1030 | 80 | 2024-11-09T10:15:13Z | 2022-09-18T10:35:09Z | 5080 |
| 331 | */Accomplice.git* | .{0,1000}\/Accomplice\.git.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 1 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 5106 |
| 332 | */ACLight.git* | .{0,1000}\/ACLight\.git.{0,1000} | offensive_tool_keyword | ACLight | A tool for advanced discovery of Privileged Accounts - including Shadow Admins. | T1087 - T1003 - T1208 | TA0001 - TA0006 - TA0008 | N/A | N/A | Discovery | https://github.com/cyberark/ACLight | 1 | 1 | N/A | AD Enumeration | 7 | 9 | 801 | 146 | 2019-09-09T06:48:45Z | 2017-05-17T09:29:41Z | 5115 |
| 333 | */ACLight/* | .{0,1000}\/ACLight\/.{0,1000} | offensive_tool_keyword | ACLight | A tool for advanced discovery of Privileged Accounts - including Shadow Admins. | T1087 - T1003 - T1208 | TA0001 - TA0006 - TA0008 | N/A | N/A | Discovery | https://github.com/cyberark/ACLight | 1 | 1 | N/A | N/A | N/A | 9 | 801 | 146 | 2019-09-09T06:48:45Z | 2017-05-17T09:29:41Z | 5116 |
| 334 | */ActiveScanPlusPlus* | .{0,1000}\/ActiveScanPlusPlus.{0,1000} | offensive_tool_keyword | ActiveScanPlusPlus | ActiveScan++ extends Burp Suite's active and passive scanning capabilities. Designed to add minimal network overhead. it identifies application behaviour that may be of interest to advanced testers | T1583 - T1595 - T1190 | TA0001 - TA0002 - TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/albinowax/ActiveScanPlusPlus | 1 | 1 | N/A | network exploitation tool | N/A | 7 | 630 | 195 | 2025-04-17T10:47:54Z | 2014-06-23T10:04:13Z | 5124 |
| 335 | */AD_Enumeration_Hunt* | .{0,1000}\/AD_Enumeration_Hunt.{0,1000} | offensive_tool_keyword | AD_Enumeration_Hunt | This repository contains a collection of PowerShell scripts and commands that can be used for Active Directory (AD) penetration testing and security assessment | T1018 - T1003 - T1033 - T1087 - T1069 - T1046 - T1069.002 - T1047 - T1083 | TA0001 - TA0007 - TA0005 - TA0002 - TA0003 | N/A | N/A | Discovery | https://github.com/alperenugurlu/AD_Enumeration_Hunt | 1 | 1 | N/A | AD Enumeration | 7 | 1 | 93 | 18 | 2023-08-05T06:10:26Z | 2023-08-05T05:16:57Z | 5125 |
| 336 | */AD_Miner.git* | .{0,1000}\/AD_Miner\.git.{0,1000} | offensive_tool_keyword | AD_Miner | AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses | T1087.002 - T1069 - T1018 - T1595 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/Mazars-Tech/AD_Miner | 1 | 1 | N/A | AD Enumeration | 7 | 10 | 1290 | 131 | 2025-03-12T10:53:09Z | 2023-09-26T12:36:59Z | 5126 |
| 337 | */AD_Miner.git* | .{0,1000}\/AD_Miner\.git.{0,1000} | greyware_tool_keyword | AD_Miner | AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses | T1482 - T1069 - T1087 | TA0007 | N/A | EMBER BEAR | Discovery | https://github.com/Mazars-Tech/AD_Miner | 1 | 1 | N/A | N/A | 6 | 10 | 1290 | 131 | 2025-03-12T10:53:09Z | 2023-09-26T12:36:59Z | 5127 |
| 338 | */AD_Miner/releases/* | .{0,1000}\/AD_Miner\/releases\/.{0,1000} | greyware_tool_keyword | AD_Miner | AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses | T1482 - T1069 - T1087 | TA0007 | N/A | EMBER BEAR | Discovery | https://github.com/Mazars-Tech/AD_Miner | 1 | 1 | N/A | N/A | 6 | 10 | 1290 | 131 | 2025-03-12T10:53:09Z | 2023-09-26T12:36:59Z | 5128 |
| 339 | */ADACLScanner.git* | .{0,1000}\/ADACLScanner\.git.{0,1000} | offensive_tool_keyword | ADACLScanner | A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory . | T1222 - T1069 - T1018 | TA0002 - TA0007 - TA0043 | N/A | N/A | Discovery | https://github.com/canix1/ADACLScanner | 1 | 1 | N/A | AD Enumeration | 7 | 10 | 1015 | 173 | 2025-04-11T14:35:08Z | 2017-04-06T12:28:37Z | 5129 |
| 340 | */adalanche/modules/* | .{0,1000}\/adalanche\/modules\/.{0,1000} | offensive_tool_keyword | adalanche | Active Directory ACL Visualizer and Explorer - who's really Domain Admin? | T1484 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/lkarlslund/Adalanche | 1 | 1 | N/A | AD Enumeration | 10 | 10 | 1908 | 184 | 2025-03-25T13:01:45Z | 2020-10-07T10:07:22Z | 5130 |
| 341 | */adaudit.git* | .{0,1000}\/adaudit\.git.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 1 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 5137 |
| 342 | */adaudit.git* | .{0,1000}\/adaudit\.git.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 1 | N/A | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 5138 |
| 343 | */ADAudit.ps1* | .{0,1000}\/ADAudit\.ps1.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 1 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 5139 |
| 344 | */adaudit.ps1* | .{0,1000}\/adaudit\.ps1.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 1 | N/A | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 5140 |
| 345 | */ADcheck.git* | .{0,1000}\/ADcheck\.git.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 1 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 5141 |
| 346 | */ADcheck.py* | .{0,1000}\/ADcheck\.py.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 1 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 5142 |
| 347 | */ADCollector.exe* | .{0,1000}\/ADCollector\.exe.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 1 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 5143 |
| 348 | */ADCollector.git* | .{0,1000}\/ADCollector\.git.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 1 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 5146 |
| 349 | */AD-common-queries.git* | .{0,1000}\/AD\-common\-queries\.git.{0,1000} | greyware_tool_keyword | AD-common-queries | Collection of common ADSI queries for Domain Account enumeration | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 1 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 5147 |
| 350 | */adcshunter.git* | .{0,1000}\/adcshunter\.git.{0,1000} | offensive_tool_keyword | adcshunter | Uses rpcdump to locate the ADCS server and identify if ESC8 is vulnerable from unauthenticated perspective. | T1018 - T1087 - T1046 - T1201 - T1595 | TA0007 - TA0043 | N/A | N/A | Discovery | https://github.com/danti1988/adcshunter | 1 | 1 | N/A | N/A | 7 | 1 | 80 | 7 | 2024-09-13T12:50:50Z | 2023-12-14T14:31:05Z | 5159 |
| 351 | */ADeleg.exe* | .{0,1000}\/ADeleg\.exe.{0,1000} | offensive_tool_keyword | adeleg | an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest | T1595 - T1087.002 - T1069.002 | TA0007 - TA0004 | N/A | N/A | Discovery | https://github.com/mtth-bfft/adeleg | 1 | 1 | N/A | N/A | 8 | 3 | 294 | 31 | 2023-06-07T15:08:53Z | 2022-02-09T19:47:04Z | 5181 |
| 352 | */ADeleg.exe* | .{0,1000}\/ADeleg\.exe.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 1 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 5182 |
| 353 | */adeleg.git* | .{0,1000}\/adeleg\.git.{0,1000} | offensive_tool_keyword | adeleg | an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest | T1595 - T1087.002 - T1069.002 | TA0007 - TA0004 | N/A | N/A | Discovery | https://github.com/mtth-bfft/adeleg | 1 | 1 | N/A | N/A | 8 | 3 | 294 | 31 | 2023-06-07T15:08:53Z | 2022-02-09T19:47:04Z | 5183 |
| 354 | */adeleg.pdb* | .{0,1000}\/adeleg\.pdb.{0,1000} | offensive_tool_keyword | adeleg | an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest | T1595 - T1087.002 - T1069.002 | TA0007 - TA0004 | N/A | N/A | Discovery | https://github.com/mtth-bfft/adeleg | 1 | 1 | N/A | N/A | 8 | 3 | 294 | 31 | 2023-06-07T15:08:53Z | 2022-02-09T19:47:04Z | 5184 |
| 355 | */ADeleginator.git* | .{0,1000}\/ADeleginator\.git.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 1 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 5185 |
| 356 | */AdFind.zip* | .{0,1000}\/AdFind\.zip.{0,1000} | greyware_tool_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5186 |
| 357 | */ADGet.exe* | .{0,1000}\\ADGet\.exe.{0,1000} | greyware_tool_keyword | adget | gather valuable informations about the AD environment | T1018 - T1027 - T1046 - T1057 - T1069 - T1087 - T1098 - T1482 | TA0001 - TA0002 - TA0003 - TA0007 - TA0011 | N/A | N/A | Discovery | https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/ | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 5198 |
| 358 | */ADHunt.git* | .{0,1000}\/ADHunt\.git.{0,1000} | offensive_tool_keyword | adhunt | Tool for exploiting Active Directory Enviroments - enumeration | T1018 - T1087 - T1087.002 - T1069 - T1069.002 | TA0007 - TA0003 - TA0001 | N/A | N/A | Discovery | https://github.com/karendm/ADHunt | 1 | 1 | N/A | AD Enumeration | 7 | 1 | 46 | 10 | 2023-08-10T18:55:39Z | 2023-06-20T13:24:10Z | 5199 |
| 359 | */adhunt.py* | \/adhunt\.py | offensive_tool_keyword | adhunt | Tool for exploiting Active Directory Enviroments - enumeration | T1018 - T1087 - T1087.002 - T1069 - T1069.002 | TA0007 - TA0003 - TA0001 | N/A | N/A | Discovery | https://github.com/karendm/ADHunt | 1 | 1 | N/A | AD Enumeration | 7 | 1 | 46 | 10 | 2023-08-10T18:55:39Z | 2023-06-20T13:24:10Z | 5200 |
| 360 | */adidnsdump.git* | .{0,1000}\/adidnsdump\.git.{0,1000} | offensive_tool_keyword | adidnsdump | By default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks. | T1018 - T1087 - T1201 - T1056 - T1039 | TA0005 - TA0009 | N/A | N/A | Discovery | https://github.com/dirkjanm/adidnsdump | 1 | 1 | N/A | N/A | N/A | 10 | 997 | 118 | 2025-04-04T09:28:20Z | 2019-04-24T17:18:46Z | 5201 |
| 361 | */ad-ldap-enum.git* | .{0,1000}\/ad\-ldap\-enum\.git.{0,1000} | offensive_tool_keyword | ad-ldap-enum | An LDAP based Active Directory user and group enumeration tool | T1087 - T1087.001 - T1018 - T1069 - T1069.002 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/CroweCybersecurity/ad-ldap-enum | 1 | 1 | N/A | AD Enumeration | 6 | 4 | 308 | 66 | 2023-02-10T19:07:34Z | 2015-08-25T19:38:39Z | 5202 |
| 362 | */adlogin.ps1* | .{0,1000}\/adlogin\.ps1.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 1 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 5203 |
| 363 | */adPEAS.git* | .{0,1000}\/adPEAS\.git.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 1 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 5209 |
| 364 | */adPEAS.ps1* | .{0,1000}\/adPEAS\.ps1.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 1 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 5210 |
| 365 | */adPEAS-Light.ps1* | .{0,1000}\/adPEAS\-Light\.ps1.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 1 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 5211 |
| 366 | */ADRecon.git* | .{0,1000}\/ADRecon\.git.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 5213 |
| 367 | */ADRecon.ps1* | .{0,1000}\/ADRecon\.ps1.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 1 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 5214 |
| 368 | */Advanced_Port_Scanner_*.exe* | .{0,1000}\/Advanced_Port_Scanner_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 5218 |
| 369 | */AppFiles/ipscan.exe* | .{0,1000}\/AppFiles\/ipscan\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 5382 |
| 370 | */asreproast_hashes_*.txt* | .{0,1000}\/asreproast_hashes_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 5424 |
| 371 | */AutoSUID.git* | .{0,1000}\/AutoSUID\.git.{0,1000} | offensive_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 1 | N/A | N/A | 7 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 5493 |
| 372 | */Azure-AccessPermissions.git* | .{0,1000}\/Azure\-AccessPermissions\.git.{0,1000} | offensive_tool_keyword | Azure-AccessPermissions | Easy to use PowerShell script to enumerate access permissions in an Azure Active Directory environment. | T1087.002 - T1018 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/csandker/Azure-AccessPermissions | 1 | 1 | N/A | AD Enumeration | 6 | 2 | 108 | 18 | 2023-02-21T06:46:24Z | 2022-10-19T10:33:24Z | 5512 |
| 373 | */AzureHound.ps1* | .{0,1000}\/AzureHound\.ps1.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 1 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 5514 |
| 374 | */backdoored-script.ps1* | .{0,1000}\/backdoored\-script\.ps1.{0,1000} | offensive_tool_keyword | Graphpython | Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/Graphpython | 1 | 1 | N/A | N/A | 7 | 2 | 145 | 13 | 2024-12-07T21:54:00Z | 2024-07-10T00:04:48Z | 5531 |
| 375 | */beacon_202_no_acl.log* | .{0,1000}\/beacon_202_no_acl\.log.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 1 | #logfile #linux | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 5578 |
| 376 | */beacon_257-objects.log* | .{0,1000}\/beacon_257\-objects\.log.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 0 | #linux | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 5579 |
| 377 | */bhqc.py -* | .{0,1000}\/bhqc\.py\s\-.{0,1000} | offensive_tool_keyword | bloodhound-quickwin | Simple script to extract useful informations from the combo BloodHound + Neo4j | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/kaluche/bloodhound-quickwin | 1 | 0 | N/A | AD Enumeration | 6 | 3 | 239 | 26 | 2025-04-04T05:11:46Z | 2021-02-16T16:04:16Z | 5615 |
| 378 | */bin/pspsy* | .{0,1000}\/bin\/pspsy.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 0 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 5642 |
| 379 | */BloodHound.exe* | .{0,1000}\/BloodHound\.exe.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 1 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 5712 |
| 380 | */BloodHound.git* | .{0,1000}\/BloodHound\.git.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 1 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 5713 |
| 381 | */bloodhound/enumeration* | .{0,1000}\/bloodhound\/enumeration.{0,1000} | offensive_tool_keyword | BloodHound | A Python based ingestor for BloodHound | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/fox-it/BloodHound.py | 1 | 1 | N/A | N/A | 10 | 10 | 2088 | 343 | 2025-03-28T11:19:13Z | 2018-02-26T14:44:20Z | 5716 |
| 382 | */bloodhound_domain.py* | .{0,1000}\/bloodhound_domain\.py.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 1 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 5717 |
| 383 | */bloodhound_domaintrust.py* | .{0,1000}\/bloodhound_domaintrust\.py.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 1 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 5718 |
| 384 | */bloodhound_gpo.py* | .{0,1000}\/bloodhound_gpo\.py.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 1 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 5719 |
| 385 | */bloodhound_object.py* | .{0,1000}\/bloodhound_object\.py.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 1 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 5720 |
| 386 | */bloodhound_ou.py* | .{0,1000}\/bloodhound_ou\.py.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 1 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 5721 |
| 387 | */bloodhound_schema.py* | .{0,1000}\/bloodhound_schema\.py.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 1 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 5722 |
| 388 | */bloodhound-data* | .{0,1000}\/bloodhound\-data.{0,1000} | offensive_tool_keyword | BloodHound | A Python based ingestor for BloodHound | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/fox-it/BloodHound.py | 1 | 1 | N/A | N/A | 10 | 10 | 2088 | 343 | 2025-03-28T11:19:13Z | 2018-02-26T14:44:20Z | 5723 |
| 389 | */bloodhound-quickwin.git* | .{0,1000}\/bloodhound\-quickwin\.git.{0,1000} | offensive_tool_keyword | bloodhound-quickwin | Simple script to extract useful informations from the combo BloodHound + Neo4j | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/kaluche/bloodhound-quickwin | 1 | 1 | N/A | AD Enumeration | 6 | 3 | 239 | 26 | 2025-04-04T05:11:46Z | 2021-02-16T16:04:16Z | 5724 |
| 390 | */bofhound.git* | .{0,1000}\/bofhound\.git.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 1 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 5745 |
| 391 | */bofhound.py* | .{0,1000}\/bofhound\.py.{0,1000} | offensive_tool_keyword | ShadowHound | set of PowerShell scripts for Active Directory enumeration | T1087 - T1018 - T1482 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Friends-Security/ShadowHound | 1 | 1 | N/A | N/A | 8 | 4 | 345 | 36 | 2024-12-01T08:06:02Z | 2024-11-21T15:01:14Z | 5746 |
| 392 | */BucketLoot.git* | .{0,1000}\/BucketLoot\.git.{0,1000} | offensive_tool_keyword | BucketLoot | BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets- flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-text | T1562.007 - T1119 - T1530 | TA0006 - TA0010 | N/A | N/A | Discovery | https://github.com/redhuntlabs/BucketLoot | 1 | 1 | N/A | N/A | 7 | 5 | 409 | 58 | 2025-01-22T10:48:27Z | 2023-07-17T09:06:14Z | 5849 |
| 393 | */c lol fuck this* | .{0,1000}\/c\slol\sfuck\sthis.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 5888 |
| 394 | */Cam-Hackers.git* | .{0,1000}\/Cam\-Hackers\.git.{0,1000} | offensive_tool_keyword | Cam-Hackers | Hack Cameras CCTV FREE | T1125 | TA0007 | N/A | N/A | Discovery | https://github.com/AngelSecurityTeam/Cam-Hackers | 1 | 1 | N/A | N/A | 6 | 10 | 2025 | 512 | 2024-08-06T18:49:02Z | 2019-11-16T18:49:35Z | 5943 |
| 395 | */CheckSMBSigning.git* | .{0,1000}\/CheckSMBSigning\.git.{0,1000} | offensive_tool_keyword | CheckSMBSigning | Checks for SMB signing disabled on all hosts in the network | T1018 - T1550 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Leo4j/CheckSMBSigning | 1 | 1 | N/A | N/A | 6 | 1 | 8 | 1 | 2023-10-13T11:55:33Z | 2023-05-17T11:47:52Z | 6001 |
| 396 | */CheckSMBSigning.ps1* | .{0,1000}\/CheckSMBSigning\.ps1.{0,1000} | offensive_tool_keyword | CheckSMBSigning | Checks for SMB signing disabled on all hosts in the network | T1018 - T1550 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Leo4j/CheckSMBSigning | 1 | 1 | N/A | N/A | 6 | 1 | 8 | 1 | 2023-10-13T11:55:33Z | 2023-05-17T11:47:52Z | 6002 |
| 397 | */cme_adcs_output_*.txt* | .{0,1000}\/cme_adcs_output_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 6114 |
| 398 | */cme_shares_output_* | .{0,1000}\/cme_shares_output_.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 6115 |
| 399 | */cme_spooler_output_* | .{0,1000}\/cme_spooler_output_.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 6116 |
| 400 | */CMLoot.git* | .{0,1000}\/CMLoot\.git.{0,1000} | offensive_tool_keyword | CMLoot | Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares | T1083 - T1039 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/1njected/CMLoot | 1 | 1 | N/A | N/A | 8 | 2 | 175 | 22 | 2023-02-05T00:24:31Z | 2022-06-02T10:59:21Z | 6118 |
| 401 | */CMLoot.ps1* | .{0,1000}\/CMLoot\.ps1.{0,1000} | offensive_tool_keyword | CMLoot | Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares | T1083 - T1039 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/1njected/CMLoot | 1 | 1 | N/A | N/A | 8 | 2 | 175 | 22 | 2023-02-05T00:24:31Z | 2022-06-02T10:59:21Z | 6119 |
| 402 | */coercer_output_*.txt* | .{0,1000}\/coercer_output_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 6146 |
| 403 | */COMHijackToolkit.ps1* | .{0,1000}\/COMHijackToolkit\.ps1.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 1 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 6158 |
| 404 | */COMInjectTarget.dll* | .{0,1000}\/COMInjectTarget\.dll.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 1 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 6163 |
| 405 | */createforestcache.py* | .{0,1000}\/createforestcache\.py.{0,1000} | offensive_tool_keyword | BloodHound | BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/fox-it/BloodHound.py | 1 | 1 | N/A | N/A | 10 | 10 | 2088 | 343 | 2025-03-28T11:19:13Z | 2018-02-26T14:44:20Z | 6231 |
| 406 | */Credentials/*.ccache* | .{0,1000}\/Credentials\/.{0,1000}\.ccache.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 6246 |
| 407 | */Credentials/firefox_*.txt* | .{0,1000}\/Credentials\/firefox_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 6249 |
| 408 | */Credentials/msol_*.txt* | .{0,1000}\/Credentials\/msol_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 6250 |
| 409 | */dcsync_*.txt | .{0,1000}\/dcsync_.{0,1000}\.txt | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 6471 |
| 410 | */DLLHound.git* | .{0,1000}\/DLLHound\.git.{0,1000} | offensive_tool_keyword | DLLHound | Find potential DLL Sideloads on your windows computer | T1574.001 - T1574.002 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/ajm4n/DLLHound | 1 | 1 | N/A | N/A | 7 | 3 | 201 | 22 | 2025-01-12T02:28:22Z | 2024-12-20T02:26:16Z | 6638 |
| 411 | */DLLHound.ps1* | .{0,1000}\/DLLHound\.ps1.{0,1000} | offensive_tool_keyword | DLLHound | Find potential DLL Sideloads on your windows computer | T1574.001 - T1574.002 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/ajm4n/DLLHound | 1 | 1 | N/A | N/A | 7 | 3 | 201 | 22 | 2025-01-12T02:28:22Z | 2024-12-20T02:26:16Z | 6639 |
| 412 | */dnsdump.py* | .{0,1000}\/dnsdump\.py.{0,1000} | offensive_tool_keyword | adidnsdump | By default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks. | T1018 - T1087 - T1201 - T1056 - T1039 | TA0005 - TA0009 | N/A | N/A | Discovery | https://github.com/dirkjanm/adidnsdump | 1 | 1 | #linux | N/A | N/A | 10 | 997 | 118 | 2025-04-04T09:28:20Z | 2019-04-24T17:18:46Z | 6673 |
| 413 | */DomainRecon/*.txt* | .{0,1000}\/DomainRecon\/.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 6725 |
| 414 | */download/v1.0/payload.dll* | .{0,1000}\/download\/v1\.0\/payload\.dll.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 6758 |
| 415 | */download/v1.1.0/pspy32* | .{0,1000}\/download\/v1\.1\.0\/pspy32.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 6759 |
| 416 | */download/v1.1.0/pspy64* | .{0,1000}\/download\/v1\.1\.0\/pspy64.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 6760 |
| 417 | */download/v1.2.0/pspy32* | .{0,1000}\/download\/v1\.2\.0\/pspy32.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 6761 |
| 418 | */download/v1.2.1/pspy32* | .{0,1000}\/download\/v1\.2\.1\/pspy32.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 6762 |
| 419 | */download/v1.2.1/pspy64* | .{0,1000}\/download\/v1\.2\.1\/pspy64.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 6763 |
| 420 | */DSInternals.psd1* | .{0,1000}\/DSInternals\.psd1.{0,1000} | offensive_tool_keyword | DSInternals | Directory Services Internals (DSInternals) PowerShell Module and Framework - abused by attackers | T1003 - T1087 - T1018 - T1110 - T1558 | TA0003 - TA0006 - TA0007 | N/A | COZY BEAR | Discovery | https://github.com/MichaelGrafnetter/DSInternals | 1 | 1 | N/A | AD Enumeration | 10 | 10 | 1760 | 265 | 2025-04-16T18:12:55Z | 2015-12-25T13:23:05Z | 6805 |
| 421 | */ecrprivenum.py* | .{0,1000}\/ecrprivenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 1 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 6884 |
| 422 | */ecrpubenum.py* | .{0,1000}\/ecrpubenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 1 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 6885 |
| 423 | */fox-it/BloodHound* | .{0,1000}\/fox\-it\/BloodHound.{0,1000} | offensive_tool_keyword | BloodHound | BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/fox-it/BloodHound.py | 1 | 1 | N/A | N/A | 10 | 10 | 2088 | 343 | 2025-03-28T11:19:13Z | 2018-02-26T14:44:20Z | 7245 |
| 424 | */Get-SMBSigning.ps1* | .{0,1000}\/Get\-SMBSigning\.ps1.{0,1000} | offensive_tool_keyword | CheckSMBSigning | Checks for SMB signing disabled on all hosts in the network | T1018 - T1550 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Leo4j/CheckSMBSigning | 1 | 1 | N/A | N/A | 6 | 1 | 8 | 1 | 2023-10-13T11:55:33Z | 2023-05-17T11:47:52Z | 7385 |
| 425 | */gMSA_dump_*.txt* | .{0,1000}\/gMSA_dump_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 7531 |
| 426 | */GMSAPasswordReader.exe* | .{0,1000}\/GMSAPasswordReader\.exe.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 1 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 7535 |
| 427 | */gofetch.exe* | .{0,1000}\/gofetch\.exe.{0,1000} | offensive_tool_keyword | GoFetch | GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application. | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | Dispossessor | Discovery | https://github.com/GoFetchAD/GoFetch | 1 | 1 | N/A | N/A | 10 | 7 | 633 | 99 | 2017-06-20T14:15:10Z | 2017-04-11T10:45:23Z | 7561 |
| 428 | */GoFetch.git* | .{0,1000}\/GoFetch\.git.{0,1000} | offensive_tool_keyword | GoFetch | GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application. | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | Dispossessor | Discovery | https://github.com/GoFetchAD/GoFetch | 1 | 1 | N/A | N/A | 10 | 7 | 633 | 99 | 2017-06-20T14:15:10Z | 2017-04-11T10:45:23Z | 7562 |
| 429 | */GONET-Scanner/* | .{0,1000}\/GONET\-Scanner\/.{0,1000} | offensive_tool_keyword | GONET-Scanner | port scanner and arp discover in go | T1595 | TA0001 | N/A | N/A | Discovery | https://github.com/luijait/GONET-Scanner | 1 | 1 | N/A | network exploitation tool | N/A | 1 | 82 | 21 | 2022-03-10T04:35:58Z | 2022-02-02T19:39:09Z | 7577 |
| 430 | */GPOBrowser.py* | .{0,1000}\/GPOBrowser\.py.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 1 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 7609 |
| 431 | */Graphpython.git* | .{0,1000}\/Graphpython\.git.{0,1000} | offensive_tool_keyword | Graphpython | Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/Graphpython | 1 | 1 | N/A | N/A | 7 | 2 | 145 | 13 | 2024-12-07T21:54:00Z | 2024-07-10T00:04:48Z | 7617 |
| 432 | */Graphpython.py* | .{0,1000}\/Graphpython\.py.{0,1000} | offensive_tool_keyword | Graphpython | Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/Graphpython | 1 | 1 | N/A | N/A | 7 | 2 | 145 | 13 | 2024-12-07T21:54:00Z | 2024-07-10T00:04:48Z | 7618 |
| 433 | */Group3r.git* | .{0,1000}\/Group3r\.git.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 1 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 7636 |
| 434 | */Group3r/releases/download/* | .{0,1000}\/Group3r\/releases\/download\/.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 1 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 7637 |
| 435 | */HijackDLL-CreateRemoteThread.cpp* | .{0,1000}\/HijackDLL\-CreateRemoteThread\.cpp.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 1 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 7774 |
| 436 | */HijackDll-Process.cpp* | .{0,1000}\/HijackDll\-Process\.cpp.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 1 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 7775 |
| 437 | */HijackDLL-Threads.* | .{0,1000}\/HijackDLL\-Threads\..{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 1 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 7776 |
| 438 | */iamassumeroleenum.py* | .{0,1000}\/iamassumeroleenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 1 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 8000 |
| 439 | */Invoke-Adeleginator* | .{0,1000}\/Invoke\-Adeleginator.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 1 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 8137 |
| 440 | */Invoke-ADEnum.git* | .{0,1000}\/Invoke\-ADEnum\.git.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 1 | N/A | N/A | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 8138 |
| 441 | */Invoke-DCOM.ps1* | .{0,1000}\/Invoke\-DCOM\.ps1.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 1 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 8146 |
| 442 | */Invoke-Maldaptive.git* | .{0,1000}\/Invoke\-Maldaptive\.git.{0,1000} | greyware_tool_keyword | Invoke-Maldaptive | MaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection. | T1027 | TA0005 - TA0007 | N/A | N/A | Discovery | https://github.com/MaLDAPtive/Invoke-Maldaptive | 1 | 1 | N/A | N/A | 7 | 3 | 277 | 26 | 2024-08-07T21:12:45Z | 2024-08-07T20:43:52Z | 8153 |
| 443 | */Invoke-SessionHunter.git* | .{0,1000}\/Invoke\-SessionHunter\.git.{0,1000} | offensive_tool_keyword | Invoke-SessionHunter | Retrieve and display information about active user sessions on remote computers. No admin privileges required | T1033 - T1078 - T1110 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-SessionHunter | 1 | 1 | N/A | N/A | 7 | 2 | 183 | 20 | 2024-08-12T13:15:10Z | 2023-08-13T13:22:05Z | 8164 |
| 444 | */ipscan.exe* | .{0,1000}\/ipscan\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 1 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8199 |
| 445 | */ipscan.git* | .{0,1000}\/ipscan\.git.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 1 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8200 |
| 446 | */ipscan_*_amd64.deb* | .{0,1000}\/ipscan_.{0,1000}_amd64\.deb.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | #linux | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8201 |
| 447 | */ipscan2-binary/*.exe* | .{0,1000}\/ipscan2\-binary\/.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8202 |
| 448 | */ipscan-any-*.jar* | .{0,1000}\/ipscan\-any\-.{0,1000}\.jar.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | #linux | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 8203 |
| 449 | */ItWasAllADream.git* | .{0,1000}\/ItWasAllADream\.git.{0,1000} | offensive_tool_keyword | ItWasAllADream | A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE | T1046 - T1210.002 - T1047 | TA0007 - TA0002 | N/A | N/A | Discovery | https://github.com/byt3bl33d3r/ItWasAllADream | 1 | 1 | N/A | N/A | 7 | 8 | 796 | 123 | 2024-05-19T16:25:52Z | 2021-07-05T20:13:49Z | 8218 |
| 450 | */jecretz.git* | .{0,1000}\/jecretz\.git.{0,1000} | offensive_tool_keyword | jecretz | Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets | T1552 - T1114 - T1119 - T1070 | TA0006 - TA0009 - TA0005 | N/A | Scattered Spider* | Discovery | https://github.com/sahadnk72/jecretz | 1 | 1 | N/A | N/A | 7 | 1 | 43 | 9 | 2022-12-08T10:00:11Z | 2020-05-25T14:40:28Z | 8234 |
| 451 | */jecretz.py* | .{0,1000}\/jecretz\.py.{0,1000} | offensive_tool_keyword | jecretz | Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets | T1552 - T1114 - T1119 - T1070 | TA0006 - TA0009 - TA0005 | N/A | Scattered Spider* | Discovery | https://github.com/sahadnk72/jecretz | 1 | 1 | N/A | N/A | 7 | 1 | 43 | 9 | 2022-12-08T10:00:11Z | 2020-05-25T14:40:28Z | 8235 |
| 452 | */john.git* | .{0,1000}\/john\.git.{0,1000} | offensive_tool_keyword | ldapdomaindump | Active Directory information dumper via LDAP | T1087 - T1005 - T1016 | TA0007 | N/A | EMBER BEAR | Discovery | https://github.com/dirkjanm/ldapdomaindump | 1 | 1 | N/A | N/A | 10 | 10 | 1242 | 201 | 2025-04-06T13:31:57Z | 2016-05-24T18:46:56Z | 8242 |
| 453 | */keepass_discover_*.txt* | .{0,1000}\/keepass_discover_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 8301 |
| 454 | */kerberoast_hashes_*.txt* | .{0,1000}\/kerberoast_hashes_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 8325 |
| 455 | */Killchain.ps1* | .{0,1000}\/Killchain\.ps1.{0,1000} | offensive_tool_keyword | Graphpython | Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/Graphpython | 1 | 1 | N/A | N/A | 7 | 2 | 145 | 13 | 2024-12-07T21:54:00Z | 2024-07-10T00:04:48Z | 8362 |
| 456 | */laconicwolf/burp-extensions* | .{0,1000}\/laconicwolf\/burp\-extensions.{0,1000} | offensive_tool_keyword | burpsuite | A collection of scripts to extend Burp Suite | T1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574 | TA0003 - TA0004 - TA0005 - TA0006 - TA0008 | N/A | Black Basta | Discovery | https://github.com/laconicwolf/burp-extensions | 1 | 1 | N/A | network exploitation tool | N/A | 2 | 142 | 31 | 2019-04-08T00:49:45Z | 2018-03-23T16:05:01Z | 8420 |
| 457 | */lambdaenum.py* | .{0,1000}\/lambdaenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 1 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 8432 |
| 458 | */lansearch.exe* | .{0,1000}\/lansearch\.exe.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 8435 |
| 459 | */LansweeperSetup_*.exe* | .{0,1000}\/LansweeperSetup_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 8436 |
| 460 | */laps_dump_*.txt* | .{0,1000}\/laps_dump_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 8440 |
| 461 | */LAPSToolkit.git* | .{0,1000}\/LAPSToolkit\.git.{0,1000} | offensive_tool_keyword | LAPSToolkit | Functions written in PowerShell that leverage PowerView to audit and attack Active Directory environments that have deployed Microsofts Local Administrator Password Solution (LAPS). It includes finding groups specifically delegated by sysadmins. finding users with All Extended Rights that can view passwords. and viewing all computers with LAPS enabled | T1087.001 - T1069 - T1069.003 - T1069.007 - T1069.002 - T1069.001 | TA0007 - TA0008 - TA0009 | N/A | Scattered Spider* | Discovery | https://github.com/leoloobeek/LAPSToolkit | 1 | 1 | N/A | N/A | 10 | 9 | 859 | 119 | 2018-01-31T14:45:35Z | 2016-04-27T00:06:20Z | 8442 |
| 462 | */ld.so /bin/sh -p* | .{0,1000}\/ld\.so\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 8463 |
| 463 | */ldap_search_bof.py* | .{0,1000}\/ldap_search_bof\.py.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 1 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 8466 |
| 464 | */ldapnomnom.git* | .{0,1000}\/ldapnomnom\.git.{0,1000} | offensive_tool_keyword | ldapnomnom | Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP) | T1110.003 - T1205 | TA0007 | N/A | N/A | Discovery | https://github.com/lkarlslund/ldapnomnom | 1 | 1 | N/A | N/A | 6 | 10 | 1030 | 80 | 2024-11-09T10:15:13Z | 2022-09-18T10:35:09Z | 8469 |
| 465 | */ldapnomnom/releases/download/* | .{0,1000}\/ldapnomnom\/releases\/download\/.{0,1000} | offensive_tool_keyword | ldapnomnom | Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP) | T1110.003 - T1205 | TA0007 | N/A | N/A | Discovery | https://github.com/lkarlslund/ldapnomnom | 1 | 1 | N/A | N/A | 6 | 10 | 1030 | 80 | 2024-11-09T10:15:13Z | 2022-09-18T10:35:09Z | 8470 |
| 466 | */ldapnomnom@latest* | .{0,1000}\/ldapnomnom\@latest.{0,1000} | offensive_tool_keyword | ldapnomnom | Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP) | T1110.003 - T1205 | TA0007 | N/A | N/A | Discovery | https://github.com/lkarlslund/ldapnomnom | 1 | 1 | N/A | N/A | 6 | 10 | 1030 | 80 | 2024-11-09T10:15:13Z | 2022-09-18T10:35:09Z | 8471 |
| 467 | */LDAP-Password-Hunter.git* | .{0,1000}\/LDAP\-Password\-Hunter\.git.{0,1000} | offensive_tool_keyword | LDAP-Password-Hunter | Password Hunter in Active Directory | T1087.002 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/LDAP-Password-Hunter | 1 | 1 | N/A | N/A | 7 | 2 | 198 | 25 | 2023-01-06T15:32:34Z | 2021-07-26T14:27:01Z | 8473 |
| 468 | */LDAPPER.git* | .{0,1000}\/LDAPPER\.git.{0,1000} | offensive_tool_keyword | LDAPPER | LDAP Querying without the Suck | T1087 - T1069 - T1018 | TA0007 | N/A | N/A | Discovery | https://github.com/shellster/LDAPPER | 1 | 1 | N/A | N/A | 7 | 1 | 99 | 11 | 2024-11-09T03:53:26Z | 2020-06-17T16:53:35Z | 8474 |
| 469 | */ldapper.py* | .{0,1000}\/ldapper\.py.{0,1000} | offensive_tool_keyword | LDAPPER | LDAP Querying without the Suck | T1087 - T1069 - T1018 | TA0007 | N/A | N/A | Discovery | https://github.com/shellster/LDAPPER | 1 | 1 | N/A | N/A | 7 | 1 | 99 | 11 | 2024-11-09T03:53:26Z | 2020-06-17T16:53:35Z | 8475 |
| 470 | */LDAPPER-master* | .{0,1000}\/LDAPPER\-master.{0,1000} | offensive_tool_keyword | LDAPPER | LDAP Querying without the Suck | T1087 - T1069 - T1018 | TA0007 | N/A | N/A | Discovery | https://github.com/shellster/LDAPPER | 1 | 0 | N/A | N/A | 7 | 1 | 99 | 11 | 2024-11-09T03:53:26Z | 2020-06-17T16:53:35Z | 8476 |
| 471 | */ldapph.db* | .{0,1000}\/ldapph\.db.{0,1000} | offensive_tool_keyword | LDAP-Password-Hunter | Password Hunter in Active Directory | T1087.002 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/LDAP-Password-Hunter | 1 | 0 | N/A | N/A | 7 | 2 | 198 | 25 | 2023-01-06T15:32:34Z | 2021-07-26T14:27:01Z | 8477 |
| 472 | */ldeepDump* | .{0,1000}\/ldeepDump.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 8485 |
| 473 | */LibSnaffle* | .{0,1000}\/LibSnaffle.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 1 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 8509 |
| 474 | */linWinPwn* | .{0,1000}\/linWinPwn.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 8550 |
| 475 | */loadbalancer.py* | .{0,1000}\/loadbalancer\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 1 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 8568 |
| 476 | */localbrute.ps1* | .{0,1000}\/localbrute\.ps1.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 1 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 8582 |
| 477 | */LocalShellExtParse.git* | .{0,1000}\/LocalShellExtParse\.git.{0,1000} | offensive_tool_keyword | LocalShellExtParse | Script to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User. | T1547.009 - T1129 | TA0003 - TA0007 | N/A | N/A | Discovery | https://github.com/herrcore/LocalShellExtParse | 1 | 1 | N/A | N/A | 9 | 1 | 20 | 4 | 2015-06-08T16:55:38Z | 2015-06-05T03:23:13Z | 8589 |
| 478 | */LocalShellExtParse.py* | .{0,1000}\/LocalShellExtParse\.py.{0,1000} | offensive_tool_keyword | LocalShellExtParse | Script to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User. | T1547.009 - T1129 | TA0003 - TA0007 | N/A | N/A | Discovery | https://github.com/herrcore/LocalShellExtParse | 1 | 1 | N/A | N/A | 9 | 1 | 20 | 4 | 2015-06-08T16:55:38Z | 2015-06-05T03:23:13Z | 8590 |
| 479 | */Locksmith.git* | .{0,1000}\/Locksmith\.git.{0,1000} | offensive_tool_keyword | Locksmith | A tiny tool to identify and remediate common misconfigurations in Active Directory Certificate Services | T1552.006 - T1222 - T1046 | TA0007 - TA0040 - TA0043 | N/A | N/A | Discovery | https://github.com/TrimarcJake/Locksmith | 1 | 1 | N/A | N/A | 8 | 10 | 1086 | 100 | 2025-04-21T12:43:50Z | 2022-04-28T01:37:32Z | 8605 |
| 480 | */lsa_dump_*.txt* | .{0,1000}\/lsa_dump_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 8637 |
| 481 | */MANSPIDER.git* | .{0,1000}\/MANSPIDER\.git.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 1 | N/A | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 8719 |
| 482 | */manspider_*.log* | .{0,1000}\/manspider_.{0,1000}\.log.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | #linux | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 8720 |
| 483 | */manspider_output*.txt | .{0,1000}\/manspider_output.{0,1000}\.txt | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 8721 |
| 484 | */manspiderDump* | .{0,1000}\/manspiderDump.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 8722 |
| 485 | */MDE_Enum.git* | .{0,1000}\/MDE_Enum\.git.{0,1000} | offensive_tool_keyword | MDE_Enum | extract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rules | T1070.006 | TA0005 - TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/0xsp-SRD/MDE_Enum | 1 | 1 | N/A | N/A | 8 | 2 | 198 | 18 | 2024-06-10T18:40:27Z | 2024-06-06T15:54:44Z | 8732 |
| 486 | */Minimalistic-offensive-security-tools.git* | .{0,1000}\/Minimalistic\-offensive\-security\-tools\.git.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 1 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 8858 |
| 487 | */Moriarty.exe* | .{0,1000}\/Moriarty\.exe.{0,1000} | offensive_tool_keyword | Moriarty | Moriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments. | T1068 - T1083 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/BC-SECURITY/Moriarty | 1 | 1 | N/A | N/A | 7 | 6 | 510 | 67 | 2024-08-07T15:06:31Z | 2023-12-11T14:15:33Z | 8895 |
| 488 | */Moriarty.git* | .{0,1000}\/Moriarty\.git.{0,1000} | offensive_tool_keyword | Moriarty | Moriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments. | T1068 - T1083 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/BC-SECURITY/Moriarty | 1 | 1 | N/A | N/A | 7 | 6 | 510 | 67 | 2024-08-07T15:06:31Z | 2023-12-11T14:15:33Z | 8897 |
| 489 | */msi_search.ps1* | .{0,1000}\/msi_search\.ps1.{0,1000} | offensive_tool_keyword | msi-search | This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs | T1005 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/mandiant/msi-search | 1 | 1 | N/A | N/A | 10 | 3 | 276 | 31 | 2023-07-20T18:12:49Z | 2023-06-29T18:31:56Z | 8937 |
| 490 | */msi-search.git* | .{0,1000}\/msi\-search\.git.{0,1000} | offensive_tool_keyword | msi-search | This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs | T1005 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/mandiant/msi-search | 1 | 1 | N/A | N/A | 10 | 3 | 276 | 31 | 2023-07-20T18:12:49Z | 2023-06-29T18:31:56Z | 8938 |
| 491 | */mtth-bfft/adeleg/releases* | .{0,1000}\/mtth\-bfft\/adeleg\/releases.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 1 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 8963 |
| 492 | */netscan.exe* | .{0,1000}\/netscan\.exe.{0,1000} | greyware_tool_keyword | netscan | SoftPerfect Network Scanner abused by threat actor | T1040 - T1046 - T1018 | TA0007 - TA0010 - TA0001 | N/A | BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - Lynx | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | network exploitation tool | 6 | 10 | N/A | N/A | N/A | N/A | 9108 |
| 493 | */netscan.exe* | .{0,1000}\/netscan\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9109 |
| 494 | */netscan_linux.tar.gz* | .{0,1000}\/netscan_linux\.tar\.gz.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | #linux | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9110 |
| 495 | */netscan_macos.dmg* | .{0,1000}\/netscan_macos\.dmg.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | #macos | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9111 |
| 496 | */netscan_setup.exe* | .{0,1000}\/netscan_setup\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9112 |
| 497 | */netscan64.exe* | .{0,1000}\/netscan64\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 1 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9113 |
| 498 | */NetSess.exe* | .{0,1000}\/NetSess\.exe.{0,1000} | offensive_tool_keyword | NetSess | Command line tool to enumerate NetBIOS sessions on a specified local or remote machine. | T1016 - T1046 - T1087 | TA0007 - TA0043 | N/A | MUSTANG PANDA | Discovery | https://www.joeware.net/freetools/tools/netsess/ | 1 | 1 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 9114 |
| 499 | */NetSess.zip* | .{0,1000}\/NetSess\.zip.{0,1000} | offensive_tool_keyword | NetSess | Command line tool to enumerate NetBIOS sessions on a specified local or remote machine. | T1016 - T1046 - T1087 | TA0007 - TA0043 | N/A | MUSTANG PANDA | Discovery | https://www.joeware.net/freetools/tools/netsess/ | 1 | 1 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 9115 |
| 500 | */NimScan.exe* | .{0,1000}\/NimScan\.exe.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 1 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 9175 |
| 501 | */NimScan.git* | .{0,1000}\/NimScan\.git.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 1 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 9176 |
| 502 | */NimScan.nim* | .{0,1000}\/NimScan\.nim.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 1 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 9177 |
| 503 | */Nmap/folder/check15* | .{0,1000}\/Nmap\/folder\/check15.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9198 |
| 504 | */Nmap/folder/check16* | .{0,1000}\/Nmap\/folder\/check16.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9199 |
| 505 | */Nmap/folder/check17* | .{0,1000}\/Nmap\/folder\/check17.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9200 |
| 506 | */nmap_smb_scan_all_*.txt* | .{0,1000}\/nmap_smb_scan_all_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 9201 |
| 507 | */nmaplowercheck15* | .{0,1000}\/nmaplowercheck15.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://nmap.org/book/nse-usage.html | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | N/A | N/A | N/A | N/A | 9204 |
| 508 | */nmaplowercheck16* | .{0,1000}\/nmaplowercheck16.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9205 |
| 509 | */nmaplowercheck17* | .{0,1000}\/nmaplowercheck17.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9206 |
| 510 | */NmapUpperCheck15* | .{0,1000}\/NmapUpperCheck15.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9209 |
| 511 | */NmapUpperCheck16* | .{0,1000}\/NmapUpperCheck16.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9210 |
| 512 | */NmapUpperCheck17* | .{0,1000}\/NmapUpperCheck17.{0,1000} | greyware_tool_keyword | nmap | Nmap (Network Mapper) is a free and open source utility for network discovery and security auditing | T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007 | TA0001 - TA0007 - TA0043 | N/A | Qilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black Basta | Discovery | https://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L2600 | 1 | 1 | N/A | will appear on your server access logs if you are scanned by nmap | 8 | 10 | 10953 | 2505 | 2025-04-21T20:45:05Z | 2012-03-09T14:47:43Z | 9211 |
| 513 | */ntds_dump_*.txt* | .{0,1000}\/ntds_dump_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 9278 |
| 514 | */NTLMRecon* | .{0,1000}\/NTLMRecon.{0,1000} | offensive_tool_keyword | NTMLRecon | A fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains | T1595 | TA0009 | N/A | N/A | Discovery | https://github.com/pwnfoo/NTLMRecon | 1 | 1 | N/A | N/A | N/A | 5 | 481 | 70 | 2024-06-24T18:11:12Z | 2019-12-01T06:06:30Z | 9289 |
| 515 | */NTLMRecon.git* | .{0,1000}\/NTLMRecon\.git.{0,1000} | offensive_tool_keyword | NTMLRecon | Enumerate information from NTLM authentication enabled web endpoints | T1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001 | TA0009 - TA0007 - TA0006 | N/A | N/A | Discovery | https://github.com/puzzlepeaches/NTLMRecon | 1 | 1 | N/A | N/A | 8 | 1 | 35 | 3 | 2023-08-16T14:34:10Z | 2023-08-09T12:10:42Z | 9290 |
| 516 | */ntlmrecon/*.py* | .{0,1000}\/ntlmrecon\/.{0,1000}\.py.{0,1000} | offensive_tool_keyword | NTMLRecon | Enumerate information from NTLM authentication enabled web endpoints | T1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001 | TA0009 - TA0007 - TA0006 | N/A | N/A | Discovery | https://github.com/puzzlepeaches/NTLMRecon | 1 | 1 | N/A | N/A | 8 | 1 | 35 | 3 | 2023-08-16T14:34:10Z | 2023-08-09T12:10:42Z | 9291 |
| 517 | */ntlmutil.py* | .{0,1000}\/ntlmutil\.py.{0,1000} | offensive_tool_keyword | NTMLRecon | A fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domains | T1595 | TA0009 | N/A | N/A | Discovery | https://github.com/pwnfoo/NTLMRecon | 1 | 1 | N/A | N/A | N/A | 5 | 481 | 70 | 2024-06-24T18:11:12Z | 2019-12-01T06:06:30Z | 9307 |
| 518 | */ntlmutil.py* | .{0,1000}\/ntlmutil\.py.{0,1000} | offensive_tool_keyword | NTMLRecon | Enumerate information from NTLM authentication enabled web endpoints | T1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001 | TA0009 - TA0007 - TA0006 | N/A | N/A | Discovery | https://github.com/puzzlepeaches/NTLMRecon | 1 | 1 | N/A | N/A | 8 | 1 | 35 | 3 | 2023-08-16T14:34:10Z | 2023-08-09T12:10:42Z | 9308 |
| 519 | */nullinux.git* | .{0,1000}\/nullinux\.git.{0,1000} | offensive_tool_keyword | nullinux | Internal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB. | T1087 - T1016 - T1077 - T1018 | TA0007 - TA0006 | N/A | N/A | Discovery | https://github.com/m8sec/nullinux | 1 | 1 | #linux | N/A | 7 | 6 | 575 | 101 | 2024-06-19T14:29:09Z | 2016-04-28T16:45:02Z | 9321 |
| 520 | */nullinux.py* | .{0,1000}\/nullinux\.py.{0,1000} | offensive_tool_keyword | nullinux | Internal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB. | T1087 - T1016 - T1077 - T1018 | TA0007 - TA0006 | N/A | N/A | Discovery | https://github.com/m8sec/nullinux | 1 | 1 | #linux | N/A | 7 | 6 | 575 | 101 | 2024-06-19T14:29:09Z | 2016-04-28T16:45:02Z | 9322 |
| 521 | */nullinux_users.txt* | .{0,1000}\/nullinux_users\.txt.{0,1000} | offensive_tool_keyword | nullinux | Internal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB. | T1087 - T1016 - T1077 - T1018 | TA0007 - TA0006 | N/A | N/A | Discovery | https://github.com/m8sec/nullinux | 1 | 0 | #linux | N/A | 7 | 6 | 575 | 101 | 2024-06-19T14:29:09Z | 2016-04-28T16:45:02Z | 9323 |
| 522 | */opt/cobaltstrike/logs* | .{0,1000}\/opt\/cobaltstrike\/logs.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 0 | #linux | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 9402 |
| 523 | */opt/lwp-scripts* | .{0,1000}\/opt\/lwp\-scripts.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 9417 |
| 524 | */opt/lwp-wordlists* | .{0,1000}\/opt\/lwp\-wordlists.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 9418 |
| 525 | */perf stat /bin/sh -p* | .{0,1000}\/perf\sstat\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 9602 |
| 526 | */perl -e 'exec \"/bin/sh\"* | .{0,1000}\/perl\s\-e\s\'exec\s\\\"\/bin\/sh\\\".{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 9607 |
| 527 | */PipeViewer.exe* | .{0,1000}\/PipeViewer\.exe.{0,1000} | offensive_tool_keyword | PipeViewer | A tool that shows detailed information about named pipes in Windows | T1022.002 - T1056.002 | TA0005 - TA0009 | N/A | N/A | discovery | https://github.com/cyberark/PipeViewer | 1 | 1 | N/A | N/A | 5 | 7 | 620 | 55 | 2024-11-15T09:55:35Z | 2022-12-22T12:35:34Z | 9700 |
| 528 | */PipeViewer.git* | .{0,1000}\/PipeViewer\.git.{0,1000} | offensive_tool_keyword | PipeViewer | A tool that shows detailed information about named pipes in Windows | T1022.002 - T1056.002 | TA0005 - TA0009 | N/A | N/A | discovery | https://github.com/cyberark/PipeViewer | 1 | 1 | N/A | N/A | 5 | 7 | 620 | 55 | 2024-11-15T09:55:35Z | 2022-12-22T12:35:34Z | 9701 |
| 529 | */PipeViewer.sln* | .{0,1000}\/PipeViewer\.sln.{0,1000} | offensive_tool_keyword | PipeViewer | A tool that shows detailed information about named pipes in Windows | T1022.002 - T1056.002 | TA0005 - TA0009 | N/A | N/A | discovery | https://github.com/cyberark/PipeViewer | 1 | 1 | N/A | N/A | 5 | 7 | 620 | 55 | 2024-11-15T09:55:35Z | 2022-12-22T12:35:34Z | 9702 |
| 530 | */PipeViewer/Program.cs* | .{0,1000}\/PipeViewer\/Program\.cs.{0,1000} | offensive_tool_keyword | PipeViewer | A tool that shows detailed information about named pipes in Windows | T1022.002 - T1056.002 | TA0005 - TA0009 | N/A | N/A | discovery | https://github.com/cyberark/PipeViewer | 1 | 1 | N/A | N/A | 5 | 7 | 620 | 55 | 2024-11-15T09:55:35Z | 2022-12-22T12:35:34Z | 9703 |
| 531 | */polenum.py* | .{0,1000}\/polenum\.py.{0,1000} | offensive_tool_keyword | polenum | Uses Impacket Library to get the password policy from a windows machine | T1012 - T1596 | TA0009 - TA0007 | N/A | N/A | Discovery | https://salsa.debian.org/pkg-security-team/polenum | 1 | 0 | #linux | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 9725 |
| 532 | */PortQry.exe* | .{0,1000}\/PortQry\.exe.{0,1000} | greyware_tool_keyword | PortQry | Microsoft port scanning tool abused by threat actors | T1046 - T1016 - T1049 | TA0007 | N/A | APT15 | Discovery | https://www.microsoft.com/en-us/download/details.aspx?id=17148 | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 9748 |
| 533 | */PortQryV2.exe* | .{0,1000}\/PortQryV2\.exe.{0,1000} | greyware_tool_keyword | PortQry | Microsoft port scanning tool abused by threat actors | T1046 - T1016 - T1049 | TA0007 | N/A | APT15 | Discovery | https://www.microsoft.com/en-us/download/details.aspx?id=17148 | 1 | 1 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 9749 |
| 534 | */portscan.git* | .{0,1000}\/portscan\.git.{0,1000} | offensive_tool_keyword | portscan | A simple TCP and UDP portscanner written in Go | T1595 - T1596 - T1594 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/zs5460/portscan | 1 | 1 | N/A | N/A | N/A | 1 | 14 | 4 | 2022-11-11T09:26:47Z | 2019-06-04T09:00:00Z | 9763 |
| 535 | */portscan/releases/* | .{0,1000}\/portscan\/releases\/.{0,1000} | offensive_tool_keyword | portscan | A simple TCP and UDP portscanner written in Go | T1595 - T1596 - T1594 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/zs5460/portscan | 1 | 1 | N/A | N/A | N/A | 1 | 14 | 4 | 2022-11-11T09:26:47Z | 2019-06-04T09:00:00Z | 9766 |
| 536 | */port-scan-tcp.ps1* | .{0,1000}\/port\-scan\-tcp\.ps1.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 1 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 9768 |
| 537 | */port-scan-udp.ps1* | .{0,1000}\/port\-scan\-udp\.ps1.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 1 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 9769 |
| 538 | */PowerView.ps1* | .{0,1000}\/PowerView\.ps1.{0,1000} | offensive_tool_keyword | SharpView | C# implementation of harmj0y's PowerView | T1018 - T1482 - T1087.002 - T1069.002 | TA0007 - TA0003 - TA0001 | N/A | Conti - APT29 | Discovery | https://github.com/tevora-threat/SharpView/ | 1 | 1 | N/A | N/A | 10 | 10 | 1032 | 196 | 2024-03-22T16:34:09Z | 2018-07-24T21:15:04Z | 9837 |
| 539 | */powerview.py* | .{0,1000}\/powerview\.py.{0,1000} | offensive_tool_keyword | powerview | PowerView.py is an alternative for the awesome original PowerView.ps1 | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/aniqfakhrul/powerview.py | 1 | 0 | N/A | N/A | 10 | 7 | 622 | 66 | 2025-04-22T09:01:39Z | 2022-06-19T16:13:04Z | 9838 |
| 540 | */powerview.py.git* | .{0,1000}\/powerview\.py\.git.{0,1000} | offensive_tool_keyword | powerview | PowerView.py is an alternative for the awesome original PowerView.ps1 | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/aniqfakhrul/powerview.py | 1 | 1 | N/A | N/A | 10 | 7 | 622 | 66 | 2025-04-22T09:01:39Z | 2022-06-19T16:13:04Z | 9839 |
| 541 | */pslist.exe* | .{0,1000}\/pslist\.exe.{0,1000} | greyware_tool_keyword | pslist | Microsoft sysinternal comandline tool to list running process abused by threat actors | T1057 - T1012 - T1106 | TA0007 | N/A | APT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - Elfin | Discovery | https://learn.microsoft.com/pt-br/sysinternals/downloads/pslist | 1 | 1 | N/A | N/A | 3 | 9 | N/A | N/A | N/A | N/A | 9972 |
| 542 | */pslist64.exe* | .{0,1000}\/pslist64\.exe.{0,1000} | greyware_tool_keyword | pslist | Microsoft sysinternal comandline tool to list running process abused by threat actors | T1057 - T1012 - T1106 | TA0007 | N/A | APT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - Elfin | Discovery | https://learn.microsoft.com/pt-br/sysinternals/downloads/pslist | 1 | 1 | N/A | N/A | 3 | 9 | N/A | N/A | N/A | N/A | 9973 |
| 543 | */PSnmap.git* | .{0,1000}\/PSnmap\.git.{0,1000} | offensive_tool_keyword | Psnmap | Powershell scanner (nmap like) | T1086 - T1046 - T1059 | TA0007 | N/A | Black Basta | Discovery | https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1 | 1 | 1 | N/A | N/A | 7 | 2 | 178 | 64 | 2024-08-23T18:24:20Z | 2015-01-24T10:46:41Z | 9976 |
| 544 | */PSnmap.ps1* | .{0,1000}\/PSnmap\.ps1.{0,1000} | offensive_tool_keyword | Psnmap | Powershell scanner (nmap like) | T1086 - T1046 - T1059 | TA0007 | N/A | Black Basta | Discovery | https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1 | 1 | 0 | N/A | N/A | 7 | 2 | 178 | 64 | 2024-08-23T18:24:20Z | 2015-01-24T10:46:41Z | 9977 |
| 545 | */PSnmap.psd1* | .{0,1000}\/PSnmap\.psd1.{0,1000} | offensive_tool_keyword | Psnmap | Powershell scanner (nmap like) | T1086 - T1046 - T1059 | TA0007 | N/A | Black Basta | Discovery | https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1 | 1 | 1 | N/A | N/A | 7 | 2 | 178 | 64 | 2024-08-23T18:24:20Z | 2015-01-24T10:46:41Z | 9978 |
| 546 | */PSnmap.psm1* | .{0,1000}\/PSnmap\.psm1.{0,1000} | offensive_tool_keyword | Psnmap | Powershell scanner (nmap like) | T1086 - T1046 - T1059 | TA0007 | N/A | Black Basta | Discovery | https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1 | 1 | 1 | N/A | N/A | 7 | 2 | 178 | 64 | 2024-08-23T18:24:20Z | 2015-01-24T10:46:41Z | 9979 |
| 547 | */pspy -* | .{0,1000}\/pspy\s\-.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1514 - T1082 | TA0007 - TA0009 - TA0003 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 0 | #linux | N/A | 6 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9984 |
| 548 | */pspy.git* | .{0,1000}\/pspy\.git.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1514 - T1082 | TA0007 - TA0009 - TA0003 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 6 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9986 |
| 549 | */pspy.git* | .{0,1000}\/pspy\.git.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9987 |
| 550 | */pspy.go* | .{0,1000}\/pspy\.go.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1514 - T1082 | TA0007 - TA0009 - TA0003 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 0 | #linux | N/A | 6 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9988 |
| 551 | */pspy/cmd* | .{0,1000}\/pspy\/cmd.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1514 - T1082 | TA0007 - TA0009 - TA0003 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 0 | #linux | N/A | 6 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9989 |
| 552 | */pspy/cmd/* | .{0,1000}\/pspy\/cmd\/.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 0 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9990 |
| 553 | */pspy/pspy.go* | .{0,1000}\/pspy\/pspy\.go.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9991 |
| 554 | */pspy32* | .{0,1000}\/pspy32.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1514 - T1082 | TA0007 - TA0009 - TA0003 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 6 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9992 |
| 555 | */pspy64* | .{0,1000}\/pspy64.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1514 - T1082 | TA0007 - TA0009 - TA0003 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 6 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9993 |
| 556 | */psscanner.go* | .{0,1000}\/psscanner\.go.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1514 - T1082 | TA0007 - TA0009 - TA0003 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 0 | #linux | N/A | 6 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9995 |
| 557 | */psscanner/psscanner.go* | .{0,1000}\/psscanner\/psscanner\.go.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 1 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 9996 |
| 558 | */pwn_php.me* | .{0,1000}\/pwn_php\.me.{0,1000} | offensive_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 10044 |
| 559 | */pwn_python.me* | .{0,1000}\/pwn_python\.me.{0,1000} | offensive_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 10045 |
| 560 | */pwn_tclsh.me* | .{0,1000}\/pwn_tclsh\.me.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 10046 |
| 561 | */pyshark.git* | .{0,1000}\/pyshark\.git.{0,1000} | greyware_tool_keyword | pyshark | Python wrapper for tshark allowing python packet parsing using wireshark dissectors | T1040 - T1213 - T1105 - T1572 | TA0009 - TA0007 | N/A | N/A | Discovery | https://github.com/KimiNewt/pyshark | 1 | 1 | N/A | N/A | 6 | 10 | 2355 | 439 | 2024-12-04T15:41:20Z | 2013-12-28T14:38:22Z | 10096 |
| 562 | */quiet-riot.git* | .{0,1000}\/quiet\-riot\.git.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 1 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 10134 |
| 563 | */rattler.git* | .{0,1000}\/rattler\.git.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 1 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 10179 |
| 564 | */Rattler_32.exe* | .{0,1000}\/Rattler_32\.exe.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 1 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 10180 |
| 565 | */Rattler_x64.exe* | .{0,1000}\/Rattler_x64\.exe.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 1 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 10181 |
| 566 | */rdpscan --* | .{0,1000}\/rdpscan\s\-\-.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 0 | #linux | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10222 |
| 567 | */rdpscan.git* | .{0,1000}\/rdpscan\.git.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 1 | N/A | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10223 |
| 568 | */rdpscan-macos.zip* | .{0,1000}\/rdpscan\-macos\.zip.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 1 | N/A | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10224 |
| 569 | */rdpscan-windows.zip* | .{0,1000}\/rdpscan\-windows\.zip.{0,1000} | greyware_tool_keyword | rdpscan | A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability | T1210 - T1046 | TA0001 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/robertdavidgraham/rdpscan | 1 | 1 | N/A | N/A | 6 | 10 | 904 | 242 | 2019-06-22T21:48:45Z | 2019-05-23T22:50:12Z | 10225 |
| 570 | */Recon-AD.git* | .{0,1000}\/Recon\-AD\.git.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 1 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 10254 |
| 571 | */Recon-AD-AllLocalGroups.dll | .{0,1000}\/Recon\-AD\-AllLocalGroups\.dll | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 1 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 10255 |
| 572 | */Recon-AD-Computers.dll | .{0,1000}\/Recon\-AD\-Computers\.dll | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 1 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 10257 |
| 573 | */Recon-AD-Domain.dll | .{0,1000}\/Recon\-AD\-Domain\.dll | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 1 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 10259 |
| 574 | */Recon-AD-Groups.dll | .{0,1000}\/Recon\-AD\-Groups\.dll | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 1 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 10261 |
| 575 | */Recon-AD-LocalGroups.dll* | .{0,1000}\/Recon\-AD\-LocalGroups\.dll.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 1 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 10264 |
| 576 | */Recon-AD-Users.dll* | .{0,1000}\/Recon\-AD\-Users\.dll.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 1 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 10267 |
| 577 | */rockyou.txt* | .{0,1000}\/rockyou\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 10494 |
| 578 | */rusthound.exe* | .{0,1000}\/rusthound\.exe.{0,1000} | offensive_tool_keyword | RustHound | Active Directory data collector for BloodHound written in Rust | T1087.002 - T1018 - T1059.003 | TA0007 - TA0001 - TA0002 | N/A | N/A | Discovery | https://github.com/OPENCYBER-FR/RustHound | 1 | 1 | N/A | AD Enumeration | 9 | 10 | 1013 | 98 | 2024-10-21T18:58:20Z | 2022-10-12T05:54:35Z | 10643 |
| 579 | */RustHound.git* | .{0,1000}\/RustHound\.git.{0,1000} | offensive_tool_keyword | RustHound | Active Directory data collector for BloodHound written in Rust | T1087.002 - T1018 - T1059.003 | TA0007 - TA0001 - TA0002 | N/A | N/A | Discovery | https://github.com/OPENCYBER-FR/RustHound | 1 | 1 | N/A | AD Enumeration | 9 | 10 | 1013 | 98 | 2024-10-21T18:58:20Z | 2022-10-12T05:54:35Z | 10644 |
| 580 | */rvim -c ':py3 import os*os.execl(\"/bin/sh\* | .{0,1000}\/rvim\s\-c\s\'\:py3\simport\sos.{0,1000}os\.execl\(\\\"\/bin\/sh\\.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 10651 |
| 581 | */RWXfinder.git* | .{0,1000}\/RWXfinder\.git.{0,1000} | offensive_tool_keyword | rwxfinder | The program uses the Windows API functions to traverse through directories and locate DLL files with RWX section | T1059.001 - T1059.003 - T1070.004 | TA0002 - TA0005 - TA0040 | N/A | N/A | Discovery | https://github.com/pwnsauc3/RWXFinder | 1 | 1 | N/A | N/A | 5 | 2 | 101 | 14 | 2023-07-15T15:42:55Z | 2023-07-14T07:47:21Z | 10653 |
| 582 | */s3aclenum.py* | .{0,1000}\/s3aclenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 1 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 10654 |
| 583 | */s3enum.py* | .{0,1000}\/s3enum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 1 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 10656 |
| 584 | */sam_dump_*.txt* | .{0,1000}\/sam_dump_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 10675 |
| 585 | */sandcat.git* | .{0,1000}\/sandcat\.git.{0,1000} | offensive_tool_keyword | sandcat | An open-source pentest oriented web browser | T1216 - T1590 - T1071 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/syhunt/sandcat | 1 | 1 | N/A | N/A | 6 | 6 | 525 | 72 | 2023-12-21T18:40:27Z | 2014-05-20T23:36:21Z | 10685 |
| 586 | */scannerPort.go* | .{0,1000}\/scannerPort\.go.{0,1000} | offensive_tool_keyword | GONET-Scanner | port scanner and arp discover in go | T1595 | TA0001 | N/A | N/A | Discovery | https://github.com/luijait/GONET-Scanner | 1 | 1 | N/A | network exploitation tool | N/A | 1 | 82 | 21 | 2022-03-10T04:35:58Z | 2022-02-02T19:39:09Z | 10713 |
| 587 | */Scans/servers_all_smb*.txt* | .{0,1000}\/Scans\/servers_all_smb.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 10715 |
| 588 | */SearchShares.ps1* | .{0,1000}\/SearchShares\.ps1.{0,1000} | offensive_tool_keyword | SearchOpenFileShares | Searches open files shares for password files or database backups - Extend as you see fit | T1083 - T1135 - T1005 - T1025 | TA0007 - TA0009 | N/A | Dispossessor | Discovery | https://github.com/fashionproof/SearchOpenFileShares | 1 | 1 | N/A | N/A | 7 | 1 | 29 | 6 | 2019-12-13T12:37:42Z | 2019-09-21T13:50:26Z | 10751 |
| 589 | */secretsdump_*.txt* | .{0,1000}\/secretsdump_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 10773 |
| 590 | */secretsmanagerenum.py* | .{0,1000}\/secretsmanagerenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 1 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 10776 |
| 591 | */SeeYouCM-Thief* | .{0,1000}\/SeeYouCM\-Thief.{0,1000} | offensive_tool_keyword | SeeYouCM-Thief | Simple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentials | T1110.001 - T1005 - T1071.001 | TA0001 - TA0011 - TA0005 | N/A | N/A | Discovery | https://github.com/trustedsec/SeeYouCM-Thief | 1 | 1 | N/A | N/A | 9 | 2 | 189 | 35 | 2023-05-11T01:04:36Z | 2022-01-14T20:12:25Z | 10780 |
| 592 | */ShadowHound.git* | .{0,1000}\/ShadowHound\.git.{0,1000} | offensive_tool_keyword | ShadowHound | set of PowerShell scripts for Active Directory enumeration | T1087 - T1018 - T1482 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Friends-Security/ShadowHound | 1 | 1 | N/A | N/A | 8 | 4 | 345 | 36 | 2024-12-01T08:06:02Z | 2024-11-21T15:01:14Z | 10838 |
| 593 | */ShadowSpray.git* | .{0,1000}\/ShadowSpray\.git.{0,1000} | offensive_tool_keyword | ShadowSpray | A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain. | T1110.003 - T1098 - T1059 - T1075 | TA0001 - TA0008 - TA0009 | N/A | Black Basta | Discovery | https://github.com/ShorSec/ShadowSpray | 1 | 1 | N/A | N/A | 7 | 5 | 459 | 80 | 2022-10-14T13:36:51Z | 2022-10-10T08:34:07Z | 10850 |
| 594 | */ShadowSpray/*.cs* | .{0,1000}\/ShadowSpray\/.{0,1000}\.cs.{0,1000} | offensive_tool_keyword | ShadowSpray | A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain. | T1110.003 - T1098 - T1059 - T1075 | TA0001 - TA0008 - TA0009 | N/A | Black Basta | Discovery | https://github.com/ShorSec/ShadowSpray | 1 | 1 | N/A | N/A | 7 | 5 | 459 | 80 | 2022-10-14T13:36:51Z | 2022-10-10T08:34:07Z | 10852 |
| 595 | */shareaudit.exe* | .{0,1000}\/shareaudit\.exe.{0,1000} | offensive_tool_keyword | ShareAudit | A tool for auditing network shares in an Active Directory environment | T1135 - T1005 - T1083 - T1210 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/dionach/ShareAudit | 1 | 1 | N/A | N/A | 8 | 1 | 42 | 15 | 2019-04-29T10:07:57Z | 2019-02-26T16:00:15Z | 10858 |
| 596 | */ShareAudit.git* | .{0,1000}\/ShareAudit\.git.{0,1000} | offensive_tool_keyword | ShareAudit | A tool for auditing network shares in an Active Directory environment | T1135 - T1005 - T1083 - T1210 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/dionach/ShareAudit | 1 | 1 | N/A | N/A | 8 | 1 | 42 | 15 | 2019-04-29T10:07:57Z | 2019-02-26T16:00:15Z | 10859 |
| 597 | */ShareAudit/releases/download/* | .{0,1000}\/ShareAudit\/releases\/download\/.{0,1000} | offensive_tool_keyword | ShareAudit | A tool for auditing network shares in an Active Directory environment | T1135 - T1005 - T1083 - T1210 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/dionach/ShareAudit | 1 | 1 | N/A | N/A | 8 | 1 | 42 | 15 | 2019-04-29T10:07:57Z | 2019-02-26T16:00:15Z | 10860 |
| 598 | */SharpADWS.git* | .{0,1000}\/SharpADWS\.git.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 1 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 10866 |
| 599 | */SharpAVKB.exe* | .{0,1000}\/SharpAVKB\.exe.{0,1000} | offensive_tool_keyword | SharpAVKB | Windows Antivirus Comparison and Patch Number Comparison | T1082 - T1518 - T1083 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpAVKB | 1 | 1 | N/A | N/A | 4 | 1 | 58 | 24 | 2019-10-28T06:50:30Z | 2019-10-14T12:44:22Z | 10875 |
| 600 | */SharpAVKB.git* | .{0,1000}\/SharpAVKB\.git.{0,1000} | offensive_tool_keyword | SharpAVKB | Windows Antivirus Comparison and Patch Number Comparison | T1082 - T1518 - T1083 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpAVKB | 1 | 1 | N/A | N/A | 4 | 1 | 58 | 24 | 2019-10-28T06:50:30Z | 2019-10-14T12:44:22Z | 10876 |
| 601 | */SharpAzbelt.git* | .{0,1000}\/SharpAzbelt\.git.{0,1000} | offensive_tool_keyword | SharpAzbelt | This is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resources | T1082 - T1003 - T1027 - T1110 - T1078 | TA0006 - TA0007 - TA0005 - TA0004 - TA0003 | N/A | N/A | Discovery | https://github.com/redskal/SharpAzbelt | 1 | 1 | N/A | N/A | 8 | 1 | 26 | 7 | 2023-09-21T21:47:32Z | 2023-09-21T21:44:03Z | 10877 |
| 602 | */SharpBuster.dll* | .{0,1000}\/SharpBuster\.dll.{0,1000} | offensive_tool_keyword | SharpBuster | This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution | T1087 - T1112 - T1048.003 - T1105 | TA0007 - TA0040 - TA0002 | N/A | N/A | Discovery | https://github.com/passthehashbrowns/SharpBuster | 1 | 1 | N/A | N/A | 7 | 1 | 62 | 7 | 2020-09-02T15:46:03Z | 2020-08-31T00:33:02Z | 10881 |
| 603 | */SharpBuster.exe* | .{0,1000}\/SharpBuster\.exe.{0,1000} | offensive_tool_keyword | SharpBuster | This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution | T1087 - T1112 - T1048.003 - T1105 | TA0007 - TA0040 - TA0002 | N/A | N/A | Discovery | https://github.com/passthehashbrowns/SharpBuster | 1 | 1 | N/A | N/A | 7 | 1 | 62 | 7 | 2020-09-02T15:46:03Z | 2020-08-31T00:33:02Z | 10882 |
| 604 | */SharpEDRChecker-*.zip* | .{0,1000}\/SharpEDRChecker\-.{0,1000}\.zip.{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 1 | N/A | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 10951 |
| 605 | */SharpEDRChecker.git* | .{0,1000}\/SharpEDRChecker\.git.{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 1 | N/A | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 10955 |
| 606 | */SharpEDRChecker/* | .{0,1000}\/SharpEDRChecker\/.{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 1 | N/A | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 10956 |
| 607 | */SharpEventLog.exe* | .{0,1000}\/SharpEventLog\.exe.{0,1000} | offensive_tool_keyword | SharpEventLog | reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration | T1078 - T1087.001 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpEventLog | 1 | 1 | N/A | N/A | 4 | 3 | 205 | 34 | 2019-10-15T06:26:52Z | 2019-10-15T06:14:32Z | 10965 |
| 608 | */SharpEventLog.git* | .{0,1000}\/SharpEventLog\.git.{0,1000} | offensive_tool_keyword | SharpEventLog | reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration | T1078 - T1087.001 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpEventLog | 1 | 1 | N/A | N/A | 4 | 3 | 205 | 34 | 2019-10-15T06:26:52Z | 2019-10-15T06:14:32Z | 10966 |
| 609 | */SharpGraphView.git* | .{0,1000}\/SharpGraphView\.git.{0,1000} | offensive_tool_keyword | SharpGraphView | Microsoft Graph API post-exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/SharpGraphView | 1 | 1 | N/A | N/A | 6 | 1 | 94 | 9 | 2024-07-13T12:27:38Z | 2024-05-04T11:23:42Z | 10990 |
| 610 | */SharpHound.ps1* | .{0,1000}\/SharpHound\.ps1.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 1 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 11005 |
| 611 | */SharpHound-v*.zip* | .{0,1000}\/SharpHound\-v.{0,1000}\.zip.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 1 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 11006 |
| 612 | */SharpLDAP.git* | .{0,1000}\/SharpLDAP\.git.{0,1000} | offensive_tool_keyword | SharpLDAP | tool written in C# that aims to do enumeration via LDAP queries | T1018 - T1069.003 | TA0007 - TA0011 | N/A | N/A | Discovery | https://github.com/mertdas/SharpLDAP | 1 | 1 | N/A | N/A | 8 | 1 | 0 | 1 | 2023-01-14T21:52:36Z | 2022-11-16T00:38:43Z | 11020 |
| 613 | */SharpNBTScan.git* | .{0,1000}\/SharpNBTScan\.git.{0,1000} | offensive_tool_keyword | SharpNBTScan | a NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumeration | T1018 - T1046 | TA0007 | Ghost Ransomware | N/A | Discovery | https://github.com/BronzeTicket/SharpNBTScan | 1 | 1 | N/A | N/A | 7 | 1 | 71 | 4 | 2021-08-06T05:36:55Z | 2021-07-12T08:57:39Z | 11044 |
| 614 | */SharpOxidResolver.git* | .{0,1000}\/SharpOxidResolver\.git.{0,1000} | offensive_tool_keyword | SharpOxidResolver | search the current domain for computers and get bindings for all of them | T1018 - T1046 - T1016 | TA0007 | N/A | KNOTWEED | Discovery | https://github.com/S3cur3Th1sSh1t/SharpOxidResolver | 1 | 1 | N/A | N/A | 9 | 1 | 50 | 9 | 2020-11-25T08:42:06Z | 2020-11-25T08:23:23Z | 11050 |
| 615 | */SharpOxidResolver/releases/download/* | .{0,1000}\/SharpOxidResolver\/releases\/download\/.{0,1000} | offensive_tool_keyword | SharpOxidResolver | search the current domain for computers and get bindings for all of them | T1018 - T1046 - T1016 | TA0007 | N/A | KNOTWEED | Discovery | https://github.com/S3cur3Th1sSh1t/SharpOxidResolver | 1 | 1 | N/A | N/A | 9 | 1 | 50 | 9 | 2020-11-25T08:42:06Z | 2020-11-25T08:23:23Z | 11051 |
| 616 | */SharpRODC.git* | .{0,1000}\/SharpRODC\.git.{0,1000} | offensive_tool_keyword | SharpRODC | audit the security of read-only domain controllers | T1012 - T1482 - T1207 - T1208 - T1209 - T1212 | TA0007 - TA0008 - TA0006 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpRODC | 1 | 1 | N/A | N/A | 8 | 2 | 115 | 8 | 2023-11-27T12:41:52Z | 2023-11-24T14:35:49Z | 11068 |
| 617 | */SharpShares.git* | .{0,1000}\/SharpShares\.git.{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/Hackcraft-Labs/SharpShares | 1 | 1 | N/A | N/A | 10 | 1 | 33 | 7 | 2023-11-13T14:08:07Z | 2023-10-25T10:34:18Z | 11087 |
| 618 | */SharpShares/Enums* | .{0,1000}\/SharpShares\/Enums.{0,1000} | offensive_tool_keyword | SMBeagle | SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host. | T1087.002 - T1021.002 - T1210 | TA0007 - TA0008 - TA0003 | N/A | N/A | Discovery | https://github.com/punk-security/SMBeagle | 1 | 1 | N/A | N/A | 9 | 8 | 712 | 80 | 2025-01-21T22:34:00Z | 2021-05-31T19:46:57Z | 11088 |
| 619 | */SharpShares/releases/download/* | .{0,1000}\/SharpShares\/releases\/download\/.{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/mitchmoser/SharpShares | 1 | 1 | N/A | N/A | 10 | 4 | 351 | 49 | 2021-09-21T08:14:27Z | 2020-09-25T22:35:57Z | 11089 |
| 620 | */SharpShares-master* | .{0,1000}\/SharpShares\-master.{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/Hackcraft-Labs/SharpShares | 1 | 0 | N/A | N/A | 10 | 1 | 33 | 7 | 2023-11-13T14:08:07Z | 2023-10-25T10:34:18Z | 11090 |
| 621 | */SharpSSDP.git* | .{0,1000}\/SharpSSDP\.git.{0,1000} | offensive_tool_keyword | SharpSSDP | execute SharpSSDP.exe through Cobalt Strike's Beacon "execute-assembly" module to discover SSDP related services | T1046 - T1016 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/rvrsh3ll/SharpSSDP | 1 | 1 | N/A | N/A | 7 | 1 | 17 | 4 | 2018-12-16T17:14:28Z | 2018-12-16T17:14:12Z | 11122 |
| 622 | */SharpSSDP/* | .{0,1000}\/SharpSSDP\/.{0,1000} | offensive_tool_keyword | SharpSSDP | execute SharpSSDP.exe through Cobalt Strike's Beacon "execute-assembly" module to discover SSDP related services | T1046 - T1016 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/rvrsh3ll/SharpSSDP | 1 | 1 | N/A | N/A | 7 | 1 | 17 | 4 | 2018-12-16T17:14:28Z | 2018-12-16T17:14:12Z | 11123 |
| 623 | */SharpView.git* | .{0,1000}\/SharpView\.git.{0,1000} | offensive_tool_keyword | SharpView | C# implementation of harmj0y's PowerView | T1018 - T1482 - T1087.002 - T1069.002 | TA0007 - TA0003 - TA0001 | N/A | Conti - APT29 | Discovery | https://github.com/tevora-threat/SharpView/ | 1 | 1 | N/A | N/A | 10 | 10 | 1032 | 196 | 2024-03-22T16:34:09Z | 2018-07-24T21:15:04Z | 11154 |
| 624 | */SilentHound.git* | .{0,1000}\/SilentHound\.git.{0,1000} | offensive_tool_keyword | SilentHound | Quietly enumerate an Active Directory Domain via LDAP parsing users + admins + groups... | T1087.002 - T1018 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/layer8secure/SilentHound | 1 | 1 | N/A | AD Enumeration | 7 | 5 | 489 | 47 | 2023-01-23T20:41:55Z | 2022-07-01T13:49:24Z | 11266 |
| 625 | */SimpleNTSyscallFuzzer.git* | .{0,1000}\/SimpleNTSyscallFuzzer\.git.{0,1000} | offensive_tool_keyword | SimpleNTSyscallFuzzer | Fuzzer for Windows kernel syscalls. | T1055.011 - T1218 | TA0005 - TA0007 | N/A | N/A | Discovery | https://github.com/waleedassar/SimpleNTSyscallFuzzer | 1 | 1 | N/A | N/A | 7 | 2 | 145 | 25 | 2024-01-25T02:39:31Z | 2022-03-12T10:16:30Z | 11278 |
| 626 | */SlinkyCat.git* | .{0,1000}\/SlinkyCat\.git.{0,1000} | offensive_tool_keyword | SlinkyCat | This script performs a series of AD enumeration tasks | T1087.002 - T1018 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/LaresLLC/SlinkyCat | 1 | 1 | N/A | AD Enumeration | 7 | 1 | 79 | 8 | 2023-07-12T15:29:31Z | 2023-07-03T23:44:18Z | 11324 |
| 627 | */SmallSecretsDump.py* | .{0,1000}\/SmallSecretsDump\.py.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 1 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 11347 |
| 628 | */SMBeagle* | .{0,1000}\/SMBeagle.{0,1000} | offensive_tool_keyword | SMBeagle | SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host. | T1087.002 - T1021.002 - T1210 | TA0007 - TA0008 - TA0003 | N/A | N/A | Discovery | https://github.com/punk-security/SMBeagle | 1 | 1 | N/A | N/A | 9 | 8 | 712 | 80 | 2025-01-21T22:34:00Z | 2021-05-31T19:46:57Z | 11364 |
| 629 | */SMBGhost/scanner.py* | .{0,1000}\/SMBGhost\/scanner\.py.{0,1000} | offensive_tool_keyword | SMBGhost | Simple scanner for CVE-2020-0796 - SMBv3 RCE. | T1210 - T1573 - T1553 - T1216 - T1027 | TA0006 - TA0011 - TA0008 | N/A | N/A | Discovery | https://github.com/ollypwn/SMBGhost | 1 | 1 | N/A | N/A | 7 | 7 | 678 | 194 | 2020-10-01T08:36:29Z | 2020-03-11T15:21:27Z | 11377 |
| 630 | */smblogin.ps1* | .{0,1000}\/smblogin\.ps1.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 1 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 11383 |
| 631 | */smbmap.git* | .{0,1000}\/smbmap\.git.{0,1000} | offensive_tool_keyword | smbmap | SMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks. | T1210.001 - T1083 - T1213 - T1021 | TA0007 - TA0003 - TA0002 - TA0001 | N/A | MuddyWater - Dispossessor | Discovery | https://github.com/ShawnDEvans/smbmap | 1 | 1 | N/A | N/A | 10 | 10 | 1890 | 359 | 2025-02-28T18:09:10Z | 2015-03-16T13:15:00Z | 11385 |
| 632 | */smbmapDump* | .{0,1000}\/smbmapDump.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 11387 |
| 633 | */smbscan-*.csv* | .{0,1000}\/smbscan\-.{0,1000}\.csv.{0,1000} | offensive_tool_keyword | smbscan | SMBScan is a tool to enumerate file shares on an internal network. | T1135 - T1046 - T1021 | TA0007 - TA0043 - TA0008 | N/A | APT22 | Discovery | https://github.com/jeffhacks/smbscan | 1 | 0 | #linux | N/A | 8 | 1 | 44 | 6 | 2025-03-24T01:55:30Z | 2021-10-26T02:28:34Z | 11398 |
| 634 | */smbscan-*.log* | .{0,1000}\/smbscan\-.{0,1000}\.log.{0,1000} | offensive_tool_keyword | smbscan | SMBScan is a tool to enumerate file shares on an internal network. | T1135 - T1046 - T1021 | TA0007 - TA0043 - TA0008 | N/A | APT22 | Discovery | https://github.com/jeffhacks/smbscan | 1 | 0 | #linux | N/A | 8 | 1 | 44 | 6 | 2025-03-24T01:55:30Z | 2021-10-26T02:28:34Z | 11399 |
| 635 | */smbscan.git* | .{0,1000}\/smbscan\.git.{0,1000} | offensive_tool_keyword | smbscan | SMBScan is a tool to enumerate file shares on an internal network. | T1135 - T1046 - T1021 | TA0007 - TA0043 - TA0008 | N/A | APT22 | Discovery | https://github.com/jeffhacks/smbscan | 1 | 1 | N/A | N/A | 8 | 1 | 44 | 6 | 2025-03-24T01:55:30Z | 2021-10-26T02:28:34Z | 11400 |
| 636 | */smbscan.py* | .{0,1000}\/smbscan\.py.{0,1000} | offensive_tool_keyword | smbscan | SMBScan is a tool to enumerate file shares on an internal network. | T1135 - T1046 - T1021 | TA0007 - TA0043 - TA0008 | N/A | APT22 | Discovery | https://github.com/jeffhacks/smbscan | 1 | 1 | N/A | N/A | 8 | 1 | 44 | 6 | 2025-03-24T01:55:30Z | 2021-10-26T02:28:34Z | 11401 |
| 637 | */smbsr.db* | .{0,1000}\/smbsr\.db.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | #linux | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 11409 |
| 638 | */SMBSR.git* | .{0,1000}\/SMBSR\.git.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 1 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 11410 |
| 639 | */smbsr.log* | .{0,1000}\/smbsr\.log.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 1 | #logfile #linux | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 11412 |
| 640 | */smbsr.py* | .{0,1000}\/smbsr\.py.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 1 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 11414 |
| 641 | */smbsr_results.csv* | .{0,1000}\/smbsr_results\.csv.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 1 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 11415 |
| 642 | */SnaffPoint.git* | .{0,1000}\/SnaffPoint\.git.{0,1000} | offensive_tool_keyword | SnaffPoint | A tool for pointesters to find candies in SharePoint | T1210.001 - T1087.002 - T1059.006 | TA0007 - TA0002 - TA0006 | N/A | N/A | Discovery | https://github.com/nheiniger/SnaffPoint | 1 | 1 | N/A | N/A | 7 | 3 | 254 | 25 | 2022-11-04T13:26:24Z | 2022-08-25T13:16:06Z | 11456 |
| 643 | */snsenum.py* | .{0,1000}\/snsenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 1 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 11482 |
| 644 | */SOAPHound.exe* | .{0,1000}\/SOAPHound\.exe.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 1 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 11483 |
| 645 | */SOAPHound.git* | .{0,1000}\/SOAPHound\.git.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 1 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 11484 |
| 646 | */SOAPHound/Program.cs* | .{0,1000}\/SOAPHound\/Program\.cs.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 1 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 11485 |
| 647 | */sshpass /bin/sh -p* | .{0,1000}\/sshpass\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 11611 |
| 648 | */StandIn.exe* | .{0,1000}\/StandIn\.exe.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 1 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 11650 |
| 649 | */StandIn.git* | .{0,1000}\/StandIn\.git.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 1 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 11651 |
| 650 | */StandIn_Net35.exe* | .{0,1000}\/StandIn_Net35\.exe.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 1 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 11652 |
| 651 | */StandIn_Net45.exe * | .{0,1000}\/StandIn_Net45\.exe\s.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 1 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 11653 |
| 652 | */StandIn-1.3.zip* | .{0,1000}\/StandIn\-1\.3\.zip.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 1 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 11654 |
| 653 | */stdbuf -i0 /bin/sh -p* | .{0,1000}\/stdbuf\s\-i0\s\/bin\/sh\s\-p.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 11666 |
| 654 | */TeamsEnum.git* | .{0,1000}\/TeamsEnum\.git.{0,1000} | offensive_tool_keyword | TeamsEnum | User Enumeration of Microsoft Teams users via API | T1589.002 - T1590 | TA0007 - TA0001 | N/A | Black Basta | Discovery | https://github.com/sse-secure-systems/TeamsEnum | 1 | 1 | N/A | N/A | 6 | 2 | 153 | 21 | 2024-03-27T18:14:25Z | 2023-04-03T18:35:15Z | 11841 |
| 655 | */teamsenum.py* | .{0,1000}\/teamsenum\.py.{0,1000} | offensive_tool_keyword | TeamsEnum | User Enumeration of Microsoft Teams users via API | T1589.002 - T1590 | TA0007 - TA0001 | N/A | Black Basta | Discovery | https://github.com/sse-secure-systems/TeamsEnum | 1 | 1 | N/A | N/A | 6 | 2 | 153 | 21 | 2024-03-27T18:14:25Z | 2023-04-03T18:35:15Z | 11842 |
| 656 | */thief.py* | .{0,1000}\/thief\.py.{0,1000} | offensive_tool_keyword | SeeYouCM-Thief | Simple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentials | T1110.001 - T1005 - T1071.001 | TA0001 - TA0011 - TA0005 | N/A | N/A | Discovery | https://github.com/trustedsec/SeeYouCM-Thief | 1 | 1 | N/A | N/A | 9 | 2 | 189 | 35 | 2023-05-11T01:04:36Z | 2022-01-14T20:12:25Z | 11894 |
| 657 | */tmp/.manspider* | .{0,1000}\/tmp\/\.manspider.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | #linux | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 11948 |
| 658 | */TokenDump.exe* | .{0,1000}\/TokenDump\.exe.{0,1000} | offensive_tool_keyword | PrivFu | inspect token information | T1057 | TA0007 | N/A | N/A | Discovery | https://github.com/daem0nc0re/PrivFu | 1 | 1 | N/A | TokenDump | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 12011 |
| 659 | */trackerjacker* | .{0,1000}\/trackerjacker.{0,1000} | offensive_tool_keyword | trackerjacker | Like nmap for mapping wifi networks you're not connected to. Maps and tracks wifi networks and devices through raw 802.11 monitoring. | T1040 - T1018 - T1591 | TA0007 - - TA0043 | N/A | N/A | Discovery | https://github.com/calebmadrigal/trackerjacker | 1 | 0 | #linux | N/A | N/A | 10 | 2672 | 190 | 2024-01-16T05:10:22Z | 2016-12-18T22:01:13Z | 12071 |
| 660 | */unshare -r /bin/sh* | .{0,1000}\/unshare\s\-r\s\/bin\/sh.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 12236 |
| 661 | */usr/bin/polenum* | .{0,1000}\/usr\/bin\/polenum.{0,1000} | offensive_tool_keyword | polenum | Uses Impacket Library to get the password policy from a windows machine | T1012 - T1596 | TA0009 - TA0007 | N/A | N/A | Discovery | https://salsa.debian.org/pkg-security-team/polenum | 1 | 0 | #linux | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 12339 |
| 662 | */usr/local/bin/nullinux* | .{0,1000}\/usr\/local\/bin\/nullinux.{0,1000} | offensive_tool_keyword | nullinux | Internal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB. | T1087 - T1016 - T1077 - T1018 | TA0007 - TA0006 | N/A | N/A | Discovery | https://github.com/m8sec/nullinux | 1 | 0 | #linux | N/A | 7 | 6 | 575 | 101 | 2024-06-19T14:29:09Z | 2016-04-28T16:45:02Z | 12352 |
| 663 | */view -c ':py3 import os*os.execl(\"/bin/sh\* | .{0,1000}\/view\s\-c\s\'\:py3\simport\sos.{0,1000}os\.execl\(\\\"\/bin\/sh\\.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 12445 |
| 664 | */watch -x sh -c 'reset* exec sh 1>&0 2>&0* | .{0,1000}\/watch\s\-x\ssh\s\-c\s\'reset.{0,1000}\sexec\ssh\s1\>\&0\s2\>\&0.{0,1000} | greyware_tool_keyword | AutoSUID | automate harvesting the SUID executable files and to find a way for further escalating the privileges | T1548.003 - T1069.001 - T1068 | TA0004 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/IvanGlinkin/AutoSUID | 1 | 0 | #linux | N/A | 9 | 4 | 375 | 77 | 2024-04-29T12:30:35Z | 2021-11-28T19:44:18Z | 12499 |
| 665 | */windapsearch.git* | .{0,1000}\/windapsearch\.git.{0,1000} | offensive_tool_keyword | windapsearch | Python script to enumerate users - groups and computers from a Windows domain through LDAP queries | T1087.002 - T1018 - T1069.002 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/ropnop/windapsearch | 1 | 1 | N/A | AD Enumeration | 7 | 9 | 866 | 154 | 2022-04-20T07:40:42Z | 2016-08-10T21:43:30Z | 12590 |
| 666 | */windapsearch.py* | .{0,1000}\/windapsearch\.py.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 1 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 12591 |
| 667 | */windapsearch_*.txt* | .{0,1000}\/windapsearch_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | linWinPwn | linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks | T1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016 | TA0007 - TA0009 - TA0003 - TA0002 - TA0005 | N/A | Black Basta | Discovery | https://github.com/lefayjey/linWinPwn | 1 | 1 | #linux | N/A | 10 | 10 | 1953 | 283 | 2025-04-15T14:51:50Z | 2021-12-16T22:13:10Z | 12592 |
| 668 | */wordlists/combined_male_names.txt* | .{0,1000}\/wordlists\/combined_male_names\.txt.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | #linux | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 12715 |
| 669 | */wordlists/familynames-usa-top1000.txt* | .{0,1000}\/wordlists\/familynames\-usa\-top1000\.txt.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | #linux | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 12716 |
| 670 | */wordlists/femalenames-usa-top1000.txt* | .{0,1000}\/wordlists\/femalenames\-usa\-top1000\.txt.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | #linux | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 12717 |
| 671 | */wordlists/malenames-usa-top1000.txt* | .{0,1000}\/wordlists\/malenames\-usa\-top1000\.txt.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | #linux | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 12718 |
| 672 | */wordlists/names_quit_riot.txt* | .{0,1000}\/wordlists\/names_quit_riot\.txt.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | #linux | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 12719 |
| 673 | *@" ( _/_ _// ~b33f"* | .{0,1000}\@\"\s\(\s_\/_\s\s\s_\/\/\s\s\s\~b33f\".{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 12872 |
| 674 | *[!] Failed to enumerate Credman:* | .{0,1000}\[!\]\s\s\s\sFailed\sto\senumerate\sCredman\:.{0,1000} | offensive_tool_keyword | SharpAzbelt | This is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resources | T1082 - T1003 - T1027 - T1110 - T1078 | TA0006 - TA0007 - TA0005 - TA0004 - TA0003 | N/A | N/A | Discovery | https://github.com/redskal/SharpAzbelt | 1 | 0 | #content | N/A | 8 | 1 | 26 | 7 | 2023-09-21T21:47:32Z | 2023-09-21T21:44:03Z | 12891 |
| 675 | *[!] AS-REP Roastable user:* | .{0,1000}\[!\]\sAS\-REP\sRoastable\suser\:.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | #content | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 12892 |
| 676 | *[!] Could not execute query. Could not bind to LDAP://rootDSE.* | .{0,1000}\[!\]\sCould\snot\sexecute\squery\.\sCould\snot\sbind\sto\sLDAP\:\/\/rootDSE\..{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | #content | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 12897 |
| 677 | *[!] Failed to enumerate ADCS data.* | .{0,1000}\[!\]\sFailed\sto\senumerate\sADCS\sdata\..{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | #content | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 12917 |
| 678 | *[!] Insecure resource delegations found. Exporting report:* | .{0,1000}\[!\]\sInsecure\sresource\sdelegations\sfound\.\sExporting\sreport\:.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | #content | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 12938 |
| 679 | *[!] Insecure trustee delegations found. Exporting report: * | .{0,1000}\[!\]\sInsecure\strustee\sdelegations\sfound\.\sExporting\sreport\:\s.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | #content | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 12939 |
| 680 | *[!] You have DCs with RC4 or DES allowed for Kerberos!!!* | .{0,1000}\[!\]\sYou\shave\sDCs\swith\sRC4\sor\sDES\sallowed\sfor\sKerberos!!!.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | #content | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 12976 |
| 681 | *[!][!][!] Checking Directories [!][!][!]* | .{0,1000}\[!\]\[!\]\[!\]\sChecking\sDirectories\s\[!\]\[!\]\[!\].{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | #content | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 12977 |
| 682 | *[!][!][!] Checking drivers [!][!][!]* | .{0,1000}\[!\]\[!\]\[!\]\sChecking\sdrivers\s\[!\]\[!\]\[!\].{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | #content | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 12978 |
| 683 | *[!][!][!] Checking modules loaded in your current process [!][!][!]* | .{0,1000}\[!\]\[!\]\[!\]\sChecking\smodules\sloaded\sin\syour\scurrent\sprocess\s\[!\]\[!\]\[!\].{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | #content | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 12979 |
| 684 | *[!][!][!] Checking Services [!][!][!]* | .{0,1000}\[!\]\[!\]\[!\]\sChecking\sServices\s\[!\]\[!\]\[!\].{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | #content | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 12980 |
| 685 | *[!][!][!] EDR Checks Complete [!][!][!]* | .{0,1000}\[!\]\[!\]\[!\]\sEDR\sChecks\sComplete\s\[!\]\[!\]\[!\].{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | #content | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 12981 |
| 686 | *[!][!][!] Welcome to SharpEDRChecker by @PwnDexter [!][!][!]* | .{0,1000}\[!\]\[!\]\[!\]\sWelcome\sto\sSharpEDRChecker\sby\s\@PwnDexter\s\[!\]\[!\]\[!\].{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | #content | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 12982 |
| 687 | *[-] Account to kerberoast does not exist!* | .{0,1000}\[\-\]\sAccount\sto\skerberoast\sdoes\snot\sexist!.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | #content | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 12997 |
| 688 | *[-] Elevating * with DCSync privileges failed* | .{0,1000}\[\-\]\sElevating\s.{0,1000}\swith\sDCSync\sprivileges\sfailed.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | #content | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 13004 |
| 689 | *[-] Kerberoast* | .{0,1000}\[\-\]\sKerberoast.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | #content | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 13020 |
| 690 | *[-] No Kerberoastable accounts found* | .{0,1000}\[\-\]\sNo\sKerberoastable\saccounts\sfound.{0,1000} | offensive_tool_keyword | Cable | *.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation* | T1087 - T1016 - T1059 - T1482 - T1078 | TA0007 - TA0002 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/logangoins/Cable | 1 | 0 | #content | N/A | 7 | 4 | 361 | 40 | 2025-04-09T01:12:47Z | 2024-08-10T19:47:08Z | 13022 |
| 691 | *[-] Removed PSRemote Collection* | .{0,1000}\[\-\]\sRemoved\sPSRemote\sCollection.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | #content | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 13026 |
| 692 | *[+] Attack aborted. Exiting* | .{0,1000}\[\+\]\sAttack\saborted\.\sExiting.{0,1000} | offensive_tool_keyword | ShadowSpray | A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain. | T1110.003 - T1098 - T1059 - T1075 | TA0001 - TA0008 - TA0009 | N/A | Black Basta | Discovery | https://github.com/ShorSec/ShadowSpray | 1 | 0 | #content | N/A | 7 | 5 | 459 | 80 | 2022-10-14T13:36:51Z | 2022-10-10T08:34:07Z | 13052 |
| 693 | *[+] Connected to \\\\*\\IPC$* | .{0,1000}\[\+\]\sConnected\sto\s\\\\\\\\.{0,1000}\\\\IPC\$.{0,1000} | offensive_tool_keyword | RemotePipeList | A small tool that can list the named pipes bound on a remote system. | T1047 - T1021.006 | TA0008 - TA0002 | N/A | N/A | Discovery | https://github.com/outflanknl/C2-Tool-Collection/tree/main/Other/RemotePipeList | 1 | 0 | #content | N/A | 10 | 10 | 1213 | 204 | 2023-10-27T14:16:17Z | 2022-04-22T13:43:35Z | 13081 |
| 694 | *[+] Defender Config Dumped to * | .{0,1000}\[\+\]\sDefender\sConfig\sDumped\sto\s.{0,1000} | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | #content | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 13097 |
| 695 | *[+] Dropping into shell* | .{0,1000}\[\+\]\sDropping\sinto\sshell.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 0 | #content #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 13111 |
| 696 | *[+] Dumped Allowed Threats to * | .{0,1000}\[\+\]\sDumped\sAllowed\sThreats\sto\s.{0,1000}\s | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | #content | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 13115 |
| 697 | *[+] Dumped Exclusion Paths to ExclusionPaths.csv* | .{0,1000}\[\+\]\sDumped\sExclusion\sPaths\sto\sExclusionPaths\.csv.{0,1000} | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | #content | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 13116 |
| 698 | *[+] Dumped Exploit Guard Protection History* | .{0,1000}\[\+\]\sDumped\sExploit\sGuard\sProtection\sHistory.{0,1000} | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | #content | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 13117 |
| 699 | *[+] Dumped Firewall Exclusions to * | .{0,1000}\[\+\]\sDumped\sFirewall\sExclusions\sto\s.{0,1000} | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | #content | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 13118 |
| 700 | *[+] Dumped Protection History to ProtectionHistory.csv* | .{0,1000}\[\+\]\sDumped\sProtection\sHistory\sto\sProtectionHistory\.csv.{0,1000} | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | #content | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 13119 |
| 701 | *[+] Dumping Defender Excluded Paths* | .{0,1000}\[\+\]\sDumping\sDefender\sExcluded\sPaths.{0,1000} | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | #content | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 13120 |
| 702 | *[+] Dumping Defender Protection History* | .{0,1000}\[\+\]\sDumping\sDefender\sProtection\sHistory.{0,1000} | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | #content | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 13121 |
| 703 | *[+] Dumping Enabled ASR Rules* | .{0,1000}\[\+\]\sDumping\sEnabled\sASR\sRules.{0,1000} | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | #content | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 13122 |
| 704 | *[+] Enumerating ASR Rules on Local System* | .{0,1000}\[\+\]\sEnumerating\sASR\sRules\son\sLocal\sSystem.{0,1000} | offensive_tool_keyword | MDE_Enum | extract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rules | T1070.006 | TA0005 - TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/0xsp-SRD/MDE_Enum | 1 | 0 | #content | N/A | 8 | 2 | 198 | 18 | 2024-06-10T18:40:27Z | 2024-06-06T15:54:44Z | 13129 |
| 705 | *[+] Enumerating ASR Rules on Remote System * | .{0,1000}\[\+\]\sEnumerating\sASR\sRules\son\sRemote\sSystem\s.{0,1000} | offensive_tool_keyword | MDE_Enum | extract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rules | T1070.006 | TA0005 - TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/0xsp-SRD/MDE_Enum | 1 | 0 | #content | N/A | 8 | 2 | 198 | 18 | 2024-06-10T18:40:27Z | 2024-06-06T15:54:44Z | 13130 |
| 706 | *[+] Enumerating driver services...* | .{0,1000}\[\+\]\sEnumerating\sdriver\sservices\.\.\..{0,1000} | offensive_tool_keyword | DriverQuery | Collect details about drivers on the system and optionally filter to find only ones not signed by Microsoft | T1124 - T1057 - T1082 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/matterpreter/OffensiveCSharp/tree/master/DriverQuery | 1 | 0 | #content | N/A | 10 | 10 | 1416 | 250 | 2023-02-06T14:56:26Z | 2019-02-06T00:32:29Z | 13131 |
| 707 | *[+] Finding Kerberoastable accounts* | .{0,1000}\[\+\]\sFinding\sKerberoastable\saccounts.{0,1000} | offensive_tool_keyword | Cable | *.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation* | T1087 - T1016 - T1059 - T1482 - T1078 | TA0007 - TA0002 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/logangoins/Cable | 1 | 0 | #content | N/A | 7 | 4 | 361 | 40 | 2025-04-09T01:12:47Z | 2024-08-10T19:47:08Z | 13143 |
| 708 | *[+] Finished Enumerating Shares* | .{0,1000}\[\+\]\sFinished\sEnumerating\sShares.{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/Hackcraft-Labs/SharpShares | 1 | 0 | #content | N/A | 10 | 1 | 33 | 7 | 2023-11-13T14:08:07Z | 2023-10-25T10:34:18Z | 13144 |
| 709 | *[+] Jecretz Results* | .{0,1000}\[\+\]\sJecretz\sResults.{0,1000} | offensive_tool_keyword | jecretz | Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets | T1552 - T1114 - T1119 - T1070 | TA0006 - TA0009 - TA0005 | N/A | Scattered Spider* | Discovery | https://github.com/sahadnk72/jecretz | 1 | 0 | #content | N/A | 7 | 1 | 43 | 9 | 2022-12-08T10:00:11Z | 2020-05-25T14:40:28Z | 13206 |
| 710 | *[+] No insecure resource delegations found. Eureka!* | .{0,1000}\[\+\]\sNo\sinsecure\sresource\sdelegations\sfound\.\sEureka!.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | #content | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 13232 |
| 711 | *[+] No insecure trustee delegations found. Eureka!* | .{0,1000}\[\+\]\sNo\sinsecure\strustee\sdelegations\sfound\.\sEureka!.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | #content | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 13233 |
| 712 | *[+] NTDS.dit, SYSTEM & SAM saved to output folder* | .{0,1000}\[\+\]\sNTDS\.dit,\sSYSTEM\s\&\sSAM\ssaved\sto\soutput\sfolder.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | #content | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 13238 |
| 713 | *[+] Pipe listing:* | .{0,1000}\[\+\]\sPipe\slisting\:.{0,1000} | offensive_tool_keyword | RemotePipeList | A small tool that can list the named pipes bound on a remote system. | T1047 - T1021.006 | TA0008 - TA0002 | N/A | N/A | Discovery | https://github.com/outflanknl/C2-Tool-Collection/tree/main/Other/RemotePipeList | 1 | 0 | #content | N/A | 10 | 10 | 1213 | 204 | 2023-10-27T14:16:17Z | 2022-04-22T13:43:35Z | 13257 |
| 714 | *[+] Querying DC without Global Catalog: * | .{0,1000}\[\+\]\sQuerying\sDC\swithout\sGlobal\sCatalog\:\s.{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/Hackcraft-Labs/SharpShares | 1 | 0 | #content | N/A | 10 | 1 | 33 | 7 | 2023-11-13T14:08:07Z | 2023-10-25T10:34:18Z | 13274 |
| 715 | *[+] SID added to msDS-AllowedToActOnBehalfOfOtherIdentity* | .{0,1000}\[\+\]\sSID\sadded\sto\smsDS\-AllowedToActOnBehalfOfOtherIdentity.{0,1000} | offensive_tool_keyword | Cable | *.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation* | T1087 - T1016 - T1059 - T1482 - T1078 | TA0007 - TA0002 - TA0003 - TA0005 | N/A | N/A | Discovery | https://github.com/logangoins/Cable | 1 | 0 | #content | N/A | 7 | 4 | 361 | 40 | 2025-04-09T01:12:47Z | 2024-08-10T19:47:08Z | 13319 |
| 716 | *[+] SID added to msDS-AllowedToActOnBehalfOfOtherIdentity* | .{0,1000}\[\+\]\sSID\sadded\sto\smsDS\-AllowedToActOnBehalfOfOtherIdentity.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | #content | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 13320 |
| 717 | *[+] Starting pspy now* | .{0,1000}\[\+\]\sStarting\spspy\snow.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 0 | #content #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 13329 |
| 718 | *[+] Starting share enumeration against * hosts* | .{0,1000}Starting\sshare\senumeration\sagainst\s.{0,1000}\shosts.{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/Hackcraft-Labs/SharpShares | 1 | 0 | #content | N/A | 10 | 1 | 33 | 7 | 2023-11-13T14:08:07Z | 2023-10-25T10:34:18Z | 13330 |
| 719 | *[+] Use secretsdump.py* | .{0,1000}\[\+\]\sUse\ssecretsdump\.py.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | #content | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 13384 |
| 720 | *[ADSI]* | Select-Object -Property *lockoutDuration* | .{0,1000}\[ADSI\].{0,1000}\s\|\sSelect\-Object\s\-Property\s.{0,1000}lockoutDuration.{0,1000} | greyware_tool_keyword | ldap queries | enumeration of Domain Password Policies | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13429 |
| 721 | *[ADSI]* | Select-Object -Property *lockoutThreshold* | .{0,1000}\[ADSI\].{0,1000}\s\|\sSelect\-Object\s\-Property\s.{0,1000}lockoutThreshold.{0,1000} | greyware_tool_keyword | ldap queries | enumeration of Domain Password Policies | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13430 |
| 722 | *[ADSI]* | Select-Object -Property *minPwdLength* | .{0,1000}\[ADSI\].{0,1000}\s\|\sSelect\-Object\s\-Property\s.{0,1000}minPwdLength.{0,1000} | greyware_tool_keyword | ldap queries | enumeration of Domain Password Policies | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13431 |
| 723 | *[ADSI]*LDAP://CN=Domain Admins*| ForEach-Object {[adsi]"LDAP://$_"}; *.distinguishedname* | .{0,1000}\[ADSI\].{0,1000}LDAP\:\/\/CN\=Domain\sAdmins.{0,1000}\|\sForEach\-Object\s\{\[adsi\]\"LDAP\:\/\/\$_\"\}\;\s.{0,1000}\.distinguishedname.{0,1000} | greyware_tool_keyword | ldap queries | enumeration of Domain Admins group members | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13432 |
| 724 | *[ADSI]*LDAP://dc=* | Select -Property pwdProperties* | .{0,1000}\[ADSI\].{0,1000}LDAP\:\/\/dc\=.{0,1000}\s\|\sSelect\s\-Property\spwdProperties.{0,1000} | greyware_tool_keyword | ldap queries | get LDAP properties for password settings directly | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13433 |
| 725 | *[adsisearcher]"(&(objectCategory=person)(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))"; $users = $searchUsers.FindAll(); $userProps = $users.Properties; $userProps | Where-Object {$_.description}* | .{0,1000}\[adsisearcher\]\"\(\&\(objectCategory\=person\)\(objectClass\=user\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\)\"\;\s\$users\s\=\s\$searchUsers\.FindAll\(\)\;\s\$userProps\s\=\s\$users\.Properties\;\s\$userProps\s\|\sWhere\-Object\s\{\$_\.description\}.{0,1000} | greyware_tool_keyword | ldap queries | find user descriptions in Active Directory: | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13434 |
| 726 | *[adsisearcher]"(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=2))"* | .{0,1000}\[adsisearcher\]\"\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\".{0,1000} | greyware_tool_keyword | ldap queries | find all disabled user accounts | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13435 |
| 727 | *[adsisearcher]"(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=2560)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))"* | .{0,1000}\[adsisearcher\]\"\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2560\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\)\".{0,1000} | greyware_tool_keyword | ldap queries | get a count of all inter domain trust accounts | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13436 |
| 728 | *[adsisearcher]"(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=32)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))* | .{0,1000}\[adsisearcher\]\"\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=32\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\).{0,1000} | greyware_tool_keyword | ldap queries | Detection of all accounts with 'Password Not Required' | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13437 |
| 729 | *[adsisearcher]'(&(objectCategory=computer)(primaryGroupID=516))').FindAll()* | .{0,1000}\[adsisearcher\]\'\(\&\(objectCategory\=computer\)\(primaryGroupID\=516\)\)\'\)\.FindAll\(\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate all Domain Controllers | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://web.archive.org/web/20240109000256/https://cyberdom.blog/2024/01/07/defender-for-identity-hunting-for-ldap/ | 1 | 0 | N/A | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 13438 |
| 730 | *[adsisearcher]'(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=32))').FindAll()* | .{0,1000}\[adsisearcher\]\'\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=32\)\)\'\)\.FindAll\(\).{0,1000} | greyware_tool_keyword | ldap queries | Enumerate all accounts that do not require a password | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca384 | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 13439 |
| 731 | *[adsisearcher]*(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=66048)(!(userAccountControl:1.2.840.113556.1.4.803:=2))* | .{0,1000}\[adsisearcher\].{0,1000}\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=66048\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\).{0,1000} | greyware_tool_keyword | ldap queries | ADSI query to retrieve all active user accounts with non-expiring passwords | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13440 |
| 732 | *[Find-DomainShare] Enumerating server * | .{0,1000}\[Find\-DomainShare\]\sEnumerating\sserver\s.{0,1000} | offensive_tool_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | #content | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 13460 |
| 733 | *[Get-ADRRevertToSelf] Token impersonation successfully reverted* | .{0,1000}\[Get\-ADRRevertToSelf\]\sToken\simpersonation\ssuccessfully\sreverted.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 13463 |
| 734 | *[Get-ADR-UserImpersonation] Alternate credentials successfully impersonated* | .{0,1000}\[Get\-ADR\-UserImpersonation\]\sAlternate\scredentials\ssuccessfully\simpersonated.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 13464 |
| 735 | *[i] AAD Join:*enumerate* | .{0,1000}\[i\]\sAAD\sJoin\:.{0,1000}enumerate.{0,1000} | offensive_tool_keyword | SharpAzbelt | This is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resources | T1082 - T1003 - T1027 - T1110 - T1078 | TA0006 - TA0007 - TA0005 - TA0004 - TA0003 | N/A | N/A | Discovery | https://github.com/redskal/SharpAzbelt | 1 | 0 | #content | N/A | 8 | 1 | 26 | 7 | 2023-09-21T21:47:32Z | 2023-09-21T21:44:03Z | 13468 |
| 736 | *[i] Checking for insecure trustee/resource delegations* | .{0,1000}\[i\]\sChecking\sfor\sinsecure\strustee\/resource\sdelegations.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 13470 |
| 737 | *[i] Credman:*Credential Blob Decrypted* | .{0,1000}\[i\]\sCredman\:.{0,1000}Credential\sBlob\sDecrypted.{0,1000} | offensive_tool_keyword | SharpAzbelt | This is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resources | T1082 - T1003 - T1027 - T1110 - T1078 | TA0006 - TA0007 - TA0005 - TA0004 - TA0003 | N/A | N/A | Discovery | https://github.com/redskal/SharpAzbelt | 1 | 0 | #content | N/A | 8 | 1 | 26 | 7 | 2023-09-21T21:47:32Z | 2023-09-21T21:44:03Z | 13471 |
| 738 | *[i] Running ADeleg and creating * | .{0,1000}\[i\]\sRunning\sADeleg\sand\screating\s.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 13477 |
| 739 | *[System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain().DomainControllers* | .{0,1000}\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\.DomainControllers.{0,1000} | greyware_tool_keyword | ldap queries | Discover all Domain Controller in the domain using ADSI | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://adsecurity.org/?p=299 | 1 | 0 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 13509 |
| 740 | *[System.DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest().GlobalCatalogs* | .{0,1000}\[System\.DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\.GlobalCatalogs.{0,1000} | greyware_tool_keyword | ldap queries | Discover all Global Catalogs in the forest using ADSI | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://adsecurity.org/?p=299 | 1 | 0 | N/A | N/A | 6 | 10 | N/A | N/A | N/A | N/A | 13510 |
| 741 | *[System.DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest().RootDomain.PDCRoleOwner.Name* | .{0,1000}\[System\.DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\.RootDomain\.PDCRoleOwner\.Name.{0,1000} | greyware_tool_keyword | ldap queries | query for the primary domain controller within the forest | T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/swarleysez/AD-common-queries | 1 | 0 | N/A | N/A | 8 | 1 | 7 | 3 | 2020-05-24T03:23:09Z | 2020-03-10T19:43:51Z | 13511 |
| 742 | *[System.Environment]::GetEnvironmentVariable('username')* | .{0,1000}\[System\.Environment\]\:\:GetEnvironmentVariable\(\'username\'\).{0,1000} | greyware_tool_keyword | powershell | alternativeto whoami | T1033 | TA0007 | N/A | N/A | Discovery | N/A | 1 | 0 | N/A | N/A | 3 | 6 | N/A | N/A | N/A | N/A | 13512 |
| 743 | *[System[Provider[@Name='Microsoft-Windows-Windows Defender'] and (EventID=5007)]]* | .{0,1000}\[System\[Provider\[\@Name\=\'Microsoft\-Windows\-Windows\sDefender\'\]\sand\s\(EventID\=5007\)\]\].{0,1000} | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | N/A | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 13516 |
| 744 | *\*_AD-Audit_*.txt* | .{0,1000}\\.{0,1000}_AD\-Audit_.{0,1000}\.txt.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 0 | N/A | N/A | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 13554 |
| 745 | *\\\\*\\*\\Get-FileLockProcess.ps1* | .{0,1000}\\\\\\\\.{0,1000}\\\\.{0,1000}\\\\Get\-FileLockProcess\.ps1.{0,1000} | offensive_tool_keyword | smbmap | SMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks. | T1210.001 - T1083 - T1213 - T1021 | TA0007 - TA0003 - TA0002 - TA0001 | N/A | MuddyWater - Dispossessor | Discovery | https://github.com/ShawnDEvans/smbmap | 1 | 0 | N/A | N/A | 10 | 10 | 1890 | 359 | 2025-02-28T18:09:10Z | 2015-03-16T13:15:00Z | 13613 |
| 746 | *\10m_usernames.txt* | .{0,1000}\\10m_usernames\.txt.{0,1000} | offensive_tool_keyword | ldapnomnom | Anonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP) | T1110.003 - T1205 | TA0007 | N/A | N/A | Discovery | https://github.com/lkarlslund/ldapnomnom | 1 | 0 | N/A | N/A | 6 | 10 | 1030 | 80 | 2024-11-09T10:15:13Z | 2022-09-18T10:35:09Z | 13714 |
| 747 | *\2023*.shareaudit* | .{0,1000}\\2023.{0,1000}\.shareaudit.{0,1000} | offensive_tool_keyword | ShareAudit | A tool for auditing network shares in an Active Directory environment | T1135 - T1005 - T1083 - T1210 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/dionach/ShareAudit | 1 | 0 | N/A | N/A | 8 | 1 | 42 | 15 | 2019-04-29T10:07:57Z | 2019-02-26T16:00:15Z | 13728 |
| 748 | *\2024*.shareaudit* | .{0,1000}\\2024.{0,1000}\.shareaudit.{0,1000} | offensive_tool_keyword | ShareAudit | A tool for auditing network shares in an Active Directory environment | T1135 - T1005 - T1083 - T1210 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/dionach/ShareAudit | 1 | 0 | N/A | N/A | 8 | 1 | 42 | 15 | 2019-04-29T10:07:57Z | 2019-02-26T16:00:15Z | 13729 |
| 749 | *\2025*.shareaudit* | .{0,1000}\\2025.{0,1000}\.shareaudit.{0,1000} | offensive_tool_keyword | ShareAudit | A tool for auditing network shares in an Active Directory environment | T1135 - T1005 - T1083 - T1210 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/dionach/ShareAudit | 1 | 0 | N/A | N/A | 8 | 1 | 42 | 15 | 2019-04-29T10:07:57Z | 2019-02-26T16:00:15Z | 13731 |
| 750 | *\accounts_passdontexpire.txt* | .{0,1000}\\accounts_passdontexpire\.txt.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 13775 |
| 751 | *\AD_Miner-* | .{0,1000}\\AD_Miner\-.{0,1000} | offensive_tool_keyword | AD_Miner | AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses | T1087.002 - T1069 - T1018 - T1595 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/Mazars-Tech/AD_Miner | 1 | 0 | N/A | AD Enumeration | 7 | 10 | 1290 | 131 | 2025-03-12T10:53:09Z | 2023-09-26T12:36:59Z | 13789 |
| 752 | *\ADAudit.ps1* | .{0,1000}\\ADAudit\.ps1.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 13794 |
| 753 | *\adaudit.ps1* | .{0,1000}\\adaudit\.ps1.{0,1000} | greyware_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1482 - T1087 | TA0007 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 8 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 13795 |
| 754 | *\ADcheck.py* | .{0,1000}\\ADcheck\.py.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 0 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 13796 |
| 755 | *\ADcheck\Scripts\activate* | .{0,1000}\\ADcheck\\Scripts\\activate.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 0 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 13797 |
| 756 | *\ADcheck-main* | .{0,1000}\\ADcheck\-main.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 0 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 13798 |
| 757 | *\ADCollector.exe* | .{0,1000}\\ADCollector\.exe.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 0 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 13799 |
| 758 | *\ADCollector3.sln* | .{0,1000}\\ADCollector3\.sln.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 0 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 13802 |
| 759 | *\ADCollector3\* | .{0,1000}\\ADCollector3\\.{0,1000} | offensive_tool_keyword | ADCollector | ADCollector is a lightweight tool that enumerates the Active Directory environment | T1087 - T1018 - T1069 - T1482 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/dev-2null/ADCollector | 1 | 0 | N/A | N/A | 7 | 7 | 629 | 81 | 2022-07-30T05:27:15Z | 2019-05-15T06:42:20Z | 13803 |
| 760 | *\ADeleg.exe* | .{0,1000}\\ADeleg\.exe.{0,1000} | offensive_tool_keyword | adeleg | an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest | T1595 - T1087.002 - T1069.002 | TA0007 - TA0004 | N/A | N/A | Discovery | https://github.com/mtth-bfft/adeleg | 1 | 0 | N/A | N/A | 8 | 3 | 294 | 31 | 2023-06-07T15:08:53Z | 2022-02-09T19:47:04Z | 13825 |
| 761 | *\ADeleg.exe* | .{0,1000}\\ADeleg\.exe.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 13826 |
| 762 | *\adeleg.pdb* | .{0,1000}\\adeleg\.pdb.{0,1000} | offensive_tool_keyword | adeleg | an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest | T1595 - T1087.002 - T1069.002 | TA0007 - TA0004 | N/A | N/A | Discovery | https://github.com/mtth-bfft/adeleg | 1 | 0 | N/A | N/A | 8 | 3 | 294 | 31 | 2023-06-07T15:08:53Z | 2022-02-09T19:47:04Z | 13827 |
| 763 | *\adeleg\adeleg\* | .{0,1000}\\adeleg\\adeleg\\.{0,1000} | offensive_tool_keyword | adeleg | an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest | T1595 - T1087.002 - T1069.002 | TA0007 - TA0004 | N/A | N/A | Discovery | https://github.com/mtth-bfft/adeleg | 1 | 0 | N/A | N/A | 8 | 3 | 294 | 31 | 2023-06-07T15:08:53Z | 2022-02-09T19:47:04Z | 13828 |
| 764 | *\adeleg\winldap\* | .{0,1000}\\adeleg\\winldap\\.{0,1000} | offensive_tool_keyword | adeleg | an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest | T1595 - T1087.002 - T1069.002 | TA0007 - TA0004 | N/A | N/A | Discovery | https://github.com/mtth-bfft/adeleg | 1 | 0 | N/A | N/A | 8 | 3 | 294 | 31 | 2023-06-07T15:08:53Z | 2022-02-09T19:47:04Z | 13829 |
| 765 | *\Adeleginator-main* | .{0,1000}\\Adeleginator\-main.{0,1000} | offensive_tool_keyword | Adeleginator | tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory | T1087 - T1136 - T1069 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/techspence/Adeleginator | 1 | 0 | N/A | N/A | 6 | 2 | 179 | 18 | 2024-09-18T20:21:42Z | 2024-03-04T03:44:52Z | 13830 |
| 766 | *\adeleg-main* | .{0,1000}\\adeleg\-main.{0,1000} | offensive_tool_keyword | adeleg | an Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest | T1595 - T1087.002 - T1069.002 | TA0007 - TA0004 | N/A | N/A | Discovery | https://github.com/mtth-bfft/adeleg | 1 | 0 | N/A | N/A | 8 | 3 | 294 | 31 | 2023-06-07T15:08:53Z | 2022-02-09T19:47:04Z | 13831 |
| 767 | *\adf.bat* | .{0,1000}\\adf\.bat.{0,1000} | greyware_tool_keyword | adfind | Adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks. | T1087 - T1016 - T1482 | TA0007 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L4 | 1 | 0 | N/A | N/A | 10 | 1 | 0 | 0 | 2022-02-15T23:58:54Z | 2022-02-24T18:51:11Z | 13832 |
| 768 | *\adfind.cf* | .{0,1000}\\adfind\.cf.{0,1000} | greyware_tool_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 13833 |
| 769 | *\AdFind.zip* | .{0,1000}\\AdFind\.zip.{0,1000} | greyware_tool_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 13834 |
| 770 | *\ADGet.exe* | .{0,1000}\\ADGet\.exe.{0,1000} | greyware_tool_keyword | adget | gather valuable informations about the AD environment | T1018 - T1027 - T1046 - T1057 - T1069 - T1087 - T1098 - T1482 | TA0001 - TA0002 - TA0003 - TA0007 - TA0011 | N/A | N/A | Discovery | https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 13848 |
| 771 | *\adhunt.py* | \\adhunt\.py | offensive_tool_keyword | adhunt | Tool for exploiting Active Directory Enviroments - enumeration | T1018 - T1087 - T1087.002 - T1069 - T1069.002 | TA0007 - TA0003 - TA0001 | N/A | N/A | Discovery | https://github.com/karendm/ADHunt | 1 | 0 | N/A | AD Enumeration | 7 | 1 | 46 | 10 | 2023-08-10T18:55:39Z | 2023-06-20T13:24:10Z | 13849 |
| 772 | *\adPEAS.ps1* | .{0,1000}\\adPEAS\.ps1.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 13858 |
| 773 | *\adPEAS_DomainPolicy.Sys* | .{0,1000}\\adPEAS_DomainPolicy\.Sys.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 13859 |
| 774 | *\adPEAS_outputfile* | .{0,1000}\\adPEAS_outputfile.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 13860 |
| 775 | *\adPEAS-Light.ps1* | .{0,1000}\\adPEAS\-Light\.ps1.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 13861 |
| 776 | *\adPEAS-main* | .{0,1000}\\adPEAS\-main.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 13862 |
| 777 | *\adPEAS-master* | .{0,1000}\\adPEAS\-master.{0,1000} | offensive_tool_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | N/A | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 13863 |
| 778 | *\ADRecon.ps1* | .{0,1000}\\ADRecon\.ps1.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 13865 |
| 779 | *\ADRecon-master* | .{0,1000}\\ADRecon\-master.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 13866 |
| 780 | *\ADRecon-Report.xlsx* | .{0,1000}\\ADRecon\-Report\.xlsx.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 13867 |
| 781 | *\Advanced IP Scanner.lnk* | .{0,1000}\\Advanced\sIP\sScanner\.lnk.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 13873 |
| 782 | *\Advanced Port Scanner Portable\* | .{0,1000}\\Advanced\sPort\sScanner\sPortable\\.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 13879 |
| 783 | *\advanced_ip_scanner* | .{0,1000}advanced_ip_scanner.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 13880 |
| 784 | *\Advanced_Port_Scanner_*.exe* | .{0,1000}\\Advanced_Port_Scanner_.{0,1000}\.exe.{0,1000} | signature_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 13881 |
| 785 | *\Angry IP Scanner.app* | .{0,1000}\\Angry\sIP\sScanner\.app.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 13937 |
| 786 | *\AppData\Local\Temp\lansweeper-* | .{0,1000}\\AppData\\Local\\Temp\\lansweeper\-.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 0 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 14031 |
| 787 | *\AppData\Local\Temp\Procmon.exe* | .{0,1000}\\AppData\\Local\\Temp\\Procmon\.exe.{0,1000} | greyware_tool_keyword | procmon | Procmon used in user temp folder | T1059.001 - T1036 - T1569.002 | TA0002 - TA0006 | N/A | N/A | Discovery | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 4 | 7 | N/A | N/A | N/A | N/A | 14039 |
| 788 | *\AppData\Local\Temp\Procmon64.exe* | .{0,1000}\\AppData\\Local\\Temp\\Procmon64\.exe.{0,1000} | greyware_tool_keyword | procmon | Procmon used in user temp folder | T1059.001 - T1036 - T1569.002 | TA0002 - TA0006 | N/A | N/A | Discovery | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 4 | 7 | N/A | N/A | N/A | N/A | 14040 |
| 789 | *\AppData\Roaming\SoftPerfect Network Scanner* | .{0,1000}\\AppData\\Roaming\\SoftPerfect\sNetwork\sScanner.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 14090 |
| 790 | *\AzureHound.ps1* | .{0,1000}\\AzureHound\.ps1.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 14182 |
| 791 | *\backdoored-script.ps1* | .{0,1000}\\backdoored\-script\.ps1.{0,1000} | offensive_tool_keyword | Graphpython | Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/Graphpython | 1 | 0 | N/A | N/A | 7 | 2 | 145 | 13 | 2024-12-07T21:54:00Z | 2024-07-10T00:04:48Z | 14198 |
| 792 | *\BitLockerRecoveryKeys.csv* | .{0,1000}\\BitLockerRecoveryKeys\.csv.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 14319 |
| 793 | *\BloodHound.exe* | .{0,1000}\\BloodHound\.exe.{0,1000} | offensive_tool_keyword | BloodHound | BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 14358 |
| 794 | *\BloodHoundGui\*.exe* | .{0,1000}\\BloodHoundGui\\.{0,1000}\.exe.{0,1000} | offensive_tool_keyword | BloodHound | BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 14359 |
| 795 | *\BloodHound-win32-X64* | .{0,1000}\\BloodHound\-win32\-X64.{0,1000} | offensive_tool_keyword | BloodHound | BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 14361 |
| 796 | *\bofhound.py* | .{0,1000}\\bofhound\.py.{0,1000} | offensive_tool_keyword | ShadowHound | set of PowerShell scripts for Active Directory enumeration | T1087 - T1018 - T1482 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Friends-Security/ShadowHound | 1 | 0 | N/A | N/A | 8 | 4 | 345 | 36 | 2024-12-01T08:06:02Z | 2024-11-21T15:01:14Z | 14363 |
| 797 | *\CheckSMBSigning.ps1* | .{0,1000}\\CheckSMBSigning\.ps1.{0,1000} | offensive_tool_keyword | CheckSMBSigning | Checks for SMB signing disabled on all hosts in the network | T1018 - T1550 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Leo4j/CheckSMBSigning | 1 | 0 | N/A | N/A | 6 | 1 | 8 | 1 | 2023-10-13T11:55:33Z | 2023-05-17T11:47:52Z | 14496 |
| 798 | *\cmdkey.exe" /list* | .{0,1000}\\cmdkey\.exe\"\s\/list.{0,1000} | greyware_tool_keyword | Cmdkey | List Saved Credentials | T1555 | TA0006 | N/A | N/A | Discovery | https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-290a | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 14564 |
| 799 | *\CMLoot.ps1* | .{0,1000}\\CMLoot\.ps1.{0,1000} | offensive_tool_keyword | CMLoot | Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB shares | T1083 - T1039 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/1njected/CMLoot | 1 | 0 | N/A | N/A | 8 | 2 | 175 | 22 | 2023-02-05T00:24:31Z | 2022-06-02T10:59:21Z | 14568 |
| 800 | *\COMHijackToolkit.ps1* | .{0,1000}\\COMHijackToolkit\.ps1.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 14579 |
| 801 | *\COMHijackToolkit\* | .{0,1000}\\COMHijackToolkit\\.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 14580 |
| 802 | *\COMInject.exe* | .{0,1000}\\COMInject\.exe.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 14584 |
| 803 | *\COMInject.sln* | .{0,1000}\\COMInject\.sln.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 14585 |
| 804 | *\COMInjectTarget.cpp* | .{0,1000}\\COMInjectTarget\.cpp.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 14586 |
| 805 | *\COMInjectTarget.dll* | .{0,1000}\\COMInjectTarget\.dll.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 14587 |
| 806 | *\COMInjectTarget\* | .{0,1000}\\COMInjectTarget\\.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 14588 |
| 807 | *\CultesDesGoules.txt* | .{0,1000}\\CultesDesGoules\.txt.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 14702 |
| 808 | *\dangerousACL_Computer.txt* | .{0,1000}\\dangerousACL_Computer\.txt.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 14786 |
| 809 | *\dangerousACL_Groups.txt* | .{0,1000}\\dangerousACL_Groups\.txt.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 14787 |
| 810 | *\dcs_weak_kerberos_ciphersuite.txt* | .{0,1000}\\dcs_weak_kerberos_ciphersuite\.txt.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 14827 |
| 811 | *\DefaultPasswordPolicy.csv* | .{0,1000}\\DefaultPasswordPolicy\.csv.{0,1000} | greyware_tool_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 14858 |
| 812 | *\DLLHound.ps1* | .{0,1000}\\DLLHound\.ps1.{0,1000} | offensive_tool_keyword | DLLHound | Find potential DLL Sideloads on your windows computer | T1574.001 - T1574.002 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/ajm4n/DLLHound | 1 | 0 | N/A | N/A | 7 | 3 | 201 | 22 | 2025-01-12T02:28:22Z | 2024-12-20T02:26:16Z | 14979 |
| 813 | *\DLLScan_$timestamp.csv* | .{0,1000}\\DLLScan_\$timestamp\.csv.{0,1000} | offensive_tool_keyword | DLLHound | Find potential DLL Sideloads on your windows computer | T1574.001 - T1574.002 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/ajm4n/DLLHound | 1 | 0 | N/A | N/A | 7 | 3 | 201 | 22 | 2025-01-12T02:28:22Z | 2024-12-20T02:26:16Z | 14986 |
| 814 | *\dnsdump.py* | .{0,1000}\\dnsdump\.py.{0,1000} | offensive_tool_keyword | adidnsdump | By default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks. | T1018 - T1087 - T1201 - T1056 - T1039 | TA0005 - TA0009 | N/A | N/A | Discovery | https://github.com/dirkjanm/adidnsdump | 1 | 0 | N/A | N/A | N/A | 10 | 997 | 118 | 2025-04-04T09:28:20Z | 2019-04-24T17:18:46Z | 15002 |
| 815 | *\domain_admins.txt* | .{0,1000}\\domain_admins\.txt.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 15023 |
| 816 | *\DSInternals.psd1* | .{0,1000}\\DSInternals\.psd1.{0,1000} | offensive_tool_keyword | DSInternals | Directory Services Internals (DSInternals) PowerShell Module and Framework - abused by attackers | T1003 - T1087 - T1018 - T1110 - T1558 | TA0003 - TA0006 - TA0007 | N/A | COZY BEAR | Discovery | https://github.com/MichaelGrafnetter/DSInternals | 1 | 0 | N/A | AD Enumeration | 10 | 10 | 1760 | 265 | 2025-04-16T18:12:55Z | 2015-12-25T13:23:05Z | 15079 |
| 817 | *\ecrprivenum.py* | .{0,1000}\\ecrprivenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 15218 |
| 818 | *\ecrpubenum.py* | .{0,1000}\\ecrpubenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 15219 |
| 819 | *\enterprise_admins.txt* | .{0,1000}\\enterprise_admins\.txt.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 15290 |
| 820 | *\ExploitGuardProtectionHistory.csv* | .{0,1000}\\ExploitGuardProtectionHistory\.csv.{0,1000} | offensive_tool_keyword | Invoke-DumpMDEConfig | PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required ) | T1518 - T1082 - T1005 | TA0009 - TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/BlackSnufkin/Invoke-DumpMDEConfig | 1 | 0 | N/A | N/A | 9 | 2 | 147 | 23 | 2024-06-10T14:00:47Z | 2024-06-09T15:11:16Z | 15396 |
| 821 | *\findspn.ps1* | .{0,1000}\\findspn\.ps1.{0,1000} | greyware_tool_keyword | Dispossessor | powershell script to find a spn - abused by Dispossessor ransomware group | T1087.002 - T1046 - T1557 | TA0007 | N/A | Dispossessor | Discovery | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 15448 |
| 822 | *\Get-SMBSigning.ps1* | .{0,1000}\\Get\-SMBSigning\.ps1.{0,1000} | offensive_tool_keyword | CheckSMBSigning | Checks for SMB signing disabled on all hosts in the network | T1018 - T1550 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Leo4j/CheckSMBSigning | 1 | 0 | N/A | N/A | 6 | 1 | 8 | 1 | 2023-10-13T11:55:33Z | 2023-05-17T11:47:52Z | 15604 |
| 823 | *\GMSAPasswordReader.exe* | .{0,1000}\\GMSAPasswordReader\.exe.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 15648 |
| 824 | *\gofetch.exe* | .{0,1000}\\gofetch\.exe.{0,1000} | offensive_tool_keyword | GoFetch | GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application. | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | Dispossessor | Discovery | https://github.com/GoFetchAD/GoFetch | 1 | 0 | N/A | N/A | 10 | 7 | 633 | 99 | 2017-06-20T14:15:10Z | 2017-04-11T10:45:23Z | 15665 |
| 825 | *\GoFetchLog.log* | .{0,1000}\\GoFetchLog\.log.{0,1000} | offensive_tool_keyword | GoFetch | GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application. | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | Dispossessor | Discovery | https://github.com/GoFetchAD/GoFetch | 1 | 0 | N/A | N/A | 10 | 7 | 633 | 99 | 2017-06-20T14:15:10Z | 2017-04-11T10:45:23Z | 15666 |
| 826 | *\GoFetch-main* | .{0,1000}GoFetch\-master.{0,1000} | offensive_tool_keyword | GoFetch | GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application. | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | Dispossessor | Discovery | https://github.com/GoFetchAD/GoFetch | 1 | 0 | N/A | N/A | 10 | 7 | 633 | 99 | 2017-06-20T14:15:10Z | 2017-04-11T10:45:23Z | 15667 |
| 827 | *\GPOBrowser.py* | .{0,1000}\\GPOBrowser\.py.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 0 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 15711 |
| 828 | *\Graphpython.py* | .{0,1000}\\Graphpython\.py.{0,1000} | offensive_tool_keyword | Graphpython | Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/Graphpython | 1 | 0 | N/A | N/A | 7 | 2 | 145 | 13 | 2024-12-07T21:54:00Z | 2024-07-10T00:04:48Z | 15718 |
| 829 | *\Group3r.cs* | .{0,1000}\\Group3r\.cs.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 15728 |
| 830 | *\group3r.log* | .{0,1000}\\group3r\.log.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 15732 |
| 831 | *\Group3r.sln* | .{0,1000}\\Group3r\.sln.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 15733 |
| 832 | *\HijackDLL-CreateRemoteThread.* | .{0,1000}\\HijackDLL\-CreateRemoteThread\..{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 15797 |
| 833 | *\HijackDLL-CreateRemoteThread\* | .{0,1000}\\HijackDLL\-CreateRemoteThread\\.{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 15798 |
| 834 | *\HijackDll-Process.* | .{0,1000}\\HijackDll\-Process\..{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 15799 |
| 835 | *\HijackDLL-Threads.* | .{0,1000}\\HijackDLL\-Threads\..{0,1000} | offensive_tool_keyword | Accomplice | Tools for discovery and abuse of COM hijacks | T1120 - T1174 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/nccgroup/Accomplice | 1 | 0 | N/A | N/A | 7 | 4 | 303 | 47 | 2019-10-15T21:54:09Z | 2019-09-04T23:32:09Z | 15800 |
| 836 | *\iamassumeroleenum.py* | .{0,1000}\\iamassumeroleenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 15863 |
| 837 | *\Invoke-ADEnum\* | .{0,1000}\\Invoke\-ADEnum\\.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 0 | N/A | N/A | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 15964 |
| 838 | *\Invoke-ADEnum-main* | .{0,1000}\\Invoke\-ADEnum\-main.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 0 | N/A | N/A | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 15965 |
| 839 | *\Invoke-DCOM.ps1* | .{0,1000}\\Invoke\-DCOM\.ps1.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 15969 |
| 840 | *\Invoke-Maldaptive-main* | .{0,1000}\\Invoke\-Maldaptive\-main.{0,1000} | greyware_tool_keyword | Invoke-Maldaptive | MaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection. | T1027 | TA0005 - TA0007 | N/A | N/A | Discovery | https://github.com/MaLDAPtive/Invoke-Maldaptive | 1 | 0 | N/A | N/A | 7 | 3 | 277 | 26 | 2024-08-07T21:12:45Z | 2024-08-07T20:43:52Z | 15976 |
| 841 | *\ipscan-*-setup.exe* | .{0,1000}\\ipscan\-.{0,1000}\-setup\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 16005 |
| 842 | *\ipscan.exe* | .{0,1000}\\ipscan\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 16006 |
| 843 | *\ipscan221.exe* | .{0,1000}\\ipscan221\.exe.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 16007 |
| 844 | *\ipscan-crash.txt* | .{0,1000}\\ipscan\-crash\.txt.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | N/A | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 16008 |
| 845 | *\jecretz.py* | .{0,1000}\\jecretz\.py.{0,1000} | offensive_tool_keyword | jecretz | Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets | T1552 - T1114 - T1119 - T1070 | TA0006 - TA0009 - TA0005 | N/A | Scattered Spider* | Discovery | https://github.com/sahadnk72/jecretz | 1 | 0 | N/A | N/A | 7 | 1 | 43 | 9 | 2022-12-08T10:00:11Z | 2020-05-25T14:40:28Z | 16031 |
| 846 | *\Killchain.ps1* | .{0,1000}\\Killchain\.ps1.{0,1000} | offensive_tool_keyword | Graphpython | Modular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/Graphpython | 1 | 0 | N/A | N/A | 7 | 2 | 145 | 13 | 2024-12-07T21:54:00Z | 2024-07-10T00:04:48Z | 16138 |
| 847 | *\krbtgtAccounts.json* | .{0,1000}\\krbtgtAccounts\.json.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 0 | N/A | N/A | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 16182 |
| 848 | *\lambdaenum.py* | .{0,1000}\\lambdaenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 16197 |
| 849 | *\lansearch.exe* | .{0,1000}\\lansearch\.exe.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 16199 |
| 850 | *\LansweeperService.exe* | .{0,1000}\\LansweeperService\.exe.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 0 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 16200 |
| 851 | *\LansweeperSetup_*.exe* | .{0,1000}\\LansweeperSetup_.{0,1000}\.exe.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 0 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 16201 |
| 852 | *\ldap_search_bof.py* | .{0,1000}\\ldap_search_bof\.py.{0,1000} | offensive_tool_keyword | bofhound | Generate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP Sentinel | T1046 - T1087 - T1003 | TA0007 - TA0009 - TA0001 | N/A | N/A | Discovery | https://github.com/fortalice/bofhound | 1 | 0 | N/A | N/A | 5 | 4 | 328 | 56 | 2024-02-23T15:36:24Z | 2022-05-10T17:41:53Z | 16218 |
| 853 | *\ldap_shell.cmd* | .{0,1000}\\ldap_shell\.cmd.{0,1000} | offensive_tool_keyword | powerview | PowerView.py is an alternative for the awesome original PowerView.ps1 | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/aniqfakhrul/powerview.py | 1 | 0 | N/A | N/A | 10 | 7 | 622 | 66 | 2025-04-22T09:01:39Z | 2022-06-19T16:13:04Z | 16219 |
| 854 | *\ldapper.py* | .{0,1000}\\ldapper\.py.{0,1000} | offensive_tool_keyword | LDAPPER | LDAP Querying without the Suck | T1087 - T1069 - T1018 | TA0007 | N/A | N/A | Discovery | https://github.com/shellster/LDAPPER | 1 | 0 | N/A | N/A | 7 | 1 | 99 | 11 | 2024-11-09T03:53:26Z | 2020-06-17T16:53:35Z | 16223 |
| 855 | *\LDAPPER-master* | .{0,1000}\\LDAPPER\-master.{0,1000} | offensive_tool_keyword | LDAPPER | LDAP Querying without the Suck | T1087 - T1069 - T1018 | TA0007 | N/A | N/A | Discovery | https://github.com/shellster/LDAPPER | 1 | 0 | N/A | N/A | 7 | 1 | 99 | 11 | 2024-11-09T03:53:26Z | 2020-06-17T16:53:35Z | 16224 |
| 856 | *\ldapph.db* | .{0,1000}\\ldapph\.db.{0,1000} | offensive_tool_keyword | LDAP-Password-Hunter | Password Hunter in Active Directory | T1087.002 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/LDAP-Password-Hunter | 1 | 0 | N/A | N/A | 7 | 2 | 198 | 25 | 2023-01-06T15:32:34Z | 2021-07-26T14:27:01Z | 16225 |
| 857 | *\LibSnaffle* | .{0,1000}\\LibSnaffle.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 16239 |
| 858 | *\loadbalancer.py* | .{0,1000}\\loadbalancer\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 16313 |
| 859 | *\Local\Temp\Advanced IP Scanner 2\* | .{0,1000}\\Local\\Temp\\Advanced\sIP\sScanner\s2\\.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 16320 |
| 860 | *\LocalShellExtParse.py* | .{0,1000}\\LocalShellExtParse\.py.{0,1000} | offensive_tool_keyword | LocalShellExtParse | Script to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User. | T1547.009 - T1129 | TA0003 - TA0007 | N/A | N/A | Discovery | https://github.com/herrcore/LocalShellExtParse | 1 | 0 | N/A | N/A | 9 | 1 | 20 | 4 | 2015-06-08T16:55:38Z | 2015-06-05T03:23:13Z | 16335 |
| 861 | *\LocalShellExtParse-master* | .{0,1000}\\LocalShellExtParse\-master.{0,1000} | offensive_tool_keyword | LocalShellExtParse | Script to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User. | T1547.009 - T1129 | TA0003 - TA0007 | N/A | N/A | Discovery | https://github.com/herrcore/LocalShellExtParse | 1 | 0 | N/A | N/A | 9 | 1 | 20 | 4 | 2015-06-08T16:55:38Z | 2015-06-05T03:23:13Z | 16336 |
| 862 | *\manspider_*.log* | .{0,1000}\\manspider_.{0,1000}\.log.{0,1000} | offensive_tool_keyword | MANSPIDER | Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported! | T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083 | TA0007 - TA0009 - TA0010 | N/A | N/A | Discovery | https://github.com/blacklanternsecurity/MANSPIDER | 1 | 0 | N/A | N/A | 8 | 10 | 1117 | 138 | 2024-07-18T06:14:04Z | 2020-03-18T13:27:20Z | 16446 |
| 863 | *\MDE_Enum.csproj* | .{0,1000}\\MDE_Enum\.csproj.{0,1000} | offensive_tool_keyword | MDE_Enum | extract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rules | T1070.006 | TA0005 - TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/0xsp-SRD/MDE_Enum | 1 | 0 | N/A | N/A | 8 | 2 | 198 | 18 | 2024-06-10T18:40:27Z | 2024-06-06T15:54:44Z | 16451 |
| 864 | *\MDE_Enum.exe* | .{0,1000}\\MDE_Enum\.exe.{0,1000} | offensive_tool_keyword | MDE_Enum | extract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rules | T1070.006 | TA0005 - TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/0xsp-SRD/MDE_Enum | 1 | 0 | N/A | N/A | 8 | 2 | 198 | 18 | 2024-06-10T18:40:27Z | 2024-06-06T15:54:44Z | 16452 |
| 865 | *\MDE_Enum\Program.cs* | .{0,1000}\\MDE_Enum\\Program\.cs.{0,1000} | offensive_tool_keyword | MDE_Enum | extract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rules | T1070.006 | TA0005 - TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/0xsp-SRD/MDE_Enum | 1 | 0 | N/A | N/A | 8 | 2 | 198 | 18 | 2024-06-10T18:40:27Z | 2024-06-06T15:54:44Z | 16453 |
| 866 | *\Moriarty.exe* | .{0,1000}\\Moriarty\.exe.{0,1000} | offensive_tool_keyword | Moriarty | Moriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments. | T1068 - T1083 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/BC-SECURITY/Moriarty | 1 | 0 | N/A | N/A | 7 | 6 | 510 | 67 | 2024-08-07T15:06:31Z | 2023-12-11T14:15:33Z | 16655 |
| 867 | *\msi_search.c* | .{0,1000}\\msi_search\.c.{0,1000} | offensive_tool_keyword | msi-search | This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs | T1005 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/mandiant/msi-search | 1 | 0 | N/A | N/A | 10 | 3 | 276 | 31 | 2023-07-20T18:12:49Z | 2023-06-29T18:31:56Z | 16685 |
| 868 | *\msi_search.exe* | .{0,1000}\\msi_search\.exe.{0,1000} | offensive_tool_keyword | msi-search | This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs | T1005 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/mandiant/msi-search | 1 | 0 | N/A | N/A | 10 | 3 | 276 | 31 | 2023-07-20T18:12:49Z | 2023-06-29T18:31:56Z | 16686 |
| 869 | *\msi_search.ps1* | .{0,1000}\\msi_search\.ps1.{0,1000} | offensive_tool_keyword | msi-search | This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs | T1005 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/mandiant/msi-search | 1 | 0 | N/A | N/A | 10 | 3 | 276 | 31 | 2023-07-20T18:12:49Z | 2023-06-29T18:31:56Z | 16687 |
| 870 | *\msi_search.x64.o* | .{0,1000}\\msi_search\.x64\.o.{0,1000} | offensive_tool_keyword | msi-search | This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs | T1005 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/mandiant/msi-search | 1 | 0 | N/A | N/A | 10 | 3 | 276 | 31 | 2023-07-20T18:12:49Z | 2023-06-29T18:31:56Z | 16688 |
| 871 | *\msi_search.x86.o* | .{0,1000}\\msi_search\.x86\.o.{0,1000} | offensive_tool_keyword | msi-search | This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairs | T1005 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/mandiant/msi-search | 1 | 0 | N/A | N/A | 10 | 3 | 276 | 31 | 2023-07-20T18:12:49Z | 2023-06-29T18:31:56Z | 16689 |
| 872 | *\net.exe" accounts* | .{0,1000}\\net\.exe\"\saccounts.{0,1000} | greyware_tool_keyword | net | Enumerate local accounts | T1087.001 - T1003 | TA0007 - TA0009 | N/A | Naikon - Magic Hound - APT38 - Dragonfly - Deep Panda - Threat Group-3390 - OilRig - Threat Group-1314 - APT28 - APT41 - menuPass - Ke3chang - Leviathan - APT5 - Orangeworm - GALLIUM - admin@338 - Chimera - APT1 - FIN8 - TA505 - ToddyCat - Turla - APT33 - Wizard Spider - Sandworm Team - APT29 - APT32 - Volt Typhoon - BRONZE BUTLER | discovery | https://thedfirreport.com/2023/02/06/collect-exfiltrate-sleep-repeat/ | 1 | 0 | N/A | greyware tool - risks of False positive ! | N/A | N/A | N/A | N/A | N/A | N/A | 16759 |
| 873 | *\net.exe* localgroup admin* | .{0,1000}\\net\.exe.{0,1000}\slocalgroup\sadmin.{0,1000} | greyware_tool_keyword | net | showing users in a privileged group. | T1069 - T1003 | TA0007 - TA0040 | N/A | Naikon - Magic Hound - APT38 - Dragonfly - Deep Panda - Threat Group-3390 - OilRig - Threat Group-1314 - APT28 - APT41 - menuPass - Ke3chang - Leviathan - APT5 - Orangeworm - GALLIUM - admin@338 - Chimera - APT1 - FIN8 - TA505 - ToddyCat - Turla - APT33 - Wizard Spider - Sandworm Team - APT29 - APT32 - Volt Typhoon - BRONZE BUTLER | Discovery | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 16760 |
| 874 | *\net.exe* sessions* | .{0,1000}\\net\.exe.{0,1000}\ssessions.{0,1000} | greyware_tool_keyword | net | List active SMB session | T1135 - T1047 | TA0007 - TA0009 | N/A | Naikon - Magic Hound - APT38 - Dragonfly - Deep Panda - Threat Group-3390 - OilRig - Threat Group-1314 - APT28 - APT41 - menuPass - Ke3chang - Leviathan - APT5 - Orangeworm - GALLIUM - admin@338 - Chimera - APT1 - FIN8 - TA505 - ToddyCat - Turla - APT33 - Wizard Spider - Sandworm Team - APT29 - APT32 - Volt Typhoon - BRONZE BUTLER | Discovery | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 16761 |
| 875 | *\net.exe* view */domain* | .{0,1000}\\net\.exe.{0,1000}\sview\s.{0,1000}\/domain.{0,1000} | greyware_tool_keyword | net | display all domain names on the network | T1016 - T1046 | TA0007 - TA0009 | N/A | Naikon - Magic Hound - APT38 - Dragonfly - Deep Panda - Threat Group-3390 - OilRig - Threat Group-1314 - APT28 - APT41 - menuPass - Ke3chang - Leviathan - APT5 - Orangeworm - GALLIUM - admin@338 - Chimera - APT1 - FIN8 - TA505 - ToddyCat - Turla - APT33 - Wizard Spider - Sandworm Team - APT29 - APT32 - Volt Typhoon - BRONZE BUTLER | Discovery | N/A | 1 | 0 | N/A | N/A | N/A | 10 | N/A | N/A | N/A | N/A | 16762 |
| 876 | *\net1 sessions* | .{0,1000}\\net1\ssessions.{0,1000} | greyware_tool_keyword | net | List active SMB session | T1135 - T1047 | TA0007 - TA0009 | N/A | Naikon - Magic Hound - APT38 - Dragonfly - Deep Panda - Threat Group-3390 - OilRig - Threat Group-1314 - APT28 - APT41 - menuPass - Ke3chang - Leviathan - APT5 - Orangeworm - GALLIUM - admin@338 - Chimera - APT1 - FIN8 - TA505 - ToddyCat - Turla - APT33 - Wizard Spider - Sandworm Team - APT29 - APT32 - Volt Typhoon - BRONZE BUTLER | Discovery | N/A | 1 | 0 | N/A | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 16785 |
| 877 | *\netscan.dbm-journal* | .{0,1000}\\netscan\.dbm\-journal.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 16809 |
| 878 | *\netscan.exe* | .{0,1000}\\netscan\.exe.{0,1000} | greyware_tool_keyword | netscan | SoftPerfect Network Scanner abused by threat actor | T1040 - T1046 - T1018 | TA0007 - TA0010 - TA0001 | N/A | BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - Lynx | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | network exploitation tool | 6 | 10 | N/A | N/A | N/A | N/A | 16810 |
| 879 | *\netscan.exe* | .{0,1000}\\netscan\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 16811 |
| 880 | *\netscan.lic* | .{0,1000}\\netscan\.lic.{0,1000} | greyware_tool_keyword | netscan | SoftPerfect Network Scanner abused by threat actor | T1040 - T1046 - T1018 | TA0007 - TA0010 - TA0001 | N/A | BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - Lynx | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | network exploitation tool | 6 | 10 | N/A | N/A | N/A | N/A | 16812 |
| 881 | *\netscan.xml* | .{0,1000}\\netscan\.xml.{0,1000} | greyware_tool_keyword | netscan | SoftPerfect Network Scanner abused by threat actor | T1040 - T1046 - T1018 | TA0007 - TA0010 - TA0001 | N/A | BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - Lynx | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | network exploitation tool | 6 | 10 | N/A | N/A | N/A | N/A | 16813 |
| 882 | *\netscan_linux.tar.gz* | .{0,1000}\\netscan_linux\.tar\.gz.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 16814 |
| 883 | *\netscan_portable.zip* | .{0,1000}\\netscan_portable\.zip.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 16815 |
| 884 | *\netscan_portable\* | .{0,1000}\\netscan_portable\\.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 16816 |
| 885 | *\netscan_setup.exe* | .{0,1000}\\netscan_setup\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 16817 |
| 886 | *\netscan_setup.tmp* | .{0,1000}\\netscan_setup\.tmp.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 16818 |
| 887 | *\netscan64.exe* | .{0,1000}\\netscan64\.exe.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 16819 |
| 888 | *\NetSess.exe* | .{0,1000}\\NetSess\.exe.{0,1000} | offensive_tool_keyword | NetSess | Command line tool to enumerate NetBIOS sessions on a specified local or remote machine. | T1016 - T1046 - T1087 | TA0007 - TA0043 | N/A | MUSTANG PANDA | Discovery | https://www.joeware.net/freetools/tools/netsess/ | 1 | 0 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 16820 |
| 889 | *\NetSess.zip* | .{0,1000}\\NetSess\.zip.{0,1000} | offensive_tool_keyword | NetSess | Command line tool to enumerate NetBIOS sessions on a specified local or remote machine. | T1016 - T1046 - T1087 | TA0007 - TA0043 | N/A | MUSTANG PANDA | Discovery | https://www.joeware.net/freetools/tools/netsess/ | 1 | 0 | N/A | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 16821 |
| 890 | *\NimScan.exe* | .{0,1000}\\NimScan\.exe.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 0 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 16871 |
| 891 | *\NimScan.nim* | .{0,1000}\\NimScan\.nim.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 0 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 16872 |
| 892 | *\nMethodNamespace=StandIn* | .{0,1000}\\nMethodNamespace\=StandIn.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 16925 |
| 893 | *\ntlmutil.py* | .{0,1000}\\ntlmutil\.py.{0,1000} | offensive_tool_keyword | NTMLRecon | Enumerate information from NTLM authentication enabled web endpoints | T1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001 | TA0009 - TA0007 - TA0006 | N/A | N/A | Discovery | https://github.com/puzzlepeaches/NTLMRecon | 1 | 0 | N/A | N/A | 8 | 1 | 35 | 3 | 2023-08-16T14:34:10Z | 2023-08-09T12:10:42Z | 17002 |
| 894 | *\Obfuscated_Command.txt* | .{0,1000}\\Obfuscated_Command\.txt.{0,1000} | greyware_tool_keyword | Invoke-Maldaptive | MaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection. | T1027 | TA0005 - TA0007 | N/A | N/A | Discovery | https://github.com/MaLDAPtive/Invoke-Maldaptive | 1 | 0 | N/A | N/A | 7 | 3 | 277 | 26 | 2024-08-07T21:12:45Z | 2024-08-07T20:43:52Z | 17021 |
| 895 | *\Outflank-Recon-AD\* | .{0,1000}\\Outflank\-Recon\-AD\\.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17065 |
| 896 | *\OxidResolver.exe* | .{0,1000}\\OxidResolver\.exe.{0,1000} | offensive_tool_keyword | SharpOxidResolver | search the current domain for computers and get bindings for all of them | T1018 - T1046 - T1016 | TA0007 | N/A | KNOTWEED | Discovery | https://github.com/S3cur3Th1sSh1t/SharpOxidResolver | 1 | 0 | N/A | N/A | 9 | 1 | 50 | 9 | 2020-11-25T08:42:06Z | 2020-11-25T08:23:23Z | 17075 |
| 897 | *\passwords.doc* | .{0,1000}\\passwords\.doc.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 17130 |
| 898 | *\passwords.docx* | .{0,1000}\\passwords\.docx.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 17132 |
| 899 | *\passwords.txt* | .{0,1000}\\passwords\.txt.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 17133 |
| 900 | *\passwords.xls* | .{0,1000}\\passwords\.xls.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 17134 |
| 901 | *\passwords.xlsx* | .{0,1000}\\passwords\.xlsx.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | N/A | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 17135 |
| 902 | *\PipeViewer.exe* | .{0,1000}\\PipeViewer\.exe.{0,1000} | offensive_tool_keyword | PipeViewer | A tool that shows detailed information about named pipes in Windows | T1022.002 - T1056.002 | TA0005 - TA0009 | N/A | N/A | discovery | https://github.com/cyberark/PipeViewer | 1 | 0 | N/A | N/A | 5 | 7 | 620 | 55 | 2024-11-15T09:55:35Z | 2022-12-22T12:35:34Z | 17282 |
| 903 | *\PipeViewer.sln* | .{0,1000}\\PipeViewer\.sln.{0,1000} | offensive_tool_keyword | PipeViewer | A tool that shows detailed information about named pipes in Windows | T1022.002 - T1056.002 | TA0005 - TA0009 | N/A | N/A | discovery | https://github.com/cyberark/PipeViewer | 1 | 0 | N/A | N/A | 5 | 7 | 620 | 55 | 2024-11-15T09:55:35Z | 2022-12-22T12:35:34Z | 17283 |
| 904 | *\PipeViewer\Program.cs* | .{0,1000}\\PipeViewer\\Program\.cs.{0,1000} | offensive_tool_keyword | PipeViewer | A tool that shows detailed information about named pipes in Windows | T1022.002 - T1056.002 | TA0005 - TA0009 | N/A | N/A | discovery | https://github.com/cyberark/PipeViewer | 1 | 0 | N/A | N/A | 5 | 7 | 620 | 55 | 2024-11-15T09:55:35Z | 2022-12-22T12:35:34Z | 17284 |
| 905 | *\polenum.py* | .{0,1000}\\polenum\.py.{0,1000} | offensive_tool_keyword | polenum | Uses Impacket Library to get the password policy from a windows machine | T1012 - T1596 | TA0009 - TA0007 | N/A | N/A | Discovery | https://salsa.debian.org/pkg-security-team/polenum | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 17315 |
| 906 | *\PortQry.exe* | .{0,1000}\\PortQry\.exe.{0,1000} | greyware_tool_keyword | PortQry | Microsoft port scanning tool abused by threat actors | T1046 - T1016 - T1049 | TA0007 | N/A | APT15 | Discovery | https://www.microsoft.com/en-us/download/details.aspx?id=17148 | 1 | 0 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 17328 |
| 907 | *\PortQryV2.exe* | .{0,1000}\\PortQryV2\.exe.{0,1000} | greyware_tool_keyword | PortQry | Microsoft port scanning tool abused by threat actors | T1046 - T1016 - T1049 | TA0007 | N/A | APT15 | Discovery | https://www.microsoft.com/en-us/download/details.aspx?id=17148 | 1 | 0 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 17329 |
| 908 | *\PortQryV2\* | .{0,1000}\\PortQryV2\\.{0,1000} | greyware_tool_keyword | PortQry | Microsoft port scanning tool abused by threat actors | T1046 - T1016 - T1049 | TA0007 | N/A | APT15 | Discovery | https://www.microsoft.com/en-us/download/details.aspx?id=17148 | 1 | 0 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 17330 |
| 909 | *\port-scan-tcp.ps1* | .{0,1000}\\port\-scan\-tcp\.ps1.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 0 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 17337 |
| 910 | *\port-scan-udp.ps1* | .{0,1000}\\port\-scan\-udp\.ps1.{0,1000} | offensive_tool_keyword | Minimalistic-offensive | A repository of tools for pentesting of restricted and isolated environments. | T1110 - T1046 - T1021 - T1203 - T1485 | TA0006 - TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/InfosecMatter/Minimalistic-offensive-security-tools | 1 | 0 | N/A | N/A | 7 | 6 | 562 | 121 | 2021-10-26T11:04:46Z | 2020-05-10T17:40:31Z | 17338 |
| 911 | *\PowerView.Log* | .{0,1000}\\PowerView\.Log.{0,1000} | offensive_tool_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | N/A | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 17408 |
| 912 | *\powerview.py* | .{0,1000}\\powerview\.py.{0,1000} | offensive_tool_keyword | powerview | PowerView.py is an alternative for the awesome original PowerView.ps1 | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/aniqfakhrul/powerview.py | 1 | 0 | N/A | N/A | 10 | 7 | 622 | 66 | 2025-04-22T09:01:39Z | 2022-06-19T16:13:04Z | 17412 |
| 913 | *\Program Files (x86)\Advanced IP Scanner\* | .{0,1000}\\Program\sFiles\s\(x86\)\\Advanced\sIP\sScanner\\.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 17492 |
| 914 | *\Program Files (x86)\Lansweeper* | .{0,1000}\\Program\sFiles\s\(x86\)\\Lansweeper.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 0 | N/A | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 17502 |
| 915 | *\Program Files\WizTree* | .{0,1000}\\Program\sFiles\\WizTree.{0,1000} | greyware_tool_keyword | wiztree | legitimate tool abused by threat actors to obtain network files and directory listings | T1083 | TA0007 | N/A | Fox Kitten - Faust - Bitlocker - Akira - Cactus - BlackSuit - Royal | Discovery | N/A | 1 | 0 | N/A | N/A | 3 | 6 | N/A | N/A | N/A | N/A | 17539 |
| 916 | *\Programs\Advanced IP Scanner Portable\* | .{0,1000}\\Programs\\Advanced\sIP\sScanner\sPortable\\.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 17562 |
| 917 | *\PsExecLog.log* | .{0,1000}\\PsExecLog\.log.{0,1000} | offensive_tool_keyword | GoFetch | GoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application. | T1078 - T1078.003 - T1021 - T1021.006 - T1076.001 | TA0005 - TA0001 - TA0003 | N/A | Dispossessor | Discovery | https://github.com/GoFetchAD/GoFetch | 1 | 0 | N/A | N/A | 10 | 7 | 633 | 99 | 2017-06-20T14:15:10Z | 2017-04-11T10:45:23Z | 17604 |
| 918 | *\pslist.exe* | .{0,1000}\\pslist\.exe.{0,1000} | greyware_tool_keyword | pslist | Microsoft sysinternal comandline tool to list running process abused by threat actors | T1057 - T1012 - T1106 | TA0007 | N/A | APT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - Elfin | Discovery | https://learn.microsoft.com/pt-br/sysinternals/downloads/pslist | 1 | 0 | N/A | N/A | 3 | 9 | N/A | N/A | N/A | N/A | 17612 |
| 919 | *\pslist64.exe* | .{0,1000}\\pslist64\.exe.{0,1000} | greyware_tool_keyword | pslist | Microsoft sysinternal comandline tool to list running process abused by threat actors | T1057 - T1012 - T1106 | TA0007 | N/A | APT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - Elfin | Discovery | https://learn.microsoft.com/pt-br/sysinternals/downloads/pslist | 1 | 0 | N/A | N/A | 3 | 9 | N/A | N/A | N/A | N/A | 17613 |
| 920 | *\PSnmap.ps1* | .{0,1000}\\PSnmap\.ps1.{0,1000} | offensive_tool_keyword | Psnmap | Powershell scanner (nmap like) | T1086 - T1046 - T1059 | TA0007 | N/A | Black Basta | Discovery | https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1 | 1 | 0 | N/A | N/A | 7 | 2 | 178 | 64 | 2024-08-23T18:24:20Z | 2015-01-24T10:46:41Z | 17614 |
| 921 | *\PSnmap.psd1* | .{0,1000}\\PSnmap\.psd1.{0,1000} | offensive_tool_keyword | Psnmap | Powershell scanner (nmap like) | T1086 - T1046 - T1059 | TA0007 | N/A | Black Basta | Discovery | https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1 | 1 | 0 | N/A | N/A | 7 | 2 | 178 | 64 | 2024-08-23T18:24:20Z | 2015-01-24T10:46:41Z | 17615 |
| 922 | *\PSnmap.psm1* | .{0,1000}\\PSnmap\.psm1.{0,1000} | offensive_tool_keyword | Psnmap | Powershell scanner (nmap like) | T1086 - T1046 - T1059 | TA0007 | N/A | Black Basta | Discovery | https://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps1 | 1 | 0 | N/A | N/A | 7 | 2 | 178 | 64 | 2024-08-23T18:24:20Z | 2015-01-24T10:46:41Z | 17616 |
| 923 | *\pspy\pspy.go* | .{0,1000}\\pspy\\pspy\.go.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 0 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 17623 |
| 924 | *\PSRecon\* | .{0,1000}\\PSRecon\\.{0,1000} | offensive_tool_keyword | PSRecon | PSRecon gathers data from a remote Windows host using PowerShell (v2 or later). organizes the data into folders. hashes all extracted data. hashes PowerShell and various system properties. and sends the data off to the security team. The data can be pushed to a share. sent over email. or retained locally. | T1059 - T1003 - T1556 - T1204 | TA0002 - TA0009 | N/A | N/A | Discovery | https://github.com/gfoss/PSRecon | 1 | 0 | N/A | N/A | 9 | 5 | 486 | 105 | 2017-07-29T15:03:04Z | 2015-08-03T05:43:38Z | 17626 |
| 925 | *\psscanner\psscanner.go* | .{0,1000}\\psscanner\\psscanner\.go.{0,1000} | offensive_tool_keyword | pspy | Monitor linux processes without root permissions | T1057 - T1082 - T1518.001 | TA0007 | N/A | N/A | Discovery | https://github.com/DominicBreuker/pspy | 1 | 0 | #linux | N/A | 8 | 10 | 5370 | 538 | 2023-01-17T21:09:22Z | 2018-02-08T21:41:37Z | 17628 |
| 926 | *\Public\Document\SessionHunter.txt* | .{0,1000}\\Public\\Document\\SessionHunter\.txt.{0,1000} | offensive_tool_keyword | Invoke-SessionHunter | Retrieve and display information about active user sessions on remote computers. No admin privileges required | T1033 - T1078 - T1110 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-SessionHunter | 1 | 0 | N/A | N/A | 7 | 2 | 183 | 20 | 2024-08-12T13:15:10Z | 2023-08-13T13:22:05Z | 17636 |
| 927 | *\pyshark\src\* | .{0,1000}\\pyshark\\src\\.{0,1000} | greyware_tool_keyword | pyshark | Python wrapper for tshark allowing python packet parsing using wireshark dissectors | T1040 - T1213 - T1105 - T1572 | TA0009 - TA0007 | N/A | N/A | Discovery | https://github.com/KimiNewt/pyshark | 1 | 0 | N/A | N/A | 6 | 10 | 2355 | 439 | 2024-12-04T15:41:20Z | 2013-12-28T14:38:22Z | 17693 |
| 928 | *\quiet-riot-main* | .{0,1000}\\quiet\-riot\-main.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 17716 |
| 929 | *\rattler.cpp* | .{0,1000}\\rattler\.cpp.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 17762 |
| 930 | *\Rattler.exe* | .{0,1000}\\Rattler\.exe.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 17763 |
| 931 | *\Rattler_32.exe* | .{0,1000}\\Rattler_32\.exe.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 17764 |
| 932 | *\Rattler_x64.exe* | .{0,1000}\\Rattler_x64\.exe.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 17765 |
| 933 | *\rattler-master* | .{0,1000}\\rattler\-master.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 17766 |
| 934 | *\Recon-AD-AllLocalGroups.dll | .{0,1000}\\Recon\-AD\-AllLocalGroups\.dll | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17830 |
| 935 | *\Recon-AD-AllLocalGroups.sln* | .{0,1000}\\Recon\-AD\-AllLocalGroups\.sln.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17832 |
| 936 | *\Recon-AD-AllLocalGroups\* | .{0,1000}\\Recon\-AD\-AllLocalGroups\\.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17833 |
| 937 | *\Recon-AD-Computers.dll | .{0,1000}\\Recon\-AD\-Computers\.dll | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17834 |
| 938 | *\Recon-AD-Computers.sln* | .{0,1000}\\Recon\-AD\-Computers\.sln.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17836 |
| 939 | *\Recon-AD-Computers\* | .{0,1000}\\Recon\-AD\-Computers\\.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17837 |
| 940 | *\Recon-AD-Domain.dll | .{0,1000}\\Recon\-AD\-Domain\.dll | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17838 |
| 941 | *\Recon-AD-Domain.sln* | .{0,1000}\\Recon\-AD\-Domain\.sln.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17840 |
| 942 | *\Recon-AD-Domain\* | .{0,1000}\\Recon\-AD\-Domain\\.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17841 |
| 943 | *\Recon-AD-Groups.dll | .{0,1000}\\Recon\-AD\-Groups\.dll | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17842 |
| 944 | *\Recon-AD-Groups.sln* | .{0,1000}\\Recon\-AD\-Groups\.sln.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17844 |
| 945 | *\Recon-AD-LocalGroups.dll* | .{0,1000}\\Recon\-AD\-LocalGroups\.dll.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17846 |
| 946 | *\Recon-AD-LocalGroups.sln* | .{0,1000}\\Recon\-AD\-LocalGroups\.sln.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17847 |
| 947 | *\Recon-AD-LocalGroups\* | .{0,1000}\\Recon\-AD\-LocalGroups\\.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17848 |
| 948 | *\Recon-AD-master* | .{0,1000}\\Recon\-AD\-master.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17849 |
| 949 | *\Recon-AD-SPNs.sln* | .{0,1000}\\Recon\-AD\-SPNs\.sln.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17851 |
| 950 | *\Recon-AD-SPNs\* | .{0,1000}\\Recon\-AD\-SPNs\\.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17852 |
| 951 | *\Recon-AD-Users.dll* | .{0,1000}\\Recon\-AD\-Users\.dll.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17854 |
| 952 | *\Recon-AD-Users.sln* | .{0,1000}\\Recon\-AD\-Users\.sln.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17855 |
| 953 | *\ReflectiveDll.cpp* | .{0,1000}\\ReflectiveDll\.cpp.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17876 |
| 954 | *\ReflectiveLoader.cpp* | .{0,1000}\\ReflectiveLoader\.cpp.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 17878 |
| 955 | *\RpcView.exe* | .{0,1000}\\RpcView\.exe.{0,1000} | greyware_tool_keyword | RpcView | RpcView is a free tool to explore and decompile Microsoft RPC interfaces | T1082 - T1016 - T1046 - T1622 | TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/silverf0x/RpcView | 1 | 0 | N/A | N/A | 6 | 10 | 965 | 255 | 2023-09-24T19:58:04Z | 2017-03-14T19:14:45Z | 18172 |
| 956 | *\RpcView64.7z* | .{0,1000}\\RpcView64\.7z.{0,1000} | greyware_tool_keyword | RpcView | RpcView is a free tool to explore and decompile Microsoft RPC interfaces | T1082 - T1016 - T1046 - T1622 | TA0007 - TA0008 | N/A | Dispossessor | Discovery | https://github.com/silverf0x/RpcView | 1 | 0 | N/A | N/A | 6 | 10 | 965 | 255 | 2023-09-24T19:58:04Z | 2017-03-14T19:14:45Z | 18173 |
| 957 | *\RunOnce\wextract_cleanup0* | .{0,1000}\\RunOnce\\wextract_cleanup0.{0,1000} | greyware_tool_keyword | PortQry | Microsoft port scanning tool abused by threat actors | T1046 - T1016 - T1049 | TA0007 | N/A | APT15 | Discovery | https://www.microsoft.com/en-us/download/details.aspx?id=17148 | 1 | 0 | #registry | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 18222 |
| 958 | *\rusthound.exe* | .{0,1000}\\rusthound\.exe.{0,1000} | offensive_tool_keyword | RustHound | Active Directory data collector for BloodHound written in Rust | T1087.002 - T1018 - T1059.003 | TA0007 - TA0001 - TA0002 | N/A | N/A | Discovery | https://github.com/OPENCYBER-FR/RustHound | 1 | 0 | N/A | AD Enumeration | 9 | 10 | 1013 | 98 | 2024-10-21T18:58:20Z | 2022-10-12T05:54:35Z | 18233 |
| 959 | *\s3aclenum.py* | .{0,1000}\\s3aclenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 18243 |
| 960 | *\s3enum.py* | .{0,1000}\\s3enum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 18244 |
| 961 | *\scanACLsResults.csv* | .{0,1000}\\scanACLsResults\.csv.{0,1000} | offensive_tool_keyword | ACLight | A tool for advanced discovery of Privileged Accounts - including Shadow Admins. | T1087 - T1003 - T1208 | TA0001 - TA0006 - TA0008 | N/A | N/A | Discovery | https://github.com/cyberark/ACLight | 1 | 0 | N/A | AD Enumeration | 7 | 9 | 801 | 146 | 2019-09-09T06:48:45Z | 2017-05-17T09:29:41Z | 18286 |
| 962 | *\SearchShares.ps1* | .{0,1000}\\SearchShares\.ps1.{0,1000} | offensive_tool_keyword | SearchOpenFileShares | Searches open files shares for password files or database backups - Extend as you see fit | T1083 - T1135 - T1005 - T1025 | TA0007 - TA0009 | N/A | Dispossessor | Discovery | https://github.com/fashionproof/SearchOpenFileShares | 1 | 0 | N/A | N/A | 7 | 1 | 29 | 6 | 2019-12-13T12:37:42Z | 2019-09-21T13:50:26Z | 18330 |
| 963 | *\secretsmanagerenum.py* | .{0,1000}\\secretsmanagerenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 18349 |
| 964 | *\ShadowSpray\*.cs* | .{0,1000}\\ShadowSpray\\.{0,1000}\.cs.{0,1000} | offensive_tool_keyword | ShadowSpray | A tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain. | T1110.003 - T1098 - T1059 - T1075 | TA0001 - TA0008 - TA0009 | N/A | Black Basta | Discovery | https://github.com/ShorSec/ShadowSpray | 1 | 0 | N/A | N/A | 7 | 5 | 459 | 80 | 2022-10-14T13:36:51Z | 2022-10-10T08:34:07Z | 18412 |
| 965 | *\shareaudit.exe* | .{0,1000}\\shareaudit\.exe.{0,1000} | offensive_tool_keyword | ShareAudit | A tool for auditing network shares in an Active Directory environment | T1135 - T1005 - T1083 - T1210 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/dionach/ShareAudit | 1 | 0 | N/A | N/A | 8 | 1 | 42 | 15 | 2019-04-29T10:07:57Z | 2019-02-26T16:00:15Z | 18418 |
| 966 | *\ShareAudit.sln* | .{0,1000}\\ShareAudit\.sln.{0,1000} | offensive_tool_keyword | ShareAudit | A tool for auditing network shares in an Active Directory environment | T1135 - T1005 - T1083 - T1210 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/dionach/ShareAudit | 1 | 0 | N/A | N/A | 8 | 1 | 42 | 15 | 2019-04-29T10:07:57Z | 2019-02-26T16:00:15Z | 18419 |
| 967 | *\Shares_CleanupCommand.txt* | .{0,1000}\\Shares_CleanupCommand\.txt.{0,1000} | offensive_tool_keyword | Invoke-ShareHunter | Enumerate the Domain for Readable and Writable Shares | T1135 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ShareHunter | 1 | 0 | N/A | N/A | 5 | 1 | 17 | 1 | 2025-02-18T14:56:51Z | 2023-09-21T14:31:17Z | 18422 |
| 968 | *\Shares_Readable.txt* | .{0,1000}\\Shares_Readable\.txt.{0,1000} | offensive_tool_keyword | Invoke-ShareHunter | Enumerate the Domain for Readable and Writable Shares | T1135 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ShareHunter | 1 | 0 | N/A | N/A | 5 | 1 | 17 | 1 | 2025-02-18T14:56:51Z | 2023-09-21T14:31:17Z | 18423 |
| 969 | *\Shares_Writable.txt"* | .{0,1000}\\Shares_Writable\.txt\".{0,1000} | offensive_tool_keyword | Invoke-ShareHunter | Enumerate the Domain for Readable and Writable Shares | T1135 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ShareHunter | 1 | 0 | N/A | N/A | 5 | 1 | 17 | 1 | 2025-02-18T14:56:51Z | 2023-09-21T14:31:17Z | 18424 |
| 970 | *\SharpADWS.csproj* | .{0,1000}\\SharpADWS\.csproj.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 18426 |
| 971 | *\SharpADWS.sln* | .{0,1000}\\SharpADWS\.sln.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 18427 |
| 972 | *\SharpADWS\* | .{0,1000}\\SharpADWS\\.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 18428 |
| 973 | *\SharpADWS-master* | .{0,1000}\\SharpADWS\-master.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 18429 |
| 974 | *\SharpAVKB.exe* | .{0,1000}\\SharpAVKB\.exe.{0,1000} | offensive_tool_keyword | SharpAVKB | Windows Antivirus Comparison and Patch Number Comparison | T1082 - T1518 - T1083 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpAVKB | 1 | 0 | N/A | N/A | 4 | 1 | 58 | 24 | 2019-10-28T06:50:30Z | 2019-10-14T12:44:22Z | 18439 |
| 975 | *\SharpAVKB.pdb* | .{0,1000}\\SharpAVKB\.pdb.{0,1000} | offensive_tool_keyword | SharpAVKB | Windows Antivirus Comparison and Patch Number Comparison | T1082 - T1518 - T1083 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpAVKB | 1 | 0 | #content | N/A | 4 | 1 | 58 | 24 | 2019-10-28T06:50:30Z | 2019-10-14T12:44:22Z | 18440 |
| 976 | *\SharpAVKB-master* | .{0,1000}\\SharpAVKB\-master.{0,1000} | offensive_tool_keyword | SharpAVKB | Windows Antivirus Comparison and Patch Number Comparison | T1082 - T1518 - T1083 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpAVKB | 1 | 0 | N/A | N/A | 4 | 1 | 58 | 24 | 2019-10-28T06:50:30Z | 2019-10-14T12:44:22Z | 18441 |
| 977 | *\SharpAzbelt.csproj* | .{0,1000}\\SharpAzbelt\.csproj.{0,1000} | offensive_tool_keyword | SharpAzbelt | This is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resources | T1082 - T1003 - T1027 - T1110 - T1078 | TA0006 - TA0007 - TA0005 - TA0004 - TA0003 | N/A | N/A | Discovery | https://github.com/redskal/SharpAzbelt | 1 | 0 | N/A | N/A | 8 | 1 | 26 | 7 | 2023-09-21T21:47:32Z | 2023-09-21T21:44:03Z | 18442 |
| 978 | *\SharpAzbelt.exe* | .{0,1000}\\SharpAzbelt\.exe.{0,1000} | offensive_tool_keyword | SharpAzbelt | This is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resources | T1082 - T1003 - T1027 - T1110 - T1078 | TA0006 - TA0007 - TA0005 - TA0004 - TA0003 | N/A | N/A | Discovery | https://github.com/redskal/SharpAzbelt | 1 | 0 | N/A | N/A | 8 | 1 | 26 | 7 | 2023-09-21T21:47:32Z | 2023-09-21T21:44:03Z | 18443 |
| 979 | *\SharpAzbelt.sln* | .{0,1000}\\SharpAzbelt\.sln.{0,1000} | offensive_tool_keyword | SharpAzbelt | This is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resources | T1082 - T1003 - T1027 - T1110 - T1078 | TA0006 - TA0007 - TA0005 - TA0004 - TA0003 | N/A | N/A | Discovery | https://github.com/redskal/SharpAzbelt | 1 | 0 | N/A | N/A | 8 | 1 | 26 | 7 | 2023-09-21T21:47:32Z | 2023-09-21T21:44:03Z | 18444 |
| 980 | *\SharpBuster.csproj* | .{0,1000}\\SharpBuster\.csproj.{0,1000} | offensive_tool_keyword | SharpBuster | This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution | T1087 - T1112 - T1048.003 - T1105 | TA0007 - TA0040 - TA0002 | N/A | N/A | Discovery | https://github.com/passthehashbrowns/SharpBuster | 1 | 0 | N/A | N/A | 7 | 1 | 62 | 7 | 2020-09-02T15:46:03Z | 2020-08-31T00:33:02Z | 18447 |
| 981 | *\SharpBuster.dll* | .{0,1000}\\SharpBuster\.dll.{0,1000} | offensive_tool_keyword | SharpBuster | This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution | T1087 - T1112 - T1048.003 - T1105 | TA0007 - TA0040 - TA0002 | N/A | N/A | Discovery | https://github.com/passthehashbrowns/SharpBuster | 1 | 0 | N/A | N/A | 7 | 1 | 62 | 7 | 2020-09-02T15:46:03Z | 2020-08-31T00:33:02Z | 18448 |
| 982 | *\SharpBuster.exe* | .{0,1000}\\SharpBuster\.exe.{0,1000} | offensive_tool_keyword | SharpBuster | This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution | T1087 - T1112 - T1048.003 - T1105 | TA0007 - TA0040 - TA0002 | N/A | N/A | Discovery | https://github.com/passthehashbrowns/SharpBuster | 1 | 0 | N/A | N/A | 7 | 1 | 62 | 7 | 2020-09-02T15:46:03Z | 2020-08-31T00:33:02Z | 18449 |
| 983 | *\SharpBuster.pdb* | .{0,1000}\\SharpBuster\.pdb.{0,1000} | offensive_tool_keyword | SharpBuster | This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution | T1087 - T1112 - T1048.003 - T1105 | TA0007 - TA0040 - TA0002 | N/A | N/A | Discovery | https://github.com/passthehashbrowns/SharpBuster | 1 | 0 | N/A | N/A | 7 | 1 | 62 | 7 | 2020-09-02T15:46:03Z | 2020-08-31T00:33:02Z | 18450 |
| 984 | *\SharpBuster.sln* | .{0,1000}\\SharpBuster\.sln.{0,1000} | offensive_tool_keyword | SharpBuster | This is a C# implementation of a directory brute forcing tool designed to allow for in-memory execution | T1087 - T1112 - T1048.003 - T1105 | TA0007 - TA0040 - TA0002 | N/A | N/A | Discovery | https://github.com/passthehashbrowns/SharpBuster | 1 | 0 | N/A | N/A | 7 | 1 | 62 | 7 | 2020-09-02T15:46:03Z | 2020-08-31T00:33:02Z | 18451 |
| 985 | *\SharpEDRChecker-*.zip* | .{0,1000}\\SharpEDRChecker\-.{0,1000}\.zip.{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | N/A | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 18519 |
| 986 | *\SharpEDRChecker.cs* | .{0,1000}\\SharpEDRChecker\.cs.{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | N/A | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 18520 |
| 987 | *\SharpEDRChecker.sln* | .{0,1000}\\SharpEDRChecker\.sln.{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | N/A | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 18524 |
| 988 | *\SharpEDRChecker\* | .{0,1000}\\SharpEDRChecker\\.{0,1000} | offensive_tool_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | N/A | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 18525 |
| 989 | *\SharpEventLog.csproj* | .{0,1000}\\SharpEventLog\.csproj.{0,1000} | offensive_tool_keyword | SharpEventLog | reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration | T1078 - T1087.001 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpEventLog | 1 | 0 | N/A | N/A | 4 | 3 | 205 | 34 | 2019-10-15T06:26:52Z | 2019-10-15T06:14:32Z | 18536 |
| 990 | *\SharpEventLog.exe* | .{0,1000}\\SharpEventLog\.exe.{0,1000} | offensive_tool_keyword | SharpEventLog | reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration | T1078 - T1087.001 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpEventLog | 1 | 0 | N/A | N/A | 4 | 3 | 205 | 34 | 2019-10-15T06:26:52Z | 2019-10-15T06:14:32Z | 18538 |
| 991 | *\SharpEventLog.pdb* | .{0,1000}\\SharpEventLog\.pdb.{0,1000} | offensive_tool_keyword | SharpEventLog | reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration | T1078 - T1087.001 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpEventLog | 1 | 0 | #content | N/A | 4 | 3 | 205 | 34 | 2019-10-15T06:26:52Z | 2019-10-15T06:14:32Z | 18539 |
| 992 | *\SharpEventLog.sln* | .{0,1000}\\SharpEventLog\.sln.{0,1000} | offensive_tool_keyword | SharpEventLog | reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration | T1078 - T1087.001 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpEventLog | 1 | 0 | N/A | N/A | 4 | 3 | 205 | 34 | 2019-10-15T06:26:52Z | 2019-10-15T06:14:32Z | 18540 |
| 993 | *\SharpEventLog-master* | .{0,1000}\\SharpEventLog\-master.{0,1000} | offensive_tool_keyword | SharpEventLog | reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration | T1078 - T1087.001 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpEventLog | 1 | 0 | N/A | N/A | 4 | 3 | 205 | 34 | 2019-10-15T06:26:52Z | 2019-10-15T06:14:32Z | 18541 |
| 994 | *\SharpGraphView.sln* | .{0,1000}\\SharpGraphView\.sln.{0,1000} | offensive_tool_keyword | SharpGraphView | Microsoft Graph API post-exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/SharpGraphView | 1 | 0 | N/A | N/A | 6 | 1 | 94 | 9 | 2024-07-13T12:27:38Z | 2024-05-04T11:23:42Z | 18564 |
| 995 | *\sharpgraphview\* | .{0,1000}\\sharpgraphview\\.{0,1000} | offensive_tool_keyword | SharpGraphView | Microsoft Graph API post-exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/SharpGraphView | 1 | 0 | N/A | N/A | 6 | 1 | 94 | 9 | 2024-07-13T12:27:38Z | 2024-05-04T11:23:42Z | 18565 |
| 996 | *\SharpHound.pdb* | .{0,1000}\\SharpHound\.pdb.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 18579 |
| 997 | *\SharpHound.pdb* | .{0,1000}\\SharpHound\.pdb.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 18581 |
| 998 | *\SharpHound.ps1* | .{0,1000}\\SharpHound\.ps1.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 18583 |
| 999 | *\SharpHoundCommon\* | .{0,1000}\\SharpHoundCommon\\.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 18584 |
| 1000 | *\SharpHound-v*.zip* | .{0,1000}\\SharpHound\-v.{0,1000}\.zip.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 18585 |
| 1001 | *\SharpLDAP\* | .{0,1000}\\SharpLDAP\\.{0,1000} | offensive_tool_keyword | SharpLDAP | tool written in C# that aims to do enumeration via LDAP queries | T1018 - T1069.003 | TA0007 - TA0011 | N/A | N/A | Discovery | https://github.com/mertdas/SharpLDAP | 1 | 0 | N/A | N/A | 8 | 1 | 0 | 1 | 2023-01-14T21:52:36Z | 2022-11-16T00:38:43Z | 18602 |
| 1002 | *\SharpNBTScan.sln* | .{0,1000}\\SharpNBTScan\.sln.{0,1000} | offensive_tool_keyword | SharpNBTScan | a NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumeration | T1018 - T1046 | TA0007 | Ghost Ransomware | N/A | Discovery | https://github.com/BronzeTicket/SharpNBTScan | 1 | 0 | N/A | N/A | 7 | 1 | 71 | 4 | 2021-08-06T05:36:55Z | 2021-07-12T08:57:39Z | 18629 |
| 1003 | *\SharpNBTScan-main* | .{0,1000}\\SharpNBTScan\-main.{0,1000} | offensive_tool_keyword | SharpNBTScan | a NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumeration | T1018 - T1046 | TA0007 | Ghost Ransomware | N/A | Discovery | https://github.com/BronzeTicket/SharpNBTScan | 1 | 0 | N/A | N/A | 7 | 1 | 71 | 4 | 2021-08-06T05:36:55Z | 2021-07-12T08:57:39Z | 18630 |
| 1004 | *\SharpRODC.* | .{0,1000}\\SharpRODC\..{0,1000} | offensive_tool_keyword | SharpRODC | audit the security of read-only domain controllers | T1012 - T1482 - T1207 - T1208 - T1209 - T1212 | TA0007 - TA0008 - TA0006 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpRODC | 1 | 0 | N/A | N/A | 8 | 2 | 115 | 8 | 2023-11-27T12:41:52Z | 2023-11-24T14:35:49Z | 18657 |
| 1005 | *\SharpRODC\* | .{0,1000}\\SharpRODC\\.{0,1000} | offensive_tool_keyword | SharpRODC | audit the security of read-only domain controllers | T1012 - T1482 - T1207 - T1208 - T1209 - T1212 | TA0007 - TA0008 - TA0006 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpRODC | 1 | 0 | N/A | N/A | 8 | 2 | 115 | 8 | 2023-11-27T12:41:52Z | 2023-11-24T14:35:49Z | 18658 |
| 1006 | *\SharpShares\* | .{0,1000}\\SharpShares\\.{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/Hackcraft-Labs/SharpShares | 1 | 0 | N/A | N/A | 10 | 1 | 33 | 7 | 2023-11-13T14:08:07Z | 2023-10-25T10:34:18Z | 18675 |
| 1007 | *\SharpShares-master* | .{0,1000}\\SharpShares\-master.{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/Hackcraft-Labs/SharpShares | 1 | 0 | N/A | N/A | 10 | 1 | 33 | 7 | 2023-11-13T14:08:07Z | 2023-10-25T10:34:18Z | 18676 |
| 1008 | *\SharpSSDP.csproj* | .{0,1000}\\SharpSSDP\.csproj.{0,1000} | offensive_tool_keyword | SharpSSDP | execute SharpSSDP.exe through Cobalt Strike's Beacon "execute-assembly" module to discover SSDP related services | T1046 - T1016 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/rvrsh3ll/SharpSSDP | 1 | 0 | N/A | N/A | 7 | 1 | 17 | 4 | 2018-12-16T17:14:28Z | 2018-12-16T17:14:12Z | 18717 |
| 1009 | *\SharpSSDP.sln* | .{0,1000}\\SharpSSDP\.sln.{0,1000} | offensive_tool_keyword | SharpSSDP | execute SharpSSDP.exe through Cobalt Strike's Beacon "execute-assembly" module to discover SSDP related services | T1046 - T1016 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/rvrsh3ll/SharpSSDP | 1 | 0 | N/A | N/A | 7 | 1 | 17 | 4 | 2018-12-16T17:14:28Z | 2018-12-16T17:14:12Z | 18718 |
| 1010 | *\SharpSSDP\* | .{0,1000}\\SharpSSDP\\.{0,1000} | offensive_tool_keyword | SharpSSDP | execute SharpSSDP.exe through Cobalt Strike's Beacon "execute-assembly" module to discover SSDP related services | T1046 - T1016 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/rvrsh3ll/SharpSSDP | 1 | 0 | N/A | N/A | 7 | 1 | 17 | 4 | 2018-12-16T17:14:28Z | 2018-12-16T17:14:12Z | 18719 |
| 1011 | *\SmallSecretsDump.py* | .{0,1000}\\SmallSecretsDump\.py.{0,1000} | offensive_tool_keyword | Adcheck | Assess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastle | T1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 | N/A | N/A | Discovery | https://github.com/CobblePot59/Adcheck | 1 | 0 | N/A | N/A | 10 | 4 | 315 | 35 | 2025-04-18T15:17:46Z | 2024-05-10T13:54:45Z | 18877 |
| 1012 | *\smbscan-*.csv* | .{0,1000}\\smbscan\-.{0,1000}\.csv.{0,1000} | offensive_tool_keyword | smbscan | SMBScan is a tool to enumerate file shares on an internal network. | T1135 - T1046 - T1021 | TA0007 - TA0043 - TA0008 | N/A | APT22 | Discovery | https://github.com/jeffhacks/smbscan | 1 | 0 | N/A | N/A | 8 | 1 | 44 | 6 | 2025-03-24T01:55:30Z | 2021-10-26T02:28:34Z | 18903 |
| 1013 | *\smbscan-*.log* | .{0,1000}\\smbscan\-.{0,1000}\.log.{0,1000} | offensive_tool_keyword | smbscan | SMBScan is a tool to enumerate file shares on an internal network. | T1135 - T1046 - T1021 | TA0007 - TA0043 - TA0008 | N/A | APT22 | Discovery | https://github.com/jeffhacks/smbscan | 1 | 0 | N/A | N/A | 8 | 1 | 44 | 6 | 2025-03-24T01:55:30Z | 2021-10-26T02:28:34Z | 18904 |
| 1014 | *\smbscan.py* | .{0,1000}\\smbscan\.py.{0,1000} | offensive_tool_keyword | smbscan | SMBScan is a tool to enumerate file shares on an internal network. | T1135 - T1046 - T1021 | TA0007 - TA0043 - TA0008 | N/A | APT22 | Discovery | https://github.com/jeffhacks/smbscan | 1 | 0 | N/A | N/A | 8 | 1 | 44 | 6 | 2025-03-24T01:55:30Z | 2021-10-26T02:28:34Z | 18905 |
| 1015 | *\SMBSigningNotRequired.txt* | .{0,1000}\\SMBSigningNotRequired\.txt.{0,1000} | offensive_tool_keyword | CheckSMBSigning | Checks for SMB signing disabled on all hosts in the network | T1018 - T1550 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/Leo4j/CheckSMBSigning | 1 | 0 | N/A | N/A | 6 | 1 | 8 | 1 | 2023-10-13T11:55:33Z | 2023-05-17T11:47:52Z | 18907 |
| 1016 | *\smbsr.db* | .{0,1000}\\smbsr\.db.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 18908 |
| 1017 | *\smbsr.log* | .{0,1000}\\smbsr\.log.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 18909 |
| 1018 | *\smbsr.py* | .{0,1000}\\smbsr\.py.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 18910 |
| 1019 | *\smbsr_results.csv* | .{0,1000}\\smbsr_results\.csv.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 18911 |
| 1020 | *\snsenum.py* | .{0,1000}\\snsenum\.py.{0,1000} | offensive_tool_keyword | quiet-riot | Unauthenticated enumeration of AWS - Azure and GCP Principals | T1087 - T1083 - T1210 | TA0007 - TA0001 | N/A | N/A | Discovery | https://github.com/righteousgambit/quiet-riot | 1 | 0 | N/A | N/A | 6 | 3 | 224 | 30 | 2024-11-13T19:41:26Z | 2021-10-28T15:12:27Z | 18932 |
| 1021 | *\SOAPHound.csproj* | .{0,1000}\\SOAPHound\.csproj.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 18933 |
| 1022 | *\SOAPHound.exe* | .{0,1000}\\SOAPHound\.exe.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 18934 |
| 1023 | *\SOAPHound.sln* | .{0,1000}\\SOAPHound\.sln.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 18935 |
| 1024 | *\SOAPHound\Enums\* | .{0,1000}\\SOAPHound\\Enums\\.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 18936 |
| 1025 | *\SOAPHound\Program.cs* | .{0,1000}\\SOAPHound\\Program\.cs.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 18937 |
| 1026 | *\SOAPHound-master* | .{0,1000}\\SOAPHound\-master.{0,1000} | offensive_tool_keyword | SOAPHound | enumerate Active Directory environments via the Active Directory Web Services (ADWS) | T1018 - T1087.002 - T1649 | TA0007 - TA0003 | N/A | N/A | Discovery | https://github.com/FalconForceTeam/SOAPHound | 1 | 0 | N/A | N/A | 8 | 8 | 736 | 76 | 2024-02-03T08:52:49Z | 2024-01-25T09:11:12Z | 18938 |
| 1027 | *\SoftPerfect Network Scanner* | .{0,1000}\\SoftPerfect\sNetwork\sScanner.{0,1000} | greyware_tool_keyword | netscan | SoftPerfect Network Scanner abused by threat actor | T1040 - T1046 - T1018 | TA0007 - TA0010 - TA0001 | N/A | BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - Lynx | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | network exploitation tool | 6 | 10 | N/A | N/A | N/A | N/A | 18947 |
| 1028 | *\SoftPerfect Network Scanner\* | .{0,1000}\\SoftPerfect\sNetwork\sScanner\\.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | N/A | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 18948 |
| 1029 | *\Software\MSDART\Active Directory Explorer* | .{0,1000}\\Software\\MSDART\\Active\sDirectory\sExplorer.{0,1000} | greyware_tool_keyword | adexplorer | Active Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actors | T1003.001 - T1087.001 | TA0006 - TA0007 | N/A | Lapsus$ - Scattered Spider* - BlackBasta | Discovery | https://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer | 1 | 0 | #registry | greyware tool - risks of False positive ! | 7 | 10 | N/A | N/A | N/A | N/A | 18965 |
| 1030 | *\Software\Sysinternals\Active Directory Explorer* | .{0,1000}\\Software\\Sysinternals\\Active\sDirectory\sExplorer.{0,1000} | greyware_tool_keyword | adexplorer | Active Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actors | T1003.001 - T1087.001 | TA0006 - TA0007 | N/A | Lapsus$ - Scattered Spider* - BlackBasta | Discovery | https://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer | 1 | 0 | #registry | greyware tool - risks of False positive ! | 7 | 10 | N/A | N/A | N/A | N/A | 18974 |
| 1031 | *\Src\Recon-AD-Groups\* | .{0,1000}\\Src\\Recon\-AD\-Groups\\.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 19084 |
| 1032 | *\Src\Recon-AD-Users\* | .{0,1000}\\Src\\Recon\-AD\-Users\\.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 0 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 19085 |
| 1033 | *\StandIn --* | .{0,1000}\\StandIn\s\-\-.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 19099 |
| 1034 | *\StandIn.exe* | .{0,1000}\\StandIn\.exe.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 19100 |
| 1035 | *\StandIn.pdb* | .{0,1000}\\StandIn\.pdb.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 19101 |
| 1036 | *\StandIn\hStandIn.cs* | .{0,1000}\\StandIn\\hStandIn\.cs.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 19102 |
| 1037 | *\StandIn\Program.cs* | .{0,1000}\\StandIn\\Program\.cs.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 19103 |
| 1038 | *\StandIn_Net35.exe* | .{0,1000}\\StandIn_Net35\.exe.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 19104 |
| 1039 | *\StandIn_Net45.exe * | .{0,1000}\\StandIn_Net45\.exe\s.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 19105 |
| 1040 | *\StandIn-1.3.zip* | .{0,1000}\\StandIn\-1\.3\.zip.{0,1000} | offensive_tool_keyword | StandIn | StandIn is a small .NET35/45 AD post-exploitation toolkit | T1087 - T1069 - T1558 - T1204 - T1136 - T1482 | TA0007 - TA0003 - TA0006 - TA0004 | N/A | N/A | Discovery | https://github.com/FuzzySecurity/StandIn | 1 | 0 | N/A | N/A | 9 | 8 | 761 | 129 | 2023-12-02T21:20:09Z | 2020-11-05T22:49:27Z | 19106 |
| 1041 | *\Start Menu\Programs\Advanced IP Scanner v2* | .{0,1000}\\Start\sMenu\\Programs\\Advanced\sIP\sScanner\sv2.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 19111 |
| 1042 | *\teamsenum.py* | .{0,1000}\\teamsenum\.py.{0,1000} | offensive_tool_keyword | TeamsEnum | User Enumeration of Microsoft Teams users via API | T1589.002 - T1590 | TA0007 - TA0001 | N/A | Black Basta | Discovery | https://github.com/sse-secure-systems/TeamsEnum | 1 | 0 | N/A | N/A | 6 | 2 | 153 | 21 | 2024-03-27T18:14:25Z | 2023-04-03T18:35:15Z | 19258 |
| 1043 | *\Temp\2\Advanced Port Scanner 2\* | .{0,1000}\\Temp\\2\\Advanced\sPort\sScanner\s2\\.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 19273 |
| 1044 | *\temp\OpenFileShares.txt* | .{0,1000}\\temp\\OpenFileShares\.txt.{0,1000} | offensive_tool_keyword | SearchOpenFileShares | Searches open files shares for password files or database backups - Extend as you see fit | T1083 - T1135 - T1005 - T1025 | TA0007 - TA0009 | N/A | Dispossessor | Discovery | https://github.com/fashionproof/SearchOpenFileShares | 1 | 0 | N/A | N/A | 7 | 1 | 29 | 6 | 2019-12-13T12:37:42Z | 2019-09-21T13:50:26Z | 19295 |
| 1045 | *\Temp\WizTree.exe* | .{0,1000}\\Temp\\WizTree\.exe.{0,1000} | greyware_tool_keyword | wiztree | legitimate tool abused by threat actors to obtain network files and directory listings | T1083 | TA0007 | N/A | Fox Kitten - Faust - Bitlocker - Akira - Cactus - BlackSuit - Royal | Discovery | N/A | 1 | 0 | N/A | N/A | 3 | 6 | N/A | N/A | N/A | N/A | 19309 |
| 1046 | *\TokenDump.cs* | .{0,1000}\\TokenDump\.cs.{0,1000} | offensive_tool_keyword | PrivFu | inspect token information | T1057 | TA0007 | N/A | N/A | Discovery | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | TokenDump | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19369 |
| 1047 | *\TokenDump.exe* | .{0,1000}\\TokenDump\.exe.{0,1000} | offensive_tool_keyword | PrivFu | inspect token information | T1057 | TA0007 | N/A | N/A | Discovery | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | TokenDump | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19370 |
| 1048 | *\TokenDump.sln* | .{0,1000}\\TokenDump\.sln.{0,1000} | offensive_tool_keyword | PrivFu | inspect token information | T1057 | TA0007 | N/A | N/A | Discovery | https://github.com/daem0nc0re/PrivFu | 1 | 0 | N/A | TokenDump | 10 | 9 | 849 | 122 | 2025-01-21T05:22:50Z | 2021-12-28T13:14:25Z | 19372 |
| 1049 | *\windapsearch.py* | .{0,1000}\\windapsearch\.py.{0,1000} | offensive_tool_keyword | smbsr | Lookup for interesting stuff in SMB shares | T1135 | TA0001 - TA0007 | N/A | N/A | Discovery | https://github.com/oldboy21/SMBSR | 1 | 0 | N/A | N/A | 7 | 2 | 149 | 23 | 2023-06-16T14:35:30Z | 2021-11-10T16:55:52Z | 19717 |
| 1050 | *\Windows\system32\ROUTE.EXE" print* | .{0,1000}\\Windows\\system32\\ROUTE\.EXE\"\sprint.{0,1000} | greyware_tool_keyword | route | display the IP routing table on a system | T1016 - T1087 - T1049 | TA0007 - TA0043 | N/A | Dispossessor | Discovery | https://vx-underground.org/Archive/Dispossessor%20Leaks | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 19732 |
| 1051 | *\WindowsShareFinder.cs* | .{0,1000}\\WindowsShareFinder\.cs.{0,1000} | offensive_tool_keyword | SMBeagle | SMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host. | T1087.002 - T1021.002 - T1210 | TA0007 - TA0008 - TA0003 | N/A | N/A | Discovery | https://github.com/punk-security/SMBeagle | 1 | 0 | N/A | N/A | 9 | 8 | 712 | 80 | 2025-01-21T22:34:00Z | 2021-05-31T19:46:57Z | 19776 |
| 1052 | *\WizTree.exe* | .{0,1000}\\WizTree\.exe.{0,1000} | greyware_tool_keyword | wiztree | legitimate tool abused by threat actors to obtain network files and directory listings | T1083 | TA0007 | N/A | Fox Kitten - Faust - Bitlocker - Akira - Cactus - BlackSuit - Royal | Discovery | N/A | 1 | 0 | N/A | N/A | 3 | 6 | N/A | N/A | N/A | N/A | 19826 |
| 1053 | *\wiztree_*_portable.zip* | .{0,1000}\\wiztree_.{0,1000}_portable\.zip.{0,1000} | greyware_tool_keyword | wiztree | legitimate tool abused by threat actors to obtain network files and directory listings | T1083 | TA0007 | N/A | Fox Kitten - Faust - Bitlocker - Akira - Cactus - BlackSuit - Royal | Discovery | N/A | 1 | 0 | N/A | N/A | 3 | 6 | N/A | N/A | N/A | N/A | 19827 |
| 1054 | *] Attempting to enumerate logged on users on * | .{0,1000}\]\sAttempting\sto\senumerate\slogged\son\susers\son\s.{0,1000} | offensive_tool_keyword | GetLoggedOnUsersRegistry | PoC To enumerate logged on users on a remote system using the winreg named pipe | T1087 - T1018 - T1057 | TA0007 - TA0008 | N/A | N/A | Discovery | https://gist.github.com/RalphDesmangles/22f580655f479f189c1de9e7720776f1 | 1 | 0 | N/A | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 19982 |
| 1055 | *] Check for ADCS Vulnerabilities* | .{0,1000}\]\sCheck\sfor\sADCS\sVulnerabilities.{0,1000} | offensive_tool_keyword | adaudit | Powershell script to do domain auditing automation | T1087 - T1069 - T1046 - T1057 - T1114 - T1018 | TA0007 - TA0003 - TA0004 - TA0006 | N/A | N/A | Discovery | https://github.com/phillips321/adaudit | 1 | 0 | N/A | N/A | 5 | 4 | 389 | 106 | 2025-04-08T06:17:54Z | 2018-04-20T11:29:06Z | 19984 |
| 1056 | *] Collecting Krbtgt* | .{0,1000}\]\sCollecting\sKrbtgt.{0,1000} | offensive_tool_keyword | Invoke-ADEnum | Automate Active Directory Enumeration | T1016 - T1482 | TA0007 | N/A | N/A | Discovery | https://github.com/Leo4j/Invoke-ADEnum | 1 | 0 | N/A | N/A | 7 | 5 | 448 | 50 | 2025-04-09T10:13:47Z | 2023-04-18T11:19:42Z | 20007 |
| 1057 | *] Found kerberoastable users: * | .{0,1000}\]\sFound\skerberoastable\susers\:\s.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 20028 |
| 1058 | *] INFO: DLL IS VULNERABLE TO DOWNLOADS INSTALLER TEST-* | .{0,1000}\]\sINFO\:\sDLL\sIS\sVULNERABLE\sTO\sDOWNLOADS\sINSTALLER\sTEST\-.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 20039 |
| 1059 | *] INFO: DLL IS VULNERABLE TO EXECUTABLE TEST* | .{0,1000}\]\sINFO\:\sDLL\sIS\sVULNERABLE\sTO\sEXECUTABLE\sTEST.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 20040 |
| 1060 | *] Kerberoast user * successfully!* | .{0,1000}\]\sKerberoast\suser\s.{0,1000}\ssuccessfully!.{0,1000} | offensive_tool_keyword | SharpADWS | SharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS) | T1087 - T1069 - T1018 - T1083 - T1595 | TA0001 - TA0002 - TA0007 | N/A | N/A | Discovery | https://github.com/wh0amitz/SharpADWS | 1 | 0 | N/A | N/A | 7 | 6 | 538 | 59 | 2024-03-19T08:57:52Z | 2024-02-13T17:28:00Z | 20045 |
| 1061 | *] Listing all vulnerabilities scanned by Moriarty* | .{0,1000}\]\sListing\sall\svulnerabilities\sscanned\sby\sMoriarty.{0,1000} | offensive_tool_keyword | Moriarty | Moriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments. | T1068 - T1083 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/BC-SECURITY/Moriarty | 1 | 0 | N/A | N/A | 7 | 6 | 510 | 67 | 2024-08-07T15:06:31Z | 2023-12-11T14:15:33Z | 20048 |
| 1062 | *] Starting nullinux setup script* | .{0,1000}\]\sStarting\snullinux\ssetup\sscript.{0,1000} | offensive_tool_keyword | nullinux | Internal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB. | T1087 - T1016 - T1077 - T1018 | TA0007 - TA0006 | N/A | N/A | Discovery | https://github.com/m8sec/nullinux | 1 | 0 | #linux #content | N/A | 7 | 6 | 575 | 101 | 2024-06-19T14:29:09Z | 2016-04-28T16:45:02Z | 20077 |
| 1063 | *] Starting share enumeration with thread limit of * | .{0,1000}\]\sStarting\sshare\senumeration\swith\sthread\slimit\sof\s.{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/Hackcraft-Labs/SharpShares | 1 | 0 | N/A | N/A | 10 | 1 | 33 | 7 | 2023-11-13T14:08:07Z | 2023-10-25T10:34:18Z | 20079 |
| 1064 | *] TARGET DLL IS NOT VULNERABLE TO * | .{0,1000}\]\sTARGET\sDLL\sIS\sNOT\sVULNERABLE\sTO\s.{0,1000} | offensive_tool_keyword | rattler | Automated DLL Enumerator | T1174 - T1574.007 | TA0005 | N/A | N/A | Discovery | https://github.com/sensepost/rattler | 1 | 0 | N/A | N/A | 9 | 6 | 531 | 135 | 2017-12-21T18:01:09Z | 2016-11-28T12:35:44Z | 20084 |
| 1065 | *_adAclOutput*.csv* | .{0,1000}_adAclOutput.{0,1000}\.csv.{0,1000} | offensive_tool_keyword | ADACLScanner | A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory . | T1222 - T1069 - T1018 | TA0002 - TA0007 - TA0043 | N/A | N/A | Discovery | https://github.com/canix1/ADACLScanner | 1 | 0 | N/A | AD Enumeration | 7 | 10 | 1015 | 173 | 2025-04-11T14:35:08Z | 2017-04-06T12:28:37Z | 20103 |
| 1066 | *_adAclOutput*.csv* | .{0,1000}_adAclOutput.{0,1000}\.csv.{0,1000} | offensive_tool_keyword | ADACLScanner | A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory . | T1222 - T1069 - T1018 | TA0002 - TA0007 - TA0043 | N/A | N/A | Discovery | https://github.com/canix1/ADACLScanner | 1 | 0 | N/A | AD Enumeration | 7 | 10 | 1015 | 173 | 2025-04-11T14:35:08Z | 2017-04-06T12:28:37Z | 20104 |
| 1067 | *_adAclOutput*.csv* | .{0,1000}_adAclOutput.{0,1000}\.csv.{0,1000} | offensive_tool_keyword | ADACLScanner | A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory . | T1222 - T1069 - T1018 | TA0002 - TA0007 - TA0043 | N/A | N/A | Discovery | https://github.com/canix1/ADACLScanner | 1 | 0 | N/A | AD Enumeration | 7 | 10 | 1015 | 173 | 2025-04-11T14:35:08Z | 2017-04-06T12:28:37Z | 20105 |
| 1068 | *_adAclOutput*.csv* | .{0,1000}_adAclOutput.{0,1000}\.csv.{0,1000} | offensive_tool_keyword | ADACLScanner | A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory . | T1222 - T1069 - T1018 | TA0002 - TA0007 - TA0043 | N/A | N/A | Discovery | https://github.com/canix1/ADACLScanner | 1 | 0 | N/A | AD Enumeration | 7 | 10 | 1015 | 173 | 2025-04-11T14:35:08Z | 2017-04-06T12:28:37Z | 20106 |
| 1069 | *_adAclOutput*.csv* | .{0,1000}_adAclOutput.{0,1000}\.csv.{0,1000} | offensive_tool_keyword | ADACLScanner | A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory . | T1222 - T1069 - T1018 | TA0002 - TA0007 - TA0043 | N/A | N/A | Discovery | https://github.com/canix1/ADACLScanner | 1 | 0 | N/A | AD Enumeration | 7 | 10 | 1015 | 173 | 2025-04-11T14:35:08Z | 2017-04-06T12:28:37Z | 20107 |
| 1070 | *_adAclOutput*.xlsx* | .{0,1000}_adAclOutput.{0,1000}\.xlsx.{0,1000} | offensive_tool_keyword | ADACLScanner | A tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory . | T1222 - T1069 - T1018 | TA0002 - TA0007 - TA0043 | N/A | N/A | Discovery | https://github.com/canix1/ADACLScanner | 1 | 0 | N/A | AD Enumeration | 7 | 10 | 1015 | 173 | 2025-04-11T14:35:08Z | 2017-04-06T12:28:37Z | 20108 |
| 1071 | *_BloodHound.zip* | .{0,1000}_BloodHound\.zip.{0,1000} | offensive_tool_keyword | BloodHound | BloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environment | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound | 1 | 1 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 20111 |
| 1072 | *_REFLECTIVEDLLINJECTION_REFLECTIVEDLLINJECTION_H* | .{0,1000}_REFLECTIVEDLLINJECTION_REFLECTIVEDLLINJECTION_H.{0,1000} | offensive_tool_keyword | Recon-AD | AD recon tool based on ADSI and reflective DLL | T1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135 | TA0007 - TA0003 - TA0004 | N/A | N/A | Discovery | https://github.com/outflanknl/Recon-AD | 1 | 1 | N/A | N/A | 8 | 4 | 326 | 55 | 2019-10-20T21:49:39Z | 2019-10-20T21:09:41Z | 20167 |
| 1073 | *_SharpHound-v*.zip* | .{0,1000}_SharpHound\-v.{0,1000}\.zip.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 20170 |
| 1074 | *<Data Name="Product">Moriarty<* | .{0,1000}\<Data\sName\=\"Product\"\>Moriarty\<.{0,1000} | offensive_tool_keyword | Moriarty | Moriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments. | T1068 - T1083 | TA0004 - TA0007 | N/A | N/A | Discovery | https://github.com/BC-SECURITY/Moriarty | 1 | 0 | N/A | N/A | 7 | 6 | 510 | 67 | 2024-08-07T15:06:31Z | 2023-12-11T14:15:33Z | 20207 |
| 1075 | *<Data Name="RelativeTargetName">delete.me<* | .{0,1000}\<Data\sName\=\"RelativeTargetName\"\>delete\.me\<.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com.cach3.com/board/read.php%3F12,10134,12202.html | 1 | 0 | N/A | risk of false positive | 8 | 10 | N/A | N/A | N/A | N/A | 20208 |
| 1076 | *<Data Name='OriginalFileName'>AdExp<* | .{0,1000}\<Data\sName\=\'OriginalFileName\'\>AdExp\<.{0,1000} | greyware_tool_keyword | adexplorer | Active Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actors | T1003.001 - T1087.001 | TA0006 - TA0007 | N/A | Lapsus$ - Scattered Spider* - BlackBasta | Discovery | https://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer | 1 | 0 | N/A | greyware tool - risks of False positive ! | 7 | 10 | N/A | N/A | N/A | N/A | 20209 |
| 1077 | *>Active Directory Editor<* | .{0,1000}\>Active\sDirectory\sEditor\<.{0,1000} | greyware_tool_keyword | adexplorer | Active Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actors | T1003.001 - T1087.001 | TA0006 - TA0007 | N/A | Lapsus$ - Scattered Spider* - BlackBasta | Discovery | https://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer | 1 | 0 | #productname | greyware tool - risks of False positive ! | 7 | 10 | N/A | N/A | N/A | N/A | 20313 |
| 1078 | *>AdFind<* | .{0,1000}\>AdFind\<.{0,1000} | greyware_tool_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | #productname | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 20318 |
| 1079 | *>Advanced IP Scanner Setup<* | .{0,1000}\>Advanced\sIP\sScanner\sSetup\<.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 0 | #description | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 20325 |
| 1080 | *>Advanced IP Scanner<* | .{0,1000}\>Advanced\sIP\sScanner\<.{0,1000} | greyware_tool_keyword | advanced-ip-scanner | The program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA) | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | MAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - Loki | Discovery | https://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox | 1 | 0 | #productname | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 20326 |
| 1081 | *>Advanced Port Scanner Setup<* | .{0,1000}\>Advanced\sPort\sScanner\sSetup\<.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 0 | #description | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 20327 |
| 1082 | *>Advanced Port Scanner<* | .{0,1000}\>Advanced\sPort\sScanner\<.{0,1000} | greyware_tool_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 0 | #productname | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 20328 |
| 1083 | *>BrowsingHistoryView<* | .{0,1000}\>BrowsingHistoryView\<.{0,1000} | offensive_tool_keyword | BrowsingHistoryView | BrowsingHistoryView is a utility that reads the history data of different Web browsers | T1217 - T1070 - T1113 | TA0009 - TA0005 - TA0007 | N/A | GOBLIN PANDA | Discovery | https://www.nirsoft.net/utils/browsing_history_view.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 20353 |
| 1084 | *>Dionach.ShareAudit<* | .{0,1000}\>Dionach\.ShareAudit\<.{0,1000} | offensive_tool_keyword | ShareAudit | A tool for auditing network shares in an Active Directory environment | T1135 - T1005 - T1083 - T1210 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/dionach/ShareAudit | 1 | 0 | #productname | N/A | 8 | 1 | 42 | 15 | 2019-04-29T10:07:57Z | 2019-02-26T16:00:15Z | 20376 |
| 1085 | *>Group3r<* | .{0,1000}\>Group3r\<.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | #companyname | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 20407 |
| 1086 | *>Lansweeper Setup<* | .{0,1000}\>Lansweeper\sSetup\<.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 0 | #description | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 20430 |
| 1087 | *>Lansweeper<* | .{0,1000}\>Lansweeper\<.{0,1000} | greyware_tool_keyword | Lansweeper | Lansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackers | T1016 - T1082 | TA0007 | N/A | EvilCorp* | Discovery | https://www.lansweeper.com/ | 1 | 0 | #productname | N/A | 6 | 7 | N/A | N/A | N/A | N/A | 20431 |
| 1088 | *>MDE_Enum<* | .{0,1000}\>MDE_Enum\<.{0,1000} | offensive_tool_keyword | MDE_Enum | extract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rules | T1070.006 | TA0005 - TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/0xsp-SRD/MDE_Enum | 1 | 0 | N/A | N/A | 8 | 2 | 198 | 18 | 2024-06-10T18:40:27Z | 2024-06-06T15:54:44Z | 20438 |
| 1089 | *>NimScan<* | .{0,1000}\>NimScan\<.{0,1000} | greyware_tool_keyword | NimScan | Really fast port scanner (With filtered option - Windows support only) | T1046 | TA0007 | N/A | N/A | Discovery | https://github.com/elddy/NimScan | 1 | 0 | N/A | N/A | 8 | 4 | 391 | 38 | 2022-02-10T13:23:02Z | 2020-08-12T14:20:46Z | 20461 |
| 1090 | *>ShareAudit.exe<* | .{0,1000}\>ShareAudit\.exe\<.{0,1000} | offensive_tool_keyword | ShareAudit | A tool for auditing network shares in an Active Directory environment | T1135 - T1005 - T1083 - T1210 | TA0007 - TA0009 | N/A | N/A | Discovery | https://github.com/dionach/ShareAudit | 1 | 0 | #originalfilename | N/A | 8 | 1 | 42 | 15 | 2019-04-29T10:07:57Z | 2019-02-26T16:00:15Z | 20532 |
| 1091 | *>SharpAVKB<* | .{0,1000}\>SharpAVKB\<.{0,1000} | offensive_tool_keyword | SharpAVKB | Windows Antivirus Comparison and Patch Number Comparison | T1082 - T1518 - T1083 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpAVKB | 1 | 0 | #productname | N/A | 4 | 1 | 58 | 24 | 2019-10-28T06:50:30Z | 2019-10-14T12:44:22Z | 20534 |
| 1092 | *>SharpEventLog<* | .{0,1000}\>SharpEventLog\<.{0,1000} | offensive_tool_keyword | SharpEventLog | reads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetration | T1078 - T1087.001 | TA0007 | N/A | N/A | Discovery | https://github.com/uknowsec/SharpEventLog | 1 | 0 | #content | N/A | 4 | 3 | 205 | 34 | 2019-10-15T06:26:52Z | 2019-10-15T06:14:32Z | 20545 |
| 1093 | *>SharpGraphView<* | .{0,1000}\>SharpGraphView\<.{0,1000} | offensive_tool_keyword | SharpGraphView | Microsoft Graph API post-exploitation toolkit | T1078.004 - T1114.002 | TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010 | N/A | N/A | Discovery | https://github.com/mlcsec/SharpGraphView | 1 | 0 | #productname | N/A | 6 | 1 | 94 | 9 | 2024-07-13T12:27:38Z | 2024-05-04T11:23:42Z | 20550 |
| 1094 | *>SharpHound<* | .{0,1000}\>SharpHound\<.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | #productname | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 20552 |
| 1095 | *>SharpNBTScan<* | .{0,1000}\>SharpNBTScan\<.{0,1000} | offensive_tool_keyword | SharpNBTScan | a NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumeration | T1018 - T1046 | TA0007 | Ghost Ransomware | N/A | Discovery | https://github.com/BronzeTicket/SharpNBTScan | 1 | 0 | #productname | N/A | 7 | 1 | 71 | 4 | 2021-08-06T05:36:55Z | 2021-07-12T08:57:39Z | 20564 |
| 1096 | *>SharpShares<* | .{0,1000}\>SharpShares\<.{0,1000} | offensive_tool_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/mitchmoser/SharpShares | 1 | 0 | #productname | N/A | 10 | 4 | 351 | 49 | 2021-09-21T08:14:27Z | 2020-09-25T22:35:57Z | 20571 |
| 1097 | *>SharpView<* | .{0,1000}\>SharpView\<.{0,1000} | offensive_tool_keyword | SharpView | C# implementation of harmj0y's PowerView | T1018 - T1482 - T1087.002 - T1069.002 | TA0007 - TA0003 - TA0001 | N/A | Conti - APT29 | Discovery | https://github.com/tevora-threat/SharpView/ | 1 | 0 | #productname | N/A | 10 | 10 | 1032 | 196 | 2024-03-22T16:34:09Z | 2018-07-24T21:15:04Z | 20581 |
| 1098 | *>SoftPerfect Network Scanner<* | .{0,1000}\>SoftPerfect\sNetwork\sScanner\<.{0,1000} | greyware_tool_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | #productname | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 20592 |
| 1099 | *>Sysinternals ADExplorer<* | .{0,1000}\>Sysinternals\sADExplorer\<.{0,1000} | greyware_tool_keyword | adexplorer | Active Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actors | T1003.001 - T1087.001 | TA0006 - TA0007 | N/A | Lapsus$ - Scattered Spider* - BlackBasta | Discovery | https://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer | 1 | 0 | #productname | greyware tool - risks of False positive ! | 7 | 10 | N/A | N/A | N/A | N/A | 20594 |
| 1100 | *>Sysinternals PsList<* | .{0,1000}\>Sysinternals\sPsList\<.{0,1000} | greyware_tool_keyword | pslist | Microsoft sysinternal comandline tool to list running process abused by threat actors | T1057 - T1012 - T1106 | TA0007 | N/A | APT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - Elfin | Discovery | https://learn.microsoft.com/pt-br/sysinternals/downloads/pslist | 1 | 0 | #productname | N/A | 3 | 9 | N/A | N/A | N/A | N/A | 20595 |
| 1101 | *>Welcome to BloodHound?s documentation!<* | .{0,1000}\>Welcome\sto\sBloodHound?s\sdocumentation!\<.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | N/A | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 20617 |
| 1102 | *006ad795269259c08e5b8e1816e05a4bbb52c97997ff238180afbc53365d3428* | .{0,1000}006ad795269259c08e5b8e1816e05a4bbb52c97997ff238180afbc53365d3428.{0,1000} | offensive_tool_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | #filehash | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 20662 |
| 1103 | *006d97f8510e34966ebd1901686cf407a57663ad42374e40c023c6611595d1e3* | .{0,1000}006d97f8510e34966ebd1901686cf407a57663ad42374e40c023c6611595d1e3.{0,1000} | greyware_tool_keyword | AD_Miner | AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses | T1482 - T1069 - T1087 | TA0007 | N/A | EMBER BEAR | Discovery | https://github.com/Mazars-Tech/AD_Miner | 1 | 0 | #filehash | N/A | 6 | 10 | 1290 | 131 | 2025-03-12T10:53:09Z | 2023-09-26T12:36:59Z | 20664 |
| 1104 | *00d223d61d1569d44bfe81805359f94c15c9549473762016605287c31733bae6* | .{0,1000}00d223d61d1569d44bfe81805359f94c15c9549473762016605287c31733bae6.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | #filehash | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 20694 |
| 1105 | *00e3b8a6e650a206a6070be87c2c1d5387c21f9f6b80d18ee683c2c0f5fd2fe5* | .{0,1000}00e3b8a6e650a206a6070be87c2c1d5387c21f9f6b80d18ee683c2c0f5fd2fe5.{0,1000} | greyware_tool_keyword | ipscan | Angry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actors | T1046 - T1040 - T1018 | TA0007 - TA0009 | N/A | Phobos - BERSERK BEAR | Discovery | https://github.com/angryip/ipscan | 1 | 0 | #filehash | N/A | 7 | 10 | 4401 | 744 | 2024-11-23T19:03:47Z | 2011-06-28T20:58:48Z | 20698 |
| 1106 | *014b459f4eff259806b56b536fd24475d1824a82213f2b4e174f7650c1cd81db* | .{0,1000}014b459f4eff259806b56b536fd24475d1824a82213f2b4e174f7650c1cd81db.{0,1000} | offensive_tool_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | #filehash | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 20717 |
| 1107 | *018bdc303d4d1d7ef36e50f7967e3adfc9e613dd51cda3865af30893bfcf5ea5* | .{0,1000}018bdc303d4d1d7ef36e50f7967e3adfc9e613dd51cda3865af30893bfcf5ea5.{0,1000} | offensive_tool_keyword | BloodHound | Use Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical. | T1482 - T1087 - T1069 - T1018 | TA0007 - TA0008 - TA0004 | N/A | APT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - Dispossessor | Discovery | https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors | 1 | 0 | #filehash | N/A | 10 | 10 | 10146 | 1759 | 2025-04-02T15:56:30Z | 2016-04-17T18:36:14Z | 20741 |
| The file is too large to be shown. View Raw |