Files
mthcht-ThreatHunting-Keywords/Discovery_category_detection.csv
mthcht 755048bf5e Mars and April 2025 update
very few additions and some corrections
2025-04-24 05:55:50 +02:00

1.8 MiB

1keywordmetadata_keyword_regexmetadata_keyword_typemetadata_toolmetadata_descriptionmetadata_tool_techniquesmetadata_tool_tacticsmetadata_malwares_namemetadata_groups_namemetadata_categorymetadata_linkmetadata_enable_endpoint_detectionmetadata_enable_proxy_detectionmetadata_tagsmetadata_commentmetadata_severity_scoremetadata_popularity_scoremetadata_github_starsmetadata_github_forksmetadata_github_updated_atmetadata_github_created_atmetadata_entry_id
2* - Sensitive Accounts.csv*.{0,1000}\s\-\sSensitive\sAccounts\.csv.{0,1000}offensive_tool_keywordACLightA tool for advanced discovery of Privileged Accounts - including Shadow Admins.T1087 - T1003 - T1208TA0001 - TA0006 - TA0008N/AN/ADiscoveryhttps://github.com/cyberark/ACLight10N/AAD Enumeration798011462019-09-09T06:48:45Z2017-05-17T09:29:41Z12
3* - ShadowSpray*.{0,1000}\s\-\sShadowSpray.{0,1000}offensive_tool_keywordShadowSprayA tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.T1110.003 - T1098 - T1059 - T1075TA0001 - TA0008 - TA0009N/ABlack BastaDiscoveryhttps://github.com/ShorSec/ShadowSpray10N/AN/A75459802022-10-14T13:36:51Z2022-10-10T08:34:07Z13
4* /c sc query WinDefend*.{0,1000}\s\/c\ssc\squery\sWinDefend.{0,1000}greyware_tool_keywordscGet information about Windows Defender serviceT1518.001 - T1049TA0007 - TA0009N/ASnatchDiscoveryhttps://thedfirreport.com/2023/02/06/collect-exfiltrate-sleep-repeat/10N/AN/A810N/AN/AN/AN/A44
5* /config:netscan.xml *.{0,1000}\s\/config\:netscan\.xml\s.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A51
6* --> GetWindowsAnti-VirusSoftware*.{0,1000}\s\-\-\>\sGetWindowsAnti\-VirusSoftware.{0,1000}offensive_tool_keywordSharpAVKBWindows Antivirus Comparison and Patch Number ComparisonT1082 - T1518 - T1083TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpAVKB10#contentN/A4158242019-10-28T06:50:30Z2019-10-14T12:44:22Z147
7* --> GetWindowsKernelExploitsKB*.{0,1000}\s\-\-\>\sGetWindowsKernelExploitsKB.{0,1000}offensive_tool_keywordSharpAVKBWindows Antivirus Comparison and Patch Number ComparisonT1082 - T1518 - T1083TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpAVKB10#contentN/A4158242019-10-28T06:50:30Z2019-10-14T12:44:22Z148
8* aad3b435b51404eeaad3b435b51404ee*.{0,1000}\saad3b435b51404eeaad3b435b51404ee.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z176
9* ADAudit.ps1*.{0,1000}\sADAudit\.ps1.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z200
10* adaudit.ps1*.{0,1000}\sadaudit\.ps1.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z201
11* ADcheck.py*.{0,1000}\sADcheck\.py.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck10N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z202
12* ADCollector.exe*.{0,1000}\sADCollector\.exe.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector10N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z203
13* --adcs --filter * --ntaccount * --enroll *.{0,1000}\s\-\-adcs\s\-\-filter\s.{0,1000}\s\-\-ntaccount\s.{0,1000}\s\-\-enroll\s.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z204
14* --adcs --old-bloodhound *.{0,1000}\s\-\-adcs\s\-\-old\-bloodhound\s.{0,1000}offensive_tool_keywordRustHoundActive Directory data collector for BloodHound written in RustT1087.002 - T1018 - T1059.003TA0007 - TA0001 - TA0002N/AN/ADiscoveryhttps://github.com/OPENCYBER-FR/RustHound10N/AAD Enumeration9101013982024-10-21T18:58:20Z2022-10-12T05:54:35Z205
15* ADeleg.exe*.{0,1000}\sADeleg\.exe.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z224
16* adhunt.py *.{0,1000}\sadhunt\.py\s.{0,1000}offensive_tool_keywordadhuntTool for exploiting Active Directory Enviroments - enumerationT1018 - T1087 - T1087.002 - T1069 - T1069.002TA0007 - TA0003 - TA0001N/AN/ADiscoveryhttps://github.com/karendm/ADHunt10N/AAD Enumeration7146102023-08-10T18:55:39Z2023-06-20T13:24:10Z229
17* adPEAS.ps1*.{0,1000}\sadPEAS\.ps1.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z235
18* adPEAS_DomainPolicy.Sys*.{0,1000}\sadPEAS_DomainPolicy\.Sys.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z236
19* adPEAS_out.txt*.{0,1000}\sadPEAS_out\.txt.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z237
20* adPEAS-Light.ps1*.{0,1000}\sadPEAS\-Light\.ps1.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z238
21* ADRecon.ps1*.{0,1000}\sADRecon\.ps1.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z239
22* --asrep --domain * --user * --pass *.{0,1000}\s\-\-asrep\s\-\-domain\s.{0,1000}\s\-\-user\s.{0,1000}\s\-\-pass\s.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z291
23* --asreproast *.{0,1000}\s\-\-asreproast\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z293
24* --authmode ntlm --username * --password *.{0,1000}\s\-\-authmode\sntlm\s\-\-username\s.{0,1000}\s\-\-password\s.{0,1000}offensive_tool_keywordadalancheActive Directory ACL Visualizer and Explorer - who's really Domain Admin?T1484 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/lkarlslund/Adalanche10N/AAD Enumeration101019081842025-03-25T13:01:45Z2020-10-07T10:07:22Z336
25* AutoSUID.sh*.{0,1000}\sAutoSUID\.sh.{0,1000}offensive_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10N/AN/A74375772024-04-29T12:30:35Z2021-11-28T19:44:18Z344
26* AzureHound.ps1*.{0,1000}\sAzureHound\.ps1.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z348
27* backdoored-script.ps1*.{0,1000}\sbackdoored\-script\.ps1.{0,1000}offensive_tool_keywordGraphpythonModular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/Graphpython10N/AN/A72145132024-12-07T21:54:00Z2024-07-10T00:04:48Z356
28* --bhdump *.{0,1000}\s\-\-bhdump\s.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z388
29* bhqc.py -*.{0,1000}\sbhqc\.py\s\-.{0,1000}offensive_tool_keywordbloodhound-quickwinSimple script to extract useful informations from the combo BloodHound + Neo4jT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/kaluche/bloodhound-quickwin10N/AAD Enumeration63239262025-04-04T05:11:46Z2021-02-16T16:04:16Z389
30* --bloodhound-file *.{0,1000}\s\-\-bloodhound\-file\s.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck10N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z415
31* bofhound.py*.{0,1000}\sbofhound\.py.{0,1000}offensive_tool_keywordShadowHoundset of PowerShell scripts for Active Directory enumerationT1087 - T1018 - T1482 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Friends-Security/ShadowHound10N/AN/A84345362024-12-01T08:06:02Z2024-11-21T15:01:14Z421
32* Brc4LdapSentinelParser*.{0,1000}\sBrc4LdapSentinelParser.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound10N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z427
33* --brute-ratel*.{0,1000}\s\-\-brute\-ratel.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound10N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z470
34* -c all -d * --domaincontroller *.{0,1000}\s\-c\sall\s\-d\s.{0,1000}\s\-\-domaincontroller\s.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z499
35* -c DCOnly -d * -u * -p * -o /tmp*.{0,1000}\s\-c\sDCOnly\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-o\s\/tmp.{0,1000}offensive_tool_keywordRustHoundActive Directory data collector for BloodHound written in RustT1087.002 - T1018 - T1059.003TA0007 - TA0001 - TA0002N/AN/ADiscoveryhttps://github.com/OPENCYBER-FR/RustHound10N/AAD Enumeration9101013982024-10-21T18:58:20Z2022-10-12T05:54:35Z503
36* can now impersonate users on * via S4U2Proxy*.{0,1000}\scan\snow\simpersonate\susers\son\s.{0,1000}\svia\sS4U2Proxy.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z542
37* --certdump *.{0,1000}\s\-\-certdump\s.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z555
38* CheckSMBSigning.ps1*.{0,1000}\sCheckSMBSigning\.ps1.{0,1000}offensive_tool_keywordCheckSMBSigningChecks for SMB signing disabled on all hosts in the networkT1018 - T1550TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Leo4j/CheckSMBSigning10N/AN/A61812023-10-13T11:55:33Z2023-05-17T11:47:52Z564
39* CMLoot.ps1*.{0,1000}\sCMLoot\.ps1.{0,1000}offensive_tool_keywordCMLootFind interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB sharesT1083 - T1039TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/1njected/CMLoot10N/AN/A82175222023-02-05T00:24:31Z2022-06-02T10:59:21Z618
40* coerce * --dc-ip *.{0,1000}\scoerce\s.{0,1000}\s\-\-dc\-ip\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z626
41* collect activedirectory --*.{0,1000}\scollect\sactivedirectory\s\-\-.{0,1000}offensive_tool_keywordadalancheActive Directory ACL Visualizer and Explorer - who's really Domain Admin?T1484 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/lkarlslund/Adalanche10N/AAD Enumeration101019081842025-03-25T13:01:45Z2020-10-07T10:07:22Z635
42* --collectallproperties*.{0,1000}\s\-\-collectallproperties.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z636
43* --CollectionMethod All *ldap*.{0,1000}\s\-\-CollectionMethod\sAll\s.{0,1000}ldap.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z637
44* --CollectionMethod All *--ZipFileName *.zip*.{0,1000}\s\-\-CollectionMethod\sAll\s.{0,1000}\-\-ZipFileName\s.{0,1000}\.zip.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z638
45* -CollectionMethod All*loggedon*.{0,1000}\s\-CollectionMethod\sAll.{0,1000}loggedon.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1552 - T1027 - T1059 - T1087TA0003 - TA0002 - TA0007N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z639
46* -CollectionMethod LoggedOn -Verbose*.{0,1000}\s\-CollectionMethod\sLoggedOn\s\-Verbose.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z640
47* --collectionmethods ACL*.{0,1000}\s\-\-collectionmethods\sACL.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z642
48* --collectionmethods ComputerOnly*.{0,1000}\s\-\-collectionmethods\sComputerOnly.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z643
49* --collectionmethods Container*.{0,1000}\s\-\-collectionmethods\sContainer.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z644
50* --collectionmethods DCOM.{0,1000}\s\-\-collectionmethods\sDCOMoffensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z645
51* --collectionmethods DCOnly*.{0,1000}\s\-\-collectionmethods\sDCOnly.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z646
52* --collectionmethods GPOLocalGroup*.{0,1000}\s\-\-collectionmethods\sGPOLocalGroup.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z647
53* --collectionmethods Group*.{0,1000}\s\-\-collectionmethods\sGroup.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z648
54* --collectionmethods LocalGroup*.{0,1000}\s\-\-collectionmethods\sLocalGroup.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z649
55* --collectionmethods LoggedOn*.{0,1000}\s\-\-collectionmethods\sLoggedOn.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z650
56* --collectionmethods ObjectProps*.{0,1000}\s\-\-collectionmethods\sObjectProps.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z651
57* --collectionmethods PSRemote*.{0,1000}\s\-\-collectionmethods\sPSRemote.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z652
58* --collectionmethods RDP*.{0,1000}\s\-\-collectionmethods\sRDP.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z653
59* --collectionmethods Session*.{0,1000}\s\-\-collectionmethods\sSession.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z654
60* --collectionmethods Trusts*.{0,1000}\s\-\-collectionmethods\sTrusts.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z655
61* COMHijackToolkit.ps1*.{0,1000}\sCOMHijackToolkit\.ps1.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z659
62* CRITICAL] Suspicous file: \\*.{0,1000}\sCRITICAL\]\sSuspicous\sfile\:\s\\\\.{0,1000}offensive_tool_keywordsmbscanSMBScan is a tool to enumerate file shares on an internal network.T1135 - T1046 - T1021TA0007 - TA0043 - TA0008N/AAPT22Discoveryhttps://github.com/jeffhacks/smbscan10N/AN/A814462025-03-24T01:55:30Z2021-10-26T02:28:34Z738
63* -d * -u *\* -p * --da*.{0,1000}\s\-d\s.{0,1000}\s\-u\s.{0,1000}\\.{0,1000}\s\-p\s.{0,1000}\s\-\-da.{0,1000}offensive_tool_keywordwindapsearchPython script to enumerate users - groups and computers from a Windows domain through LDAP queriesT1087.002 - T1018 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/ropnop/windapsearch10N/AAD Enumeration798661542022-04-20T07:40:42Z2016-08-10T21:43:30Z770
64* --dc * -m custom --filter *objectCategory*.{0,1000}\s\-\-dc\s.{0,1000}\s\-m\scustom\s\-\-filter\s.{0,1000}objectCategory.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z786
65* -dc-ip * -dump *.{0,1000}\s\-dc\-ip\s.{0,1000}\s\-dump\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z789
66* --dc-ip * --vuln --enabled*.{0,1000}\s\-\-dc\-ip\s.{0,1000}\s\-\-vuln\s\-\-enabled.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z794
67* -dc-ip *SAMDump*.{0,1000}\s\-dc\-ip\s.{0,1000}SAMDump.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z795
68* dclist *.{0,1000}\sdclist\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/10N/AN/A1010N/AN/AN/AN/A796
69* dir /s */ Microsoft.ActiveDirectory.Management.dll*.{0,1000}\sdir\s\/s\s.{0,1000}\/\sMicrosoft\.ActiveDirectory\.Management\.dll.{0,1000}greyware_tool_keyworddirthreat actors searched for Active Directory related DLLs in directoriesT1059 - T1083 - T1018TA0002 - TA0009 - TA0040N/AN/ADiscoveryhttps://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/10N/AN/AN/AN/AN/AN/AN/AN/A844
70* --dirnames bank financ payable payment reconcil remit voucher vendor eft swift *.{0,1000}\s\-\-dirnames\sbank\sfinanc\spayable\spayment\sreconcil\sremit\svoucher\svendor\seft\sswift\s.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10N/AN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z848
71* DLLHound.ps1*.{0,1000}\sDLLHound\.ps1.{0,1000}offensive_tool_keywordDLLHoundFind potential DLL Sideloads on your windows computerT1574.001 - T1574.002TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/ajm4n/DLLHound10N/AN/A73201222025-01-12T02:28:22Z2024-12-20T02:26:16Z869
72* --dnsdump *.{0,1000}\s\-\-dnsdump\s.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z887
73* dnsdump.py*.{0,1000}\sdnsdump\.py.{0,1000}offensive_tool_keywordadidnsdumpBy default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks.T1018 - T1087 - T1201 - T1056 - T1039TA0005 - TA0009N/AN/ADiscoveryhttps://github.com/dirkjanm/adidnsdump10N/AN/AN/A109971182025-04-04T09:28:20Z2019-04-24T17:18:46Z888
74* --doLocalAdminSessionEnum*.{0,1000}\s\-\-doLocalAdminSessionEnum.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z908
75* domainDumper*.{0,1000}\sdomainDumper.{0,1000}offensive_tool_keywordldapdomaindumpActive Directory information dumper via LDAPT1087 - T1005 - T1016TA0007N/AEMBER BEARDiscoveryhttps://github.com/dirkjanm/ldapdomaindump10N/AN/A101012422012025-04-06T13:31:57Z2016-05-24T18:46:56Z911
76* --dont-enumerate-acls *.{0,1000}\s\-\-dont\-enumerate\-acls\s.{0,1000}offensive_tool_keywordSMBeagleSMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.T1087.002 - T1021.002 - T1210TA0007 - TA0008 - TA0003N/AN/ADiscoveryhttps://github.com/punk-security/SMBeagle10N/AN/A98712802025-01-21T22:34:00Z2021-05-31T19:46:57Z925
77* --dont-enumerate-acls * -e *.{0,1000}\s\-\-dont\-enumerate\-acls\s.{0,1000}\s\-e\s.{0,1000}offensive_tool_keywordSMBeagleSMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.T1087.002 - T1021.002 - T1210TA0007 - TA0008 - TA0003N/AN/ADiscoveryhttps://github.com/punk-security/SMBeagle10N/AN/A98712802025-01-21T22:34:00Z2021-05-31T19:46:57Z926
78* DSInternals.psd1*.{0,1000}\sDSInternals\.psd1.{0,1000}offensive_tool_keywordDSInternalsDirectory Services Internals (DSInternals) PowerShell Module and Framework - abused by attackersT1003 - T1087 - T1018 - T1110 - T1558TA0003 - TA0006 - TA0007N/ACOZY BEARDiscoveryhttps://github.com/MichaelGrafnetter/DSInternals10N/AAD Enumeration101017602652025-04-16T18:12:55Z2015-12-25T13:23:05Z968
79* -e bat com vbs ps1 psd1 psm1 pem key rsa pub reg txt cfg conf config *.{0,1000}\s\-e\sbat\scom\svbs\sps1\spsd1\spsm1\spem\skey\srsa\spub\sreg\stxt\scfg\sconf\sconfig\s.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10N/AN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z1008
80* -e pfx p12 pkcs12 pem key crt cer csr jks keystore key keys der *.{0,1000}\s\-e\spfx\sp12\spkcs12\spem\skey\scrt\scer\scsr\sjks\skeystore\skey\skeys\sder\s.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10N/AN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z1009
81* -e ppk rsa pem ssh rsa*.{0,1000}\s\-e\sppk\srsa\spem\sssh\srsa.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10N/AN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z1010
82* ecrprivenum.py*.{0,1000}\secrprivenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z1020
83* ecrpubenum.py*.{0,1000}\secrpubenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z1021
84* --excludedcs*.{0,1000}\s\-\-excludedcs.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z1096
85* -exec bypass -nop -c whoami*.{0,1000}\s\-exec\sbypass\s\-nop\s\-c\swhoami.{0,1000}greyware_tool_keywordwhoamiwhoami is a legitimate command used to identify the current user executing the command in a terminal or command prompt.whoami can be used to gather information about the current user's privileges. credentials. and account name. which can then be used for Lateral Movement. privilege escalation. or targeted attacks within the compromised network.T1003.001 - T1087 - T1057 TA0007N/ABlack BastaDiscoveryN/A10N/AN/A910N/AN/AN/AN/A1101
86* -f "(objectcategory=computer)" -s subtree dn operatingSystem*.{0,1000}\s\-f\s\"\(objectcategory\=computer\)\"\s\-s\ssubtree\sdn\soperatingSystem.{0,1000}greyware_tool_keywordadfindEnumerate All Computers in the DomainT1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior10N/AN/A1010N/AN/AN/AN/A1143
87* -f "(objectcategory=person)" -s subtree samaccountname userPrincipalName*.{0,1000}\s\-f\s\"\(objectcategory\=person\)\"\s\-s\ssubtree\ssamaccountname\suserPrincipalName.{0,1000}greyware_tool_keywordadfindEnumerate All Users in the DomainT1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior10N/AN/A1010N/AN/AN/AN/A1144
88* -f "(objectcategory=trustedDomain)" -s subtree name trustAttributes trustDirection trustType*.{0,1000}\s\-f\s\"\(objectcategory\=trustedDomain\)\"\s\-s\ssubtree\sname\strustAttributes\strustDirection\strustType.{0,1000}greyware_tool_keywordadfindDump All Domain TrustsT1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior10N/AN/A1010N/AN/AN/AN/A1145
89* -f passw -e xlsx csv *.{0,1000}\s\-f\spassw\s\-e\sxlsx\scsv\s.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10N/AN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z1173
90* -f passw user admin account network login logon cred *.{0,1000}\s\-f\spassw\suser\sadmin\saccount\snetwork\slogin\slogon\scred\s.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10N/AN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z1174
91* -fake-hostname *.{0,1000}\s\-fake\-hostname\s.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z1186
92* --force-kerb *.{0,1000}\s\-\-force\-kerb\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z1210
93* --format=krb5asrep* --wordlist=*.{0,1000}\s\-\-format\=krb5asrep.{0,1000}\s\-\-wordlist\=.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z1227
94* FROM LDAPHUNTERFINDINGS*.{0,1000}\sFROM\sLDAPHUNTERFINDINGS.{0,1000}offensive_tool_keywordLDAP-Password-HunterPassword Hunter in Active DirectoryT1087.002TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/LDAP-Password-Hunter10N/AN/A72198252023-01-06T15:32:34Z2021-07-26T14:27:01Z1240
95* -g -n --kerberoast*.{0,1000}\s\-g\s\-n\s\-\-kerberoast.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z1279
96* Get-ADReplAccount -SamAccountName 'AZUREADSSOACC$' *.{0,1000}\sGet\-ADReplAccount\s\-SamAccountName\s\'AZUREADSSOACC\$\'\s.{0,1000}offensive_tool_keywordDSInternalsDirectory Services Internals (DSInternals) PowerShell Module and Framework - abused by attackersT1003 - T1087 - T1018 - T1110 - T1558TA0003 - TA0006 - TA0007N/ACOZY BEARDiscoveryhttps://github.com/MichaelGrafnetter/DSInternals10N/AAD Enumeration101017602652025-04-16T18:12:55Z2015-12-25T13:23:05Z1313
97* Get-DomainController | select Name,OSversion,IPAddress |fl*.{0,1000}\sGet\-DomainController\s\|\sselect\sName,OSversion,IPAddress\s\|fl.{0,1000}offensive_tool_keywordpowerviewPowerView is a PowerShell tool to gain network situational awareness on Windows domainsT1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/ADispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDADiscoveryhttps://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps110N/AN/A10101227446602020-08-17T23:19:49Z2012-05-26T16:08:48Z1317
98* Get-DomainGPO -Identity "{AB306569-220D-43FF-B03B-83E8F4EF8081}"*.{0,1000}\sGet\-DomainGPO\s\-Identity\s\"\{AB306569\-220D\-43FF\-B03B\-83E8F4EF8081\}\".{0,1000}offensive_tool_keywordpowerviewPowerView is a PowerShell tool to gain network situational awareness on Windows domainsT1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/ADispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDADiscoveryhttps://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps110N/AN/A10101227446602020-08-17T23:19:49Z2012-05-26T16:08:48Z1318
99* Get-SMBSigning.ps1*.{0,1000}\sGet\-SMBSigning\.ps1.{0,1000}offensive_tool_keywordCheckSMBSigningChecks for SMB signing disabled on all hosts in the networkT1018 - T1550TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Leo4j/CheckSMBSigning10N/AN/A61812023-10-13T11:55:33Z2023-05-17T11:47:52Z1331
100* GPOBrowser.py*.{0,1000}\sGPOBrowser\.py.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck10N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z1370
101* Graphpython.py*.{0,1000}\sGraphpython\.py.{0,1000}offensive_tool_keywordGraphpythonModular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/Graphpython10N/AN/A72145132024-12-07T21:54:00Z2024-07-10T00:04:48Z1378
102* -H * -u * -p * -r *C$/Users*.{0,1000}\s\-H\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-r\s.{0,1000}C\$\/Users.{0,1000}offensive_tool_keywordsmbmapSMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks.T1210.001 - T1083 - T1213 - T1021TA0007 - TA0003 - TA0002 - TA0001N/AMuddyWater - DispossessorDiscoveryhttps://github.com/ShawnDEvans/smbmap10N/AN/A101018903592025-02-28T18:09:10Z2015-03-16T13:15:00Z1397
103* HijackDLL-Threads.dll*.{0,1000}\sHijackDLL\-Threads\.dll.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z1423
104* --host-file *.txt -u * --prompt --admin --no-banner*.{0,1000}\s\-\-host\-file\s.{0,1000}\.txt\s\-u\s.{0,1000}\s\-\-prompt\s\-\-admin\s\-\-no\-banner.{0,1000}offensive_tool_keywordsmbmapSMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks.T1210.001 - T1083 - T1213 - T1021TA0007 - TA0003 - TA0002 - TA0001N/AMuddyWater - DispossessorDiscoveryhttps://github.com/ShawnDEvans/smbmap10N/AN/A101018903592025-02-28T18:09:10Z2015-03-16T13:15:00Z1436
105* iamassumeroleenum.py*.{0,1000}\siamassumeroleenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z1602
106* --impersonate Administrator -shell *.{0,1000}\s\-\-impersonate\sAdministrator\s\-shell\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z1635
107* --input 10m_usernames.txt*.{0,1000}\s\-\-input\s10m_usernames\.txt.{0,1000}offensive_tool_keywordldapnomnomAnonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)T1110.003 - T1205TA0007N/AN/ADiscoveryhttps://github.com/lkarlslund/ldapnomnom10N/AN/A6101030802024-11-09T10:15:13Z2022-09-18T10:35:09Z1665
108* -InputPath .\TrustedForests.txt*.{0,1000}\s\-InputPath\s\.\\TrustedForests\.txt.{0,1000}offensive_tool_keywordLocksmithA tiny tool to identify and remediate common misconfigurations in Active Directory Certificate ServicesT1552.006 - T1222 - T1046TA0007 - TA0040 - TA0043N/AN/ADiscoveryhttps://github.com/TrimarcJake/Locksmith10N/AN/A81010861002025-04-21T12:43:50Z2022-04-28T01:37:32Z1667
109* INTO LDAPHUNTERFINDINGS*.{0,1000}\sINTO\sLDAPHUNTERFINDINGS.{0,1000}offensive_tool_keywordLDAP-Password-HunterPassword Hunter in Active DirectoryT1087.002TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/LDAP-Password-Hunter10N/AN/A72198252023-01-06T15:32:34Z2021-07-26T14:27:01Z1725
110* Invoke-CertToAccessToken -tenant *.{0,1000}\sInvoke\-CertToAccessToken\s\-tenant\s.{0,1000}offensive_tool_keywordSharpGraphViewMicrosoft Graph API post-exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/SharpGraphView10N/AN/A619492024-07-13T12:27:38Z2024-05-04T11:23:42Z1738
111* Invoke-DCOM.ps1*.{0,1000}\sInvoke\-DCOM\.ps1.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z1739
112* Invoke-ShareFinder -CheckShareAccess*.{0,1000}\sInvoke\-ShareFinder\s\-CheckShareAccess.{0,1000}offensive_tool_keywordpowerviewPowerView is a PowerShell tool to gain network situational awareness on Windows domainsT1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/ADispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDADiscoveryhttps://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps110N/AN/A10101227446602020-08-17T23:19:49Z2012-05-26T16:08:48Z1751
113* -ip * -smb2support *lwpshare* .{0,1000}\s\-ip\s.{0,1000}\s\-smb2support\s.{0,1000}lwpshare.{0,1000}\soffensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z1758
114* -it bloodhound*.{0,1000}\s\-it\sbloodhound.{0,1000}offensive_tool_keywordBloodHoundA Python based ingestor for BloodHoundT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/fox-it/BloodHound.py10N/AN/A101020883432025-03-28T11:19:13Z2018-02-26T14:44:20Z1790
115* -jar ipscan.exe*.{0,1000}\s\-jar\sipscan\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/Anetwork exploitation tool71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z1798
116* jecretz.py*.{0,1000}\sjecretz\.py.{0,1000}offensive_tool_keywordjecretzJira Secret Hunter - Helps you find credentials and sensitive contents in Jira ticketsT1552 - T1114 - T1119 - T1070TA0006 - TA0009 - TA0005N/AScattered Spider*Discoveryhttps://github.com/sahadnk72/jecretz10N/AN/A714392022-12-08T10:00:11Z2020-05-25T14:40:28Z1804
117* -k --kerberoast*.{0,1000}\s\-k\s\-\-kerberoast.{0,1000}offensive_tool_keywordSilentHoundQuietly enumerate an Active Directory Domain via LDAP parsing users + admins + groups...T1087.002 - T1018 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/layer8secure/SilentHound10N/AAD Enumeration75489472023-01-23T20:41:55Z2022-07-01T13:49:24Z1840
118* Kerberoastable -action list*.{0,1000}\sKerberoastable\s\-action\slist.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z1858
119* Kerberoastable -action write -target *.{0,1000}\sKerberoastable\s\-action\swrite\s\-target\s.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z1859
120* Killchain.ps1*.{0,1000}\sKillchain\.ps1.{0,1000}offensive_tool_keywordGraphpythonModular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/Graphpython10N/AN/A72145132024-12-07T21:54:00Z2024-07-10T00:04:48Z1883
121* lambdaenum.py*.{0,1000}\slambdaenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z1923
122* ldap * --gmsa *dump*.{0,1000}\sldap\s.{0,1000}\s\-\-gmsa\s.{0,1000}dump.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z1932
123* --ldap servicePrincipalName=* --domain * --user * --pass *.{0,1000}\s\-\-ldap\sservicePrincipalName\=.{0,1000}\s\-\-domain\s.{0,1000}\s\-\-user\s.{0,1000}\s\-\-pass\s.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z1936
124* ldapper.py*.{0,1000}\sldapper\.py.{0,1000}offensive_tool_keywordLDAPPERLDAP Querying without the SuckT1087 - T1069 - T1018TA0007N/AN/ADiscoveryhttps://github.com/shellster/LDAPPER10N/AN/A7199112024-11-09T03:53:26Z2020-06-17T16:53:35Z1939
125* ldapph.db*.{0,1000}\sldapph\.db.{0,1000}offensive_tool_keywordLDAP-Password-HunterPassword Hunter in Active DirectoryT1087.002TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/LDAP-Password-Hunter10N/AN/A72198252023-01-06T15:32:34Z2021-07-26T14:27:01Z1940
126* --ldapusername * --ldappassword *.{0,1000}\s\-\-ldapusername\s\s.{0,1000}\s\-\-ldappassword\s.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z1944
127* linWinPwn*.{0,1000}\slinWinPwn.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z1958
128* loadbalancer.py*.{0,1000}\sloadbalancer\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z1999
129* --localadminsessionenum *.{0,1000}\s\-\-localadminsessionenum\s.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z2016
130* --LocalGMEnum --Host *.{0,1000}\s\s\-\-LocalGMEnum\s\-\-Host\s.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector10N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z2019
131* LocalShellExtParse.py*.{0,1000}\sLocalShellExtParse\.py.{0,1000}offensive_tool_keywordLocalShellExtParseScript to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User.T1547.009 - T1129TA0003 - TA0007N/AN/ADiscoveryhttps://github.com/herrcore/LocalShellExtParse10N/AN/A912042015-06-08T16:55:38Z2015-06-05T03:23:13Z2025
132* -M dfscoerce *.{0,1000}\s\-M\sdfscoerce\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2059
133* -M handlekatz *.{0,1000}\s\-M\shandlekatz\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2063
134* -M keepass_discover *.{0,1000}\s\-M\skeepass_discover\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2064
135* -M laps --kdcHost *.{0,1000}\s\-M\slaps\s\-\-kdcHost\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2068
136* -M ldap-checker *.{0,1000}\s\-M\sldap\-checker\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2069
137* -M lsassy *.{0,1000}\s\-M\slsassy\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2071
138* -M MAQ --kdcHost *.{0,1000}\s\-M\sMAQ\s\-\-kdcHost\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2072
139* -M masky *CA=*.{0,1000}\s\-M\smasky\s.{0,1000}CA\=.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2073
140* -M ms17-010 *.{0,1000}\s\-M\sms17\-010\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2074
141* -M mssql_priv *.{0,1000}\s\-M\smssql_priv\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2075
142* -M nanodump *.{0,1000}\s\-M\snanodump\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2077
143* -M petitpotam *.{0,1000}\s\-M\spetitpotam\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2080
144* -M printnightmare *.{0,1000}\s\-M\sprintnightmare\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2082
145* -m privileged-users --full *.{0,1000}\s\-m\sprivileged\-users\s\-\-full\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2083
146* -M procdump .{0,1000}\s\-M\sprocdump\soffensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2084
147* -M runasppl *.{0,1000}\s\-M\srunasppl\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2087
148* -M shadowcoerce *.{0,1000}\s\-M\sshadowcoerce\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2090
149* -M spider_plus *.{0,1000}\s\-M\sspider_plus\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2096
150* -M teams_localdb *.{0,1000}\s\-M\steams_localdb\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2099
151* -M zerologon *.{0,1000}\s\-M\szerologon\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2106
152* -Module Bloodhound -Method All*.{0,1000}\s\-Module\sBloodhound\s\-Method\sAll.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z2175
153* -Module Bloodhound -Scope All*.{0,1000}\s\-Module\sBloodhound\s\-Scope\sAll.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z2176
154* netscan.exe *.{0,1000}\snetscan\.exe\s.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A2301
155* netscan64.exe *.{0,1000}\snetscan64\.exe\s.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A2302
156* NimScan.exe*.{0,1000}\sNimScan\.exe.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan10N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z2317
157* NimScan.nim*.{0,1000}\sNimScan\.nim.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan10N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z2318
158* -no-pass -just-dc-user *.{0,1000}\s\-no\-pass\s\-just\-dc\-user\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2358
159* -no-preauth * -dc-ip *.{0,1000}\s\-no\-preauth\s.{0,1000}\s\-dc\-ip\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2364
160* ntlmrecon*.{0,1000}\sntlmrecon.{0,1000}offensive_tool_keywordNTMLReconA fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domainsT1595TA0009N/AN/ADiscoveryhttps://github.com/pwnfoo/NTLMRecon10N/AN/AN/A5481702024-06-24T18:11:12Z2019-12-01T06:06:30Z2402
161* nullinux.py*.{0,1000}\snullinux\.py.{0,1000}offensive_tool_keywordnullinuxInternal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB.T1087 - T1016 - T1077 - T1018TA0007 - TA0006N/AN/ADiscoveryhttps://github.com/m8sec/nullinux10#linuxN/A765751012024-06-19T14:29:09Z2016-04-28T16:45:02Z2411
162* --only-abuse --dc-host *.{0,1000}\s\-\-only\-abuse\s\-\-dc\-host\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2448
163* options.fake_hostname*.{0,1000}\soptions\.fake_hostname.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z2454
164* --output rootDSEs.json --dump*.{0,1000}\s\-\-output\srootDSEs\.json\s\-\-dump.{0,1000}offensive_tool_keywordldapnomnomAnonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)T1110.003 - T1205TA0007N/AN/ADiscoveryhttps://github.com/lkarlslund/ldapnomnom10N/AN/A6101030802024-11-09T10:15:13Z2022-09-18T10:35:09Z2470
165* -p 'aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0'*.{0,1000}\s\-p\s\'aad3b435b51404eeaad3b435b51404ee\:31d6cfe0d16ae931b73c59d7e0c089c0\'.{0,1000}offensive_tool_keywordad-ldap-enumAn LDAP based Active Directory user and group enumeration toolT1087 - T1087.001 - T1018 - T1069 - T1069.002TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/CroweCybersecurity/ad-ldap-enum10N/AAD Enumeration64308662023-02-10T19:07:34Z2015-08-25T19:38:39Z2485
166* --passnotreq --domain * --user * --pass *.{0,1000}\s\-\-passnotreq\s\-\-domain\s.{0,1000}\s\-\-user\s.{0,1000}\s\-\-pass\s.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z2524
167* --password-not-required --kdcHost *cme*.{0,1000}\s\-\-password\-not\-required\s\-\-kdcHost\s.{0,1000}cme.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2533
168* -pathToBloodHoundGraph * -pathToOutputGoFetchPath * -pathToAdditionalPayload *.{0,1000}\s\-pathToBloodHoundGraph\s.{0,1000}\s\-pathToOutputGoFetchPath\s.{0,1000}\s\s\-pathToAdditionalPayload\s.{0,1000}offensive_tool_keywordGoFetchGoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.T1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/ADispossessorDiscoveryhttps://github.com/GoFetchAD/GoFetch10N/AN/A107633992017-06-20T14:15:10Z2017-04-11T10:45:23Z2545
169* -PathToGraph *.json -PathToPayload *.exe*.{0,1000}\s\-PathToGraph\s.{0,1000}\.json\s\-PathToPayload\s.{0,1000}\.exe.{0,1000}offensive_tool_keywordGoFetchGoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.T1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/ADispossessorDiscoveryhttps://github.com/GoFetchAD/GoFetch10N/AN/A107633992017-06-20T14:15:10Z2017-04-11T10:45:23Z2547
170* -perm -4000 -o -perm -2000*.{0,1000}\s\-perm\s\-4000\s\-o\s\-perm\s\-2000.{0,1000}greyware_tool_keywordfindLook for files with the SGID (Set Group ID) bit setT1083 - T1069 - T1202TA0004 - TA0007N/AN/ADiscoveryN/A10#linuxN/A710N/AN/AN/AN/A2584
171* -pfx *.pfx -dc-ip *.{0,1000}\s\-pfx\s.{0,1000}\.pfx\s\-dc\-ip\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2598
172* polenum.py*.{0,1000}\spolenum\.py.{0,1000}offensive_tool_keywordpolenumUses Impacket Library to get the password policy from a windows machineT1012 - T1596TA0009 - TA0007N/AN/ADiscoveryhttps://salsa.debian.org/pkg-security-team/polenum10N/AN/A810N/AN/AN/AN/A2625
173* powerview.py*.{0,1000}\spowerview\.py.{0,1000}offensive_tool_keywordpowerviewPowerView.py is an alternative for the awesome original PowerView.ps1T1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/aniqfakhrul/powerview.py10N/AN/A107622662025-04-22T09:01:39Z2022-06-19T16:13:04Z2656
174* PSnmap.ps1*.{0,1000}\sPSnmap\.ps1.{0,1000}offensive_tool_keywordPsnmapPowershell scanner (nmap like)T1086 - T1046 - T1059TA0007N/ABlack BastaDiscoveryhttps://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps110N/AN/A72178642024-08-23T18:24:20Z2015-01-24T10:46:41Z2696
175* pwn_php.me*.{0,1000}\spwn_php\.me.{0,1000}offensive_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10N/AN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z2730
176* pwn_python.me*.{0,1000}\spwn_python\.me.{0,1000}offensive_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10N/AN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z2731
177* pwn_tclsh.me*.{0,1000}\spwn_tclsh\.me.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10N/AN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z2732
178* Rattler.exe*.{0,1000}\sRattler\.exe.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z2773
179* Rattler_32.exe*.{0,1000}\sRattler_32\.exe.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z2774
180* Rattler_x64.exe*.{0,1000}\sRattler_x64\.exe.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z2775
181* RBCD -action write -delegate-to * -delegate-from *.{0,1000}\sRBCD\s\-action\swrite\s\-delegate\-to\s.{0,1000}\s\-delegate\-from\s.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z2778
182* -Recommended -SprayEmptyPasswords*.{0,1000}\s\-Recommended\s\-SprayEmptyPasswords.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum10N/AN/A75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z2806
183* -request -dc-ip *.{0,1000}\s\-request\s\-dc\-ip\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2864
184* --rid-brute 2>&1 *.txt*.{0,1000}\s\-\-rid\-brute\s2\>\&1\s.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2901
185* rusthound.exe*.{0,1000}\srusthound\.exe.{0,1000}offensive_tool_keywordRustHoundActive Directory data collector for BloodHound written in RustT1087.002 - T1018 - T1059.003TA0007 - TA0001 - TA0002N/AN/ADiscoveryhttps://github.com/OPENCYBER-FR/RustHound10N/AAD Enumeration9101013982024-10-21T18:58:20Z2022-10-12T05:54:35Z2954
186* s3aclenum.py*.{0,1000}\ss3aclenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z2969
187* s3enum.py*.{0,1000}\ss3enum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z2970
188* -save-old -dc-ip *.{0,1000}\s\-save\-old\s\-dc\-ip\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2982
189* -sc getacls -sddlfilter *.{0,1000}\s\-sc\sgetacls\s\-sddlfilter\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryN/A10N/AN/A1010N/AN/AN/AN/A2984
190* -sc trustdump*.{0,1000}\s\-sc\strustdump.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/10N/AN/A1010N/AN/AN/AN/A2987
191* scan * --dc-ip *.{0,1000}\sscan\s.{0,1000}\s\-\-dc\-ip\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z2988
192* --scan-local-shares * -e *.{0,1000}\s\-\-scan\-local\-shares\s.{0,1000}\s\-e\s.{0,1000}offensive_tool_keywordSMBeagleSMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.T1087.002 - T1021.002 - T1210TA0007 - TA0008 - TA0003N/AN/ADiscoveryhttps://github.com/punk-security/SMBeagle10N/AN/A98712802025-01-21T22:34:00Z2021-05-31T19:46:57Z2992
193* -SCCMHost * -Outfile *.{0,1000}\s\-SCCMHost\s.{0,1000}\s\-Outfile\s.{0,1000}offensive_tool_keywordCMLootFind interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB sharesT1083 - T1039TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/1njected/CMLoot10N/AN/A82175222023-02-05T00:24:31Z2022-06-02T10:59:21Z3002
194* --script smb-vuln-ms08-067,smb-vuln-ms17-010*.{0,1000}\s\-\-script\ssmb\-vuln\-ms08\-067,smb\-vuln\-ms17\-010.{0,1000}greyware_tool_keywordnmapnmap vuln scan of most used vulnerabilitiesT1046 - T1203 - T1210TA0007N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A3011
195* SearchShares.ps1*.{0,1000}\sSearchShares\.ps1.{0,1000}offensive_tool_keywordSearchOpenFileSharesSearches open files shares for password files or database backups - Extend as you see fitT1083 - T1135 - T1005 - T1025TA0007 - TA0009N/ADispossessorDiscoveryhttps://github.com/fashionproof/SearchOpenFileShares10N/AN/A712962019-12-13T12:37:42Z2019-09-21T13:50:26Z3023
196* secretsmanagerenum.py*.{0,1000}\ssecretsmanagerenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z3033
197* --SessionEnum --Host *.{0,1000}\s\-\-SessionEnum\s\-\-Host\s.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector10N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z3055
198* SharpBuster.dll*.{0,1000}\sSharpBuster\.dll.{0,1000}offensive_tool_keywordSharpBusterThis is a C# implementation of a directory brute forcing tool designed to allow for in-memory executionT1087 - T1112 - T1048.003 - T1105TA0007 - TA0040 - TA0002N/AN/ADiscoveryhttps://github.com/passthehashbrowns/SharpBuster10N/AN/A716272020-09-02T15:46:03Z2020-08-31T00:33:02Z3078
199* SharpBuster.exe*.{0,1000}\sSharpBuster\.exe.{0,1000}offensive_tool_keywordSharpBusterThis is a C# implementation of a directory brute forcing tool designed to allow for in-memory executionT1087 - T1112 - T1048.003 - T1105TA0007 - TA0040 - TA0002N/AN/ADiscoveryhttps://github.com/passthehashbrowns/SharpBuster10N/AN/A716272020-09-02T15:46:03Z2020-08-31T00:33:02Z3079
200* SharpEDRChecker*.{0,1000}\sSharpEDRChecker.{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10N/AN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z3085
201* SharpHound.ps1*.{0,1000}\sSharpHound\.ps1.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z3091
202*- --skippasswordcheck*.{0,1000}\-\s\-\-skippasswordcheck.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z3157
203* --skipregistryloggedon*.{0,1000}\s\-\-skipregistryloggedon.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z3158
204* SmallSecretsDump.py*.{0,1000}\sSmallSecretsDump\.py.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck10N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z3172
205* smb * --dpapi *password*.{0,1000}\ssmb\s.{0,1000}\s\-\-dpapi\s.{0,1000}password.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z3176
206* smb * --gen-relay-list *.txt*.{0,1000}\ssmb\s.{0,1000}\s\-\-gen\-relay\-list\s.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z3177
207* smb * --lsa --log *.{0,1000}\ssmb\s.{0,1000}\s\-\-lsa\s\-\-log\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z3178
208* smb * -M msol *.{0,1000}\ssmb\s.{0,1000}\s\-M\smsol\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z3181
209* smb * -M ntlmv1 *.{0,1000}\ssmb\s.{0,1000}\s\-M\sntlmv1\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z3182
210* smb * --ntds --log *.{0,1000}\ssmb\s.{0,1000}\s\-\-ntds\s\-\-log\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z3187
211* smb * --sam --log *.{0,1000}\ssmb\s.{0,1000}\s\-\-sam\s\-\-log\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z3188
212* smbscan.py *.{0,1000}\ssmbscan\.py\s.{0,1000}offensive_tool_keywordsmbscanSMBScan is a tool to enumerate file shares on an internal network.T1135 - T1046 - T1021TA0007 - TA0043 - TA0008N/AAPT22Discoveryhttps://github.com/jeffhacks/smbscan10N/AN/A814462025-03-24T01:55:30Z2021-10-26T02:28:34Z3234
213* smbsr.log*.{0,1000}\ssmbsr\.log.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z3238
214* smbsr.py*.{0,1000}\ssmbsr\.py.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z3240
215* smbsr_results.csv*.{0,1000}\ssmbsr_results\.csv.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z3241
216* snsenum.py*.{0,1000}\ssnsenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z3289
217* SOAPHound.ADWS*.{0,1000}\sSOAPHound\.ADWS.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10#contentN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z3290
218* -sS -p- --min-rate=* -Pn*.{0,1000}\s\-sS\s\-p\-\s\-\-min\-rate\=.{0,1000}\s\-Pn.{0,1000}offensive_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditing (stealphy mode)T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://nmap.org/book/nse-usage.html10N/AN/AN/AN/AN/AN/AN/AN/A3352
219* --stealth --secureldap*.{0,1000}\s\-\-stealth\s\-\-secureldap.{0,1000}signature_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z3406
220* -sV --script vulners *.{0,1000}\s\-sV\s\-\-script\svulners\s.{0,1000}offensive_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://nmap.org/book/nse-usage.html10N/AN/AN/AN/AN/AN/AN/AN/A3433
221* teamsenum.py*.{0,1000}\steamsenum\.py.{0,1000}offensive_tool_keywordTeamsEnumUser Enumeration of Microsoft Teams users via APIT1589.002 - T1590TA0007 - TA0001N/ABlack BastaDiscoveryhttps://github.com/sse-secure-systems/TeamsEnum10N/AN/A62153212024-03-27T18:14:25Z2023-04-03T18:35:15Z3494
222* thief.py*.{0,1000}\sthief\.py.{0,1000}offensive_tool_keywordSeeYouCM-ThiefSimple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentialsT1110.001 - T1005 - T1071.001TA0001 - TA0011 - TA0005N/AN/ADiscoveryhttps://github.com/trustedsec/SeeYouCM-Thief10N/AN/A92189352023-05-11T01:04:36Z2022-01-14T20:12:25Z3516
223* -u http* --wordlisturl * -e php,aspx --recursion true*.{0,1000}\s\-u\shttp.{0,1000}\s\-\-wordlisturl\s.{0,1000}\s\-e\sphp,aspx\s\-\-recursion\strue.{0,1000}offensive_tool_keywordSharpBusterThis is a C# implementation of a directory brute forcing tool designed to allow for in-memory executionT1087 - T1112 - T1048.003 - T1105TA0007 - TA0040 - TA0002N/AN/ADiscoveryhttps://github.com/passthehashbrowns/SharpBuster10N/AN/A716272020-09-02T15:46:03Z2020-08-31T00:33:02Z3599
224* --unconstrained-users*.{0,1000}\s\-\-unconstrained\-users.{0,1000}offensive_tool_keywordwindapsearchPython script to enumerate users - groups and computers from a Windows domain through LDAP queriesT1087.002 - T1018 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/ropnop/windapsearch10N/AAD Enumeration798661542022-04-20T07:40:42Z2016-08-10T21:43:30Z3613
225* userenum * --dc *.{0,1000}\suserenum\s.{0,1000}\s\-\-dc\s.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z3642
226* --UserEnum --Host *.{0,1000}\s\-\-UserEnum\s\-\-Host\s.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector10N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z3644
227* --user-spns*.{0,1000}\s\-\-user\-spns.{0,1000}offensive_tool_keywordwindapsearchPython script to enumerate users - groups and computers from a Windows domain through LDAP queriesT1087.002 - T1018 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/ropnop/windapsearch10N/AAD Enumeration798661542022-04-20T07:40:42Z2016-08-10T21:43:30Z3654
228* -vulnerable -stdout -hide-admins*.{0,1000}\s\-vulnerable\s\-stdout\s\-hide\-admins.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z3681
229* We have found at least * potential SUID exploitable file(s)*.{0,1000}\sWe\shave\sfound\sat\sleast\s.{0,1000}\spotential\sSUID\sexploitable\sfile\(s\).{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10N/AN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z3696
230* where /r C:\Windows\WinSxS\ *Microsoft.ActiveDirectory.Management.dll*.{0,1000}\swhere\s\/r\sC\:\\Windows\\WinSxS\\\s.{0,1000}Microsoft\.ActiveDirectory\.Management\.dll.{0,1000}greyware_tool_keywordwherethreat actors searched for Active Directory related DLLs in directoriesT1059 - T1083 - T1018TA0002 - TA0009 - TA0040N/AN/ADiscoveryhttps://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/10N/AN/AN/AN/AN/AN/AN/AN/A3704
231* Win64/NetTool.SoftPerfectNetscan*.{0,1000}\sWin64\/NetTool\.SoftPerfectNetscan.{0,1000}signature_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10#AvsignatureN/A810N/AN/AN/AN/A3712
232* windapsearch.py*.{0,1000}\swindapsearch\.py.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z3714
233* -word-list-path tomatch.txt*.{0,1000}\s\-word\-list\-path\stomatch\.txt.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z3752
234*"ADWS request with ldapbase (*.{0,1000}\"ADWS\srequest\swith\sldapbase\s\(.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10#contentN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z3819
235*"C:\Windows\system32\ARP.EXE" /a*.{0,1000}\"C\:\\Windows\\system32\\ARP\.EXE\"\s\/a.{0,1000}greyware_tool_keywordarpArp displays and modifies information about a system's Address Resolution Protocol (ARP) cacheT1018TA0007N/ATurla - APT32 - OrangewormDiscoveryN/A10N/AN/A57N/AN/AN/AN/A3825
236*"Dump BH data"*.{0,1000}\"Dump\sBH\sdata\".{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10#contentN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z3836
237*"samaccounttype=268435456)(samaccounttype=268435457)(samaccounttype=536870912)(samaccounttype=536870913)*.{0,1000}\"samaccounttype\=268435456\)\(samaccounttype\=268435457\)\(samaccounttype\=536870912\)\(samaccounttype\=536870913\).{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://thedfirreport.com/2024/08/26/blacksuit-ransomware/10N/AN/AN/A7N/AN/AN/AN/A3866
238*# @oldboy21*.{0,1000}\#\s\s\@oldboy21.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z3883
239*# Minimalistic TCP and UDP port scanners*.{0,1000}\#\sMinimalistic\sTCP\sand\sUDP\sport\sscanners.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools10N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z3901
240*$ADelegReport*.{0,1000}\$ADelegReport.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z3939
241*$adPEAS_*.{0,1000}\$adPEAS_.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10#contentN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z3940
242*$attacker_IPlist*.{0,1000}\$attacker_IPlist.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn10#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z3942
243*$base64adrecon*.{0,1000}\$base64adrecon.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10#contentAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z3945
244*$EmptyPasswordUsers*.{0,1000}\$EmptyPasswordUsers.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum10N/AN/A75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z3960
245*$InsecureResourceDelegations*.{0,1000}\$InsecureResourceDelegations.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z3986
246*$InsecureTrusteeDelegations*.{0,1000}\$InsecureTrusteeDelegations.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z3987
247*$PotentialComputersWithEmptyPassword*.{0,1000}\$PotentialComputersWithEmptyPassword.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum10N/Asimple backdoor with anydesk75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z4007
248*$PotentialUsersWithEmptyPassword*.{0,1000}\$PotentialUsersWithEmptyPassword.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum10N/Asimple backdoor with anydesk75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z4008
249*$SprayEmptyPasswords*.{0,1000}\$SprayEmptyPasswords.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum10N/AN/A75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z4017
250*(!soaphound=*.{0,1000}\(!soaphound\=.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10#ldapioc in ldap query https://github.com/FalconForceTeam/SOAPHound/blob/818a0b5add9d70c3d210f0ddcde781a85cd0cba2/ADWSUtils.cs#L42C21-L42C3088736762024-02-03T08:52:49Z2024-01-25T09:11:12Z4052
251*(&(&(objectCategory=person)(objectClass=user))(|(description=*pass*)(comment=*pass*)))*.{0,1000}\(\&\(\&\(objectCategory\=person\)\(objectClass\=user\)\)\(\|\(description\=.{0,1000}pass.{0,1000}\)\(comment\=.{0,1000}pass.{0,1000}\)\)\).{0,1000}greyware_tool_keywordldap queriesmetasploit enum_ad_user_commentsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/hunting-for-reconnaissance-activities-using-ldap-search-filters/ba-p/82472610N/AN/A84N/AN/AN/AN/A4053
252*(&(objectCategory=computer)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(!(userAccountControl:1.2.840.113556.1.4.803:=8192))(!(userAccountControl:1.2.840.113556.1.4.803:=67100867)))*.{0,1000}\(\&\(objectCategory\=computer\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=8192\)\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=67100867\)\)\).{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/mitchmoser/SharpShares10N/AN/A104351492021-09-21T08:14:27Z2020-09-25T22:35:57Z4054
253*(&(objectCategory=computer)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(operatingSystem=*server*)(!(userAccountControl:1.2.840.113556.1.4.803:=8192))(!(userAccountControl:1.2.840.113556.1.4.803:=67100867)))*.{0,1000}\(\&\(objectCategory\=computer\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(operatingSystem\=.{0,1000}server.{0,1000}\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=8192\)\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=67100867\)\)\).{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/mitchmoser/SharpShares10N/AN/A104351492021-09-21T08:14:27Z2020-09-25T22:35:57Z4055
254*(&(objectCategory=computer)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(userAccountControl:1.2.840.113556.1.4.803:=8192))*.{0,1000}\(\&\(objectCategory\=computer\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=8192\)\).{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/mitchmoser/SharpShares10N/AN/A104351492021-09-21T08:14:27Z2020-09-25T22:35:57Z4056
255*(&(objectCategory=computer)(msDS-isRODC=TRUE))*.{0,1000}\(\&\(objectCategory\=computer\)\(msDS\-isRODC\=TRUE\)\).{0,1000}greyware_tool_keywordldap queriesEnumerate Read-Only Domain Controllers (RODC)T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/mthcht/ThreatHunting-Keywords10N/AN/A86563612025-03-03T15:48:41Z2023-05-16T15:38:26Z4057
256*(&(objectCategory=computer)(ms-MCS-AdmPwd=*)(sAMAccountName=" + target + "))*.{0,1000}\(\&\(objectCategory\=computer\)\(ms\-MCS\-AdmPwd\=.{0,1000}\)\(sAMAccountName\=\"\s\+\starget\s\+\s\"\)\).{0,1000}greyware_tool_keywordldap queriesLAPS passwords (from SharpLAPS)T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4058
257*(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=65536)(memberOf=CN=Administrators*.{0,1000}\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=65536\)\(memberOf\=CN\=Administrators.{0,1000}greyware_tool_keywordldap queriesEnumerate Accounts with Non-Expiring Passwords and Administrative PrivilegesT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/mthcht/ThreatHunting-Keywords10N/AN/A86563612025-03-03T15:48:41Z2023-05-16T15:38:26Z4059
258*(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=65536)*.{0,1000}\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=65536\).{0,1000}greyware_tool_keywordldap queriesEnumerate all users with the account configuration 'Password never expires'T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4060
259*(&(objectClass=group)(managedBy=*)(groupType:1.2.840.113556.1.4.803:=2147483648))*.{0,1000}\(\&\(objectClass\=group\)\(managedBy\=.{0,1000}\)\(groupType\:1\.2\.840\.113556\.1\.4\.803\:\=2147483648\)\).{0,1000}greyware_tool_keywordldap queriesmetasploit enum_ad_managedby_groups.rbT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/rapid7/metasploit-framework/blob/d37a82500d1d08f9d8ab3da9b194653835748fae/modules/post/windows/gather/enum_ad_managedby_groups.rb#L5910N/AN/A81035400142722025-04-22T20:14:59Z2011-08-30T06:13:20Z4061
260*(&(objectclass=group)(samaccountname=*domain admins*))*.{0,1000}\(\&\(objectclass\=group\)\(samaccountname\=.{0,1000}domain\sadmins.{0,1000}\)\).{0,1000}greyware_tool_keywordldap queriesEnumerate Domain Administrators GroupT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca38410N/AN/A810N/AN/AN/AN/A4062
261*(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))(!msds-supportedencryptiontypes:1.2.840.113556.1.4.804:=24))*.{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(!msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.804\:\=24\)\).{0,1000}greyware_tool_keywordldap queriesKerberoastingT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4063
262*(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2))(msds-supportedencryptiontypes:1.2.840.113556.1.4.804:=24))*.{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.804\:\=24\)\).{0,1000}greyware_tool_keywordldap queriesKerberoastingT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4064
263*(&(samAccountType=805306368)(servicePrincipalName=*)(!samAccountName=krbtgt)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))*.{0,1000}\(\&\(samAccountType\=805306368\)\(servicePrincipalName\=.{0,1000}\)\(!samAccountName\=krbtgt\)\(!\(UserAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\).{0,1000}greyware_tool_keywordldap queriesKerberoastingT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4065
264*([adsisearcher]'(&(objectCategory=computer)(!(primaryGroupID=516)(userAccountControl:1.2.840.113556.1.4.803:=524288)))').FindAll()*.{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=computer\)\(!\(primaryGroupID\=516\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=524288\)\)\)\'\)\.FindAll\(\).{0,1000}greyware_tool_keywordldap queriesEnumerate all servers configured for Unconstrained DelegationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryN/A10N/AN/A910N/AN/AN/AN/A4067
265*([adsisearcher]'(&(objectCategory=computer)(userAccountControl:1.2.840.113556.1.4.803:=8192))').FindAll()*.{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=computer\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=8192\)\)\'\)\.FindAll\(\).{0,1000}greyware_tool_keywordldap queriesEnumerate all Domain ControllersT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://web.archive.org/web/20240109000256/https://cyberdom.blog/2024/01/07/defender-for-identity-hunting-for-ldap/10N/AN/A910N/AN/AN/AN/A4068
266*([adsisearcher]'(&(objectCategory=user)(!(samAccountName=krbtgt)(servicePrincipalName=*)))').FindAll()*.{0,1000}\(\[adsisearcher\]\'\(\&\(objectCategory\=user\)\(!\(samAccountName\=krbtgt\)\(servicePrincipalName\=.{0,1000}\)\)\)\'\)\.FindAll\(\).{0,1000}greyware_tool_keywordldap queriesSearch for user accounts with SPN but not TGT accountsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca38410N/AN/A810N/AN/AN/AN/A4069
267*([adsisearcher]'(adminCount=1)').FindAll()*.{0,1000}\(\[adsisearcher\]\'\(adminCount\=1\)\'\)\.FindAll\(\).{0,1000}greyware_tool_keywordldap queriesSearch for all objects with AdminSHHolderT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca38410N/AN/A810N/AN/AN/AN/A4070
268*([DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest()).Domains*.{0,1000}\(\[DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\)\.Domains.{0,1000}greyware_tool_keywordldap queriesQueries for domain level and mode informationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z4071
269*([DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest()).Sites | *.{0,1000}\(\[DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\)\.Sites\s\|\s.{0,1000}greyware_tool_keywordldap queriesenumeration of AD Forest SitesT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z4072
270*([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).FindAllDomainControllers() | Select-Object -Property *.{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.FindAllDomainControllers\(\)\s\|\sSelect\-Object\s\-Property\s.{0,1000}greyware_tool_keywordldap queriesquerying all domain controllers with detailed propertiesT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z4073
271*([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()*.{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.GetAllTrustRelationships\(\).{0,1000}greyware_tool_keywordldap queriesget all trust relationships in the current domainT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z4074
272*([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()*.{0,1000}\(\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\)\.GetAllTrustRelationships\(\).{0,1000}greyware_tool_keywordpowershellPowershell enumerate domains and forestsT1482 - T1069.002TA0007 - TA0008N/ABlack BastaDiscoveryhttps://medium.com/@simone.kraus/black-basta-playbook-chat-leak-d5036936166d10N/AN/A1010N/AN/AN/AN/A4075
273*(Get-ADForest).Domains | %{ Get-ADDomainController -Filter * -Server $_ }*.{0,1000}\(Get\-ADForest\)\.Domains\s\|\s\%\{\sGet\-ADDomainController\s\-Filter\s.{0,1000}\s\-Server\s\$_\s\}.{0,1000}greyware_tool_keywordldap queriesEnumerate all of the domain controllers for all domains in a forestT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryN/A10N/AN/A66N/AN/AN/AN/A4077
274*(msds-supportedencryptiontypes=0)(msds-supportedencryptiontypes:1.2.840.113556.1.4.803:=4)))*.{0,1000}\(msds\-supportedencryptiontypes\=0\)\(msds\-supportedencryptiontypes\:1\.2\.840\.113556\.1\.4\.803\:\=4\)\)\).{0,1000}greyware_tool_keywordldap queriesused by Rubeus and S4UTomato toolsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryN/A10N/AN/A1010N/AN/AN/AN/A4081
275*(objectCategory=person)(objectClass=user)(serviceAccount=TRUE)*.{0,1000}\(objectCategory\=person\)\(objectClass\=user\)\(serviceAccount\=TRUE\).{0,1000}greyware_tool_keywordldap queriesQuery to find service accounts which are typically high-privileged and targeted for privilege escalationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/mthcht/ThreatHunting-Keywords10N/AN/A86563612025-03-03T15:48:41Z2023-05-16T15:38:26Z4085
276*(objectclass=group)(samaccountname=domain admins)*.{0,1000}\(objectclass\=group\)\(samaccountname\=domain\sadmins\).{0,1000}greyware_tool_keywordldap queriesEnumerate Domain AdminsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4086
277*(userAccountControl:1.2.840.113556.1.4.803:=524288)*.{0,1000}\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=524288\).{0,1000}greyware_tool_keywordldap queriesAccounts Trusted for DelegationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://gist.github.com/jsecurity101/9c7e94f95b8d90f9252d64949562ba5d10N/AN/A810N/AN/AN/AN/A4091
278*./AutoSUID.sh*.{0,1000}\.\/AutoSUID\.sh.{0,1000}offensive_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A74375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4105
279*./capsh --gid=0 --uid=0 --*.{0,1000}\.\/capsh\s\-\-gid\=0\s\-\-uid\=0\s\-\-.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4112
280*./chroot / /bin/sh -p*.{0,1000}\.\/chroot\s\/\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4115
281*./env /bin/sh -p*.{0,1000}\.\/env\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4131
282*./expect -c 'spawn /bin/sh -p;interact'*.{0,1000}\.\/expect\s\-c\s\'spawn\s\/bin\/sh\s\-p\;interact\'.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4134
283*./flock -u / /bin/sh -p*.{0,1000}\.\/flock\s\-u\s\/\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4139
284*./nice /bin/sh -p*.{0,1000}\.\/nice\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4171
285*./nmap*.{0,1000}\.\/nmap.{0,1000}greyware_tool_keywordnmapA very common tool. Network host vuln and port detector.T1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap11#linuxgreyware tool - risks of False positive !8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z4173
286*./rview -c ':py3 import os*os.execl(\"/bin/sh\*.{0,1000}\.\/rview\s\-c\s\'\:py3\simport\sos.{0,1000}os\.execl\(\\\"\/bin\/sh\\.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z4195
287*.exe /HistorySource 1 /SaveDirect /scomma *.{0,1000}\.exe\s\s\/HistorySource\s1\s\/SaveDirect\s\/scomma\s.{0,1000}offensive_tool_keywordBrowsingHistoryViewBrowsingHistoryView is a utility that reads the history data of different Web browsersT1217 - T1070 - T1113TA0009 - TA0005 - TA0007N/AGOBLIN PANDADiscoveryhttps://www.nirsoft.net/utils/browsing_history_view.html10N/AN/A1010N/AN/AN/AN/A4317
288*.exe --buildcache -c *\cache.txt*.{0,1000}\.exe\s\s\-\-buildcache\s\-c\s.{0,1000}\\cache\.txt.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z4320
289*.exe * /hide * /range:* /auto:*.*.{0,1000}\.exe\s.{0,1000}\s\/hide\s.{0,1000}\s\/range\:.{0,1000}\s\/auto\:.{0,1000}\..{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A4325
290*.exe /hide /range:all*.{0,1000}\.exe\s\/hide\s\/range\:all.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A4334
291*.exe /HistorySource 1 /LoadChrome 1 /shtml *.{0,1000}\.exe\s\/HistorySource\s1\s\/LoadChrome\s1\s\/shtml\s.{0,1000}offensive_tool_keywordBrowsingHistoryViewBrowsingHistoryView is a utility that reads the history data of different Web browsersT1217 - T1070 - T1113TA0009 - TA0005 - TA0007N/AGOBLIN PANDADiscoveryhttps://www.nirsoft.net/utils/browsing_history_view.html10N/AN/A1010N/AN/AN/AN/A4335
292*.exe /s:ip_ranges.txt /f:scan_results.txt*.{0,1000}\.exe\s\/s\:ip_ranges\.txt\s\/f\:scan_results\.txt.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox10N/AN/A710N/AN/AN/AN/A4347
293*.exe /wakeall*.{0,1000}\.exe\s\/wakeall.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A4348
294*.exe acl -dn * -scope * -trustee *.{0,1000}\.exe\sacl\s\-dn\s.{0,1000}\s\-scope\s.{0,1000}\s\-trustee\s.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z4350
295*.exe --ACLScan * --OU *.{0,1000}\.exe\s\-\-ACLScan\s.{0,1000}\s\-\-OU\s.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector10N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z4351
296*.exe --asrep.{0,1000}\.exe\s\-\-asrepoffensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z4384
297*.exe Certify -action find -enrolleeSuppliesSubject -clientAuth*.{0,1000}\.exe\sCertify\s\-action\sfind\s\-enrolleeSuppliesSubject\s\-clientAuth.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z4402
298*.exe Certify -action find*.{0,1000}\.exe\sCertify\s\-action\sfind.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z4403
299*.exe --CollectionMethods Session --Loop*.{0,1000}\.exe\s\-\-CollectionMethods\sSession\s\-\-Loop.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z4406
300*.exe -d * -u * -p * -m LDAPS*.{0,1000}\.exe\s\-d\s.{0,1000}\s\-u\s.{0,1000}\s\-p\s.{0,1000}\s\-m\sLDAPS.{0,1000}offensive_tool_keywordSharpLdapRelayScanSharLdapRealyScan is a tool to check Domain Controllers for LDAP server protections regarding the relay of NTLM authenticationvand it's a C# port of?LdapRelayScanT1557.001 - T1078.003 - T1046TA0002 - TA0007 - TA0040N/AN/ADiscoveryhttps://github.com/klezVirus/SharpLdapRelayScan10N/Anetwork exploitation tool7181182022-02-26T22:03:11Z2022-02-12T08:16:59Z4419
301*.exe DCSync -action list*.{0,1000}\.exe\sDCSync\s\-action\slist.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z4422
302*.exe DCSync -action write -target *.{0,1000}\.exe\sDCSync\s\-action\swrite\s\-target\s.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z4423
303*.exe DontReqPreAuth -action list*.{0,1000}\.exe\sDontReqPreAuth\s\-action\slist.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z4427
304*.exe DontReqPreAuth -action write -target *.{0,1000}\.exe\sDontReqPreAuth\s\-action\swrite\s\-target\s.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z4428
305*.exe -gcb -sc trustdmp > *.{0,1000}\.exe\s\-gcb\s\-sc\strustdmp\s\>\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z4443
306*.exe Get-DomainController -Domain * -Server * -Credential *.{0,1000}\.exe\sGet\-DomainController\s\-Domain\s.{0,1000}\s\-Server\s.{0,1000}\s\-Credential\s.{0,1000}offensive_tool_keywordSharpViewC# implementation of harmj0y's PowerViewT1018 - T1482 - T1087.002 - T1069.002TA0007 - TA0003 - TA0001N/AConti - APT29Discoveryhttps://github.com/tevora-threat/SharpView/10N/AN/A101010321962024-03-22T16:34:09Z2018-07-24T21:15:04Z4444
307*.exe --gpo --filter admin --domain*.{0,1000}\.exe\s\-\-gpo\s\-\-filter\sadmin\s\-\-domain.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z4459
308*.exe --LDAPs --DisableSigning*.{0,1000}\.exe\s\-\-LDAPs\s\-\-DisableSigning.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector10N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z4515
309*.exe --list-vulns*.{0,1000}\.exe\s\-\-list\-vulns.{0,1000}offensive_tool_keywordMoriartyMoriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments.T1068 - T1083TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/BC-SECURITY/Moriarty10N/AN/A76510672024-08-07T15:06:31Z2023-12-11T14:15:33Z4518
310*.exe RBCD -action read -delegate-to *.{0,1000}\.exe\sRBCD\s\-action\sread\s\-delegate\-to\s.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z4582
311*.exe -sc adinfo > *.{0,1000}\.exe\s\-sc\sadinfo\s\>\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z4598
312*.exe -sc dclist > *.{0,1000}\.exe\s\-sc\sdclist\s\>\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z4599
313*.exe -sc getacls -sddlfilter *.{0,1000}\.exe\s\-sc\sgetacls\s\-sddlfilter\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A4600
314*.exe -sc trustdmp > *.{0,1000}\.exe\s\-sc\strustdmp\s\>\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z4601
315*.exe --showstats -c *\cache.txt*.{0,1000}\.exe\s\-\-showstats\s\-c\s.{0,1000}\\cache\.txt.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z4610
316*.exe --spn --domain * --user * --pass *.{0,1000}\.exe\s\-\-spn\s\-\-domain\s.{0,1000}\s\-\-user\s.{0,1000}\s\-\-pass\s.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z4619
317*.exe -subnets -f (objectCategory=subnet) > *.{0,1000}\.exe\s\-subnets\s\-f\s\(objectCategory\=subnet\)\s\>\s.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z4623
318*.exe Whisker -action add -target * -cert-pass *.{0,1000}\.exe\sWhisker\s\-action\sadd\s\-target\s.{0,1000}\s\-cert\-pass\s.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z4641
319*.exe Whisker -action list -target *.{0,1000}\.exe\sWhisker\s\-action\slist\s\-target\s.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z4642
320*.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation *.{0,1000}\.NET\spost\-exploitation\stoolkit\sfor\sActive\sDirectory\sreconnaissance\sand\sexploitation\s.{0,1000}offensive_tool_keywordCable*.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation*T1087 - T1016 - T1059 - T1482 - T1078TA0007 - TA0002 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/logangoins/Cable10#contentN/A74361402025-04-09T01:12:47Z2024-08-10T19:47:08Z4707
321*.powerview.ldap_session*.{0,1000}\.powerview\.ldap_session.{0,1000}offensive_tool_keywordpowerviewPowerView.py is an alternative for the awesome original PowerView.ps1T1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/aniqfakhrul/powerview.py10#contentN/A107622662025-04-22T09:01:39Z2022-06-19T16:13:04Z4738
322*.ps1 -Base *OU=*DC=* -Credentials * -Server *.{0,1000}\.ps1\s\-Base\s.{0,1000}OU\=.{0,1000}DC\=.{0,1000}\s\-Credentials\s.{0,1000}\s\-Server\s.{0,1000}offensive_tool_keywordADACLScannerA tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .T1222 - T1069 - T1018TA0002 - TA0007 - TA0043N/AN/ADiscoveryhttps://github.com/canix1/ADACLScanner10N/AAD Enumeration71010151732025-04-11T14:35:08Z2017-04-06T12:28:37Z4759
323*.py --cached --ntuser NTUSER.DAT*.{0,1000}\.py\s\-\-cached\s\-\-ntuser\sNTUSER\.DAT.{0,1000}offensive_tool_keywordLocalShellExtParseScript to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User.T1547.009 - T1129TA0003 - TA0007N/AN/ADiscoveryhttps://github.com/herrcore/LocalShellExtParse10N/AN/A912042015-06-08T16:55:38Z2015-06-05T03:23:13Z4816
324*.py --ntuser NTUSER.DAT --usrclass UsrClass.dat*.{0,1000}\.py\s\-\-ntuser\sNTUSER\.DAT\s\-\-usrclass\sUsrClass\.dat.{0,1000}offensive_tool_keywordLocalShellExtParseScript to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User.T1547.009 - T1129TA0003 - TA0007N/AN/ADiscoveryhttps://github.com/herrcore/LocalShellExtParse10N/AN/A912042015-06-08T16:55:38Z2015-06-05T03:23:13Z4840
325*.py -u * ?print-zones *.{0,1000}\.py\s\-u\s.{0,1000}\s\?print\-zones\s.{0,1000}offensive_tool_keywordadidnsdumpBy default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks.T1018 - T1087 - T1201 - T1056 - T1039TA0005 - TA0009N/AN/ADiscoveryhttps://github.com/dirkjanm/adidnsdump10N/AN/AN/A109971182025-04-04T09:28:20Z2019-04-24T17:18:46Z4847
326*/.manspider/logs*.{0,1000}\/\.manspider\/logs.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10#linuxN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z5023
327*/.manspider/loot*.{0,1000}\/\.manspider\/loot.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10#linuxN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z5024
328*/.powerview/.powerview_history*.{0,1000}\/\.powerview\/\.powerview_history.{0,1000}offensive_tool_keywordpowerviewPowerView.py is an alternative for the awesome original PowerView.ps1T1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/aniqfakhrul/powerview.py10#linuxN/A107622662025-04-22T09:01:39Z2022-06-19T16:13:04Z5029
329*/.powerview/logs*.{0,1000}\/\.powerview\/logs.{0,1000}offensive_tool_keywordpowerviewPowerView.py is an alternative for the awesome original PowerView.ps1T1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/aniqfakhrul/powerview.py10#linuxN/A107622662025-04-22T09:01:39Z2022-06-19T16:13:04Z5030
330*/10m_usernames.txt*.{0,1000}\/10m_usernames\.txt.{0,1000}offensive_tool_keywordldapnomnomAnonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)T1110.003 - T1205TA0007N/AN/ADiscoveryhttps://github.com/lkarlslund/ldapnomnom10N/AN/A6101030802024-11-09T10:15:13Z2022-09-18T10:35:09Z5080
331*/Accomplice.git*.{0,1000}\/Accomplice\.git.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice11N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z5106
332*/ACLight.git*.{0,1000}\/ACLight\.git.{0,1000}offensive_tool_keywordACLightA tool for advanced discovery of Privileged Accounts - including Shadow Admins.T1087 - T1003 - T1208TA0001 - TA0006 - TA0008N/AN/ADiscoveryhttps://github.com/cyberark/ACLight11N/AAD Enumeration798011462019-09-09T06:48:45Z2017-05-17T09:29:41Z5115
333*/ACLight/*.{0,1000}\/ACLight\/.{0,1000}offensive_tool_keywordACLightA tool for advanced discovery of Privileged Accounts - including Shadow Admins.T1087 - T1003 - T1208TA0001 - TA0006 - TA0008N/AN/ADiscoveryhttps://github.com/cyberark/ACLight11N/AN/AN/A98011462019-09-09T06:48:45Z2017-05-17T09:29:41Z5116
334*/ActiveScanPlusPlus*.{0,1000}\/ActiveScanPlusPlus.{0,1000}offensive_tool_keywordActiveScanPlusPlusActiveScan++ extends Burp Suite's active and passive scanning capabilities. Designed to add minimal network overhead. it identifies application behaviour that may be of interest to advanced testersT1583 - T1595 - T1190TA0001 - TA0002 - TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/albinowax/ActiveScanPlusPlus11N/Anetwork exploitation toolN/A76301952025-04-17T10:47:54Z2014-06-23T10:04:13Z5124
335*/AD_Enumeration_Hunt*.{0,1000}\/AD_Enumeration_Hunt.{0,1000}offensive_tool_keywordAD_Enumeration_HuntThis repository contains a collection of PowerShell scripts and commands that can be used for Active Directory (AD) penetration testing and security assessmentT1018 - T1003 - T1033 - T1087 - T1069 - T1046 - T1069.002 - T1047 - T1083TA0001 - TA0007 - TA0005 - TA0002 - TA0003N/AN/ADiscoveryhttps://github.com/alperenugurlu/AD_Enumeration_Hunt11N/AAD Enumeration7193182023-08-05T06:10:26Z2023-08-05T05:16:57Z5125
336*/AD_Miner.git*.{0,1000}\/AD_Miner\.git.{0,1000}offensive_tool_keywordAD_MinerAD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknessesT1087.002 - T1069 - T1018 - T1595TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/Mazars-Tech/AD_Miner11N/AAD Enumeration71012901312025-03-12T10:53:09Z2023-09-26T12:36:59Z5126
337*/AD_Miner.git*.{0,1000}\/AD_Miner\.git.{0,1000}greyware_tool_keywordAD_MinerAD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknessesT1482 - T1069 - T1087TA0007 N/AEMBER BEARDiscoveryhttps://github.com/Mazars-Tech/AD_Miner11N/AN/A61012901312025-03-12T10:53:09Z2023-09-26T12:36:59Z5127
338*/AD_Miner/releases/*.{0,1000}\/AD_Miner\/releases\/.{0,1000}greyware_tool_keywordAD_MinerAD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknessesT1482 - T1069 - T1087TA0007 N/AEMBER BEARDiscoveryhttps://github.com/Mazars-Tech/AD_Miner11N/AN/A61012901312025-03-12T10:53:09Z2023-09-26T12:36:59Z5128
339*/ADACLScanner.git*.{0,1000}\/ADACLScanner\.git.{0,1000}offensive_tool_keywordADACLScannerA tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .T1222 - T1069 - T1018TA0002 - TA0007 - TA0043N/AN/ADiscoveryhttps://github.com/canix1/ADACLScanner11N/AAD Enumeration71010151732025-04-11T14:35:08Z2017-04-06T12:28:37Z5129
340*/adalanche/modules/*.{0,1000}\/adalanche\/modules\/.{0,1000}offensive_tool_keywordadalancheActive Directory ACL Visualizer and Explorer - who's really Domain Admin?T1484 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/lkarlslund/Adalanche11N/AAD Enumeration101019081842025-03-25T13:01:45Z2020-10-07T10:07:22Z5130
341*/adaudit.git*.{0,1000}\/adaudit\.git.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit11N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z5137
342*/adaudit.git*.{0,1000}\/adaudit\.git.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit11N/AN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z5138
343*/ADAudit.ps1*.{0,1000}\/ADAudit\.ps1.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit11N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z5139
344*/adaudit.ps1*.{0,1000}\/adaudit\.ps1.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit11N/AN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z5140
345*/ADcheck.git*.{0,1000}\/ADcheck\.git.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck11N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z5141
346*/ADcheck.py*.{0,1000}\/ADcheck\.py.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck11N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z5142
347*/ADCollector.exe*.{0,1000}\/ADCollector\.exe.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector11N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z5143
348*/ADCollector.git*.{0,1000}\/ADCollector\.git.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector11N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z5146
349*/AD-common-queries.git*.{0,1000}\/AD\-common\-queries\.git.{0,1000}greyware_tool_keywordAD-common-queriesCollection of common ADSI queries for Domain Account enumerationT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries11N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z5147
350*/adcshunter.git*.{0,1000}\/adcshunter\.git.{0,1000}offensive_tool_keywordadcshunterUses rpcdump to locate the ADCS server and identify if ESC8 is vulnerable from unauthenticated perspective.T1018 - T1087 - T1046 - T1201 - T1595TA0007 - TA0043N/AN/ADiscoveryhttps://github.com/danti1988/adcshunter11N/AN/A718072024-09-13T12:50:50Z2023-12-14T14:31:05Z5159
351*/ADeleg.exe*.{0,1000}\/ADeleg\.exe.{0,1000}offensive_tool_keywordadelegan Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forestT1595 - T1087.002 - T1069.002TA0007 - TA0004N/AN/ADiscoveryhttps://github.com/mtth-bfft/adeleg11N/AN/A83294312023-06-07T15:08:53Z2022-02-09T19:47:04Z5181
352*/ADeleg.exe*.{0,1000}\/ADeleg\.exe.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator11N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z5182
353*/adeleg.git*.{0,1000}\/adeleg\.git.{0,1000}offensive_tool_keywordadelegan Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forestT1595 - T1087.002 - T1069.002TA0007 - TA0004N/AN/ADiscoveryhttps://github.com/mtth-bfft/adeleg11N/AN/A83294312023-06-07T15:08:53Z2022-02-09T19:47:04Z5183
354*/adeleg.pdb*.{0,1000}\/adeleg\.pdb.{0,1000}offensive_tool_keywordadelegan Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forestT1595 - T1087.002 - T1069.002TA0007 - TA0004N/AN/ADiscoveryhttps://github.com/mtth-bfft/adeleg11N/AN/A83294312023-06-07T15:08:53Z2022-02-09T19:47:04Z5184
355*/ADeleginator.git*.{0,1000}\/ADeleginator\.git.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator11N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z5185
356*/AdFind.zip*.{0,1000}\/AdFind\.zip.{0,1000}greyware_tool_keywordadfindadfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environmentT1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior11N/AN/A1010N/AN/AN/AN/A5186
357*/ADGet.exe*.{0,1000}\\ADGet\.exe.{0,1000}greyware_tool_keywordadgetgather valuable informations about the AD environmentT1018 - T1027 - T1046 - T1057 - T1069 - T1087 - T1098 - T1482TA0001 - TA0002 - TA0003 - TA0007 - TA0011N/AN/ADiscoveryhttps://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/11N/AN/A1010N/AN/AN/AN/A5198
358*/ADHunt.git*.{0,1000}\/ADHunt\.git.{0,1000}offensive_tool_keywordadhuntTool for exploiting Active Directory Enviroments - enumerationT1018 - T1087 - T1087.002 - T1069 - T1069.002TA0007 - TA0003 - TA0001N/AN/ADiscoveryhttps://github.com/karendm/ADHunt11N/AAD Enumeration7146102023-08-10T18:55:39Z2023-06-20T13:24:10Z5199
359*/adhunt.py*\/adhunt\.pyoffensive_tool_keywordadhuntTool for exploiting Active Directory Enviroments - enumerationT1018 - T1087 - T1087.002 - T1069 - T1069.002TA0007 - TA0003 - TA0001N/AN/ADiscoveryhttps://github.com/karendm/ADHunt11N/AAD Enumeration7146102023-08-10T18:55:39Z2023-06-20T13:24:10Z5200
360*/adidnsdump.git*.{0,1000}\/adidnsdump\.git.{0,1000}offensive_tool_keywordadidnsdumpBy default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks.T1018 - T1087 - T1201 - T1056 - T1039TA0005 - TA0009N/AN/ADiscoveryhttps://github.com/dirkjanm/adidnsdump11N/AN/AN/A109971182025-04-04T09:28:20Z2019-04-24T17:18:46Z5201
361*/ad-ldap-enum.git*.{0,1000}\/ad\-ldap\-enum\.git.{0,1000}offensive_tool_keywordad-ldap-enumAn LDAP based Active Directory user and group enumeration toolT1087 - T1087.001 - T1018 - T1069 - T1069.002TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/CroweCybersecurity/ad-ldap-enum11N/AAD Enumeration64308662023-02-10T19:07:34Z2015-08-25T19:38:39Z5202
362*/adlogin.ps1*.{0,1000}\/adlogin\.ps1.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools11N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z5203
363*/adPEAS.git*.{0,1000}\/adPEAS\.git.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS11N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z5209
364*/adPEAS.ps1*.{0,1000}\/adPEAS\.ps1.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS11N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z5210
365*/adPEAS-Light.ps1*.{0,1000}\/adPEAS\-Light\.ps1.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS11N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z5211
366*/ADRecon.git*.{0,1000}\/ADRecon\.git.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z5213
367*/ADRecon.ps1*.{0,1000}\/ADRecon\.ps1.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon11N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z5214
368*/Advanced_Port_Scanner_*.exe*.{0,1000}\/Advanced_Port_Scanner_.{0,1000}\.exe.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/11N/AN/A710N/AN/AN/AN/A5218
369*/AppFiles/ipscan.exe*.{0,1000}\/AppFiles\/ipscan\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z5382
370*/asreproast_hashes_*.txt*.{0,1000}\/asreproast_hashes_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z5424
371*/AutoSUID.git*.{0,1000}\/AutoSUID\.git.{0,1000}offensive_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID11N/AN/A74375772024-04-29T12:30:35Z2021-11-28T19:44:18Z5493
372*/Azure-AccessPermissions.git*.{0,1000}\/Azure\-AccessPermissions\.git.{0,1000}offensive_tool_keywordAzure-AccessPermissionsEasy to use PowerShell script to enumerate access permissions in an Azure Active Directory environment.T1087.002 - T1018 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/csandker/Azure-AccessPermissions11N/AAD Enumeration62108182023-02-21T06:46:24Z2022-10-19T10:33:24Z5512
373*/AzureHound.ps1*.{0,1000}\/AzureHound\.ps1.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors11N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z5514
374*/backdoored-script.ps1*.{0,1000}\/backdoored\-script\.ps1.{0,1000}offensive_tool_keywordGraphpythonModular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/Graphpython11N/AN/A72145132024-12-07T21:54:00Z2024-07-10T00:04:48Z5531
375*/beacon_202_no_acl.log*.{0,1000}\/beacon_202_no_acl\.log.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound11#logfile #linuxN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z5578
376*/beacon_257-objects.log*.{0,1000}\/beacon_257\-objects\.log.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound10#linuxN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z5579
377*/bhqc.py -*.{0,1000}\/bhqc\.py\s\-.{0,1000}offensive_tool_keywordbloodhound-quickwinSimple script to extract useful informations from the combo BloodHound + Neo4jT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/kaluche/bloodhound-quickwin10N/AAD Enumeration63239262025-04-04T05:11:46Z2021-02-16T16:04:16Z5615
378*/bin/pspsy*.{0,1000}\/bin\/pspsy.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy10#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z5642
379*/BloodHound.exe*.{0,1000}\/BloodHound\.exe.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors11N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z5712
380*/BloodHound.git*.{0,1000}\/BloodHound\.git.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors11N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z5713
381*/bloodhound/enumeration*.{0,1000}\/bloodhound\/enumeration.{0,1000}offensive_tool_keywordBloodHoundA Python based ingestor for BloodHoundT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/fox-it/BloodHound.py11N/AN/A101020883432025-03-28T11:19:13Z2018-02-26T14:44:20Z5716
382*/bloodhound_domain.py*.{0,1000}\/bloodhound_domain\.py.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound11N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z5717
383*/bloodhound_domaintrust.py*.{0,1000}\/bloodhound_domaintrust\.py.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound11N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z5718
384*/bloodhound_gpo.py*.{0,1000}\/bloodhound_gpo\.py.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound11N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z5719
385*/bloodhound_object.py*.{0,1000}\/bloodhound_object\.py.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound11N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z5720
386*/bloodhound_ou.py*.{0,1000}\/bloodhound_ou\.py.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound11N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z5721
387*/bloodhound_schema.py*.{0,1000}\/bloodhound_schema\.py.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound11N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z5722
388*/bloodhound-data*.{0,1000}\/bloodhound\-data.{0,1000}offensive_tool_keywordBloodHoundA Python based ingestor for BloodHoundT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/fox-it/BloodHound.py11N/AN/A101020883432025-03-28T11:19:13Z2018-02-26T14:44:20Z5723
389*/bloodhound-quickwin.git*.{0,1000}\/bloodhound\-quickwin\.git.{0,1000}offensive_tool_keywordbloodhound-quickwinSimple script to extract useful informations from the combo BloodHound + Neo4jT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/kaluche/bloodhound-quickwin11N/AAD Enumeration63239262025-04-04T05:11:46Z2021-02-16T16:04:16Z5724
390*/bofhound.git*.{0,1000}\/bofhound\.git.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound11N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z5745
391*/bofhound.py*.{0,1000}\/bofhound\.py.{0,1000}offensive_tool_keywordShadowHoundset of PowerShell scripts for Active Directory enumerationT1087 - T1018 - T1482 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Friends-Security/ShadowHound11N/AN/A84345362024-12-01T08:06:02Z2024-11-21T15:01:14Z5746
392*/BucketLoot.git*.{0,1000}\/BucketLoot\.git.{0,1000}offensive_tool_keywordBucketLootBucketLoot is an automated S3-compatible bucket inspector that can help users extract assets- flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exposed storage buckets by scanning files that store data in plain-textT1562.007 - T1119 - T1530TA0006 - TA0010N/AN/ADiscoveryhttps://github.com/redhuntlabs/BucketLoot11N/AN/A75409582025-01-22T10:48:27Z2023-07-17T09:06:14Z5849
393*/c lol fuck this*.{0,1000}\/c\slol\sfuck\sthis.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z5888
394*/Cam-Hackers.git*.{0,1000}\/Cam\-Hackers\.git.{0,1000}offensive_tool_keywordCam-HackersHack Cameras CCTV FREET1125TA0007N/AN/ADiscoveryhttps://github.com/AngelSecurityTeam/Cam-Hackers11N/AN/A61020255122024-08-06T18:49:02Z2019-11-16T18:49:35Z5943
395*/CheckSMBSigning.git*.{0,1000}\/CheckSMBSigning\.git.{0,1000}offensive_tool_keywordCheckSMBSigningChecks for SMB signing disabled on all hosts in the networkT1018 - T1550TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Leo4j/CheckSMBSigning11N/AN/A61812023-10-13T11:55:33Z2023-05-17T11:47:52Z6001
396*/CheckSMBSigning.ps1*.{0,1000}\/CheckSMBSigning\.ps1.{0,1000}offensive_tool_keywordCheckSMBSigningChecks for SMB signing disabled on all hosts in the networkT1018 - T1550TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Leo4j/CheckSMBSigning11N/AN/A61812023-10-13T11:55:33Z2023-05-17T11:47:52Z6002
397*/cme_adcs_output_*.txt*.{0,1000}\/cme_adcs_output_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z6114
398*/cme_shares_output_*.{0,1000}\/cme_shares_output_.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z6115
399*/cme_spooler_output_*.{0,1000}\/cme_spooler_output_.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z6116
400*/CMLoot.git*.{0,1000}\/CMLoot\.git.{0,1000}offensive_tool_keywordCMLootFind interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB sharesT1083 - T1039TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/1njected/CMLoot11N/AN/A82175222023-02-05T00:24:31Z2022-06-02T10:59:21Z6118
401*/CMLoot.ps1*.{0,1000}\/CMLoot\.ps1.{0,1000}offensive_tool_keywordCMLootFind interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB sharesT1083 - T1039TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/1njected/CMLoot11N/AN/A82175222023-02-05T00:24:31Z2022-06-02T10:59:21Z6119
402*/coercer_output_*.txt*.{0,1000}\/coercer_output_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z6146
403*/COMHijackToolkit.ps1*.{0,1000}\/COMHijackToolkit\.ps1.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice11N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z6158
404*/COMInjectTarget.dll*.{0,1000}\/COMInjectTarget\.dll.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice11N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z6163
405*/createforestcache.py*.{0,1000}\/createforestcache\.py.{0,1000}offensive_tool_keywordBloodHoundBloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environmentT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/fox-it/BloodHound.py11N/AN/A101020883432025-03-28T11:19:13Z2018-02-26T14:44:20Z6231
406*/Credentials/*.ccache*.{0,1000}\/Credentials\/.{0,1000}\.ccache.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z6246
407*/Credentials/firefox_*.txt*.{0,1000}\/Credentials\/firefox_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z6249
408*/Credentials/msol_*.txt*.{0,1000}\/Credentials\/msol_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z6250
409*/dcsync_*.txt.{0,1000}\/dcsync_.{0,1000}\.txtoffensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z6471
410*/DLLHound.git*.{0,1000}\/DLLHound\.git.{0,1000}offensive_tool_keywordDLLHoundFind potential DLL Sideloads on your windows computerT1574.001 - T1574.002TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/ajm4n/DLLHound11N/AN/A73201222025-01-12T02:28:22Z2024-12-20T02:26:16Z6638
411*/DLLHound.ps1*.{0,1000}\/DLLHound\.ps1.{0,1000}offensive_tool_keywordDLLHoundFind potential DLL Sideloads on your windows computerT1574.001 - T1574.002TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/ajm4n/DLLHound11N/AN/A73201222025-01-12T02:28:22Z2024-12-20T02:26:16Z6639
412*/dnsdump.py*.{0,1000}\/dnsdump\.py.{0,1000}offensive_tool_keywordadidnsdumpBy default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks.T1018 - T1087 - T1201 - T1056 - T1039TA0005 - TA0009N/AN/ADiscoveryhttps://github.com/dirkjanm/adidnsdump11#linuxN/AN/A109971182025-04-04T09:28:20Z2019-04-24T17:18:46Z6673
413*/DomainRecon/*.txt*.{0,1000}\/DomainRecon\/.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z6725
414*/download/v1.0/payload.dll*.{0,1000}\/download\/v1\.0\/payload\.dll.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z6758
415*/download/v1.1.0/pspy32*.{0,1000}\/download\/v1\.1\.0\/pspy32.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z6759
416*/download/v1.1.0/pspy64*.{0,1000}\/download\/v1\.1\.0\/pspy64.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z6760
417*/download/v1.2.0/pspy32*.{0,1000}\/download\/v1\.2\.0\/pspy32.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z6761
418*/download/v1.2.1/pspy32*.{0,1000}\/download\/v1\.2\.1\/pspy32.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z6762
419*/download/v1.2.1/pspy64*.{0,1000}\/download\/v1\.2\.1\/pspy64.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z6763
420*/DSInternals.psd1*.{0,1000}\/DSInternals\.psd1.{0,1000}offensive_tool_keywordDSInternalsDirectory Services Internals (DSInternals) PowerShell Module and Framework - abused by attackersT1003 - T1087 - T1018 - T1110 - T1558TA0003 - TA0006 - TA0007N/ACOZY BEARDiscoveryhttps://github.com/MichaelGrafnetter/DSInternals11N/AAD Enumeration101017602652025-04-16T18:12:55Z2015-12-25T13:23:05Z6805
421*/ecrprivenum.py*.{0,1000}\/ecrprivenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot11N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z6884
422*/ecrpubenum.py*.{0,1000}\/ecrpubenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot11N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z6885
423*/fox-it/BloodHound*.{0,1000}\/fox\-it\/BloodHound.{0,1000}offensive_tool_keywordBloodHoundBloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environmentT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/fox-it/BloodHound.py11N/AN/A101020883432025-03-28T11:19:13Z2018-02-26T14:44:20Z7245
424*/Get-SMBSigning.ps1*.{0,1000}\/Get\-SMBSigning\.ps1.{0,1000}offensive_tool_keywordCheckSMBSigningChecks for SMB signing disabled on all hosts in the networkT1018 - T1550TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Leo4j/CheckSMBSigning11N/AN/A61812023-10-13T11:55:33Z2023-05-17T11:47:52Z7385
425*/gMSA_dump_*.txt*.{0,1000}\/gMSA_dump_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z7531
426*/GMSAPasswordReader.exe*.{0,1000}\/GMSAPasswordReader\.exe.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors11N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z7535
427*/gofetch.exe*.{0,1000}\/gofetch\.exe.{0,1000}offensive_tool_keywordGoFetchGoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.T1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/ADispossessorDiscoveryhttps://github.com/GoFetchAD/GoFetch11N/AN/A107633992017-06-20T14:15:10Z2017-04-11T10:45:23Z7561
428*/GoFetch.git*.{0,1000}\/GoFetch\.git.{0,1000}offensive_tool_keywordGoFetchGoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.T1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/ADispossessorDiscoveryhttps://github.com/GoFetchAD/GoFetch11N/AN/A107633992017-06-20T14:15:10Z2017-04-11T10:45:23Z7562
429*/GONET-Scanner/*.{0,1000}\/GONET\-Scanner\/.{0,1000}offensive_tool_keywordGONET-Scannerport scanner and arp discover in goT1595TA0001N/AN/ADiscoveryhttps://github.com/luijait/GONET-Scanner11N/Anetwork exploitation toolN/A182212022-03-10T04:35:58Z2022-02-02T19:39:09Z7577
430*/GPOBrowser.py*.{0,1000}\/GPOBrowser\.py.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck11N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z7609
431*/Graphpython.git*.{0,1000}\/Graphpython\.git.{0,1000}offensive_tool_keywordGraphpythonModular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/Graphpython11N/AN/A72145132024-12-07T21:54:00Z2024-07-10T00:04:48Z7617
432*/Graphpython.py*.{0,1000}\/Graphpython\.py.{0,1000}offensive_tool_keywordGraphpythonModular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/Graphpython11N/AN/A72145132024-12-07T21:54:00Z2024-07-10T00:04:48Z7618
433*/Group3r.git*.{0,1000}\/Group3r\.git.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r11N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z7636
434*/Group3r/releases/download/*.{0,1000}\/Group3r\/releases\/download\/.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r11N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z7637
435*/HijackDLL-CreateRemoteThread.cpp*.{0,1000}\/HijackDLL\-CreateRemoteThread\.cpp.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice11N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z7774
436*/HijackDll-Process.cpp*.{0,1000}\/HijackDll\-Process\.cpp.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice11N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z7775
437*/HijackDLL-Threads.*.{0,1000}\/HijackDLL\-Threads\..{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice11N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z7776
438*/iamassumeroleenum.py*.{0,1000}\/iamassumeroleenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot11N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z8000
439*/Invoke-Adeleginator*.{0,1000}\/Invoke\-Adeleginator.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator11N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z8137
440*/Invoke-ADEnum.git*.{0,1000}\/Invoke\-ADEnum\.git.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum11N/AN/A75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z8138
441*/Invoke-DCOM.ps1*.{0,1000}\/Invoke\-DCOM\.ps1.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors11N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z8146
442*/Invoke-Maldaptive.git*.{0,1000}\/Invoke\-Maldaptive\.git.{0,1000}greyware_tool_keywordInvoke-MaldaptiveMaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection.T1027TA0005 - TA0007N/AN/ADiscoveryhttps://github.com/MaLDAPtive/Invoke-Maldaptive11N/AN/A73277262024-08-07T21:12:45Z2024-08-07T20:43:52Z8153
443*/Invoke-SessionHunter.git*.{0,1000}\/Invoke\-SessionHunter\.git.{0,1000}offensive_tool_keywordInvoke-SessionHunterRetrieve and display information about active user sessions on remote computers. No admin privileges requiredT1033 - T1078 - T1110TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-SessionHunter11N/AN/A72183202024-08-12T13:15:10Z2023-08-13T13:22:05Z8164
444*/ipscan.exe*.{0,1000}\/ipscan\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan11N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8199
445*/ipscan.git*.{0,1000}\/ipscan\.git.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan11N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8200
446*/ipscan_*_amd64.deb*.{0,1000}\/ipscan_.{0,1000}_amd64\.deb.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10#linuxN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8201
447*/ipscan2-binary/*.exe*.{0,1000}\/ipscan2\-binary\/.{0,1000}\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8202
448*/ipscan-any-*.jar*.{0,1000}\/ipscan\-any\-.{0,1000}\.jar.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10#linuxN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z8203
449*/ItWasAllADream.git*.{0,1000}\/ItWasAllADream\.git.{0,1000}offensive_tool_keywordItWasAllADreamA PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCET1046 - T1210.002 - T1047TA0007 - TA0002N/AN/ADiscoveryhttps://github.com/byt3bl33d3r/ItWasAllADream11N/AN/A787961232024-05-19T16:25:52Z2021-07-05T20:13:49Z8218
450*/jecretz.git*.{0,1000}\/jecretz\.git.{0,1000}offensive_tool_keywordjecretzJira Secret Hunter - Helps you find credentials and sensitive contents in Jira ticketsT1552 - T1114 - T1119 - T1070TA0006 - TA0009 - TA0005N/AScattered Spider*Discoveryhttps://github.com/sahadnk72/jecretz11N/AN/A714392022-12-08T10:00:11Z2020-05-25T14:40:28Z8234
451*/jecretz.py*.{0,1000}\/jecretz\.py.{0,1000}offensive_tool_keywordjecretzJira Secret Hunter - Helps you find credentials and sensitive contents in Jira ticketsT1552 - T1114 - T1119 - T1070TA0006 - TA0009 - TA0005N/AScattered Spider*Discoveryhttps://github.com/sahadnk72/jecretz11N/AN/A714392022-12-08T10:00:11Z2020-05-25T14:40:28Z8235
452*/john.git*.{0,1000}\/john\.git.{0,1000}offensive_tool_keywordldapdomaindumpActive Directory information dumper via LDAPT1087 - T1005 - T1016TA0007N/AEMBER BEARDiscoveryhttps://github.com/dirkjanm/ldapdomaindump11N/AN/A101012422012025-04-06T13:31:57Z2016-05-24T18:46:56Z8242
453*/keepass_discover_*.txt*.{0,1000}\/keepass_discover_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z8301
454*/kerberoast_hashes_*.txt*.{0,1000}\/kerberoast_hashes_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z8325
455*/Killchain.ps1*.{0,1000}\/Killchain\.ps1.{0,1000}offensive_tool_keywordGraphpythonModular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/Graphpython11N/AN/A72145132024-12-07T21:54:00Z2024-07-10T00:04:48Z8362
456*/laconicwolf/burp-extensions*.{0,1000}\/laconicwolf\/burp\-extensions.{0,1000}offensive_tool_keywordburpsuiteA collection of scripts to extend Burp SuiteT1556 - T1556.001 - T1556.002 - T1556.003 - T1557 - T1558 - T1573 - T1574TA0003 - TA0004 - TA0005 - TA0006 - TA0008N/ABlack BastaDiscoveryhttps://github.com/laconicwolf/burp-extensions11N/Anetwork exploitation toolN/A2142312019-04-08T00:49:45Z2018-03-23T16:05:01Z8420
457*/lambdaenum.py*.{0,1000}\/lambdaenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot11N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z8432
458*/lansearch.exe*.{0,1000}\/lansearch\.exe.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/11N/AN/A710N/AN/AN/AN/A8435
459*/LansweeperSetup_*.exe*.{0,1000}\/LansweeperSetup_.{0,1000}\.exe.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/11N/AN/A67N/AN/AN/AN/A8436
460*/laps_dump_*.txt*.{0,1000}\/laps_dump_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z8440
461*/LAPSToolkit.git*.{0,1000}\/LAPSToolkit\.git.{0,1000}offensive_tool_keywordLAPSToolkitFunctions written in PowerShell that leverage PowerView to audit and attack Active Directory environments that have deployed Microsofts Local Administrator Password Solution (LAPS). It includes finding groups specifically delegated by sysadmins. finding users with All Extended Rights that can view passwords. and viewing all computers with LAPS enabledT1087.001 - T1069 - T1069.003 - T1069.007 - T1069.002 - T1069.001TA0007 - TA0008 - TA0009N/AScattered Spider*Discoveryhttps://github.com/leoloobeek/LAPSToolkit11N/AN/A1098591192018-01-31T14:45:35Z2016-04-27T00:06:20Z8442
462*/ld.so /bin/sh -p*.{0,1000}\/ld\.so\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z8463
463*/ldap_search_bof.py*.{0,1000}\/ldap_search_bof\.py.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound11N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z8466
464*/ldapnomnom.git*.{0,1000}\/ldapnomnom\.git.{0,1000}offensive_tool_keywordldapnomnomAnonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)T1110.003 - T1205TA0007N/AN/ADiscoveryhttps://github.com/lkarlslund/ldapnomnom11N/AN/A6101030802024-11-09T10:15:13Z2022-09-18T10:35:09Z8469
465*/ldapnomnom/releases/download/*.{0,1000}\/ldapnomnom\/releases\/download\/.{0,1000}offensive_tool_keywordldapnomnomAnonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)T1110.003 - T1205TA0007N/AN/ADiscoveryhttps://github.com/lkarlslund/ldapnomnom11N/AN/A6101030802024-11-09T10:15:13Z2022-09-18T10:35:09Z8470
466*/ldapnomnom@latest*.{0,1000}\/ldapnomnom\@latest.{0,1000}offensive_tool_keywordldapnomnomAnonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)T1110.003 - T1205TA0007N/AN/ADiscoveryhttps://github.com/lkarlslund/ldapnomnom11N/AN/A6101030802024-11-09T10:15:13Z2022-09-18T10:35:09Z8471
467*/LDAP-Password-Hunter.git*.{0,1000}\/LDAP\-Password\-Hunter\.git.{0,1000}offensive_tool_keywordLDAP-Password-HunterPassword Hunter in Active DirectoryT1087.002TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/LDAP-Password-Hunter11N/AN/A72198252023-01-06T15:32:34Z2021-07-26T14:27:01Z8473
468*/LDAPPER.git*.{0,1000}\/LDAPPER\.git.{0,1000}offensive_tool_keywordLDAPPERLDAP Querying without the SuckT1087 - T1069 - T1018TA0007N/AN/ADiscoveryhttps://github.com/shellster/LDAPPER11N/AN/A7199112024-11-09T03:53:26Z2020-06-17T16:53:35Z8474
469*/ldapper.py*.{0,1000}\/ldapper\.py.{0,1000}offensive_tool_keywordLDAPPERLDAP Querying without the SuckT1087 - T1069 - T1018TA0007N/AN/ADiscoveryhttps://github.com/shellster/LDAPPER11N/AN/A7199112024-11-09T03:53:26Z2020-06-17T16:53:35Z8475
470*/LDAPPER-master*.{0,1000}\/LDAPPER\-master.{0,1000}offensive_tool_keywordLDAPPERLDAP Querying without the SuckT1087 - T1069 - T1018TA0007N/AN/ADiscoveryhttps://github.com/shellster/LDAPPER10N/AN/A7199112024-11-09T03:53:26Z2020-06-17T16:53:35Z8476
471*/ldapph.db*.{0,1000}\/ldapph\.db.{0,1000}offensive_tool_keywordLDAP-Password-HunterPassword Hunter in Active DirectoryT1087.002TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/LDAP-Password-Hunter10N/AN/A72198252023-01-06T15:32:34Z2021-07-26T14:27:01Z8477
472*/ldeepDump*.{0,1000}\/ldeepDump.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z8485
473*/LibSnaffle*.{0,1000}\/LibSnaffle.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r11N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z8509
474*/linWinPwn*.{0,1000}\/linWinPwn.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z8550
475*/loadbalancer.py*.{0,1000}\/loadbalancer\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot11N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z8568
476*/localbrute.ps1*.{0,1000}\/localbrute\.ps1.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools11N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z8582
477*/LocalShellExtParse.git*.{0,1000}\/LocalShellExtParse\.git.{0,1000}offensive_tool_keywordLocalShellExtParseScript to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User.T1547.009 - T1129TA0003 - TA0007N/AN/ADiscoveryhttps://github.com/herrcore/LocalShellExtParse11N/AN/A912042015-06-08T16:55:38Z2015-06-05T03:23:13Z8589
478*/LocalShellExtParse.py*.{0,1000}\/LocalShellExtParse\.py.{0,1000}offensive_tool_keywordLocalShellExtParseScript to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User.T1547.009 - T1129TA0003 - TA0007N/AN/ADiscoveryhttps://github.com/herrcore/LocalShellExtParse11N/AN/A912042015-06-08T16:55:38Z2015-06-05T03:23:13Z8590
479*/Locksmith.git*.{0,1000}\/Locksmith\.git.{0,1000}offensive_tool_keywordLocksmithA tiny tool to identify and remediate common misconfigurations in Active Directory Certificate ServicesT1552.006 - T1222 - T1046TA0007 - TA0040 - TA0043N/AN/ADiscoveryhttps://github.com/TrimarcJake/Locksmith11N/AN/A81010861002025-04-21T12:43:50Z2022-04-28T01:37:32Z8605
480*/lsa_dump_*.txt*.{0,1000}\/lsa_dump_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z8637
481*/MANSPIDER.git*.{0,1000}\/MANSPIDER\.git.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER11N/AN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z8719
482*/manspider_*.log*.{0,1000}\/manspider_.{0,1000}\.log.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10#linuxN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z8720
483*/manspider_output*.txt.{0,1000}\/manspider_output.{0,1000}\.txtoffensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z8721
484*/manspiderDump*.{0,1000}\/manspiderDump.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z8722
485*/MDE_Enum.git*.{0,1000}\/MDE_Enum\.git.{0,1000}offensive_tool_keywordMDE_Enumextract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rulesT1070.006TA0005 - TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/0xsp-SRD/MDE_Enum11N/AN/A82198182024-06-10T18:40:27Z2024-06-06T15:54:44Z8732
486*/Minimalistic-offensive-security-tools.git*.{0,1000}\/Minimalistic\-offensive\-security\-tools\.git.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools11N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z8858
487*/Moriarty.exe*.{0,1000}\/Moriarty\.exe.{0,1000}offensive_tool_keywordMoriartyMoriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments.T1068 - T1083TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/BC-SECURITY/Moriarty11N/AN/A76510672024-08-07T15:06:31Z2023-12-11T14:15:33Z8895
488*/Moriarty.git*.{0,1000}\/Moriarty\.git.{0,1000}offensive_tool_keywordMoriartyMoriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments.T1068 - T1083TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/BC-SECURITY/Moriarty11N/AN/A76510672024-08-07T15:06:31Z2023-12-11T14:15:33Z8897
489*/msi_search.ps1*.{0,1000}\/msi_search\.ps1.{0,1000}offensive_tool_keywordmsi-searchThis tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairsT1005 TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/mandiant/msi-search11N/AN/A103276312023-07-20T18:12:49Z2023-06-29T18:31:56Z8937
490*/msi-search.git*.{0,1000}\/msi\-search\.git.{0,1000}offensive_tool_keywordmsi-searchThis tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairsT1005 TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/mandiant/msi-search11N/AN/A103276312023-07-20T18:12:49Z2023-06-29T18:31:56Z8938
491*/mtth-bfft/adeleg/releases*.{0,1000}\/mtth\-bfft\/adeleg\/releases.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator11N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z8963
492*/netscan.exe*.{0,1000}\/netscan\.exe.{0,1000}greyware_tool_keywordnetscanSoftPerfect Network Scanner abused by threat actorT1040 - T1046 - T1018TA0007 - TA0010 - TA0001N/ABlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - LynxDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/Anetwork exploitation tool610N/AN/AN/AN/A9108
493*/netscan.exe*.{0,1000}\/netscan\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/AN/A810N/AN/AN/AN/A9109
494*/netscan_linux.tar.gz*.{0,1000}\/netscan_linux\.tar\.gz.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11#linuxN/A810N/AN/AN/AN/A9110
495*/netscan_macos.dmg*.{0,1000}\/netscan_macos\.dmg.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11#macosN/A810N/AN/AN/AN/A9111
496*/netscan_setup.exe*.{0,1000}\/netscan_setup\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/AN/A810N/AN/AN/AN/A9112
497*/netscan64.exe*.{0,1000}\/netscan64\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/11N/AN/A810N/AN/AN/AN/A9113
498*/NetSess.exe*.{0,1000}\/NetSess\.exe.{0,1000}offensive_tool_keywordNetSessCommand line tool to enumerate NetBIOS sessions on a specified local or remote machine. T1016 - T1046 - T1087TA0007 - TA0043N/AMUSTANG PANDADiscoveryhttps://www.joeware.net/freetools/tools/netsess/11N/AN/A79N/AN/AN/AN/A9114
499*/NetSess.zip*.{0,1000}\/NetSess\.zip.{0,1000}offensive_tool_keywordNetSessCommand line tool to enumerate NetBIOS sessions on a specified local or remote machine. T1016 - T1046 - T1087TA0007 - TA0043N/AMUSTANG PANDADiscoveryhttps://www.joeware.net/freetools/tools/netsess/11N/AN/A79N/AN/AN/AN/A9115
500*/NimScan.exe*.{0,1000}\/NimScan\.exe.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan11N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z9175
501*/NimScan.git*.{0,1000}\/NimScan\.git.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan11N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z9176
502*/NimScan.nim*.{0,1000}\/NimScan\.nim.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan11N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z9177
503*/Nmap/folder/check15*.{0,1000}\/Nmap\/folder\/check15.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9198
504*/Nmap/folder/check16*.{0,1000}\/Nmap\/folder\/check16.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9199
505*/Nmap/folder/check17*.{0,1000}\/Nmap\/folder\/check17.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9200
506*/nmap_smb_scan_all_*.txt*.{0,1000}\/nmap_smb_scan_all_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z9201
507*/nmaplowercheck15*.{0,1000}\/nmaplowercheck15.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://nmap.org/book/nse-usage.html11N/Awill appear on your server access logs if you are scanned by nmap810N/AN/AN/AN/A9204
508*/nmaplowercheck16*.{0,1000}\/nmaplowercheck16.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9205
509*/nmaplowercheck17*.{0,1000}\/nmaplowercheck17.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9206
510*/NmapUpperCheck15*.{0,1000}\/NmapUpperCheck15.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9209
511*/NmapUpperCheck16*.{0,1000}\/NmapUpperCheck16.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9210
512*/NmapUpperCheck17*.{0,1000}\/NmapUpperCheck17.{0,1000}greyware_tool_keywordnmapNmap (Network Mapper) is a free and open source utility for network discovery and security auditingT1595 - T1592 - T1589 - T1590 - T1591 - T1190 - T1059 - T1046 - T1016 - T1049 - T1007TA0001 - TA0007 - TA0043N/AQilin - Cactus - EMBER BEAR - ENERGETIC BEAR - MUSTANG PANDA - TA2101 - FIN13 - Black BastaDiscoveryhttps://github.com/nmap/nmap/blob/635675b1430a89e950f71112d3bfc74feee4b19a/nselib/http.lua#L260011N/Awill appear on your server access logs if you are scanned by nmap8101095325052025-04-21T20:45:05Z2012-03-09T14:47:43Z9211
513*/ntds_dump_*.txt*.{0,1000}\/ntds_dump_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z9278
514*/NTLMRecon*.{0,1000}\/NTLMRecon.{0,1000}offensive_tool_keywordNTMLReconA fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domainsT1595TA0009N/AN/ADiscoveryhttps://github.com/pwnfoo/NTLMRecon11N/AN/AN/A5481702024-06-24T18:11:12Z2019-12-01T06:06:30Z9289
515*/NTLMRecon.git*.{0,1000}\/NTLMRecon\.git.{0,1000}offensive_tool_keywordNTMLReconEnumerate information from NTLM authentication enabled web endpointsT1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001TA0009 - TA0007 - TA0006N/AN/ADiscoveryhttps://github.com/puzzlepeaches/NTLMRecon11N/AN/A813532023-08-16T14:34:10Z2023-08-09T12:10:42Z9290
516*/ntlmrecon/*.py*.{0,1000}\/ntlmrecon\/.{0,1000}\.py.{0,1000}offensive_tool_keywordNTMLReconEnumerate information from NTLM authentication enabled web endpointsT1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001TA0009 - TA0007 - TA0006N/AN/ADiscoveryhttps://github.com/puzzlepeaches/NTLMRecon11N/AN/A813532023-08-16T14:34:10Z2023-08-09T12:10:42Z9291
517*/ntlmutil.py*.{0,1000}\/ntlmutil\.py.{0,1000}offensive_tool_keywordNTMLReconA fast and flexible NTLM reconnaissance tool without external dependencies. Useful to find out information about NTLM endpoints when working with a large set of potential IP addresses and domainsT1595TA0009N/AN/ADiscoveryhttps://github.com/pwnfoo/NTLMRecon11N/AN/AN/A5481702024-06-24T18:11:12Z2019-12-01T06:06:30Z9307
518*/ntlmutil.py*.{0,1000}\/ntlmutil\.py.{0,1000}offensive_tool_keywordNTMLReconEnumerate information from NTLM authentication enabled web endpointsT1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001TA0009 - TA0007 - TA0006N/AN/ADiscoveryhttps://github.com/puzzlepeaches/NTLMRecon11N/AN/A813532023-08-16T14:34:10Z2023-08-09T12:10:42Z9308
519*/nullinux.git*.{0,1000}\/nullinux\.git.{0,1000}offensive_tool_keywordnullinuxInternal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB.T1087 - T1016 - T1077 - T1018TA0007 - TA0006N/AN/ADiscoveryhttps://github.com/m8sec/nullinux11#linuxN/A765751012024-06-19T14:29:09Z2016-04-28T16:45:02Z9321
520*/nullinux.py*.{0,1000}\/nullinux\.py.{0,1000}offensive_tool_keywordnullinuxInternal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB.T1087 - T1016 - T1077 - T1018TA0007 - TA0006N/AN/ADiscoveryhttps://github.com/m8sec/nullinux11#linuxN/A765751012024-06-19T14:29:09Z2016-04-28T16:45:02Z9322
521*/nullinux_users.txt*.{0,1000}\/nullinux_users\.txt.{0,1000}offensive_tool_keywordnullinuxInternal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB.T1087 - T1016 - T1077 - T1018TA0007 - TA0006N/AN/ADiscoveryhttps://github.com/m8sec/nullinux10#linuxN/A765751012024-06-19T14:29:09Z2016-04-28T16:45:02Z9323
522*/opt/cobaltstrike/logs*.{0,1000}\/opt\/cobaltstrike\/logs.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound10#linuxN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z9402
523*/opt/lwp-scripts*.{0,1000}\/opt\/lwp\-scripts.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z9417
524*/opt/lwp-wordlists*.{0,1000}\/opt\/lwp\-wordlists.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z9418
525*/perf stat /bin/sh -p*.{0,1000}\/perf\sstat\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z9602
526*/perl -e 'exec \"/bin/sh\"*.{0,1000}\/perl\s\-e\s\'exec\s\\\"\/bin\/sh\\\".{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z9607
527*/PipeViewer.exe*.{0,1000}\/PipeViewer\.exe.{0,1000}offensive_tool_keywordPipeViewer A tool that shows detailed information about named pipes in WindowsT1022.002 - T1056.002TA0005 - TA0009N/AN/Adiscoveryhttps://github.com/cyberark/PipeViewer11N/AN/A57620552024-11-15T09:55:35Z2022-12-22T12:35:34Z9700
528*/PipeViewer.git*.{0,1000}\/PipeViewer\.git.{0,1000}offensive_tool_keywordPipeViewer A tool that shows detailed information about named pipes in WindowsT1022.002 - T1056.002TA0005 - TA0009N/AN/Adiscoveryhttps://github.com/cyberark/PipeViewer11N/AN/A57620552024-11-15T09:55:35Z2022-12-22T12:35:34Z9701
529*/PipeViewer.sln*.{0,1000}\/PipeViewer\.sln.{0,1000}offensive_tool_keywordPipeViewer A tool that shows detailed information about named pipes in WindowsT1022.002 - T1056.002TA0005 - TA0009N/AN/Adiscoveryhttps://github.com/cyberark/PipeViewer11N/AN/A57620552024-11-15T09:55:35Z2022-12-22T12:35:34Z9702
530*/PipeViewer/Program.cs*.{0,1000}\/PipeViewer\/Program\.cs.{0,1000}offensive_tool_keywordPipeViewer A tool that shows detailed information about named pipes in WindowsT1022.002 - T1056.002TA0005 - TA0009N/AN/Adiscoveryhttps://github.com/cyberark/PipeViewer11N/AN/A57620552024-11-15T09:55:35Z2022-12-22T12:35:34Z9703
531*/polenum.py*.{0,1000}\/polenum\.py.{0,1000}offensive_tool_keywordpolenumUses Impacket Library to get the password policy from a windows machineT1012 - T1596TA0009 - TA0007N/AN/ADiscoveryhttps://salsa.debian.org/pkg-security-team/polenum10#linuxN/A810N/AN/AN/AN/A9725
532*/PortQry.exe*.{0,1000}\/PortQry\.exe.{0,1000}greyware_tool_keywordPortQryMicrosoft port scanning tool abused by threat actorsT1046 - T1016 - T1049TA0007N/AAPT15Discoveryhttps://www.microsoft.com/en-us/download/details.aspx?id=1714811N/AN/A67N/AN/AN/AN/A9748
533*/PortQryV2.exe*.{0,1000}\/PortQryV2\.exe.{0,1000}greyware_tool_keywordPortQryMicrosoft port scanning tool abused by threat actorsT1046 - T1016 - T1049TA0007N/AAPT15Discoveryhttps://www.microsoft.com/en-us/download/details.aspx?id=1714811N/AN/A67N/AN/AN/AN/A9749
534*/portscan.git*.{0,1000}\/portscan\.git.{0,1000}offensive_tool_keywordportscanA simple TCP and UDP portscanner written in GoT1595 - T1596 - T1594TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/zs5460/portscan11N/AN/AN/A11442022-11-11T09:26:47Z2019-06-04T09:00:00Z9763
535*/portscan/releases/*.{0,1000}\/portscan\/releases\/.{0,1000}offensive_tool_keywordportscanA simple TCP and UDP portscanner written in GoT1595 - T1596 - T1594TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/zs5460/portscan11N/AN/AN/A11442022-11-11T09:26:47Z2019-06-04T09:00:00Z9766
536*/port-scan-tcp.ps1*.{0,1000}\/port\-scan\-tcp\.ps1.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools11N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z9768
537*/port-scan-udp.ps1*.{0,1000}\/port\-scan\-udp\.ps1.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools11N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z9769
538*/PowerView.ps1*.{0,1000}\/PowerView\.ps1.{0,1000}offensive_tool_keywordSharpViewC# implementation of harmj0y's PowerViewT1018 - T1482 - T1087.002 - T1069.002TA0007 - TA0003 - TA0001N/AConti - APT29Discoveryhttps://github.com/tevora-threat/SharpView/11N/AN/A101010321962024-03-22T16:34:09Z2018-07-24T21:15:04Z9837
539*/powerview.py*.{0,1000}\/powerview\.py.{0,1000}offensive_tool_keywordpowerviewPowerView.py is an alternative for the awesome original PowerView.ps1T1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/aniqfakhrul/powerview.py10N/AN/A107622662025-04-22T09:01:39Z2022-06-19T16:13:04Z9838
540*/powerview.py.git*.{0,1000}\/powerview\.py\.git.{0,1000}offensive_tool_keywordpowerviewPowerView.py is an alternative for the awesome original PowerView.ps1T1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/aniqfakhrul/powerview.py11N/AN/A107622662025-04-22T09:01:39Z2022-06-19T16:13:04Z9839
541*/pslist.exe*.{0,1000}\/pslist\.exe.{0,1000}greyware_tool_keywordpslistMicrosoft sysinternal comandline tool to list running process abused by threat actorsT1057 - T1012 - T1106TA0007N/AAPT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - ElfinDiscoveryhttps://learn.microsoft.com/pt-br/sysinternals/downloads/pslist11N/AN/A39N/AN/AN/AN/A9972
542*/pslist64.exe*.{0,1000}\/pslist64\.exe.{0,1000}greyware_tool_keywordpslistMicrosoft sysinternal comandline tool to list running process abused by threat actorsT1057 - T1012 - T1106TA0007N/AAPT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - ElfinDiscoveryhttps://learn.microsoft.com/pt-br/sysinternals/downloads/pslist11N/AN/A39N/AN/AN/AN/A9973
543*/PSnmap.git*.{0,1000}\/PSnmap\.git.{0,1000}offensive_tool_keywordPsnmapPowershell scanner (nmap like)T1086 - T1046 - T1059TA0007N/ABlack BastaDiscoveryhttps://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps111N/AN/A72178642024-08-23T18:24:20Z2015-01-24T10:46:41Z9976
544*/PSnmap.ps1*.{0,1000}\/PSnmap\.ps1.{0,1000}offensive_tool_keywordPsnmapPowershell scanner (nmap like)T1086 - T1046 - T1059TA0007N/ABlack BastaDiscoveryhttps://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps110N/AN/A72178642024-08-23T18:24:20Z2015-01-24T10:46:41Z9977
545*/PSnmap.psd1*.{0,1000}\/PSnmap\.psd1.{0,1000}offensive_tool_keywordPsnmapPowershell scanner (nmap like)T1086 - T1046 - T1059TA0007N/ABlack BastaDiscoveryhttps://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps111N/AN/A72178642024-08-23T18:24:20Z2015-01-24T10:46:41Z9978
546*/PSnmap.psm1*.{0,1000}\/PSnmap\.psm1.{0,1000}offensive_tool_keywordPsnmapPowershell scanner (nmap like)T1086 - T1046 - T1059TA0007N/ABlack BastaDiscoveryhttps://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps111N/AN/A72178642024-08-23T18:24:20Z2015-01-24T10:46:41Z9979
547*/pspy -*.{0,1000}\/pspy\s\-.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1514 - T1082TA0007 - TA0009 - TA0003N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy10#linuxN/A61053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9984
548*/pspy.git*.{0,1000}\/pspy\.git.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1514 - T1082TA0007 - TA0009 - TA0003N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A61053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9986
549*/pspy.git*.{0,1000}\/pspy\.git.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9987
550*/pspy.go*.{0,1000}\/pspy\.go.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1514 - T1082TA0007 - TA0009 - TA0003N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy10#linuxN/A61053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9988
551*/pspy/cmd*.{0,1000}\/pspy\/cmd.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1514 - T1082TA0007 - TA0009 - TA0003N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy10#linuxN/A61053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9989
552*/pspy/cmd/*.{0,1000}\/pspy\/cmd\/.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy10#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9990
553*/pspy/pspy.go*.{0,1000}\/pspy\/pspy\.go.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9991
554*/pspy32*.{0,1000}\/pspy32.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1514 - T1082TA0007 - TA0009 - TA0003N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A61053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9992
555*/pspy64*.{0,1000}\/pspy64.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1514 - T1082TA0007 - TA0009 - TA0003N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A61053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9993
556*/psscanner.go*.{0,1000}\/psscanner\.go.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1514 - T1082TA0007 - TA0009 - TA0003N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy10#linuxN/A61053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9995
557*/psscanner/psscanner.go*.{0,1000}\/psscanner\/psscanner\.go.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy11#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z9996
558*/pwn_php.me*.{0,1000}\/pwn_php\.me.{0,1000}offensive_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z10044
559*/pwn_python.me*.{0,1000}\/pwn_python\.me.{0,1000}offensive_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z10045
560*/pwn_tclsh.me*.{0,1000}\/pwn_tclsh\.me.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z10046
561*/pyshark.git*.{0,1000}\/pyshark\.git.{0,1000}greyware_tool_keywordpysharkPython wrapper for tshark allowing python packet parsing using wireshark dissectorsT1040 - T1213 - T1105 - T1572TA0009 - TA0007N/AN/ADiscoveryhttps://github.com/KimiNewt/pyshark11N/AN/A61023554392024-12-04T15:41:20Z2013-12-28T14:38:22Z10096
562*/quiet-riot.git*.{0,1000}\/quiet\-riot\.git.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot11N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z10134
563*/rattler.git*.{0,1000}\/rattler\.git.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler11N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z10179
564*/Rattler_32.exe*.{0,1000}\/Rattler_32\.exe.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler11N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z10180
565*/Rattler_x64.exe*.{0,1000}\/Rattler_x64\.exe.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler11N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z10181
566*/rdpscan --*.{0,1000}\/rdpscan\s\-\-.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan10#linuxN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10222
567*/rdpscan.git*.{0,1000}\/rdpscan\.git.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan11N/AN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10223
568*/rdpscan-macos.zip*.{0,1000}\/rdpscan\-macos\.zip.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan11N/AN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10224
569*/rdpscan-windows.zip*.{0,1000}\/rdpscan\-windows\.zip.{0,1000}greyware_tool_keywordrdpscanA quick scanner for the CVE-2019-0708 "BlueKeep" vulnerabilityT1210 - T1046TA0001 - TA0008N/ADispossessorDiscoveryhttps://github.com/robertdavidgraham/rdpscan11N/AN/A6109042422019-06-22T21:48:45Z2019-05-23T22:50:12Z10225
570*/Recon-AD.git*.{0,1000}\/Recon\-AD\.git.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD11N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z10254
571*/Recon-AD-AllLocalGroups.dll.{0,1000}\/Recon\-AD\-AllLocalGroups\.dlloffensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD11N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z10255
572*/Recon-AD-Computers.dll.{0,1000}\/Recon\-AD\-Computers\.dlloffensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD11N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z10257
573*/Recon-AD-Domain.dll.{0,1000}\/Recon\-AD\-Domain\.dlloffensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD11N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z10259
574*/Recon-AD-Groups.dll.{0,1000}\/Recon\-AD\-Groups\.dlloffensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD11N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z10261
575*/Recon-AD-LocalGroups.dll*.{0,1000}\/Recon\-AD\-LocalGroups\.dll.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD11N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z10264
576*/Recon-AD-Users.dll*.{0,1000}\/Recon\-AD\-Users\.dll.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD11N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z10267
577*/rockyou.txt*.{0,1000}\/rockyou\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z10494
578*/rusthound.exe*.{0,1000}\/rusthound\.exe.{0,1000}offensive_tool_keywordRustHoundActive Directory data collector for BloodHound written in RustT1087.002 - T1018 - T1059.003TA0007 - TA0001 - TA0002N/AN/ADiscoveryhttps://github.com/OPENCYBER-FR/RustHound11N/AAD Enumeration9101013982024-10-21T18:58:20Z2022-10-12T05:54:35Z10643
579*/RustHound.git*.{0,1000}\/RustHound\.git.{0,1000}offensive_tool_keywordRustHoundActive Directory data collector for BloodHound written in RustT1087.002 - T1018 - T1059.003TA0007 - TA0001 - TA0002N/AN/ADiscoveryhttps://github.com/OPENCYBER-FR/RustHound11N/AAD Enumeration9101013982024-10-21T18:58:20Z2022-10-12T05:54:35Z10644
580*/rvim -c ':py3 import os*os.execl(\"/bin/sh\*.{0,1000}\/rvim\s\-c\s\'\:py3\simport\sos.{0,1000}os\.execl\(\\\"\/bin\/sh\\.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z10651
581*/RWXfinder.git*.{0,1000}\/RWXfinder\.git.{0,1000}offensive_tool_keywordrwxfinderThe program uses the Windows API functions to traverse through directories and locate DLL files with RWX sectionT1059.001 - T1059.003 - T1070.004TA0002 - TA0005 - TA0040N/AN/ADiscoveryhttps://github.com/pwnsauc3/RWXFinder11N/AN/A52101142023-07-15T15:42:55Z2023-07-14T07:47:21Z10653
582*/s3aclenum.py*.{0,1000}\/s3aclenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot11N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z10654
583*/s3enum.py*.{0,1000}\/s3enum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot11N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z10656
584*/sam_dump_*.txt*.{0,1000}\/sam_dump_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z10675
585*/sandcat.git*.{0,1000}\/sandcat\.git.{0,1000}offensive_tool_keywordsandcatAn open-source pentest oriented web browserT1216 - T1590 - T1071TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/syhunt/sandcat11N/AN/A66525722023-12-21T18:40:27Z2014-05-20T23:36:21Z10685
586*/scannerPort.go*.{0,1000}\/scannerPort\.go.{0,1000}offensive_tool_keywordGONET-Scannerport scanner and arp discover in goT1595TA0001N/AN/ADiscoveryhttps://github.com/luijait/GONET-Scanner11N/Anetwork exploitation toolN/A182212022-03-10T04:35:58Z2022-02-02T19:39:09Z10713
587*/Scans/servers_all_smb*.txt*.{0,1000}\/Scans\/servers_all_smb.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z10715
588*/SearchShares.ps1*.{0,1000}\/SearchShares\.ps1.{0,1000}offensive_tool_keywordSearchOpenFileSharesSearches open files shares for password files or database backups - Extend as you see fitT1083 - T1135 - T1005 - T1025TA0007 - TA0009N/ADispossessorDiscoveryhttps://github.com/fashionproof/SearchOpenFileShares11N/AN/A712962019-12-13T12:37:42Z2019-09-21T13:50:26Z10751
589*/secretsdump_*.txt*.{0,1000}\/secretsdump_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z10773
590*/secretsmanagerenum.py*.{0,1000}\/secretsmanagerenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot11N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z10776
591*/SeeYouCM-Thief*.{0,1000}\/SeeYouCM\-Thief.{0,1000}offensive_tool_keywordSeeYouCM-ThiefSimple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentialsT1110.001 - T1005 - T1071.001TA0001 - TA0011 - TA0005N/AN/ADiscoveryhttps://github.com/trustedsec/SeeYouCM-Thief11N/AN/A92189352023-05-11T01:04:36Z2022-01-14T20:12:25Z10780
592*/ShadowHound.git*.{0,1000}\/ShadowHound\.git.{0,1000}offensive_tool_keywordShadowHoundset of PowerShell scripts for Active Directory enumerationT1087 - T1018 - T1482 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Friends-Security/ShadowHound11N/AN/A84345362024-12-01T08:06:02Z2024-11-21T15:01:14Z10838
593*/ShadowSpray.git*.{0,1000}\/ShadowSpray\.git.{0,1000}offensive_tool_keywordShadowSprayA tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.T1110.003 - T1098 - T1059 - T1075TA0001 - TA0008 - TA0009N/ABlack BastaDiscoveryhttps://github.com/ShorSec/ShadowSpray11N/AN/A75459802022-10-14T13:36:51Z2022-10-10T08:34:07Z10850
594*/ShadowSpray/*.cs*.{0,1000}\/ShadowSpray\/.{0,1000}\.cs.{0,1000}offensive_tool_keywordShadowSprayA tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.T1110.003 - T1098 - T1059 - T1075TA0001 - TA0008 - TA0009N/ABlack BastaDiscoveryhttps://github.com/ShorSec/ShadowSpray11N/AN/A75459802022-10-14T13:36:51Z2022-10-10T08:34:07Z10852
595*/shareaudit.exe*.{0,1000}\/shareaudit\.exe.{0,1000}offensive_tool_keywordShareAuditA tool for auditing network shares in an Active Directory environmentT1135 - T1005 - T1083 - T1210TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/dionach/ShareAudit11N/AN/A8142152019-04-29T10:07:57Z2019-02-26T16:00:15Z10858
596*/ShareAudit.git*.{0,1000}\/ShareAudit\.git.{0,1000}offensive_tool_keywordShareAuditA tool for auditing network shares in an Active Directory environmentT1135 - T1005 - T1083 - T1210TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/dionach/ShareAudit11N/AN/A8142152019-04-29T10:07:57Z2019-02-26T16:00:15Z10859
597*/ShareAudit/releases/download/*.{0,1000}\/ShareAudit\/releases\/download\/.{0,1000}offensive_tool_keywordShareAuditA tool for auditing network shares in an Active Directory environmentT1135 - T1005 - T1083 - T1210TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/dionach/ShareAudit11N/AN/A8142152019-04-29T10:07:57Z2019-02-26T16:00:15Z10860
598*/SharpADWS.git*.{0,1000}\/SharpADWS\.git.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS11N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z10866
599*/SharpAVKB.exe*.{0,1000}\/SharpAVKB\.exe.{0,1000}offensive_tool_keywordSharpAVKBWindows Antivirus Comparison and Patch Number ComparisonT1082 - T1518 - T1083TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpAVKB11N/AN/A4158242019-10-28T06:50:30Z2019-10-14T12:44:22Z10875
600*/SharpAVKB.git*.{0,1000}\/SharpAVKB\.git.{0,1000}offensive_tool_keywordSharpAVKBWindows Antivirus Comparison and Patch Number ComparisonT1082 - T1518 - T1083TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpAVKB11N/AN/A4158242019-10-28T06:50:30Z2019-10-14T12:44:22Z10876
601*/SharpAzbelt.git*.{0,1000}\/SharpAzbelt\.git.{0,1000}offensive_tool_keywordSharpAzbeltThis is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resourcesT1082 - T1003 - T1027 - T1110 - T1078TA0006 - TA0007 - TA0005 - TA0004 - TA0003N/AN/ADiscoveryhttps://github.com/redskal/SharpAzbelt11N/AN/A812672023-09-21T21:47:32Z2023-09-21T21:44:03Z10877
602*/SharpBuster.dll*.{0,1000}\/SharpBuster\.dll.{0,1000}offensive_tool_keywordSharpBusterThis is a C# implementation of a directory brute forcing tool designed to allow for in-memory executionT1087 - T1112 - T1048.003 - T1105TA0007 - TA0040 - TA0002N/AN/ADiscoveryhttps://github.com/passthehashbrowns/SharpBuster11N/AN/A716272020-09-02T15:46:03Z2020-08-31T00:33:02Z10881
603*/SharpBuster.exe*.{0,1000}\/SharpBuster\.exe.{0,1000}offensive_tool_keywordSharpBusterThis is a C# implementation of a directory brute forcing tool designed to allow for in-memory executionT1087 - T1112 - T1048.003 - T1105TA0007 - TA0040 - TA0002N/AN/ADiscoveryhttps://github.com/passthehashbrowns/SharpBuster11N/AN/A716272020-09-02T15:46:03Z2020-08-31T00:33:02Z10882
604*/SharpEDRChecker-*.zip*.{0,1000}\/SharpEDRChecker\-.{0,1000}\.zip.{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker11N/AN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z10951
605*/SharpEDRChecker.git*.{0,1000}\/SharpEDRChecker\.git.{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker11N/AN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z10955
606*/SharpEDRChecker/*.{0,1000}\/SharpEDRChecker\/.{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker11N/AN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z10956
607*/SharpEventLog.exe*.{0,1000}\/SharpEventLog\.exe.{0,1000}offensive_tool_keywordSharpEventLogreads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetrationT1078 - T1087.001TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpEventLog11N/AN/A43205342019-10-15T06:26:52Z2019-10-15T06:14:32Z10965
608*/SharpEventLog.git*.{0,1000}\/SharpEventLog\.git.{0,1000}offensive_tool_keywordSharpEventLogreads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetrationT1078 - T1087.001TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpEventLog11N/AN/A43205342019-10-15T06:26:52Z2019-10-15T06:14:32Z10966
609*/SharpGraphView.git*.{0,1000}\/SharpGraphView\.git.{0,1000}offensive_tool_keywordSharpGraphViewMicrosoft Graph API post-exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/SharpGraphView11N/AN/A619492024-07-13T12:27:38Z2024-05-04T11:23:42Z10990
610*/SharpHound.ps1*.{0,1000}\/SharpHound\.ps1.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors11N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z11005
611*/SharpHound-v*.zip*.{0,1000}\/SharpHound\-v.{0,1000}\.zip.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound11N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z11006
612*/SharpLDAP.git*.{0,1000}\/SharpLDAP\.git.{0,1000}offensive_tool_keywordSharpLDAPtool written in C# that aims to do enumeration via LDAP queriesT1018 - T1069.003TA0007 - TA0011N/AN/ADiscoveryhttps://github.com/mertdas/SharpLDAP11N/AN/A81012023-01-14T21:52:36Z2022-11-16T00:38:43Z11020
613*/SharpNBTScan.git*.{0,1000}\/SharpNBTScan\.git.{0,1000}offensive_tool_keywordSharpNBTScana NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumerationT1018 - T1046TA0007Ghost RansomwareN/ADiscoveryhttps://github.com/BronzeTicket/SharpNBTScan11N/AN/A717142021-08-06T05:36:55Z2021-07-12T08:57:39Z11044
614*/SharpOxidResolver.git*.{0,1000}\/SharpOxidResolver\.git.{0,1000}offensive_tool_keywordSharpOxidResolversearch the current domain for computers and get bindings for all of themT1018 - T1046 - T1016TA0007N/AKNOTWEEDDiscoveryhttps://github.com/S3cur3Th1sSh1t/SharpOxidResolver11N/AN/A915092020-11-25T08:42:06Z2020-11-25T08:23:23Z11050
615*/SharpOxidResolver/releases/download/*.{0,1000}\/SharpOxidResolver\/releases\/download\/.{0,1000}offensive_tool_keywordSharpOxidResolversearch the current domain for computers and get bindings for all of themT1018 - T1046 - T1016TA0007N/AKNOTWEEDDiscoveryhttps://github.com/S3cur3Th1sSh1t/SharpOxidResolver11N/AN/A915092020-11-25T08:42:06Z2020-11-25T08:23:23Z11051
616*/SharpRODC.git*.{0,1000}\/SharpRODC\.git.{0,1000}offensive_tool_keywordSharpRODCaudit the security of read-only domain controllersT1012 - T1482 - T1207 - T1208 - T1209 - T1212TA0007 - TA0008 - TA0006N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpRODC11N/AN/A8211582023-11-27T12:41:52Z2023-11-24T14:35:49Z11068
617*/SharpShares.git*.{0,1000}\/SharpShares\.git.{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/Hackcraft-Labs/SharpShares11N/AN/A1013372023-11-13T14:08:07Z2023-10-25T10:34:18Z11087
618*/SharpShares/Enums*.{0,1000}\/SharpShares\/Enums.{0,1000}offensive_tool_keywordSMBeagleSMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.T1087.002 - T1021.002 - T1210TA0007 - TA0008 - TA0003N/AN/ADiscoveryhttps://github.com/punk-security/SMBeagle11N/AN/A98712802025-01-21T22:34:00Z2021-05-31T19:46:57Z11088
619*/SharpShares/releases/download/*.{0,1000}\/SharpShares\/releases\/download\/.{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/mitchmoser/SharpShares11N/AN/A104351492021-09-21T08:14:27Z2020-09-25T22:35:57Z11089
620*/SharpShares-master*.{0,1000}\/SharpShares\-master.{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/Hackcraft-Labs/SharpShares10N/AN/A1013372023-11-13T14:08:07Z2023-10-25T10:34:18Z11090
621*/SharpSSDP.git*.{0,1000}\/SharpSSDP\.git.{0,1000}offensive_tool_keywordSharpSSDP execute SharpSSDP.exe through Cobalt Strike's Beacon "execute-assembly" module to discover SSDP related servicesT1046 - T1016TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/rvrsh3ll/SharpSSDP11N/AN/A711742018-12-16T17:14:28Z2018-12-16T17:14:12Z11122
622*/SharpSSDP/*.{0,1000}\/SharpSSDP\/.{0,1000}offensive_tool_keywordSharpSSDP execute SharpSSDP.exe through Cobalt Strike's Beacon "execute-assembly" module to discover SSDP related servicesT1046 - T1016TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/rvrsh3ll/SharpSSDP11N/AN/A711742018-12-16T17:14:28Z2018-12-16T17:14:12Z11123
623*/SharpView.git*.{0,1000}\/SharpView\.git.{0,1000}offensive_tool_keywordSharpViewC# implementation of harmj0y's PowerViewT1018 - T1482 - T1087.002 - T1069.002TA0007 - TA0003 - TA0001N/AConti - APT29Discoveryhttps://github.com/tevora-threat/SharpView/11N/AN/A101010321962024-03-22T16:34:09Z2018-07-24T21:15:04Z11154
624*/SilentHound.git*.{0,1000}\/SilentHound\.git.{0,1000}offensive_tool_keywordSilentHoundQuietly enumerate an Active Directory Domain via LDAP parsing users + admins + groups...T1087.002 - T1018 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/layer8secure/SilentHound11N/AAD Enumeration75489472023-01-23T20:41:55Z2022-07-01T13:49:24Z11266
625*/SimpleNTSyscallFuzzer.git*.{0,1000}\/SimpleNTSyscallFuzzer\.git.{0,1000}offensive_tool_keywordSimpleNTSyscallFuzzerFuzzer for Windows kernel syscalls.T1055.011 - T1218TA0005 - TA0007N/AN/ADiscoveryhttps://github.com/waleedassar/SimpleNTSyscallFuzzer11N/AN/A72145252024-01-25T02:39:31Z2022-03-12T10:16:30Z11278
626*/SlinkyCat.git*.{0,1000}\/SlinkyCat\.git.{0,1000}offensive_tool_keywordSlinkyCatThis script performs a series of AD enumeration tasksT1087.002 - T1018 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/LaresLLC/SlinkyCat11N/AAD Enumeration717982023-07-12T15:29:31Z2023-07-03T23:44:18Z11324
627*/SmallSecretsDump.py*.{0,1000}\/SmallSecretsDump\.py.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck11N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z11347
628*/SMBeagle*.{0,1000}\/SMBeagle.{0,1000}offensive_tool_keywordSMBeagleSMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.T1087.002 - T1021.002 - T1210TA0007 - TA0008 - TA0003N/AN/ADiscoveryhttps://github.com/punk-security/SMBeagle11N/AN/A98712802025-01-21T22:34:00Z2021-05-31T19:46:57Z11364
629*/SMBGhost/scanner.py*.{0,1000}\/SMBGhost\/scanner\.py.{0,1000}offensive_tool_keywordSMBGhostSimple scanner for CVE-2020-0796 - SMBv3 RCE.T1210 - T1573 - T1553 - T1216 - T1027TA0006 - TA0011 - TA0008N/AN/ADiscoveryhttps://github.com/ollypwn/SMBGhost11N/AN/A776781942020-10-01T08:36:29Z2020-03-11T15:21:27Z11377
630*/smblogin.ps1*.{0,1000}\/smblogin\.ps1.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools11N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z11383
631*/smbmap.git*.{0,1000}\/smbmap\.git.{0,1000}offensive_tool_keywordsmbmapSMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks.T1210.001 - T1083 - T1213 - T1021TA0007 - TA0003 - TA0002 - TA0001N/AMuddyWater - DispossessorDiscoveryhttps://github.com/ShawnDEvans/smbmap11N/AN/A101018903592025-02-28T18:09:10Z2015-03-16T13:15:00Z11385
632*/smbmapDump*.{0,1000}\/smbmapDump.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z11387
633*/smbscan-*.csv*.{0,1000}\/smbscan\-.{0,1000}\.csv.{0,1000}offensive_tool_keywordsmbscanSMBScan is a tool to enumerate file shares on an internal network.T1135 - T1046 - T1021TA0007 - TA0043 - TA0008N/AAPT22Discoveryhttps://github.com/jeffhacks/smbscan10#linuxN/A814462025-03-24T01:55:30Z2021-10-26T02:28:34Z11398
634*/smbscan-*.log*.{0,1000}\/smbscan\-.{0,1000}\.log.{0,1000}offensive_tool_keywordsmbscanSMBScan is a tool to enumerate file shares on an internal network.T1135 - T1046 - T1021TA0007 - TA0043 - TA0008N/AAPT22Discoveryhttps://github.com/jeffhacks/smbscan10#linuxN/A814462025-03-24T01:55:30Z2021-10-26T02:28:34Z11399
635*/smbscan.git*.{0,1000}\/smbscan\.git.{0,1000}offensive_tool_keywordsmbscanSMBScan is a tool to enumerate file shares on an internal network.T1135 - T1046 - T1021TA0007 - TA0043 - TA0008N/AAPT22Discoveryhttps://github.com/jeffhacks/smbscan11N/AN/A814462025-03-24T01:55:30Z2021-10-26T02:28:34Z11400
636*/smbscan.py*.{0,1000}\/smbscan\.py.{0,1000}offensive_tool_keywordsmbscanSMBScan is a tool to enumerate file shares on an internal network.T1135 - T1046 - T1021TA0007 - TA0043 - TA0008N/AAPT22Discoveryhttps://github.com/jeffhacks/smbscan11N/AN/A814462025-03-24T01:55:30Z2021-10-26T02:28:34Z11401
637*/smbsr.db*.{0,1000}\/smbsr\.db.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10#linuxN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z11409
638*/SMBSR.git*.{0,1000}\/SMBSR\.git.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR11N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z11410
639*/smbsr.log*.{0,1000}\/smbsr\.log.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR11#logfile #linuxN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z11412
640*/smbsr.py*.{0,1000}\/smbsr\.py.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR11N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z11414
641*/smbsr_results.csv*.{0,1000}\/smbsr_results\.csv.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR11N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z11415
642*/SnaffPoint.git*.{0,1000}\/SnaffPoint\.git.{0,1000}offensive_tool_keywordSnaffPointA tool for pointesters to find candies in SharePointT1210.001 - T1087.002 - T1059.006TA0007 - TA0002 - TA0006N/AN/ADiscoveryhttps://github.com/nheiniger/SnaffPoint11N/AN/A73254252022-11-04T13:26:24Z2022-08-25T13:16:06Z11456
643*/snsenum.py*.{0,1000}\/snsenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot11N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z11482
644*/SOAPHound.exe*.{0,1000}\/SOAPHound\.exe.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound11N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z11483
645*/SOAPHound.git*.{0,1000}\/SOAPHound\.git.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound11N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z11484
646*/SOAPHound/Program.cs*.{0,1000}\/SOAPHound\/Program\.cs.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound11N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z11485
647*/sshpass /bin/sh -p*.{0,1000}\/sshpass\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z11611
648*/StandIn.exe*.{0,1000}\/StandIn\.exe.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn11N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z11650
649*/StandIn.git*.{0,1000}\/StandIn\.git.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn11N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z11651
650*/StandIn_Net35.exe*.{0,1000}\/StandIn_Net35\.exe.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn11N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z11652
651*/StandIn_Net45.exe *.{0,1000}\/StandIn_Net45\.exe\s.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn11N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z11653
652*/StandIn-1.3.zip*.{0,1000}\/StandIn\-1\.3\.zip.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn11N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z11654
653*/stdbuf -i0 /bin/sh -p*.{0,1000}\/stdbuf\s\-i0\s\/bin\/sh\s\-p.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z11666
654*/TeamsEnum.git*.{0,1000}\/TeamsEnum\.git.{0,1000}offensive_tool_keywordTeamsEnumUser Enumeration of Microsoft Teams users via APIT1589.002 - T1590TA0007 - TA0001N/ABlack BastaDiscoveryhttps://github.com/sse-secure-systems/TeamsEnum11N/AN/A62153212024-03-27T18:14:25Z2023-04-03T18:35:15Z11841
655*/teamsenum.py*.{0,1000}\/teamsenum\.py.{0,1000}offensive_tool_keywordTeamsEnumUser Enumeration of Microsoft Teams users via APIT1589.002 - T1590TA0007 - TA0001N/ABlack BastaDiscoveryhttps://github.com/sse-secure-systems/TeamsEnum11N/AN/A62153212024-03-27T18:14:25Z2023-04-03T18:35:15Z11842
656*/thief.py*.{0,1000}\/thief\.py.{0,1000}offensive_tool_keywordSeeYouCM-ThiefSimple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentialsT1110.001 - T1005 - T1071.001TA0001 - TA0011 - TA0005N/AN/ADiscoveryhttps://github.com/trustedsec/SeeYouCM-Thief11N/AN/A92189352023-05-11T01:04:36Z2022-01-14T20:12:25Z11894
657*/tmp/.manspider*.{0,1000}\/tmp\/\.manspider.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10#linuxN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z11948
658*/TokenDump.exe*.{0,1000}\/TokenDump\.exe.{0,1000}offensive_tool_keywordPrivFuinspect token informationT1057TA0007N/AN/ADiscoveryhttps://github.com/daem0nc0re/PrivFu11N/ATokenDump1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z12011
659*/trackerjacker*.{0,1000}\/trackerjacker.{0,1000}offensive_tool_keywordtrackerjackerLike nmap for mapping wifi networks you're not connected to. Maps and tracks wifi networks and devices through raw 802.11 monitoring.T1040 - T1018 - T1591TA0007 - - TA0043N/AN/ADiscoveryhttps://github.com/calebmadrigal/trackerjacker10#linuxN/AN/A1026721902024-01-16T05:10:22Z2016-12-18T22:01:13Z12071
660*/unshare -r /bin/sh*.{0,1000}\/unshare\s\-r\s\/bin\/sh.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z12236
661*/usr/bin/polenum*.{0,1000}\/usr\/bin\/polenum.{0,1000}offensive_tool_keywordpolenumUses Impacket Library to get the password policy from a windows machineT1012 - T1596TA0009 - TA0007N/AN/ADiscoveryhttps://salsa.debian.org/pkg-security-team/polenum10#linuxN/A810N/AN/AN/AN/A12339
662*/usr/local/bin/nullinux*.{0,1000}\/usr\/local\/bin\/nullinux.{0,1000}offensive_tool_keywordnullinuxInternal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB.T1087 - T1016 - T1077 - T1018TA0007 - TA0006N/AN/ADiscoveryhttps://github.com/m8sec/nullinux10#linuxN/A765751012024-06-19T14:29:09Z2016-04-28T16:45:02Z12352
663*/view -c ':py3 import os*os.execl(\"/bin/sh\*.{0,1000}\/view\s\-c\s\'\:py3\simport\sos.{0,1000}os\.execl\(\\\"\/bin\/sh\\.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z12445
664*/watch -x sh -c 'reset* exec sh 1>&0 2>&0*.{0,1000}\/watch\s\-x\ssh\s\-c\s\'reset.{0,1000}\sexec\ssh\s1\>\&0\s2\>\&0.{0,1000}greyware_tool_keywordAutoSUIDautomate harvesting the SUID executable files and to find a way for further escalating the privilegesT1548.003 - T1069.001 - T1068TA0004 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/IvanGlinkin/AutoSUID10#linuxN/A94375772024-04-29T12:30:35Z2021-11-28T19:44:18Z12499
665*/windapsearch.git*.{0,1000}\/windapsearch\.git.{0,1000}offensive_tool_keywordwindapsearchPython script to enumerate users - groups and computers from a Windows domain through LDAP queriesT1087.002 - T1018 - T1069.002TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/ropnop/windapsearch11N/AAD Enumeration798661542022-04-20T07:40:42Z2016-08-10T21:43:30Z12590
666*/windapsearch.py*.{0,1000}\/windapsearch\.py.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR11N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z12591
667*/windapsearch_*.txt*.{0,1000}\/windapsearch_.{0,1000}\.txt.{0,1000}offensive_tool_keywordlinWinPwnlinWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checksT1087.002 - T1018 - T1069.002 - T1046 - T1083 - T1016TA0007 - TA0009 - TA0003 - TA0002 - TA0005N/ABlack BastaDiscoveryhttps://github.com/lefayjey/linWinPwn11#linuxN/A101019532832025-04-15T14:51:50Z2021-12-16T22:13:10Z12592
668*/wordlists/combined_male_names.txt*.{0,1000}\/wordlists\/combined_male_names\.txt.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10#linuxN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z12715
669*/wordlists/familynames-usa-top1000.txt*.{0,1000}\/wordlists\/familynames\-usa\-top1000\.txt.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10#linuxN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z12716
670*/wordlists/femalenames-usa-top1000.txt*.{0,1000}\/wordlists\/femalenames\-usa\-top1000\.txt.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10#linuxN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z12717
671*/wordlists/malenames-usa-top1000.txt*.{0,1000}\/wordlists\/malenames\-usa\-top1000\.txt.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10#linuxN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z12718
672*/wordlists/names_quit_riot.txt*.{0,1000}\/wordlists\/names_quit_riot\.txt.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10#linuxN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z12719
673*@" ( _/_ _// ~b33f"*.{0,1000}\@\"\s\(\s_\/_\s\s\s_\/\/\s\s\s\~b33f\".{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z12872
674*[!] Failed to enumerate Credman:*.{0,1000}\[!\]\s\s\s\sFailed\sto\senumerate\sCredman\:.{0,1000}offensive_tool_keywordSharpAzbeltThis is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resourcesT1082 - T1003 - T1027 - T1110 - T1078TA0006 - TA0007 - TA0005 - TA0004 - TA0003N/AN/ADiscoveryhttps://github.com/redskal/SharpAzbelt10#contentN/A812672023-09-21T21:47:32Z2023-09-21T21:44:03Z12891
675*[!] AS-REP Roastable user:*.{0,1000}\[!\]\sAS\-REP\sRoastable\suser\:.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10#contentN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z12892
676*[!] Could not execute query. Could not bind to LDAP://rootDSE.*.{0,1000}\[!\]\sCould\snot\sexecute\squery\.\sCould\snot\sbind\sto\sLDAP\:\/\/rootDSE\..{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10#contentN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z12897
677*[!] Failed to enumerate ADCS data.*.{0,1000}\[!\]\sFailed\sto\senumerate\sADCS\sdata\..{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10#contentN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z12917
678*[!] Insecure resource delegations found. Exporting report:*.{0,1000}\[!\]\sInsecure\sresource\sdelegations\sfound\.\sExporting\sreport\:.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10#contentN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z12938
679*[!] Insecure trustee delegations found. Exporting report: *.{0,1000}\[!\]\sInsecure\strustee\sdelegations\sfound\.\sExporting\sreport\:\s.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10#contentN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z12939
680*[!] You have DCs with RC4 or DES allowed for Kerberos!!!*.{0,1000}\[!\]\sYou\shave\sDCs\swith\sRC4\sor\sDES\sallowed\sfor\sKerberos!!!.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10#contentN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z12976
681*[!][!][!] Checking Directories [!][!][!]*.{0,1000}\[!\]\[!\]\[!\]\sChecking\sDirectories\s\[!\]\[!\]\[!\].{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10#contentN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z12977
682*[!][!][!] Checking drivers [!][!][!]*.{0,1000}\[!\]\[!\]\[!\]\sChecking\sdrivers\s\[!\]\[!\]\[!\].{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10#contentN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z12978
683*[!][!][!] Checking modules loaded in your current process [!][!][!]*.{0,1000}\[!\]\[!\]\[!\]\sChecking\smodules\sloaded\sin\syour\scurrent\sprocess\s\[!\]\[!\]\[!\].{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10#contentN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z12979
684*[!][!][!] Checking Services [!][!][!]*.{0,1000}\[!\]\[!\]\[!\]\sChecking\sServices\s\[!\]\[!\]\[!\].{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10#contentN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z12980
685*[!][!][!] EDR Checks Complete [!][!][!]*.{0,1000}\[!\]\[!\]\[!\]\sEDR\sChecks\sComplete\s\[!\]\[!\]\[!\].{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10#contentN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z12981
686*[!][!][!] Welcome to SharpEDRChecker by @PwnDexter [!][!][!]*.{0,1000}\[!\]\[!\]\[!\]\sWelcome\sto\sSharpEDRChecker\sby\s\@PwnDexter\s\[!\]\[!\]\[!\].{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10#contentN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z12982
687*[-] Account to kerberoast does not exist!*.{0,1000}\[\-\]\sAccount\sto\skerberoast\sdoes\snot\sexist!.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10#contentN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z12997
688*[-] Elevating * with DCSync privileges failed*.{0,1000}\[\-\]\sElevating\s.{0,1000}\swith\sDCSync\sprivileges\sfailed.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10#contentN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z13004
689*[-] Kerberoast*.{0,1000}\[\-\]\sKerberoast.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10#contentAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z13020
690*[-] No Kerberoastable accounts found*.{0,1000}\[\-\]\sNo\sKerberoastable\saccounts\sfound.{0,1000}offensive_tool_keywordCable*.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation*T1087 - T1016 - T1059 - T1482 - T1078TA0007 - TA0002 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/logangoins/Cable10#contentN/A74361402025-04-09T01:12:47Z2024-08-10T19:47:08Z13022
691*[-] Removed PSRemote Collection*.{0,1000}\[\-\]\sRemoved\sPSRemote\sCollection.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10#contentN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z13026
692*[+] Attack aborted. Exiting*.{0,1000}\[\+\]\sAttack\saborted\.\sExiting.{0,1000}offensive_tool_keywordShadowSprayA tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.T1110.003 - T1098 - T1059 - T1075TA0001 - TA0008 - TA0009N/ABlack BastaDiscoveryhttps://github.com/ShorSec/ShadowSpray10#contentN/A75459802022-10-14T13:36:51Z2022-10-10T08:34:07Z13052
693*[+] Connected to \\\\*\\IPC$*.{0,1000}\[\+\]\sConnected\sto\s\\\\\\\\.{0,1000}\\\\IPC\$.{0,1000}offensive_tool_keywordRemotePipeListA small tool that can list the named pipes bound on a remote system.T1047 - T1021.006TA0008 - TA0002N/AN/ADiscoveryhttps://github.com/outflanknl/C2-Tool-Collection/tree/main/Other/RemotePipeList10#contentN/A101012132042023-10-27T14:16:17Z2022-04-22T13:43:35Z13081
694*[+] Defender Config Dumped to *.{0,1000}\[\+\]\sDefender\sConfig\sDumped\sto\s.{0,1000}offensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10#contentN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z13097
695*[+] Dropping into shell*.{0,1000}\[\+\]\sDropping\sinto\sshell.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy10#content #linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z13111
696*[+] Dumped Allowed Threats to * .{0,1000}\[\+\]\sDumped\sAllowed\sThreats\sto\s.{0,1000}\soffensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10#contentN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z13115
697*[+] Dumped Exclusion Paths to ExclusionPaths.csv*.{0,1000}\[\+\]\sDumped\sExclusion\sPaths\sto\sExclusionPaths\.csv.{0,1000}offensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10#contentN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z13116
698*[+] Dumped Exploit Guard Protection History*.{0,1000}\[\+\]\sDumped\sExploit\sGuard\sProtection\sHistory.{0,1000}offensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10#contentN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z13117
699*[+] Dumped Firewall Exclusions to *.{0,1000}\[\+\]\sDumped\sFirewall\sExclusions\sto\s.{0,1000}offensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10#contentN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z13118
700*[+] Dumped Protection History to ProtectionHistory.csv*.{0,1000}\[\+\]\sDumped\sProtection\sHistory\sto\sProtectionHistory\.csv.{0,1000}offensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10#contentN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z13119
701*[+] Dumping Defender Excluded Paths*.{0,1000}\[\+\]\sDumping\sDefender\sExcluded\sPaths.{0,1000}offensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10#contentN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z13120
702*[+] Dumping Defender Protection History*.{0,1000}\[\+\]\sDumping\sDefender\sProtection\sHistory.{0,1000}offensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10#contentN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z13121
703*[+] Dumping Enabled ASR Rules*.{0,1000}\[\+\]\sDumping\sEnabled\sASR\sRules.{0,1000}offensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10#contentN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z13122
704*[+] Enumerating ASR Rules on Local System*.{0,1000}\[\+\]\sEnumerating\sASR\sRules\son\sLocal\sSystem.{0,1000}offensive_tool_keywordMDE_Enumextract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rulesT1070.006TA0005 - TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/0xsp-SRD/MDE_Enum10#contentN/A82198182024-06-10T18:40:27Z2024-06-06T15:54:44Z13129
705*[+] Enumerating ASR Rules on Remote System *.{0,1000}\[\+\]\sEnumerating\sASR\sRules\son\sRemote\sSystem\s.{0,1000}offensive_tool_keywordMDE_Enumextract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rulesT1070.006TA0005 - TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/0xsp-SRD/MDE_Enum10#contentN/A82198182024-06-10T18:40:27Z2024-06-06T15:54:44Z13130
706*[+] Enumerating driver services...*.{0,1000}\[\+\]\sEnumerating\sdriver\sservices\.\.\..{0,1000}offensive_tool_keywordDriverQueryCollect details about drivers on the system and optionally filter to find only ones not signed by MicrosoftT1124 - T1057 - T1082TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/matterpreter/OffensiveCSharp/tree/master/DriverQuery10#contentN/A101014162502023-02-06T14:56:26Z2019-02-06T00:32:29Z13131
707*[+] Finding Kerberoastable accounts*.{0,1000}\[\+\]\sFinding\sKerberoastable\saccounts.{0,1000}offensive_tool_keywordCable*.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation*T1087 - T1016 - T1059 - T1482 - T1078TA0007 - TA0002 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/logangoins/Cable10#contentN/A74361402025-04-09T01:12:47Z2024-08-10T19:47:08Z13143
708*[+] Finished Enumerating Shares*.{0,1000}\[\+\]\sFinished\sEnumerating\sShares.{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/Hackcraft-Labs/SharpShares10#contentN/A1013372023-11-13T14:08:07Z2023-10-25T10:34:18Z13144
709*[+] Jecretz Results*.{0,1000}\[\+\]\sJecretz\sResults.{0,1000}offensive_tool_keywordjecretzJira Secret Hunter - Helps you find credentials and sensitive contents in Jira ticketsT1552 - T1114 - T1119 - T1070TA0006 - TA0009 - TA0005N/AScattered Spider*Discoveryhttps://github.com/sahadnk72/jecretz10#contentN/A714392022-12-08T10:00:11Z2020-05-25T14:40:28Z13206
710*[+] No insecure resource delegations found. Eureka!*.{0,1000}\[\+\]\sNo\sinsecure\sresource\sdelegations\sfound\.\sEureka!.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10#contentN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z13232
711*[+] No insecure trustee delegations found. Eureka!*.{0,1000}\[\+\]\sNo\sinsecure\strustee\sdelegations\sfound\.\sEureka!.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10#contentN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z13233
712*[+] NTDS.dit, SYSTEM & SAM saved to output folder*.{0,1000}\[\+\]\sNTDS\.dit,\sSYSTEM\s\&\sSAM\ssaved\sto\soutput\sfolder.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10#contentN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z13238
713*[+] Pipe listing:*.{0,1000}\[\+\]\sPipe\slisting\:.{0,1000}offensive_tool_keywordRemotePipeListA small tool that can list the named pipes bound on a remote system.T1047 - T1021.006TA0008 - TA0002N/AN/ADiscoveryhttps://github.com/outflanknl/C2-Tool-Collection/tree/main/Other/RemotePipeList10#contentN/A101012132042023-10-27T14:16:17Z2022-04-22T13:43:35Z13257
714*[+] Querying DC without Global Catalog: *.{0,1000}\[\+\]\sQuerying\sDC\swithout\sGlobal\sCatalog\:\s.{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/Hackcraft-Labs/SharpShares10#contentN/A1013372023-11-13T14:08:07Z2023-10-25T10:34:18Z13274
715*[+] SID added to msDS-AllowedToActOnBehalfOfOtherIdentity*.{0,1000}\[\+\]\sSID\sadded\sto\smsDS\-AllowedToActOnBehalfOfOtherIdentity.{0,1000}offensive_tool_keywordCable*.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation*T1087 - T1016 - T1059 - T1482 - T1078TA0007 - TA0002 - TA0003 - TA0005N/AN/ADiscoveryhttps://github.com/logangoins/Cable10#contentN/A74361402025-04-09T01:12:47Z2024-08-10T19:47:08Z13319
716*[+] SID added to msDS-AllowedToActOnBehalfOfOtherIdentity*.{0,1000}\[\+\]\sSID\sadded\sto\smsDS\-AllowedToActOnBehalfOfOtherIdentity.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10#contentN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z13320
717*[+] Starting pspy now*.{0,1000}\[\+\]\sStarting\spspy\snow.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy10#content #linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z13329
718*[+] Starting share enumeration against * hosts*.{0,1000}Starting\sshare\senumeration\sagainst\s.{0,1000}\shosts.{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/Hackcraft-Labs/SharpShares10#contentN/A1013372023-11-13T14:08:07Z2023-10-25T10:34:18Z13330
719*[+] Use secretsdump.py*.{0,1000}\[\+\]\sUse\ssecretsdump\.py.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10#contentN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z13384
720*[ADSI]* | Select-Object -Property *lockoutDuration*.{0,1000}\[ADSI\].{0,1000}\s\|\sSelect\-Object\s\-Property\s.{0,1000}lockoutDuration.{0,1000}greyware_tool_keywordldap queriesenumeration of Domain Password PoliciesT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13429
721*[ADSI]* | Select-Object -Property *lockoutThreshold*.{0,1000}\[ADSI\].{0,1000}\s\|\sSelect\-Object\s\-Property\s.{0,1000}lockoutThreshold.{0,1000}greyware_tool_keywordldap queriesenumeration of Domain Password PoliciesT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13430
722*[ADSI]* | Select-Object -Property *minPwdLength*.{0,1000}\[ADSI\].{0,1000}\s\|\sSelect\-Object\s\-Property\s.{0,1000}minPwdLength.{0,1000}greyware_tool_keywordldap queriesenumeration of Domain Password PoliciesT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13431
723*[ADSI]*LDAP://CN=Domain Admins*| ForEach-Object {[adsi]"LDAP://$_"}; *.distinguishedname*.{0,1000}\[ADSI\].{0,1000}LDAP\:\/\/CN\=Domain\sAdmins.{0,1000}\|\sForEach\-Object\s\{\[adsi\]\"LDAP\:\/\/\$_\"\}\;\s.{0,1000}\.distinguishedname.{0,1000}greyware_tool_keywordldap queriesenumeration of Domain Admins group membersT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13432
724*[ADSI]*LDAP://dc=* | Select -Property pwdProperties*.{0,1000}\[ADSI\].{0,1000}LDAP\:\/\/dc\=.{0,1000}\s\|\sSelect\s\-Property\spwdProperties.{0,1000}greyware_tool_keywordldap queriesget LDAP properties for password settings directlyT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13433
725*[adsisearcher]"(&(objectCategory=person)(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))"; $users = $searchUsers.FindAll(); $userProps = $users.Properties; $userProps | Where-Object {$_.description}*.{0,1000}\[adsisearcher\]\"\(\&\(objectCategory\=person\)\(objectClass\=user\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\)\"\;\s\$users\s\=\s\$searchUsers\.FindAll\(\)\;\s\$userProps\s\=\s\$users\.Properties\;\s\$userProps\s\|\sWhere\-Object\s\{\$_\.description\}.{0,1000}greyware_tool_keywordldap queriesfind user descriptions in Active Directory:T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13434
726*[adsisearcher]"(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=2))"*.{0,1000}\[adsisearcher\]\"\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\".{0,1000}greyware_tool_keywordldap queriesfind all disabled user accountsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13435
727*[adsisearcher]"(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=2560)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))"*.{0,1000}\[adsisearcher\]\"\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2560\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\)\".{0,1000}greyware_tool_keywordldap queriesget a count of all inter domain trust accountsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13436
728*[adsisearcher]"(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=32)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))*.{0,1000}\[adsisearcher\]\"\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=32\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\)\).{0,1000}greyware_tool_keywordldap queriesDetection of all accounts with 'Password Not Required'T1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13437
729*[adsisearcher]'(&(objectCategory=computer)(primaryGroupID=516))').FindAll()*.{0,1000}\[adsisearcher\]\'\(\&\(objectCategory\=computer\)\(primaryGroupID\=516\)\)\'\)\.FindAll\(\).{0,1000}greyware_tool_keywordldap queriesEnumerate all Domain ControllersT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://web.archive.org/web/20240109000256/https://cyberdom.blog/2024/01/07/defender-for-identity-hunting-for-ldap/10N/AN/A910N/AN/AN/AN/A13438
730*[adsisearcher]'(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=32))').FindAll()*.{0,1000}\[adsisearcher\]\'\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=32\)\)\'\)\.FindAll\(\).{0,1000}greyware_tool_keywordldap queriesEnumerate all accounts that do not require a passwordT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://jsecurity101.medium.com/uncovering-adversarial-ldap-tradecraft-658b2deca38410N/AN/A810N/AN/AN/AN/A13439
731*[adsisearcher]*(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=66048)(!(userAccountControl:1.2.840.113556.1.4.803:=2))*.{0,1000}\[adsisearcher\].{0,1000}\(\&\(objectCategory\=person\)\(objectClass\=user\)\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=66048\)\(!\(userAccountControl\:1\.2\.840\.113556\.1\.4\.803\:\=2\)\).{0,1000}greyware_tool_keywordldap queriesADSI query to retrieve all active user accounts with non-expiring passwordsT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13440
732*[Find-DomainShare] Enumerating server *.{0,1000}\[Find\-DomainShare\]\sEnumerating\sserver\s.{0,1000}offensive_tool_keywordpowerviewPowerView is a PowerShell tool to gain network situational awareness on Windows domainsT1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/ADispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDADiscoveryhttps://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps110#contentN/A10101227446602020-08-17T23:19:49Z2012-05-26T16:08:48Z13460
733*[Get-ADRRevertToSelf] Token impersonation successfully reverted*.{0,1000}\[Get\-ADRRevertToSelf\]\sToken\simpersonation\ssuccessfully\sreverted.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z13463
734*[Get-ADR-UserImpersonation] Alternate credentials successfully impersonated*.{0,1000}\[Get\-ADR\-UserImpersonation\]\sAlternate\scredentials\ssuccessfully\simpersonated.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z13464
735*[i] AAD Join:*enumerate*.{0,1000}\[i\]\sAAD\sJoin\:.{0,1000}enumerate.{0,1000}offensive_tool_keywordSharpAzbeltThis is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resourcesT1082 - T1003 - T1027 - T1110 - T1078TA0006 - TA0007 - TA0005 - TA0004 - TA0003N/AN/ADiscoveryhttps://github.com/redskal/SharpAzbelt10#contentN/A812672023-09-21T21:47:32Z2023-09-21T21:44:03Z13468
736*[i] Checking for insecure trustee/resource delegations*.{0,1000}\[i\]\sChecking\sfor\sinsecure\strustee\/resource\sdelegations.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z13470
737*[i] Credman:*Credential Blob Decrypted*.{0,1000}\[i\]\sCredman\:.{0,1000}Credential\sBlob\sDecrypted.{0,1000}offensive_tool_keywordSharpAzbeltThis is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resourcesT1082 - T1003 - T1027 - T1110 - T1078TA0006 - TA0007 - TA0005 - TA0004 - TA0003N/AN/ADiscoveryhttps://github.com/redskal/SharpAzbelt10#contentN/A812672023-09-21T21:47:32Z2023-09-21T21:44:03Z13471
738*[i] Running ADeleg and creating *.{0,1000}\[i\]\sRunning\sADeleg\sand\screating\s.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z13477
739*[System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain().DomainControllers*.{0,1000}\[System\.DirectoryServices\.ActiveDirectory\.Domain\]\:\:GetCurrentDomain\(\)\.DomainControllers.{0,1000}greyware_tool_keywordldap queriesDiscover all Domain Controller in the domain using ADSIT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://adsecurity.org/?p=29910N/AN/A610N/AN/AN/AN/A13509
740*[System.DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest().GlobalCatalogs*.{0,1000}\[System\.DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\.GlobalCatalogs.{0,1000}greyware_tool_keywordldap queriesDiscover all Global Catalogs in the forest using ADSIT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://adsecurity.org/?p=29910N/AN/A610N/AN/AN/AN/A13510
741*[System.DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest().RootDomain.PDCRoleOwner.Name*.{0,1000}\[System\.DirectoryServices\.ActiveDirectory\.Forest\]\:\:GetCurrentForest\(\)\.RootDomain\.PDCRoleOwner\.Name.{0,1000}greyware_tool_keywordldap queriesquery for the primary domain controller within the forestT1087 - T1087.002 - T1018 - T1069 - T1069.002 - T1069.003 - T1133 - T1139TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/swarleysez/AD-common-queries10N/AN/A81732020-05-24T03:23:09Z2020-03-10T19:43:51Z13511
742*[System.Environment]::GetEnvironmentVariable('username')*.{0,1000}\[System\.Environment\]\:\:GetEnvironmentVariable\(\'username\'\).{0,1000}greyware_tool_keywordpowershellalternativeto whoamiT1033 TA0007N/AN/ADiscoveryN/A10N/AN/A36N/AN/AN/AN/A13512
743*[System[Provider[@Name='Microsoft-Windows-Windows Defender'] and (EventID=5007)]]*.{0,1000}\[System\[Provider\[\@Name\=\'Microsoft\-Windows\-Windows\sDefender\'\]\sand\s\(EventID\=5007\)\]\].{0,1000}offensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10N/AN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z13516
744*\*_AD-Audit_*.txt*.{0,1000}\\.{0,1000}_AD\-Audit_.{0,1000}\.txt.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum10N/AN/A75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z13554
745*\\\\*\\*\\Get-FileLockProcess.ps1*.{0,1000}\\\\\\\\.{0,1000}\\\\.{0,1000}\\\\Get\-FileLockProcess\.ps1.{0,1000}offensive_tool_keywordsmbmapSMBMap allows users to enumerate samba share drives across an entire domain. List share drives. drive permissions. share contents. upload/download functionality. file name auto-download pattern matching. and even execute remote commands. This tool was designed with pen testing in mind. and is intended to simplify searching for potentially sensitive data across large networks.T1210.001 - T1083 - T1213 - T1021TA0007 - TA0003 - TA0002 - TA0001N/AMuddyWater - DispossessorDiscoveryhttps://github.com/ShawnDEvans/smbmap10N/AN/A101018903592025-02-28T18:09:10Z2015-03-16T13:15:00Z13613
746*\10m_usernames.txt*.{0,1000}\\10m_usernames\.txt.{0,1000}offensive_tool_keywordldapnomnomAnonymously bruteforce Active Directory usernames from Domain Controllers by abusing LDAP Ping requests (cLDAP)T1110.003 - T1205TA0007N/AN/ADiscoveryhttps://github.com/lkarlslund/ldapnomnom10N/AN/A6101030802024-11-09T10:15:13Z2022-09-18T10:35:09Z13714
747*\2023*.shareaudit*.{0,1000}\\2023.{0,1000}\.shareaudit.{0,1000}offensive_tool_keywordShareAuditA tool for auditing network shares in an Active Directory environmentT1135 - T1005 - T1083 - T1210TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/dionach/ShareAudit10N/AN/A8142152019-04-29T10:07:57Z2019-02-26T16:00:15Z13728
748*\2024*.shareaudit*.{0,1000}\\2024.{0,1000}\.shareaudit.{0,1000}offensive_tool_keywordShareAuditA tool for auditing network shares in an Active Directory environmentT1135 - T1005 - T1083 - T1210TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/dionach/ShareAudit10N/AN/A8142152019-04-29T10:07:57Z2019-02-26T16:00:15Z13729
749*\2025*.shareaudit*.{0,1000}\\2025.{0,1000}\.shareaudit.{0,1000}offensive_tool_keywordShareAuditA tool for auditing network shares in an Active Directory environmentT1135 - T1005 - T1083 - T1210TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/dionach/ShareAudit10N/AN/A8142152019-04-29T10:07:57Z2019-02-26T16:00:15Z13731
750*\accounts_passdontexpire.txt*.{0,1000}\\accounts_passdontexpire\.txt.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z13775
751*\AD_Miner-*.{0,1000}\\AD_Miner\-.{0,1000}offensive_tool_keywordAD_MinerAD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknessesT1087.002 - T1069 - T1018 - T1595TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/Mazars-Tech/AD_Miner10N/AAD Enumeration71012901312025-03-12T10:53:09Z2023-09-26T12:36:59Z13789
752*\ADAudit.ps1*.{0,1000}\\ADAudit\.ps1.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z13794
753*\adaudit.ps1*.{0,1000}\\adaudit\.ps1.{0,1000}greyware_tool_keywordadauditPowershell script to do domain auditing automationT1482 - T1087TA0007N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A843891062025-04-08T06:17:54Z2018-04-20T11:29:06Z13795
754*\ADcheck.py*.{0,1000}\\ADcheck\.py.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck10N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z13796
755*\ADcheck\Scripts\activate*.{0,1000}\\ADcheck\\Scripts\\activate.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck10N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z13797
756*\ADcheck-main*.{0,1000}\\ADcheck\-main.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck10N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z13798
757*\ADCollector.exe*.{0,1000}\\ADCollector\.exe.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector10N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z13799
758*\ADCollector3.sln*.{0,1000}\\ADCollector3\.sln.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector10N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z13802
759*\ADCollector3\*.{0,1000}\\ADCollector3\\.{0,1000}offensive_tool_keywordADCollectorADCollector is a lightweight tool that enumerates the Active Directory environmentT1087 - T1018 - T1069 - T1482TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/dev-2null/ADCollector10N/AN/A77629812022-07-30T05:27:15Z2019-05-15T06:42:20Z13803
760*\ADeleg.exe*.{0,1000}\\ADeleg\.exe.{0,1000}offensive_tool_keywordadelegan Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forestT1595 - T1087.002 - T1069.002TA0007 - TA0004N/AN/ADiscoveryhttps://github.com/mtth-bfft/adeleg10N/AN/A83294312023-06-07T15:08:53Z2022-02-09T19:47:04Z13825
761*\ADeleg.exe*.{0,1000}\\ADeleg\.exe.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z13826
762*\adeleg.pdb*.{0,1000}\\adeleg\.pdb.{0,1000}offensive_tool_keywordadelegan Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forestT1595 - T1087.002 - T1069.002TA0007 - TA0004N/AN/ADiscoveryhttps://github.com/mtth-bfft/adeleg10N/AN/A83294312023-06-07T15:08:53Z2022-02-09T19:47:04Z13827
763*\adeleg\adeleg\*.{0,1000}\\adeleg\\adeleg\\.{0,1000}offensive_tool_keywordadelegan Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forestT1595 - T1087.002 - T1069.002TA0007 - TA0004N/AN/ADiscoveryhttps://github.com/mtth-bfft/adeleg10N/AN/A83294312023-06-07T15:08:53Z2022-02-09T19:47:04Z13828
764*\adeleg\winldap\*.{0,1000}\\adeleg\\winldap\\.{0,1000}offensive_tool_keywordadelegan Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forestT1595 - T1087.002 - T1069.002TA0007 - TA0004N/AN/ADiscoveryhttps://github.com/mtth-bfft/adeleg10N/AN/A83294312023-06-07T15:08:53Z2022-02-09T19:47:04Z13829
765*\Adeleginator-main*.{0,1000}\\Adeleginator\-main.{0,1000}offensive_tool_keywordAdeleginatortool that uses ADeleg to find insecure trustee and resource delegations in Active DirectoryT1087 - T1136 - T1069TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/techspence/Adeleginator10N/AN/A62179182024-09-18T20:21:42Z2024-03-04T03:44:52Z13830
766*\adeleg-main*.{0,1000}\\adeleg\-main.{0,1000}offensive_tool_keywordadelegan Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forestT1595 - T1087.002 - T1069.002TA0007 - TA0004N/AN/ADiscoveryhttps://github.com/mtth-bfft/adeleg10N/AN/A83294312023-06-07T15:08:53Z2022-02-09T19:47:04Z13831
767*\adf.bat*.{0,1000}\\adf\.bat.{0,1000}greyware_tool_keywordadfindAdfind is a command-line tool often used by administrators for Active Directory queries. However. attackers can misuse it to gather valuable information about the network environment. including user accounts. group memberships. domain controllers. and domain trusts. This gathered intelligence can aid in Lateral Movement. privilege escalation. or even data exfiltration. Such reconnaissance activities often precede more damaging attacks.T1087 - T1016 - T1482TA0007N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://github.com/aancw/community-threats/blob/82ece2dec931d175ed47276d426f526610aa8262/Ryuk/VFS/adf.bat#L410N/AN/A101002022-02-15T23:58:54Z2022-02-24T18:51:11Z13832
768*\adfind.cf*.{0,1000}\\adfind\.cf.{0,1000}greyware_tool_keywordadfindadfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environmentT1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior10N/AN/A1010N/AN/AN/AN/A13833
769*\AdFind.zip*.{0,1000}\\AdFind\.zip.{0,1000}greyware_tool_keywordadfindadfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environmentT1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior10N/AN/A1010N/AN/AN/AN/A13834
770*\ADGet.exe*.{0,1000}\\ADGet\.exe.{0,1000}greyware_tool_keywordadgetgather valuable informations about the AD environmentT1018 - T1027 - T1046 - T1057 - T1069 - T1087 - T1098 - T1482TA0001 - TA0002 - TA0003 - TA0007 - TA0011N/AN/ADiscoveryhttps://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/10N/AN/A1010N/AN/AN/AN/A13848
771*\adhunt.py*\\adhunt\.pyoffensive_tool_keywordadhuntTool for exploiting Active Directory Enviroments - enumerationT1018 - T1087 - T1087.002 - T1069 - T1069.002TA0007 - TA0003 - TA0001N/AN/ADiscoveryhttps://github.com/karendm/ADHunt10N/AAD Enumeration7146102023-08-10T18:55:39Z2023-06-20T13:24:10Z13849
772*\adPEAS.ps1*.{0,1000}\\adPEAS\.ps1.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z13858
773*\adPEAS_DomainPolicy.Sys*.{0,1000}\\adPEAS_DomainPolicy\.Sys.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z13859
774*\adPEAS_outputfile*.{0,1000}\\adPEAS_outputfile.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z13860
775*\adPEAS-Light.ps1*.{0,1000}\\adPEAS\-Light\.ps1.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z13861
776*\adPEAS-main*.{0,1000}\\adPEAS\-main.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z13862
777*\adPEAS-master*.{0,1000}\\adPEAS\-master.{0,1000}offensive_tool_keywordadPEASadPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and othersT1016 - T1087.002 - T1482 - T1207 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/61106960/adPEAS10N/AN/A81010951322025-04-01T16:16:15Z2020-12-23T08:10:19Z13863
778*\ADRecon.ps1*.{0,1000}\\ADRecon\.ps1.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z13865
779*\ADRecon-master*.{0,1000}\\ADRecon\-master.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z13866
780*\ADRecon-Report.xlsx*.{0,1000}\\ADRecon\-Report\.xlsx.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z13867
781*\Advanced IP Scanner.lnk*.{0,1000}\\Advanced\sIP\sScanner\.lnk.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox10N/AN/A710N/AN/AN/AN/A13873
782*\Advanced Port Scanner Portable\*.{0,1000}\\Advanced\sPort\sScanner\sPortable\\.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/10N/AN/A710N/AN/AN/AN/A13879
783*\advanced_ip_scanner*.{0,1000}advanced_ip_scanner.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox10N/AN/A710N/AN/AN/AN/A13880
784*\Advanced_Port_Scanner_*.exe*.{0,1000}\\Advanced_Port_Scanner_.{0,1000}\.exe.{0,1000}signature_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/10N/AN/A710N/AN/AN/AN/A13881
785*\Angry IP Scanner.app*.{0,1000}\\Angry\sIP\sScanner\.app.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z13937
786*\AppData\Local\Temp\lansweeper-*.{0,1000}\\AppData\\Local\\Temp\\lansweeper\-.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/10N/AN/A67N/AN/AN/AN/A14031
787*\AppData\Local\Temp\Procmon.exe*.{0,1000}\\AppData\\Local\\Temp\\Procmon\.exe.{0,1000}greyware_tool_keywordprocmonProcmon used in user temp folderT1059.001 - T1036 - T1569.002TA0002 - TA0006N/AN/ADiscoveryN/A10N/Agreyware tool - risks of False positive !47N/AN/AN/AN/A14039
788*\AppData\Local\Temp\Procmon64.exe*.{0,1000}\\AppData\\Local\\Temp\\Procmon64\.exe.{0,1000}greyware_tool_keywordprocmonProcmon used in user temp folderT1059.001 - T1036 - T1569.002TA0002 - TA0006N/AN/ADiscoveryN/A10N/Agreyware tool - risks of False positive !47N/AN/AN/AN/A14040
789*\AppData\Roaming\SoftPerfect Network Scanner*.{0,1000}\\AppData\\Roaming\\SoftPerfect\sNetwork\sScanner.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A14090
790*\AzureHound.ps1*.{0,1000}\\AzureHound\.ps1.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z14182
791*\backdoored-script.ps1*.{0,1000}\\backdoored\-script\.ps1.{0,1000}offensive_tool_keywordGraphpythonModular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/Graphpython10N/AN/A72145132024-12-07T21:54:00Z2024-07-10T00:04:48Z14198
792*\BitLockerRecoveryKeys.csv*.{0,1000}\\BitLockerRecoveryKeys\.csv.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z14319
793*\BloodHound.exe*.{0,1000}\\BloodHound\.exe.{0,1000}offensive_tool_keywordBloodHoundBloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environmentT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z14358
794*\BloodHoundGui\*.exe*.{0,1000}\\BloodHoundGui\\.{0,1000}\.exe.{0,1000}offensive_tool_keywordBloodHoundBloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environmentT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z14359
795*\BloodHound-win32-X64*.{0,1000}\\BloodHound\-win32\-X64.{0,1000}offensive_tool_keywordBloodHoundBloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environmentT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z14361
796*\bofhound.py*.{0,1000}\\bofhound\.py.{0,1000}offensive_tool_keywordShadowHoundset of PowerShell scripts for Active Directory enumerationT1087 - T1018 - T1482 - T1069TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Friends-Security/ShadowHound10N/AN/A84345362024-12-01T08:06:02Z2024-11-21T15:01:14Z14363
797*\CheckSMBSigning.ps1*.{0,1000}\\CheckSMBSigning\.ps1.{0,1000}offensive_tool_keywordCheckSMBSigningChecks for SMB signing disabled on all hosts in the networkT1018 - T1550TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Leo4j/CheckSMBSigning10N/AN/A61812023-10-13T11:55:33Z2023-05-17T11:47:52Z14496
798*\cmdkey.exe" /list*.{0,1000}\\cmdkey\.exe\"\s\/list.{0,1000}greyware_tool_keywordCmdkeyList Saved CredentialsT1555TA0006N/AN/ADiscoveryhttps://www.cisa.gov/news-events/cybersecurity-advisories/aa24-290a10N/AN/A1010N/AN/AN/AN/A14564
799*\CMLoot.ps1*.{0,1000}\\CMLoot\.ps1.{0,1000}offensive_tool_keywordCMLootFind interesting files stored on (System Center) Configuration Manager (SCCM/CM) SMB sharesT1083 - T1039TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/1njected/CMLoot10N/AN/A82175222023-02-05T00:24:31Z2022-06-02T10:59:21Z14568
800*\COMHijackToolkit.ps1*.{0,1000}\\COMHijackToolkit\.ps1.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z14579
801*\COMHijackToolkit\*.{0,1000}\\COMHijackToolkit\\.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z14580
802*\COMInject.exe*.{0,1000}\\COMInject\.exe.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z14584
803*\COMInject.sln*.{0,1000}\\COMInject\.sln.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z14585
804*\COMInjectTarget.cpp*.{0,1000}\\COMInjectTarget\.cpp.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z14586
805*\COMInjectTarget.dll*.{0,1000}\\COMInjectTarget\.dll.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z14587
806*\COMInjectTarget\*.{0,1000}\\COMInjectTarget\\.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z14588
807*\CultesDesGoules.txt*.{0,1000}\\CultesDesGoules\.txt.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z14702
808*\dangerousACL_Computer.txt*.{0,1000}\\dangerousACL_Computer\.txt.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z14786
809*\dangerousACL_Groups.txt*.{0,1000}\\dangerousACL_Groups\.txt.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z14787
810*\dcs_weak_kerberos_ciphersuite.txt*.{0,1000}\\dcs_weak_kerberos_ciphersuite\.txt.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z14827
811*\DefaultPasswordPolicy.csv*.{0,1000}\\DefaultPasswordPolicy\.csv.{0,1000}greyware_tool_keywordadreconADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.T1018 - T1087.001 - T1069.001 - T1003.002 - T1482TA0007 - TA0009 - TA0040N/AScattered Spider*Discoveryhttps://github.com/adrecon/ADRecon10N/AAD Enumeration787801092024-10-15T03:41:29Z2018-12-15T13:00:09Z14858
812*\DLLHound.ps1*.{0,1000}\\DLLHound\.ps1.{0,1000}offensive_tool_keywordDLLHoundFind potential DLL Sideloads on your windows computerT1574.001 - T1574.002TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/ajm4n/DLLHound10N/AN/A73201222025-01-12T02:28:22Z2024-12-20T02:26:16Z14979
813*\DLLScan_$timestamp.csv*.{0,1000}\\DLLScan_\$timestamp\.csv.{0,1000}offensive_tool_keywordDLLHoundFind potential DLL Sideloads on your windows computerT1574.001 - T1574.002TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/ajm4n/DLLHound10N/AN/A73201222025-01-12T02:28:22Z2024-12-20T02:26:16Z14986
814*\dnsdump.py*.{0,1000}\\dnsdump\.py.{0,1000}offensive_tool_keywordadidnsdumpBy default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones. similar to a zone transfer. This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks.T1018 - T1087 - T1201 - T1056 - T1039TA0005 - TA0009N/AN/ADiscoveryhttps://github.com/dirkjanm/adidnsdump10N/AN/AN/A109971182025-04-04T09:28:20Z2019-04-24T17:18:46Z15002
815*\domain_admins.txt*.{0,1000}\\domain_admins\.txt.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z15023
816*\DSInternals.psd1*.{0,1000}\\DSInternals\.psd1.{0,1000}offensive_tool_keywordDSInternalsDirectory Services Internals (DSInternals) PowerShell Module and Framework - abused by attackersT1003 - T1087 - T1018 - T1110 - T1558TA0003 - TA0006 - TA0007N/ACOZY BEARDiscoveryhttps://github.com/MichaelGrafnetter/DSInternals10N/AAD Enumeration101017602652025-04-16T18:12:55Z2015-12-25T13:23:05Z15079
817*\ecrprivenum.py*.{0,1000}\\ecrprivenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z15218
818*\ecrpubenum.py*.{0,1000}\\ecrpubenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z15219
819*\enterprise_admins.txt*.{0,1000}\\enterprise_admins\.txt.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z15290
820*\ExploitGuardProtectionHistory.csv*.{0,1000}\\ExploitGuardProtectionHistory\.csv.{0,1000}offensive_tool_keywordInvoke-DumpMDEConfigPowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )T1518 - T1082 - T1005TA0009 - TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/BlackSnufkin/Invoke-DumpMDEConfig10N/AN/A92147232024-06-10T14:00:47Z2024-06-09T15:11:16Z15396
821*\findspn.ps1*.{0,1000}\\findspn\.ps1.{0,1000}greyware_tool_keywordDispossessorpowershell script to find a spn - abused by Dispossessor ransomware groupT1087.002 - T1046 - T1557TA0007N/ADispossessorDiscoveryhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A15448
822*\Get-SMBSigning.ps1*.{0,1000}\\Get\-SMBSigning\.ps1.{0,1000}offensive_tool_keywordCheckSMBSigningChecks for SMB signing disabled on all hosts in the networkT1018 - T1550TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Leo4j/CheckSMBSigning10N/AN/A61812023-10-13T11:55:33Z2023-05-17T11:47:52Z15604
823*\GMSAPasswordReader.exe*.{0,1000}\\GMSAPasswordReader\.exe.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z15648
824*\gofetch.exe*.{0,1000}\\gofetch\.exe.{0,1000}offensive_tool_keywordGoFetchGoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.T1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/ADispossessorDiscoveryhttps://github.com/GoFetchAD/GoFetch10N/AN/A107633992017-06-20T14:15:10Z2017-04-11T10:45:23Z15665
825*\GoFetchLog.log*.{0,1000}\\GoFetchLog\.log.{0,1000}offensive_tool_keywordGoFetchGoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.T1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/ADispossessorDiscoveryhttps://github.com/GoFetchAD/GoFetch10N/AN/A107633992017-06-20T14:15:10Z2017-04-11T10:45:23Z15666
826*\GoFetch-main*.{0,1000}GoFetch\-master.{0,1000}offensive_tool_keywordGoFetchGoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.T1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/ADispossessorDiscoveryhttps://github.com/GoFetchAD/GoFetch10N/AN/A107633992017-06-20T14:15:10Z2017-04-11T10:45:23Z15667
827*\GPOBrowser.py*.{0,1000}\\GPOBrowser\.py.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck10N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z15711
828*\Graphpython.py*.{0,1000}\\Graphpython\.py.{0,1000}offensive_tool_keywordGraphpythonModular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/Graphpython10N/AN/A72145132024-12-07T21:54:00Z2024-07-10T00:04:48Z15718
829*\Group3r.cs*.{0,1000}\\Group3r\.cs.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z15728
830*\group3r.log*.{0,1000}\\group3r\.log.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z15732
831*\Group3r.sln*.{0,1000}\\Group3r\.sln.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z15733
832*\HijackDLL-CreateRemoteThread.*.{0,1000}\\HijackDLL\-CreateRemoteThread\..{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z15797
833*\HijackDLL-CreateRemoteThread\*.{0,1000}\\HijackDLL\-CreateRemoteThread\\.{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z15798
834*\HijackDll-Process.*.{0,1000}\\HijackDll\-Process\..{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z15799
835*\HijackDLL-Threads.*.{0,1000}\\HijackDLL\-Threads\..{0,1000}offensive_tool_keywordAccompliceTools for discovery and abuse of COM hijacksT1120 - T1174TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/nccgroup/Accomplice10N/AN/A74303472019-10-15T21:54:09Z2019-09-04T23:32:09Z15800
836*\iamassumeroleenum.py*.{0,1000}\\iamassumeroleenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z15863
837*\Invoke-ADEnum\*.{0,1000}\\Invoke\-ADEnum\\.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum10N/AN/A75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z15964
838*\Invoke-ADEnum-main*.{0,1000}\\Invoke\-ADEnum\-main.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum10N/AN/A75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z15965
839*\Invoke-DCOM.ps1*.{0,1000}\\Invoke\-DCOM\.ps1.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z15969
840*\Invoke-Maldaptive-main*.{0,1000}\\Invoke\-Maldaptive\-main.{0,1000}greyware_tool_keywordInvoke-MaldaptiveMaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection.T1027TA0005 - TA0007N/AN/ADiscoveryhttps://github.com/MaLDAPtive/Invoke-Maldaptive10N/AN/A73277262024-08-07T21:12:45Z2024-08-07T20:43:52Z15976
841*\ipscan-*-setup.exe*.{0,1000}\\ipscan\-.{0,1000}\-setup\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z16005
842*\ipscan.exe*.{0,1000}\\ipscan\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z16006
843*\ipscan221.exe*.{0,1000}\\ipscan221\.exe.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z16007
844*\ipscan-crash.txt*.{0,1000}\\ipscan\-crash\.txt.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10N/AN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z16008
845*\jecretz.py*.{0,1000}\\jecretz\.py.{0,1000}offensive_tool_keywordjecretzJira Secret Hunter - Helps you find credentials and sensitive contents in Jira ticketsT1552 - T1114 - T1119 - T1070TA0006 - TA0009 - TA0005N/AScattered Spider*Discoveryhttps://github.com/sahadnk72/jecretz10N/AN/A714392022-12-08T10:00:11Z2020-05-25T14:40:28Z16031
846*\Killchain.ps1*.{0,1000}\\Killchain\.ps1.{0,1000}offensive_tool_keywordGraphpythonModular cross-platform Microsoft Graph API (Entra - o365 and Intune) enumeration and exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/Graphpython10N/AN/A72145132024-12-07T21:54:00Z2024-07-10T00:04:48Z16138
847*\krbtgtAccounts.json*.{0,1000}\\krbtgtAccounts\.json.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum10N/AN/A75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z16182
848*\lambdaenum.py*.{0,1000}\\lambdaenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z16197
849*\lansearch.exe*.{0,1000}\\lansearch\.exe.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/10N/AN/A710N/AN/AN/AN/A16199
850*\LansweeperService.exe*.{0,1000}\\LansweeperService\.exe.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/10N/AN/A67N/AN/AN/AN/A16200
851*\LansweeperSetup_*.exe*.{0,1000}\\LansweeperSetup_.{0,1000}\.exe.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/10N/AN/A67N/AN/AN/AN/A16201
852*\ldap_search_bof.py*.{0,1000}\\ldap_search_bof\.py.{0,1000}offensive_tool_keywordbofhoundGenerate BloodHound compatible JSON from logs written by ldapsearch BOF - pyldapsearch and Brute Ratel's LDAP SentinelT1046 - T1087 - T1003TA0007 - TA0009 - TA0001N/AN/ADiscoveryhttps://github.com/fortalice/bofhound10N/AN/A54328562024-02-23T15:36:24Z2022-05-10T17:41:53Z16218
853*\ldap_shell.cmd*.{0,1000}\\ldap_shell\.cmd.{0,1000}offensive_tool_keywordpowerviewPowerView.py is an alternative for the awesome original PowerView.ps1T1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/aniqfakhrul/powerview.py10N/AN/A107622662025-04-22T09:01:39Z2022-06-19T16:13:04Z16219
854*\ldapper.py*.{0,1000}\\ldapper\.py.{0,1000}offensive_tool_keywordLDAPPERLDAP Querying without the SuckT1087 - T1069 - T1018TA0007N/AN/ADiscoveryhttps://github.com/shellster/LDAPPER10N/AN/A7199112024-11-09T03:53:26Z2020-06-17T16:53:35Z16223
855*\LDAPPER-master*.{0,1000}\\LDAPPER\-master.{0,1000}offensive_tool_keywordLDAPPERLDAP Querying without the SuckT1087 - T1069 - T1018TA0007N/AN/ADiscoveryhttps://github.com/shellster/LDAPPER10N/AN/A7199112024-11-09T03:53:26Z2020-06-17T16:53:35Z16224
856*\ldapph.db*.{0,1000}\\ldapph\.db.{0,1000}offensive_tool_keywordLDAP-Password-HunterPassword Hunter in Active DirectoryT1087.002TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/LDAP-Password-Hunter10N/AN/A72198252023-01-06T15:32:34Z2021-07-26T14:27:01Z16225
857*\LibSnaffle*.{0,1000}\\LibSnaffle.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z16239
858*\loadbalancer.py*.{0,1000}\\loadbalancer\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z16313
859*\Local\Temp\Advanced IP Scanner 2\*.{0,1000}\\Local\\Temp\\Advanced\sIP\sScanner\s2\\.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox10N/AN/A710N/AN/AN/AN/A16320
860*\LocalShellExtParse.py*.{0,1000}\\LocalShellExtParse\.py.{0,1000}offensive_tool_keywordLocalShellExtParseScript to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User.T1547.009 - T1129TA0003 - TA0007N/AN/ADiscoveryhttps://github.com/herrcore/LocalShellExtParse10N/AN/A912042015-06-08T16:55:38Z2015-06-05T03:23:13Z16335
861*\LocalShellExtParse-master*.{0,1000}\\LocalShellExtParse\-master.{0,1000}offensive_tool_keywordLocalShellExtParseScript to parse first load time for Shell Extensions loaded by user. Also enumerates all loaded Shell Extensions that are only installed for the Current User.T1547.009 - T1129TA0003 - TA0007N/AN/ADiscoveryhttps://github.com/herrcore/LocalShellExtParse10N/AN/A912042015-06-08T16:55:38Z2015-06-05T03:23:13Z16336
862*\manspider_*.log*.{0,1000}\\manspider_.{0,1000}\.log.{0,1000}offensive_tool_keywordMANSPIDERSpider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!T1046 - T1021 - T1021.002 - T1114 - T1114.001 - T1083TA0007 - TA0009 - TA0010N/AN/ADiscoveryhttps://github.com/blacklanternsecurity/MANSPIDER10N/AN/A81011171382024-07-18T06:14:04Z2020-03-18T13:27:20Z16446
863*\MDE_Enum.csproj*.{0,1000}\\MDE_Enum\.csproj.{0,1000}offensive_tool_keywordMDE_Enumextract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rulesT1070.006TA0005 - TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/0xsp-SRD/MDE_Enum10N/AN/A82198182024-06-10T18:40:27Z2024-06-06T15:54:44Z16451
864*\MDE_Enum.exe*.{0,1000}\\MDE_Enum\.exe.{0,1000}offensive_tool_keywordMDE_Enumextract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rulesT1070.006TA0005 - TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/0xsp-SRD/MDE_Enum10N/AN/A82198182024-06-10T18:40:27Z2024-06-06T15:54:44Z16452
865*\MDE_Enum\Program.cs*.{0,1000}\\MDE_Enum\\Program\.cs.{0,1000}offensive_tool_keywordMDE_Enumextract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rulesT1070.006TA0005 - TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/0xsp-SRD/MDE_Enum10N/AN/A82198182024-06-10T18:40:27Z2024-06-06T15:54:44Z16453
866*\Moriarty.exe*.{0,1000}\\Moriarty\.exe.{0,1000}offensive_tool_keywordMoriartyMoriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments.T1068 - T1083TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/BC-SECURITY/Moriarty10N/AN/A76510672024-08-07T15:06:31Z2023-12-11T14:15:33Z16655
867*\msi_search.c*.{0,1000}\\msi_search\.c.{0,1000}offensive_tool_keywordmsi-searchThis tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairsT1005 TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/mandiant/msi-search10N/AN/A103276312023-07-20T18:12:49Z2023-06-29T18:31:56Z16685
868*\msi_search.exe*.{0,1000}\\msi_search\.exe.{0,1000}offensive_tool_keywordmsi-searchThis tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairsT1005 TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/mandiant/msi-search10N/AN/A103276312023-07-20T18:12:49Z2023-06-29T18:31:56Z16686
869*\msi_search.ps1*.{0,1000}\\msi_search\.ps1.{0,1000}offensive_tool_keywordmsi-searchThis tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairsT1005 TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/mandiant/msi-search10N/AN/A103276312023-07-20T18:12:49Z2023-06-29T18:31:56Z16687
870*\msi_search.x64.o*.{0,1000}\\msi_search\.x64\.o.{0,1000}offensive_tool_keywordmsi-searchThis tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairsT1005 TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/mandiant/msi-search10N/AN/A103276312023-07-20T18:12:49Z2023-06-29T18:31:56Z16688
871*\msi_search.x86.o*.{0,1000}\\msi_search\.x86\.o.{0,1000}offensive_tool_keywordmsi-searchThis tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file to investigate local privilege escalation vulnerabilities through MSI repairsT1005 TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/mandiant/msi-search10N/AN/A103276312023-07-20T18:12:49Z2023-06-29T18:31:56Z16689
872*\net.exe" accounts*.{0,1000}\\net\.exe\"\saccounts.{0,1000}greyware_tool_keywordnetEnumerate local accountsT1087.001 - T1003TA0007 - TA0009N/ANaikon - Magic Hound - APT38 - Dragonfly - Deep Panda - Threat Group-3390 - OilRig - Threat Group-1314 - APT28 - APT41 - menuPass - Ke3chang - Leviathan - APT5 - Orangeworm - GALLIUM - admin@338 - Chimera - APT1 - FIN8 - TA505 - ToddyCat - Turla - APT33 - Wizard Spider - Sandworm Team - APT29 - APT32 - Volt Typhoon - BRONZE BUTLERdiscoveryhttps://thedfirreport.com/2023/02/06/collect-exfiltrate-sleep-repeat/10N/Agreyware tool - risks of False positive !N/AN/AN/AN/AN/AN/A16759
873*\net.exe* localgroup admin*.{0,1000}\\net\.exe.{0,1000}\slocalgroup\sadmin.{0,1000}greyware_tool_keywordnetshowing users in a privileged group. T1069 - T1003TA0007 - TA0040N/ANaikon - Magic Hound - APT38 - Dragonfly - Deep Panda - Threat Group-3390 - OilRig - Threat Group-1314 - APT28 - APT41 - menuPass - Ke3chang - Leviathan - APT5 - Orangeworm - GALLIUM - admin@338 - Chimera - APT1 - FIN8 - TA505 - ToddyCat - Turla - APT33 - Wizard Spider - Sandworm Team - APT29 - APT32 - Volt Typhoon - BRONZE BUTLERDiscoveryhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A16760
874*\net.exe* sessions*.{0,1000}\\net\.exe.{0,1000}\ssessions.{0,1000}greyware_tool_keywordnetList active SMB sessionT1135 - T1047TA0007 - TA0009N/ANaikon - Magic Hound - APT38 - Dragonfly - Deep Panda - Threat Group-3390 - OilRig - Threat Group-1314 - APT28 - APT41 - menuPass - Ke3chang - Leviathan - APT5 - Orangeworm - GALLIUM - admin@338 - Chimera - APT1 - FIN8 - TA505 - ToddyCat - Turla - APT33 - Wizard Spider - Sandworm Team - APT29 - APT32 - Volt Typhoon - BRONZE BUTLERDiscoveryN/A10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A16761
875*\net.exe* view */domain*.{0,1000}\\net\.exe.{0,1000}\sview\s.{0,1000}\/domain.{0,1000}greyware_tool_keywordnetdisplay all domain names on the networkT1016 - T1046TA0007 - TA0009N/ANaikon - Magic Hound - APT38 - Dragonfly - Deep Panda - Threat Group-3390 - OilRig - Threat Group-1314 - APT28 - APT41 - menuPass - Ke3chang - Leviathan - APT5 - Orangeworm - GALLIUM - admin@338 - Chimera - APT1 - FIN8 - TA505 - ToddyCat - Turla - APT33 - Wizard Spider - Sandworm Team - APT29 - APT32 - Volt Typhoon - BRONZE BUTLERDiscoveryN/A10N/AN/AN/A10N/AN/AN/AN/A16762
876*\net1 sessions*.{0,1000}\\net1\ssessions.{0,1000}greyware_tool_keywordnetList active SMB sessionT1135 - T1047TA0007 - TA0009N/ANaikon - Magic Hound - APT38 - Dragonfly - Deep Panda - Threat Group-3390 - OilRig - Threat Group-1314 - APT28 - APT41 - menuPass - Ke3chang - Leviathan - APT5 - Orangeworm - GALLIUM - admin@338 - Chimera - APT1 - FIN8 - TA505 - ToddyCat - Turla - APT33 - Wizard Spider - Sandworm Team - APT29 - APT32 - Volt Typhoon - BRONZE BUTLERDiscoveryN/A10N/Agreyware tool - risks of False positive !1010N/AN/AN/AN/A16785
877*\netscan.dbm-journal*.{0,1000}\\netscan\.dbm\-journal.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A16809
878*\netscan.exe*.{0,1000}\\netscan\.exe.{0,1000}greyware_tool_keywordnetscanSoftPerfect Network Scanner abused by threat actorT1040 - T1046 - T1018TA0007 - TA0010 - TA0001N/ABlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - LynxDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/Anetwork exploitation tool610N/AN/AN/AN/A16810
879*\netscan.exe*.{0,1000}\\netscan\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A16811
880*\netscan.lic*.{0,1000}\\netscan\.lic.{0,1000}greyware_tool_keywordnetscanSoftPerfect Network Scanner abused by threat actorT1040 - T1046 - T1018TA0007 - TA0010 - TA0001N/ABlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - LynxDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/Anetwork exploitation tool610N/AN/AN/AN/A16812
881*\netscan.xml*.{0,1000}\\netscan\.xml.{0,1000}greyware_tool_keywordnetscanSoftPerfect Network Scanner abused by threat actorT1040 - T1046 - T1018TA0007 - TA0010 - TA0001N/ABlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - LynxDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/Anetwork exploitation tool610N/AN/AN/AN/A16813
882*\netscan_linux.tar.gz*.{0,1000}\\netscan_linux\.tar\.gz.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A16814
883*\netscan_portable.zip*.{0,1000}\\netscan_portable\.zip.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A16815
884*\netscan_portable\*.{0,1000}\\netscan_portable\\.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A16816
885*\netscan_setup.exe*.{0,1000}\\netscan_setup\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A16817
886*\netscan_setup.tmp*.{0,1000}\\netscan_setup\.tmp.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A16818
887*\netscan64.exe*.{0,1000}\\netscan64\.exe.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A16819
888*\NetSess.exe*.{0,1000}\\NetSess\.exe.{0,1000}offensive_tool_keywordNetSessCommand line tool to enumerate NetBIOS sessions on a specified local or remote machine. T1016 - T1046 - T1087TA0007 - TA0043N/AMUSTANG PANDADiscoveryhttps://www.joeware.net/freetools/tools/netsess/10N/AN/A79N/AN/AN/AN/A16820
889*\NetSess.zip*.{0,1000}\\NetSess\.zip.{0,1000}offensive_tool_keywordNetSessCommand line tool to enumerate NetBIOS sessions on a specified local or remote machine. T1016 - T1046 - T1087TA0007 - TA0043N/AMUSTANG PANDADiscoveryhttps://www.joeware.net/freetools/tools/netsess/10N/AN/A79N/AN/AN/AN/A16821
890*\NimScan.exe*.{0,1000}\\NimScan\.exe.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan10N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z16871
891*\NimScan.nim*.{0,1000}\\NimScan\.nim.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan10N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z16872
892*\nMethodNamespace=StandIn*.{0,1000}\\nMethodNamespace\=StandIn.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z16925
893*\ntlmutil.py*.{0,1000}\\ntlmutil\.py.{0,1000}offensive_tool_keywordNTMLReconEnumerate information from NTLM authentication enabled web endpointsT1212 - T1212.001 - T1071 - T1071.001 - T1087 - T1087.001TA0009 - TA0007 - TA0006N/AN/ADiscoveryhttps://github.com/puzzlepeaches/NTLMRecon10N/AN/A813532023-08-16T14:34:10Z2023-08-09T12:10:42Z17002
894*\Obfuscated_Command.txt*.{0,1000}\\Obfuscated_Command\.txt.{0,1000}greyware_tool_keywordInvoke-MaldaptiveMaLDAPtive is a framework for LDAP SearchFilter parsing - obfuscation - deobfuscation and detection.T1027TA0005 - TA0007N/AN/ADiscoveryhttps://github.com/MaLDAPtive/Invoke-Maldaptive10N/AN/A73277262024-08-07T21:12:45Z2024-08-07T20:43:52Z17021
895*\Outflank-Recon-AD\*.{0,1000}\\Outflank\-Recon\-AD\\.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17065
896*\OxidResolver.exe*.{0,1000}\\OxidResolver\.exe.{0,1000}offensive_tool_keywordSharpOxidResolversearch the current domain for computers and get bindings for all of themT1018 - T1046 - T1016TA0007N/AKNOTWEEDDiscoveryhttps://github.com/S3cur3Th1sSh1t/SharpOxidResolver10N/AN/A915092020-11-25T08:42:06Z2020-11-25T08:23:23Z17075
897*\passwords.doc*.{0,1000}\\passwords\.doc.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z17130
898*\passwords.docx*.{0,1000}\\passwords\.docx.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z17132
899*\passwords.txt*.{0,1000}\\passwords\.txt.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z17133
900*\passwords.xls*.{0,1000}\\passwords\.xls.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z17134
901*\passwords.xlsx*.{0,1000}\\passwords\.xlsx.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10N/AAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z17135
902*\PipeViewer.exe*.{0,1000}\\PipeViewer\.exe.{0,1000}offensive_tool_keywordPipeViewer A tool that shows detailed information about named pipes in WindowsT1022.002 - T1056.002TA0005 - TA0009N/AN/Adiscoveryhttps://github.com/cyberark/PipeViewer10N/AN/A57620552024-11-15T09:55:35Z2022-12-22T12:35:34Z17282
903*\PipeViewer.sln*.{0,1000}\\PipeViewer\.sln.{0,1000}offensive_tool_keywordPipeViewer A tool that shows detailed information about named pipes in WindowsT1022.002 - T1056.002TA0005 - TA0009N/AN/Adiscoveryhttps://github.com/cyberark/PipeViewer10N/AN/A57620552024-11-15T09:55:35Z2022-12-22T12:35:34Z17283
904*\PipeViewer\Program.cs*.{0,1000}\\PipeViewer\\Program\.cs.{0,1000}offensive_tool_keywordPipeViewer A tool that shows detailed information about named pipes in WindowsT1022.002 - T1056.002TA0005 - TA0009N/AN/Adiscoveryhttps://github.com/cyberark/PipeViewer10N/AN/A57620552024-11-15T09:55:35Z2022-12-22T12:35:34Z17284
905*\polenum.py*.{0,1000}\\polenum\.py.{0,1000}offensive_tool_keywordpolenumUses Impacket Library to get the password policy from a windows machineT1012 - T1596TA0009 - TA0007N/AN/ADiscoveryhttps://salsa.debian.org/pkg-security-team/polenum10N/AN/A810N/AN/AN/AN/A17315
906*\PortQry.exe*.{0,1000}\\PortQry\.exe.{0,1000}greyware_tool_keywordPortQryMicrosoft port scanning tool abused by threat actorsT1046 - T1016 - T1049TA0007N/AAPT15Discoveryhttps://www.microsoft.com/en-us/download/details.aspx?id=1714810N/AN/A67N/AN/AN/AN/A17328
907*\PortQryV2.exe*.{0,1000}\\PortQryV2\.exe.{0,1000}greyware_tool_keywordPortQryMicrosoft port scanning tool abused by threat actorsT1046 - T1016 - T1049TA0007N/AAPT15Discoveryhttps://www.microsoft.com/en-us/download/details.aspx?id=1714810N/AN/A67N/AN/AN/AN/A17329
908*\PortQryV2\*.{0,1000}\\PortQryV2\\.{0,1000}greyware_tool_keywordPortQryMicrosoft port scanning tool abused by threat actorsT1046 - T1016 - T1049TA0007N/AAPT15Discoveryhttps://www.microsoft.com/en-us/download/details.aspx?id=1714810N/AN/A67N/AN/AN/AN/A17330
909*\port-scan-tcp.ps1*.{0,1000}\\port\-scan\-tcp\.ps1.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools10N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z17337
910*\port-scan-udp.ps1*.{0,1000}\\port\-scan\-udp\.ps1.{0,1000}offensive_tool_keywordMinimalistic-offensiveA repository of tools for pentesting of restricted and isolated environments.T1110 - T1046 - T1021 - T1203 - T1485TA0006 - TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/InfosecMatter/Minimalistic-offensive-security-tools10N/AN/A765621212021-10-26T11:04:46Z2020-05-10T17:40:31Z17338
911*\PowerView.Log*.{0,1000}\\PowerView\.Log.{0,1000}offensive_tool_keywordpowerviewPowerView is a PowerShell tool to gain network situational awareness on Windows domainsT1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/ADispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDADiscoveryhttps://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps110N/AN/A10101227446602020-08-17T23:19:49Z2012-05-26T16:08:48Z17408
912*\powerview.py*.{0,1000}\\powerview\.py.{0,1000}offensive_tool_keywordpowerviewPowerView.py is an alternative for the awesome original PowerView.ps1T1046 - T1087.001 - T1016TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/aniqfakhrul/powerview.py10N/AN/A107622662025-04-22T09:01:39Z2022-06-19T16:13:04Z17412
913*\Program Files (x86)\Advanced IP Scanner\*.{0,1000}\\Program\sFiles\s\(x86\)\\Advanced\sIP\sScanner\\.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox10N/AN/A710N/AN/AN/AN/A17492
914*\Program Files (x86)\Lansweeper*.{0,1000}\\Program\sFiles\s\(x86\)\\Lansweeper.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/10N/AN/A67N/AN/AN/AN/A17502
915*\Program Files\WizTree*.{0,1000}\\Program\sFiles\\WizTree.{0,1000}greyware_tool_keywordwiztreelegitimate tool abused by threat actors to obtain network files and directory listingsT1083TA0007N/AFox Kitten - Faust - Bitlocker - Akira - Cactus - BlackSuit - RoyalDiscoveryN/A10N/AN/A36N/AN/AN/AN/A17539
916*\Programs\Advanced IP Scanner Portable\*.{0,1000}\\Programs\\Advanced\sIP\sScanner\sPortable\\.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox10N/AN/A710N/AN/AN/AN/A17562
917*\PsExecLog.log*.{0,1000}\\PsExecLog\.log.{0,1000}offensive_tool_keywordGoFetchGoFetch is a tool to automatically exercise an attack plan generated by the BloodHound application.T1078 - T1078.003 - T1021 - T1021.006 - T1076.001TA0005 - TA0001 - TA0003N/ADispossessorDiscoveryhttps://github.com/GoFetchAD/GoFetch10N/AN/A107633992017-06-20T14:15:10Z2017-04-11T10:45:23Z17604
918*\pslist.exe*.{0,1000}\\pslist\.exe.{0,1000}greyware_tool_keywordpslistMicrosoft sysinternal comandline tool to list running process abused by threat actorsT1057 - T1012 - T1106TA0007N/AAPT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - ElfinDiscoveryhttps://learn.microsoft.com/pt-br/sysinternals/downloads/pslist10N/AN/A39N/AN/AN/AN/A17612
919*\pslist64.exe*.{0,1000}\\pslist64\.exe.{0,1000}greyware_tool_keywordpslistMicrosoft sysinternal comandline tool to list running process abused by threat actorsT1057 - T1012 - T1106TA0007N/AAPT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - ElfinDiscoveryhttps://learn.microsoft.com/pt-br/sysinternals/downloads/pslist10N/AN/A39N/AN/AN/AN/A17613
920*\PSnmap.ps1*.{0,1000}\\PSnmap\.ps1.{0,1000}offensive_tool_keywordPsnmapPowershell scanner (nmap like)T1086 - T1046 - T1059TA0007N/ABlack BastaDiscoveryhttps://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps110N/AN/A72178642024-08-23T18:24:20Z2015-01-24T10:46:41Z17614
921*\PSnmap.psd1*.{0,1000}\\PSnmap\.psd1.{0,1000}offensive_tool_keywordPsnmapPowershell scanner (nmap like)T1086 - T1046 - T1059TA0007N/ABlack BastaDiscoveryhttps://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps110N/AN/A72178642024-08-23T18:24:20Z2015-01-24T10:46:41Z17615
922*\PSnmap.psm1*.{0,1000}\\PSnmap\.psm1.{0,1000}offensive_tool_keywordPsnmapPowershell scanner (nmap like)T1086 - T1046 - T1059TA0007N/ABlack BastaDiscoveryhttps://github.com/KurtDeGreeff/PlayPowershell/blob/master/PSnmap.ps110N/AN/A72178642024-08-23T18:24:20Z2015-01-24T10:46:41Z17616
923*\pspy\pspy.go*.{0,1000}\\pspy\\pspy\.go.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy10#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z17623
924*\PSRecon\*.{0,1000}\\PSRecon\\.{0,1000}offensive_tool_keywordPSReconPSRecon gathers data from a remote Windows host using PowerShell (v2 or later). organizes the data into folders. hashes all extracted data. hashes PowerShell and various system properties. and sends the data off to the security team. The data can be pushed to a share. sent over email. or retained locally.T1059 - T1003 - T1556 - T1204TA0002 - TA0009N/AN/ADiscoveryhttps://github.com/gfoss/PSRecon10N/AN/A954861052017-07-29T15:03:04Z2015-08-03T05:43:38Z17626
925*\psscanner\psscanner.go*.{0,1000}\\psscanner\\psscanner\.go.{0,1000}offensive_tool_keywordpspyMonitor linux processes without root permissionsT1057 - T1082 - T1518.001TA0007N/AN/ADiscoveryhttps://github.com/DominicBreuker/pspy10#linuxN/A81053705382023-01-17T21:09:22Z2018-02-08T21:41:37Z17628
926*\Public\Document\SessionHunter.txt*.{0,1000}\\Public\\Document\\SessionHunter\.txt.{0,1000}offensive_tool_keywordInvoke-SessionHunterRetrieve and display information about active user sessions on remote computers. No admin privileges requiredT1033 - T1078 - T1110TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-SessionHunter10N/AN/A72183202024-08-12T13:15:10Z2023-08-13T13:22:05Z17636
927*\pyshark\src\*.{0,1000}\\pyshark\\src\\.{0,1000}greyware_tool_keywordpysharkPython wrapper for tshark allowing python packet parsing using wireshark dissectorsT1040 - T1213 - T1105 - T1572TA0009 - TA0007N/AN/ADiscoveryhttps://github.com/KimiNewt/pyshark10N/AN/A61023554392024-12-04T15:41:20Z2013-12-28T14:38:22Z17693
928*\quiet-riot-main*.{0,1000}\\quiet\-riot\-main.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z17716
929*\rattler.cpp*.{0,1000}\\rattler\.cpp.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z17762
930*\Rattler.exe*.{0,1000}\\Rattler\.exe.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z17763
931*\Rattler_32.exe*.{0,1000}\\Rattler_32\.exe.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z17764
932*\Rattler_x64.exe*.{0,1000}\\Rattler_x64\.exe.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z17765
933*\rattler-master*.{0,1000}\\rattler\-master.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z17766
934*\Recon-AD-AllLocalGroups.dll.{0,1000}\\Recon\-AD\-AllLocalGroups\.dlloffensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17830
935*\Recon-AD-AllLocalGroups.sln*.{0,1000}\\Recon\-AD\-AllLocalGroups\.sln.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17832
936*\Recon-AD-AllLocalGroups\*.{0,1000}\\Recon\-AD\-AllLocalGroups\\.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17833
937*\Recon-AD-Computers.dll.{0,1000}\\Recon\-AD\-Computers\.dlloffensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17834
938*\Recon-AD-Computers.sln*.{0,1000}\\Recon\-AD\-Computers\.sln.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17836
939*\Recon-AD-Computers\*.{0,1000}\\Recon\-AD\-Computers\\.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17837
940*\Recon-AD-Domain.dll.{0,1000}\\Recon\-AD\-Domain\.dlloffensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17838
941*\Recon-AD-Domain.sln*.{0,1000}\\Recon\-AD\-Domain\.sln.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17840
942*\Recon-AD-Domain\*.{0,1000}\\Recon\-AD\-Domain\\.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17841
943*\Recon-AD-Groups.dll.{0,1000}\\Recon\-AD\-Groups\.dlloffensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17842
944*\Recon-AD-Groups.sln*.{0,1000}\\Recon\-AD\-Groups\.sln.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17844
945*\Recon-AD-LocalGroups.dll*.{0,1000}\\Recon\-AD\-LocalGroups\.dll.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17846
946*\Recon-AD-LocalGroups.sln*.{0,1000}\\Recon\-AD\-LocalGroups\.sln.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17847
947*\Recon-AD-LocalGroups\*.{0,1000}\\Recon\-AD\-LocalGroups\\.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17848
948*\Recon-AD-master*.{0,1000}\\Recon\-AD\-master.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17849
949*\Recon-AD-SPNs.sln*.{0,1000}\\Recon\-AD\-SPNs\.sln.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17851
950*\Recon-AD-SPNs\*.{0,1000}\\Recon\-AD\-SPNs\\.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17852
951*\Recon-AD-Users.dll*.{0,1000}\\Recon\-AD\-Users\.dll.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17854
952*\Recon-AD-Users.sln*.{0,1000}\\Recon\-AD\-Users\.sln.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17855
953*\ReflectiveDll.cpp*.{0,1000}\\ReflectiveDll\.cpp.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17876
954*\ReflectiveLoader.cpp*.{0,1000}\\ReflectiveLoader\.cpp.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z17878
955*\RpcView.exe*.{0,1000}\\RpcView\.exe.{0,1000}greyware_tool_keywordRpcViewRpcView is a free tool to explore and decompile Microsoft RPC interfacesT1082 - T1016 - T1046 - T1622TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/silverf0x/RpcView10N/AN/A6109652552023-09-24T19:58:04Z2017-03-14T19:14:45Z18172
956*\RpcView64.7z*.{0,1000}\\RpcView64\.7z.{0,1000}greyware_tool_keywordRpcViewRpcView is a free tool to explore and decompile Microsoft RPC interfacesT1082 - T1016 - T1046 - T1622TA0007 - TA0008N/ADispossessorDiscoveryhttps://github.com/silverf0x/RpcView10N/AN/A6109652552023-09-24T19:58:04Z2017-03-14T19:14:45Z18173
957*\RunOnce\wextract_cleanup0*.{0,1000}\\RunOnce\\wextract_cleanup0.{0,1000}greyware_tool_keywordPortQryMicrosoft port scanning tool abused by threat actorsT1046 - T1016 - T1049TA0007N/AAPT15Discoveryhttps://www.microsoft.com/en-us/download/details.aspx?id=1714810#registryN/A67N/AN/AN/AN/A18222
958*\rusthound.exe*.{0,1000}\\rusthound\.exe.{0,1000}offensive_tool_keywordRustHoundActive Directory data collector for BloodHound written in RustT1087.002 - T1018 - T1059.003TA0007 - TA0001 - TA0002N/AN/ADiscoveryhttps://github.com/OPENCYBER-FR/RustHound10N/AAD Enumeration9101013982024-10-21T18:58:20Z2022-10-12T05:54:35Z18233
959*\s3aclenum.py*.{0,1000}\\s3aclenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z18243
960*\s3enum.py*.{0,1000}\\s3enum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z18244
961*\scanACLsResults.csv*.{0,1000}\\scanACLsResults\.csv.{0,1000}offensive_tool_keywordACLightA tool for advanced discovery of Privileged Accounts - including Shadow Admins.T1087 - T1003 - T1208TA0001 - TA0006 - TA0008N/AN/ADiscoveryhttps://github.com/cyberark/ACLight10N/AAD Enumeration798011462019-09-09T06:48:45Z2017-05-17T09:29:41Z18286
962*\SearchShares.ps1*.{0,1000}\\SearchShares\.ps1.{0,1000}offensive_tool_keywordSearchOpenFileSharesSearches open files shares for password files or database backups - Extend as you see fitT1083 - T1135 - T1005 - T1025TA0007 - TA0009N/ADispossessorDiscoveryhttps://github.com/fashionproof/SearchOpenFileShares10N/AN/A712962019-12-13T12:37:42Z2019-09-21T13:50:26Z18330
963*\secretsmanagerenum.py*.{0,1000}\\secretsmanagerenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z18349
964*\ShadowSpray\*.cs*.{0,1000}\\ShadowSpray\\.{0,1000}\.cs.{0,1000}offensive_tool_keywordShadowSprayA tool to spray Shadow Credentials across an entire domain in hopes of abusing long forgotten GenericWrite/GenericAll DACLs over other objects in the domain.T1110.003 - T1098 - T1059 - T1075TA0001 - TA0008 - TA0009N/ABlack BastaDiscoveryhttps://github.com/ShorSec/ShadowSpray10N/AN/A75459802022-10-14T13:36:51Z2022-10-10T08:34:07Z18412
965*\shareaudit.exe*.{0,1000}\\shareaudit\.exe.{0,1000}offensive_tool_keywordShareAuditA tool for auditing network shares in an Active Directory environmentT1135 - T1005 - T1083 - T1210TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/dionach/ShareAudit10N/AN/A8142152019-04-29T10:07:57Z2019-02-26T16:00:15Z18418
966*\ShareAudit.sln*.{0,1000}\\ShareAudit\.sln.{0,1000}offensive_tool_keywordShareAuditA tool for auditing network shares in an Active Directory environmentT1135 - T1005 - T1083 - T1210TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/dionach/ShareAudit10N/AN/A8142152019-04-29T10:07:57Z2019-02-26T16:00:15Z18419
967*\Shares_CleanupCommand.txt*.{0,1000}\\Shares_CleanupCommand\.txt.{0,1000}offensive_tool_keywordInvoke-ShareHunterEnumerate the Domain for Readable and Writable SharesT1135TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ShareHunter10N/AN/A511712025-02-18T14:56:51Z2023-09-21T14:31:17Z18422
968*\Shares_Readable.txt*.{0,1000}\\Shares_Readable\.txt.{0,1000}offensive_tool_keywordInvoke-ShareHunterEnumerate the Domain for Readable and Writable SharesT1135TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ShareHunter10N/AN/A511712025-02-18T14:56:51Z2023-09-21T14:31:17Z18423
969*\Shares_Writable.txt"*.{0,1000}\\Shares_Writable\.txt\".{0,1000}offensive_tool_keywordInvoke-ShareHunterEnumerate the Domain for Readable and Writable SharesT1135TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ShareHunter10N/AN/A511712025-02-18T14:56:51Z2023-09-21T14:31:17Z18424
970*\SharpADWS.csproj*.{0,1000}\\SharpADWS\.csproj.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z18426
971*\SharpADWS.sln*.{0,1000}\\SharpADWS\.sln.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z18427
972*\SharpADWS\*.{0,1000}\\SharpADWS\\.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z18428
973*\SharpADWS-master*.{0,1000}\\SharpADWS\-master.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z18429
974*\SharpAVKB.exe*.{0,1000}\\SharpAVKB\.exe.{0,1000}offensive_tool_keywordSharpAVKBWindows Antivirus Comparison and Patch Number ComparisonT1082 - T1518 - T1083TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpAVKB10N/AN/A4158242019-10-28T06:50:30Z2019-10-14T12:44:22Z18439
975*\SharpAVKB.pdb*.{0,1000}\\SharpAVKB\.pdb.{0,1000}offensive_tool_keywordSharpAVKBWindows Antivirus Comparison and Patch Number ComparisonT1082 - T1518 - T1083TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpAVKB10#contentN/A4158242019-10-28T06:50:30Z2019-10-14T12:44:22Z18440
976*\SharpAVKB-master*.{0,1000}\\SharpAVKB\-master.{0,1000}offensive_tool_keywordSharpAVKBWindows Antivirus Comparison and Patch Number ComparisonT1082 - T1518 - T1083TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpAVKB10N/AN/A4158242019-10-28T06:50:30Z2019-10-14T12:44:22Z18441
977*\SharpAzbelt.csproj*.{0,1000}\\SharpAzbelt\.csproj.{0,1000}offensive_tool_keywordSharpAzbeltThis is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resourcesT1082 - T1003 - T1027 - T1110 - T1078TA0006 - TA0007 - TA0005 - TA0004 - TA0003N/AN/ADiscoveryhttps://github.com/redskal/SharpAzbelt10N/AN/A812672023-09-21T21:47:32Z2023-09-21T21:44:03Z18442
978*\SharpAzbelt.exe*.{0,1000}\\SharpAzbelt\.exe.{0,1000}offensive_tool_keywordSharpAzbeltThis is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resourcesT1082 - T1003 - T1027 - T1110 - T1078TA0006 - TA0007 - TA0005 - TA0004 - TA0003N/AN/ADiscoveryhttps://github.com/redskal/SharpAzbelt10N/AN/A812672023-09-21T21:47:32Z2023-09-21T21:44:03Z18443
979*\SharpAzbelt.sln*.{0,1000}\\SharpAzbelt\.sln.{0,1000}offensive_tool_keywordSharpAzbeltThis is an attempt to port Azbelt by Leron Gray from Nim to C#. It can be used to enumerate and pilfer Azure-related credentials from Windows boxes and Azure IaaS resourcesT1082 - T1003 - T1027 - T1110 - T1078TA0006 - TA0007 - TA0005 - TA0004 - TA0003N/AN/ADiscoveryhttps://github.com/redskal/SharpAzbelt10N/AN/A812672023-09-21T21:47:32Z2023-09-21T21:44:03Z18444
980*\SharpBuster.csproj*.{0,1000}\\SharpBuster\.csproj.{0,1000}offensive_tool_keywordSharpBusterThis is a C# implementation of a directory brute forcing tool designed to allow for in-memory executionT1087 - T1112 - T1048.003 - T1105TA0007 - TA0040 - TA0002N/AN/ADiscoveryhttps://github.com/passthehashbrowns/SharpBuster10N/AN/A716272020-09-02T15:46:03Z2020-08-31T00:33:02Z18447
981*\SharpBuster.dll*.{0,1000}\\SharpBuster\.dll.{0,1000}offensive_tool_keywordSharpBusterThis is a C# implementation of a directory brute forcing tool designed to allow for in-memory executionT1087 - T1112 - T1048.003 - T1105TA0007 - TA0040 - TA0002N/AN/ADiscoveryhttps://github.com/passthehashbrowns/SharpBuster10N/AN/A716272020-09-02T15:46:03Z2020-08-31T00:33:02Z18448
982*\SharpBuster.exe*.{0,1000}\\SharpBuster\.exe.{0,1000}offensive_tool_keywordSharpBusterThis is a C# implementation of a directory brute forcing tool designed to allow for in-memory executionT1087 - T1112 - T1048.003 - T1105TA0007 - TA0040 - TA0002N/AN/ADiscoveryhttps://github.com/passthehashbrowns/SharpBuster10N/AN/A716272020-09-02T15:46:03Z2020-08-31T00:33:02Z18449
983*\SharpBuster.pdb*.{0,1000}\\SharpBuster\.pdb.{0,1000}offensive_tool_keywordSharpBusterThis is a C# implementation of a directory brute forcing tool designed to allow for in-memory executionT1087 - T1112 - T1048.003 - T1105TA0007 - TA0040 - TA0002N/AN/ADiscoveryhttps://github.com/passthehashbrowns/SharpBuster10N/AN/A716272020-09-02T15:46:03Z2020-08-31T00:33:02Z18450
984*\SharpBuster.sln*.{0,1000}\\SharpBuster\.sln.{0,1000}offensive_tool_keywordSharpBusterThis is a C# implementation of a directory brute forcing tool designed to allow for in-memory executionT1087 - T1112 - T1048.003 - T1105TA0007 - TA0040 - TA0002N/AN/ADiscoveryhttps://github.com/passthehashbrowns/SharpBuster10N/AN/A716272020-09-02T15:46:03Z2020-08-31T00:33:02Z18451
985*\SharpEDRChecker-*.zip*.{0,1000}\\SharpEDRChecker\-.{0,1000}\.zip.{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10N/AN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z18519
986*\SharpEDRChecker.cs*.{0,1000}\\SharpEDRChecker\.cs.{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10N/AN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z18520
987*\SharpEDRChecker.sln*.{0,1000}\\SharpEDRChecker\.sln.{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10N/AN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z18524
988*\SharpEDRChecker\*.{0,1000}\\SharpEDRChecker\\.{0,1000}offensive_tool_keywordSharpEDRCheckerChecks for the presence of known defensive products such as AV/EDR and logging toolsT1083 - T1518.001 - T1063TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/PwnDexter/SharpEDRChecker10N/AN/A88706982023-10-09T11:17:49Z2020-06-16T10:25:00Z18525
989*\SharpEventLog.csproj*.{0,1000}\\SharpEventLog\.csproj.{0,1000}offensive_tool_keywordSharpEventLogreads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetrationT1078 - T1087.001TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpEventLog10N/AN/A43205342019-10-15T06:26:52Z2019-10-15T06:14:32Z18536
990*\SharpEventLog.exe*.{0,1000}\\SharpEventLog\.exe.{0,1000}offensive_tool_keywordSharpEventLogreads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetrationT1078 - T1087.001TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpEventLog10N/AN/A43205342019-10-15T06:26:52Z2019-10-15T06:14:32Z18538
991*\SharpEventLog.pdb*.{0,1000}\\SharpEventLog\.pdb.{0,1000}offensive_tool_keywordSharpEventLogreads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetrationT1078 - T1087.001TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpEventLog10#contentN/A43205342019-10-15T06:26:52Z2019-10-15T06:14:32Z18539
992*\SharpEventLog.sln*.{0,1000}\\SharpEventLog\.sln.{0,1000}offensive_tool_keywordSharpEventLogreads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetrationT1078 - T1087.001TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpEventLog10N/AN/A43205342019-10-15T06:26:52Z2019-10-15T06:14:32Z18540
993*\SharpEventLog-master*.{0,1000}\\SharpEventLog\-master.{0,1000}offensive_tool_keywordSharpEventLogreads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetrationT1078 - T1087.001TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpEventLog10N/AN/A43205342019-10-15T06:26:52Z2019-10-15T06:14:32Z18541
994*\SharpGraphView.sln*.{0,1000}\\SharpGraphView\.sln.{0,1000}offensive_tool_keywordSharpGraphViewMicrosoft Graph API post-exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/SharpGraphView10N/AN/A619492024-07-13T12:27:38Z2024-05-04T11:23:42Z18564
995*\sharpgraphview\*.{0,1000}\\sharpgraphview\\.{0,1000}offensive_tool_keywordSharpGraphViewMicrosoft Graph API post-exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/SharpGraphView10N/AN/A619492024-07-13T12:27:38Z2024-05-04T11:23:42Z18565
996*\SharpHound.pdb*.{0,1000}\\SharpHound\.pdb.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z18579
997*\SharpHound.pdb*.{0,1000}\\SharpHound\.pdb.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z18581
998*\SharpHound.ps1*.{0,1000}\\SharpHound\.ps1.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z18583
999*\SharpHoundCommon\*.{0,1000}\\SharpHoundCommon\\.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z18584
1000*\SharpHound-v*.zip*.{0,1000}\\SharpHound\-v.{0,1000}\.zip.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z18585
1001*\SharpLDAP\*.{0,1000}\\SharpLDAP\\.{0,1000}offensive_tool_keywordSharpLDAPtool written in C# that aims to do enumeration via LDAP queriesT1018 - T1069.003TA0007 - TA0011N/AN/ADiscoveryhttps://github.com/mertdas/SharpLDAP10N/AN/A81012023-01-14T21:52:36Z2022-11-16T00:38:43Z18602
1002*\SharpNBTScan.sln*.{0,1000}\\SharpNBTScan\.sln.{0,1000}offensive_tool_keywordSharpNBTScana NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumerationT1018 - T1046TA0007Ghost RansomwareN/ADiscoveryhttps://github.com/BronzeTicket/SharpNBTScan10N/AN/A717142021-08-06T05:36:55Z2021-07-12T08:57:39Z18629
1003*\SharpNBTScan-main*.{0,1000}\\SharpNBTScan\-main.{0,1000}offensive_tool_keywordSharpNBTScana NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumerationT1018 - T1046TA0007Ghost RansomwareN/ADiscoveryhttps://github.com/BronzeTicket/SharpNBTScan10N/AN/A717142021-08-06T05:36:55Z2021-07-12T08:57:39Z18630
1004*\SharpRODC.*.{0,1000}\\SharpRODC\..{0,1000}offensive_tool_keywordSharpRODCaudit the security of read-only domain controllersT1012 - T1482 - T1207 - T1208 - T1209 - T1212TA0007 - TA0008 - TA0006N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpRODC10N/AN/A8211582023-11-27T12:41:52Z2023-11-24T14:35:49Z18657
1005*\SharpRODC\*.{0,1000}\\SharpRODC\\.{0,1000}offensive_tool_keywordSharpRODCaudit the security of read-only domain controllersT1012 - T1482 - T1207 - T1208 - T1209 - T1212TA0007 - TA0008 - TA0006N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpRODC10N/AN/A8211582023-11-27T12:41:52Z2023-11-24T14:35:49Z18658
1006*\SharpShares\*.{0,1000}\\SharpShares\\.{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/Hackcraft-Labs/SharpShares10N/AN/A1013372023-11-13T14:08:07Z2023-10-25T10:34:18Z18675
1007*\SharpShares-master*.{0,1000}\\SharpShares\-master.{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/Hackcraft-Labs/SharpShares10N/AN/A1013372023-11-13T14:08:07Z2023-10-25T10:34:18Z18676
1008*\SharpSSDP.csproj*.{0,1000}\\SharpSSDP\.csproj.{0,1000}offensive_tool_keywordSharpSSDP execute SharpSSDP.exe through Cobalt Strike's Beacon "execute-assembly" module to discover SSDP related servicesT1046 - T1016TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/rvrsh3ll/SharpSSDP10N/AN/A711742018-12-16T17:14:28Z2018-12-16T17:14:12Z18717
1009*\SharpSSDP.sln*.{0,1000}\\SharpSSDP\.sln.{0,1000}offensive_tool_keywordSharpSSDP execute SharpSSDP.exe through Cobalt Strike's Beacon "execute-assembly" module to discover SSDP related servicesT1046 - T1016TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/rvrsh3ll/SharpSSDP10N/AN/A711742018-12-16T17:14:28Z2018-12-16T17:14:12Z18718
1010*\SharpSSDP\*.{0,1000}\\SharpSSDP\\.{0,1000}offensive_tool_keywordSharpSSDP execute SharpSSDP.exe through Cobalt Strike's Beacon "execute-assembly" module to discover SSDP related servicesT1046 - T1016TA0007 - TA0005N/AN/ADiscoveryhttps://github.com/rvrsh3ll/SharpSSDP10N/AN/A711742018-12-16T17:14:28Z2018-12-16T17:14:12Z18719
1011*\SmallSecretsDump.py*.{0,1000}\\SmallSecretsDump\.py.{0,1000}offensive_tool_keywordAdcheckAssess the security of your Active Directory with few or all privileges. This tool offers functionalities similar to PingCastleT1087 - T1012 - T1482 - T1059 - T1203 - T1212 - T1480 - T1552 - T1112 - T1207 - T1483 - T1113 - T1057 - T1136 - T1119 - T1082 - T1553 - T1140 - T1107 - T1078 - T1562TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009N/AN/ADiscoveryhttps://github.com/CobblePot59/Adcheck10N/AN/A104315352025-04-18T15:17:46Z2024-05-10T13:54:45Z18877
1012*\smbscan-*.csv*.{0,1000}\\smbscan\-.{0,1000}\.csv.{0,1000}offensive_tool_keywordsmbscanSMBScan is a tool to enumerate file shares on an internal network.T1135 - T1046 - T1021TA0007 - TA0043 - TA0008N/AAPT22Discoveryhttps://github.com/jeffhacks/smbscan10N/AN/A814462025-03-24T01:55:30Z2021-10-26T02:28:34Z18903
1013*\smbscan-*.log*.{0,1000}\\smbscan\-.{0,1000}\.log.{0,1000}offensive_tool_keywordsmbscanSMBScan is a tool to enumerate file shares on an internal network.T1135 - T1046 - T1021TA0007 - TA0043 - TA0008N/AAPT22Discoveryhttps://github.com/jeffhacks/smbscan10N/AN/A814462025-03-24T01:55:30Z2021-10-26T02:28:34Z18904
1014*\smbscan.py*.{0,1000}\\smbscan\.py.{0,1000}offensive_tool_keywordsmbscanSMBScan is a tool to enumerate file shares on an internal network.T1135 - T1046 - T1021TA0007 - TA0043 - TA0008N/AAPT22Discoveryhttps://github.com/jeffhacks/smbscan10N/AN/A814462025-03-24T01:55:30Z2021-10-26T02:28:34Z18905
1015*\SMBSigningNotRequired.txt*.{0,1000}\\SMBSigningNotRequired\.txt.{0,1000}offensive_tool_keywordCheckSMBSigningChecks for SMB signing disabled on all hosts in the networkT1018 - T1550TA0007 - TA0008N/AN/ADiscoveryhttps://github.com/Leo4j/CheckSMBSigning10N/AN/A61812023-10-13T11:55:33Z2023-05-17T11:47:52Z18907
1016*\smbsr.db*.{0,1000}\\smbsr\.db.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z18908
1017*\smbsr.log*.{0,1000}\\smbsr\.log.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z18909
1018*\smbsr.py*.{0,1000}\\smbsr\.py.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z18910
1019*\smbsr_results.csv*.{0,1000}\\smbsr_results\.csv.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z18911
1020*\snsenum.py*.{0,1000}\\snsenum\.py.{0,1000}offensive_tool_keywordquiet-riotUnauthenticated enumeration of AWS - Azure and GCP PrincipalsT1087 - T1083 - T1210TA0007 - TA0001N/AN/ADiscoveryhttps://github.com/righteousgambit/quiet-riot10N/AN/A63224302024-11-13T19:41:26Z2021-10-28T15:12:27Z18932
1021*\SOAPHound.csproj*.{0,1000}\\SOAPHound\.csproj.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z18933
1022*\SOAPHound.exe*.{0,1000}\\SOAPHound\.exe.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z18934
1023*\SOAPHound.sln*.{0,1000}\\SOAPHound\.sln.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z18935
1024*\SOAPHound\Enums\*.{0,1000}\\SOAPHound\\Enums\\.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z18936
1025*\SOAPHound\Program.cs*.{0,1000}\\SOAPHound\\Program\.cs.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z18937
1026*\SOAPHound-master*.{0,1000}\\SOAPHound\-master.{0,1000}offensive_tool_keywordSOAPHoundenumerate Active Directory environments via the Active Directory Web Services (ADWS)T1018 - T1087.002 - T1649TA0007 - TA0003N/AN/ADiscoveryhttps://github.com/FalconForceTeam/SOAPHound10N/AN/A88736762024-02-03T08:52:49Z2024-01-25T09:11:12Z18938
1027*\SoftPerfect Network Scanner*.{0,1000}\\SoftPerfect\sNetwork\sScanner.{0,1000}greyware_tool_keywordnetscanSoftPerfect Network Scanner abused by threat actorT1040 - T1046 - T1018TA0007 - TA0010 - TA0001N/ABlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - AvosLocker - FiveHands - Yanluowang - MONTI - DarkSide - Everest - Cicada3301 - MedusaLocker - DragonForce - Phobos - LynxDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/Anetwork exploitation tool610N/AN/AN/AN/A18947
1028*\SoftPerfect Network Scanner\*.{0,1000}\\SoftPerfect\sNetwork\sScanner\\.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10N/AN/A810N/AN/AN/AN/A18948
1029*\Software\MSDART\Active Directory Explorer*.{0,1000}\\Software\\MSDART\\Active\sDirectory\sExplorer.{0,1000}greyware_tool_keywordadexplorerActive Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actorsT1003.001 - T1087.001TA0006 - TA0007N/ALapsus$ - Scattered Spider* - BlackBastaDiscoveryhttps://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer10#registrygreyware tool - risks of False positive !710N/AN/AN/AN/A18965
1030*\Software\Sysinternals\Active Directory Explorer*.{0,1000}\\Software\\Sysinternals\\Active\sDirectory\sExplorer.{0,1000}greyware_tool_keywordadexplorerActive Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actorsT1003.001 - T1087.001TA0006 - TA0007N/ALapsus$ - Scattered Spider* - BlackBastaDiscoveryhttps://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer10#registrygreyware tool - risks of False positive !710N/AN/AN/AN/A18974
1031*\Src\Recon-AD-Groups\*.{0,1000}\\Src\\Recon\-AD\-Groups\\.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z19084
1032*\Src\Recon-AD-Users\*.{0,1000}\\Src\\Recon\-AD\-Users\\.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD10N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z19085
1033*\StandIn --*.{0,1000}\\StandIn\s\-\-.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z19099
1034*\StandIn.exe*.{0,1000}\\StandIn\.exe.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z19100
1035*\StandIn.pdb*.{0,1000}\\StandIn\.pdb.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z19101
1036*\StandIn\hStandIn.cs*.{0,1000}\\StandIn\\hStandIn\.cs.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z19102
1037*\StandIn\Program.cs*.{0,1000}\\StandIn\\Program\.cs.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z19103
1038*\StandIn_Net35.exe*.{0,1000}\\StandIn_Net35\.exe.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z19104
1039*\StandIn_Net45.exe *.{0,1000}\\StandIn_Net45\.exe\s.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z19105
1040*\StandIn-1.3.zip*.{0,1000}\\StandIn\-1\.3\.zip.{0,1000}offensive_tool_keywordStandInStandIn is a small .NET35/45 AD post-exploitation toolkitT1087 - T1069 - T1558 - T1204 - T1136 - T1482TA0007 - TA0003 - TA0006 - TA0004N/AN/ADiscoveryhttps://github.com/FuzzySecurity/StandIn10N/AN/A987611292023-12-02T21:20:09Z2020-11-05T22:49:27Z19106
1041*\Start Menu\Programs\Advanced IP Scanner v2*.{0,1000}\\Start\sMenu\\Programs\\Advanced\sIP\sScanner\sv2.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox10N/AN/A710N/AN/AN/AN/A19111
1042*\teamsenum.py*.{0,1000}\\teamsenum\.py.{0,1000}offensive_tool_keywordTeamsEnumUser Enumeration of Microsoft Teams users via APIT1589.002 - T1590TA0007 - TA0001N/ABlack BastaDiscoveryhttps://github.com/sse-secure-systems/TeamsEnum10N/AN/A62153212024-03-27T18:14:25Z2023-04-03T18:35:15Z19258
1043*\Temp\2\Advanced Port Scanner 2\*.{0,1000}\\Temp\\2\\Advanced\sPort\sScanner\s2\\.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/10N/AN/A710N/AN/AN/AN/A19273
1044*\temp\OpenFileShares.txt*.{0,1000}\\temp\\OpenFileShares\.txt.{0,1000}offensive_tool_keywordSearchOpenFileSharesSearches open files shares for password files or database backups - Extend as you see fitT1083 - T1135 - T1005 - T1025TA0007 - TA0009N/ADispossessorDiscoveryhttps://github.com/fashionproof/SearchOpenFileShares10N/AN/A712962019-12-13T12:37:42Z2019-09-21T13:50:26Z19295
1045*\Temp\WizTree.exe*.{0,1000}\\Temp\\WizTree\.exe.{0,1000}greyware_tool_keywordwiztreelegitimate tool abused by threat actors to obtain network files and directory listingsT1083TA0007N/AFox Kitten - Faust - Bitlocker - Akira - Cactus - BlackSuit - RoyalDiscoveryN/A10N/AN/A36N/AN/AN/AN/A19309
1046*\TokenDump.cs*.{0,1000}\\TokenDump\.cs.{0,1000}offensive_tool_keywordPrivFuinspect token informationT1057TA0007N/AN/ADiscoveryhttps://github.com/daem0nc0re/PrivFu10N/ATokenDump1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19369
1047*\TokenDump.exe*.{0,1000}\\TokenDump\.exe.{0,1000}offensive_tool_keywordPrivFuinspect token informationT1057TA0007N/AN/ADiscoveryhttps://github.com/daem0nc0re/PrivFu10N/ATokenDump1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19370
1048*\TokenDump.sln*.{0,1000}\\TokenDump\.sln.{0,1000}offensive_tool_keywordPrivFuinspect token informationT1057TA0007N/AN/ADiscoveryhttps://github.com/daem0nc0re/PrivFu10N/ATokenDump1098491222025-01-21T05:22:50Z2021-12-28T13:14:25Z19372
1049*\windapsearch.py*.{0,1000}\\windapsearch\.py.{0,1000}offensive_tool_keywordsmbsrLookup for interesting stuff in SMB sharesT1135TA0001 - TA0007N/AN/ADiscoveryhttps://github.com/oldboy21/SMBSR10N/AN/A72149232023-06-16T14:35:30Z2021-11-10T16:55:52Z19717
1050*\Windows\system32\ROUTE.EXE" print*.{0,1000}\\Windows\\system32\\ROUTE\.EXE\"\sprint.{0,1000}greyware_tool_keywordroutedisplay the IP routing table on a systemT1016 - T1087 - T1049TA0007 - TA0043N/ADispossessorDiscoveryhttps://vx-underground.org/Archive/Dispossessor%20Leaks10N/AN/A1010N/AN/AN/AN/A19732
1051*\WindowsShareFinder.cs*.{0,1000}\\WindowsShareFinder\.cs.{0,1000}offensive_tool_keywordSMBeagleSMBeagle is an (SMB) fileshare auditing tool that hunts out all files it can see in the network and reports if the file can be read and/or written. All these findings are streamed out to either a CSV file or an elasticsearch host.T1087.002 - T1021.002 - T1210TA0007 - TA0008 - TA0003N/AN/ADiscoveryhttps://github.com/punk-security/SMBeagle10N/AN/A98712802025-01-21T22:34:00Z2021-05-31T19:46:57Z19776
1052*\WizTree.exe*.{0,1000}\\WizTree\.exe.{0,1000}greyware_tool_keywordwiztreelegitimate tool abused by threat actors to obtain network files and directory listingsT1083TA0007N/AFox Kitten - Faust - Bitlocker - Akira - Cactus - BlackSuit - RoyalDiscoveryN/A10N/AN/A36N/AN/AN/AN/A19826
1053*\wiztree_*_portable.zip* .{0,1000}\\wiztree_.{0,1000}_portable\.zip.{0,1000} greyware_tool_keywordwiztreelegitimate tool abused by threat actors to obtain network files and directory listingsT1083TA0007N/AFox Kitten - Faust - Bitlocker - Akira - Cactus - BlackSuit - RoyalDiscoveryN/A10N/AN/A36N/AN/AN/AN/A19827
1054*] Attempting to enumerate logged on users on *.{0,1000}\]\sAttempting\sto\senumerate\slogged\son\susers\son\s.{0,1000}offensive_tool_keywordGetLoggedOnUsersRegistryPoC To enumerate logged on users on a remote system using the winreg named pipeT1087 - T1018 - T1057TA0007 - TA0008N/AN/ADiscoveryhttps://gist.github.com/RalphDesmangles/22f580655f479f189c1de9e7720776f110N/AN/A88N/AN/AN/AN/A19982
1055*] Check for ADCS Vulnerabilities*.{0,1000}\]\sCheck\sfor\sADCS\sVulnerabilities.{0,1000}offensive_tool_keywordadauditPowershell script to do domain auditing automationT1087 - T1069 - T1046 - T1057 - T1114 - T1018TA0007 - TA0003 - TA0004 - TA0006N/AN/ADiscoveryhttps://github.com/phillips321/adaudit10N/AN/A543891062025-04-08T06:17:54Z2018-04-20T11:29:06Z19984
1056*] Collecting Krbtgt*.{0,1000}\]\sCollecting\sKrbtgt.{0,1000}offensive_tool_keywordInvoke-ADEnumAutomate Active Directory EnumerationT1016 - T1482TA0007N/AN/ADiscoveryhttps://github.com/Leo4j/Invoke-ADEnum10N/AN/A75448502025-04-09T10:13:47Z2023-04-18T11:19:42Z20007
1057*] Found kerberoastable users: *.{0,1000}\]\sFound\skerberoastable\susers\:\s.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z20028
1058*] INFO: DLL IS VULNERABLE TO DOWNLOADS INSTALLER TEST-*.{0,1000}\]\sINFO\:\sDLL\sIS\sVULNERABLE\sTO\sDOWNLOADS\sINSTALLER\sTEST\-.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z20039
1059*] INFO: DLL IS VULNERABLE TO EXECUTABLE TEST*.{0,1000}\]\sINFO\:\sDLL\sIS\sVULNERABLE\sTO\sEXECUTABLE\sTEST.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z20040
1060*] Kerberoast user * successfully!*.{0,1000}\]\sKerberoast\suser\s.{0,1000}\ssuccessfully!.{0,1000}offensive_tool_keywordSharpADWSSharpADWS Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS)T1087 - T1069 - T1018 - T1083 - T1595TA0001 - TA0002 - TA0007N/AN/ADiscoveryhttps://github.com/wh0amitz/SharpADWS10N/AN/A76538592024-03-19T08:57:52Z2024-02-13T17:28:00Z20045
1061*] Listing all vulnerabilities scanned by Moriarty*.{0,1000}\]\sListing\sall\svulnerabilities\sscanned\sby\sMoriarty.{0,1000}offensive_tool_keywordMoriartyMoriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments.T1068 - T1083TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/BC-SECURITY/Moriarty10N/AN/A76510672024-08-07T15:06:31Z2023-12-11T14:15:33Z20048
1062*] Starting nullinux setup script*.{0,1000}\]\sStarting\snullinux\ssetup\sscript.{0,1000}offensive_tool_keywordnullinuxInternal penetration testing tool for Linux that can be used to enumerate OS information/domain information/ shares/ directories and users through SMB.T1087 - T1016 - T1077 - T1018TA0007 - TA0006N/AN/ADiscoveryhttps://github.com/m8sec/nullinux10#linux #contentN/A765751012024-06-19T14:29:09Z2016-04-28T16:45:02Z20077
1063*] Starting share enumeration with thread limit of *.{0,1000}\]\sStarting\sshare\senumeration\swith\sthread\slimit\sof\s.{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/Hackcraft-Labs/SharpShares10N/AN/A1013372023-11-13T14:08:07Z2023-10-25T10:34:18Z20079
1064*] TARGET DLL IS NOT VULNERABLE TO *.{0,1000}\]\sTARGET\sDLL\sIS\sNOT\sVULNERABLE\sTO\s.{0,1000}offensive_tool_keywordrattlerAutomated DLL EnumeratorT1174 - T1574.007TA0005N/AN/ADiscoveryhttps://github.com/sensepost/rattler10N/AN/A965311352017-12-21T18:01:09Z2016-11-28T12:35:44Z20084
1065*_adAclOutput*.csv*.{0,1000}_adAclOutput.{0,1000}\.csv.{0,1000}offensive_tool_keywordADACLScannerA tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .T1222 - T1069 - T1018TA0002 - TA0007 - TA0043N/AN/ADiscoveryhttps://github.com/canix1/ADACLScanner10N/AAD Enumeration71010151732025-04-11T14:35:08Z2017-04-06T12:28:37Z20103
1066*_adAclOutput*.csv*.{0,1000}_adAclOutput.{0,1000}\.csv.{0,1000}offensive_tool_keywordADACLScannerA tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .T1222 - T1069 - T1018TA0002 - TA0007 - TA0043N/AN/ADiscoveryhttps://github.com/canix1/ADACLScanner10N/AAD Enumeration71010151732025-04-11T14:35:08Z2017-04-06T12:28:37Z20104
1067*_adAclOutput*.csv*.{0,1000}_adAclOutput.{0,1000}\.csv.{0,1000}offensive_tool_keywordADACLScannerA tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .T1222 - T1069 - T1018TA0002 - TA0007 - TA0043N/AN/ADiscoveryhttps://github.com/canix1/ADACLScanner10N/AAD Enumeration71010151732025-04-11T14:35:08Z2017-04-06T12:28:37Z20105
1068*_adAclOutput*.csv*.{0,1000}_adAclOutput.{0,1000}\.csv.{0,1000}offensive_tool_keywordADACLScannerA tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .T1222 - T1069 - T1018TA0002 - TA0007 - TA0043N/AN/ADiscoveryhttps://github.com/canix1/ADACLScanner10N/AAD Enumeration71010151732025-04-11T14:35:08Z2017-04-06T12:28:37Z20106
1069*_adAclOutput*.csv*.{0,1000}_adAclOutput.{0,1000}\.csv.{0,1000}offensive_tool_keywordADACLScannerA tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .T1222 - T1069 - T1018TA0002 - TA0007 - TA0043N/AN/ADiscoveryhttps://github.com/canix1/ADACLScanner10N/AAD Enumeration71010151732025-04-11T14:35:08Z2017-04-06T12:28:37Z20107
1070*_adAclOutput*.xlsx*.{0,1000}_adAclOutput.{0,1000}\.xlsx.{0,1000}offensive_tool_keywordADACLScannerA tool with GUI used to create reports of access control lists (DACLs) and system access control lists (SACLs) in Active Directory .T1222 - T1069 - T1018TA0002 - TA0007 - TA0043N/AN/ADiscoveryhttps://github.com/canix1/ADACLScanner10N/AAD Enumeration71010151732025-04-11T14:35:08Z2017-04-06T12:28:37Z20108
1071*_BloodHound.zip*.{0,1000}_BloodHound\.zip.{0,1000}offensive_tool_keywordBloodHoundBloodHound is a single page Javascript web application. built on top of Linkurious. compiled with Electron. with a Neo4j database fed by a C# data collector. BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. Attackers can use BloodHound to easily identify highly complex attack paths that would otherwise be impossible to quickly identify. Defenders can use BloodHound to identify and eliminate those same attack paths. Both blue and red teams can use BloodHound to easily gain a deeper understanding of privilege relationships in an Active Directory environmentT1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound11N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z20111
1072*_REFLECTIVEDLLINJECTION_REFLECTIVEDLLINJECTION_H*.{0,1000}_REFLECTIVEDLLINJECTION_REFLECTIVEDLLINJECTION_H.{0,1000}offensive_tool_keywordRecon-ADAD recon tool based on ADSI and reflective DLLT1087 - T1069 - T1082 - T1016 - T1033 - T1046 - T1135TA0007 - TA0003 - TA0004N/AN/ADiscoveryhttps://github.com/outflanknl/Recon-AD11N/AN/A84326552019-10-20T21:49:39Z2019-10-20T21:09:41Z20167
1073*_SharpHound-v*.zip*.{0,1000}_SharpHound\-v.{0,1000}\.zip.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10N/AN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z20170
1074*<Data Name="Product">Moriarty<*.{0,1000}\<Data\sName\=\"Product\"\>Moriarty\<.{0,1000}offensive_tool_keywordMoriartyMoriarty is designed to enumerate missing KBs - detect various vulnerabilities and suggest potential exploits for Privilege Escalation in Windows environments.T1068 - T1083TA0004 - TA0007N/AN/ADiscoveryhttps://github.com/BC-SECURITY/Moriarty10N/AN/A76510672024-08-07T15:06:31Z2023-12-11T14:15:33Z20207
1075*<Data Name="RelativeTargetName">delete.me<*.{0,1000}\<Data\sName\=\"RelativeTargetName\"\>delete\.me\<.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com.cach3.com/board/read.php%3F12,10134,12202.html10N/Arisk of false positive810N/AN/AN/AN/A20208
1076*<Data Name='OriginalFileName'>AdExp<*.{0,1000}\<Data\sName\=\'OriginalFileName\'\>AdExp\<.{0,1000}greyware_tool_keywordadexplorerActive Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actorsT1003.001 - T1087.001TA0006 - TA0007N/ALapsus$ - Scattered Spider* - BlackBastaDiscoveryhttps://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer10N/Agreyware tool - risks of False positive !710N/AN/AN/AN/A20209
1077*>Active Directory Editor<*.{0,1000}\>Active\sDirectory\sEditor\<.{0,1000}greyware_tool_keywordadexplorerActive Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actorsT1003.001 - T1087.001TA0006 - TA0007N/ALapsus$ - Scattered Spider* - BlackBastaDiscoveryhttps://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer10#productnamegreyware tool - risks of False positive !710N/AN/AN/AN/A20313
1078*>AdFind<*.{0,1000}\>AdFind\<.{0,1000}greyware_tool_keywordadfindadfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environmentT1087 - T1016 - T1482TA0007 - TA0008 - TA0043N/AAPT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - DispossessorDiscoveryhttps://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior10#productnameN/A1010N/AN/AN/AN/A20318
1079*>Advanced IP Scanner Setup<*.{0,1000}\>Advanced\sIP\sScanner\sSetup\<.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox10#descriptionN/A710N/AN/AN/AN/A20325
1080*>Advanced IP Scanner<*.{0,1000}\>Advanced\sIP\sScanner\<.{0,1000}greyware_tool_keywordadvanced-ip-scannerThe program shows all network devices. gives you access to shared folders. provides remote control of computers (via RDP and Radmin) and can even remotely switch computers off. It is easy to use and runs as a portable edition (abused by TA)T1135 - T1021 - T1016 - T1046TA0007 - TA0043N/AMAZE - BlackSuit - Royal - Akira - LockBit - Diavol - GoGoogle - INC Ransom - Hive - ZolaConti2 - Darkside - UNC24653 - Egregor4 - Hades - Evilcorp5 - REvil6 - Ryuk - UNC18787 - UNC24477 - Vice Society - FiveHands - Sarcoma - DragonForce - MedusaLocker - Mimic - LokiDiscoveryhttps://www.huntandhackett.com/blog/advanced-ip-scanner-the-preferred-scanner-in-the-apt-toolbox10#productnameN/A710N/AN/AN/AN/A20326
1081*>Advanced Port Scanner Setup<*.{0,1000}\>Advanced\sPort\sScanner\sSetup\<.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/10#descriptionN/A710N/AN/AN/AN/A20327
1082*>Advanced Port Scanner<*.{0,1000}\>Advanced\sPort\sScanner\<.{0,1000}greyware_tool_keywordadvanced port scannerport scanner tool abused by ransomware actorsT1135 - T1021 - T1016 - T1046TA0007 - TA0043N/ADispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa LockerDiscoveryhttps://www.advanced-port-scanner.com/10#productnameN/A710N/AN/AN/AN/A20328
1083*>BrowsingHistoryView<*.{0,1000}\>BrowsingHistoryView\<.{0,1000}offensive_tool_keywordBrowsingHistoryViewBrowsingHistoryView is a utility that reads the history data of different Web browsersT1217 - T1070 - T1113TA0009 - TA0005 - TA0007N/AGOBLIN PANDADiscoveryhttps://www.nirsoft.net/utils/browsing_history_view.html10N/AN/A1010N/AN/AN/AN/A20353
1084*>Dionach.ShareAudit<*.{0,1000}\>Dionach\.ShareAudit\<.{0,1000}offensive_tool_keywordShareAuditA tool for auditing network shares in an Active Directory environmentT1135 - T1005 - T1083 - T1210TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/dionach/ShareAudit10#productnameN/A8142152019-04-29T10:07:57Z2019-02-26T16:00:15Z20376
1085*>Group3r<*.{0,1000}\>Group3r\<.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10#companynameAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z20407
1086*>Lansweeper Setup<*.{0,1000}\>Lansweeper\sSetup\<.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/10#descriptionN/A67N/AN/AN/AN/A20430
1087*>Lansweeper<*.{0,1000}\>Lansweeper\<.{0,1000}greyware_tool_keywordLansweeperLansweeper discovers and inventories IT assets - gathering system - software and user data - abused by attackersT1016 - T1082TA0007N/AEvilCorp*Discoveryhttps://www.lansweeper.com/10#productnameN/A67N/AN/AN/AN/A20431
1088*>MDE_Enum<*.{0,1000}\>MDE_Enum\<.{0,1000}offensive_tool_keywordMDE_Enumextract and display detailed information about Windows Defender exclusions and Attack Surface Reduction (ASR) rulesT1070.006TA0005 - TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/0xsp-SRD/MDE_Enum10N/AN/A82198182024-06-10T18:40:27Z2024-06-06T15:54:44Z20438
1089*>NimScan<*.{0,1000}\>NimScan\<.{0,1000}greyware_tool_keywordNimScanReally fast port scanner (With filtered option - Windows support only)T1046TA0007N/AN/ADiscoveryhttps://github.com/elddy/NimScan10N/AN/A84391382022-02-10T13:23:02Z2020-08-12T14:20:46Z20461
1090*>ShareAudit.exe<*.{0,1000}\>ShareAudit\.exe\<.{0,1000}offensive_tool_keywordShareAuditA tool for auditing network shares in an Active Directory environmentT1135 - T1005 - T1083 - T1210TA0007 - TA0009N/AN/ADiscoveryhttps://github.com/dionach/ShareAudit10#originalfilenameN/A8142152019-04-29T10:07:57Z2019-02-26T16:00:15Z20532
1091*>SharpAVKB<*.{0,1000}\>SharpAVKB\<.{0,1000}offensive_tool_keywordSharpAVKBWindows Antivirus Comparison and Patch Number ComparisonT1082 - T1518 - T1083TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpAVKB10#productnameN/A4158242019-10-28T06:50:30Z2019-10-14T12:44:22Z20534
1092*>SharpEventLog<*.{0,1000}\>SharpEventLog\<.{0,1000}offensive_tool_keywordSharpEventLogreads all computer information related to successful (4624) or failed (4625) logins on the local machine to quickly identify operations and maintenance personnel during internal network penetrationT1078 - T1087.001TA0007N/AN/ADiscoveryhttps://github.com/uknowsec/SharpEventLog10#contentN/A43205342019-10-15T06:26:52Z2019-10-15T06:14:32Z20545
1093*>SharpGraphView<*.{0,1000}\>SharpGraphView\<.{0,1000}offensive_tool_keywordSharpGraphViewMicrosoft Graph API post-exploitation toolkitT1078.004 - T1114.002TA0001 - TA0003 - TA0006 - TA0008 - TA0007 - TA0010N/AN/ADiscoveryhttps://github.com/mlcsec/SharpGraphView10#productnameN/A619492024-07-13T12:27:38Z2024-05-04T11:23:42Z20550
1094*>SharpHound<*.{0,1000}\>SharpHound\<.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10#productnameN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z20552
1095*>SharpNBTScan<*.{0,1000}\>SharpNBTScan\<.{0,1000}offensive_tool_keywordSharpNBTScana NetBIOS scanner. Ghost actors use this tool for hostname and IP address enumerationT1018 - T1046TA0007Ghost RansomwareN/ADiscoveryhttps://github.com/BronzeTicket/SharpNBTScan10#productnameN/A717142021-08-06T05:36:55Z2021-07-12T08:57:39Z20564
1096*>SharpShares<*.{0,1000}\>SharpShares\<.{0,1000}offensive_tool_keywordSharpSharesMultithreaded C# .NET Assembly to enumerate accessible network shares in a domainT1046 - T1135TA0007 - TA0001N/ABlackSuit - Royal - BianLian - FogDiscoveryhttps://github.com/mitchmoser/SharpShares10#productnameN/A104351492021-09-21T08:14:27Z2020-09-25T22:35:57Z20571
1097*>SharpView<*.{0,1000}\>SharpView\<.{0,1000}offensive_tool_keywordSharpViewC# implementation of harmj0y's PowerViewT1018 - T1482 - T1087.002 - T1069.002TA0007 - TA0003 - TA0001N/AConti - APT29Discoveryhttps://github.com/tevora-threat/SharpView/10#productnameN/A101010321962024-03-22T16:34:09Z2018-07-24T21:15:04Z20581
1098*>SoftPerfect Network Scanner<*.{0,1000}\>SoftPerfect\sNetwork\sScanner\<.{0,1000}greyware_tool_keywordsoftperfect networkscannerSoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShellT1046 - T1065 - T1135 TA0007 N/ADispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - AnunakDiscoveryhttps://www.softperfect.com/products/networkscanner/10#productnameN/A810N/AN/AN/AN/A20592
1099*>Sysinternals ADExplorer<*.{0,1000}\>Sysinternals\sADExplorer\<.{0,1000}greyware_tool_keywordadexplorerActive Directory Explorer (AD Explorer) is an advanced Active Directory (AD) viewer and editor. You can use AD Explorer to easily navigate an AD database. It can be abused by malicious actorsT1003.001 - T1087.001TA0006 - TA0007N/ALapsus$ - Scattered Spider* - BlackBastaDiscoveryhttps://learn.microsoft.com/en-us/sysinternals/downloads/adexplorer10#productnamegreyware tool - risks of False positive !710N/AN/AN/AN/A20594
1100*>Sysinternals PsList<*.{0,1000}\>Sysinternals\sPsList\<.{0,1000}greyware_tool_keywordpslistMicrosoft sysinternal comandline tool to list running process abused by threat actorsT1057 - T1012 - T1106TA0007N/AAPT10 - APT15 - APT33 - APT34 - Sandworm - APT35 - CHRYSENE - menuPass - GhostEmperor - Magnallium - ElfinDiscoveryhttps://learn.microsoft.com/pt-br/sysinternals/downloads/pslist10#productnameN/A39N/AN/AN/AN/A20595
1101*>Welcome to BloodHound?s documentation!<*.{0,1000}\>Welcome\sto\sBloodHound?s\sdocumentation!\<.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10N/AN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z20617
1102*006ad795269259c08e5b8e1816e05a4bbb52c97997ff238180afbc53365d3428*.{0,1000}006ad795269259c08e5b8e1816e05a4bbb52c97997ff238180afbc53365d3428.{0,1000}offensive_tool_keywordGroup3rFind vulnerabilities in AD Group PolicyT1484.002 - T1069.002 - T1087.002TA0007 - TA0040N/AKNOTWEEDDiscoveryhttps://github.com/Group3r/Group3r10#filehashAD Enumeration78781682025-04-08T05:03:34Z2021-07-05T05:05:42Z20662
1103*006d97f8510e34966ebd1901686cf407a57663ad42374e40c023c6611595d1e3*.{0,1000}006d97f8510e34966ebd1901686cf407a57663ad42374e40c023c6611595d1e3.{0,1000}greyware_tool_keywordAD_MinerAD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknessesT1482 - T1069 - T1087TA0007 N/AEMBER BEARDiscoveryhttps://github.com/Mazars-Tech/AD_Miner10#filehashN/A61012901312025-03-12T10:53:09Z2023-09-26T12:36:59Z20664
1104*00d223d61d1569d44bfe81805359f94c15c9549473762016605287c31733bae6*.{0,1000}00d223d61d1569d44bfe81805359f94c15c9549473762016605287c31733bae6.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10#filehashN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z20694
1105*00e3b8a6e650a206a6070be87c2c1d5387c21f9f6b80d18ee683c2c0f5fd2fe5*.{0,1000}00e3b8a6e650a206a6070be87c2c1d5387c21f9f6b80d18ee683c2c0f5fd2fe5.{0,1000}greyware_tool_keywordipscanAngry IP Scanner - fast and friendly network scanner - abused by a lot ransomware actorsT1046 - T1040 - T1018TA0007 - TA0009N/APhobos - BERSERK BEARDiscoveryhttps://github.com/angryip/ipscan10#filehashN/A71044017442024-11-23T19:03:47Z2011-06-28T20:58:48Z20698
1106*014b459f4eff259806b56b536fd24475d1824a82213f2b4e174f7650c1cd81db*.{0,1000}014b459f4eff259806b56b536fd24475d1824a82213f2b4e174f7650c1cd81db.{0,1000}offensive_tool_keywordsharphoundC# Data Collector for BloodHoundT1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046TA0007 - TA0043 - TA0005 - TA0042Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExxAPT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - DispossessorDiscoveryhttps://github.com/BloodHoundAD/SharpHound10#filehashN/AN/A109041952025-04-18T20:45:04Z2021-07-12T17:07:04Z20717
1107*018bdc303d4d1d7ef36e50f7967e3adfc9e613dd51cda3865af30893bfcf5ea5*.{0,1000}018bdc303d4d1d7ef36e50f7967e3adfc9e613dd51cda3865af30893bfcf5ea5.{0,1000}offensive_tool_keywordBloodHoundUse Invoke-BloodHound from SharpHound.ps1 or use SharpHound.exe. Both can be run reflectively. Examples below use the PowerShell variant but arguments are identical.T1482 - T1087 - T1069 - T1018TA0007 - TA0008 - TA0004N/AAPT29 - MAZE - LockBit - Conti - XingLocker - Revil - Hive - Black Basta - Wizard Spider - TA2101 - TRAVELING SPIDER - Chimera - TA505 - APT20 - COZY BEAR - EMBER BEAR - DispossessorDiscoveryhttps://github.com/BloodHoundAD/BloodHound/tree/master/Collectors10#filehashN/A10101014617592025-04-02T15:56:30Z2016-04-17T18:36:14Z20741
The file is too large to be shown. View Raw