Dépôts

Dépôts de dafthack

Dernier commit 19 août 2020

 (2 stars) (1 fork) (0 issues indexées) (0 good first issues ouvertes)

A basic PHP redirection site that captures request headers

Dernier commit 13 sept. 2021

 (10 stars) (4 forks) (0 issues indexées) (0 good first issues ouvertes)

Custom Query list for the Bloodhound GUI based off my cheatsheet

Dernier commit 24 mai 2021

 (7 stars) (2 forks) (0 issues indexées) (0 good first issues ouvertes)

Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine if the provided credential is a local administrator. It's useful if you obtain a password hash for a user and want to see where they are local admin on a network. It is essentially a Frankenstein of two of my favorite tools along with some of my own code. It utilizes Kevin Robertson's (@kevin_robertson) Invoke-TheHash project for the credential checking portion. Additionally, the script utilizes modules from PowerView by Will Schroeder (@harmj0y) and Matt Graeber (@mattifestation) to enumerate domain computers to find targets for testing admin access against.

Dernier commit 5 juin 2019

 (179 stars) (34 forks) (0 issues indexées) (0 good first issues ouvertes)

This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.

Dernier commit 6 avr. 2026

 (2 820 stars) (553 forks) (0 issues indexées) (0 good first issues ouvertes)

Covenant is a collaborative .NET C2 framework for red teamers.

Dernier commit 9 juin 2020

 (6 stars) (2 forks) (0 issues indexées) (0 good first issues ouvertes)

DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!

Dernier commit 11 juil. 2024

 (2 053 stars) (413 forks) (0 issues indexées) (0 good first issues ouvertes)

This module mangles two lists of names together to generate a list of potential email addresses or usernames. It can also be used to simply combine a list of full names in the format (firstname lastname) into either email addresses or usernames.

Dernier commit 25 sept. 2017

 (51 stars) (17 forks) (0 issues indexées) (0 good first issues ouvertes)
dafthack/EmpirePowerShell

Empire is a PowerShell and Python post-exploitation agent.

Dernier commit 29 nov. 2018

 (8 stars) (1 fork) (0 issues indexées) (0 good first issues ouvertes)

A script for tracking and decoding input data messages sent to and from a particular Ethereum address or from every transaction in a block.

Dernier commit 14 sept. 2021

 (9 stars) (3 forks) (0 issues indexées) (0 good first issues ouvertes)

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

Dernier commit 16 juin 2020

 (4 stars) (2 forks) (0 issues indexées) (0 good first issues ouvertes)

A Post-exploitation Toolset for Interacting with the Microsoft Graph API

Dernier commit 9 avr. 2026

 (1 296 stars) (164 forks) (0 issues indexées) (0 good first issues ouvertes)

This function runs a number of checks on a system to help provide situational awareness to a penetration tester during the reconnaissance phase. It gathers information about the local system, users, and domain information. It does not use any 'net', 'ipconfig', 'whoami', 'netstat', or other system commands to help avoid detection.

Dernier commit 3 oct. 2017

 (465 stars) (120 forks) (0 issues indexées) (0 good first issues ouvertes)

A tool for checking if MFA is enabled on multiple Microsoft Services

Dernier commit 4 mars 2025

 (1 555 stars) (217 forks) (0 issues indexées) (0 good first issues ouvertes)

A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, if the account is locked, or if the account is disabled.

Dernier commit 30 nov. 2022

 (1 087 stars) (185 forks) (0 issues indexées) (0 good first issues ouvertes)

MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.

Dernier commit 7 août 2025

 (3 240 stars) (595 forks) (0 issues indexées) (0 good first issues ouvertes)

Random Tools

Dernier commit 13 sept. 2018

 (19 stars) (4 forks) (0 issues indexées) (0 good first issues ouvertes)

Using TLS 1.3 to evade censors, bypass network defenses, and blend in with the noise

Dernier commit 6 août 2020

 (3 stars) (2 forks) (0 issues indexées) (0 good first issues ouvertes)

A script for generating custom passphrase lists to be used for password cracking with hashcat rules

Dernier commit 27 juin 2018

 (82 stars) (22 forks) (0 issues indexées) (0 good first issues ouvertes)

Personal AI Infrastructure for upgrading humans.

Dernier commit 8 nov. 2025

 (1 star) (1 fork) (0 issues indexées) (0 good first issues ouvertes)