倉庫

dafthack 的倉庫

最近提交 2020年8月19日

 (2 stars) (1 fork) (0 個已索引 issue) (0 個開放 good first issue)

A basic PHP redirection site that captures request headers

最近提交 2021年9月13日

 (10 stars) (4 forks) (0 個已索引 issue) (0 個開放 good first issue)

Custom Query list for the Bloodhound GUI based off my cheatsheet

最近提交 2021年5月24日

 (7 stars) (2 forks) (0 個已索引 issue) (0 個開放 good first issue)

Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine if the provided credential is a local administrator. It's useful if you obtain a password hash for a user and want to see where they are local admin on a network. It is essentially a Frankenstein of two of my favorite tools along with some of my own code. It utilizes Kevin Robertson's (@kevin_robertson) Invoke-TheHash project for the credential checking portion. Additionally, the script utilizes modules from PowerView by Will Schroeder (@harmj0y) and Matt Graeber (@mattifestation) to enumerate domain computers to find targets for testing admin access against.

最近提交 2019年6月5日

 (179 stars) (34 forks) (0 個已索引 issue) (0 個開放 good first issue)

This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.

最近提交 2026年4月6日

 (2,820 stars) (553 forks) (0 個已索引 issue) (0 個開放 good first issue)

Covenant is a collaborative .NET C2 framework for red teamers.

最近提交 2020年6月9日

 (6 stars) (2 forks) (0 個已索引 issue) (0 個開放 good first issue)

DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!

最近提交 2024年7月11日

 (2,053 stars) (413 forks) (0 個已索引 issue) (0 個開放 good first issue)

This module mangles two lists of names together to generate a list of potential email addresses or usernames. It can also be used to simply combine a list of full names in the format (firstname lastname) into either email addresses or usernames.

最近提交 2017年9月25日

 (51 stars) (17 forks) (0 個已索引 issue) (0 個開放 good first issue)
dafthack/EmpirePowerShell

Empire is a PowerShell and Python post-exploitation agent.

最近提交 2018年11月29日

 (8 stars) (1 fork) (0 個已索引 issue) (0 個開放 good first issue)

A script for tracking and decoding input data messages sent to and from a particular Ethereum address or from every transaction in a block.

最近提交 2021年9月14日

 (9 stars) (3 forks) (0 個已索引 issue) (0 個開放 good first issue)

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

最近提交 2020年6月16日

 (4 stars) (2 forks) (0 個已索引 issue) (0 個開放 good first issue)

A Post-exploitation Toolset for Interacting with the Microsoft Graph API

最近提交 2026年4月9日

 (1,296 stars) (164 forks) (0 個已索引 issue) (0 個開放 good first issue)

This function runs a number of checks on a system to help provide situational awareness to a penetration tester during the reconnaissance phase. It gathers information about the local system, users, and domain information. It does not use any 'net', 'ipconfig', 'whoami', 'netstat', or other system commands to help avoid detection.

最近提交 2017年10月3日

 (465 stars) (120 forks) (0 個已索引 issue) (0 個開放 good first issue)

A tool for checking if MFA is enabled on multiple Microsoft Services

最近提交 2025年3月4日

 (1,555 stars) (217 forks) (0 個已索引 issue) (0 個開放 good first issue)

A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, if the account is locked, or if the account is disabled.

最近提交 2022年11月30日

 (1,087 stars) (185 forks) (0 個已索引 issue) (0 個開放 good first issue)

MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.

最近提交 2025年8月7日

 (3,240 stars) (595 forks) (0 個已索引 issue) (0 個開放 good first issue)

Random Tools

最近提交 2018年9月13日

 (19 stars) (4 forks) (0 個已索引 issue) (0 個開放 good first issue)

Using TLS 1.3 to evade censors, bypass network defenses, and blend in with the noise

最近提交 2020年8月6日

 (3 stars) (2 forks) (0 個已索引 issue) (0 個開放 good first issue)

A script for generating custom passphrase lists to be used for password cracking with hashcat rules

最近提交 2018年6月27日

 (82 stars) (22 forks) (0 個已索引 issue) (0 個開放 good first issue)

Personal AI Infrastructure for upgrading humans.

最近提交 2025年11月8日

 (1 star) (1 fork) (0 個已索引 issue) (0 個開放 good first issue)