18 Repos
Tools for auditing, exploiting, and managing Windows environments.
Explore 18 awesome GitHub repositories matching part of an awesome list · Windows Security Utilities. Refine with filters or upvote what's useful.
PowerSploit is a collection of PowerShell modules designed for security assessment, penetration testing, and red team operations. It provides a framework for auditing Windows system configurations and evaluating the effectiveness of security defenses within an enterprise environment. The framework focuses on techniques that leverage native system administration tools and scripting environments to perform operations. It includes capabilities for executing arbitrary commands, escalating user privileges, and maintaining system persistence through event subscriptions. By utilizing in-memory execu
Framework for post-exploitation tasks using PowerShell.
LaZagne is a cross-platform credential recovery tool designed to extract passwords and secrets from operating systems, browsers, and applications. It functions as a security utility for retrieving stored credentials from compromised systems during penetration testing. The tool provides capabilities for decrypting domain credentials and extracting sensitive data from system storage, including memory dumps, credential managers, keychains, and password hashes. It recovers stored passwords from common software by accessing plaintext files, APIs, and local databases. The project supports digital
Recovers stored credentials from various applications.
Bloodhound is an Active Directory attack path mapper and security auditor designed to visualize trust relationships and permission chains. It serves as an attack surface management tool that identifies paths to domain administrator and other high-privileged accounts. The project uses a graph database analyzer to map complex identity and access relationships. It quantifies the risk of privilege escalation by identifying misconfigured permissions and trust links within Windows domains. The system provides capabilities for Active Directory security analysis, identity and access auditing, and ne
Visualizes Active Directory trust relationships and attack paths.
Commando-VM is a Windows penetration testing distribution and offensive security toolkit. It provides a specialized virtual machine environment loaded with a curated suite of security auditing and exploitation tools designed for red teaming operations. The project facilitates the creation of red team infrastructure and security audit environments. It focuses on windows security auditing and penetration testing to help simulate adversary behavior and identify exploitable security flaws. The environment is established through script-based provisioning and modular toolset deployment. This proce
Automated deployment of penetration testing tools on Windows.
This project is a Windows security removal tool designed to permanently disable and delete antivirus services and security monitoring components from the operating system. It functions as a system performance optimizer and policy manager to remove security mitigations and clear policy files that restrict application execution. The tool includes a Windows ISO customizer that embeds configuration files and unattended installation scripts into bootable images. This allows security features to be bypassed and services to be disabled before the initial system boot. The software covers broad capab
A specialized utility for permanently disabling and deleting antivirus and security components on Windows.
Responder is a man-in-the-middle framework and network protocol spoofing tool designed to intercept network name queries and impersonate requested resources. It functions as a poisoner for LLMNR, NBT-NS, and MDNS, redirecting network traffic from clients to a controlled listener. The project serves as a credential capture tool that runs rogue servers for SMB, HTTP, and LDAP to collect NTLM hashes and clear text credentials. It enables the harvesting of encrypted authentication tokens and the interception of usernames and passwords sent without encryption. Its broader capabilities include int
Poisoning tool for network name resolution protocols.
Rubeus is a comprehensive Kerberos attack toolkit for Active Directory environments, written in C#. It provides a full suite of operations for manipulating Kerberos tickets, exploiting delegation configurations, and performing credential attacks against Windows domains. The toolkit enables ticket extraction from logon sessions and memory, with real-time monitoring via Event Tracing for Windows. It supports forging golden and silver tickets with arbitrary privileges, as well as the creation of forged delegation contexts. Delegation attacks include abuse of constrained and unconstrained delegat
Tool for interacting with and abusing Kerberos tickets.
Windows-Exploit-Suggester ist ein Security-Audit-Tool zum Scannen von Windows-Systemen auf veraltete Komponenten und fehlende Sicherheits-Patches. Es fungiert als Vulnerability-Scanner, der den Patch-Stand des Ziels mit offiziellen Sicherheitsbulletins der Hersteller vergleicht, um Sicherheitslücken zu identifizieren. Das Tool ist auf Exploit-Mapping spezialisiert und verknüpft identifizierte fehlende Updates mit bekanntem öffentlichem Exploit-Code und verfügbaren Penetration-Testing-Modulen. Es automatisiert den Rechercheprozess durch den Abgleich fehlender Patches mit spezifischen Schwachstellen-IDs, um anwendbare Angriffsvektoren zu bestimmen. Das System umfasst Funktionen für den Remote-Patch-Stand-Vergleich und heuristische Erkennung, um den Status eines Hosts abzuleiten. Es hält die Genauigkeit durch einen Synchronisationsmechanismus aufrecht, der die neuesten Sicherheitsdaten von Herstellerquellen herunterlädt und parst, um die interne Schwachstellendatenbank zu aktualisieren.
Identifies missing patches and potential vulnerabilities on Windows systems.
WinPwn is a Windows penetration testing framework designed for conducting internal security assessments and privilege escalation. It functions as a suite for Active Directory security auditing, credential extraction, and the execution of privilege escalation scripts. The toolset enables the automation of SMB relay attacks to intercept and reuse authentication hashes. It provides specialized capabilities for retrieving passwords and hashes from system memory, registries, and browsers using obfuscated techniques to avoid detection. The framework covers broad capability areas including domain a
Automates reconnaissance and privilege escalation on Windows domains.
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
Searches and extracts data from Microsoft Exchange environments.
.NET IPv4/IPv6 machine-in-the-middle tool for penetration testers
Performs spoofing and man-in-the-middle attacks on Windows networks.
Adversary tradecraft detection, protection, and hunting
Traces and explores Windows kernel activities.
A tool to abuse Exchange services
Gains remote shell access via Outlook and Exchange features.
Interactive CTF Exploration Tool
Exploration tool for collaborative translation framework attacks.
Uses Empire's (https://github.com/BC-SECURITY/Empire) RESTful API to automate gaining Domain and/or Enterprise Admin rights in Active Directory environments using some of the most common offensive TTPs.
Automates privilege escalation to Domain Admin in Active Directory.
RedSnarf is a pen-testing / red-teaming tool for Windows environments
Retrieves credentials and hashes from Windows infrastructure.
Rid_enum is a null session RID cycle attack for brute forcing domain controllers.
Enumerates domain users and performs password brute-forcing.
SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers
Decrypts credentials stored in System Center Operations Manager databases.