awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to fox-it/aclpwn.py

Projects sharing features with Aclpwn.py

30 open-source projects similar to fox-it/aclpwn.py, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • ghostpack/certifyGhostPack avatar

    GhostPack/Certify

    1,994View on GitHub↗

    Certify is a C# tool to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS).

    C#
    View on GitHub↗1,994
  • dirkjanm/ldapdomaindumpdirkjanm avatar

    dirkjanm/ldapdomaindump

    1,379View on GitHub↗
    Python
    View on GitHub↗1,379
  • fox-it/invoke-aclpwnF

    fox-it/Invoke-ACLPwn

    0View on GitHub↗
    View on GitHub↗0
  • bloodhoundad/bloodhoundBloodHoundAD avatar

    BloodHoundAD/BloodHound

    10,552View on GitHub↗

    BloodHound is a graph-based security analysis tool designed to map trust relationships and attack vectors within Active Directory environments. It functions as an attack path mapper and risk assessment system that uses graph theory to identify hidden relationships and paths leading to high-privilege accounts. The tool specializes in network attack surface mapping and privilege escalation pathfinding. It quantifies security risks by measuring the reliability of attack paths to critical targets, allowing for the prioritization of vulnerability elimination. The system provides capabilities for

    PowerShell
    View on GitHub↗10,552
  • byt3bl33d3r/crackmapexecbyt3bl33d3r avatar

    byt3bl33d3r/CrackMapExec

    9,144View on GitHub↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    Python
    View on GitHub↗9,144

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • ghostpack/pspkiauditGhostPack avatar

    GhostPack/PSPKIAudit

    936View on GitHub↗

    PowerShell toolkit for auditing Active Directory Certificate Services (AD CS).

    PowerShell
    View on GitHub↗936
  • notmedic/netntlmtosilverticketNotMedic avatar

    NotMedic/NetNTLMtoSilverTicket

    963View on GitHub↗

    SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket

    PowerShell
    View on GitHub↗963
  • canix1/adaclscannercanix1 avatar

    canix1/ADACLScanner

    1,172View on GitHub↗

    Repo for ADACLScan.ps1 - Your number one script for ACL's in Active Directory

    PowerShell
    View on GitHub↗1,172
  • mantvydasb/redteaming-tactics-and-techniquesmantvydasb avatar

    mantvydasb/RedTeaming-Tactics-and-Techniques

    4,620View on GitHub↗

    This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior. It serves as a comprehensive collection of technical guides and tactics for executing red team operations. The repository provides detailed instructions for Active Directory exploitation, including Kerberos abuse and domain privilege escalation. It covers defense evasion through API unhooking and payload obfuscation, as well as Windows internals research involving the manipulation of kernel objects and system memory. The capability surface extends to network penetration testi

    PowerShelloffensive-securityoscppentesting
    View on GitHub↗4,620
  • cube0x0/nopaccube0x0 avatar

    cube0x0/noPac

    1,403View on GitHub↗

    CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.

    C#
    View on GitHub↗1,403
  • cube0x0/cve-2021-1675cube0x0 avatar

    cube0x0/CVE-2021-1675

    1,989View on GitHub↗

    C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527

    C#
    View on GitHub↗1,989
  • creddefense/creddefenseC

    CredDefense/CredDefense

    0View on GitHub↗
    View on GitHub↗0
  • bloodhoundad/sharphound3B

    BloodHoundAD/SharpHound3

    0View on GitHub↗
    View on GitHub↗0
  • cyberark/aclightcyberark avatar

    cyberark/ACLight

    828View on GitHub↗

    A script for advanced discovery of Privileged Accounts - includes Shadow Admins

    PowerShell
    View on GitHub↗828
  • bb00/zer0dumpB

    bb00/zer0dump

    0View on GitHub↗
    View on GitHub↗0
  • compasssecurity/bloodhoundqueriesC

    CompassSecurity/BloodHoundQueries

    0View on GitHub↗
    View on GitHub↗0
  • dirkjanm/privexchangedirkjanm avatar

    dirkjanm/PrivExchange

    1,066View on GitHub↗

    Exchange your privileges for Domain Admin privs by abusing Exchange

    Python
    View on GitHub↗1,066
  • cfalta/poshadcsC

    cfalta/PoshADCS

    0View on GitHub↗
    View on GitHub↗0
  • dafthack/mailsniperdafthack avatar

    dafthack/MailSniper

    3,246View on GitHub↗

    MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.

    PowerShell
    View on GitHub↗3,246
  • dirkjanm/roadtoolsdirkjanm avatar

    dirkjanm/ROADtools

    2,644View on GitHub↗

    (Rogue Office 365 and Azure (active) Directory tools)

    Python
    View on GitHub↗2,644
  • fatrodzianko/get-rbcd-threadedF

    FatRodzianko/Get-RBCD-Threaded

    0View on GitHub↗
    View on GitHub↗0
  • fox-it/adconnectdumpfox-it avatar

    fox-it/adconnectdump

    794View on GitHub↗

    This toolkit offers several ways to extract and decrypt stored Entra ID (Azure AD) and Active Directory credentials from Entra ID Connect servers. These credentials have high privileges in both the on-premise directory and the cloud. The tools were originally released as part of my Azure AD…

    C#
    View on GitHub↗794
  • dafthack/domainpasswordspraydafthack avatar

    dafthack/DomainPasswordSpray

    2,057View on GitHub↗

    DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!

    PowerShell
    View on GitHub↗2,057
  • fox-it/mitm6fox-it avatar

    fox-it/mitm6

    1,911View on GitHub↗

    mitm6 is a pentesting tool that exploits the default configuration of Windows to take over the default DNS server. It does this by replying to DHCPv6 messages, providing victims with a link-local IPv6 address and setting the attackers host as default DNS server. As DNS server, mitm6 will…

    Python
    View on GitHub↗1,911
  • gentilkiwi/mimikatzgentilkiwi avatar

    gentilkiwi/mimikatz

    21,630View on GitHub↗

    Mimikatz is a security research suite designed for auditing Windows authentication and managing system security configurations. It provides a comprehensive framework for extracting sensitive credentials, manipulating process privileges, and managing digital identity assets directly from system memory or offline memory dumps. The project distinguishes itself through advanced system-level exploitation techniques, including runtime process injection, API hooking, and the ability to bypass cryptographic export restrictions. It features a specialized toolkit for Kerberos protocol operations, allow

    C
    View on GitHub↗21,630
  • gerenios/aadinternalsGerenios avatar

    Gerenios/AADInternals

    1,657View on GitHub↗

    AADInternals is PowerShell module for administering Azure AD and Office 365

    PowerShell
    View on GitHub↗1,657
  • cyberark/zbangC

    cyberark/zBang

    0View on GitHub↗
    View on GitHub↗0
  • c3c/adexplorersnapshot.pyC

    c3c/ADExplorerSnapshot.py

    0View on GitHub↗
    View on GitHub↗0
  • ghostpack/rubeusGhostPack avatar

    GhostPack/Rubeus

    4,890View on GitHub↗

    Rubeus is a comprehensive Kerberos attack toolkit for Active Directory environments, written in C#. It provides a full suite of operations for manipulating Kerberos tickets, exploiting delegation configurations, and performing credential attacks against Windows domains. The toolkit enables ticket extraction from logon sessions and memory, with real-time monitoring via Event Tracing for Windows. It supports forging golden and silver tickets with arbitrary privileges, as well as the creation of forged delegation contexts. Delegation attacks include abuse of constrained and unconstrained delegat

    C#kerberos
    View on GitHub↗4,890
  • bc-security/invoke-zerologonB

    BC-SECURITY/Invoke-ZeroLogon

    0View on GitHub↗
    View on GitHub↗0