It's a post-exploitation tool (e.g. Veil-Pillage, smbexec) It's meant to be the 'glue' between exploitation frameworks when pentesting Active Directory It's fully concurrent: you're able to connect, authenticate etc.. to multiple hosts at the same time It has an internal database which is used to store credentials and track users with Administrative privileges It's functionality is based on several other tools and libraries (a list of them are in the Github repo's README) It's opsec safe: everything is either run in memory, enumerated over the network using WinAPI calls or executed using built-in windows tools/features. Part 1, will cover the basics such as using credentials, dumping credentials, executing commands and using the
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A reconnaissance tool that retrieves information from Office 365 and Azure Active Directory using a valid credential.
Open-source project for building instrumented environments to simulate attacks and test detections.
A comprehensive malware-analysis tool that utilizes external AV scanners to identify malicious elements in binary files.
LinEnum is a tool for Linux enumeration that provides detailed system information and performs various checks and tasks.
Macro_Pack is a tool used to automate obfuscation and generation of Office documents for pentest, demo, and social engineering assessments.
A C#-based Command and Control Framework for remote access and control of compromised systems.
Open-source Java application for creating proxies for traffic analysis & modification.
Alpha release of External C2 framework for Cobalt Strike with enhanced data channels.
A tool for managing multiple reverse shell sessions/clients via terminal with a RESTful API.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.