CrackMapExec Logo

CrackMapExec

0
Free
Visit Website

It's a post-exploitation tool (e.g. Veil-Pillage, smbexec) It's meant to be the 'glue' between exploitation frameworks when pentesting Active Directory It's fully concurrent: you're able to connect, authenticate etc.. to multiple hosts at the same time It has an internal database which is used to store credentials and track users with Administrative privileges It's functionality is based on several other tools and libraries (a list of them are in the Github repo's README) It's opsec safe: everything is either run in memory, enumerated over the network using WinAPI calls or executed using built-in windows tools/features. Part 1, will cover the basics such as using credentials, dumping credentials, executing commands and using the

FEATURES

ALTERNATIVES

Pacu is an open-source AWS exploitation framework for offensive security testing against cloud environments.

Tool for attacking Active Directory environments through SQL Server access.

A comprehensive malware-analysis tool that utilizes external AV scanners to identify malicious elements in binary files.

A blog post about bypassing AppLocker using PowerShell diagnostic scripts

Full-featured C2 framework for stealthy communication and control on web servers.

Alpha release of External C2 framework for Cobalt Strike with enhanced data channels.

Pupy is a cross-platform C2 and post-exploitation framework for remote access and control of compromised systems across various operating systems.

A C#-based Command and Control Framework for remote access and control of compromised systems.