PowerUpSQL is a tool that allows for the enumeration and attack of Active Directory environments through access to a SQL Server, enabling the targeting of not only the current domain but also trusting forests in a Two-Way External Trust.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A PoC tool for generating Excel files with embedded macros without using Excel.
A collection of precompiled Windows exploits for privilege escalation.
A modular and script-friendly multithread bruteforcer for managing task parameters in Python scripts.
A post-exploitation tool for Azure Active Directory and Office 365 environments that manages access tokens and provides interactive access to Microsoft 365 services.
The Proxmark III is a versatile device for sniffing, reading, and cloning RFID tags with strong community support.
A tool that checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names.
Open source application for retrieving passwords stored on a local computer with support for various software and platforms.
Ophcrack is a free Windows password cracker based on rainbow tables with various features for password recovery.
Wfuzz is a tool designed for bruteforcing Web Applications with multiple features like multiple injection points, recursion, and payload combinations.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.