SprayingToolkit is a collection of Python scripts/utilities that facilitate password spraying attacks against Lync/S4B & OWA, making the process quicker, less painful, and more efficient. The toolkit consists of four tools: 1. Atomizer: A fast password sprayer for Lync/Skype For Business and OWA, built on Asyncio and Python 3.7. 2. Vaporizer: A port of @OrOneEqualsOne's GatherContacts Burp extension to mitmproxy, which scrapes Google and Bing for LinkedIn profiles, generates emails, and performs password sprays in real-time. 3. Aerosol: A tool that scrapes all text from a target website and sends it to AWS Comprehend for analysis to generate custom wordlists for password spraying. 4. Spindrift: A tool that converts names to active directory usernames. These tools can be used for various password spraying attacks and reconnaissance activities.
FEATURES
ALTERNATIVES
Local pentest lab using docker compose to spin up victim and attacker services.
A C++ staged shellcode loader with evasion capabilities, compatible with Sliver and other shellcode sources, designed for offensive security testing.
Ophcrack is a free Windows password cracker based on rainbow tables with various features for password recovery.
Charlotte is an undetected C++ shellcode launcher for executing shellcode with stealth.
An open-source intelligence collection, research, and artifact management tool inspired by SpiderFoot, Harpoon, and DataSploit.
SauronEye helps in identifying files containing sensitive data such as passwords through targeted directory searches.
Mortar is an evasion technique to defeat and divert detection and prevention of security products, including AV, EDR, and XDR solutions.
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.