
Internal-Monologue
Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

A little tool to play with Windows security

Tool for extracting Windows credentials (passwords, hashes, Kerberos tickets) from memory and performing pass-the-hash, pass-the-ticket, and golden…


a tool to manipulate dcc(domain cached credentials) in windows registry, based mainly on the work of mimikatz and impacket

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

Red teaming tool to dump LSASS memory, bypassing basic countermeasures.

Trying to tame the three-headed dog.

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. In C#, C++, Crystal, Python, Rust, Golang, Nim…


Credentials gathering tool automating remote procdump and parse of lsass process.

Credential Guard Bypass Via Patching Wdigest Memory

Modified mimikatz binary with resource modification and digital signature to evade 360 Antivirus detection for credential dumping in penetration…

This tool leverages the Process Forking technique using the RtlCreateProcessReflection API to clone the lsass.exe process. Once the clone is created,…

Active Directory security risk assessment tool that evaluates vulnerabilities, misconfigurations, and maturity using a streamlined methodology,…

Extract Windows credentials directly from VM memory snapshots and virtual disks