Skip to content
View n3wpr's full-sized avatar
🐰
Why are you wearing that stupid man suit?
🐰
Why are you wearing that stupid man suit?

Block or report n3wpr

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

BloodyAD is an Active Directory Privilege Escalation Framework

Python 2,070 196 Updated Jan 19, 2026

Lsass dumper evading (all ?) EDR detection

C 47 12 Updated Nov 10, 2025

Dump lsass using only NTAPI functions by hand-crafting Minidump files (without MiniDumpWriteDump!!!)

C# 697 96 Updated May 7, 2025

Dumping LSASS with a duplicated handle from custom LSA plugin

C# 204 25 Updated Feb 23, 2022

Extract WinSCP Credentials from any Windows System or winscp config file

Python 22 5 Updated Jul 10, 2025

Extract SAM and SYSTEM using Volume Shadow Copy (VSS) API. With multiple exfiltration options and XOR obfuscation

C# 330 47 Updated Jan 13, 2026

The swiss army knife of LSASS dumping

C 2,065 261 Updated Sep 17, 2024

Privilege Escalation Enumeration Script for Windows

PowerShell 3,665 499 Updated Jan 30, 2026

⏬ Dumb downloader that scrapes the web

Python 56,717 9,808 Updated Apr 27, 2025

Fragtunnel is a proof-of-concept (PoC) TCP tunnel tool that you can use to tunnel your application's traffic and bypass next-generation firewalls en route to the target.

Python 220 34 Updated Jun 4, 2024

LudusHound is a tool for red and blue teams that transforms BloodHound data into a fully functional, Active Directory replica environment via Ludus for controlled testing.

PowerShell 350 24 Updated Sep 3, 2025

SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connectivity using Windows Filtering Platform (WFP). This version fo…

C 432 65 Updated Nov 3, 2025

Why is this running?

Go 12,270 292 Updated Jan 24, 2026

CVE-2025-55182 POC

JavaScript 792 206 Updated Dec 8, 2025

Explanation and full RCE PoC for CVE-2025-55182

Python 1,360 193 Updated Dec 8, 2025

🧙‍♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

JavaScript 1,288 213 Updated Jun 17, 2025

Python alternative to Mimikatz lsadump::dcshadow

Python 157 17 Updated Jun 24, 2025

A small tool to convert Base64-encoded .kirbi tickets from Rubeus into .ccache files for Impacket

Python 72 20 Updated May 18, 2020

Sandboxie Plus & Classic

C 17,378 1,900 Updated Jan 30, 2026

PHP tool that takes screenshots of a given ips/ports combo list and then try to guess the service.

PHP 10 7 Updated Dec 2, 2022

A PHP tool to brute force vhost configured on a server.

PHP 89 31 Updated Dec 2, 2022

Try to find the origin IP of a webapp protected by Cloudflare.

Python 356 70 Updated Aug 8, 2024

This repo covers some code execution and AV Evasion methods for Macros in Office documents

VBA 1,259 233 Updated Jan 27, 2022

PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.

PowerShell 72 11 Updated Oct 22, 2025

Random Tools

PowerShell 851 213 Updated Oct 20, 2022

Impacket is a collection of Python classes for working with network protocols.

Python 15,405 3,859 Updated Jan 30, 2026

List of Awesome Red Team / Red Teaming Resources This list is for anyone wishing to learn about Red Teaming but do not have a starting point.

723 104 Updated Jan 9, 2025

PoC Exploit for the NTLM reflection SMB flaw.

Python 668 126 Updated Jan 20, 2026

CVE-2024-20338 talk for Behind The Code Talk

Shell 4 Updated Jun 10, 2024

Tool for viewing NTDS.dit

C# 191 16 Updated Mar 14, 2025
Next