A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support OSCP, Active Directory, CRTE, eJPT and eCPPT.
-
Updated
Sep 24, 2025
A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support OSCP, Active Directory, CRTE, eJPT and eCPPT.
Active Directory Auditing and Enumeration
AI-powered modular Active Directory red-team framework for authorized penetration testing, AD enumeration, attack-path analysis, Kerberos/ADCS workflows, reporting, operator automation, and MCP server integration.
Hands-on projects for beginners to learn and practice Active Directory monitoring using various tools.
Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay, delegation), with per-technique OPSEC/telemetry notes. Drives netexec, impacket, certipy, bloodyAD, BloodHound CE.
impacket programming manual and tutorial — write your own AD PoC with Kerberos/RPC/DCOM/WMI source-level guides (中英双语+PDF)
This repository contains my preparation notes for CRTP and Red Teaming, focused on Active Directory attacks and defenses.
A modular Active Directory lab builder for hands-on penetration testing and security research in isolated environments.
Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a single XSLX + HTML report about your AD domain.
Addon for BHCE
An implementation of PyADRecon using ADWS instead of LDAP. Generates individual CSV files and a single XSLX + HTML report about your AD domain. Evades EDR detections through ADWS.
GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted objects via SHOW_DELETED, mapping who can restore them, and revealing when a reanimated identity regains privileged group membership.
A desktop/web app for security engineers and Active Directory administrators to load, browse, compare, audit, and baseline-check Group Policy Object (GPO) backups — without needing a domain controller.
Analyze secretsdump output and hashcat potfiles to find shared passwords and weak credentials in Active Directory
Crackmapexec custom scripts used in my internal pentests.
WINFLESHER v2.0 - ATTACK SURFACE SECURITY FRAMEWORK
Centralized Active Directory Auditing Tool
AI agent harness for Active Directory offensive security — 8 skill domains, 13 slash commands, 7 agents, ROE-safe orchestration. Part of DoOS by Evaluris Solutions Labs.
By manipulating LSASS memory flags like UseLogonCredential and IsCredGuardEnabled, this repo demonstrates how Credential Guard can be bypassed—restoring cleartext credentials despite the protection appearing active. Requires SYSTEM-level access and targets VBS-based defenses.
My cyber security notes.
To associate your repository with the active-directory-security topic, visit your repo's landing page and select "manage topics."