Author: ddos

FindGPPPasswords

FindGPPPasswords: Uncover Group Policy Preferences Passwords

FindGPPPasswords A cross-platform tool to find and decrypt Group Policy Preferences passwords from the SYSVOL share using low-privileged domain accounts. Features  Only requires a low privileges domain user account.  Automatically gets the list of all...

Microsoft 365 reconnaissance

MSFTRecon: Unauthenticated Recon Tool for Microsoft 365 & Azure

MSFTRecon is a reconnaissance tool designed for red teamers and security professionals to map Microsoft 365 and Azure tenant infrastructure. It performs comprehensive enumeration without requiring authentication, helping identify potential security misconfigurations and attack...

reverse-engineer REST APIs

mitmproxy2swagger: Automagically reverse-engineer REST APIs

mitmproxy2swagger A tool for automatically converting mitmproxy captures to OpenAPI 3.0 specifications. This means that you can automatically reverse-engineer REST APIs by just running the apps and capturing the traffic. Install First, you will need python3 and pip3....

Email misconfiguration tool

MailFail: Identify Email Misconfigurations in Your Browser

MailFail identifies and provides commands to exploit a large number of email-related misconfigurations for the current domain and subdomain within a web browser. The extension’s UI popup highlights any misconfigurations in red and links...

katana: next-generation crawling and spidering framework

Katana A next-generation crawling and spidering framework Feature Fast And fully configurable web crawling Standard and Headless mode support JavaScript parsing / crawling Customizable automatic form filling Scope control – Preconfigured field / Regex Customizable output – Preconfigured fields INPUT – STDIN, URL and LIST...