AD Attack Paths
9 tools
DACL Reader
Grades Active Directory ACL attack paths from PowerView/xlsx exports, with a Tier 0 baseline to cut the noise.
Open tool
ADCS ESC Finder
Classifies ESC1–ESC16 from Certipy / Certify / certutil output with operator + defender guidance.
Open tool
Delegation Auditor
Finds unconstrained / constrained / S4U2Self / RBCD delegation with the exact S4U commands.
Open tool
Attack Path Chainer
Ranks the shortest paths from widely-held principals to Domain Admin. Exports BloodHound OpenGraph.
Open tool
NTLM Relay & Coercion Analyzer
Finds relay-viable hosts (SMB signing off) from NetExec/nmap output, maps coercion vectors, and builds the ntlmrelayx + ADCS ESC8 chain.
Open tool
BloodHound Diff
Compare two SharpHound collections to surface new attack edges, new Tier-0 paths, and removed privileges between snapshots. Drop before/after JSON files — offline.
Open tool
Trust & Forest Map
Visualize AD domain/forest trusts from nltest, Get-ADTrust, or BloodHound exports. Flags SID filtering gaps, PAM trusts, selective auth, and cross-forest attack paths.
Open tool
NEW
Shadow Credential & gMSA Auditor
Find who can write msDS-KeyCredentialLink (Shadow Credentials → PKINIT account takeover) and who can read gMSA passwords. Certipy/pyWhisker/Whisker + gMSADumper commands, edges export.
Open tool
NEW
DCSync Rights Auditor
Paste an ACL export over the domain head — aggregates DS-Replication-Get-Changes + Get-Changes-All per principal and flags exactly who can DCSync (full / partial / indirect).
Open tool
Credentials & Hashes
6 tools
PreAuth Enum Analyzer
Turns kerbrute / GetNPUsers output into a clean valid-user list and the AS-REP-roastable subset.
Open tool
Kerberoast Triage
Ranks Kerberoast / AS-REP targets by crackability × impact; exports hashes to the Hash Analyzer.
Open tool
Kerberos Ticket Inspector
Decodes a base64 .kirbi and flags golden / silver tickets — pure ASN.1, no key needed.
Open tool
Hash Analyzer
Identifies a hash, gives its hashcat/john mode, crack difficulty, and copy-paste crack commands.
Open tool
GPP Password Decryptor
Decrypts Group Policy Preferences cpassword values to plaintext — the AES key is public.
Open tool
NEW
Timeroast Analyzer
Paste Timeroast output ($sntp-ms$ hashes keyed by RID) — cleans hashes, builds the hashcat -m 31300 crack plan, generates a targeted computer-name wordlist, and maps RIDs to accounts.
Open tool
Web App
3 tools
Payload Studio
Context-aware XSS / SQLi / SSTI / injection payloads plus an 11-way WAF-bypass encoder.
Open tool
Upload Filter Analyzer
Describe an upload filter, get the bypass techniques that still apply with benign PoCs and fixes.
Open tool
JWT / Token Inspector
Decodes a JWT, flags weaknesses (alg:none, weak HS256 secret, kid/jku), and maps Microsoft Entra / Azure AD claims to abuse potential.
Open tool
Cloud
2 tools
Entra / Azure Token & Scope Analyzer
Paste an Azure/Entra access token (JWT), decoded claims, or a Graph grants export — classify delegated vs app-only Graph permissions, flag escalation-to-Global-Admin, wids directory roles, and FOCI family membership.
Open tool
AWS IAM PassRole Analyzer
Paste aws iam get-account-authorization-details JSON to map IAM privilege-escalation paths: iam:PassRole chains, wildcard actions, admin-equivalent permissions, and cross-account trust abuse.
Open tool
Recon & Planning
3 tools
Linux Privesc Parser
Turns linPEAS / sudo -l / SUID / getcap output into a ranked path to root with GTFOBins commands.
Open tool
Password Spray Planner
Computes a lockout-safe spray cadence + schedule + candidate passwords. Planning only — never fires.
Open tool
Certificate Validator
Matches keys to certs/CSRs and flags AD logon certs (PKINIT / ESC1 UPN SANs). Fully offline.
Open tool
Detection & Defense
5 tools
GPO Security Auditor
Flag non-admin GPO write rights on privileged OUs, WDigest cleartext creds, missing Credential Guard, LSASS PPL gaps, disabled PowerShell ScriptBlock logging, and absent AppLocker.
Open tool
LAPS Auditor
Find computers missing LAPS, who can read ms-Mcs-AdmPwd or msLAPS-Password, stale password age, and Legacy vs Windows LAPS gaps. Coverage meter + operator paths.
Open tool
DC Infrastructure & Legacy Protocol Auditor
Flag SMBv1, NTLMv1/LM, LDAP signing gaps, Print Spooler on DCs, RC4/DES Kerberos, obsolete OS, stale computer accounts, and old functional levels — PingCastle Anomalies coverage.
Open tool
Password Policy & Account Hygiene Auditor
Audit AD password policies, fine-grained PSOs, PASSWD_NOTREQD accounts, reversible encryption, krbtgt age, adminCount drift, and DA count — PingCastle/PurpleKnight gap coverage.
Open tool
Detection Rule Generator
Paste an EHWS finding, MITRE ATT&CK technique ID, or Windows Event ID to get a ready-to-deploy SIGMA rule and Sysmon config snippet. 16 technique KB, fully offline.
Open tool
Utilities
8 tools
Hash Generator
Generate MD5, SHA-1, SHA-256, SHA-512, and other hashes from any text input. Offline, client-side.
Open tool
Hash Identifier
Identify unknown hash types by length and character set. Useful for rapid triage of captured credential material.
Open tool
Encoder / Decoder
Base64, URL, HTML entity, hex encoding and decoding. Fast in-browser conversion with no data leaving your machine.
Open tool
Subnet Calculator
Calculate CIDR ranges, host counts, broadcast addresses, and network boundaries. Covers IPv4 subnetting.
Open tool
JSON Formatter
Prettify, validate, and minify JSON data. Useful for making BloodHound exports and API responses readable.
Open tool
Password Generator
Generate strong, randomised passwords to defined complexity rules. Fully offline — no passwords leave your browser.
Open tool
Cron Builder
Build and validate cron expressions visually. Useful for reviewing scheduled-task persistence on Linux targets.
Open tool
IP Info
Look up geolocation, ASN, and ISP data for any IP address. Quick triage for external-facing infrastructure.
Open tool