Curtis Houghton (curtishoughton)

curtishoughton

User data from Github https://github.com/curtishoughton

Location:England, United Kingdom

GitHub:@curtishoughton

Curtis Houghton's repositories

Penetration-Testing-Cheat-Sheet

An in-depth guide to help people who are new to penetration testing or red teaming and are looking to gain an overview of the penetration testing process. This guide will focus on both the penetration testing and red team process and contain detailed information.

License:GPL-3.0Stargazers:126Issues:1Issues:0

AADInternals-Endpoints

AADInternals-Endpoints PowerShell module

Language:PowerShellLicense:MITStargazers:0Issues:0Issues:0

ADExplorerSnapshot.py

ADExplorerSnapshot.py is an AD Explorer snapshot parser. It is made as an ingestor for BloodHound, and also supports full-object dumping to NDJSON.

Language:PythonStargazers:0Issues:0Issues:0

Amnesiac

Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with lateral movement within Active Directory environments

Language:PowerShellLicense:BSD-3-ClauseStargazers:0Issues:0Issues:0

APEX

Azure Post Exploitation Framework

Stargazers:0Issues:0Issues:0

autobloody

Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound

License:MITStargazers:0Issues:0Issues:0

bloodyAD

BloodyAD is an Active Directory Privilege Escalation Framework

License:MITStargazers:0Issues:0Issues:0

Certify

Active Directory certificate abuse.

Language:C#License:NOASSERTIONStargazers:0Issues:0Issues:0

CVE-2024-21762

out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability

Language:PythonStargazers:0Issues:0Issues:0

CVE-2024-49113

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

cve-ss-poc

a signal handler race condition in OpenSSH's server (sshd)

Language:CStargazers:0Issues:0Issues:0

EDR-Preloader

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

Language:C++Stargazers:0Issues:0Issues:0

EDRSilencer

A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.

Language:CLicense:MITStargazers:0Issues:0Issues:0

GhostDriver

yet another AV killer tool using BYOVD

Language:RustLicense:GPL-3.0Stargazers:0Issues:0Issues:0

InternalAllTheThings

Active Directory and Internal Pentest Cheatsheets

Stargazers:0Issues:0Issues:0

MemProcFS

MemProcFS

Language:CLicense:AGPL-3.0Stargazers:0Issues:0Issues:0

msldap

LDAP library for auditing MS AD

License:NOASSERTIONStargazers:0Issues:0Issues:0

netcredz

With zero depedencies, NetCredz extracts credentials from pcap files or live traffic, supporting NTLM, LDAP, HTTP, SMTP, SNMP, Telnet, FTP, and Kerberos, while also detecting DHCPv6 and LLMNR traffic. Inspired by PCredz from Laurent Gaffie

Language:PythonLicense:GPL-3.0Stargazers:0Issues:0Issues:0

Nimperiments

Various one-off pentesting projects written in Nim. Updates happen on a whim.

Language:NimStargazers:0Issues:0Issues:0

pingcastle

PingCastle - Get Active Directory Security at 80% in 20% of the time

Language:C#License:NOASSERTIONStargazers:0Issues:0Issues:0

powershell-multithreaded-tcp-port-scanner

A powershell Multi-Threaded TCP Port Scanner

Language:PowerShellLicense:GPL-3.0Stargazers:0Issues:0Issues:0

process-inject-kit

Port of Cobalt Strike's Process Inject Kit

Stargazers:0Issues:0Issues:0

PyPhisher

Easy to use phishing tool with 77 website templates. Author is not responsible for any misuse.

Language:PythonLicense:GPL-3.0Stargazers:0Issues:0Issues:0

pywhisker

Python version of the C# tool for "Shadow Credentials" attacks

Language:PythonLicense:GPL-3.0Stargazers:0Issues:0Issues:0

rengine

reNgine is an automated reconnaissance framework.

Language:HTMLLicense:GPL-3.0Stargazers:0Issues:0Issues:0

ROADtools

A collection of Azure AD/Entra tools for offensive and defensive security purposes

License:MITStargazers:0Issues:0Issues:0

routersploit

Exploitation Framework for Embedded Devices

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0

SCCMSecrets

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

Language:PythonStargazers:0Issues:0Issues:0

ThreadlessInject-C

This repository implements Threadless Injection in C

Language:CStargazers:0Issues:0Issues:0

TrickDump

Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!

Stargazers:0Issues:0Issues:0