Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
-
Updated
Mar 1, 2026
Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support OSCP, Active Directory, CRTE, eJPT and eCPPT.
Active Directory Auditing and Enumeration
Hands-on projects for beginners to learn and practice Active Directory monitoring using various tools.
This Repository contains my CRTP cum Red Teaming Active Directory attack and Defence preparation notes.
AD Lab Setup Scripts
Addon for BHCE
Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a single XSLX + HTML report about your AD domain.
An implementation of PyADRecon using ADWS instead of LDAP. Generates individual CSV files and a single XSLX + HTML report about your AD domain. Evades EDR detections through ADWS.
Analyze secretsdump output and hashcat potfiles to find shared passwords and weak credentials in Active Directory
Crackmapexec custom scripts used in my internal pentests.
Centralized Active Directory Auditing Tool
My cyber security notes.
By manipulating LSASS memory flags like UseLogonCredential and IsCredGuardEnabled, this repo demonstrates how Credential Guard can be bypassed—restoring cleartext credentials despite the protection appearing active. Requires SYSTEM-level access and targets VBS-based defenses.
WINFLESHER v0.1.0.5 - MITRE EXPLOITATION FRAMEWORK
A user-friendly and powerful tool to analyze Windows Security Events
A small tool to identify and remediate common misconfigurations in Active Directory Certificate Services
Automated Bash script to deploy a curated Active Directory pentesting toolset.
my notes & methodology used
AR.PY - Admin and React simplifies the account managing in order to make managing, disabling and password resetting automated.
Add a description, image, and links to the active-directory-security topic page so that developers can more easily learn about it.
To associate your repository with the active-directory-security topic, visit your repo's landing page and select "manage topics."