Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
-
Updated
Mar 1, 2026
Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support OSCP, Active Directory, CRTE, eJPT and eCPPT.
Active Directory Auditing and Enumeration
Hands-on projects for beginners to learn and practice Active Directory monitoring using various tools.
AD Lab Setup Scripts
This Repository contains my CRTP cum Red Teaming Active Directory attack and Defence preparation notes.
Python3 implementation of ADRecon with support for NTLM and Kerberos authentication querying LDAP. Generates individual CSV files and a single XSLX + HTML report about your AD domain.
Addon for BHCE
An implementation of PyADRecon using ADWS instead of LDAP. Generates individual CSV files and a single XSLX + HTML report about your AD domain. Evades EDR detections through ADWS.
Analyze secretsdump output and hashcat potfiles to find shared passwords and weak credentials in Active Directory
Crackmapexec custom scripts used in my internal pentests.
Centralized Active Directory Auditing Tool
By manipulating LSASS memory flags like UseLogonCredential and IsCredGuardEnabled, this repo demonstrates how Credential Guard can be bypassed—restoring cleartext credentials despite the protection appearing active. Requires SYSTEM-level access and targets VBS-based defenses.
My cyber security notes.
Validate AD credentials over NTLM and Kerberos - passwords, hashes, keys, and tickets
WINFLESHER v0.1.0.5 - MITRE EXPLOITATION FRAMEWORK
A user-friendly and powerful tool to analyze Windows Security Events
A small tool to identify and remediate common misconfigurations in Active Directory Certificate Services
Automated Bash script to deploy a curated Active Directory pentesting toolset.
my notes & methodology used
Add a description, image, and links to the active-directory-security topic page so that developers can more easily learn about it.
To associate your repository with the active-directory-security topic, visit your repo's landing page and select "manage topics."