Skip to content
View darmado's full-sized avatar
😀
😀

Block or report darmado

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 250 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
46 stars written in PowerShell
Clear filter

Six Degrees of Domain Admin

PowerShell 10,342 1,783 Updated Aug 1, 2025

game of active directory

PowerShell 6,919 961 Updated Jul 16, 2025

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

PowerShell 4,855 651 Updated Sep 6, 2025

Automation for internal Windows Penetrationtest / AD-Security

PowerShell 3,566 544 Updated Aug 28, 2025

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.

PowerShell 2,349 344 Updated Aug 21, 2025
PowerShell 2,334 371 Updated Oct 14, 2023

A collection of scripts for assessing Microsoft Azure security

PowerShell 2,249 334 Updated Jul 23, 2025

Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute

PowerShell 2,188 397 Updated Sep 23, 2019

BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world.…

PowerShell 2,181 288 Updated Jun 7, 2023

Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made w…

PowerShell 2,027 207 Updated Dec 11, 2024

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

PowerShell 2,023 353 Updated Jun 21, 2025
PowerShell 1,622 310 Updated Apr 14, 2025

Adversary Tactics - PowerShell Training

PowerShell 1,559 337 Updated Jan 22, 2020

PowerShell framework to assess Azure security

PowerShell 1,227 177 Updated Sep 7, 2024

ConPtyShell - Fully Interactive Reverse Shell for Windows

PowerShell 1,153 175 Updated Jan 20, 2023

Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking, IOCs collection & PE Backdooring. You feed it wi…

PowerShell 999 141 Updated May 21, 2025

Invoke-AtomicRedTeam is a PowerShell module to execute tests as defined in the [atomics folder](https://github.com/redcanaryco/atomic-red-team/tree/master/atomics) of Red Canary's Atomic Red Team p…

PowerShell 953 224 Updated Sep 8, 2025

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches

PowerShell 888 137 Updated Mar 7, 2025

Open source C2 server created for stealth red team operations

PowerShell 827 171 Updated Sep 26, 2022

A post exploitation tool based on a web application, focusing on bypassing endpoint protection and application whitelisting

PowerShell 820 129 Updated Apr 4, 2025

WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)

PowerShell 782 82 Updated Feb 3, 2023

Azure JWT Token Manipulation Toolset

PowerShell 686 108 Updated Dec 6, 2024

Simple & Powerful PowerShell Script Obfuscator

PowerShell 580 84 Updated May 13, 2025
PowerShell 526 90 Updated Sep 15, 2022

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

PowerShell 524 113 Updated Jan 21, 2022

PowerShell Ransomware Simulator with C2 Server

PowerShell 488 124 Updated Jan 19, 2024

Zero Infrastructure Password Cracking

PowerShell 409 62 Updated Aug 22, 2024

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

PowerShell 406 61 Updated Sep 27, 2024

Some scripts to abuse kerberos using Powershell

PowerShell 343 45 Updated Jul 27, 2023

Collection of OPSEC Tradecraft and TTPs for Red Team Operations

PowerShell 309 34 Updated Sep 15, 2025
Next