diff --git a/Offensive.md b/Offensive.md index 93923b7..cc53830 100644 --- a/Offensive.md +++ b/Offensive.md @@ -982,6 +982,10 @@ Some tools can be categorized in more than one category. But because the current dafthack/MSOLSpray A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, if the account is locked, or if the account is disabled. + + danf42/GetLsaSecrets + C# implementation of Get-LSASecrets originally written in PowerShell + DanMcInerney/icebreaker Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment