Post-Exploitation
Pivoting, tunnelling, shells and credential harvesting. · 17 commands
Netcat (nc)
mediumThe TCP/IP “swiss-army knife”.
socat
mediumMultipurpose relay — “netcat on steroids”.
proxychains
lowForce any TCP tool through a proxy chain.
Chisel
mediumFast TCP/UDP tunnel over HTTP/SSH.
Mimikatz
highExtract Windows credentials from memory.
Weevely
highStealthy PHP web shell & manager.
Impacket
highPython toolkit of Windows/AD attack scripts.
BloodHound
mediumMap Active Directory attack paths.
PowerSploit
highPowerShell post-exploitation modules.
sshuttle
lowTransparent VPN-over-SSH for pivoting.
Ligolo-ng
mediumFast tunneling/pivoting via a TUN interface.
pwncat
highSupercharged reverse-shell handler.
pspy
lowWatch processes/cron without root.
Linux Exploit Suggester
lowSuggest kernel/privesc exploits for a host.
Certipy
highAttack Active Directory Certificate Services.
Rubeus
highKerberos abuse toolkit for Windows.
SharpHound
mediumBloodHound data collector for AD.