🔴
[ADRunners]
⌕ /
WEB REV HUB
AD WEB REV
CORE ⚙Command Generator
ACTIVE DIRECTORY ◈Techniques Enumeration AS-REP Roasting Kerberoasting Pass-the-Hash Pass-the-Ticket Lateral Movement ACL Abuse DCSync Golden Ticket LLMNR / NTLM Relay Delegation Attacks Shadow Credentials noPAC (CVE-2021-42278) Auth Coercion LAPS Abuse GPO Abuse Domain/Forest Trusts ADIDNS Hijacking Azure AD / Hybrid AD CS Overview
AD CS 🔐Certipy-AD / AD CS ESC1 — SAN Abuse ESC2 — Any Purpose EKU ESC3 — Enrollment Agent ESC4 — Template ACL ESC5 — CA Object ACL ESC6 — CA Flag (SAN) ESC7 — CA Permissions ESC8 — NTLM Relay HTTP ESC9/10 — UPN Mapping ESC11 — NTLM Relay RPC ESC12 — CA Shell Access ESC13 — Policy Group ESC14 — Explicit Mapping ESC15 — EKU Bypass ESC16 — CA Sec Extension ESC17 — Server Auth MITM
TOOLS ⬡Tool Reference Impacket NetExec (nxc) BloodHound Evil-WinRM Kerbrute Mimikatz / Rubeus Responder + ntlmrelayx Coercer + PetitPotam LDAP / SMB Tools
BUG BOUNTY ◎Bug Bounty Hub Methodology SSRF XSS SSTI SQL Injection LFI / Path Traversal XXE CORS Misconfig JWT Attacks IDOR / BOLA OAuth 2.0 HTTP Smuggling Prototype Pollution GraphQL Security Open Redirect Subdomain Takeover Race Conditions Cache Poisoning Deserialization 2FA Bypass File Upload Report Writing
TOOLING ⚡NetExec SMB LDAP WinRM SSH MSSQL Modules ⮐Rev Shells Linux Windows TTY Upgrade 🐍Sliver C2 Listeners Generate Implants HTTP C2 Profile Profiles & Stagers Sessions & Beacons Multi-player Armory Server Cmds 👹Havoc C2 Server Setup Listeners Demon Implant Token Ops Lateral Movement Pivoting / SOCKS5 Injection BOFs & In-Memory Sleep Masks / OPSEC ⬡BH Analyzer ↗
REPORTING ◻Report Writer
ABOUT ◈NetRunners
adrunners.shatcode.org
shatcode.org · WEB · REV
For authorized pentesting & security research only.
ad v1.0 // NetRunners
Login

No account? Register

Create Account

Have an account? Login

⚠
Legal Disclaimer
Read carefully before continuing
Authorised Use Only
Purpose

ADRunners is a professional reference platform for authorised penetration testers, red team operators and security researchers. All techniques, tools and commands documented here are intended exclusively for use on systems and networks for which you hold explicit written authorisation.

Legal Notice

Accessing, testing or attacking computer systems without prior written consent is illegal in most jurisdictions and may constitute a criminal offence under laws including the Computer Fraud and Abuse Act (CFAA), the Computer Misuse Act (CMA), the EU Directive on Attacks Against Information Systems, and equivalent national legislation.

Liability

The authors and operators of this platform accept no responsibility or liability for any damage, data loss, legal consequences or other harm resulting from the misuse of the information provided. You are solely responsible for ensuring your activities comply with applicable law and the scope of your engagement.

This acknowledgement is stored locally and will not be shown again on this device.