Skip to content
@TheManticoreProject

The Manticore Project

Crowdsourced open source offensive and defensive security tools, to heighten the security posture of the community as a whole


The Manticore Project is a collective of Go developers and security researchers dedicated to building offensive and defensive security tools, with the shared goal of strengthening the overall security posture of the community.


Tools

  • manticore-adidns: Query, add, modify, remove, and resurrect Active Directory-integrated DNS records (A, AAAA, NS, CNAME, SOA, SRV) and enumerate and inspect DNS zones on a domain controller over LDAP
  • manticore-changepassword: Change and reset Active Directory account passwords (plaintext or NTLM hashes) on domain controllers over MS-SAMR (SMB or MS-RPC transport) and LDAP
  • manticore-cve: CVE exploitation toolkit with a hierarchical command structure to list available years and CVE IDs and run individual CVE exploitation modules
  • manticore-keycredentials: Create, enroll, attach, describe, list, find, extract, remove, and flush shadow credentials (msDS-KeyCredentialLink entries, their RSA key material, and device IDs) on Active Directory accounts over LDAP
  • manticore-msrpc: Enumerate, monitor, and fuzz MS-RPC interfaces through a target's endpoint mapper
  • manticore-registry: Read, write, search, back up, compare, secure, and live-monitor the Windows registry (keys, values, and ACLs) on remote hosts over MS-RRP (the Remote Registry protocol, \winreg over DCE/RPC over SMB)
  • manticore-sidtool: Convert, describe, and look up Windows Security Identifiers (revision level, identifier authority, sub-authorities, and relative identifier) in their string, hexadecimal, base64, and raw bytes representations
  • manticore-smbexec: Run commands and open a semi-interactive shell as SYSTEM (cmd and PowerShell payloads, output staged on a writable share) on remote Windows hosts over MS-SCMR
  • manticore-zerologon: Detect and exploit the Zerologon authentication bypass (CVE-2020-1472) on Active Directory domain controllers over MS-NRPC

Libraries

  • Manticore: A cross platform library to write offensive and defensive security tools in Go
  • gopengraph: A Go library to create BloodHound OpenGraphs easily
  • goopts: A library to parse arguments given in command line to a program
  • winacl: A library to work with Windows Security Descriptors

Socials

You can find us on the following platforms:

Popular repositories Loading

  1. manticore-delegations manticore-delegations Public

    A tool to work with all types of Kerberos delegations (unconstrained, constrained, and resource-based constrained delegations) in Active Directory

    Go 222 18

  2. manticore-findgpppasswords manticore-findgpppasswords Public

    A cross-platform tool to find and decrypt Group Policy Preferences passwords from the SYSVOL share using low-privileged domain accounts

    Go 175 23

  3. Manticore Manticore Public

    A cross platform library to write offensive and defensive security tools in Go

    Go 158 7

  4. LDAPWordlistHarvester LDAPWordlistHarvester Public

    A tool that allows you to extract a client-specific wordlist from the LDAP of an Active Directory.

    Go 59 4

  5. DescribeNTSecurityDescriptor DescribeNTSecurityDescriptor Public

    A cross-platform tool to parse and describe the contents of a raw ntSecurityDescriptor structure

    Go 52 3

  6. winacl winacl Public

    A cross platform Go library to work with Windows Security Descriptors

    Go 43 5

Repositories

Showing 10 of 23 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…