The Manticore Project is a collective of Go developers and security researchers dedicated to building offensive and defensive security tools, with the shared goal of strengthening the overall security posture of the community.
- manticore-aclmonitor: Watch, diff, and report live changes to the Windows security descriptors of Active Directory objects over LDAP
- manticore-adidns: Query, add, modify, remove, and resurrect Active Directory-integrated DNS records (A, AAAA, NS, CNAME, SOA, SRV) and enumerate and inspect DNS zones on a domain controller over LDAP
- manticore-changepassword: Change and reset Active Directory account passwords (plaintext or NTLM hashes) on domain controllers over MS-SAMR (SMB or MS-RPC transport) and LDAP
- manticore-cve: CVE exploitation toolkit with a hierarchical command structure to list available years and CVE IDs and run individual CVE exploitation modules
- manticore-delegations: Work with all types of Kerberos delegation (unconstrained, constrained, and resource-based constrained delegation) in Active Directory
- manticore-findasreproastables: Extract the list of AS-REP roastable users from Active Directory
- manticore-findgpppasswords: Find and decrypt Group Policy Preferences passwords from the SYSVOL share using low-privileged domain accounts
- manticore-findkerberoastables: Extract the list of Kerberoastable users from Active Directory
- manticore-keycredentials: Create, enroll, attach, describe, list, find, extract, remove, and flush shadow credentials (msDS-KeyCredentialLink entries, their RSA key material, and device IDs) on Active Directory accounts over LDAP
- manticore-keytab: Work with keytab files used by Kerberos to store authentication information
- manticore-ldapconsole: Perform custom LDAP queries against a Windows domain interactively or as one-off commands, with colored output and XLSX export
- manticore-ldapmonitor: Watch, diff, and report live changes to Active Directory objects across a domain's naming contexts over LDAP
- manticore-msrpc: Enumerate, monitor, and fuzz MS-RPC interfaces through a target's endpoint mapper
- manticore-registry: Read, write, search, back up, compare, secure, and live-monitor the Windows registry (keys, values, and ACLs) on remote hosts over MS-RRP (the Remote Registry protocol, \winreg over DCE/RPC over SMB)
- manticore-sidtool: Convert, describe, and look up Windows Security Identifiers (revision level, identifier authority, sub-authorities, and relative identifier) in their string, hexadecimal, base64, and raw bytes representations
- manticore-smbclientng: Fast, cross-platform, and user-friendly client for interacting with SMB shares
- manticore-smbexec: Run commands and open a semi-interactive shell as SYSTEM (cmd and PowerShell payloads, output staged on a writable share) on remote Windows hosts over MS-SCMR
- manticore-zerologon: Detect and exploit the Zerologon authentication bypass (CVE-2020-1472) on Active Directory domain controllers over MS-NRPC
- Manticore: A cross platform library to write offensive and defensive security tools in Go
- gopengraph: A Go library to create BloodHound OpenGraphs easily
- goopts: A library to parse arguments given in command line to a program
- winacl: A library to work with Windows Security Descriptors
You can find us on the following platforms:
- For general information and announcements:
- For code and development:
- For community and discussion:
- Discord: https://discord.gg/w8TNWB6TNb
