targets | Manage target hosts |
creds | Manage stored credentials |
set | Configure persistent settings |
ldap | LDAP enumeration, modification, and vulnerability scanning |
adcs | AD Certificate Services analysis and exploitation |
smb | SMB signing checks and GPP extraction |
spray | Password spraying across multiple protocols |
coerce | Authentication coercion attacks |
krb | Kerberos ticket operations |
bloodhound | BloodHound data collection |
dns | DNS enumeration and zone transfers |
adidns | ADIDNS record manipulation |
adws | Active Directory Web Services |
rdp | RDP operations |
ssh | SSH operations |
winrm | WinRM operations |
psremote | PowerShell Remoting operations |
wmi | WMI queries |
mssql | MSSQL enumeration and exploitation |
rpc | RPC operations |
nfs | NFS enumeration |
ftp | FTP operations |
tickets | Kerberos ticket management |
parse | Parse certificate and key files |
port | Port scanning and banner grabbing |
arp | ARP host discovery |
poison | Network poisoning |
proxy | SOCKS5 proxy configuration |
sccm | SCCM enumeration |
visualize | BloodHound graph visualization |
install | Install binary and shell aliases |
logs | Log management |
query | Database query and export |
tftp | TFTP operations |
exclude | Windows Defender exclusions |