Scripts, utilities, and automation I’ve written.

Headhunter

Headhunter

Headhunter: Smart Executive Discovery in Massive Active Directory Environments

The Problem

You’re on an engagement and need to map out the executive structure of a Fortune 500 company. The Active Directory forest has 250,000+ users spread across multiple domains. You need names, titles, org hierarchy, and contact information for every VP and above.

Why executives? They’re high-value targets: elevated privileges, access to sensitive data and systems, and typically good vectors for social engineering. A well-crafted spearphishing campaign targeting VPs yields better results than burning zero-days on random endpoints. Plus, understanding the org structure helps you identify approval chains, find executive assistants (who often have delegated access), and build effective pretexts.

[]

BGPeepr

BGPeepr

Ever find yourself needing to map out all IP ranges owned by a company? Like, really map it out—not just their website, but their entire network footprint across the internet?

This is where BGPeepr can help.

The Genesis

Back in 2015, I was doing recon work and kept finding myself manually digging through BGP routing tables trying to figure out what networks belonged to who. After the hundredth time copying and pasting ASNs and CIDR blocks, I thought: “there has to be a better way.”

[]