This is your work, valued
Inveigh. .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers
★ 3kInvoke-TheHash. PowerShell Pass The Hash Utils
★ 1.8kPowermad. PowerShell MachineAccountQuota and DNS exploit tools
★ 1.5kInveighZero. .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers
★ 814Tater. Tater is a PowerShell implementation of the Hot Potato Windows Privilege Escalation exploit from @breenmachine and @foxglovesec
★ 455Sharpmad. C# version of Powermad
★ 172Conveigh. Conveigh is a Windows PowerShell LLMNR/NBNS spoofer detection tool
★ 99Empire. Empire is a pure PowerShell post-exploitation agent.
★ 11Quiddity. .NET miscellaneous protocol library meant for infosec testing/defense.
★ 10TangledWinExec. PoCs and tools for investigation of Windows process execution techniques
★ 957PPLmedic. Dump the memory of any PPL with a Userland exploit chain
★ 353Freeze. Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods
★ 1.5kAmsi-Killer. Lifetime AMSI bypass
★ 680PetitPotam. PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
★ 2.3kSharpSMBSpray. Spray a hash via smb to check for local administrator access
★ 143onedrive_user_enum. onedrive user enumeration - pentest tool to enumerate valid o365 users
★ 761OffensiveNim. My experiments in weaponizing Nim (https://nim-lang.org/)
★ 3.1kopenedr. Open EDR public repository
★ 2.7kSharpSecDump. .Net port of the remote SAM + LSA Secrets dumping functionality of impacket's secretsdump.py
★ 614StandIn. StandIn is a small .NET35/45 AD post-exploitation toolkit
★ 257UltimateWDACBypassList. A centralized resource for previously documented WDAC bypass techniques
★ 629Sharp-Suite. Also known by Microsoft as Knifecoat :hot_pepper:
★ 1.1klsassy. Extract credentials from lsass remotely
★ 2.2kDNSUpdate. A python based script to update DNS entries in ADIDNS
★ 43OffensiveCSharp. Collection of Offensive C# Tooling
★ 1.5kSharpMove. .NET Project for performing Authenticated Remote Execution
★ 409SCShell. Fileless lateral movement tool that relies on ChangeServiceConfigA to run command
★ 1.6kWinshark. A wireshark plugin to instrument ETW
★ 592RequestAADRefreshToken. C#
★ 159SocksOverRDP. Socks5/4/4a Proxy support for Remote Desktop Protocol / Terminal Services / Citrix / XenApp / XenDesktop
★ 1.3kSysWhispers. AV/EDR evasion via direct system calls.
★ 2krdp-rs. Remote Desktop Protocol in RUST
★ 251SharpHide. Tool to create hidden registry keys.
★ 489SharpChromium. .NET 4.0 CLR Project to retrieve Chromium data, such as cookies, history and saved logins.
★ 761DetectionLab. Automate the creation of a lab environment complete with security tooling and logging best practices
★ 5kWindowsProtocolTestSuites. ⭐⭐ Join us at SambaXP for the SMB3 IO Lab (April 20-23, 2026), see upcoming Interoperability Events
★ 562Findomain. The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.
★ 3.8kxolo. Tool to crawl, visualize and interact with SQL server links in a d3 graph to help in your red/blue/purple/.../risk assessments pentest hacking team exercises.
★ 19MobileHackingCheatSheet. Basics on commands/tools/info on how to assess the security of mobile applications
★ 1.7kgraftcp. A flexible tool for redirecting a program's TCP, UDP, and DNS traffic to SOCKS5 or HTTP proxies.
★ 2.6kflamingo. Flamingo captures credentials sprayed across the network by various IT and security products.
★ 489Salsa-tools. Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched
★ 587SharpRDP. Remote Desktop Protocol .NET Console Application for Authenticated Command Execution
★ 1.2kMSBuildAPICaller. MSBuild Without MSBuild.exe
★ 155UACME. Defeating Windows User Account Control
★ 7.7kGet-RBCD-Threaded. Tool to discover Resource-Based Constrained Delegation attack paths in Active Directory environments
★ 133sandbox-attacksurface-analysis-tools. Set of tools to analyze Windows sandboxes for exposed attack surface.
★ 2.3kSMBLibrary. Free, Open Source, User-Mode SMB 1.0/CIFS, SMB 2.0, SMB 2.1 and SMB 3.0 server and client library
★ 876WitnessMe. Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.
★ 760UhOh365. A script that can see if an email address is valid in Office365 (user/email enumeration). This does not perform any login attempts, is unthrottled, and is incredibly useful for social engineering assessments to find which emails exist and which don't.
★ 609Recon-AD. Recon-AD, an AD recon tool based on ADSI and reflective DLL’s
★ 332CarbonCopy. A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux
★ 1.4kminikerberos. Kerberos manipulation library in pure Python
★ 304ticket_converter. A little tool to convert ccache tickets into kirbi (KRB-CRED) and vice versa based on impacket.
★ 171Cloud-Security-Research. Cloud-related research releases from the Rhino Security Labs team.
★ 392ridrelay. Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.
★ 399Dumpert. LSASS memory dumper using direct system calls and API unhooking.
★ 1.6kGTFOBins.github.io. GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
★ 14kphantap. Phantom Tap (PhanTap) - an ‘invisible’ network tap aimed at red teams
★ 625WindowsTimeline. Windows 10 (v1803+) ActivitiesCache.db parsers (SQLite, PowerShell, .EXE)
★ 197SharpGPOAbuse. SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.
★ 1.3kh8mail. Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email
★ 5.2knecrobrowser-old-go. Go
★ 143muraena. Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities.
★ 1.1kVECTR. VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios
★ 1.6kCheck-LocalAdminHash. Check-LocalAdminHash is a PowerShell tool that attempts to authenticate to multiple hosts over either WMI or SMB using a password hash to determine if the provided credential is a local administrator. It's useful if you obtain a password hash for a user and want to see where they are local admin on a network. It is essentially a Frankenstein of two of my favorite tools along with some of my own code. It utilizes Kevin Robertson's (@kevin_robertson) Invoke-TheHash project for the credential checking portion. Additionally, the script utilizes modules from PowerView by Will Schroeder (@harmj0y) and Matt Graeber (@mattifestation) to enumerate domain computers to find targets for testing admin access against.
★ 178runzero-tools. Open source tools, libraries, and datasets related to the runZero product and associated research
★ 123fireprox. AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation
★ 2.3kEWSToolkit. Abusing Exchange via EWS
★ 151SharpShooter. Payload Generation Framework
★ 2kbta. Open source Active Directory security audit framework.
★ 138PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
★ 80kInvoke-Clipboard. All of Your Copy/Paste Belong to Us: Stealing the clipboard and using it for C2 communications
★ 88Venom. Venom - A Multi-hop Proxy for Penetration Testers
★ 2.2kshodan-python. The official Python library for Shodan
★ 2.9kwebxcel. 🤔 A REST backend built with plain VBA Microsoft Excel macros. Yes. Macros.
★ 466TikiTorch. Process Injection
★ 765krbrelayx. Kerberos relaying and unconstrained delegation abuse toolkit
★ 1.6ksRDI. Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode
★ 2.5kgit-history. Quickly browse the history of a file from any git repository
★ 14kpingcastle. PingCastle - Get Active Directory Security at 80% in 20% of the time
★ 2.9kExchange2domain. CVE-2018-8581
★ 369PrivExchange. Exchange your privileges for Domain Admin privs by abusing Exchange
★ 1.1kimpacket_static_binaries. Standalone binaries for Linux/Windows of Impacket's examples
★ 751wsIPC. Working Set Page Cache side-channel IPC PoC
★ 66LOLBAS. Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
★ 8.7kOffensiveDLR. Toolbox containing research notes & PoC code for weaponizing .NET's DLR
★ 526DCOMrade. Powershell script for enumerating vulnerable DCOM Applications
★ 263cloudgoat. CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
★ 3.7kphishdetect. PhishDetect is a library to help identify phishing pages
★ 107RedTeamPowershellScripts. Various PowerShell scripts that may be useful during red team exercise
★ 963waybackurls. Fetch all the URLs that the Wayback Machine knows about for a domain
★ 4.5kSharpCompile. SharpCompile is an aggressor script for Cobalt Strike which allows you to compile and execute C# in realtime. This is a more slick approach than manually compiling an .NET assembly and loading it into Cobalt Strike. The project aims to make it easier to move away from adhoc PowerShell execution instead creating a temporary assembly and executing using beacon's 'execute-assembly' in seconds.
★ 288EmbedInHTML. Embed and hide any file in an HTML file
★ 491credgrap_ie_edge. Extract stored credentials from Internet Explorer and Edge
★ 323SlackExtract. A PowerShell script to download all files, messages and user profiles that a user has access to in slack.
★ 161ja3. JA3 is a standard for creating SSL client fingerprints in an easy to produce and shareable way.
★ 3.1kkeyring. Proper Payload Protection Prevents Poor Performance
★ 76keyserver. Easily serve HTTP and DNS keys for proper payload protection
★ 59joincap. Merge multiple pcap files together, gracefully.
★ 219trufflehog. Find, verify, and analyze leaked credentials
★ 27kSharpSploit. SharpSploit is a .NET post-exploitation library written in C#
★ 1.9koleviewdotnet. A .net OLE/COM viewer and inspector to merge functionality of OleView and Test Container
★ 1.4kdatasploit. An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and give data in multiple formats.
★ 3.3kredteam-notebook. Collection of commands, tips and tricks and references I found useful during preparation for OSCP exam.
★ 441sectaskbars. Security Product Taskbar Icons (to identify from screenshots)
★ 58HELK. The Hunting ELK
★ 3.9kshellen. :cherry_blossom: Interactive shellcoding environment to easily craft shellcodes
★ 907PCredz. This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP, IMAP, etc from a pcap file or from a live interface.
★ 2.5kpacu. The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
★ 5.3kDivertTCPconn. A TCP packet diverter for Windows platform
★ 346WinDivert. WinDivert: Windows Packet Divert
★ 3.2kMicroBurst. A collection of scripts for assessing Microsoft Azure security
★ 2.4kInception. Provides In-memory compilation and reflective loading of C# apps for AV evasion.
★ 369Red-Teaming-Toolkit. This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
★ 11kChiron. Chiron - An IPv6 Security Assessment framework with advanced IPv6 Extension Headers manipulation capabilities.
★ 209SharpCloud. Simple C# for checking for the existence of credential files related to AWS, Microsoft Azure, and Google Compute.
★ 177Security-Research. Exploits written by the Rhino Security Labs team
★ 1.1kethereum-bnb-mev-bot. 🔵 Ethereum and BNB (BSC) Mev bot - Arbitrage
★ 365MakeMeEnterpriseAdmin. PowerShell
★ 267Pause-Process. PowerShell script which allows pausing\unpausing Win32/64 exes
★ 144Sharp-WMIExec. C#
★ 206extractTVpasswords. tool to extract passwords from TeamViewer memory using Frida
★ 462BloodHound.py. A Python based ingestor for BloodHound
★ 2.4kNTLMInjector. In case you didn't now how to restore the user password after a password reset (get the previous hash with DCSync)
★ 171Invoke-TmpDavFS. Memory Backed Powershell WebDav Server
★ 137detect-responder. Python
★ 76SQLC2. SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.
★ 75UserEnum. Domain user enumeration tool
★ 216CloudScraper. CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.
★ 537GatherContacts. A Burp Suite Extension to pull Employee Names from Google and Bing LinkedIn Search Results
★ 210Worse-PDF. Turn a normal PDF file into malicious.Use to steal Net-NTLM Hashes from windows machines.
★ 344Seth. Perform a MitM attack and extract clear text credentials from RDP connections
★ 1.5kLOLBAS. Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
★ 1.6kBad-Pdf. Steal Net-NTLM Hash using Bad-PDF
★ 1.1kntlmv1-multi. NTLMv1 Multitool
★ 669goddi. goddi (go dump domain info) dumps Active Directory domain information
★ 424Invoke-DOSfuscation. Cmd.exe Command Obfuscation Generator & Detection Test Harness
★ 948PowerMeta. PowerMeta searches for publicly available files hosted on various websites for a particular domain by using specially crafted Google, and Bing searches. It then allows for the download of those files from the target domain. After retrieving the files, the metadata associated with them can be analyzed by PowerMeta. Some interesting things commonly found in metadata are usernames, domains, software titles, and computer names.
★ 580snallygaster. Tool to scan for secret files on HTTP servers
★ 2.1kODIN. Automated network asset, email, and social media profile discovery and cataloguing.
★ 665Internal-Monologue. Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS
★ 1.7kTokenvator. A tool to elevate privilege with Windows Tokens
★ 1.1kgitleaks. Find secrets with Gitleaks 🔑
★ 28kAD-control-paths. Active Directory Control Paths auditing and graphing tools
★ 678nextnet. nextnet is a pivot point discovery tool written in Go.
★ 452idb. idb is a tool to simplify some common tasks for iOS pentesting and research
★ 956SomeStuff. Some PowerShell Stuff
★ 279Get-RBACGroupMemberReport.ps1. PowerShell script to report the membership of Exchange RBAC role groups
★ 10asatools. Main repository to pull all NCC Group Cisco ASA-related tool projects.
★ 238LAPSToolkit. Tool to audit and attack LAPS environments
★ 951ketshash. A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.
★ 169ProcessHollowing. Simple Process Hollowing in C#
★ 68pwntools. CTF framework and exploit development library
★ 14kmoistpetal. Open source offensive security platform for red team, by red team.
★ 385InsecurePowerShell. InsecurePowerShell is PowerShell with some security features removed.
★ 105al-khaser. Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
★ 7.1kmerlin. Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
★ 5.6kPSAmsi. PSAmsi is a tool for auditing and defeating AMSI signatures.
★ 398demiguise. HTA encryption tool for RedTeams
★ 1.4ksimplydomain. Subdomain brute force focused on speed and data serialization
★ 75Misc-Powershell-Scripts. Random Tools
★ 852Phant0m. Windows Event Log Killer
★ 1.8kDotNetToJScript. A tool to create a JScript file which loads a .NET v2 assembly from memory.
★ 1.3knom. Rust parser combinator framework
★ 10kInvoke-PSImage. Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute
★ 2.2kPowerShellScripts. Collection of PowerShell scripts
★ 451Invoke-Piper. Forward local or remote tcp ports through SMB pipes.
★ 295Invoke-SocksProxy. Socks proxy, and reverse socks server using powershell.
★ 810LyncSniper. LyncSniper: A tool for penetration testing Skype for Business and Lync deployments
★ 307statistically-likely-usernames. Wordlists for creating statistically likely username lists for use in password attacks and security testing. Used for pentesting for over 10 years with amazing results.
★ 1.4kSimplyEmail. Email recon made fast and easy, with a framework to build on
★ 952awesome-dotnet. A collection of awesome .NET libraries, tools, frameworks and software
★ 22kAD-Pentest-Script. Active Directory pentest scripts
★ 121PenTesting-Scripts. A ton of helpful tools
★ 345PoSh-R2. PowerShell - Rapid Response... For the incident responder in you!
★ 306Sharpire. A C# implementation of the PowerShell Empire Agent
★ 74PowerProvider. PowerShell
★ 41WheresMyImplant. A Bring Your Own Land Toolkit that Doubles as a WMI Provider
★ 289atomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.
★ 12kExternalC2. A library for integrating communication channels with the Cobalt Strike External C2 server
★ 289SharpSocks. Tunnellable HTTP/HTTPS socks4a proxy written in C# and deployable via PowerShell
★ 494peda. PEDA - Python Exploit Development Assistance for GDB
★ 6.1kRsaCtfTool. RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data
★ 7klibc-database. Build a database of libc offsets to simplify exploitation
★ 1.9kSecLists. SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
★ 72kCredDefense. Credential and Red Teaming Defense for Windows Environments
★ 330Java-Deserialization-Cheat-Sheet. The cheat sheet about Java Deserialization vulnerabilities
★ 3.2kRevoke-Obfuscation. PowerShell Obfuscation Detection Framework
★ 752RemoteRecon. Remote Recon and Collection
★ 461misc. JavaScript
★ 11PSReflect-Functions. Module to provide PowerShell functions that abstract Win32 API functions
★ 253RedTips. Red Team Tips as posted by @vysecurity on Twitter
★ 1.1kStarFighters. A JavaScript and VBScript Based Empire Launcher, which runs within their own embedded PowerShell Host.
★ 320PowerLine. C#
★ 309PowEnum. Executes common PowerSploit Powerview functions then combines output into a spreadsheet for easy analysis.
★ 71SessionGopher. SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally.
★ 1.3kInvoke-CradleCrafter. PowerShell Remote Download Cradle Generator & Obfuscator
★ 854manticore. Symbolic execution tool
★ 3.9kThreatHunter-Playbook. A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
★ 4.6kWMImplant. This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is translated into a WMI-equivalent for use on a network/remote machine. WMImplant is WMI based.
★ 861Sherlock. PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.
★ 2kHostRecon. This function runs a number of checks on a system to help provide situational awareness to a penetration tester during the reconnaissance phase. It gathers information about the local system, users, and domain information. It does not use any 'net', 'ipconfig', 'whoami', 'netstat', or other system commands to help avoid detection.
★ 465ADAudit. Windows PowerShell module to help in the auditing of Active Directory environments.
★ 51ObfuscatedEmpire. ObfuscatedEmpire is a fork of Empire with Invoke-Obfuscation integrated directly into it's functionality.
★ 232domainhunter. Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names
★ 1.7kRed-Team-Infrastructure-Wiki. Wiki to collect Red Team infrastructure hardening resources
★ 4.5kFiercePhish. FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more.
★ 1.4kASREPRoast. Project that retrieves crackable hashes from KRB5 AS-REP responses for users without kerberoast preauthentication enabled.
★ 209