This is your work, valued
Mostly Red Team tools for penetration testing. My learning platform links: https://truecyber.world https://mr.un1k0d3r.world
EDRs. C
2.2kSCShell. Fileless lateral movement tool that relies on ChangeServiceConfigA to run command
1.6kPowerLessShell. Run PowerShell command without invoking powershell.exe
1.6kDKMC. DKMC - Dont kill my cat - Malicious payload evasion tool
1.4kRedTeamPowershellScripts. Various PowerShell scripts that may be useful during red team exercise
963MaliciousMacroGenerator. Malicious Macro Generator
831ThunderShell. Python / C# Unmanaged PowerShell based RAT
772RedTeamCSharpScripts. C# Script used for Red Team
717RedTeamCCode. Red Team C code repo
574CatMyPhish. Search for categorized domain
463.NetConfigLoader. .net config loader
355PoisonHandler. lateral movement techniques that can be used during red team exercises
278MaliciousClickOnceGenerator. Quick Malicious ClickOnceGenerator for Red Team
274Windows-SignedBinary. Python
259AMSI-ETW-Patch. Patch AMSI and ETW
251ADHuntTool. official repo for the AdHuntTool (part of the old RedTeamCSharpScripts repo)
234Shellcoding. Shellcoding utilities
225WindowsDllsExport. A list of all the DLLs export in C:\windows\system32\
220ATP-PowerShell-Scripts. Microsoft Signed PowerShell scripts
218Cookie-and-Handle-Stealer. C or BOF file to extract WebKit master key to decrypt user cookie
210DLLsForHackers. Dll that can be used for side loading and other attack vector.
206Elevate-System-Trusted-BOF. C
181AzureRedOps. Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID
178MaliciousDLLGenerator. DLL Generator for side loading attack
176DotnetNoVirtualProtectShellcodeLoader. load shellcode without P/D Invoke and VirtualProtect call.
172RedTeamScripts. Repo with various Red Team scripts
148SCT-obfuscator. Cobalt Strike SCT payload obfuscator
144SPFAbuse. SPF are not as strong as you may think. Red Team tool to send email on behalf of your target corp
143RemoteProcessInjection. C# remote process injection utility for Cobalt Strike
88Base64-Obfuscator. Simple PowerShell Base64 encoder to avoid detection of your malicious payload
81SearchIPOwner. Search public IP owner through ARIN
64MsGraphFunzy. Scripts to interact with Microsoft Graph APIs
46BOFCode. Bunch of BOF files
45pentest-tools. Custom pentesting tools
26SideChannelAttack. Side Channel script
25LOLBAS. Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
12blog.mr.un1k0d3r.com. Mr.Un1k0d3r.com blog
10CVE-2021-1675. C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
8PPLDump_BOF. A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.
5openedr. Open EDR public repository
5PowerSploit. PowerSploit - A PowerShell Post-Exploitation Framework
5CVE-2020-1472. Test tool for CVE-2020-1472
3impacket. Impacket is a collection of Python classes for working with network protocols.
3