This is your work, valued
Security Researcher/Red/Purple Teaming/Adversary Simulation/Threat Hunter. Contributors of Atomic Red Team, PS Empire, MITRE ATT&CK Framework, LOLBas, and more.
Red-Teaming-Toolkit. This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
11kAD-Attack-Defense. Attack and defend active directory using modern post exploitation adversary tradecraft activity
4.8kawesome-mitre-attack. A curated list of awesome resources related to Mitre ATT&CK™ Framework
621MaliciousMacroMSBuild. Generates Malicious Macro and Execute Powershell or Shellcode via MSBuild Application Whitelisting Bypass.
507red-team-scripts. A collection of red teaming and adversary emulation related tools, scripts, techniques, notes, etc
327SharpDoor. SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file.
318VeilTransfer. VeilTransfer is a data exfiltration utility designed to test and enhance the detection capabilities. This tool simulates real-world data exfiltration techniques used by advanced threat actors, allowing organizations to evaluate and improve their security posture.
157ycsm. This is a quick script installation for resilient redirector using nginx reverse proxy and letsencrypt compatible with some popular Post-Ex Tools (Cobalt Strike, Empire, Metasploit, PoshC2).
87TTPMapper. TTPMapper is an AI-driven threat intelligence parser that converts unstructured reports whether from web URLs or PDF files into structured intelligence. Using the DeepSeek LLM, it extracts MITRE ATT&CK techniques, IOCs, threat actors, and generates contextual summaries.
57Invoke-AtomicAssessment. Invoke-AtomicAssessment is a powerful tool designed to facilitate adversary emulation by leveraging Atomic Red Team.
47e2modrewrite. Convert Empire profiles to Apache mod_rewrite scripts
29Red-Team-Infrastructure-Wiki. Wiki to collect Red Team infrastructure hardening resources
19awesome-threat-detection. A curated list of awesome threat detection and hunting resources
19awesome-threat-intelligence. A curated list of Awesome Threat Intelligence resources
18Seatbelt. Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
15PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
15SecLists. SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
14atomic-red-team. Small and highly portable detection tests.
13C3. Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive toolkits.
11DeTTECT. Detect Tactics, Techniques & Combat Threats
11ThreatHunter-Playbook. A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.
10infosecn1nja.
9Empire. Empire is a PowerShell and Python post-exploitation agent.
8HELK. The Hunting ELK
7BloodHound. Six Degrees of Domain Admin
7Malleable-C2-Profiles. Cobalt Strike - Malleable C2 Profiles. A collection of profiles used in different projects using Cobalt Strike https://www.cobaltstrike.com/.
7CyberChef. The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
7Veil. Veil 3.1.X (Check version info in Veil at runtime)
6LOLBAS. Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
6AggressorScripts. Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources
5ATTACK. MITRE ATT&CK Windows Logging Cheat Sheets
5MaliciousMacroGenerator. Malicious Macro Generator
5domainhunter. Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names
4ThreatHunting. An informational repo about hunting for adversaries in your IT environment.
3PoshC2_Python. Python Server for PoshC2
3metasploit-framework. Metasploit Framework
2sigma. Generic Signature Format for SIEM Systems
2Rubeus. Trying to tame the three-headed dog.
2indonesian-wordlist. Indonesian wordlist useful for password cracking
1Egress-Assess. Egress-Assess is a tool used to test egress data detection capabilities
1persistence-aggressor-script. initial commit
1sliver. Adversary Emulation Framework
1