This is your work, valued
RedTeaming-Tactics-and-Techniques. Red Teaming Tactics and Techniques
★ 4.7kRed-Team-Infrastructure-Automation. Disposable and resilient red team infrastructure with Terraform
★ 282Invoke-PowerCloud. Deliver powershell paylods via DNS TXT via CloudFlare using PowerShell
★ 62network-playground. Network and web related exploratory playground.
★ 19RdpThief. Extracting Clear Text Passwords from mstsc.exe using API Hooking.
★ 18asm-playground. Assembler tinkering happens here. All your bytes are belong to us.
★ 12c-playground. C & Shellcode Playground..
★ 10comptia-ports. A simple script to test your knowledge on well known ports
★ 10punbup. Python unbup script for McAfee .bup files (with some additional fun features). This script is fully implemented in python it's not just another wrapper around 7zip!
★ 3threat-INTel. Archive of publicly available threat INTel reports (mostly APT Reports but not limited to).
★ 3InjectProc. InjectProc - Process Injection Techniques [This project is not maintained anymore]
★ 2token-priv. Token Privilege Research
★ 1ERC.Xdbg. An Xdbg Plugin of the ERC Library.
★ 190awesome-threat-intelligence. A curated list of Awesome Threat Intelligence resources
★ 10kpe_to_shellcode. Converts PE into a shellcode
★ 2.8kCallObfuscator. Obfuscate specific windows apis with different apis
★ 1kFarmer. C#
★ 427speakeasy. Windows kernel and user mode emulation.
★ 2kAlaris. A protective and Low Level Shellcode Loader that defeats modern EDR systems.
★ 917macro_pack. macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research.
★ 2.3kTelemetrySourcerer. Enumerate and disable common sources of telemetry used by AV/EDR.
★ 853Awesome-CobaltStrike. List of Awesome CobaltStrike Resources
★ 4.4kHackSysExtremeVulnerableDriver. HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux
★ 3kActive-Directory-Exploitation-Cheat-Sheet. A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
★ 6.7kCS-Situational-Awareness-BOF. Situational Awareness commands implemented using Beacon Object Files
★ 1.8kcs-rdll-ipc-example. Example code for using named pipe output with beacon ReflectiveDLLs
★ 118kmdf-keylogger. Keylogger driver for Windows
★ 45MemoryModule. Library to load a DLL from memory.
★ 3.2kavepoc. some pocs for antivirus evasion
★ 128weirdhta. A tool to create obfuscated HTA script.
★ 177Covenant. Covenant is a collaborative .NET C2 framework for red teamers.
★ 4.7kChecklists. Red Teaming & Pentesting checklists for various engagements
★ 2.7kDigital-Signature-Hijack. Binaries, PowerShell scripts and information about Digital Signature Hijacking.
★ 225CAPE. Malware Configuration And Payload Extraction
★ 761ReaCOM. ReaCOM has got a lot of tools to use and is related to component object model
★ 73injection. C++
★ 830SharpGPOAbuse. SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.
★ 1.3kEvilClippy. A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows.
★ 2.2kLethalHTA. Lateral Movement technique using DCOM and HTA
★ 233avet. AntiVirus Evasion Tool
★ 1.8kRed-Baron. Automate creating resilient, disposable, secure and agile infrastructure for Red Teams
★ 386Awesome-Red-Teaming. List of Awesome Red Teaming Resources
★ 8kDomainCheck. DomainCheck is designed to assist operators with monitoring changes related to their domain names. This includes negative changes in categorization, VirusTotal detections, and appearances on malware blacklists. DomainCheck currently works only with NameCheap.
★ 247AggressorCollection. Collection of awesome Cobalt Strike Aggressor Scripts. All credit due to the authors
★ 152ExploitCapcom. This is a standalone exploit for a vulnerable feature in Capcom.sys
★ 341token-priv. Token Privilege Research
★ 886atomic-threat-coverage. Actionable analytics designed to combat threats
★ 1kShellcodeLoader. Small tool to load shellcodes or PEs to analyze them
★ 4ZeusInjector. An Open Source Windows DLL Injector With All Known Techniques Available
★ 89AD-Attack-Defense. Attack and defend active directory using modern post exploitation adversary tradecraft activity
★ 4.8kawesome-burp-extensions. A curated list of amazingly awesome Burp Extensions
★ 3.4kdns-exe-persistance. C++
★ 46awesome-pentest. A collection of awesome penetration testing resources, tools and other shiny things
★ 27kawesome-windows-security. List of Awesome Windows Security Resources
★ 317SQLInjectionWiki. A wiki focusing on aggregating and documenting various SQL injection methods
★ 795Awesome-Red-Teaming. List of Awesome Red Teaming Resources
★ 3RedELK. Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.
★ 2.7kja3. JA3 is a standard for creating SSL client fingerprints in an easy to produce and shareable way.
★ 3.1kcensys-subdomain-finder. ⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.
★ 840red_team_telemetry. Python
★ 98fuxploider. File upload vulnerability scanner and exploitation tool.
★ 3.3kgef. GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux
★ 8.3kcreddump. Automatically exported from code.google.com/p/creddump
★ 284DoHC2. DoHC2 allows the ExternalC2 library from Ryan Hanson (https://github.com/ryhanson/ExternalC2) to be leveraged for command and control (C2) via DNS over HTTPS (DoH).
★ 449SharpSploit. SharpSploit is a .NET post-exploitation library written in C#
★ 1.9kInternal-Monologue. Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS
★ 1.7kMailSniper. MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
★ 3.3kphishery. An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector
★ 1kluckystrike. A PowerShell based utility for the creation of malicious Office macro documents.
★ 1.1kranger. A tool for security professionals to access and interact with remote Microsoft Windows based systems.
★ 431PSSysmonTools. Sysmon Tools for PowerShell
★ 233Seatbelt. Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
★ 4.6kPentest-and-Development-Tips. A collection of pentest and development tips
★ 1.1kPenetration-Testing-Tools. A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.
★ 3kShellkiller. A killer reverse-shell script that is able to use a lot of techniques to ensure your shell will pop back to you.
★ 30ShellPop. Pop shells like a master.
★ 1.5kRed-Teaming-Toolkit. This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
★ 11kredsnarf. RedSnarf is a pen-testing / red-teaming tool for Windows environments
★ 1.2kRed-Baron. Automate creating resilient, disposable, secure and agile infrastructure for Red Teams.
★ 924Red-Teaming-Toolkit. A collection of open source and commercial tools that aid in red team operations.
★ 2Injectors. 💉 DLL/Shellcode injection techniques
★ 714nishang. Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
★ 10kLOLBAS. Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
★ 1.6kptf. The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
★ 5.5kCyberThreatHunting. A collection of resources for Threat Hunters
★ 916WinPwnage. UAC bypass, Elevate, Persistence methods
★ 2.8klpeworkshop. Windows / Linux Local Privilege Escalation Workshop
★ 1kephemera-miscellany. Ephemera and other documentation associated with the 1337list project.
★ 396Infosec_Reference. An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
★ 6katomic-red-team. Small and highly portable detection tests based on MITRE's ATT&CK.
★ 12kGTFOBins.github.io. GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
★ 14kDARKSURGEON. DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.
★ 469Red-Team-Infrastructure-Wiki. Wiki to collect Red Team infrastructure hardening resources
★ 4.5kawesome-ctf. A curated list of CTF frameworks, libraries, resources and softwares
★ 12kRedHunt-OS. Virtual Machine for Adversary Emulation and Threat Hunting
★ 1.3kpyrebox. Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU
★ 1.7kPayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
★ 80kUsnJrnl2Csv. Parser for $UsnJrnl on NTFS
★ 125ViperMonkey. A VBA parser and emulation engine to analyze malicious macros.
★ 1.1kSherlock. PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.
★ 2kPoshC2_Old. Powershell C2 Server and Implants
★ 574aktaion. Aktaion: Open Source ML tool and data samples for Exploit and Phishing Research
★ 144DET. (extensible) Data Exfiltration Toolkit (DET)
★ 821uac-a-mola. Python
★ 107ACE. Automated, Collection, and Enrichment Platform
★ 325InjectProc. InjectProc - Process Injection Techniques [This project is not maintained anymore]
★ 993awesome-incident-response. A curated list of tools for incident response
★ 9.3kdemos. Demos of various injection techniques found in malware
★ 787asm. Learning assembly for Linux x86_64
★ 3.6kEmpire. Empire is a PowerShell and Python post-exploitation agent.
★ 7.9kimpacket. Impacket is a collection of Python classes for working with network protocols.
★ 16kpysap. pysap is an open source Python library that provides modules for crafting and sending packets using SAP's NI, Diag, Enqueue, Router, MS, SNC, IGS, RFC and HDB protocols.
★ 252SwipeMenuListView. [DEPRECATED] A swipe menu for ListView.
★ 3.5kokhttp. A meticulous HTTP client for the JVM, Android, and GraalVM.
★ 47kAXStretchableHeaderTabViewController. Stretchable header view + Horizontal swipable tab view
★ 284AHKActionSheet. An alternative to the UIActionSheet inspired by the Spotify app.
★ 1.1kC-41. C-41 is an application to help people develop film at home by providing a series of "recipes" for photographers to use.
★ 2kissue-1-lighter-view-controllers. Example project for the 1st issue of objc.io
★ 730MVCNetworking. MVCNetworking is a sample that shows how to create a network application using the Model-View-Controller design pattern. Specifically, it displays a photo gallery by getting the gallery's XML description, thumbnails and photos from a web server, and uses Core Data to cache this information locally.
★ 12Coffee-Shop-MVC. companion Xcode project for the MVC episode of my iOS design patterns blog series
★ 4MGSwipeTableCell. An easy to use UITableViewCell subclass that allows to display swippable buttons with a variety of transitions.
★ 6.9kSWTableViewCell. An easy-to-use UITableViewCell subclass that implements a swippable content view which exposes utility buttons (similar to iOS 7 Mail Application)
★ 7.1kMCSwipeTableViewCell. :point_up_2: Convenient UITableViewCell subclass that implements a swippable content to trigger actions (similar to the Mailbox app).
★ 2.9kMGSwipeTabBarController. Simple swipe tab bar controller for iOS
★ 84SwipeView. SwipeView is a class designed to simplify the implementation of horizontal, paged scrolling views on iOS. It is based on a UIScrollView, but adds convenient functionality such as a UITableView-style dataSource/delegate interface for loading views dynamically, and efficient view loading, unloading and recycling.
★ 2.6kios. iPhone app
★ 189