Jakarta, Indonesia

Rahmat Nurfauzi

Elite
@infosecn1nja

Security Researcher/Red/Purple Teaming/Adversary Simulation/Threat Hunter. Contributors of Atomic Red Team, PS Empire, MITRE ATT&CK Framework, LOLBas, and more.

Red-Teaming-Toolkit. This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

11k

AD-Attack-Defense. Attack and defend active directory using modern post exploitation adversary tradecraft activity

4.8k

awesome-mitre-attack. A curated list of awesome resources related to Mitre ATT&CK™ Framework

621

MaliciousMacroMSBuild. Generates Malicious Macro and Execute Powershell or Shellcode via MSBuild Application Whitelisting Bypass.

508

red-team-scripts. A collection of red teaming and adversary emulation related tools, scripts, techniques, notes, etc

327

SharpDoor. SharpDoor is alternative RDPWrap written in C# to allowed multiple RDP (Remote Desktop) sessions by patching termsrv.dll file.

318

VeilTransfer. VeilTransfer is a data exfiltration utility designed to test and enhance the detection capabilities. This tool simulates real-world data exfiltration techniques used by advanced threat actors, allowing organizations to evaluate and improve their security posture.

157

ycsm. This is a quick script installation for resilient redirector using nginx reverse proxy and letsencrypt compatible with some popular Post-Ex Tools (Cobalt Strike, Empire, Metasploit, PoshC2).

87

TTPMapper. TTPMapper is an AI-driven threat intelligence parser that converts unstructured reports whether from web URLs or PDF files into structured intelligence. Using the DeepSeek LLM, it extracts MITRE ATT&CK techniques, IOCs, threat actors, and generates contextual summaries.

57

Invoke-AtomicAssessment. Invoke-AtomicAssessment is a powerful tool designed to facilitate adversary emulation by leveraging Atomic Red Team.

47

e2modrewrite. Convert Empire profiles to Apache mod_rewrite scripts

29

Red-Team-Infrastructure-Wiki. Wiki to collect Red Team infrastructure hardening resources

19

awesome-threat-detection. A curated list of awesome threat detection and hunting resources

19

awesome-threat-intelligence. A curated list of Awesome Threat Intelligence resources

18

Seatbelt. Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.

15

PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF

15

SecLists. SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

14

atomic-red-team. Small and highly portable detection tests.

13

C3. Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive toolkits.

11

DeTTECT. Detect Tactics, Techniques & Combat Threats

11

ThreatHunter-Playbook. A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.

10

infosecn1nja.

9

Empire. Empire is a PowerShell and Python post-exploitation agent.

8

HELK. The Hunting ELK

7

BloodHound. Six Degrees of Domain Admin

7

Malleable-C2-Profiles. Cobalt Strike - Malleable C2 Profiles. A collection of profiles used in different projects using Cobalt Strike https://www.cobaltstrike.com/.

7

CyberChef. The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

7

Veil. Veil 3.1.X (Check version info in Veil at runtime)

6

LOLBAS. Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

6

AggressorScripts. Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources

5

ATTACK. MITRE ATT&CK Windows Logging Cheat Sheets

5

MaliciousMacroGenerator. Malicious Macro Generator

5

domainhunter. Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

4

ThreatHunting. An informational repo about hunting for adversaries in your IT environment.

3

PoshC2_Python. Python Server for PoshC2

3

metasploit-framework. Metasploit Framework

2

sigma. Generic Signature Format for SIEM Systems

2

Rubeus. Trying to tame the three-headed dog.

2

indonesian-wordlist. Indonesian wordlist useful for password cracking

1

Egress-Assess. Egress-Assess is a tool used to test egress data detection capabilities

1

persistence-aggressor-script. initial commit

1

sliver. Adversary Emulation Framework

1
42
Apply