Red Teaming Toolkit

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
Alternatives To Red Teaming Toolkit
Project NameStarsDownloadsRepos Using ThisPackages Using ThisMost Recent CommitTotal ReleasesLatest ReleaseOpen IssuesLicenseLanguage
Awesome Hacking69,405
2 months ago27cc0-1.0
A collection of various awesome lists for hackers, pentesters and security researchers
6 days ago20mitPython
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
2 days ago4mitJupyter Notebook
This repository is primarily maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking / penetration testing, digital forensics and incident response (DFIR), artificial intelligence, vulnerability research, exploit development, reverse engineering, and more.
13 days ago50June 06, 202163mitPython
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
Awesome Hacking Resources13,406
a year ago11gpl-3.0
A collection of hacking / penetration testing resources to make you better!
Hacker Roadmap11,121
a year ago3mit
A collection of hacking tools, resources and references to practice ethical hacking.
a month ago18November 07, 2022128gpl-3.0Rust
🤖 The Modern Port Scanner 🤖
Owasp Mastg10,700
13 hours ago123cc-by-sa-4.0Python
The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
18 days ago147mitPython
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
3 days ago8October 03, 202257Python
Web path scanner
Alternatives To Red Teaming Toolkit
Select To Compare

Alternative Project Comparisons

Red Teaming Toolkit

This repository contains cutting-edge open-source security tools (OST) that will help you during adversary simulation and as information intended for threat hunter can make detection and prevention control easier. The list of tools below that could be potentially misused by threat actors such as APT and Human-Operated Ransomware (HumOR). If you want to contribute to this list send me a pull request.

Table of Contents


Name Description URL
RustScan The Modern Port Scanner. Find ports quickly (3 seconds at its fastest). Run scripts through our scripting engine (Python, Lua, Shell supported). RustScan/RustScan
Amass In-depth Attack Surface Mapping and Asset Discovery OWASP/Amass
gitleaks Gitleaks is a SAST tool for detecting hardcoded secrets like passwords, api keys, and tokens in git repos. zricethezav/gitleaks
S3Scanner Scan for open S3 buckets and dump the contents sa7mon/S3Scanner
cloud_enum Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud. initstring/cloud_enum
Recon-ng Open Source Intelligence gathering tool aimed at reducing the time spent harvesting information from open sources. lanmaster53/recon-ng
buster An advanced tool for email reconnaissance sham00n/buster
linkedin2username OSINT Tool: Generate username lists for companies on LinkedIn initstring/linkedin2username
WitnessMe Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier. byt3bl33d3r/WitnessMe
pagodo pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching opsdisk/pagodo
AttackSurfaceMapper AttackSurfaceMapper is a tool that aims to automate the reconnaissance process. superhedgy/AttackSurfaceMapper
SpiderFoot SpiderFoot is an open source intelligence (OSINT) automation tool. It integrates with just about every data source available and utilises a range of methods for data analysis, making that data easy to navigate. smicallef/spiderfoot
dnscan dnscan is a python wordlist-based DNS subdomain scanner. rbsec/dnscan
spoofcheck A program that checks if a domain can be spoofed from. The program checks SPF and DMARC records for weak configurations that allow spoofing. BishopFox/spoofcheck
LinkedInt LinkedIn Recon Tool vysecurity/LinkedInt

Initial Access

Brute Force

Name Description URL
SprayingToolkit Scripts to make password spraying attacks against Lync/S4B, OWA & O365 a lot quicker, less painful and more efficient byt3bl33d3r/SprayingToolkit
o365recon Retrieve information via O365 with a valid cred nyxgeek/o365recon
CredMaster Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling knavesec/CredMaster

Payload Development

Name Description URL
Ivy Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. optiv/Ivy
PEzor Open-Source PE Packer phra/PEzor
GadgetToJScript A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA scripts. med0x2e/GadgetToJScript
ScareCrow Payload creation framework designed around EDR bypass. optiv/ScareCrow
Donut Donut is a position-independent code that enables in-memory execution of VBScript, JScript, EXE, DLL files and dotNET assemblies. TheWover/donut
Mystikal macOS Initial Access Payload Generator D00MFist/Mystikal
charlotte c++ fully undetected shellcode launcher ;) 9emin1/charlotte
InvisibilityCloak Proof-of-concept obfuscation toolkit for C# post-exploitation tools. This will perform the below actions for a C# visual studio project. xforcered/InvisibilityCloak
Dendrobate Dendrobate is a framework that facilitates the development of payloads that hook unmanaged code through managed .NET code. FuzzySecurity/Dendrobate
Offensive VBA and XLS Entanglement This repo provides examples of how VBA can be used for offensive purposes beyond a simple dropper or shell injector. As we develop more use cases, the repo will be updated. BC-SECURITY/Offensive-VBA-and-XLS-Entanglement
xlsGen Tiny Excel BIFF8 Generator, to Embedded 4.0 Macros in *.xls aaaddress1/xlsGen
darkarmour Windows AV Evasion bats3c/darkarmour
InlineWhispers Tool for working with Direct System Calls in Cobalt Strike's Beacon Object Files (BOF) outflanknl/InlineWhispers
EvilClippy A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows. outflanknl/EvilClippy
OfficePurge VBA purge your Office documents with OfficePurge. VBA purging removes P-code from module streams within Office documents. fireeye/OfficePurge
ThreatCheck Identifies the bytes that Microsoft Defender / AMSI Consumer flags on. rasta-mouse/ThreatCheck
CrossC2 Generate CobaltStrike's cross-platform payload gloxec/CrossC2
Ruler Ruler is a tool that allows you to interact with Exchange servers remotely, through either the MAPI/HTTP or RPC/HTTP protocol. sensepost/ruler
DueDLLigence Shellcode runner framework for application whitelisting bypasses and DLL side-loading. The shellcode included in this project spawns calc.exe. fireeye/DueDLLigence
RuralBishop RuralBishop is practically a carbon copy of UrbanBishop by b33f, but all P/Invoke calls have been replaced with D/Invoke. rasta-mouse/RuralBishop
TikiTorch TikiTorch was named in homage to CACTUSTORCH by Vincent Yiu. The basic concept of CACTUSTORCH is that it spawns a new process, allocates a region of memory, then uses CreateRemoteThread to run the desired shellcode within that target process. Both the process and shellcode are specified by the user. rasta-mouse/TikiTorch
SharpShooter SharpShooter is a payload creation framework for the retrieval and execution of arbitrary CSharp source code. SharpShooter is capable of creating payloads in a variety of formats, including HTA, JS, VBS and WSF. mdsecactivebreach/SharpShooter
SharpSploit SharpSploit is a .NET post-exploitation library written in C# cobbr/SharpSploit
MSBuildAPICaller MSBuild Without MSBuild.exe rvrsh3ll/MSBuildAPICaller
macro_pack macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of MS Office documents, VB scripts, and other formats for pentest, demo, and social engineering assessments. sevagas/macro_pack
inceptor Template-Driven AV/EDR Evasion Framework klezVirus/inceptor
mortar evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR) 0xsp-SRD/mortar
ProtectMyTooling Multi-Packer wrapper letting us daisy-chain various packers, obfuscators and other Red Team oriented weaponry. Featured with artifacts watermarking, IOCs collection & PE Backdooring. You feed it with your implant, it does a lot of sneaky things and spits out obfuscated executable. mgeeky/ProtectMyTooling
Freeze Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods optiv/Freeze



Name Description URL
o365-attack-toolkit A toolkit to attack Office365 mdsecactivebreach/o365-attack-toolkit
Evilginx2 Evilginx2 is a man-in-the-middle attack framework used for phishing credentials and session cookies of any web service. kgretzky/evilginx2
Gophish Gophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training. gophish/gophish
PwnAuth PwnAuth a web application framework for launching and managing OAuth abuse campaigns. fireeye/PwnAuth
Modlishka Modlishka is a flexible and powerful reverse proxy, that will take your ethical phishing campaigns to the next level. drk1wi/Modlishka

Watering Hole Attack

Name Description URL
BeEF BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser beefproject/beef

Command and Control

Remote Access Tools (RAT)

Name Description URL
Cobalt Strike Cobalt Strike is software for Adversary Simulations and Red Team Operations.
Brute Ratel C4 Brute Ratel is the most advanced Red Team & Adversary Simulation Software in the current C2 Market.
Empire Empire 5 is a post-exploitation framework that includes a pure-PowerShell Windows agent, and compatibility with Python 3.x Linux/OS X agents. BC-SECURITY/Empire
PoshC2 PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement. nettitude/PoshC2
Koadic Koadic C3 COM Command & Control - JScript RAT zerosum0x0/koadic
merlin Merlin is a cross-platform post-exploitation Command & Control server and agent written in Go. Ne0nd0g/merlin
Mythic A cross-platform, post-exploit, red teaming framework built with python3, docker, docker-compose, and a web browser UI. its-a-feature/Mythic
Covenant Covenant is a .NET command and control framework that aims to highlight the attack surface of .NET, make the use of offensive .NET tradecraft easier, and serve as a collaborative command and control platform for red teamers. cobbr/Covenant
shad0w A post exploitation framework designed to operate covertly on heavily monitored environments bats3c/shad0w
Sliver Sliver is a general purpose cross-platform implant framework that supports C2 over Mutual-TLS, HTTP(S), and DNS. BishopFox/sliver
SILENTTRINITY An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR byt3bl33d3r/SILENTTRINITY
Pupy Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python n1nj4sec/pupy
Havoc Havoc is a modern and malleable post-exploitation command and control framework, created by @C5pider. HavocFramework/Havoc
NimPlant A light first-stage C2 implant written in Nim and Python chvancooten/NimPlant
SharpC2 SharpC2 is a Command & Control (C2) framework written in C#. It consists of an ASP.NET Core Team Server, a .NET Framework implant, and a .NET MAUI client. rasta-mouse/SharpC2


Name Description URL
pwndrop Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV. kgretzky/pwndrop
C2concealer A command line tool that generates randomized C2 malleable profiles for use in Cobalt Strike. FortyNorthSecurity/C2concealer
FindFrontableDomains Search for potential frontable domains rvrsh3ll/FindFrontableDomains
Domain Hunter Checks expired domains for categorization/reputation and history to determine good candidates for phishing and C2 domain names threatexpress/domainhunter
RedWarden Flexible CobaltStrike Malleable Redirector mgeeky/RedWarden
AzureC2Relay AzureC2Relay is an Azure Function that validates and relays Cobalt Strike beacon traffic by verifying the incoming requests based on a Cobalt Strike Malleable C2 profile. Flangvik/AzureC2Relay
C3 C3 (Custom Command and Control) is a tool that allows Red Teams to rapidly develop and utilise esoteric command and control channels (C2). FSecureLABS/C3
Chameleon A tool for evading Proxy categorisation mdsecactivebreach/Chameleon
Cobalt Strike Malleable C2 Design and Reference Guide Cobalt Strike Malleable C2 Design and Reference Guide
redirect.rules Quick and dirty dynamic redirect.rules generator
CobaltBus Cobalt Strike External C2 Integration With Azure Servicebus, C2 traffic via Azure Servicebus Flangvik/CobaltBus
SourcePoint SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion. Tylous/SourcePoint
RedGuard RedGuard is a C2 front flow control tool,Can avoid Blue Teams,AVs,EDRs check. wikiZ/RedGuard
skyhook A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections. blackhillsinfosec/skyhook

Log Aggregation

Name Description URL
RedELK Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations. outflanknl/RedELK
Elastic for Red Teaming Repository of resources for configuring a Red Team SIEM using Elastic. SecurityRiskAdvisors/RedTeamSIEM
RedEye RedEye is a visual analytic tool supporting Red & Blue Team operations cisagov/RedEye

Situational Awareness

Host Situational Awareness

Name Description URL
AggressiveProxy AggressiveProxy is a combination of a .NET 3.5 binary (LetMeOutSharp) and a Cobalt Strike aggressor script (AggressiveProxy.cna). Once LetMeOutSharp is executed on a workstation, it will try to enumerate all available proxy configurations and try to communicate with the Cobalt Strike server over HTTP(s) using the identified proxy configurations. EncodeGroup/AggressiveProxy
Gopher C# tool to discover low hanging fruits EncodeGroup/Gopher
SharpEDRChecker Checks running processes, process metadata, Dlls loaded into your current process and the each DLLs metadata, common install directories, installed services and each service binaries metadata, installed drivers and each drivers metadata, all for the presence of known defensive products such as AV's, EDR's and logging tools. PwnDexter/SharpEDRChecker
Situational Awareness BOF This Repo intends to serve two purposes. First it provides a nice set of basic situational awareness commands implemented in BOF. trustedsec/CS-Situational-Awareness-BOF
Seatbelt Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives. GhostPack/Seatbelt
SauronEye SauronEye is a search tool built to aid red teams in finding files containing specific keywords. vivami/SauronEye
SharpShares Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain mitchmoser/SharpShares
SharpAppLocker C# port of the Get-AppLockerPolicy PowerShell cmdlet with extended features. Includes the ability to filter and search for a specific type of rules and actions.
SharpPrinter Printer is a modified and console version of ListNetworks rvrsh3ll/SharpPrinter

Domain Situational Awareness

Name Description URL
StandIn StandIn is a small AD post-compromise toolkit. StandIn came about because recently at xforcered we needed a .NET native solution to perform resource based constrained delegation. FuzzySecurity/StandIn
Recon-AD An AD recon tool based on ADSI and reflective DLL’s outflanknl/Recon-AD
BloodHound Six Degrees of Domain Admin BloodHoundAD/BloodHound
PSPKIAudit PowerShell toolkit for auditing Active Directory Certificate Services (AD CS). GhostPack/PSPKIAudit
SharpView C# implementation of harmj0y's PowerView tevora-threat/SharpView
Rubeus Rubeus is a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpy's Kekeo project (CC BY-NC-SA 4.0 license) and Vincent LE TOUX's MakeMeEnterpriseAdmin project (GPL v3.0 license). GhostPack/Rubeus
nanorobeus A minimalistic tool for managing Kerberos tickets. Supports redteam frameworks wavvs/nanorobeus
Grouper A PowerShell script for helping to find vulnerable settings in AD Group Policy. (deprecated, use Grouper2 instead!) l0ss/Grouper
ImproHound Identify the attack paths in BloodHound breaking your AD tiering improsec/ImproHound
ADRecon ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. adrecon/ADRecon
ADCSPwn A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts (Petitpotam) and relaying to the certificate service. bats3c/ADCSPwn

Credential Dumping

Name Description URL
Mimikatz Mimikatz is an open-source application that allows users to view and save authentication credentials like Kerberos tickets. gentilkiwi/mimikatz
Dumpert LSASS memory dumper using direct system calls and API unhooking. outflanknl/Dumpert
CredBandit CredBandit is a proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that back through your already existing Beacon communication channel. xforcered/CredBandit
CloneVault CloneVault allows a red team operator to export and import entries including attributes from Windows Credential Manager. mdsecactivebreach/CloneVault
SharpLAPS Retrieve LAPS password from LDAP swisskyrepo/SharpLAPS
SharpDPAPI SharpDPAPI is a C# port of some DPAPI functionality from @gentilkiwi's Mimikatz project. GhostPack/SharpDPAPI
KeeThief Allows for the extraction of KeePass 2.X key material from memory, as well as the backdooring and enumeration of the KeePass trigger system. GhostPack/KeeThief
SafetyKatz SafetyKatz is a combination of slightly modified version of @gentilkiwi's Mimikatz project and @subtee's .NET PE Loader. GhostPack/SafetyKatz
forkatz credential dump using forshaw technique using SeTrustedCredmanAccessPrivilege Barbarisch/forkatz
PPLKiller Tool to bypass LSA Protection (aka Protected Process Light) RedCursorSecurityConsulting/PPLKiller
LaZagne The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. AlessandroZ/LaZagne
AndrewSpecial AndrewSpecial, dumping lsass' memory stealthily and bypassing "Cilence" since 2019. hoangprod/AndrewSpecial
Net-GPPPassword .NET implementation of Get-GPPPassword. Retrieves the plaintext password and other information for accounts pushed through Group Policy Preferences. outflanknl/Net-GPPPassword
SharpChromium .NET 4.0 CLR Project to retrieve Chromium data, such as cookies, history and saved logins. djhohnstein/SharpChromium
Chlonium Chlonium is an application designed for cloning Chromium Cookies. rxwx/chlonium
SharpCloud SharpCloud is a simple C# utility for checking for the existence of credential files related to Amazon Web Services, Microsoft Azure, and Google Compute. chrismaddalena/SharpCloud
pypykatz Mimikatz implementation in pure Python. At least a part of it :) skelsec/pypykatz
nanodump A Beacon Object File that creates a minidump of the LSASS process. helpsystems/nanodump
Koh Koh is a C# and Beacon Object File (BOF) toolset that allows for the capture of user credential material via purposeful token/logon session leakage. GhostPack/Koh

Privilege Escalation

Name Description URL
ElevateKit The Elevate Kit demonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload. rsmudge/ElevateKit
Watson Watson is a .NET tool designed to enumerate missing KBs and suggest exploits for Privilege Escalation vulnerabilities. rasta-mouse/Watson
SharpUp SharpUp is a C# port of various PowerUp functionality. Currently, only the most common checks have been ported; no weaponization functions have yet been implemented. GhostPack/SharpUp
dazzleUP A tool that detects the privilege escalation vulnerabilities caused by misconfigurations and missing updates in the Windows operating systems. dazzleUP detects the following vulnerabilities. hlldz/dazzleUP
PEASS Privilege Escalation Awesome Scripts SUITE (with colors) carlospolop/PEASS-ng
SweetPotato A collection of various native Windows privilege escalation techniques from service accounts to SYSTEM CCob/SweetPotato
MultiPotato Another Potato to get SYSTEM via SeImpersonate privileges S3cur3Th1sSh1t/MultiPotato
KrbRelayUp a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings). Dec0ne/KrbRelayUp
GodPotato As Long as You Have the ImpersonatePrivilege Permission, Then You are the SYSTEM! BeichenDream/GodPotato

Defense Evasion

Name Description URL
RefleXXion RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. hlldz/RefleXXion
EDRSandBlast EDRSandBlast is a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections (Kernel callbacks and ETW TI provider) and LSASS protections. wavestone-cdt/EDRSandblast
unDefender Killing your preferred antimalware by abusing native symbolic links and NT paths. APTortellini/unDefender
Backstab A tool to kill antimalware protected processes Yaxser/Backstab
SPAWN - Cobalt Strike BOF Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning sacrificial process with Arbitrary Code Guard (ACG), BlockDll, and PPID spoofing. boku7/spawn
BOF.NET - A .NET Runtime for Cobalt Strike's Beacon Object Files BOF.NET is a small native BOF object combined with the BOF.NET managed runtime that enables the development of Cobalt Strike BOFs directly in .NET. BOF.NET removes the complexity of native compilation along with the headaches of manually importing native API.
NetLoader Loads any C# binary from filepath or url, patching AMSI and bypassing Windows Defender on runtime Flangvik/NetLoader
FindObjects-BOF A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific modules or process handles. outflanknl/FindObjects-BOF
SharpUnhooker C# Based Universal API Unhooker - Automatically Unhook API Hives (ntdll.dll,kernel32.dll,user32.dll,advapi32.dll,and kernelbase.dll). GetRektBoy724/SharpUnhooker
EvtMute Apply a filter to the events being reported by windows event logging bats3c/EvtMute
InlineExecute-Assembly InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional fork and run execute-assembly module xforcered/InlineExecute-Assembly
Phant0m Windows Event Log Killer hlldz/Phant0m
SharpBlock A method of bypassing EDR's active projection DLL's by preventing entry point execution. CCob/SharpBlock
NtdllUnpatcher Example code for EDR bypassing, please use this for testing blue team detection capabilities against this type of malware that will bypass EDR's userland hooks. Kharos102/NtdllUnpatcher
DarkLoadLibrary LoadLibrary for offensive operations. bats3c/DarkLoadLibrary
BlockETW .Net 3.5 / 4.5 Assembly to block ETW telemetry in a process Soledge/BlockEtw
firewalker This repo contains a simple library which can be used to add FireWalker hook bypass capabilities to existing code mdsecactivebreach/firewalker
KillDefenderBOF Beacon Object File PoC implementation of KillDefender Cerbersec/KillDefenderBOF
Mangle Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs optiv/Mangle
AceLdr Cobalt Strike UDRL for memory scanner evasion. kyleavery/AceLdr
AtomLdr CA DLL loader with advanced evasive features NUL0x4C/AtomLdr
Inline-Execute-PE Execute unmanaged Windows executables in CobaltStrike Beacons Octoberfest7/Inline-Execute-PE
SigFlip SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature. med0x2e/SigFlip
Blackout kill anti-malware protected processes (BYOVD) ZeroMemoryEx/Blackout


Name Description URL
SharpStay .NET project for installing Persistence 0xthirteen/SharpStay
SharPersist Windows persistence toolkit written in C#. fireeye/SharPersist
SharpHide Tool to create hidden registry keys. outflanknl/SharpHide
DoUCMe This leverages the NetUserAdd Win32 API to create a new computer account. This is done by setting the usri1_priv of the USER_INFO_1 type to 0x1000. Ben0xA/DoUCMe
A Black Path Toward The Sun (TCP tunneling over HTTP for web application servers) nccgroup/ABPTTS
pivotnacci A tool to make socks connections through HTTP agents blackarrowsec/pivotnacci
reGeorg The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn. sensepost/reGeorg
DAMP The Discretionary ACL Modification Project: Persistence Through Host-based Security Descriptor Modification. HarmJ0y/DAMP
IIS-Raid A native backdoor module for Microsoft IIS (Internet Information Services) 0x09AL/IIS-Raid
SharPyShell tiny and obfuscated ASP.NET webshell for C# web applications antonioCoco/SharPyShell
ScheduleRunner A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation netero1010/ScheduleRunner
SharpEventPersist Persistence by writing/reading shellcode from Event Log improsec/SharpEventPersist
Kraken Kraken, a modular multi-language webshell coded by @secu_x11. kraken-ng/Kraken
HiddenDesktop HVNC for Cobalt Strike WKL-Sec/HiddenDesktop

Lateral Movement

Name Description URL
Liquid Snake LiquidSnake is a tool that allows operators to perform fileless lateral movement using WMI Event Subscriptions and GadgetToJScript RiccardoAncarani/LiquidSnake
PowerUpSQL A PowerShell Toolkit for Attacking SQL Server NetSPI/PowerUpSQL
SQLRecon A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation. skahwah/SQLRecon
SCShell Fileless lateral movement tool that relies on ChangeServiceConfigA to run command Mr-Un1k0d3r/SCShell
SharpRDP Remote Desktop Protocol Console Application for Authenticated Command Execution 0xthirteen/SharpRDP
MoveKit Movekit is an extension of built in Cobalt Strike lateral movement by leveraging the execute_assembly function with the SharpMove and SharpRDP .NET assemblies. 0xthirteen/MoveKit
SharpNoPSExec File less command execution for lateral movement. juliourena/SharpNoPSExec
Responder/MultiRelay LLMNR/NBT-NS/mDNS Poisoner and NTLMv1/2 Relay. lgandx/Responder
impacket Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself. SecureAuthCorp/impacket
Farmer Farmer is a project for collecting NetNTLM hashes in a Windows domain. mdsecactivebreach/Farmer
CIMplant C# port of WMImplant which uses either CIM or WMI to query remote systems. It can use provided credentials or the current user's session. FortyNorthSecurity/CIMplant
PowerLessShell PowerLessShell rely on MSBuild.exe to remotely execute PowerShell scripts and commands without spawning powershell.exe. You can also execute raw shellcode using the same approach. Mr-Un1k0d3r/PowerLessShell
SharpGPOAbuse SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO. FSecureLABS/SharpGPOAbuse
kerbrute A tool to quickly bruteforce and enumerate valid Active Directory accounts through Kerberos Pre-Authentication ropnop/kerbrute
mssqlproxy mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse blackarrowsec/mssqlproxy
Invoke-TheHash PowerShell Pass The Hash Utils Kevin-Robertson/Invoke-TheHash
InveighZero .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers Kevin-Robertson/InveighZero
SharpSpray SharpSpray a simple code set to perform a password spraying attack against all users of a domain using LDAP and is compatible with Cobalt Strike. jnqpblc/SharpSpray
CrackMapExec A swiss army knife for pentesting networks byt3bl33d3r/CrackMapExec
SharpAllowedToAct A C# implementation of a computer object takeover through Resource-Based Constrained Delegation (msDS-AllowedToActOnBehalfOfOtherIdentity) based on the research by @elad_shamir. pkb1s/SharpAllowedToAct
SharpRDPHijack Sharp RDP Hijack is a proof-of-concept .NET/C# Remote Desktop Protocol (RDP) session hijack utility for disconnected sessions bohops/SharpRDPHijack
CheeseTools This repository has been made basing onto the already existing MiscTool, so big shout-out to rasta-mouse for releasing them and for giving me the right motivation to work on them. klezVirus/CheeseTools
SharpSpray SharpSpray is a Windows domain password spraying tool written in .NET C#. iomoath/SharpSpray
MalSCCM This tool allows you to abuse local or remote SCCM servers to deploy malicious applications to hosts they manage. nettitude/MalSCCM
Coercer A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 9 methods. p0dalirius/Coercer
SharpSploit SharpSploit is a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers. cobbr/SharpSploit
orpheus Bypassing Kerberoast Detections with Modified KDC Options and Encryption Types trustedsec/orpheus
Chisel Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. Single executable including both client and server. jpillora/chisel
frp frp is a fast reverse proxy that allows you to expose a local server located behind a NAT or firewall to the Internet. fatedier/frp


Name Description URL
SharpExfiltrate Modular C# framework to exfiltrate loot over secure and trusted channels. Flangvik/SharpExfiltrate
DNSExfiltrator Data exfiltration over DNS request covert channel Arno0x/DNSExfiltrator
Egress-Assess Egress-Assess is a tool used to test egress data detection capabilities. FortyNorthSecurity/Egress-Assess


Threat-informed Defense

Name Description URL
Tidal Cyber Tidal Cyber helps enterprise organizations to define, measure, and improve their defenses to address the adversary behaviors that are most important to them.
Control Validation Compass Threat modeling aide & purple team content repository, pointing security & intelligence teams to 10,000+ publicly-accessible technical and policy controls and 2,100+ offensive security tests, aligned with nearly 600 common attacker techniques


Amazon Web Services (AWS)

Name Description URL
pacu The AWS exploitation framework, designed for testing the security of Amazon Web Services environments. RhinoSecurityLabs/pacu
CloudMapper CloudMapper helps you analyze your Amazon Web Services (AWS) environments. duo-labs/cloudmapper
Enumerate IAM permissions Enumerate the permissions associated with AWS credential set andresriancho/enumerate-iam


Name Description URL
Azure AD Connect password extraction This toolkit offers several ways to extract and decrypt stored Azure AD and Active Directory credentials from Azure AD Connect servers. fox-it/adconnectdump
Storm Spotter Azure Red Team tool for graphing Azure and Azure Active Directory objects Azure/Stormspotter
ROADtools The Azure AD exploration framework. dirkjanm/ROADtools
MicroBurst: A PowerShell Toolkit for Attacking Azure A collection of scripts for assessing Microsoft Azure security NetSPI/MicroBurst
AADInternals AADInternals PowerShell module for administering Azure AD and Office 365 Gerenios/AADInternals
TeamFiltration TeamFiltration is a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts. Flangvik/TeamFiltration
MAAD Attack Framework An attack tool for simple, fast & effective security testing of M365 & Azure AD. vectra-ai-research/MAAD-AF

Adversary Emulation

Name Description URL
Stratus Red Team Stratus Red Team is "Atomic Red Team™" for the cloud, allowing to emulate offensive attack techniques in a granular and self-contained manner. DataDog/stratus-red-team
Prelude Operator A Platform for Developer-first advanced security· Defend your organization by mimicking real adversarial attacks.
Prelude Build An open source IDE for authoring, testing, and verifying production-ready security tests..
Caldera An automated adversary emulation system that performs post-compromise adversarial behavior within Windows Enterprise networks. mitre/caldera
APTSimulator A Windows Batch script that uses a set of tools and output files to make a system look as if it was compromised. NextronSystems/APTSimulator
Atomic Red Team Small and highly portable detection tests mapped to the Mitre ATT&CK Framework. redcanaryco/atomic-red-team
Network Flight Simulator flightsim is a lightweight utility used to generate malicious network traffic and help security teams to evaluate security controls and network visibility. alphasoc/flightsim
Metta A security preparedness tool to do adversarial simulation. uber-common/metta
Red Team Automation (RTA) RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK. endgameinc/RTA

Living Off the Living Off the Land

Name Description URL
Living Off The Land Drivers Living Off The Land Drivers is a curated list of Windows drivers used by adversaries to bypass security controls and carry out attacks
GTFOBins GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems
LOLBAS The goal of the LOLBAS project is to document every binary, script, and library that can be used for Living Off The Land techniques
Living Off Trusted Sites (LOTS) Project Attackers are using popular legitimate domains when conducting phishing, C&C, exfiltration and downloading tools to evade detection. The list of websites below allow attackers to use their domain or subdomain
Filesec Stay up-to-date with the latest file extensions being used by attackers.
LOOBins Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in macOS binaries and how they can be used by threat actors for malicious purposes.
WTFBins WTFBin(n): a binary that behaves exactly like malware, except, somehow, it's not? This project aims to catalogue benign applications that exhibit suspicious behavior. These binaries can emit noise and false positives in threat hunting and automated detections.
Hijack Libs This project provides an curated list of DLL Hijacking candidates

Red Team Scripts

Name Description URL
RedTeamCCode Red Team C code repo Mr-Un1k0d3r/RedTeamCCode
EDRs This repo contains information about EDRs that can be useful during red team exercise. Mr-Un1k0d3r/EDRs
Cobalt Strike Community Kit Community Kit is a central repository of extensions written by the user community to extend the capabilities of Cobalt Strike.

Red Team Infrastructure

Name Description URL
Red Team Infrastructure Wiki Wiki to collect Red Team infrastructure hardening resources bluscreenofjeff/Red-Team-Infrastructure-Wiki



To the extent possible under law, Rahmat Nurfauzi "@infosecn1nja" has waived all copyright and related or neighboring rights to this work.

Popular Hackers Projects
Popular Penetration Testing Projects
Popular Security Categories
Related Searches

Get A Weekly Email With Trending Projects For These Categories
No Spam. Unsubscribe easily at any time.