Lists (32)
Sort Name ascending (A-Z)
Active Directory Security
Repos regarding Active Directory security/offensive tools for red teaming AD.AI/ML 🤖
Blue Team 📘
C2 Tools/Infrastructure 📡
Repos for C2 infrastructure and C2 tools.CLI 🖥️
CLI tools and reposCloud Security/Pentesting ☁️
CobaltStrike
CobaltStrike ReposContent Discovery & Fuzzing
Tools for content discovery and fuzzing.CRTO 🔴 ⚔️
Repos related to Zero-Point Security CRTO course for Red Team Operator 1 certificationCVEs
Collection of PoC for CVEsDocker Security 🐳
Domain Security
Tools regarding the security of domains, domain spoofing, subdomain takeover, etc.Google Cloud Security
Host Enumeration & PrivEsc 🔍
Repos related to host enumeration, host recon, and PrivEsc.Kerberos 🐶
Repos related to Kerberos attack/defense/managementLudus 🏟
Ludus related reposMalDocs 📃
Repos regarding maldocsMarkdown Ⓜ️
Repos regarding Markdown and markdown tools.NTLM Relaying & Forced Auth
Tools for NTLM relaying and forcing authOffsenive C#/.NET
Repos for offensive tooling in C# or .NETOSINT 🕵️
A collection of repos for OSINT!Password Attacks 🗝️
Repos related to password attacks, such as password spraying.Persistence 💾
Repos relating to establishing/maintaining persistence on compromised hosts.Phishing 🎣
Repos to aid in phishing.PowerShell
Repos relating to PowerShell (Modules, Tools, Scripts, etc.)Proxy & Port Forwarding
Repos and tools for proxying and port forwarding!Red Team 🚩
Rust 🦀
Repos related to RustSubdomain Enumeration & Hacking
WebSockets
Wordlists 📖
Collection of wordlists for password cracking, fuzzing, content discovery, username enumeration, etc.ZSH
Repos related to ZSH (Themes, plugins, etc.)- All languages
- ActionScript
- Arduino
- Assembly
- AutoIt
- Batchfile
- BlitzBasic
- C
- C#
- C++
- CMake
- CSS
- Dart
- Dockerfile
- Go
- Groff
- HCL
- HTML
- Hack
- Java
- JavaScript
- Jinja
- Jupyter Notebook
- Just
- Kotlin
- Lua
- Nim
- Nix
- OCaml
- Objective-C
- PHP
- Pascal
- Perl
- PowerShell
- Python
- QML
- R
- Roff
- Ruby
- Rust
- SCSS
- Shell
- Standard ML
- TypeScript
- VBA
- Vala
- Vim Script
- Vue
- YARA
- Zig
Starred repositories
Collection of BOFs created for red team/adversary engagements. Created to be small and interchangeable, for quick recon or eventing.
Ghidra script for extracting embedded Rust crate dependency strings from a compiled Rust binary
Cobalt-Strike / unhook-bof
Forked from rsmudge/unhook-bofRemove API hooks from a Beacon process.
UDC2 implementation that provides an ICMP C2 channel
KVC enables unsigned driver loading via DSE bypass (g_CiOptions patch, skci.dll hijack, SeCiCallbacks redirection) and PP/PPL manipulation for LSASS memory dumping on modern Windows with HVCI/VBS.
Red teaming tool to dump LSASS memory, bypassing basic countermeasures.
Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective
BOF to steal browser cookies & credentials
UAC Bypass using UIAccess program QuickAssist
Custom dyld version inherited from original Apple dyld implementation
A collection of scripts and documents to help future XProtect Remediator (XPR) research
template for developing custom C2 channels for Cobalt Strike using IAT hooks applied by a reflective loader.
Usermode exploit to bypass any AC using a 0day shatter attack.
Create your own AirTag with OpenHaystack, but without the need to own an Apple device
Send files and folders anywhere in the world without storing in cloud - any size, any format, no accounts, no restrictions.
Wiretap is a transparent, VPN-like proxy server that tunnels traffic via WireGuard and requires no special privileges to run.
A C# based Red Team utility, to execute commands on a remote windows system using SMB/SCCM
Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.
Minimal, self-hosted, 0-config alternative to ngrok. Caddy+OpenSSH+50 lines of Python.
A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.
Tunnel relay allows you to expose local services to the outside world over HTTPS
Cobalt Strike module x loader x profile x wike / A public collection of open resources for Cobalt Strike (only legal use in Red Team and penetration testing