Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
APT-GUID — APT-GUID | Kitploit
أدوات/GitHubGitHub/al1ex/apt-guid
الاستخبارات مفتوحة المصدر (OSINT)تصعيد الامتيازاتتحليل الثغرات الأمنيةالاستغلالجمع المعلوماتما بعد الاستغلالالقيادة والسيطرةالهندسة الاجتماعيةالتعلم والتعليمالفريق الأحمرموارد منسقة
2312منذ 5 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
GitHub
al1ex/apt-guid

APT-GUID

APT-GUID

عرض المستودع

مقدمة المشروع

تجميع بعض المواد في مجال APT، تشمل على سبيل المثال لا الحصر الجوانب التالية

  • أدوات هجوم APT

  • تقارير تحليل APT

  • تقنيات هجوم APT

تنظيم الأدوات

جمع المعلومات

جمع المعلومات الاستخباراتية النشط
  • EyeWitness يمكنه الحصول على لقطات شاشة للمواقع، وتوفير بعض معلومات الخادم، وتحديد بيانات الاعتماد الافتراضية حيثما أمكن https://github.com/ChrisTruncer/EyeWitness
  • AWSBucketDump أداة可用于 التعداد السريع لمجموعات AWS S3 بحثًا عن الغنائم https://github.com/jordanpotti/AWSBucketDump
  • AQUATONE أداة لجمع المعلومات حول النطاقات https://github.com/michenriksen/aquatone
  • Spoofcheck للتحقق مما إذا كان يمكن انتحال النطاق، يفحص هذا البرنامج سجلات SPF و DMARC بحثًا عن تكوينات ضعيفة تسمح بالانتحال https://github.com/BishopFox/spoofcheck
  • Nmap يستخدم لاكتشاف المضيفين والخدمات على شبكات الحاسوب https://github.com/nmap/nmap
  • dnsrecon سكربت تعداد DNS https://github.com/darkoperator/dnsrecon
  • dirsearch أداة سطر أوامر بسيطة لتخمين أدلة المواقع https://github.com/maurosoria/dirsearch
  • Sn1per أداة اختبار اختراق آلية https://github.com/1N3/Sn1per
جمع المعلومات الاستخباراتية السلبي
  • Social Mapper أداة رسم خرائط وسائل التواصل الاجتماعي OSINT، تأخذ قائمة بأسماء المستخدمين والصور (أو أسماء شركات LinkedIn) وتقوم بعمليات بحث مستهدفة تلقائية واسعة النطاق عبر مواقع وسائل التواصل الاجتماعي المتعددة. غير مقيدة بواجهات برمجة التطبيقات لأنها تستخدم Selenium. https://github.com/SpiderLabs/social_mapper
  • skiptracer إطار عمل استغلال OSINT https://github.com/xillwillx/skiptracer
  • FOCA يستخدم بشكل أساسي للعثور على البيانات الوصفية والمعلومات المخفية في المستندات الممسوحة ضوئيًا. https://github.com/ElevenPaths/FOCA
  • theHarvester يُستخدم لجمع النطاقات الفرعية وعناوين البريد الإلكتروني والمضيفات الافتراضية والمنافذ/اللافتات وأسماء الموظفين من مصادر عامة مختلفة. https://github.com/laramies/theHarvester
  • Metagoofil أداة لاستخراج البيانات الوصفية للمستندات العامة (pdf، doc، xls، ppt، إلخ) المتوفرة في الموقع المستهدف. https://github.com/laramies/metagoofil
  • SimplyEmail استطلاع البريد الإلكتروني. https://github.com/killswitch-GUI/SimplyEmail
  • truffleHog يبحث عن البيانات الحساسة في مستودعات git، مع التعمق في تاريخ الالتزامات والفروع. https://github.com/dxa4481/truffleHog
  • Just-Metadata أداة لجمع وتحليل البيانات الوصفية حول عناوين IP. تحاول العثور على العلاقات بين الأنظمة في مجموعات البيانات الكبيرة. https://github.com/ChrisTruncer/Just-Metadata
  • typofinder يعرض الدولة/المنطقة التي يقع فيها عنوان IP. https://github.com/nccgroup/typofinder
  • pwnedOrNot سكربت بايثون للتحقق مما إذا كان حساب البريد الإلكتروني قد تعرض للاختراق بسبب خرق للبيانات؛ إذا تعرض الحساب للاختراق، فإنه يواصل البحث عن كلمة مرور هذا الحساب. https://github.com/thewhiteh4t/pwnedOrNot
  • GitHarvester تُستخدم هذه الأداة لجمع المعلومات من GitHub، مثل google dork. https://github.com/metac0rtex/GitHarvester

استغلال الثغرات

  • WinRAR Remote Code Execution إثبات مفهوم لاستغلال CVE-2018-20250. https://github.com/WyAtu/CVE-2018-20250
  • Composite Moniker إثبات مفهوم لاستغلال CVE-2017-8570. https://github.com/rxwx/CVE-2017-8570
  • Exploit toolkit CVE-2017-8759 https://github.com/bhdresh/CVE-2017-8759
  • CVE-2017-11882 Exploit https://github.com/unamer/CVE-2017-11882
  • Adobe Flash Exploit CVE-2018-4878. https://github.com/anbai-inc/CVE-2018-4878
  • Exploit toolkit CVE-2017-0199 هو سكربت بايثون مناسب يوفر لمختبري الاختراق والباحثين الأمنيين طريقة سريعة وفعالة لاختبار Microsoft Office RCE. https://github.com/bhdresh/CVE-2017-0199
  • demiguise أداة تشفير HTA https://github.com/nccgroup/demiguise
  • Office-DDE-Payloads مجموعة سكربتات وقوالب لتوليد مستندات Office مضمّنة مع DDE (تقنية تنفيذ بدون ماكرو). https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads
  • CACTUSTORCH توليد حمولات لمحاكاة الخصوم. https://github.com/mdsecactivebreach/CACTUSTORCH
  • SharpShooter إطار عمل لإنشاء الحمولات لتنفيذ أكواد CSharp عشوائية. https://github.com/mdsecactivebreach/SharpShooter
  • DKMC أداة لتوليد شيلكود مُشوّش مخزّن داخل الصور. الصورة صالحة 100%، والشيلكود صالح 100%. https://github.com/Mr-Un1k0d3r/DKMC
  • Malicious Macro Generator لتوليد ماكروات مُشوّشة تتضمن أيضًا آليات الهروب من برامج مكافحة الفيروسات/صناديق الرمل. https://github.com/Mr-Un1k0d3r/MaliciousMacroGenerator
  • SCT-obfuscator أداة تشويش حمولات Cobalt Strike SCT.

التصيد والهندسة الاجتماعية

  • King Phisher https://github.com/securestate/king-phisher
  • FiercePhish https://github.com/Raikia/FiercePhish
  • ReelPhish https://github.com/fireeye/ReelPhish/
  • Gophish https://github.com/gophish/gophish
  • CredSniper https://github.com/ustayready/CredSniper
  • PwnAuth https://github.com/fireeye/PwnAuth
  • Phishing Frenzy https://github.com/pentestgeek/phishing-frenzy
  • Phishing Pretexts https://github.com/L4bF0x/PhishingPretexts
  • Modlishka https://github.com/drk1wi/Modlishka
  • Evilginx2 https://github.com/kgretzky/evilginx2

أطر C2

  • Cobalt Strike https://cobaltstrike.com/

  • Empire https://github.com/EmpireProject/Empire

  • Metasploit Framework https://github.com/rapid7/metasploit-framework

  • SILENTTRINITY https://github.com/byt3bl33d3r/SILENTTRINITY

  • Pupy https://github.com/n1nj4sec/pupy

  • Koadic https://github.com/zerosum0x0/koadic

  • PoshC2 https://github.com/nettitude/PoshC2_Python

  • Gcat https://github.com/byt3bl33d3r/gcat

  • TrevorC2 https://github.com/trustedsec/trevorc2

  • Merlin https://github.com/Ne0nd0g/merlin

  • Quasar https://github.com/quasar/QuasarRAT

  • Covenant https://github.com/cobbr/Covenant

  • FactionC2 https://github.com/FactionC2/

  • DNScat2 https://github.com/iagox86/dnscat2

  • Sliver https://github.com/BishopFox/sliver

  • EvilOSX

ما بعد الاستغلال

  • CrackMapExec https://github.com/byt3bl33d3r/CrackMapExec
  • PowerLessShell https://github.com/Mr-Un1k0d3r/PowerLessShell
  • GoFetch ينفذ تلقائيًا خطط الهجوم التي يولّدها BloodHound. https://github.com/GoFetchAD/GoFetch
  • ANGRYPUPPY أتمتة مسارات هجوم bloodhound في CobaltStrike. https://github.com/vysec/ANGRYPUPPY
  • DeathStar https://github.com/byt3bl33d3r/DeathStar
  • SharpHound https://github.com/BloodHoundAD/SharpHound
  • BloodHound.py هو أداة إدخال BloodHound قائمة على Python ومبنية على Impacket. https://github.com/fox-it/BloodHound.py
  • Responder أداة هجوم الرجل في المنتصف https://github.com/SpiderLabs/Responder
  • SessionGopher أداة PowerShell تستخدم WMI لاستخراج معلومات الجلسات المحفوظة لأدوات الوصول عن بُعد مثل WinSCP و PuTTY و SuperPuTTY و FileZilla و Microsoft Remote Desktop. https://github.com/fireeye/SessionGopher
  • PowerSploit مجموعة أدوات pwsh https://github.com/PowerShellMafia/PowerSploit
  • Nishang https://github.com/samratashok/nishang
  • Inveigh أداة هجوم الرجل في المنتصف https://github.com/Kevin-Robertson/Inveigh
  • PowerUpSQL مجموعة أدوات PowerShell لمهاجمة SQL Server. https://github.com/NetSPI/PowerUpSQL
  • MailSniper https://github.com/dafthack/MailSniper

الوكلاء الشبكيون

  • Tunna يُستخدم لتجاوز قيود الشبكة في البيئات المحمية بجدار الحماية https://github.com/SECFORCE/Tunna
  • reGeorg أداة وكيل socks https://github.com/sensepost/reGeorg
  • Blade أداة إدارة Webshell https://github.com/wonderqs/Blade
  • TinyShell إطار عمل Web Shell. https://github.com/threatexpress/tinyshell
  • PowerLurk مجموعة أدوات PowerShell لبناء WMI خبيث. https://github.com/Sw4mpf0x/PowerLurk
  • DAMP استمرارية عبر تعديل واصفات الأمان المستندة إلى المضيف https://github.com/HarmJ0y/DAMP

رفع الامتيازات

رفع الامتيازات داخل النطاق
  • PowerView https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1
  • Get-GPPPassword https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-GPPPassword.ps1
  • Invoke-ACLpwn https://github.com/fox-it/Invoke-ACLPwn
  • BloodHound https://github.com/BloodHoundAD/BloodHound
  • PyKEK https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS14-068/pykek
  • Grouper أداة للبحث التلقائي عن ثغرات نهج المجموعة https://github.com/l0ss/Grouper
  • ADRecon https://github.com/sense-of-security/ADRecon
  • ADACLScanner https://github.com/canix1/ADACLScanner
  • ACLight لاكتشاف حسابات النطاق ذات الامتيازات العالية التي يمكن استهدافها - بما في ذلك Shadow Admins. https://github.com/cyberark/ACLight
  • LAPSToolkit https://github.com/leoloobeek/LAPSToolkit
  • PingCastle https://www.pingcastle.com/download
  • RiskySPNs مجموعة سكربتات PowerShell تركز على اكتشاف والاستعلام عن الحسابات المرتبطة بـ SPN (أسماء الخدمة الرئيسية). https://github.com/cyberark/RiskySPN
  • Mystique أداة PowerShell تعمل مع امتدادات Kerberos S4U، تساعد هذه الوحدة الفرق الزرقاء على تحديد تكوينات تفويض Kerberos الخطيرة من خلال الجمع بين KCD والتحويل البروتوكولي، وتساعد الفرق الحمراء على انتحال شخصية أي مستخدم. https://github.com/machosec/Mystique
رفع الامتيازات في Linux
  • https://github.com/Al1ex/Heptagram/tree/master/Linux/Elevation مجموعة رفع امتيازات Linux
  • https://github.com/AlessandroZ/BeRoot py، يبحث عن طرق رفع الامتيازات عبر فحص الأخطاء الشائعة في التكوين. يدعم Windows/Linux/Mac
  • https://github.com/mschwager/0wned إنشاء مستخدمين بصلاحيات عالية باستخدام حزم python
  • https://github.com/mzet-/linux-exploit-suggester سكربت يبحث عن التصحيحات غير المطبقة في linux
  • https://github.com/belane/linux-soft-exploit-suggester سكربت يبحث عن البرامج الثغرة في linux
  • https://github.com/dirtycow/dirtycow.github.io استغلال ثغرة رفع الامتيازات Dirty Cow
  • https://github.com/FireFart/dirtycow استغلال ثغرة رفع الامتيازات Dirty Cow
  • https://github.com/stanleyb0y/sushell يستخدم لص su لسرقة كلمة مرور المستخدم الجذر من مستخدم منخفض الامتياز
  • https://github.com/jas502n/CVE-2018-17182/ ثغرة رفع الامتيازات VMA-UAF في نواة Linux CVE-2018-17182
  • https://github.com/jas502n/CVE-2018-14665 CVE-2018-14665، استغلال رفع الامتيازات لخادم Xorg X في Linux
  • https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897 استغلال Syscall لرفع الامتيازات في نظام Linux
  • https://github.com/can1357/CVE-2018-8897 استغلال Syscall لرفع الامتيازات في نظام Linux
  • https://github.com/SecWiki/linux-kernel-exploits linux-kernel-exploits مجموعة ثغرات رفع الامتيازات لمنصة Linux
  • https://github.com/nilotpalbiswas/Auto-Root-Exploit سكربت رفع امتيازات تلقائي في linux
  • https://github.com/WazeHell/PE-Linux أداة رفع الامتيازات في Linux
رفع الامتيازات في Windows
  • https://github.com/Al1ex/Heptagram/tree/master/Windows/Elevation مجموعة رفع امتيازات Windows
  • http://www.fuzzysecurity.com/tutorials/16.html مقالات مرجعية لرفع الامتيازات على مستوى الدروس لمنصة windows
  • https://github.com/SecWiki/windows-kernel-exploits مجموعة استغلالات رفع الامتيازات لمنصة Windows
  • https://github.com/51x/WHP أدوات متنوعة لرفع الامتيازات والاستغلال في windows
  • https://github.com/rasta-mouse/Sherlock التحقق من ثغرات رفع الامتيازات في win
  • https://github.com/WindowsExploits/Exploits استغلالات Microsoft CVE-2012-0217 و CVE-2016-3309 و CVE-2016-3371 و CVE-2016-7255 و CVE-2017-0213 لرفع الامتيازات
  • https://github.com/decoder-it/lonelypotato متغير RottenPotatoNG، يستخدم خداع اسم النطاق المحلي NBNS وخداع وكيل WPAD لرفع الامتيازات
  • https://github.com/ohpe/juicy-potato متغير RottenPotatoNG، يستخدم كائنات com ورموز المستخدم لرفع الامتيازات
  • https://github.com/foxglovesec/Potato متغير RottenPotatoNG، يستخدم خداع اسم النطاق المحلي وخداع الوكيل لرفع الامتيازات
  • https://github.com/DanMcInerney/icebreaker إذا كنت في بيئة شبكة داخلية ولكن خارج بيئة AD، سيساعدك icebreaker في الحصول على بيانات اعتماد Active Directory بنص واضح (مخزنة في وحدة تحكم النطاق ويمكن استخدامها لرفع الامتيازات)
  • https://github.com/hausec/ADAPE-Script سكربت رفع الامتيازات في Active Directory
  • https://github.com/klionsec/BypassAV-AllThings استخدام جملة aspx مع حمولة رفع الامتيازات لرفع الامتيازات
  • https://github.com/St0rn/Windows-10-Exploit إضافة msf، win10 uac bypass
  • https://github.com/sam-b/CVE-2014-4113 استغلال ثغرة Win32k.sys kernel للاستخراج، ms14-058

تسريب البيانات

  • CloakifyFactory ومجموعة أدوات Cloakify - https://github.com/TryCatchHCF/Cloakify
  • DET (مقدمة كما هي)، هي إثبات مفهوم لتنفيذ تسريب البيانات عبر قناة واحدة أو متعددة في نفس الوقت. https://github.com/sensepost/DET
  • DNSExfiltrator . https://github.com/Arno0x/DNSExfiltrator
  • PyExfil حزمة Python لتسريب البيانات. https://github.com/ytisf/PyExfil
  • Egress-Assess أداة لاختبار قدرات كشف تسريب البيانات الصادرة. https://github.com/ChrisTruncer/Egress-Assess
  • Powershell RAT باب خلفي قائم على python ينقل البيانات كمرفقات بريد إلكتروني عبر Gmail. https://github.com/Viralmaniar/Powershell-RAT

أخرى

محاكاة الخصوم
  • MITRE CALDERA يحاكي أساليب هجوم المخترقين ويحللها https://github.com/mitre/caldera
  • APTSimulator https://github.com/NextronSystems/APTSimulator
  • Atomic Red Team - https://github.com/redcanaryco/atomic-red-team
  • Network Flight Simulator https://github.com/alphasoc/flightsim
  • Metta - https://github.com/uber-common/metta
  • Red Team Automation (RTA) - يوفر RTA إطار عمل سكربتات يسمح للفرق الزرقاء بنمذجة الهجمات بناءً على MITER ATT&CK واختبار قدرات الكشف لديهم ضد الأدوات الخبيثة. https://github.com/endgameinc/RTA
الهجمات اللاسلكية
  • Wifiphisher أداة هجوم الاقتران التلقائي WIFI. https://github.com/wifiphisher/wifiphisher
  • mana هجوم الرجل في المنتصف. https://github.com/sensepost/mana
الهجمات على الأنظمة المدمجة- magspoof https://github.com/samyk/magspoof
  • WarBerryPi https://github.com/secgroundzero/warberry
  • P4wnP1 https://github.com/mame82/P4wnP1
  • malusb https://github.com/ebursztein/malusb
  • Fenrir https://github.com/Orange-Cyberdefense/fenrir-ocd
  • poisontap https://github.com/samyk/poisontap
  • WHID https://github.com/whid-injector/WHID
  • PhanTap https://github.com/nccgroup/phantap
إخفاء الاتصالات
  • RocketChat https://rocket.chat
  • Etherpad https://etherpad.org/
تنظيم السجلات
  • RedELK https://github.com/outflanknl/RedELK/
  • CobaltSplunk https://github.com/vysec/CobaltSplunk
  • Red Team Telemetry https://github.com/ztgrace/red_team_telemetry
  • Elastic for Red Teaming https://github.com/SecurityRiskAdvisors/RedTeamSIEM
  • Ghostwriter https://github.com/GhostManager/Ghostwriter
تسليح C#
  • SharpSploit إطار عمل ما بعد الاختراق لـ .NET https://github.com/cobbr/SharpSploit
  • GhostPack مجموعة أدوات Csharp https://github.com/GhostPack
  • SharpWeb لقراءة كلمات مرور المتصفحات الشائعة https://github.com/djhohnstein/SharpWeb
  • reconerator https://github.com/stufus/reconerator
  • SharpView نسخة C# من PowerView. https://github.com/tevora-threat/SharpView
  • Watson https://github.com/rasta-mouse/Watson
LABS
  • Detection Lab لأتمتة إنشاء مختبر https://github.com/clong/DetectionLab ---توصية بخمس نجوم
  • Modern Windows Attacks and Defense Labhttps://github.com/jaredhaight/WindowsAttackAndDefenseLab
  • Invoke-UserSimulator https://github.com/ubeeri/Invoke-UserSimulator
  • Invoke-ADLabDeployer لأتمتة نشر بيئة Active Directory https://github.com/outflanknl/Invoke-ADLabDeployer
  • Sheepl https://github.com/SpiderLabs/sheepl
Script
Aggressor Scripts
  • https://github.com/invokethreatguy/CSASC
  • https://github.com/secgroundzero/CS-Aggressor-Scripts
  • https://github.com/Und3rf10w/Aggressor-scripts
  • https://github.com/harleyQu1nn/AggressorScripts
  • https://github.com/rasta-mouse/Aggressor-Script
  • https://github.com/RhinoSecurityLabs/Aggressor-Scripts
  • https://github.com/bluscreenofjeff/AggressorScripts
  • https://github.com/001SPARTaN/aggressor_scripts
  • https://github.com/360-A-Team/CobaltStrike-Toolset
  • https://github.com/FortyNorthSecurity/AggressorAssessor
  • https://github.com/ramen0x3f/AggressorScripts
Red-Team
  • https://github.com/FuzzySecurity/PowerShell-Suite
  • https://github.com/nettitude/Powershell
  • https://github.com/Mr-Un1k0d3r/RedTeamPowershellScripts
  • https://github.com/threatexpress/red-team-scripts
  • https://github.com/SadProcessor/SomeStuff
  • https://github.com/rvrsh3ll/Misc-Powershell-Scripts
  • https://github.com/enigma0x3/Misc-PowerShell-Stuff
  • https://github.com/ChrisTruncer/PenTestScripts
  • https://github.com/bluscreenofjeff/Scripts
  • https://github.com/xorrior/RandomPS-Scripts
  • https://github.com/xorrior/Random-CSharpTools
  • https://github.com/leechristensen/Random
  • https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/social-engineering
تنزيل الأداة
  • pwndb أداة سطر أوامر بلغة بايثون للبحث عن بيانات الاعتماد المسربة باستخدام خدمة Onion بنفس الاسم. https://github.com/davidtavarez/pwndb/
  • LinkedInt أداة استطلاع LinkedIn. https://github.com/vysecurity/LinkedInt
  • CrossLinked أداة تعداد LinkedIn، تستخرج أسماء الموظفين الصالحين من المؤسسات عبر الزحف على محركات البحث. https://github.com/m8r0wn/CrossLinked
  • findomain أداة تعداد سريع للنطاقات الفرعية، تستخدم سجلات شفافية الشهادات وبعض واجهات برمجة التطبيقات. https://github.com/Edu4rdSHL/findomain
  • https://github.com/Mr-Un1k0d3r/SCT-obfuscator
  • Invoke-Obfuscation أداة تشويش PowerShell. https://github.com/danielbohannon/Invoke-Obfuscation
  • Invoke-CradleCrafter مولّد ومُشوّش للتنزيلات عن بُعد في PowerShell. https://github.com/danielbohannon/Invoke-CradleCrafter
  • Invoke-DOSfuscation أداة توليد وتشويش أوامر cmd.exe وأداة اختبار كشف. https://github.com/danielbohannon/Invoke-DOSfuscation
  • morphHTA. https://github.com/vysec/morphHTA
  • Unicorn أداة بسيطة تستخدم هجوم تخفيض إصدار PowerShell وحقن الشيلكود مباشرة في الذاكرة. https://github.com/trustedsec/unicorn
  • Shellter أداة حقن شيلكود ديناميكية، وأول أداة حقن PE ديناميكية حقيقية على الإطلاق. https://www.shellterproject.com/
  • EmbedInHTML تضمين وإخفاء أي ملف داخل HTML. https://github.com/Arno0x/EmbedInHTML
  • SigThief يسرق التوقيعات ويصنع توقيعًا غير صالح. https://github.com/secretsquirrel/SigThief
  • Veil، https://github.com/Veil-Framework/Veil
  • CheckPlease وحدات هروب من بيئة الاختبار مكتوبة بـ PowerShell وPython وGo وRuby وC وC# وPerl وRust. https://github.com/Arvanaghi/CheckPlease
  • Invoke-PSImage أداة لتضمين سكربتات PowerShell داخل وحدات البكسل في ملفات PNG وتنفيذها. https://github.com/peewpw/Invoke-PSImage
  • LuckyStrike أداة قائمة على PowerShell لإنشاء مستندات Office ضارة تحتوي على ماكرو. تُستخدم لأغراض الاختراق أو التعليم فقط. https://github.com/curi0usJack/luckystrike
  • ClickOnceGenerator https://github.com/Mr-Un1k0d3r/ClickOnceGenerator
  • macro_pack أداة من @EmericNasi لتشويش وتوليد مستندات MS Office وسكربتات VB وتنسيقات أخرى تلقائيًا لاختبارات الاختراق والعروض التقديمية وتقييمات الهندسة الاجتماعية. https://github.com/sevagas/macro_pack
  • StarFighters قاذف Empire قائم على JavaScript و VBScript. https://github.com/Cn33liz/StarFighters
  • nps_payload سيولد هذا السكربت حمولات لتجنب أنظمة كشف التسلل الأساسية. يستخدم تقنيات معروضة علنًا من عدة مصادر مختلفة. https://github.com/trustedsec/nps_payload
  • SocialEngineeringPay يحمّل سلسلة من تقنيات الهندسة الاجتماعية والحمولات لسرقة بيانات الاعتماد وهجمات التصيد بالرمح. https://github.com/bhdresh/SocialEngineeringPayloads
  • Social-Engineer Toolkit إطار عمل اختبار اختراق مفتوح المصدر مصمم للهندسة الاجتماعية. https://github.com/trustedsec/social-engineer-toolkit
  • phishery خادم HTTP بسيط يدعم SSL، والغرض الرئيسي منه هو التصيد للحصول على بيانات الاعتماد عبر المصادقة الأساسية. https://github.com/ryhanson/phishery
  • PowerShdll تشغيل PowerShell مع rundll32. تجاوز قيود البرامج. https://github.com/p3nt4/PowerShdll
  • UltimateAppLockerByPassList يوثق التقنيات الأكثر شيوعًا لتجاوز AppLocker. https://github.com/api0cradle/UltimateAppLockerByPassList
  • ruler، يتيح لك التفاعل عن بُعد مع خوادم Exchange عبر بروتوكول MAPI/HTTP أو RPC/HTTP. https://github.com/sensepost/ruler
  • Generate-Macro سكربت PowerShell مستقل يولّد مستندات Microsoft Office ضارة تحتوي على حمولة وطريقة استمرارية محددة. https://github.com/enigma0x3/Generate-Macro
  • MaliciousMacroMSBuild يولّد ماكروات ضارة وينفذ Powershell أو شيلكود عبر تجاوز القائمة البيضاء للتطبيقات باستخدام MSBuild. https://github.com/infosecn1nja/MaliciousMacroMSBuild
  • Meta Twin أداة استنساخ بيانات تعريف الملفات. تستخرج البيانات الوصفية من ملف بما في ذلك التوقيع الرقمي، ثم تحقنها في ملف آخر. https://github.com/threatexpress/metatwin
  • WePWNise يولّد كود VBA مستقل عن البنية لاستخدامه في مستندات أو قوالب Office، ويتجاوز تلقائيًا ضوابط التطبيقات. https://github.com/mwrlabs/wePWNise
  • DotNetToJScript لإنشاء ملف JScript يقوم بتحميل تجميعات .NET v2 من الذاكرة. https://github.com/tyranid/DotNetToJScript
  • PSAmsi أداة لتدقيق وتعطيل توقيعات AMSI. https://github.com/cobbr/PSAmsi
  • ReflectiveDLLInjection https://github.com/stephenfewer/ReflectiveDLLInjection
  • ps1encode لتوليد وتشفير حمولات metasploit القائمة على powershell. https://github.com/CroweCybersecurity/ps1encode
  • Worse-PDF. يُستخدم لسرقة تجزئات Net-NTLM من أجهزة Windows. https://github.com/3gstudent/Worse-PDF
  • SpookFlare يوفر زوايا مختلفة لتجاوز الإجراءات الأمنية. https://github.com/hlldz/SpookFlare
  • GreatSCT مشروع مفتوح المصدر لتوليد تجاوزات للقوائم البيضاء للتطبيقات. https://github.com/GreatSCT/GreatSCT
  • NPS تشغيل Powershell بدون Powershell. https://github.com/Ben0xA/nps
  • Meterpreter_Paranoid_Mode.sh يحمي اتصالات Meterpreter المرحلية/غير المرحلية. https://github.com/r00t-3xp10it/Meterpreter_Paranoid_Mode-SSL
  • backdoor-factory (BDF) سيصحح الملفات التنفيذية الثنائية باستخدام الشيلكود الذي يريده المستخدم، ويكمل التنفيذ الطبيعي للحالة قبل التصحيح. https://github.com/secretsquirrel/the-backdoor-factory
  • MacroShop مجموعة سكربتات للمساعدة في توصيل الحمولات عبر ماكروات Office. https://github.com/khr0x40sh/MacroShop
  • UnmanagedPowerShell تنفيذ PowerShell من عمليات غير مُدارة. https://github.com/leechristensen/UnmanagedPowerShell
  • evil-ssdp Spoof يستجيب SSDP لتصيد تجزئات NTLM على الشبكة. ينشئ جهاز UPNP مزيفًا لإغراء المستخدمين بزيارة صفحات ويب ضارة للتصيد. https://gitlab.com/initstring/evil-ssdp
  • Ebowla إطار عمل لصنع حمولات مرتبطة بالبيئة. https://github.com/Genetic-Malware/Ebowla
  • make-pdf أداة مدمجة يمكن استخدامها لإنشاء مستندات PDF تحتوي على ملفات مدمجة. https://github.com/DidierStevens/DidierStevensSuite/blob/master/make-pdf-embedded.py
  • avet (أداة تجنب برامج مكافحة الفيروسات) تستهدف أجهزة Windows بملفات قابلة للتنفيذ باستخدام تقنيات تجنب مختلفة. https://github.com/govolution/avet
  • EvilClippy أداة مساعدة عبر المنصات لإنشاء مستندات MS Office ضارة. يمكنها إخفاء ماكروات VBA وتشويشها. تعمل على Linux و OSX و Windows. https://github.com/outflanknl/EvilClippy
  • CallObfuscator يشوش استدعاءات Windows API من أدوات التحليل الثابت والمصححات. https://github.com/d35ha/CallObfuscator
  • Donut أداة توليد شيلكود تنشئ حمولات شيلكود مستقلة عن العنوان من تجميعات .NET. يمكن استخدام هذا الشيلكود لحقن التجميعات في أي عملية Windows. https://github.com/TheWover/donut
  • https://github.com/Marten4n6/EvilOSX
  • EggShell https://github.com/neoneggplant/EggShell

  • Rapid Attack Infrastructure (RAI) مجموعة أدوات البنية التحتية للفريق الأحمر https://github.com/obscuritylabs/RAI

  • Red Baron https://github.com/byt3bl33d3r/Red-Baron

  • EvilURL يولّد نطاقات إلكترونية خبيثة غير مرغوبة لهجمات التجانس IDN ويكشفها. https://github.com/UndeadSec/EvilURL

  • Domain Hunter يفحص النطاقات المنتهية وتصنيف bluecoat وسجلات Archive.org التاريخية لتحديد أفضل الخيارات للنطاقات المستخدمة في التصيد و C2. https://github.com/threatexpress/domainhunter

  • PowerDNS https://github.com/mdsecactivebreach/PowerDNS

  • Chameleon أداة للتهرب من تصنيفات الوكيل. https://github.com/mdsecactivebreach/Chameleon

  • CatMyFish https://github.com/Mr-Un1k0d3r/CatMyFish

  • Malleable C2 ملفات تعريف C2 https://github.com/rsmudge/Malleable-C2-Profiles

  • Malleable-C2-Randomizer https://github.com/bluscreenofjeff/Malleable-C2-Randomizer

  • FindFrontableDomains يبحث عن نطاقات قابلة للتوسعة محتملة. https://github.com/rvrsh3ll/FindFrontableDomains

  • Postfix-Server-Setup إعداد سريع لخادم تصيد https://github.com/n0pe-sled/Postfix-Server-Setup

  • DomainFrontingLists قوائم النطاقات الأمامية المتاحة لـ CDN https://github.com/vysec/DomainFrontingLists

  • Apache2-Mod-Rewrite-Setup إعادة توجيه C2 https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup

  • mod_rewrite rule تجنب بيئة الاختبار https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10

  • external_c2 framework External C2 مكتوب بلغة python. https://github.com/Und3rf10w/external_c2_framework

  • Malleable-C2-Profiles https://www.cobaltstrike.com/. https://github.com/xx0hcd/Malleable-C2-Profiles

  • ExternalC2 https://github.com/ryhanson/ExternalC2

  • cs2modrewrite https://github.com/threatexpress/cs2modrewrite

  • e2modrewrite https://github.com/infosecn1nja/e2modrewrite

  • redi إعداد إعادة توجيه CobaltStrike https://github.com/taherio/redi

  • cat-sites مكتبة مواقع للتصنيف. https://github.com/audrummer15/cat-sites

  • ycsm إعداد سريع لوكيل عكسي nginx https://github.com/infosecn1nja/ycsm

  • Domain Fronting Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting

  • DomainFrontDiscover https://github.com/peewpw/DomainFrontDiscover

  • Automated Empire Infrastructure https://github.com/bneg/RedTeam-Automation

  • Serving Random Payloads مع NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9

  • meek https://github.com/arlolra/meek

  • CobaltStrike-ToolKit سكربتات CS https://github.com/killswitch-GUI/CobaltStrike-ToolKit

  • mkhtaccess_red توليد تلقائي لـ HTaccess لتوصيل الحمولات - يستخرج تلقائيًا عناوين IP/الشبكات من شركات/مصادر بيئة الاختبار المعروفة سابقًا ويعيد توجيهها إلى حمولات غير ضارة. https://github.com/violentlydave/mkhtaccess_red

  • RedFile خدمة الحمولات https://github.com/outflanknl/RedFile

  • keyserver https://github.com/leoloobeek/keyserver

  • DoHC2 https://github.com/SpiderLabs/DoHC2

  • HTran https://github.com/HiwinCN/HTran

  • DomainPasswordSpray https://github.com/dafthack/DomainPasswordSpray
  • WMIOps https://github.com/ChrisTruncer/WMIOps
  • Mimikatz https://github.com/gentilkiwi/mimikatz
  • LaZagne https://github.com/AlessandroZ/LaZagne
  • mimipenguin لاستخراج كلمات مرور linux https://github.com/huntergregal/mimipenguin
  • PsExec https://docs.microsoft.com/en-us/sysinternals/downloads/psexec
  • KeeThief https://github.com/HarmJ0y/KeeThief
  • PSAttack https://github.com/jaredhaight/PSAttack
  • Internal Monologue Attack استرجاع تجزئات NTLM دون لمس LSASS. https://github.com/eladshamir/Internal-Monologue
  • Impacket مجموعة أدوات python https://github.com/CoreSecurity/impacket
  • icebreaker إذا كنت على شبكة داخلية ولكن لست في بيئة AD، فسيحصل على بيانات اعتماد Active Directory بنص واضح. https://github.com/DanMcInerney/icebreaker
  • Living Off The Land Binaries and Scripts (and now also Libraries) https://github.com/api0cradle/LOLBAS
  • WSUSpendu https://github.com/AlsidOfficial/WSUSpendu
  • Evilgrade https://github.com/infobyte/evilgrade
  • NetRipper أداة ما بعد الاستغلال لأنظمة Windows تستخدم ربط API لاعتراض حركة مرور الشبكة والوظائف المتعلقة بالتشفير للمستخدمين منخفضي الامتياز، مما يتيح التقاط حركة المرور بنص واضح وحركة المرور المشفرة قبل التشفير/بعد فك التشفير. https://github.com/NytroRST/NetRipper
  • LethalHTA تقنية حركة جانبية باستخدام DCOM و HTA. https://github.com/codewhitesec/LethalHTA
  • Invoke-PowerThIEf https://github.com/nettitude/Invoke-PowerThIEf
  • RedSnarf https://github.com/nccgroup/redsnarf
  • HoneypotBuster وحدة Microsoft PowerShell مصممة للفرق الحمراء، يمكن استخدامها للعثور على مصائد العسل والرموز المميزة على الشبكة أو المضيف. https://github.com/JavelinNetworks/HoneypotBuster
  • PAExec تشغيل برامج Windows على أجهزة كمبيوتر Windows عن بُعد دون الحاجة إلى تثبيت البرنامج أولاً على الكمبيوتر البعيد. https://www.poweradmin.com/paexec/
  • Rubeus https://github.com/GhostPack/Rubeus
  • kekeo https://github.com/gentilkiwi/kekeo
  • https://guif.re/linuxeop مجموعة أوامر رفع الامتيازات في linux
  • https://github.com/breenmachine/RottenPotatoNG استخدام خداع اسم النطاق المحلي NBNS وخداع وكيل WPAD لرفع الامتيازات
  • https://github.com/unamer/CVE-2018-8120 يؤثر على مكون Win32k، لرفع الامتيازات على win7 و win2008
  • https://github.com/alpha1ab/CVE-2018-8120 يضيف winXP و win2k3 إلى win7 و win2k8
  • https://github.com/0xbadjuju/Tokenvator أداة لرفع الامتيازات باستخدام رموز Windows، توفر واجهة سطر أوامر تفاعلية