
APT-GUID
Eine Sammlung von Materialien zum Thema APT, einschließlich, aber nicht beschränkt auf die folgenden Bereiche
APT-Angriffswerkzeuge
APT-Analyseberichte
APT-Angriffstechniken
Cobalt Strike https://cobaltstrike.com/
Metasploit Framework https://github.com/rapid7/metasploit-framework
SILENTTRINITY https://github.com/byt3bl33d3r/SILENTTRINITY
Covenant https://github.com/cobbr/Covenant
FactionC2 https://github.com/FactionC2/
EvilOSX
Rapid Attack Infrastructure (RAI) ist eine Werkzeugsammlung für Red-Team-Infrastruktur https://github.com/obscuritylabs/RAI
Red Baron https://github.com/byt3bl33d3r/Red-Baron
EvilURL erzeugt bösartige Unicode-Domains für IDN-Homograph-Angriffe und erkennt diese. https://github.com/UndeadSec/EvilURL
Domain Hunter prüft abgelaufene Domains, Bluecoat-Kategorisierung und Archive.org-Verlauf, um die besten Optionen für Phishing- und C2-Domains zu ermitteln. https://github.com/threatexpress/domainhunter
Chameleon ist ein Werkzeug zur Umgehung der Proxy-Kategorisierung. https://github.com/mdsecactivebreach/Chameleon
CatMyFish https://github.com/Mr-Un1k0d3r/CatMyFish
Malleable C2 C2-Profile https://github.com/rsmudge/Malleable-C2-Profiles
Malleable-C2-Randomizer https://github.com/bluscreenofjeff/Malleable-C2-Randomizer
FindFrontableDomains sucht nach potenziell frontbaren Domains. https://github.com/rvrsh3ll/FindFrontableDomains
Postfix-Server-Setup für den schnellen Aufbau eines Phishing-Servers https://github.com/n0pe-sled/Postfix-Server-Setup
DomainFrontingLists ist eine Liste verfügbarer CDN-Fronting-Domains https://github.com/vysec/DomainFrontingLists
Apache2-Mod-Rewrite-Setup für C2-Redirects https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup
mod_rewrite rule zur Sandbox-Umgehung https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10
external_c2 framework ist ein in Python geschriebenes External C2. https://github.com/Und3rf10w/external_c2_framework
Malleable-C2-Profiles https://www.cobaltstrike.com/. https://github.com/xx0hcd/Malleable-C2-Profiles
ExternalC2 https://github.com/ryhanson/ExternalC2
cs2modrewrite https://github.com/threatexpress/cs2modrewrite
e2modrewrite https://github.com/infosecn1nja/e2modrewrite
redi richtet Cobalt-Strike-Redirects ein https://github.com/taherio/redi
cat-sites ist eine Bibliothek von Websites zur Kategorisierung. https://github.com/audrummer15/cat-sites
ycsm für die schnelle Einrichtung eines nginx-Reverse-Proxys https://github.com/infosecn1nja/ycsm
Domain Fronting Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting
DomainFrontDiscover https://github.com/peewpw/DomainFrontDiscover
Automated Empire Infrastructure https://github.com/bneg/RedTeam-Automation
Serving Random Payloads mit NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9
CobaltStrike-ToolKit CS-Skripte https://github.com/killswitch-GUI/CobaltStrike-ToolKit
mkhtaccess_red erzeugt automatisch HTaccess für die Payload-Zustellung – extrahiert automatisch IPs/Netze usw. von zuvor gesehenen Sandbox-Unternehmen/-Quellen und leitet sie auf gutartige Payloads um. https://github.com/violentlydave/mkhtaccess_red
RedFile Payload-Dienst https://github.com/outflanknl/RedFile
keyserver https://github.com/leoloobeek/keyserver