Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
APT-GUID — APT-GUID | Kitploit
Tools/GitHubGitHub/al1ex/apt-guid
OSINT (Open-Source-Intelligence)Privilege EscalationSchwachstellenanalyseExploitationInformationsbeschaffungPost-ExploitationCommand and ControlSocial EngineeringLernen & BildungRed TeamingKuratierte Ressourcen
23126vor 5 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
GitHub
al1ex/apt-guid

APT-GUID

APT-GUID

Repository anzeigen

Projektbeschreibung

Eine Sammlung von Materialien zum Thema APT, einschließlich, aber nicht beschränkt auf die folgenden Bereiche

  • APT-Angriffswerkzeuge

  • APT-Analyseberichte

  • APT-Angriffstechniken

Tools-Sammlung

Informationssammlung

Aktive Informationssammlung
  • EyeWitness kann Screenshots von Websites erfassen, einige Serverinformationen bereitstellen und bei Möglichkeit Standard-Anmeldedaten identifizieren https://github.com/ChrisTruncer/EyeWitness
  • AWSBucketDump ist ein Werkzeug zur schnellen Aufzählung von AWS-S3-Buckets auf der Suche nach Beute https://github.com/jordanpotti/AWSBucketDump
  • AQUATONE ist ein Werkzeug zur Informationssammlung über Domains https://github.com/michenriksen/aquatone
  • Spoofcheck prüft, ob eine Domain gespooft werden kann. Das Programm untersucht SPF- und DMARC-Einträge auf schwache Konfigurationen, die Spoofing erlauben https://github.com/BishopFox/spoofcheck
  • Nmap wird verwendet, um Hosts und Dienste in Computernetzwerken zu entdecken https://github.com/nmap/nmap
  • dnsrecon ist ein DNS-Enumeration-Skript https://github.com/darkoperator/dnsrecon
  • dirsearch ist ein einfaches Befehlszeilen-Tool zum Brute-Forcing von Website-Verzeichnissen https://github.com/maurosoria/dirsearch
  • Sn1per ist ein automatisiertes Penetrationstest-Werkzeug https://github.com/1N3/Sn1per
Passive Informationssammlung
  • Social Mapper ist ein OSINT-Tool zur Kartierung sozialer Medien. Es nimmt eine Liste von Benutzernamen und Bildern (oder LinkedIn-Firmennamen) und führt eine automatisierte, groß angelegte Suche nach Zielpersonen auf mehreren Social-Media-Websites durch. Es ist nicht durch APIs eingeschränkt, da es Selenium verwendet. https://github.com/SpiderLabs/social_mapper
  • skiptracer ist ein OSINT-Exploitation-Framework https://github.com/xillwillx/skiptracer
  • FOCA wird hauptsächlich verwendet, um Metadaten und versteckte Informationen in gescannten Dokumenten zu finden. https://github.com/ElevenPaths/FOCA
  • theHarvester wird verwendet, um Subdomains, E-Mail-Adressen, virtuelle Hosts, Ports/Banner und Mitarbeiternamen aus verschiedenen öffentlichen Quellen zu sammeln. https://github.com/laramies/theHarvester
  • Metagoofil ist ein Werkzeug zum Extrahieren von Metadaten aus öffentlich verfügbaren Dokumenten (PDF, DOC, XLS, PPT usw.) auf Zielwebsites. https://github.com/laramies/metagoofil
  • SimplyEmail für E-Mail-Reconnaissance. https://github.com/killswitch-GUI/SimplyEmail
  • truffleHog durchsucht Git-Repositories nach sensiblen Daten, indem es tief in die Commit-Historie und Branches eindringt. https://github.com/dxa4481/truffleHog
  • Just-Metadata ist ein Werkzeug zum Sammeln und Analysieren von Metadaten über IP-Adressen. Es versucht, Beziehungen zwischen Systemen in großen Datensätzen zu finden. https://github.com/ChrisTruncer/Just-Metadata
  • typofinder zeigt das Land/die Region an, in dem/der sich eine IP-Adresse befindet. https://github.com/nccgroup/typofinder
  • pwnedOrNot ist ein Python-Skript, das prüft, ob ein E-Mail-Konto durch einen Datenleak kompromittiert wurde; falls das Konto kompromittiert ist, versucht es, das Passwort für dieses Konto zu finden. https://github.com/thewhiteh4t/pwnedOrNot

Exploitation

  • WinRAR Remote Code Execution Proof-of-Concept-Exploit für CVE-2018-20250. https://github.com/WyAtu/CVE-2018-20250
  • Composite Moniker Proof-of-Concept-Exploit für CVE-2017-8570. https://github.com/rxwx/CVE-2017-8570
  • Exploit toolkit CVE-2017-8759 https://github.com/bhdresh/CVE-2017-8759
  • CVE-2017-11882 Exploit https://github.com/unamer/CVE-2017-11882
  • Adobe Flash Exploit CVE-2018-4878. https://github.com/anbai-inc/CVE-2018-4878
  • Exploit toolkit CVE-2017-0199 ist ein praktisches Python-Skript, das Pentestern und Sicherheitsforschern eine schnelle und effektive Methode bietet, Microsoft Office RCE zu testen. https://github.com/bhdresh/CVE-2017-0199
  • demiguise ist ein HTA-Verschlüsselungswerkzeug https://github.com/nccgroup/demiguise
  • Office-DDE-Payloads ist eine Sammlung von Skripten und Vorlagen zur Erstellung von Office-Dokumenten mit eingebettetem DDE (makrolose Befehlausführungstechnik). https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads
  • CACTUSTORCH wird zur Payload-Erzeugung für die Adversary-Simulation verwendet. https://github.com/mdsecactivebreach/CACTUSTORCH
  • SharpShooter ist ein Framework zur Erstellung von Payloads für die Ausführung beliebigen C#-Quellcodes. https://github.com/mdsecactivebreach/SharpShooter
  • DKMC ist ein Werkzeug zur Erzeugung von obfuskiertem Shellcode, der in Bildern gespeichert wird. Das Bild ist zu 100 % ein gültiges Bild und zu 100 % gültiger Shellcode. https://github.com/Mr-Un1k0d3r/DKMC
  • Malicious Macro Generator erzeugt obfuskierte Makros, die auch AV-/Sandbox-Escape-Mechanismen enthalten.

Social-Engineering-Phishing

  • King Phisher https://github.com/securestate/king-phisher
  • FiercePhish https://github.com/Raikia/FiercePhish
  • ReelPhish https://github.com/fireeye/ReelPhish/
  • Gophish https://github.com/gophish/gophish
  • CredSniper https://github.com/ustayready/CredSniper
  • PwnAuth https://github.com/fireeye/PwnAuth
  • Phishing Frenzy https://github.com/pentestgeek/phishing-frenzy
  • Phishing Pretexts https://github.com/L4bF0x/PhishingPretexts
  • Modlishka https://github.com/drk1wi/Modlishka
  • Evilginx2 https://github.com/kgretzky/evilginx2

C2-Frameworks

  • Cobalt Strike https://cobaltstrike.com/

  • Empire https://github.com/EmpireProject/Empire

  • Metasploit Framework https://github.com/rapid7/metasploit-framework

  • SILENTTRINITY https://github.com/byt3bl33d3r/SILENTTRINITY

  • Pupy https://github.com/n1nj4sec/pupy

  • Koadic https://github.com/zerosum0x0/koadic

  • PoshC2 https://github.com/nettitude/PoshC2_Python

  • Gcat https://github.com/byt3bl33d3r/gcat

  • TrevorC2 https://github.com/trustedsec/trevorc2

  • Merlin https://github.com/Ne0nd0g/merlin

  • Quasar https://github.com/quasar/QuasarRAT

  • Covenant https://github.com/cobbr/Covenant

  • FactionC2 https://github.com/FactionC2/

  • DNScat2 https://github.com/iagox86/dnscat2

  • Sliver https://github.com/BishopFox/sliver

  • EvilOSX

Post-Exploitation

  • CrackMapExec https://github.com/byt3bl33d3r/CrackMapExec
  • PowerLessShell https://github.com/Mr-Un1k0d3r/PowerLessShell
  • GoFetch automatisiert BloodHound zur Erstellung von Angriffsplänen. https://github.com/GoFetchAD/GoFetch
  • ANGRYPUPPY automatisiert BloodHound-Angriffspfade in CobaltStrike. https://github.com/vysec/ANGRYPUPPY
  • DeathStar https://github.com/byt3bl33d3r/DeathStar
  • SharpHound https://github.com/BloodHoundAD/SharpHound
  • BloodHound.py ist ein auf Impacket basierender Python-BloodHound-Ingestor. https://github.com/fox-it/BloodHound.py
  • Responder ist ein Man-in-the-Middle-Angriffswerkzeug https://github.com/SpiderLabs/Responder
  • SessionGopher ist ein PowerShell-Werkzeug, das WMI verwendet, um gespeicherte Sitzungsinformationen von Remote-Zugriffswerkzeugen wie WinSCP, PuTTY, SuperPuTTY, FileZilla und Microsoft Remote Desktop zu extrahieren. https://github.com/fireeye/SessionGopher
  • PowerSploit ist eine PowerShell-Werkzeugsammlung https://github.com/PowerShellMafia/PowerSploit
  • Nishang https://github.com/samratashok/nishang
  • Inveigh ist ein Man-in-the-Middle-Angriffswerkzeug https://github.com/Kevin-Robertson/Inveigh
  • PowerUpSQL ist ein PowerShell-Toolkit für Angriffe auf SQL Server. https://github.com/NetSPI/PowerUpSQL
  • MailSniper https://github.com/dafthack/MailSniper

Netzwerk-Proxys

  • Tunna wird verwendet, um Netzwerkbeschränkungen in Firewall-Umgebungen zu umgehen https://github.com/SECFORCE/Tunna
  • reGeorg ist ein SOCKS-Proxy-Werkzeug https://github.com/sensepost/reGeorg
  • Blade ist ein Webshell-Verwaltungswerkzeug https://github.com/wonderqs/Blade
  • TinyShell ist ein Web-Shell-Framework. https://github.com/threatexpress/tinyshell
  • PowerLurk ist eine PowerShell-Werkzeugsammlung zum Erstellen bösartiger WMI-Objekte. https://github.com/Sw4mpf0x/PowerLurk
  • DAMP realisiert Persistenz durch hostbasierte Sicherheitsdeskriptor-Modifikationen. https://github.com/HarmJ0y/DAMP

Privilege Escalation

Privilege Escalation in der Domäne
  • PowerView https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1
  • Get-GPPPassword https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-GPPPassword.ps1
  • Invoke-ACLpwn https://github.com/fox-it/Invoke-ACLPwn
  • BloodHound https://github.com/BloodHoundAD/BloodHound
  • PyKEK https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS14-068/pykek
  • Grouper ist ein Werkzeug zur automatischen Suche nach Gruppenrichtlinien-Schwachstellen. https://github.com/l0ss/Grouper
  • ADRecon https://github.com/sense-of-security/ADRecon
  • ADACLScanner https://github.com/canix1/ADACLScanner
  • ACLight wird verwendet, um privilegierte Domänenkonten zu finden, die als Angriffsziel dienen können – einschließlich Shadow Admins. https://github.com/cyberark/ACLight
  • LAPSToolkit https://github.com/leoloobeek/LAPSToolkit
  • PingCastle https://www.pingcastle.com/download
  • RiskySPNs ist eine Sammlung von PowerShell-Skripten, die sich auf die Erkennung und Abfrage von Konten konzentriert, die mit SPNs (Service Principal Names) verknüpft sind. https://github.com/cyberark/RiskySPN
  • Mystique ist ein PowerShell-Werkzeug, das mit den Kerberos-S4U-Erweiterungen verwendet werden kann. Durch die Kombination von KCD mit Protokollübergang unterstützt dieses Modul Blue Teams dabei, gefährliche Kerberos-Delegierungskonfigurationen zu erkennen, und Red Teams dabei, jeden Benutzer zu imitieren.
Linux Privilege Escalation
  • https://github.com/Al1ex/Heptagram/tree/master/Linux/Elevation Linux-Privilege-Escalation-Sammlung
  • https://github.com/AlessandroZ/BeRoot py, findet Privilege-Escalation-Methoden durch die Prüfung häufiger Fehlkonfigurationen. Unterstützt Windows/Linux/Mac
  • https://github.com/mschwager/0wned nutzt Python-Pakete zur Erstellung von Benutzern mit hohen Rechten
  • https://github.com/mzet-/linux-exploit-suggester Skript zum Auffinden fehlender Linux-Patches
  • https://github.com/belane/linux-soft-exploit-suggester zum Auffinden von Linux-Software mit Schwachstellen
  • https://github.com/dirtycow/dirtycow.github.io Dirty-Cow-Privilege-Escalation-Exploit
  • https://github.com/FireFart/dirtycow Dirty-Cow-Privilege-Escalation-Exploit
  • https://github.com/stanleyb0y/sushell nutzt einen su-Dieb, damit Benutzer mit niedrigen Rechten das Root-Passwort stehlen können
  • https://github.com/jas502n/CVE-2018-17182/ Linux-Kernel-VMA-UAF-Privilege-Escalation-Schwachstelle CVE-2018-17182
  • https://github.com/jas502n/CVE-2018-14665 CVE-2018-14665, Privilege-Escalation-Exploit für den Xorg-X-Server unter Linux
  • https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897 Linux-System erreicht Privilege Escalation über Syscall
  • https://github.com/can1357/CVE-2018-8897 Linux-System erreicht Privilege Escalation über Syscall
  • https://github.com/SecWiki/linux-kernel-exploits linux-kernel-exploits – Sammlung von Privilege-Escalation-Schwachstellen für die Linux-Plattform
  • https://github.com/nilotpalbiswas/Auto-Root-Exploit automatisches Linux-Privilege-Escalation-Skript
Windows Privilege Escalation
  • https://github.com/Al1ex/Heptagram/tree/master/Windows/Elevation Windows-Privilege-Escalation-Sammlung
  • http://www.fuzzysecurity.com/tutorials/16.html Tutorial-Level-Privilege-Escalation-Referenzartikel für die Windows-Plattform
  • https://github.com/SecWiki/windows-kernel-exploits Sammlung von Privilege-Escalation-Exploits für die Windows-Plattform
  • https://github.com/51x/WHP verschiedene Privilege-Escalation- und Exploitation-Werkzeuge für Windows
  • https://github.com/rasta-mouse/Sherlock Windows-Privilege-Escalation-Schwachstellenprüfung
  • https://github.com/WindowsExploits/Exploits Microsoft-Privilege-Escalation-Exploits für CVE-2012-0217, CVE-2016-3309, CVE-2016-3371, CVE-2016-7255, CVE-2017-0213
  • https://github.com/decoder-it/lonelypotato RottenPotatoNG-Variante, nutzt NBNS-Local-Domain-Spoofing und WPAD-Proxy-Spoofing zur Privilege Escalation
  • https://github.com/ohpe/juicy-potato RottenPotatoNG-Variante, nutzt COM-Objekte und Benutzer-Tokens zur Privilege Escalation
  • https://github.com/foxglovesec/Potato RottenPotatoNG-Variante, nutzt lokales Domain-Spoofing und Proxy-Spoofing zur Privilege Escalation
  • https://github.com/DanMcInerney/icebreaker Wenn Sie sich in einem internen Netzwerk, aber außerhalb der AD-Umgebung befinden, hilft Ihnen icebreaker, Klartext-Active-Directory-Anmeldedaten zu beschaffen (die in Domänencontrollern gespeicherten Active-Directory-Daten können für die Privilege Escalation verwendet werden)
  • https://github.com/hausec/ADAPE-Script Active-Directory-Privilege-Escalation-Skript
  • https://github.com/klionsec/BypassAV-AllThings nutzt aspx-Webshells (One-Liner) in Kombination mit Privilege-Escalation-Payloads
  • https://github.com/St0rn/Windows-10-Exploit MSF-Plugin, Win10-UAC-Bypass

Datenexfiltration

  • CloakifyFactory & the Cloakify Toolset - https://github.com/TryCatchHCF/Cloakify
  • DET (is provided AS IS), ist ein Proof of Concept, das Datenerfiltration über einen einzelnen oder mehrere Kanäle gleichzeitig durchführt. https://github.com/sensepost/DET
  • DNSExfiltrator . https://github.com/Arno0x/DNSExfiltrator
  • PyExfil ist ein Python-Paket für Datenerfiltration. https://github.com/ytisf/PyExfil
  • Egress-Assess ist ein Werkzeug zum Testen der Erkennung ausgehender Daten. https://github.com/ChrisTruncer/Egress-Assess
  • Powershell RAT ist ein auf Python basierender Backdoor, der Gmail nutzt, um Daten als E-Mail-Anhänge zu übertragen. https://github.com/Viralmaniar/Powershell-RAT

Sonstiges

Adversary Simulation
  • MITRE CALDERA simuliert die Angriffstechniken von Eindringlingen und analysiert sie https://github.com/mitre/caldera
  • APTSimulator https://github.com/NextronSystems/APTSimulator
  • Atomic Red Team - https://github.com/redcanaryco/atomic-red-team
  • Network Flight Simulator https://github.com/alphasoc/flightsim
  • Metta - https://github.com/uber-common/metta
  • Red Team Automation (RTA) – RTA bietet ein Skript-Framework, mit dem Blue Teams ihre Erkennungsfähigkeiten gegen bösartige Werkzeuge testen können, modelliert nach MITRE ATT&CK. https://github.com/endgameinc/RTA
Drahtlose Angriffe
  • Wifiphisher ist ein Werkzeug für automatische WLAN-Assoziationsangriffe. https://github.com/wifiphisher/wifiphisher
  • mana für Man-in-the-Middle-Angriffe. https://github.com/sensepost/mana
Angriffe auf eingebettete Systeme- magspoof https://github.com/samyk/magspoof
  • WarBerryPi https://github.com/secgroundzero/warberry
  • P4wnP1 https://github.com/mame82/P4wnP1
  • malusb https://github.com/ebursztein/malusb
  • Fenrir https://github.com/Orange-Cyberdefense/fenrir-ocd
  • poisontap https://github.com/samyk/poisontap
  • WHID https://github.com/whid-injector/WHID
  • PhanTap https://github.com/nccgroup/phantap
Kommunikations-Tarnung
  • RocketChat https://rocket.chat
  • Etherpad https://etherpad.org/
Log-Verwaltung
  • RedELK https://github.com/outflanknl/RedELK/
  • CobaltSplunk https://github.com/vysec/CobaltSplunk
  • Red Team Telemetry https://github.com/ztgrace/red_team_telemetry
  • Elastic for Red Teaming https://github.com/SecurityRiskAdvisors/RedTeamSIEM
  • Ghostwriter https://github.com/GhostManager/Ghostwriter
C#-Waffenisierung
  • SharpSploit .NET-Post-Exploitation-Framework https://github.com/cobbr/SharpSploit
  • GhostPack C#-Toolset https://github.com/GhostPack
  • SharpWeb Liest gängige Browser-Passwörter aus https://github.com/djhohnstein/SharpWeb
  • reconerator https://github.com/stufus/reconerator
  • SharpView C#-Version von PowerView. https://github.com/tevora-threat/SharpView
  • Watson https://github.com/rasta-mouse/Watson
LABS
  • Detection Lab Automatisierter Aufbau eines Labs https://github.com/clong/DetectionLab --- Fünf-Sterne-Empfehlung
  • Modern Windows Attacks and Defense Labhttps://github.com/jaredhaight/WindowsAttackAndDefenseLab
  • Invoke-UserSimulator https://github.com/ubeeri/Invoke-UserSimulator
  • Invoke-ADLabDeployer Automatisierte Bereitstellung von AD-Umgebungen https://github.com/outflanknl/Invoke-ADLabDeployer
  • Sheepl https://github.com/SpiderLabs/sheepl
Script
Aggressor Scripts
  • https://github.com/invokethreatguy/CSASC
  • https://github.com/secgroundzero/CS-Aggressor-Scripts
  • https://github.com/Und3rf10w/Aggressor-scripts
  • https://github.com/harleyQu1nn/AggressorScripts
  • https://github.com/rasta-mouse/Aggressor-Script
  • https://github.com/RhinoSecurityLabs/Aggressor-Scripts
  • https://github.com/bluscreenofjeff/AggressorScripts
  • https://github.com/001SPARTaN/aggressor_scripts
  • https://github.com/360-A-Team/CobaltStrike-Toolset
  • https://github.com/FortyNorthSecurity/AggressorAssessor
  • https://github.com/ramen0x3f/AggressorScripts
Red-Team
  • https://github.com/FuzzySecurity/PowerShell-Suite
  • https://github.com/nettitude/Powershell
  • https://github.com/Mr-Un1k0d3r/RedTeamPowershellScripts
  • https://github.com/threatexpress/red-team-scripts
  • https://github.com/SadProcessor/SomeStuff
  • https://github.com/rvrsh3ll/Misc-Powershell-Scripts
  • https://github.com/enigma0x3/Misc-PowerShell-Stuff
  • https://github.com/ChrisTruncer/PenTestScripts
  • https://github.com/bluscreenofjeff/Scripts
  • https://github.com/xorrior/RandomPS-Scripts
  • https://github.com/xorrior/Random-CSharpTools
  • https://github.com/leechristensen/Random
  • https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/social-engineering
Tool herunterladen
  • GitHarvester wird verwendet, um Informationen von GitHub zu sammeln, z. B. mit Google Dorks. https://github.com/metac0rtex/GitHarvester
  • pwndb ist ein Python-Befehlszeilen-Tool, das den gleichnamigen Onion-Dienst nutzt, um nach geleakten Zugangsdaten zu suchen. https://github.com/davidtavarez/pwndb/
  • LinkedInt ist ein Reconnaissance-Tool für LinkedIn. https://github.com/vysecurity/LinkedInt
  • CrossLinked ist ein LinkedIn-Enumerationstool, das mithilfe von Suchmaschinen-Scraping gültige Mitarbeiternamen aus Organisationen extrahiert. https://github.com/m8r0wn/CrossLinked
  • findomain ist ein schnelles Tool zur Subdomain-Enumeration, das Certificate-Transparency-Logs und einige APIs verwendet. https://github.com/Edu4rdSHL/findomain
  • https://github.com/Mr-Un1k0d3r/MaliciousMacroGenerator
  • SCT-obfuscator ist ein Obfuskator für Cobalt-Strike-SCT-Payloads. https://github.com/Mr-Un1k0d3r/SCT-obfuscator
  • Invoke-Obfuscation ist ein PowerShell-Obfuskator. https://github.com/danielbohannon/Invoke-Obfuscation
  • Invoke-CradleCrafter ist ein Generator und Obfuskator für PowerShell-Remote-Download-Cradles. https://github.com/danielbohannon/Invoke-CradleCrafter
  • Invoke-DOSfuscation ist ein Generator für cmd.exe-Befehlsobfuskation und ein Tool zum Testen der Erkennung. https://github.com/danielbohannon/Invoke-DOSfuscation
  • morphHTA. https://github.com/vysec/morphHTA
  • Unicorn ist ein einfaches Werkzeug, das PowerShell-Downgrade-Angriffe einsetzt und Shellcode direkt in den Speicher injiziert. https://github.com/trustedsec/unicorn
  • Shellter ist ein dynamisches Shellcode-Injektionswerkzeug und der erste echte dynamische PE-Infektor überhaupt. https://www.shellterproject.com/
  • EmbedInHTML bettet beliebige Dateien in HTML ein und versteckt sie. https://github.com/Arno0x/EmbedInHTML
  • SigThief stiehlt Signaturen und erzeugt daraus eine ungültige Signatur. https://github.com/secretsquirrel/SigThief
  • Veil, https://github.com/Veil-Framework/Veil
  • CheckPlease ist ein mit PowerShell, Python, Go, Ruby, C, C#, Perl und Rust geschriebenes Sandbox-Escape-Modul. https://github.com/Arvanaghi/CheckPlease
  • Invoke-PSImage ist ein Werkzeug, das PowerShell-Skripte in die Pixel von PNG-Dateien einbettet und ausführen kann. https://github.com/peewpw/Invoke-PSImage
  • LuckyStrike ist ein auf PowerShell basierendes Dienstprogramm zum Erstellen bösartiger Office-Makrodokumente. Es ist ausschließlich für Penetrationstests oder Bildungszwecke gedacht. https://github.com/curi0usJack/luckystrike
  • ClickOnceGenerator https://github.com/Mr-Un1k0d3r/ClickOnceGenerator
  • macro_pack ist ein Werkzeug von @EmericNasi zur automatisierten Obfuskation und Erzeugung von MS-Office-Dokumenten, VBS-Skripten und anderen Formaten für Penetrationstests, Demonstrationen und Social-Engineering-Bewertungen. https://github.com/sevagas/macro_pack
  • StarFighters ist ein auf JavaScript und VBScript basierender Empire-Launcher. https://github.com/Cn33liz/StarFighters
  • nps_payload erzeugt Payloads, um grundlegende Intrusion-Detection zu umgehen. Es nutzt öffentlich präsentierte Techniken aus mehreren verschiedenen Quellen. https://github.com/trustedsec/nps_payload
  • SocialEngineeringPayloads bietet eine Reihe von Social-Engineering-Techniken und Payloads für Credential-Theft und Spear-Phishing-Angriffe. https://github.com/bhdresh/SocialEngineeringPayloads
  • Social-Engineer Toolkit ist ein Open-Source-Penetrationstest-Framework, das für Social Engineering entwickelt wurde. https://github.com/trustedsec/social-engineer-toolkit
  • phishery ist ein einfacher SSL-fähiger HTTP-Server, dessen Hauptzweck darin besteht, über die Basisauthentifizierung Phishing-Zugangsdaten zu sammeln. https://github.com/ryhanson/phishery
  • PowerShdll führt PowerShell zusammen mit rundll32 aus. Es umgeht Softwareeinschränkungen. https://github.com/p3nt4/PowerShdll
  • UltimateAppLockerByPassList dokumentiert die am häufigsten verwendeten Techniken zur Umgehung von AppLocker. https://github.com/api0cradle/UltimateAppLockerByPassList
  • ruler ermöglicht die Remote-Interaktion mit Exchange-Servern über MAPI/HTTP- oder RPC/HTTP-Protokolle. https://github.com/sensepost/ruler
  • Generate-Macro ist ein eigenständiges PowerShell-Skript, das bösartige Microsoft-Office-Dokumente mit angegebenen Payloads und Persistenzmethoden erzeugt. https://github.com/enigma0x3/Generate-Macro
  • MaliciousMacroMSBuild erzeugt bösartige Makros und führt PowerShell oder Shellcode über die MSBuild-Anwendungs-Whitelist-Umgehung aus. https://github.com/infosecn1nja/MaliciousMacroMSBuild
  • Meta Twin ist ein Datei-Ressourcen-Kloner. Es extrahiert Metadaten (einschließlich digitaler Signaturen) aus einer Datei und injiziert sie in eine andere Datei. https://github.com/threatexpress/metatwin
  • WePWNise erzeugt architekturunabhängigen VBA-Code für den Einsatz in Office-Dokumenten oder -Vorlagen und umgeht automatisch Anwendungskontrollen. https://github.com/mwrlabs/wePWNise
  • DotNetToJScript erstellt eine JScript-Datei, die .NET-v2-Assemblys aus dem Speicher lädt. https://github.com/tyranid/DotNetToJScript
  • PSAmsi ist ein Werkzeug zum Prüfen und Brechen von AMSI-Signaturen. https://github.com/cobbr/PSAmsi
  • ReflectiveDLLInjection https://github.com/stephenfewer/ReflectiveDLLInjection
  • ps1encode wird zum Erzeugen und Codieren von PowerShell-basierten Metasploit-Payloads verwendet. https://github.com/CroweCybersecurity/ps1encode
  • Worse-PDF dient zum Stehlen von Net-NTLM-Hashes von Windows-Rechnern. https://github.com/3gstudent/Worse-PDF
  • SpookFlare bietet verschiedene Ansätze zur Umgehung von Sicherheitsmaßnahmen. https://github.com/hlldz/SpookFlare
  • GreatSCT ist ein Open-Source-Projekt zur Erzeugung von Anwendungs-Whitelist-Umgehungen. https://github.com/GreatSCT/GreatSCT
  • NPS führt PowerShell aus, ohne PowerShell zu verwenden. https://github.com/Ben0xA/nps
  • Meterpreter_Paranoid_Mode.sh schützt die gestaffelten/ungestaffelten Verbindungen von Meterpreter. https://github.com/r00t-3xp10it/Meterpreter_Paranoid_Mode-SSL
  • backdoor-factory (BDF) patcht ausführbare Binärdateien mit dem vom Benutzer gewünschten Shellcode, sodass sie weiterhin normal wie vor dem Patchen ausgeführt werden. https://github.com/secretsquirrel/the-backdoor-factory
  • MacroShop ist eine Skriptsammlung, die bei der Zustellung von Payloads über Office-Makros hilft. https://github.com/khr0x40sh/MacroShop
  • UnmanagedPowerShell führt PowerShell aus nicht verwalteten Prozessen aus. https://github.com/leechristensen/UnmanagedPowerShell
  • evil-ssdp Spoof führt SSDP-Phishing-Antworten aus, um NTLM-Hashes im Netzwerk zu sammeln. Es erstellt ein gefälschtes UPNP-Gerät, das Benutzer dazu verleitet, bösartige Phishing-Webseiten aufzurufen. https://gitlab.com/initstring/evil-ssdp
  • Ebowla ist ein Framework zur Erstellung umgebungsabhängiger (environment-keyed) Payloads. https://github.com/Genetic-Malware/Ebowla
  • make-pdf ist ein eingebettetes Werkzeug zum Erstellen von PDF-Dokumenten mit eingebetteten Dateien. https://github.com/DidierStevens/DidierStevensSuite/blob/master/make-pdf-embedded.py
  • avet (AntiVirusEvasionTool) zielt mit verschiedenen Umgehungstechniken und ausführbaren Dateien auf Windows-Rechner ab. https://github.com/govolution/avet
  • EvilClippy ist ein plattformübergreifender Assistent zum Erstellen bösartiger MS-Office-Dokumente. Es kann VBA-Makros verstecken und Makros obfuskieren. Läuft unter Linux, OSX und Windows. https://github.com/outflanknl/EvilClippy
  • CallObfuscator verschleiert Windows-API-Aufrufe vor statischen Analysetools und Debuggern. https://github.com/d35ha/CallObfuscator
  • Donut ist ein Shellcode-Generierungswerkzeug, das positionsunabhängige Shellcode-Payloads aus .NET-Assemblys erstellt. Dieser Shellcode kann verwendet werden, um Assemblys in beliebige Windows-Prozesse zu injizieren. https://github.com/TheWover/donut
  • https://github.com/Marten4n6/EvilOSX
  • EggShell https://github.com/neoneggplant/EggShell

  • Rapid Attack Infrastructure (RAI) ist eine Werkzeugsammlung für Red-Team-Infrastruktur https://github.com/obscuritylabs/RAI

  • Red Baron https://github.com/byt3bl33d3r/Red-Baron

  • EvilURL erzeugt bösartige Unicode-Domains für IDN-Homograph-Angriffe und erkennt diese. https://github.com/UndeadSec/EvilURL

  • Domain Hunter prüft abgelaufene Domains, Bluecoat-Kategorisierung und Archive.org-Verlauf, um die besten Optionen für Phishing- und C2-Domains zu ermitteln. https://github.com/threatexpress/domainhunter

  • PowerDNS https://github.com/mdsecactivebreach/PowerDNS

  • Chameleon ist ein Werkzeug zur Umgehung der Proxy-Kategorisierung. https://github.com/mdsecactivebreach/Chameleon

  • CatMyFish https://github.com/Mr-Un1k0d3r/CatMyFish

  • Malleable C2 C2-Profile https://github.com/rsmudge/Malleable-C2-Profiles

  • Malleable-C2-Randomizer https://github.com/bluscreenofjeff/Malleable-C2-Randomizer

  • FindFrontableDomains sucht nach potenziell frontbaren Domains. https://github.com/rvrsh3ll/FindFrontableDomains

  • Postfix-Server-Setup für den schnellen Aufbau eines Phishing-Servers https://github.com/n0pe-sled/Postfix-Server-Setup

  • DomainFrontingLists ist eine Liste verfügbarer CDN-Fronting-Domains https://github.com/vysec/DomainFrontingLists

  • Apache2-Mod-Rewrite-Setup für C2-Redirects https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup

  • mod_rewrite rule zur Sandbox-Umgehung https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10

  • external_c2 framework ist ein in Python geschriebenes External C2. https://github.com/Und3rf10w/external_c2_framework

  • Malleable-C2-Profiles https://www.cobaltstrike.com/. https://github.com/xx0hcd/Malleable-C2-Profiles

  • ExternalC2 https://github.com/ryhanson/ExternalC2

  • cs2modrewrite https://github.com/threatexpress/cs2modrewrite

  • e2modrewrite https://github.com/infosecn1nja/e2modrewrite

  • redi richtet Cobalt-Strike-Redirects ein https://github.com/taherio/redi

  • cat-sites ist eine Bibliothek von Websites zur Kategorisierung. https://github.com/audrummer15/cat-sites

  • ycsm für die schnelle Einrichtung eines nginx-Reverse-Proxys https://github.com/infosecn1nja/ycsm

  • Domain Fronting Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting

  • DomainFrontDiscover https://github.com/peewpw/DomainFrontDiscover

  • Automated Empire Infrastructure https://github.com/bneg/RedTeam-Automation

  • Serving Random Payloads mit NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9

  • meek https://github.com/arlolra/meek

  • CobaltStrike-ToolKit CS-Skripte https://github.com/killswitch-GUI/CobaltStrike-ToolKit

  • mkhtaccess_red erzeugt automatisch HTaccess für die Payload-Zustellung – extrahiert automatisch IPs/Netze usw. von zuvor gesehenen Sandbox-Unternehmen/-Quellen und leitet sie auf gutartige Payloads um. https://github.com/violentlydave/mkhtaccess_red

  • RedFile Payload-Dienst https://github.com/outflanknl/RedFile

  • keyserver https://github.com/leoloobeek/keyserver

  • DoHC2 https://github.com/SpiderLabs/DoHC2

  • HTran https://github.com/HiwinCN/HTran

  • DomainPasswordSpray https://github.com/dafthack/DomainPasswordSpray
  • WMIOps https://github.com/ChrisTruncer/WMIOps
  • Mimikatz https://github.com/gentilkiwi/mimikatz
  • LaZagne https://github.com/AlessandroZ/LaZagne
  • mimipenguin sammelt Linux-Passwörter https://github.com/huntergregal/mimipenguin
  • PsExec https://docs.microsoft.com/en-us/sysinternals/downloads/psexec
  • KeeThief https://github.com/HarmJ0y/KeeThief
  • PSAttack https://github.com/jaredhaight/PSAttack
  • Internal Monologue Attack ruft NTLM-Hashes ab, ohne LSASS zu berühren. https://github.com/eladshamir/Internal-Monologue
  • Impacket ist eine Python-Werkzeugsammlung https://github.com/CoreSecurity/impacket
  • icebreaker beschafft Klartext-Active-Directory-Anmeldedaten, wenn Sie sich in einem internen Netzwerk, aber außerhalb der AD-Umgebung befinden. https://github.com/DanMcInerney/icebreaker
  • Living Off The Land Binaries and Scripts (and now also Libraries) https://github.com/api0cradle/LOLBAS
  • WSUSpendu https://github.com/AlsidOfficial/WSUSpendu
  • Evilgrade https://github.com/infobyte/evilgrade
  • NetRipper ist ein Post-Exploitation-Werkzeug für Windows-Systeme, das API-Hooks verwendet, um Netzwerkverkehr und verschlüsselungsbezogene Funktionen von Benutzern mit geringen Rechten abzufangen und so Klartext- und verschlüsselten Datenverkehr vor der Verschlüsselung bzw. nach der Entschlüsselung zu erfassen. https://github.com/NytroRST/NetRipper
  • LethalHTA ist eine Lateral-Movement-Technik mit DCOM und HTA. https://github.com/codewhitesec/LethalHTA
  • Invoke-PowerThIEf https://github.com/nettitude/Invoke-PowerThIEf
  • RedSnarf https://github.com/nccgroup/redsnarf
  • HoneypotBuster ist ein für Red Teams entwickeltes Microsoft-PowerShell-Modul, das zum Auffinden von Honeypots und Token im Netzwerk oder auf Hosts verwendet werden kann. https://github.com/JavelinNetworks/HoneypotBuster
  • PAExec startet Windows-Programme auf entfernten Windows-Rechnern, ohne dass zuvor Software auf dem entfernten Rechner installiert werden muss. https://www.poweradmin.com/paexec/
  • https://github.com/machosec/Mystique
  • Rubeus https://github.com/GhostPack/Rubeus
  • kekeo https://github.com/gentilkiwi/kekeo
  • https://github.com/WazeHell/PE-Linux Linux-Privilege-Escalation-Werkzeug
  • https://guif.re/linuxeop Sammlung von Linux-Privilege-Escalation-Befehlen
  • https://github.com/sam-b/CVE-2014-4113 nutzt die Win32k.sys-Kernel-Schwachstelle zur Privilege Escalation, ms14-058
  • https://github.com/breenmachine/RottenPotatoNG nutzt NBNS-Local-Domain-Spoofing und WPAD-Proxy-Spoofing zur Privilege Escalation
  • https://github.com/unamer/CVE-2018-8120 betrifft die Win32k-Komponente, Privilege Escalation für Win7 und Win2008
  • https://github.com/alpha1ab/CVE-2018-8120 erweitert die Unterstützung zusätzlich zu Win7 und Win2k8 um WinXP und Win2k3
  • https://github.com/0xbadjuju/Tokenvator Werkzeug zur Rechteerweiterung mithilfe von Windows-Tokens, bietet eine interaktive Befehlszeilenoberfläche