Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
Awesome-Red-Team-Operations — Kuratierte Sammlung von Red-Team- und Pentest-Tools, gruppiert nach Phase: Payloads, AMSI-Bypasses, Pivoting, Persistenz, Privilege Escalation, Credential-Harvesting und Exfiltration. | Kitploit
Tools/GitHubGitHub/joasasantos/awesome-red-team-operations
Phishing-ToolsPrivilege EscalationSchwachstellenscannerExploitationDatenexfiltrationInformationsbeschaffungPost-ExploitationPenetrationstestsCommand and Control

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Red Teaming
Kuratierte Ressourcen
Payload-Entwicklung
GitHubjoasasantos/awesome-red-team-operations

Awesome-Red-Team-Operations

Kuratierte Sammlung von Red-Team- und Pentest-Tools, gruppiert nach Phase: Payloads, AMSI-Bypasses, Pivoting, Persistenz, Privilege Escalation, Credential-Harvesting und Exfiltration.

Repository anzeigen
1.7k331vor 4 JahrenVon Kitploit geprüft

Awesome Red-Team-Operation

PenTest- und Red-Team-Tools von Joas und S3cur3Th1sSh1t

PowerShell-Skripte

  • https://github.com/S3cur3Th1sSh1t/WinPwn

  • https://github.com/dafthack/MailSniper

  • https://github.com/putterpanda/mimikittenz

  • https://github.com/dafthack/DomainPasswordSpray

  • https://github.com/mdavis332/DomainPasswordSpray

  • https://github.com/jnqpblc/SharpSpray

  • https://github.com/Arvanaghi/SessionGopher

  • https://github.com/samratashok/nishang

  • https://github.com/PowerShellMafia/PowerSploit

  • https://github.com/fdiskyou/PowerOPS

  • https://github.com/giMini/PowerMemory

  • https://github.com/Kevin-Robertson/Inveigh

  • https://github.com/MichaelGrafnetter/DSInternals

  • https://github.com/PowerShellEmpire/PowerTools

  • https://github.com/FuzzySecurity/PowerShell-Suite

  • https://github.com/hlldz/Invoke-Phant0m

  • https://github.com/leoloobeek/LAPSToolkit

  • https://github.com/n00py/LAPSDumper

  • https://github.com/sense-of-security/ADRecon

  • https://github.com/adrecon/ADRecon

  • https://github.com/S3cur3Th1sSh1t/Grouper

  • https://github.com/l0ss/Grouper2

  • https://github.com/NetSPI/PowerShell

  • https://github.com/NetSPI/PowerUpSQL

  • https://github.com/GhostPack

  • https://github.com/Kevin-Robertson/Powermad

AMSI-Bypass

  • https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell

  • https://github.com/Flangvik/AMSI.fail

  • https://github.com/p3nt4/PowerShdll

  • https://github.com/jaredhaight/PSAttack

  • https://github.com/Cn33liz/p0wnedShell

  • https://github.com/cobbr/InsecurePowerShell

  • https://github.com/bitsadmin/nopowershell

  • https://github.com/Mr-Un1k0d3r/PowerLessShell

  • https://github.com/OmerYa/Invisi-Shell

  • https://github.com/Hackplayers/Salsa-tools

  • https://github.com/padovah4ck/PSByPassCLM

  • https://github.com/rasta-mouse/AmsiScanBufferBypass

  • https://github.com/itm4n/VBA-RunPE

  • https://github.com/cfalta/PowerShellArmoury

  • https://github.com/Mr-B0b/SpaceRunner

  • https://github.com/RythmStick/AMSITrigger

  • https://github.com/rmdavy/AMSI_Ordinal_Bypass

  • https://github.com/mgeeky/Stracciatella

Payload-Hosting

  • https://github.com/kgretzky/pwndrop

  • https://github.com/sc0tfree/updog

Netzwerkfreigaben-Scanner

  • https://github.com/SnaffCon/Snaffler

  • https://github.com/djhohnstein/SharpShares

  • https://github.com/vivami/SauronEye

  • https://github.com/leftp/VmdkReader

Reverse-Shells

  • https://github.com/xct/xc

  • https://github.com/cytopia/pwncat

  • https://github.com/Kudaes/LOLBITS

Backdoor-Finder

  • https://github.com/linuz/Sticky-Keys-Slayer

  • https://github.com/ztgrace/sticky_keys_hunter

  • https://github.com/countercept/doublepulsar-detection-script

Pivoting

  • https://github.com/0x36/VPNPivot

  • https://github.com/securesocketfunneling/ssf

  • https://github.com/p3nt4/Invoke-SocksProxy

  • https://github.com/sensepost/reGeorg

  • https://github.com/hayasec/reGeorg-Weblogic

  • https://github.com/nccgroup/ABPTTS

  • https://github.com/RedTeamOperations/PivotSuite

  • https://github.com/trustedsec/egressbuster

  • https://github.com/vincentcox/bypass-firewalls-by-DNS-history

  • https://github.com/shantanu561993/SharpChisel

  • https://github.com/jpillora/chisel

  • https://github.com/esrrhs/pingtunnel

  • https://github.com/sysdream/ligolo

  • https://github.com/nccgroup/SocksOverRDP

  • https://github.com/blackarrowsec/mssqlproxy

Persistenz unter Windows

  • https://github.com/fireeye/SharPersist

  • https://github.com/outflanknl/SharpHide

  • https://github.com/HarmJ0y/DAMP

Framework-Erkennung

  • https://github.com/Tuhinshubhra/CMSeeK

  • https://github.com/Dionach/CMSmap - Wordpress-, Joomla- und Drupal-Scanner

  • https://github.com/wpscanteam/wpscan

  • https://github.com/Ekultek/WhatWaf

  • https://github.com/KingOfBugbounty/KingOfBugBountyTips

Framework-Scanner / Exploitation

  • https://github.com/wpscanteam/wpscan - Wordpress

  • https://github.com/n00py/WPForce

  • https://github.com/m4ll0k/WPSeku https://github.com/swisskyrepo/Wordpresscan

  • https://github.com/rastating/wordpress-exploit-framework

  • https://github.com/coldfusion39/domi-owned - Lotus Domino

  • https://github.com/droope/droopescan - Drupal

  • https://github.com/whoot/Typo-Enumerator - Typo3

  • https://github.com/rezasp/joomscan - Joomla

Datei / Verzeichnis / Parameter-Erkennung

  • https://github.com/OJ/gobuster

  • https://github.com/nccgroup/dirble

  • https://github.com/maK-/parameth

  • https://github.com/devanshbatham/ParamSpider - Sammelt Parameter aus dunklen Ecken von Web-Archiven

  • https://github.com/s0md3v/Arjun - 💗

  • https://github.com/Cillian-Collins/dirscraper - Verzeichnis-Suche aus JavaScript-Dateien

  • https://github.com/hannob/snallygaster

  • https://github.com/maurosoria/dirsearch

  • https://github.com/s0md3v/Breacher - Admin-Panel-Finder

  • https://github.com/mazen160/server-status_PWN

  • https://github.com/helviojunior/turbosearch

REST-API-Audit

  • https://github.com/microsoft/restler-fuzzer - RESTler ist das erste zustandsbehaftete REST-API-Fuzzing-Tool zum automatischen Testen von Cloud-Diensten über ihre REST-APIs und zum Auffinden von Sicherheits- und Zuverlässigkeitsfehlern in diesen Diensten.

  • https://github.com/flipkart-incubator/Astra

Windows Privilege Escalation / Audit

  • https://github.com/itm4n/PrivescCheck - Skript zur Enumeration von Privilege Escalation für Windows

  • https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS - leistungsfähiges Privilege-Escalation-Prüfskript mit schöner Ausgabe

  • https://github.com/AlessandroZ/BeRoot

  • https://github.com/rasta-mouse/Sherlock

  • https://github.com/hfiref0x/UACME - UAC

  • https://github.com/rootm0s/WinPwnage - UAC

  • https://github.com/abatchy17/WindowsExploits

  • https://github.com/dafthack/HostRecon

  • https://github.com/sensepost/rattler - findet anfällige DLLs für Preloading-Angriffe

  • https://github.com/WindowsExploits/Exploits

  • https://github.com/Cybereason/siofra - DLL-Hijack-Scanner

  • https://github.com/0xbadjuju/Tokenvator - admin zu system

  • https://github.com/MojtabaTajik/Robber

  • https://github.com/411Hall/JAWS

  • https://github.com/GhostPack/SharpUp

  • https://github.com/GhostPack/Seatbelt

  • https://github.com/A-mIn3/WINspect

LinkedIn

  • https://www.linkedin.com/in/joas-antonio-dos-santos

Windows-Privilegienmissbrauch (Privilege Escalation)

  • https://github.com/gtworek/Priv2Admin - Windows-Privilegien missbrauchen

  • https://github.com/itm4n/UsoDllLoader - lädt schädliche DLLs aus system32

  • https://github.com/TsukiCTF/Lovely-Potato - Potato-Exploits mit Automatisierung ausnutzen

  • https://github.com/antonioCoco/RogueWinRM - vom Dienstkonto zum System

  • https://github.com/antonioCoco/RoguePotato - Eine weitere lokale Windows-Privilege-Escalation vom Dienstkonto zum System

  • https://github.com/itm4n/PrintSpoofer - Missbrauch von Identitätswechsel-Privilegien unter Windows 10 und Server 2019

  • https://github.com/BeichenDream/BadPotato - itm4ns Printspoofer in C#

  • https://github.com/itm4n/FullPowers - Stellt den Standard-Privilegiensatz eines LOCAL/NETWORK SERVICE-Kontos wieder her

Exfiltration

  • https://github.com/gentilkiwi/mimikatz

  • https://github.com/GhostPack/SafetyKatz

  • https://github.com/Flangvik/BetterSafetyKatz - Fork von SafetyKatz, der dynamisch die neueste vorkompilierte Version von Mimikatz direkt aus dem gentilkiwi GitHub-Repo lädt, Signaturen zur Laufzeit patcht und SharpSploit DInvoke nutzt, um PE in den Speicher zu laden.

  • https://github.com/GhostPack/Rubeus

  • https://github.com/Arvanaghi/SessionGopher

  • https://github.com/peewpw/Invoke-WCMDump

  • https://github.com/tiagorlampert/sAINT

  • https://github.com/AlessandroZ/LaZagneForensic - Remote-LaZagne

  • https://github.com/eladshamir/Internal-Monologue

  • https://github.com/djhohnstein/SharpWeb - Sammeln von Browser-Anmeldedaten

  • https://github.com/moonD4rk/HackBrowserData - hack-browser-data ist ein Open-Source-Tool, mit dem du Daten [Passwörter|Lesezeichen|Cookies|Verlauf] aus dem Browser entschlüsseln kannst.

  • https://github.com/mwrlabs/SharpClipHistory - Die ClipHistory-Funktion ruft die letzten 25 Kopier-/Einfüge-Aktionen ab.

  • https://github.com/outflanknl/Dumpert - Dumpt LSASS mithilfe direkter Systemaufrufe und API-Unhooking

  • https://github.com/b4rtik/SharpMiniDump - Erstellt einen Minidump des LSASS-Prozesses aus dem Speicher - mithilfe von Dumpert

Staging

  • Rapid Attack Infrastructure (RAI) Red-Team-Infrastruktur ... Schnell ... Flott ... Vereinfacht. Eine der mühsamsten Phasen einer Red-Team-Operation ist normalerweise der Aufbau der Infrastruktur. Dies umfasst in der Regel einen Teamserver oder Controller, Domains, Redirectoren und einen Phishing-Server. https://github.com/obscuritylabs/RAI

  • Red Baron ist eine Sammlung von Modulen und benutzerdefinierten/Third-Party-Providern für Terraform, die versucht, die Erstellung von widerstandsfähiger, wegwerfbarer, sicherer und agiler Infrastruktur für Red Teams zu automatisieren. https://github.com/byt3bl33d3r/Red-Baron

  • EvilURL generiert Unicode-Bösewicht-Domains für IDN-Homograph-Angriffe und erkennt diese. https://github.com/UndeadSec/EvilURL

  • Domain Hunter prüft abgelaufene Domains, Bluecoat-Kategorisierung und die Archive.org-Verlauf, um gute Kandidaten für Phishing- und C2-Domainnamen zu ermitteln. https://github.com/threatexpress/domainhunter

  • PowerDNS ist ein einfacher Proof of Concept, der die Ausführung von PowerShell-Skripten nur über DNS demonstriert. https://github.com/mdsecactivebreach/PowerDNS

  • Chameleon ist ein Tool zur Umgehung der Proxy-Kategorisierung. https://github.com/mdsecactivebreach/Chameleon

  • CatMyFish durchsucht nach kategorisierten Domains, die bei Red-Teaming-Einsätzen verwendet werden können. Perfekt, um eine Whitelisted-Domain für dein Cobalt-Strike-Beacon-C&C einzurichten. https://github.com/Mr-Un1k0d3r/CatMyFish

  • Malleable C2 ist eine domänenspezifische Sprache, um Indikatoren in der Beacon-Kommunikation neu zu definieren. https://github.com/rsmudge/Malleable-C2-Profiles

  • Malleable-C2-Randomizer: Dieses Skript randomisiert Cobalt-Strike-Malleable-C2-Profile mithilfe einer Metasprache, in der Hoffnung, die Chancen zu verringern, signaturbasierte Erkennungskontrollen auszulösen. https://github.com/bluscreenofjeff/Malleable-C2-Randomizer

Buffer Overflow und Exploit-Entwicklung

  • https://github.com/CyberSecurityUP/Buffer-Overflow-Labs

  • https://github.com/gh0x0st/Buffer_Overflow

  • https://github.com/freddiebarrsmith/Buffer-Overflow-Exploit-Development-Practice

  • https://github.com/21y4d/Windows_BufferOverflowx32

  • https://github.com/johnjhacking/Buffer-Overflow-Guide

  • https://github.com/npapernot/buffer-overflow-attack

  • https://github.com/V1n1v131r4/OSCP-Buffer-Overflow

  • https://github.com/KINGSABRI/BufferOverflow-Kit

  • https://github.com/FabioBaroni/awesome-exploit-development

  • https://github.com/Gallopsled/pwntools

  • https://github.com/hardenedlinux/linux-exploit-development-tutorial

  • https://github.com/Billy-Ellis/Exploit-Challenges

  • https://github.com/wtsxDev/Exploit-Development

MindMaps von Joas

  • https://www.mindmeister.com/pt/1746180947/web-attacks-bug-bounty-and-appsec-by-joas-antonio

  • https://www.mindmeister.com/pt/1760781948/information-security-certifications-by-joas-antonio

  • https://www.mindmeister.com/pt/1781013629/the-best-labs-and-ctf-red-team-and-pentest

  • https://www.mindmeister.com/pt/1760781948/information-security-certifications-by-joas-antonio

  • https://www.mindmeister.com/pt/1746187693/cyber-security-career-knowledge-by-joas-antonio

Lateral Movement

  • https://github.com/0xthirteen/SharpRDP

  • https://github.com/0xthirteen/MoveKit

  • https://github.com/0xthirteen/SharpMove

  • https://github.com/rvrsh3ll/SharpCOM

  • https://github.com/malcomvetter/CSExec

  • https://github.com/byt3bl33d3r/CrackMapExec

  • https://github.com/cube0x0/SharpMapExec

  • https://github.com/nccgroup/WMIcmd

  • https://github.com/rasta-mouse/MiscTools

  • https://github.com/byt3bl33d3r/DeathStar

  • https://github.com/SpiderLabs/portia

  • https://github.com/Screetsec/Vegile

  • https://github.com/DanMcInerney/icebreaker

  • https://github.com/MooseDojo/apt2

  • https://github.com/hdm/nextnet

  • https://github.com/mubix/IOXIDResolver

  • https://github.com/Hackplayers/evil-winrm

  • https://github.com/bohops/WSMan-WinRM

  • https://github.com/dirkjanm/krbrelayx

Post-Exploitation

  • https://github.com/mubix/post-exploitation

  • https://github.com/emilyanncr/Windows-Post-Exploitation

  • https://github.com/nettitude/Invoke-PowerThIEf

  • https://github.com/ThunderGunExpress/BADministration

  • https://github.com/bohops/SharpRDPHijack

  • https://github.com/antonioCoco/RunasCs

  • https://github.com/klsecservices/Invoke-Vnc

  • https://github.com/mandatoryprogrammer/CursedChrome

  • https://github.com/djhohnstein/WireTap

  • https://github.com/GhostPack/Lockless

  • https://github.com/infosecn1nja/SharpDoor

  • Phishing-Tools

  • https://github.com/hlldz/pickl3

  • https://github.com/shantanu561993/SharpLoginPrompt

  • https://github.com/Dviros/CredsLeaker

  • https://github.com/bitsadmin/fakelogonscreen

  • https://github.com/CCob/PinSwipe

Wrapper für verschiedene Tools

  • https://github.com/bohops/GhostBuild

  • https://github.com/S3cur3Th1sSh1t/PowerSharpPack

  • https://github.com/rvrsh3ll/Rubeus-Rundll32- https://github.com/checkymander/Zolom

Active Directory – Audit- und Exploit-Tools

  • https://github.com/mwrlabs/SharpGPOAbuse

  • https://github.com/BloodHoundAD/BloodHound

  • https://github.com/BloodHoundAD/SharpHound3

  • https://github.com/chryzsh/awesome-bloodhound

  • https://github.com/hausec/Bloodhound-Custom-Queries

  • https://github.com/CompassSecurity/BloodHoundQueries

  • https://github.com/vletoux/pingcastle

  • https://github.com/cyberark/ACLight

  • https://github.com/canix1/ADACLScanner

  • https://github.com/fox-it/Invoke-ACLPwn

  • https://github.com/NinjaStyle82/rbcd_permissions

  • https://github.com/NotMedic/NetNTLMtoSilverTicket

  • https://github.com/dirkjanm/ldapdomaindump

Web-Schwachstellenscanner / Burp-Plugins

  • https://github.com/m4ll0k/WAScan – All-in-One-Scanner

  • https://github.com/s0md3v/XSStrike – XSS-Erkennung

  • https://github.com/federicodotta/Java-Deserialization-Scanner

  • https://github.com/d3vilbug/HackBar

  • https://github.com/gyoisamurai/GyoiThon

  • https://github.com/snoopysecurity/awesome-burp-extensions

  • https://github.com/sting8k/BurpSuite_403Bypasser – Burpsuite-Erweiterung zur Umgehung eingeschränkter 403-Verzeichnisse

  • https://github.com/BishopFox/GadgetProbe

Web-Exploitation-Tools

  • https://github.com/OsandaMalith/LFiFreak – LFI

  • https://github.com/enjoiz/XXEinjector – XXE

  • https://github.com/tennc/webshell – Webshells

  • https://github.com/flozz/p0wny-shell

  • https://github.com/epinna/tplmap – SSTI

  • https://github.com/orf/xcat – XPath-Injektion

  • https://github.com/almandin/fuxploider – Datei-Uploads

  • https://github.com/nccgroup/freddy – Deserialisierung

  • https://github.com/irsdl/IIS-ShortName-Scanner – Ausnutzung der IIS-Kurznamen-Schwachstelle

  • https://github.com/frohoff/ysoserial – Ausnutzung der Java-Deserialisierung

  • https://github.com/pwntester/ysoserial.net – Ausnutzung der .NET-Deserialisierung

  • https://github.com/internetwache/GitTools – Ausnutzung vorhandener .git-Ordner

  • https://github.com/cujanovic/SSRF-Testing – SSRF-Tutorials

  • https://github.com/ambionics/phpggc – PHP-Unserialize-Payload-Generator

  • https://github.com/BuffaloWill/oxml_xxe – Generator für schädliche Office-XXE-Payloads

  • https://github.com/tijme/angularjs-csti-scanner – AngularJS-CSTI-Scanner

Linux Privilege Escalation / Audit

  • https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS – leistungsfähiges Privilege-Escalation-Prüfskript mit übersichtlicher Ausgabe

  • https://github.com/mzet-/linux-exploit-suggester

  • https://github.com/rebootuser/LinEnum

  • https://github.com/diego-treitos/linux-smart-enumeration

  • https://github.com/CISOfy/lynis

  • https://github.com/AlessandroZ/BeRoot

  • https://github.com/future-architect/vuls

  • https://github.com/ngalongc/AutoLocalPrivilegeEscalation

  • https://github.com/b3rito/yodo

  • https://github.com/belane/linux-soft-exploit-suggester – nach anfälliger installierter Software suchen

  • https://github.com/sevagas/swap_digger

  • https://github.com/NullArray/RootHelper

  • https://github.com/NullArray/MIDA-Multitool

  • https://github.com/initstring/dirty_sock

  • https://github.com/jondonas/linux-exploit-suggester-2

  • https://github.com/sosdave/KeyTabExtract

Command and Control

  • Cobalt Strike ist eine Software für Adversary-Simulationen und Red-Team-Operationen. https://cobaltstrike.com/

  • Empire ist ein Post-Exploitation-Framework, das einen reinen PowerShell-2.0-Agenten für Windows sowie einen reinen Python-2.6/2.7-Agenten für Linux/OS X enthält. https://github.com/EmpireProject/Empire

  • Das Metasploit Framework ist ein Computersicherheitsprojekt, das Informationen über Sicherheitslücken bereitstellt und bei Penetrationstests sowie der Entwicklung von IDS-Signaturen hilft. https://github.com/rapid7/metasploit-framework

  • SILENTTRINITY ist ein Post-Exploitation-Agent, der auf Python, IronPython, C#/.NET basiert. https://github.com/byt3bl33d3r/SILENTTRINITY

  • Pupy ist ein Open-Source-, plattformübergreifendes (Windows, Linux, OSX, Android) Remote-Administrations- und Post-Exploitation-Tool, das hauptsächlich in Python geschrieben ist. https://github.com/n1nj4sec/pupy

  • Koadic, auch als COM Command & Control bekannt, ist ein Windows-Post-Exploitation-Rootkit, das anderen Penetrationstest-Tools wie Meterpreter und Powershell Empire ähnelt. https://github.com/zerosum0x0/koadic

  • PoshC2 ist ein proxy-bewusstes C2-Framework, das vollständig in PowerShell geschrieben ist und Penetrationstestern bei Red Teaming, Post-Exploitation und Lateral Movement hilft. https://github.com/nettitude/PoshC2_Python

  • Gcat ist eine heimliche, auf Python basierende Backdoor, die Gmail als Command-and-Control-Server nutzt. https://github.com/byt3bl33d3r/gcat

  • TrevorC2 ist eine legitime (durchsuchbare) Website, die Client/Server-Kommunikation für verdeckte Befehlsausführung tunnelt. https://github.com/trustedsec/trevorc2

  • Merlin ist ein plattformübergreifender Post-Exploitation-HTTP/2-Command-&-Control-Server und -Agent, der in Go geschrieben ist. https://github.com/Ne0nd0g/merlin

  • Quasar ist ein schnelles und leichtgewichtiges Remote-Administration-Tool, das in C# programmiert ist. Mit hoher Stabilität und einer benutzerfreundlichen Oberfläche ist Quasar die perfekte Remote-Administrationslösung für Sie.

Adversary-Emulation

  • MITRE CALDERA – Ein automatisiertes Adversary-Emulationssystem, das Post-Compromise-Adversary-Verhalten in Windows-Enterprise-Netzwerken ausführt. https://github.com/mitre/caldera

  • APTSimulator – Ein Windows-Batch-Skript, das eine Reihe von Tools und Ausgabedateien verwendet, um ein System so aussehen zu lassen, als wäre es kompromittiert. https://github.com/NextronSystems/APTSimulator

  • Atomic Red Team – Kleine und hochportable Erkennungstests, die dem Mitre ATT&CK Framework zugeordnet sind. https://github.com/redcanaryco/atomic-red-team

  • Network Flight Simulator – flightsim ist ein leichtgewichtiges Dienstprogramm, das verwendet wird, um bösartigen Netzwerkverkehr zu erzeugen und Sicherheitsteams dabei zu helfen, Sicherheitskontrollen und Netzwerksichtbarkeit zu bewerten. https://github.com/alphasoc/flightsim

  • Metta – Ein Tool zur Sicherheitsvorbereitung für die Durchführung von Adversary-Simulationen. https://github.com/uber-common/metta

  • Red Team Automation (RTA) – RTA bietet ein Framework aus Skripten, das es Blue Teams ermöglicht, ihre Erkennungsfähigkeiten gegen bösartige Tradecrafts zu testen, angelehnt an MITRE ATT&CK. https://github.com/endgameinc/RTA

Repositories

  • https://github.com/infosecn1nja/Red-Teaming-Toolkit

  • https://github.com/S3cur3Th1sSh1t/Pentest-Tools

  • https://github.com/yeyintminthuhtut/Awesome-Red-Teaming

  • https://github.com/enaqx/awesome-pentest

  • https://github.com/Muhammd/Awesome-Pentest

  • https://github.com/CyberSecurityUP/Awesome-PenTest-Practice

  • https://drive.google.com/drive/u/0/folders/12Mvq6kE2HJDwN2CZhEGWizyWt87YunkU

  • https://github.com/0x4D31/awesome-oscp

  • https://github.com/six2dez/OSCP-Human-Guide

  • https://github.com/RustyShackleford221/OSCP-Prep

  • https://github.com/wwong99/pentest-notes/blob/master/oscp_resources/OSCP-Survival-Guide.md

Malware-Analyse und Reverse Engineering

  • https://github.com/rshipp/awesome-malware-analysis

  • https://github.com/topics/malware-analysis

  • https://github.com/Apress/malware-analysis-detection-engineering

  • https://github.com/SpiderLabs/malware-analysis

  • https://github.com/ytisf/theZoo

  • https://github.com/arxlan786/Malware-Analysis

  • https://github.com/nheijmans/malzoo

  • https://github.com/mikesiko/PracticalMalwareAnalysis-Labs

  • https://github.com/secrary/SSMA

  • https://github.com/merces/aleph

  • https://github.com/mentebinaria/retoolkit

  • https://github.com/mytechnotalent/Reverse-Engineering

  • https://github.com/wtsxDev/reverse-engineering

  • https://github.com/mentebinaria/retoolkit

  • https://github.com/topics/reverse-engineering

  • https://github.com/0xZ0F/Z0FCourse_ReverseEngineering

  • https://github.com/NationalSecurityAgency/ghidra

Tool herunterladen
  • https://github.com/med0x2e/NoAmci

  • https://github.com/rvrsh3ll/NoMSBuild

  • https://github.com/bohops/UltimateWDACBypassList

  • https://github.com/jxy-s/herpaderping

  • https://github.com/Cn33liz/MSBuildShell

  • https://github.com/hausec/ADAPE-Script

  • https://github.com/SecWiki/windows-kernel-exploits

  • https://github.com/bitsadmin/wesng

  • https://github.com/rasta-mouse/Watson

  • https://github.com/b4rtik/ATPMiniDump - Umgeht den Credential-Diebstahl von WinDefender ATP

  • https://github.com/aas-n/spraykatz - entferntes procdump.exe, kopiert die Dump-Datei auf das lokale System und nutzt pypykatz zur Analyse/Extraktion

  • https://github.com/0x09AL/RdpThief - extrahiert Live-RDP-Anmeldungen

  • https://github.com/chrismaddalena/SharpCloud - Einfacher C#-Code zum Prüfen, ob Credential-Dateien für AWS, Microsoft Azure und Google Compute vorhanden sind.

  • https://github.com/djhohnstein/SharpChromium - .NET-4.0-CLR-Projekt zum Abrufen von Chromium-Daten wie Cookies, Verlauf und gespeicherten Anmeldungen.

  • https://github.com/jfmaes/SharpHandler - Dieses Projekt nutzt offene Handles auf LSASS erneut, um LSASS zu parsen oder einen Minidump zu erstellen.

  • https://github.com/V1V1/SharpScribbles - ThunderFox für Firefox-Anmeldedaten, SitkyNotesExtract für "Notizen als Passwörter"

  • https://github.com/securesean/DecryptAutoLogon - Kommandozeilen-Tool zum Extrahieren/Entschlüsseln des Passworts, das von SysInternals AutoLogon in der LSA gespeichert wurde.

  • https://github.com/G0ldenGunSec/SharpSecDump - .NET-Port der Remote-SAM- und LSA-Secrets-Dumping-Funktionalität von impackets secretsdump.py

  • https://github.com/EncodeGroup/Gopher - C#-Tool zum Auffinden von Low Hanging Fruits wie SessionGopher

  • https://github.com/GhostPack/SharpDPAPI - DPAPI-Anmeldedaten per C#

  • LSASS-Dump ohne Mimikatz

  • https://github.com/Hackndo/lsassy

  • https://github.com/aas-n/spraykatz

  • https://github.com/b4rtik/SharpKatz - C#-Portierung der Mimikatz-Befehle sekurlsa::logonpasswords, sekurlsa::ekeys und lsadump::dcsync

  • Credential-Harvesting (Linux-spezifisch)

  • https://github.com/huntergregal/mimipenguin

  • https://github.com/n1nj4sec/mimipy

  • https://github.com/dirtycow/dirtycow.github.io

  • https://github.com/mthbernardes/sshLooterC - SSH-Credential-Loot

  • https://github.com/blendin/3snake - SSH-/Sudo-/SU-Credential-Loot

  • https://github.com/0xmitsurugi/gimmecredz

  • https://github.com/TarlogicSecurity/tickey - Tool zum Extrahieren von Kerberos-Tickets aus Linux-Kernel-Keys.

  • Datenexfiltration – DNS/ICMP/WLAN-Exfiltration

  • https://github.com/FortyNorthSecurity/Egress-Assess

  • https://github.com/p3nt4/Invoke-TmpDavFS

  • https://github.com/DhavalKapil/icmptunnel

  • https://github.com/iagox86/dnscat2

  • https://github.com/Arno0x/DNSExfiltrator

  • https://github.com/spieglt/FlyingCarpet - WLAN-Exfiltration

  • https://github.com/SECFORCE/Tunna - Tunna ist eine Sammlung von Tools, die jede TCP-Kommunikation über HTTP verpackt und tunnelt.

  • https://github.com/sysdream/chashell

  • https://github.com/no0be/DNSlivery - Einfache Bereitstellung von Dateien und Payloads über DNS

  • FindFrontableDomains sucht nach potenziell frontbaren Domains. https://github.com/rvrsh3ll/FindFrontableDomains

  • Postfix-Server-Setup: Das Einrichten eines Phishing-Servers ist ein sehr langer und mühsamer Prozess. Es kann Stunden dauern, und in Minuten kompromittiert werden. https://github.com/n0pe-sled/Postfix-Server-Setup

  • DomainFrontingLists ist eine Liste von Domain-Fronting-fähigen Domains nach CDN. https://github.com/vysec/DomainFrontingLists

  • Apache2-Mod-Rewrite-Setup: Implementiere Mod-Rewrite schnell in deiner Infrastruktur. https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup

  • mod_rewrite-Regel, um Vendor-Sandboxes zu umgehen. https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10

  • external_c2 framework: ein Python-Framework für die Verwendung mit Cobalt Strikes External C2. https://github.com/Und3rf10w/external_c2_framework

  • Malleable-C2-Profiles: Eine Sammlung von Profilen, die in verschiedenen Projekten mit Cobalt Strike (https://www.cobaltstrike.com/) verwendet werden. https://github.com/xx0hcd/Malleable-C2-Profiles

  • ExternalC2: eine Bibliothek zur Integration von Kommunikationskanälen mit dem Cobalt-Strike-External-C2-Server. https://github.com/ryhanson/ExternalC2

  • cs2modrewrite: ein Tool zum Konvertieren von Cobalt-Strike-Profilen in ModRewrite-Skripte. https://github.com/threatexpress/cs2modrewrite

  • e2modrewrite: ein Tool zum Konvertieren von Empire-Profilen in Apache-ModRewrite-Skripte. https://github.com/infosecn1nja/e2modrewrite

  • redi: automatisiertes Skript zum Einrichten von CobaltStrike-Redirectoren (Nginx-Reverse-Proxy, Let's Encrypt). https://github.com/taherio/redi

  • cat-sites: Bibliothek von Websites zur Kategorisierung. https://github.com/audrummer15/cat-sites

  • ycsm ist eine schnelle Skriptinstallation für einen widerstandsfähigen Redirector mit Nginx-Reverse-Proxy und Let's Encrypt, kompatibel mit einigen beliebten Post-Ex-Tools (Cobalt Strike, Empire, Metasploit, PoshC2). https://github.com/infosecn1nja/ycsm

  • Domain Fronting für Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting

  • DomainFrontDiscover: Skripte und Ergebnisse zum Auffinden von Domain-Fronting-fähigen CloudFront-Domains. https://github.com/peewpw/DomainFrontDiscover

  • Automatisierte Empire-Infrastruktur https://github.com/bneg/RedTeam-Automation

  • Ausliefern zufälliger Payloads mit NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9

  • meek ist ein blockierungsresistenter pluggable Transport für Tor. Es kodiert einen Datenstrom als eine Folge von HTTPS-Anfragen und -Antworten. https://github.com/arlolra/meek

  • CobaltStrike-ToolKit: Einige nützliche Skripte für CobaltStrike. https://github.com/killswitch-GUI/CobaltStrike-ToolKit

  • mkhtaccess_red: Automatisches Generieren einer HTaccess für die Payload-Bereitstellung – zieht automatisch IPs/Netze usw. von bekannten Sandbox-Unternehmen/Quellen, die zuvor gesehen wurden, und leitet sie auf eine harmlose Payload um. https://github.com/violentlydave/mkhtaccess_red

  • RedFile: eine Flask-WSGI-Anwendung, die Dateien intelligent ausliefert und sich gut für bedingte RedTeam-Payloads eignet. https://github.com/outflanknl/RedFile

  • keyserver: Einfaches Ausliefern von HTTP- und DNS-Keys für einen ordnungsgemäßen Payload-Schutz. https://github.com/leoloobeek/keyserver

  • DoHC2 ermöglicht die Nutzung der ExternalC2-Bibliothek von Ryan Hanson (https://github.com/ryhanson/ExternalC2) für Command and Control (C2) über DNS over HTTPS (DoH). Es wurde für die beliebte Adversary-Simulation- und Red-Team-Operations-Software Cobalt Strike (https://www.cobaltstrike.com) entwickelt. https://github.com/SpiderLabs/DoHC2

  • HTran ist ein Connection Bouncer, eine Art Proxy-Server. Ein „Listener“-Programm wird heimlich auf einen ahnungslosen Host irgendwo im Internet gehackt. https://github.com/HiwinCN/HTran

  • https://github.com/Mr-Un1k0d3r/SCShell

  • https://github.com/rvazarkar/GMSAPasswordReader

  • https://github.com/fdiskyou/hunter

  • https://github.com/360-Linton-Lab/WMIHACKER

  • https://github.com/leechristensen/SpoolSample

  • https://github.com/leftp/SpoolSamplerNET

  • https://github.com/lexfo/rpc2socks

  • https://github.com/checkymander/sshiva

  • https://github.com/dev-2null/ADCollector

  • https://github.com/0xacb/viewgen – .NET-Viewstates deserialisieren

  • https://github.com/Illuminopi/RCEvil.NET – .NET-Viewstates deserialisieren

  • https://github.com/DominicBreuker/pspy

  • https://github.com/itsKindred/modDetective

  • https://github.com/nongiach/sudo_inject

  • https://github.com/Anon-Exploiter/SUID3NUM – SUID-Binaries finden und in GTFOBins nachschlagen / ausnutzbar oder nicht

  • https://github.com/nccgroup/GTFOBLookup – Offline-GTFOBins

  • https://github.com/TH3xACE/SUDO_KILLER – Ausnutzung von sudo-Fehlkonfigurationen

  • https://raw.githubusercontent.com/sleventyeleven/linuxprivchecker/master/linuxprivchecker.py

  • https://github.com/inquisb/unix-privesc-check

  • https://github.com/hc0d3r/tas – TTY einfach manipulieren und gefälschte Binaries erstellen

  • https://github.com/SecWiki/linux-kernel-exploits

  • https://github.com/initstring/uptux

  • https://github.com/andrew-d/static-binaries – nicht wirklich Privilege Escalation, aber hilfreich

  • https://github.com/quasar/QuasarRAT
  • Covenant ist ein .NET-Command-and-Control-Framework, das darauf abzielt, die Angriffsfläche von .NET aufzuzeigen, die Nutzung offensiver .NET-Tradecrafts zu erleichtern und als kollaborative Command-and-Control-Plattform für Red Teamer zu dienen. https://github.com/cobbr/Covenant

  • FactionC2 ist ein C2-Framework, das eine auf Websockets basierende API verwendet, die die Interaktion mit Agenten und Transports ermöglicht. https://github.com/FactionC2/

  • DNScat2 ist ein Tool, das entwickelt wurde, um einen verschlüsselten Command-and-Control-Kanal (C&C) über das DNS-Protokoll zu erstellen. https://github.com/iagox86/dnscat2

  • Sliver ist ein allgemeines, plattformübergreifendes Implant-Framework, das C2 über Mutual-TLS, HTTP(S) und DNS unterstützt. https://github.com/BishopFox/sliver

  • EvilOSX ist eine bösartige RAT (Remote Administration Tool) für macOS / OS X. https://github.com/Marten4n6/EvilOSX

  • EggShell ist ein Post-Exploitation-Überwachungstool, das in Python geschrieben ist. Es bietet eine Befehlszeilensitzung mit zusätzlicher Funktionalität zwischen Ihnen und einem Zielrechner. https://github.com/neoneggplant/EggShell

  • https://github.com/hax0rtahm1d/Reverse-Engineering

  • https://github.com/tylerha97/awesome-reversing