
Kuratierte Sammlung von Red-Team- und Pentest-Tools, gruppiert nach Phase: Payloads, AMSI-Bypasses, Pivoting, Persistenz, Privilege Escalation, Credential-Harvesting und Exfiltration.
https://github.com/Dionach/CMSmap - Wordpress-, Joomla- und Drupal-Scanner
https://github.com/wpscanteam/wpscan - Wordpress
https://github.com/m4ll0k/WPSeku https://github.com/swisskyrepo/Wordpresscan
https://github.com/coldfusion39/domi-owned - Lotus Domino
https://github.com/droope/droopescan - Drupal
https://github.com/rezasp/joomscan - Joomla
https://github.com/devanshbatham/ParamSpider - Sammelt Parameter aus dunklen Ecken von Web-Archiven
https://github.com/Cillian-Collins/dirscraper - Verzeichnis-Suche aus JavaScript-Dateien
https://github.com/s0md3v/Breacher - Admin-Panel-Finder
https://github.com/microsoft/restler-fuzzer - RESTler ist das erste zustandsbehaftete REST-API-Fuzzing-Tool zum automatischen Testen von Cloud-Diensten über ihre REST-APIs und zum Auffinden von Sicherheits- und Zuverlässigkeitsfehlern in diesen Diensten.
https://github.com/itm4n/PrivescCheck - Skript zur Enumeration von Privilege Escalation für Windows
https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS - leistungsfähiges Privilege-Escalation-Prüfskript mit schöner Ausgabe
https://github.com/sensepost/rattler - findet anfällige DLLs für Preloading-Angriffe
https://github.com/Cybereason/siofra - DLL-Hijack-Scanner
https://github.com/0xbadjuju/Tokenvator - admin zu system
https://github.com/gtworek/Priv2Admin - Windows-Privilegien missbrauchen
https://github.com/itm4n/UsoDllLoader - lädt schädliche DLLs aus system32
https://github.com/TsukiCTF/Lovely-Potato - Potato-Exploits mit Automatisierung ausnutzen
https://github.com/antonioCoco/RogueWinRM - vom Dienstkonto zum System
https://github.com/antonioCoco/RoguePotato - Eine weitere lokale Windows-Privilege-Escalation vom Dienstkonto zum System
https://github.com/itm4n/PrintSpoofer - Missbrauch von Identitätswechsel-Privilegien unter Windows 10 und Server 2019
https://github.com/BeichenDream/BadPotato - itm4ns Printspoofer in C#
https://github.com/itm4n/FullPowers - Stellt den Standard-Privilegiensatz eines LOCAL/NETWORK SERVICE-Kontos wieder her
https://github.com/Flangvik/BetterSafetyKatz - Fork von SafetyKatz, der dynamisch die neueste vorkompilierte Version von Mimikatz direkt aus dem gentilkiwi GitHub-Repo lädt, Signaturen zur Laufzeit patcht und SharpSploit DInvoke nutzt, um PE in den Speicher zu laden.
https://github.com/AlessandroZ/LaZagneForensic - Remote-LaZagne
https://github.com/djhohnstein/SharpWeb - Sammeln von Browser-Anmeldedaten
https://github.com/moonD4rk/HackBrowserData - hack-browser-data ist ein Open-Source-Tool, mit dem du Daten [Passwörter|Lesezeichen|Cookies|Verlauf] aus dem Browser entschlüsseln kannst.
https://github.com/mwrlabs/SharpClipHistory - Die ClipHistory-Funktion ruft die letzten 25 Kopier-/Einfüge-Aktionen ab.
https://github.com/outflanknl/Dumpert - Dumpt LSASS mithilfe direkter Systemaufrufe und API-Unhooking
https://github.com/b4rtik/SharpMiniDump - Erstellt einen Minidump des LSASS-Prozesses aus dem Speicher - mithilfe von Dumpert
Rapid Attack Infrastructure (RAI) Red-Team-Infrastruktur ... Schnell ... Flott ... Vereinfacht. Eine der mühsamsten Phasen einer Red-Team-Operation ist normalerweise der Aufbau der Infrastruktur. Dies umfasst in der Regel einen Teamserver oder Controller, Domains, Redirectoren und einen Phishing-Server. https://github.com/obscuritylabs/RAI
Red Baron ist eine Sammlung von Modulen und benutzerdefinierten/Third-Party-Providern für Terraform, die versucht, die Erstellung von widerstandsfähiger, wegwerfbarer, sicherer und agiler Infrastruktur für Red Teams zu automatisieren. https://github.com/byt3bl33d3r/Red-Baron
EvilURL generiert Unicode-Bösewicht-Domains für IDN-Homograph-Angriffe und erkennt diese. https://github.com/UndeadSec/EvilURL
Domain Hunter prüft abgelaufene Domains, Bluecoat-Kategorisierung und die Archive.org-Verlauf, um gute Kandidaten für Phishing- und C2-Domainnamen zu ermitteln. https://github.com/threatexpress/domainhunter
PowerDNS ist ein einfacher Proof of Concept, der die Ausführung von PowerShell-Skripten nur über DNS demonstriert. https://github.com/mdsecactivebreach/PowerDNS
Chameleon ist ein Tool zur Umgehung der Proxy-Kategorisierung. https://github.com/mdsecactivebreach/Chameleon
CatMyFish durchsucht nach kategorisierten Domains, die bei Red-Teaming-Einsätzen verwendet werden können. Perfekt, um eine Whitelisted-Domain für dein Cobalt-Strike-Beacon-C&C einzurichten. https://github.com/Mr-Un1k0d3r/CatMyFish
Malleable C2 ist eine domänenspezifische Sprache, um Indikatoren in der Beacon-Kommunikation neu zu definieren. https://github.com/rsmudge/Malleable-C2-Profiles
Malleable-C2-Randomizer: Dieses Skript randomisiert Cobalt-Strike-Malleable-C2-Profile mithilfe einer Metasprache, in der Hoffnung, die Chancen zu verringern, signaturbasierte Erkennungskontrollen auszulösen. https://github.com/bluscreenofjeff/Malleable-C2-Randomizer
https://github.com/freddiebarrsmith/Buffer-Overflow-Exploit-Development-Practice
https://github.com/hardenedlinux/linux-exploit-development-tutorial
https://www.mindmeister.com/pt/1746180947/web-attacks-bug-bounty-and-appsec-by-joas-antonio
https://www.mindmeister.com/pt/1760781948/information-security-certifications-by-joas-antonio
https://www.mindmeister.com/pt/1781013629/the-best-labs-and-ctf-red-team-and-pentest
https://www.mindmeister.com/pt/1760781948/information-security-certifications-by-joas-antonio
https://www.mindmeister.com/pt/1746187693/cyber-security-career-knowledge-by-joas-antonio
Phishing-Tools
https://github.com/m4ll0k/WAScan – All-in-One-Scanner
https://github.com/s0md3v/XSStrike – XSS-Erkennung
https://github.com/federicodotta/Java-Deserialization-Scanner
https://github.com/sting8k/BurpSuite_403Bypasser – Burpsuite-Erweiterung zur Umgehung eingeschränkter 403-Verzeichnisse
https://github.com/tennc/webshell – Webshells
https://github.com/orf/xcat – XPath-Injektion
https://github.com/almandin/fuxploider – Datei-Uploads
https://github.com/nccgroup/freddy – Deserialisierung
https://github.com/irsdl/IIS-ShortName-Scanner – Ausnutzung der IIS-Kurznamen-Schwachstelle
https://github.com/frohoff/ysoserial – Ausnutzung der Java-Deserialisierung
https://github.com/pwntester/ysoserial.net – Ausnutzung der .NET-Deserialisierung
https://github.com/internetwache/GitTools – Ausnutzung vorhandener .git-Ordner
https://github.com/cujanovic/SSRF-Testing – SSRF-Tutorials
https://github.com/ambionics/phpggc – PHP-Unserialize-Payload-Generator
https://github.com/BuffaloWill/oxml_xxe – Generator für schädliche Office-XXE-Payloads
https://github.com/tijme/angularjs-csti-scanner – AngularJS-CSTI-Scanner
https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS – leistungsfähiges Privilege-Escalation-Prüfskript mit übersichtlicher Ausgabe
https://github.com/belane/linux-soft-exploit-suggester – nach anfälliger installierter Software suchen
Cobalt Strike ist eine Software für Adversary-Simulationen und Red-Team-Operationen. https://cobaltstrike.com/
Empire ist ein Post-Exploitation-Framework, das einen reinen PowerShell-2.0-Agenten für Windows sowie einen reinen Python-2.6/2.7-Agenten für Linux/OS X enthält. https://github.com/EmpireProject/Empire
Das Metasploit Framework ist ein Computersicherheitsprojekt, das Informationen über Sicherheitslücken bereitstellt und bei Penetrationstests sowie der Entwicklung von IDS-Signaturen hilft. https://github.com/rapid7/metasploit-framework
SILENTTRINITY ist ein Post-Exploitation-Agent, der auf Python, IronPython, C#/.NET basiert. https://github.com/byt3bl33d3r/SILENTTRINITY
Pupy ist ein Open-Source-, plattformübergreifendes (Windows, Linux, OSX, Android) Remote-Administrations- und Post-Exploitation-Tool, das hauptsächlich in Python geschrieben ist. https://github.com/n1nj4sec/pupy
Koadic, auch als COM Command & Control bekannt, ist ein Windows-Post-Exploitation-Rootkit, das anderen Penetrationstest-Tools wie Meterpreter und Powershell Empire ähnelt. https://github.com/zerosum0x0/koadic
PoshC2 ist ein proxy-bewusstes C2-Framework, das vollständig in PowerShell geschrieben ist und Penetrationstestern bei Red Teaming, Post-Exploitation und Lateral Movement hilft. https://github.com/nettitude/PoshC2_Python
Gcat ist eine heimliche, auf Python basierende Backdoor, die Gmail als Command-and-Control-Server nutzt. https://github.com/byt3bl33d3r/gcat
TrevorC2 ist eine legitime (durchsuchbare) Website, die Client/Server-Kommunikation für verdeckte Befehlsausführung tunnelt. https://github.com/trustedsec/trevorc2
Merlin ist ein plattformübergreifender Post-Exploitation-HTTP/2-Command-&-Control-Server und -Agent, der in Go geschrieben ist. https://github.com/Ne0nd0g/merlin
Quasar ist ein schnelles und leichtgewichtiges Remote-Administration-Tool, das in C# programmiert ist. Mit hoher Stabilität und einer benutzerfreundlichen Oberfläche ist Quasar die perfekte Remote-Administrationslösung für Sie.
MITRE CALDERA – Ein automatisiertes Adversary-Emulationssystem, das Post-Compromise-Adversary-Verhalten in Windows-Enterprise-Netzwerken ausführt. https://github.com/mitre/caldera
APTSimulator – Ein Windows-Batch-Skript, das eine Reihe von Tools und Ausgabedateien verwendet, um ein System so aussehen zu lassen, als wäre es kompromittiert. https://github.com/NextronSystems/APTSimulator
Atomic Red Team – Kleine und hochportable Erkennungstests, die dem Mitre ATT&CK Framework zugeordnet sind. https://github.com/redcanaryco/atomic-red-team
Network Flight Simulator – flightsim ist ein leichtgewichtiges Dienstprogramm, das verwendet wird, um bösartigen Netzwerkverkehr zu erzeugen und Sicherheitsteams dabei zu helfen, Sicherheitskontrollen und Netzwerksichtbarkeit zu bewerten. https://github.com/alphasoc/flightsim
Metta – Ein Tool zur Sicherheitsvorbereitung für die Durchführung von Adversary-Simulationen. https://github.com/uber-common/metta
Red Team Automation (RTA) – RTA bietet ein Framework aus Skripten, das es Blue Teams ermöglicht, ihre Erkennungsfähigkeiten gegen bösartige Tradecrafts zu testen, angelehnt an MITRE ATT&CK. https://github.com/endgameinc/RTA
https://drive.google.com/drive/u/0/folders/12Mvq6kE2HJDwN2CZhEGWizyWt87YunkU
https://github.com/wwong99/pentest-notes/blob/master/oscp_resources/OSCP-Survival-Guide.md
https://github.com/b4rtik/ATPMiniDump - Umgeht den Credential-Diebstahl von WinDefender ATP
https://github.com/aas-n/spraykatz - entferntes procdump.exe, kopiert die Dump-Datei auf das lokale System und nutzt pypykatz zur Analyse/Extraktion
https://github.com/0x09AL/RdpThief - extrahiert Live-RDP-Anmeldungen
https://github.com/chrismaddalena/SharpCloud - Einfacher C#-Code zum Prüfen, ob Credential-Dateien für AWS, Microsoft Azure und Google Compute vorhanden sind.
https://github.com/djhohnstein/SharpChromium - .NET-4.0-CLR-Projekt zum Abrufen von Chromium-Daten wie Cookies, Verlauf und gespeicherten Anmeldungen.
https://github.com/jfmaes/SharpHandler - Dieses Projekt nutzt offene Handles auf LSASS erneut, um LSASS zu parsen oder einen Minidump zu erstellen.
https://github.com/V1V1/SharpScribbles - ThunderFox für Firefox-Anmeldedaten, SitkyNotesExtract für "Notizen als Passwörter"
https://github.com/securesean/DecryptAutoLogon - Kommandozeilen-Tool zum Extrahieren/Entschlüsseln des Passworts, das von SysInternals AutoLogon in der LSA gespeichert wurde.
https://github.com/G0ldenGunSec/SharpSecDump - .NET-Port der Remote-SAM- und LSA-Secrets-Dumping-Funktionalität von impackets secretsdump.py
https://github.com/EncodeGroup/Gopher - C#-Tool zum Auffinden von Low Hanging Fruits wie SessionGopher
https://github.com/GhostPack/SharpDPAPI - DPAPI-Anmeldedaten per C#
LSASS-Dump ohne Mimikatz
https://github.com/b4rtik/SharpKatz - C#-Portierung der Mimikatz-Befehle sekurlsa::logonpasswords, sekurlsa::ekeys und lsadump::dcsync
Credential-Harvesting (Linux-spezifisch)
https://github.com/mthbernardes/sshLooterC - SSH-Credential-Loot
https://github.com/blendin/3snake - SSH-/Sudo-/SU-Credential-Loot
https://github.com/TarlogicSecurity/tickey - Tool zum Extrahieren von Kerberos-Tickets aus Linux-Kernel-Keys.
Datenexfiltration – DNS/ICMP/WLAN-Exfiltration
https://github.com/spieglt/FlyingCarpet - WLAN-Exfiltration
https://github.com/SECFORCE/Tunna - Tunna ist eine Sammlung von Tools, die jede TCP-Kommunikation über HTTP verpackt und tunnelt.
https://github.com/no0be/DNSlivery - Einfache Bereitstellung von Dateien und Payloads über DNS
FindFrontableDomains sucht nach potenziell frontbaren Domains. https://github.com/rvrsh3ll/FindFrontableDomains
Postfix-Server-Setup: Das Einrichten eines Phishing-Servers ist ein sehr langer und mühsamer Prozess. Es kann Stunden dauern, und in Minuten kompromittiert werden. https://github.com/n0pe-sled/Postfix-Server-Setup
DomainFrontingLists ist eine Liste von Domain-Fronting-fähigen Domains nach CDN. https://github.com/vysec/DomainFrontingLists
Apache2-Mod-Rewrite-Setup: Implementiere Mod-Rewrite schnell in deiner Infrastruktur. https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup
mod_rewrite-Regel, um Vendor-Sandboxes zu umgehen. https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10
external_c2 framework: ein Python-Framework für die Verwendung mit Cobalt Strikes External C2. https://github.com/Und3rf10w/external_c2_framework
Malleable-C2-Profiles: Eine Sammlung von Profilen, die in verschiedenen Projekten mit Cobalt Strike (https://www.cobaltstrike.com/) verwendet werden. https://github.com/xx0hcd/Malleable-C2-Profiles
ExternalC2: eine Bibliothek zur Integration von Kommunikationskanälen mit dem Cobalt-Strike-External-C2-Server. https://github.com/ryhanson/ExternalC2
cs2modrewrite: ein Tool zum Konvertieren von Cobalt-Strike-Profilen in ModRewrite-Skripte. https://github.com/threatexpress/cs2modrewrite
e2modrewrite: ein Tool zum Konvertieren von Empire-Profilen in Apache-ModRewrite-Skripte. https://github.com/infosecn1nja/e2modrewrite
redi: automatisiertes Skript zum Einrichten von CobaltStrike-Redirectoren (Nginx-Reverse-Proxy, Let's Encrypt). https://github.com/taherio/redi
cat-sites: Bibliothek von Websites zur Kategorisierung. https://github.com/audrummer15/cat-sites
ycsm ist eine schnelle Skriptinstallation für einen widerstandsfähigen Redirector mit Nginx-Reverse-Proxy und Let's Encrypt, kompatibel mit einigen beliebten Post-Ex-Tools (Cobalt Strike, Empire, Metasploit, PoshC2). https://github.com/infosecn1nja/ycsm
Domain Fronting für Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting
DomainFrontDiscover: Skripte und Ergebnisse zum Auffinden von Domain-Fronting-fähigen CloudFront-Domains. https://github.com/peewpw/DomainFrontDiscover
Automatisierte Empire-Infrastruktur https://github.com/bneg/RedTeam-Automation
Ausliefern zufälliger Payloads mit NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9
meek ist ein blockierungsresistenter pluggable Transport für Tor. Es kodiert einen Datenstrom als eine Folge von HTTPS-Anfragen und -Antworten. https://github.com/arlolra/meek
CobaltStrike-ToolKit: Einige nützliche Skripte für CobaltStrike. https://github.com/killswitch-GUI/CobaltStrike-ToolKit
mkhtaccess_red: Automatisches Generieren einer HTaccess für die Payload-Bereitstellung – zieht automatisch IPs/Netze usw. von bekannten Sandbox-Unternehmen/Quellen, die zuvor gesehen wurden, und leitet sie auf eine harmlose Payload um. https://github.com/violentlydave/mkhtaccess_red
RedFile: eine Flask-WSGI-Anwendung, die Dateien intelligent ausliefert und sich gut für bedingte RedTeam-Payloads eignet. https://github.com/outflanknl/RedFile
keyserver: Einfaches Ausliefern von HTTP- und DNS-Keys für einen ordnungsgemäßen Payload-Schutz. https://github.com/leoloobeek/keyserver
DoHC2 ermöglicht die Nutzung der ExternalC2-Bibliothek von Ryan Hanson (https://github.com/ryhanson/ExternalC2) für Command and Control (C2) über DNS over HTTPS (DoH). Es wurde für die beliebte Adversary-Simulation- und Red-Team-Operations-Software Cobalt Strike (https://www.cobaltstrike.com) entwickelt. https://github.com/SpiderLabs/DoHC2
HTran ist ein Connection Bouncer, eine Art Proxy-Server. Ein „Listener“-Programm wird heimlich auf einen ahnungslosen Host irgendwo im Internet gehackt. https://github.com/HiwinCN/HTran
https://github.com/0xacb/viewgen – .NET-Viewstates deserialisieren
https://github.com/Illuminopi/RCEvil.NET – .NET-Viewstates deserialisieren
https://github.com/Anon-Exploiter/SUID3NUM – SUID-Binaries finden und in GTFOBins nachschlagen / ausnutzbar oder nicht
https://github.com/nccgroup/GTFOBLookup – Offline-GTFOBins
https://github.com/TH3xACE/SUDO_KILLER – Ausnutzung von sudo-Fehlkonfigurationen
https://github.com/hc0d3r/tas – TTY einfach manipulieren und gefälschte Binaries erstellen
https://github.com/andrew-d/static-binaries – nicht wirklich Privilege Escalation, aber hilfreich
Covenant ist ein .NET-Command-and-Control-Framework, das darauf abzielt, die Angriffsfläche von .NET aufzuzeigen, die Nutzung offensiver .NET-Tradecrafts zu erleichtern und als kollaborative Command-and-Control-Plattform für Red Teamer zu dienen. https://github.com/cobbr/Covenant
FactionC2 ist ein C2-Framework, das eine auf Websockets basierende API verwendet, die die Interaktion mit Agenten und Transports ermöglicht. https://github.com/FactionC2/
DNScat2 ist ein Tool, das entwickelt wurde, um einen verschlüsselten Command-and-Control-Kanal (C&C) über das DNS-Protokoll zu erstellen. https://github.com/iagox86/dnscat2
Sliver ist ein allgemeines, plattformübergreifendes Implant-Framework, das C2 über Mutual-TLS, HTTP(S) und DNS unterstützt. https://github.com/BishopFox/sliver
EvilOSX ist eine bösartige RAT (Remote Administration Tool) für macOS / OS X. https://github.com/Marten4n6/EvilOSX
EggShell ist ein Post-Exploitation-Überwachungstool, das in Python geschrieben ist. Es bietet eine Befehlszeilensitzung mit zusätzlicher Funktionalität zwischen Ihnen und einem Zielrechner. https://github.com/neoneggplant/EggShell