Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Red-Team — Red-Team Attack Guid | Kitploit
Tools/GitHubGitHub/al1ex/red-team
ExploitationInformation GatheringWeb SecurityCTFPenetration TestingLearning & EducationRed TeamingCurated Resources
GitHubal1ex/red-team

Red-Team

Red-Team Attack Guid

View Repository
28067175 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Project Introduction

This project is used to collect and summarize the following aspects of Red Team:

  • Red Team attack mindset

  • Red Team attack tools

  • Red Team attack methods

Highlights

  • https://mitre-attack.github.io/ MITRE's wiki summarizing attack techniques
  • https://huntingday.github.io MITRE | ATT&CK Chinese site
  • https://arxiv.org Cornell University open-access documents
  • http://www.owasp.org.cn/owasp-project/owasp-things OWASP project
  • http://www.irongeek.com/i.php?page=security/hackingillustrated Videos and documents from security conferences at home and abroad
  • https://github.com/knownsec/KCon KCon conference article PPTs
  • https://github.com/SecWiki/sec-chart Collection of various security-related mind maps
  • https://github.com/knownsec/RD_Checklist Knownsec skill checklist
  • https://github.com/ChrisLinn/greyhame-2017 Grey Robe skill book 2017 version
  • https://github.com/Hack-with-Github/Awesome-Hacking GitHub 10k-star recommendation: hacker growth technical checklist
  • https://github.com/k4m4/movies-for-hackers Security-related movies
  • https://github.com/jaredthecoder/awesome-vehicle-security Resource list for vehicle security and car hacking
  • https://www.jianshu.com/p/852e0fbe2f4c Security product vendor classification
  • https://www.reddit.com/r/Python/comments/a81mg3/the_entire_mit_intro_computer_science_class_using/ MIT machine learning video
  • https://github.com/fxsjy/jieba py, Jieba Chinese word segmentation
  • https://github.com/thunlp/THULAC-Python py, Tsinghua Chinese word segmentation
  • https://github.com/lancopku/PKUSeg-python py3, Peking University Chinese word segmentation
  • https://github.com/fengdu78/Coursera-ML-AndrewNg-Notes Andrew Ng machine learning Python notes
  • https://paperswithcode.com/sota Machine learning specific projects, demos, code
  • https://github.com/duoergun0729/nlp An open-source introductory book on NLP (Neuro-Linguistic Programming)
  • https://www.freebuf.com/articles/web/195304.html One-sentence webshell tricks

Attack & Defense Testing

Series Content

  • https://micropoor.blogspot.com/2019/01/php8.html PHP Security News 8 AM course series: Advanced Persistent Penetration -- Microporor
  • https://github.com/Micropoor/Micro8 Microporor 100 lessons on advanced attack & defense
  • https://github.com/maskhed/Papers Includes classic attack & defense teaching materials such as the 100 lessons, and security knowledge
  • https://github.com/infosecn1nja/AD-Attack-Defense Red/blue team attack & defense handbook
  • https://github.com/yeyintminthuhtut/Awesome-Red-Teaming Excellent Red Team resource list
  • https://github.com/foobarto/redteam-notebook Red Team standard penetration testing process + common commands
  • https://github.com/tom0li/collection-document Article collection: security department, SDL, SRC, penetration testing, exploit
  • https://github.com/kbandla/APTnotes Various public documents and related APT notes, plus software samples
  • https://wizardforcel.gitbooks.io/web-hacking-101/content Web Hacking 101 Chinese version
  • https://techvomit.net/web-application-penetration-testing-notes/ Web penetration testing notes
  • https://github.com/qazbnm456/awesome-web-security Web security materials and resource list
  • http://pentestmonkey.net/category/cheat-sheet Common penetration testing cheat sheets
  • https://github.com/demonsec666/Security-Toolkit Common tools and usage scenarios in the penetration attack chain
  • https://github.com/Kinimiwar/Penetration-Testing Excellent resource collection in the penetration testing field
  • https://github.com/jshaw87/Cheatsheets Penetration testing / security cheat sheets / notes

Basic Security

  • https://book.yunzhan365.com/umta/rtnp/mobile/index.html Cybersecurity popular science booklet
  • http://sec.cuc.edu.cn/huangwei/textbook/ns/ Network security electronic textbook. CUC information security course website
  • https://mitre.github.io/attack-navigator/enterprise/ MITRE ATT&CK intrusion detection entries
  • https://github.com/danielmiessler/SecLists Lists include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, etc.
  • https://github.com/GitGuardian/APISecurityBestPractices API interface testing checklist
  • https://github.com/ym2011/SecurityManagement Shares the bits and pieces of building a security management system, ISO27001, classified protection, and security review processes
  • https://mp.weixin.qq.com/s/O36e0gl4cs0ErQPsb5L68Q Blockchain, Ethereum smart contract audit Checklist
  • https://github.com/slowmist/eos-bp-nodes-security-checklist Blockchain, EOS bp nodes security checklist (EOS super node security implementation guide)
  • https://xz.aliyun.com/t/2089 Fintech SDL security design checklist
  • https://github.com/juliocesarfort/public-pentesting-reports A list of public penetration testing reports released by several consulting firms and academic security organizations.
  • http://www.freebuf.com/articles/network/169632.html A checklist for building an SOC with open-source software
  • https://github.com/0xRadi/OWASP-Web-Checklist OWASP website check items
  • https://www.securitypaper.org/ SDL development security lifecycle management
  • https://github.com/Jsitech/JShielder One-click server hardening script for Linux
  • https://github.com/wstart/DB_BaseLine Database baseline check tool

Study Handbooks

  • https://github.com/HarmJ0y/CheatSheets Cheat sheets for multiple projects (Beacon / Cobalt Strike, PowerView, PowerUp, Empire and PowerSploit)
  • https://wizardforcel.gitbooks.io/kali-linux-web-pentest-cookbook/content/ Kali Linux Web Penetration Testing Cookbook, Chinese version
  • https://github.com/louchaooo/kali-tools-zh Manual introducing tool usage under Kali
  • https://www.offensive-security.com/metasploit-unleashed/ Metasploit guidance notes by Offensive Security (Kali)
  • http://www.hackingarticles.in/comprehensive-guide-on-hydra-a-brute-forcing-tool/ Hydra usage manual
  • https://www.gitbook.com/book/t0data/burpsuite/details Burp Suite practical guide
  • https://zhuanlan.zhihu.com/p/26618074 How to use Nmap extension scripts (NSE)
  • https://somdev.me/21-things-xss/ 21 extended uses of XSS
  • https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/ SQL injection cheat sheet
  • https://sqlwiki.netspi.com/ All the SQL injection knowledge points you need can be found here
  • https://github.com/kevins1022/SQLInjectionWiki A wiki focused on aggregating and documenting various SQL injection methods
  • https://github.com/hardenedlinux/linux-exploit-development-tutorial Linux exploit development introduction
  • https://wizardforcel.gitbooks.io/asani/content Android Security Made Simple, Chinese version
  • https://wizardforcel.gitbooks.io/lpad/content Android Penetration Testing Learning Manual, Chinese version
  • https://github.com/writeups/ios iOS vulnerability writeup notes
  • http://blog.safebuff.com/2016/07/03/SSRF-Tips/ SSRF vulnerability exploitation manual

Practice Ranges

Download Tool