Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Awesome-Red-Teaming — List of Awesome Red Teaming Resources | Kitploit
Tools/GitHubGitHub/yeyintminthuhtut/awesome-red-teaming
Privilege EscalationExploitationPost-ExploitationPenetration TestingLearning & EducationRed TeamingCurated Resources
GitHubyeyintminthuhtut/awesome-red-teaming

Awesome-Red-Teaming

List of Awesome Red Teaming Resources

View Repository
8.1k1.7k274 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

This List is no longer updated.

Awesome Red Teaming

List of Awesome Red Team / Red Teaming Resources

This list is for anyone wishing to learn about Red Teaming but do not have a starting point.

Anyway, this is a living resources and will update regularly with latest Adversarial Tactics and Techniques based on Mitre ATT&CK

You can help by sending Pull Requests to add more information.

Table of Contents

  • Initial Access
  • Execution
  • Persistence
  • Privilege Escalation
  • Defense Evasion
  • Credential Access
  • Discovery
  • Lateral Movement
  • Collection
  • Exfiltration
  • Command and Control
  • Embedded and Peripheral Devices Hacking
  • Misc
  • RedTeam Gadgets
  • Ebooks
  • Training
  • Certification

↑ Initial Access

  • The Hitchhiker’s Guide To Initial Access
  • How To: Empire’s Cross Platform Office Macro
  • Phishing with PowerPoint
  • PHISHING WITH EMPIRE
  • Bash Bunny
  • OWASP Presentation of Social Engineering - OWASP
  • USB Drop Attacks: The Danger of “Lost And Found” Thumb Drives
  • Weaponizing data science for social engineering: Automated E2E spear phishing on Twitter - Defcon 24
  • Cobalt Strike - Spear Phishing documentation
  • Cobalt Strike Blog - What's the go-to phishing technique or exploit?
  • Spear phishing with Cobalt Strike - Raphael Mudge
  • EMAIL RECONNAISSANCE AND PHISHING TEMPLATE GENERATION MADE SIMPLE
  • Phishing for access
  • Excel macros with PowerShell
  • PowerPoint and Custom Actions
  • Macro-less Code Exec in MSWord
  • Multi-Platform Macro Phishing Payloads
  • Abusing Microsoft Word Features for Phishing: “subDoc”
  • Phishing Against Protected View
  • POWERSHELL EMPIRE STAGERS 1: PHISHING WITH AN OFFICE MACRO AND EVADING AVS
  • The PlugBot: Hardware Botnet Research Project
  • Luckystrike: An Evil Office Document Generator
  • The Absurdly Underestimated Dangers of CSV Injection
  • Macroless DOC malware that avoids detection with Yara rule
  • Phishing between the app whitelists
  • Executing Metasploit & Empire Payloads from MS Office Document Properties (part 1 of 2)
  • Executing Metasploit & Empire Payloads from MS Office Document Properties (part 2 of 2)
  • Social Engineer Portal
  • 7 Best social Engineering attack
  • Using Social Engineering Tactics For Big Data Espionage - RSA Conference Europe 2012
  • USING THE DDE ATTACK WITH POWERSHELL EMPIRE
  • Phishing on Twitter - POT
  • Microsoft Office – NTLM Hashes via Frameset
  • Defense-In-Depth write-up
  • Spear Phishing 101

↑ Execution

  • Research on CMSTP.exe,
  • Windows oneliners to download remote payload and execute arbitrary code
  • Executing Commands and Bypassing AppLocker with PowerShell Diagnostic Scripts
  • WSH Injection: A Case Study
  • Gscript Dropper

↑ Persistence

  • A View of Persistence
  • hiding registry keys with psreflect
  • Persistence using RunOnceEx – Hidden from Autoruns.exe
  • Persistence using GlobalFlags in Image File Execution Options – Hidden from Autoruns.exe
  • Putting data in Alternate data streams and how to execute it – part 2
  • WMI Persistence with Cobalt Strike
  • Leveraging INF-SCT Fetch & Execute Techniques For Bypass, Evasion, & Persistence
  • Leveraging INF-SCT Fetch & Execute Techniques For Bypass, Evasion, & Persistence (Part 2)
  • Vshadow: Abusing the Volume Shadow Service for Evasion, Persistence, and Active Directory Database Extraction

↑ Privilege Escalation

Download Tool