
sliver
Adversary Emulation Framework

Adversary Emulation Framework

DejaVU - Open Source Deception Framework

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

CrossC2 developed based on the Cobalt Strike framework can be used for other cross-platform system control. CrossC2Kit provides some interfaces for…

Malicious shortcut generator for collecting NTLM hashes from insecure file shares.

Modules used by the Havoc Framework

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

A basic emulation of an "RPC Backdoor"

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

A C# tool with more flexibility to customize scheduled task for both persistence and lateral movement in red team operation