
vcsa-hardening-tool
Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

Automates BloodHound integration with Cobalt Strike to discover AD escalation paths, mark compromised assets as owned, and investigate beacon…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Tools and Techniques for Red Team / Penetration Testing

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

PowerShell framework for offensive security operations, providing scripts for penetration testing, red teaming, post-exploitation, privilege…

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

LLMNR, NBT-NS, and MDNS poisoner with 17+ rogue authentication servers for capturing NetNTLM hashes, cleartext credentials, and Kerberos AS-REP…

Attack and defend active directory using modern post exploitation adversary tradecraft activity

📦 Make security testing of K8s, Docker, and Containerd easier.

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.