
paragon
Red Team engagement platform with the goal of unifying offensive tools behind a simple UI

Red Team engagement platform with the goal of unifying offensive tools behind a simple UI

Tools and Techniques for Red Team / Penetration Testing

Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic look legit.

Memory PE loading technique for file-less attacks, enabling in-memory execution of EXEs without DOS/PE headers, supporting relocation and import…

Rust-based PoC using Windows fibers to execute in-memory code stealthily, hiding payload stacks from EDR by switching between control and payload…

indirect syscalls for AV/EDR evasion in Go assembly

SSH Exploit for CVE-2024-6387 : RCE in OpenSSH's server, on glibc-based Linux systems

Curated collection of EDR bypass resources including PoCs, tools, workshops, presentations, and blogs for ethical hacking and red team operations.

Wiki to collect Red Team infrastructure hardening resources

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with…

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

Python-based command and control framework with encrypted TLS communication, multiple agent support (Python/C), interactive sessions, file transfer,…

🦫 | GoRedOps is a repository dedicated to gathering and sharing advanced techniques and offensive malware for Red Team, with a specific focus on…

Adversary simulation and Red teaming platform with AI


Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.

Header-only Windows x64 indirect syscall library. Zero CRT, zero IAT, VEH anti-BP, AMSI/ETW bypass, W^X memory, per-call dynamic stubs.