
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

An open-source post-exploitation framework for students, researchers and developers.

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Attack and defend active directory using modern post exploitation adversary tradecraft activity

This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2…

Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Red team automation framework built on Cobalt Strike, integrating exploit modules, post-exploitation tools, and lateral movement capabilities for…

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

📦 Make security testing of K8s, Docker, and Containerd easier.