
RedTeam-Tools
Tools and Techniques for Red Team / Penetration Testing

Tools and Techniques for Red Team / Penetration Testing

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Wiki to collect Red Team infrastructure hardening resources

↕️🤫 Stealth redirector for your red team operation security

✉️ HTML Smuggling generator&obfuscator for your Red Team operations

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

PowerShell toolkit for remote template injection attacks and defense. Injects malicious links into Office Word documents for phishing, with…

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

This little tool is to calculate a MurmurHash value of a favicon to hunt phishing websites on the Shodan platform.

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

Educational trojan simulator for cybersecurity training, simulating phishing attacks with social engineering, system reconnaissance, anti-sandbox…

Um estudo de caso do CVE-2024-21413. Usado como parâmetro a sala do TryHackMe Moniker Link (CVE-2024-21413). Feito edições com claude code no exploit.

Hunt down social media accounts by username across social networks

A tool to transform Chromium browsers into a C2 Implant

Bulk domain spoofability checker using authoritative SPF and DMARC record analysis with custom, real-world tested spoof logic and optional DKIM…