
RedGhost
Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM,…

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Partial python implementation of SharpGPOAbuse

Powershell script for enumerating vulnerable DCOM Applications

PowerSploit - A PowerShell Post-Exploitation Framework

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Tools and Techniques for Red Team / Penetration Testing

Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.

A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

PowerShell Pass The Hash Utils

Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS

RunasCs - Csharp and open version of windows builtin runas.exe

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…