
JS-Tap
JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

C# Tool to interact with MS Exchange based on MS docs

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware

Inject DLLs into the explorer process using icons

Tools for attacking Computer Use Agents

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Remote Administration Tool for Android devices

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

List of Awesome Red Teaming Resources

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Tools and Techniques for Red Team / Penetration Testing

An evil RAT (Remote Administration Tool) for macOS / OS X.

Curated collection of red team and pentest tools grouped by phase: payloads, AMSI bypasses, pivoting, persistence, privesc, credential harvesting,…