
atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.

Small and highly portable detection tests based on MITRE's ATT&CK.

Adversary simulation framework for authoring and automating attacker TTPs as repeatable YAML scenarios, helping red and blue teams validate detection…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Async PICO Hub is a work-in-progress framework to extend Cobalt Strike with custom event monitoring and in-process Asynchronous BOFs

Technical Reference to multiple relay techniques

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

A Cobalt Strike Beacon Object File that exploits the BlueHammer vulnerability that to obtain a copy of the SAM database.

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

A collection of selenium tests that might aid it takeover of a selenium node


Automation for internal Windows Penetrationtest / AD-Security


LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

Ansible-based attack platform for deploying and managing a standardized Linux penetration testing environment with automated tool installation,…

A Python package is used to execute Atomic Red Team tests (Atomics) across multiple operating system environments.

A helper script for consolidating Aggressor and BOF repositories into a single CNA for Cobalt Strike.

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege

Providing Azure pipelines to create an infrastructure and run Atomic tests.