
atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.

Small and highly portable detection tests based on MITRE's ATT&CK.

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Exploits Windows IPv6 default configuration to spoof DNS via DHCPv6, redirecting victim traffic for credential relaying and man-in-the-middle attacks…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

Unit tests for blue teams to aid with building detections for some common macOS post exploitation methods.

Providing Azure pipelines to create an infrastructure and run Atomic tests.

Bash-based post-exploitation tool for semi-automated network pivoting, enabling lateral movement through compromised systems during penetration tests.

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

A collection of selenium tests that might aid it takeover of a selenium node

Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been…

A Python package is used to execute Atomic Red Team tests (Atomics) across multiple operating system environments.

Automation for internal Windows Penetrationtest / AD-Security

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Pop shells like a master.

Automated Tactics Techniques & Procedures

Technical Reference to multiple relay techniques

GitPwnd is a network penetration tool that lets you use a git repo for command and control of compromised machines