Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Awesome-Red-Teaming — Liste de ressources Awesome pour le Red Teaming | Kitploit
Outils/GitHubGitHub/yeyintminthuhtut/awesome-red-teaming
Escalade de PrivilègesExploitationPost-ExploitationTests d'IntrusionApprentissage et ÉducationRed TeamingRessources Organisées
GitHubyeyintminthuhtut/awesome-red-teaming

Awesome-Red-Teaming

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

Liste de ressources Awesome pour le Red Teaming

Voir le dépôt
8.1k1.7k8il y a 4 ansVérifié par Kitploit

Cette liste n'est plus mise à jour.

Awesome Red Teaming

Liste des ressources Awesome Red Team / Red Teaming

Cette liste est destinée à toute personne souhaitant en savoir plus sur le Red Teaming mais qui ne dispose pas d'un point de départ.

Quoi qu'il en soit, il s'agit d'une ressource vivante qui sera mise à jour régulièrement avec les dernières tactiques et techniques adverses basées sur Mitre ATT&CK

Vous pouvez aider en envoyant des Pull Requests pour ajouter plus d'informations.

Table des matières

  • Accès initial
  • Exécution
  • Persistance
  • Élévation de privilèges
  • Contournement de la défense
  • Accès aux identifiants
  • Découverte
  • Mouvement latéral
  • Collecte
  • Exfiltration
  • Commande et contrôle
  • Piratage des périphériques embarqués et périphériques
  • Divers
  • Gadgets RedTeam
  • Ebooks
  • Formation
  • Certification

↑ Accès initial

  • The Hitchhiker’s Guide To Initial Access
  • How To: Empire’s Cross Platform Office Macro
  • Phishing with PowerPoint
  • PHISHING WITH EMPIRE
  • Bash Bunny
  • OWASP Presentation of Social Engineering - OWASP
  • USB Drop Attacks: The Danger of "Lost And Found" Thumb Drives
  • Weaponizing data science for social engineering: Automated E2E spear phishing on Twitter - Defcon 24
  • Cobalt Strike - Spear Phishing documentation
  • Cobalt Strike Blog - What's the go-to phishing technique or exploit?
  • Spear phishing with Cobalt Strike - Raphael Mudge
  • EMAIL RECONNAISSANCE AND PHISHING TEMPLATE GENERATION MADE SIMPLE
  • Phishing for access
  • Excel macros with PowerShell
  • PowerPoint and Custom Actions
  • Macro-less Code Exec in MSWord
  • Multi-Platform Macro Phishing Payloads

↑ Exécution

  • Research on CMSTP.exe,
  • Windows oneliners to download remote payload and execute arbitrary code
  • Executing Commands and Bypassing AppLocker with PowerShell Diagnostic Scripts
  • WSH Injection: A Case Study
  • Gscript Dropper

↑ Persistance

  • A View of Persistence
  • hiding registry keys with psreflect
  • Persistence using RunOnceEx – Hidden from Autoruns.exe
  • Persistence using GlobalFlags in Image File Execution Options – Hidden from Autoruns.exe
  • Putting data in Alternate data streams and how to execute it – part 2
  • WMI Persistence with Cobalt Strike
  • Leveraging INF-SCT Fetch & Execute Techniques For Bypass, Evasion, & Persistence
  • Leveraging INF-SCT Fetch & Execute Techniques For Bypass, Evasion, & Persistence (Part 2)
  • Vshadow: Abusing the Volume Shadow Service for Evasion, Persistence, and Active Directory Database Extraction

↑ Élévation de privilèges

Contournement du contrôle de compte d'utilisateur

  • First entry: Welcome and fileless UAC bypass,
  • Exploiting Environment Variables in Scheduled Tasks for UAC Bypass,
  • Comment contourner l'UAC en 3 parties : Part 1. Part 2. Part 3.
  • Bypassing UAC using App Paths,
  • "Fileless" UAC Bypass using sdclt.exe,
  • UAC Bypass or story about three escalations,
  • "Fileless" UAC Bypass Using eventvwr.exe and Registry Hijacking,
  • Bypassing UAC on Windows 10 using Disk Cleanup,
  • Using IARPUninstallStringLauncher COM interface to bypass UAC,
  • Fileless UAC Bypass using sdclt
  • Eventvwr File-less UAC Bypass CNA
  • Windows 7 UAC whitelist

Escalade

  • Windows Privilege Escalation Checklist
  • From Patch Tuesday to DA
  • A Path for Privilege Escalation

↑ Contournement de la défense

  • Window 10 Device Guard Bypass
  • App Locker ByPass List
  • Window Signed Binary
  • Bypass Application Whitelisting Script Protections - Regsvr32.exe & COM Scriptlets (.sct files)
  • Bypassing Application Whitelisting using MSBuild.exe - Device Guard Example and Mitigations
  • Empire without powershell
  • Powershell without Powershell to bypass app whitelist
  • MS Signed mimikatz in just 3 steps
  • Hiding your process from sysinternals
  • code signing certificate cloning attacks and defenses
  • userland api monitoring and code injection detection
  • In memory evasion
  • Bypassing AMSI via COM Server Hijacking
  • process doppelganging
  • Week of Evading Microsoft ATA - Announcement and Day 1 to Day 5
  • VEIL-EVASION AES ENCRYPTED HTTPKEY REQUEST: SAND-BOX EVASION
  • Putting data in Alternate data streams and how to execute it

↑ Accès aux identifiants

  • Windows Access Tokens and Alternate credentials
  • Bringing the hashes home with reGeorg & Empire
  • Intercepting passwords with Empire and winning
  • Local Administrator Password Solution (LAPS) Part 1
  • Local Administrator Password Solution (LAPS) Part 2
  • USING A SCF FILE TO GATHER HASHES
  • Remote Hash Extraction On Demand Via Host Security Descriptor Modification
  • Offensive Encrypted Data Storage
  • Practical guide to NTLM Relaying
  • Dump Clear-Text Passwords for All Admins in the Domain Using Mimikatz DCSync
  • Dumping Domain Password Hashes

↑ Découverte

  • Red Team Operating in a Modern Environment
  • My First Go with BloodHound
  • Introducing BloodHound
  • A Red Teamer’s Guide to GPOs and OUs
  • Automated Derivative Administrator Search
  • A Pentester’s Guide to Group Scoping
  • Local Group Enumeration
  • The PowerView PowerUsage Series #1 - Mass User Profile Enumeration
  • The PowerView PowerUsage Series #2 – Mapping Computer Shortnames With the Global Catalog
  • The PowerView PowerUsage Series #3 – Enumerating GPO edit rights in a foreign domain
  • The PowerView PowerUsage Series #4 – Finding cross-trust ACEs
  • Aggressor PowerView
  • Lay of the Land with BloodHound
  • Scanning for Active Directory Privileges & Privileged Accounts
  • Microsoft LAPS Security & Active Directory LAPS Configuration Recon
  • Trust Direction: An Enabler for Active Directory Enumeration and Trust Exploitation
  • SPN Discovery

↑ Mouvement latéral* A Citrix Story

  • Jumping Network Segregation with RDP
  • Pass hash pass ticket no pain
  • Abusing DNSAdmins privilege for escalation in Active Directory
  • Using SQL Server for attacking a Forest Trust
  • Extending BloodHound for Red Teamers
  • OPSEC Considerations for beacon commands
  • My First Go with BloodHound
  • Kerberos Party Tricks: Weaponizing Kerberos Protocol Flaws
  • Lateral movement using excel application and dcom
  • Lay of the Land with BloodHound
  • The Most Dangerous User Right You (Probably) Have Never Heard Of
  • Agentless Post Exploitation
  • A Guide to Attacking Domain Trusts
  • Pass-the-Hash Is Dead: Long Live LocalAccountTokenFilterPolicy
  • Targeted Kerberoasting
  • Kerberoasting Without Mimikatz
  • Abusing GPO Permissions

↑ Collecte

  • Accès au presse-papiers depuis l'écran de verrouillage dans Windows 10 Partie 1
  • Accès au presse-papiers depuis l'écran de verrouillage dans Windows 10 Partie 2

↑ Exfiltration

  • Exfiltration de données DNS — Qu'est-ce que c'est et comment l'utiliser ?
  • Tunneling DNS
  • sg1 : couteau suisse pour le chiffrement de données, l'exfiltration et la communication furtive
  • Exfiltration de données sur canal furtif de requête DNS : DNSExfiltrator
  • DET (extensible) Boîte à outils d'exfiltration de données
  • Exfiltration de données via injection de formule Partie 1

↑ Commande et Contrôle

Domain Fronting

  • Empre Domain Fronting
  • Échapper et contourner les réseaux restreints - Tom Steele et Chris Patten
  • Trouver des domaines frontables
  • TOR Fronting – Utilisation des services cachés pour la confidentialité
  • PoC simple de domain fronting avec serveur C2 GAE
  • Domain Fronting via les domaines alternatifs Cloudfront
  • Trouver des domaines Azure frontables - thoth / Fionnbharr (@a_profligate)
  • Google Groups : Article de blog sur la recherche de 2000+ domaines Azure avec Censys
  • Informations Red Team sur le Domain Fronting HTTPS des hôtes Google avec Cobalt Strike
  • SSL Domain Fronting 101
  • Comment j'ai identifié 93k domaines CloudFront frontables
  • Domaines SSL CloudFront validés
  • Détournement CloudFront
  • Dépôt GitHub CloudFrunt

Proxies de connexion

  • Redirection des balises DNS Cobalt Strike
  • Configuration de la réécriture Apache2Mod
  • Redirecteurs HTTP C2 Cobalt Strike avec Apache mod_rewrite
  • Redirecteurs haute réputation et Domain Fronting
  • Redirecteurs basés sur le cloud pour le piratage distribué
  • Contrer les intervenants en réponse aux incidents avec Apache mod_rewrite
  • Redirection basée sur le système d'exploitation avec Apache mod_rewrite
  • Redirection d'URI invalide avec Apache mod_rewrite
  • Renforcez votre hameçonnage avec Apache mod_rewrite et la redirection utilisateur mobile
  • Règle mod_rewrite pour contourner les sandbox des fournisseurs
  • Expirer les liens de hameçonnage avec Apache RewriteMap
  • Servir des charges utiles aléatoires avec NGINX
  • Configuration automatique de Mod_Rewrite
  • Redirecteurs hybrides Cobalt Strike
  • Élargissez votre horizon Red Team – SAAS C2 moderne

Services Web

  • C2 avec Dropbox
  • C2 avec Gmail
  • C2 avec Twitter
  • Office 365 pour C2 Cobalt Strike
  • Informations Red Team sur le Domain Fronting HTTPS des hôtes Google avec Cobalt Strike
  • Une backdoor Windows furtive basée sur Python utilisant Github comme serveur C&C
  • External C2 (Commande et Contrôle Tiers)
  • Cobalt Strike via External C2 – beacon home de la manière la plus obscure
  • External C2 pour Cobalt Strike
  • Framework External C2 pour Cobalt Strike
  • Framework External C2 - Dépôt GitHub
  • Se cacher dans le cloud : Beacon C2 Cobalt Strike avec les API Amazon
  • Explorer le framework ExternalC2 de Cobalt Strike

Protocole de couche applicative

  • C2 WebSocket
  • C2 WMI
  • C2 Site Web
  • C2 Image
  • C2 Javascript
  • C2 Interface Web
  • C2 avec DNS
  • C2 avec HTTPS
  • C2 avec WebDAV
  • Présentation de Merlin — Outil de Commande & Contrôle HTTP/2 multiplateforme pour post-exploitation
  • InternetExplorer.Application pour C2

Infrastructure

  • Déploiement automatisé d'infrastructure Red Team avec Terraform - Partie 1
  • Déploiement automatisé d'infrastructure Red Team avec Terraform - Partie 2
  • Infrastructure Red Team - AWS EBS chiffré
  • 6 CONSEILS POUR L'INFRASTRUCTURE RED TEAM
  • Comment construire une infrastructure C2 avec Digital Ocean – Partie 1
  • Infrastructure pour les opérations Red Team continues
  • Agrégation et surveillance des logs d'infrastructure d'attaque
  • Profils C2 malléables randomisés rendus faciles
  • Migration de votre infrastructure
  • C2 ICMP
  • Utilisation des fonctionnalités WebDAV comme canal furtif
  • Infrastructure Red Team sécurisée
  • SORTIR DE BLUECOAT AVEC COBALTSTIKE & LET'S ENCRYPT
  • Commande et Contrôle via Active Directory
  • Une vision pour les opérations Red Team distribuées
  • Conception d'infrastructure d'attaque Red Team furtive efficace

↑ Piratage de dispositifs embarqués et périphériques

  • Commencer avec le Proxmark3 & ProxBrute
  • Guide pratique pour la copie de badges RFID
  • Contenu d'un sac à dos de pentesteur physique
  • MagSpoof - usurpateur de carte de crédit/bande magnétique
  • Sniffeur de clavier sans fil
  • Piratage RFID avec le Proxmark 3
  • Couteau suisse pour RFID
  • Exploration de la surface d'attaque NFC
  • Déjouer les cartes à puce
  • Rétro-ingénierie des clés maîtresses HID iClass
  • Projet Open Pwn Android (AOPP)

↑ Divers

  • Conseils rouges de Vysec
  • Conseils Cobalt Strike pour les red teams du CCDC 2016
  • Modèles pour les opérations Red Team
  • Planification d'un exercice Red Team
  • Raphael Mudge - Astuces Red Team douteuses
  • Présentation de la méthodologie de résilience adverse partie 1
  • Présentation de la méthodologie de résilience adverse partie 2
  • Red Team responsable
  • Red Teaming pour le Pacific Rim CCDC 2017
  • Comment je me suis préparé pour le Red Team au PRCCDC 2015
  • Red Teaming pour le Pacific Rim CCDC 2016
  • Red Teams responsables
  • Awesome-CobaltStrike
  • RedTeaming de zéro à un Partie 1 Partie 2

↑ Gadgets RedTeam

Implants réseau

  • LAN Tap Pro
  • LAN Turtle
  • Bash Bunny
  • Key Croc
  • Packet Squirrel
  • Shark Jack

Audit WiFi

  • WiFi Pineapple
  • Adaptateur USB sans fil longue portée Alpha
  • Monstre Wifi-Deauth
  • Crazy PA
  • Signal Owl

IoT

  • BLE Key
  • Proxmark3
  • Sniffeur Zigbee
  • Kit d'exploitation IoT Attify

Radio logicielle - SDR

  • HackRF One Bundle
  • RTL-SDR
  • YARD stick one Bundle
  • Ubertooth

Divers

  • Key Grabber
  • Magspoof
  • Poison tap
  • keysweeper
  • USB Rubber Ducky
  • Screen Crab
  • O.MG Cable
  • Keysy
  • Dorothy pour Okta SSO## ↑ Livres électroniques
  • Next Generation Red Teaming
  • Targeted Cyber Attack
  • Advanced Penetration Testing: Hacking the World's Most Secure Networks
  • Social Engineers' Playbook Practical Pretexting
  • The Hacker Playbook 3: Practical Guide To Penetration Testing
  • How to Hack Like a PORNSTAR: A step by step process for breaking into a BANK

↑ Formation ( Gratuit )

  • Tradecraft - a course on red team operations
  • Advanced Threat Tactics Course & Notes
  • FireEye - a whiteboard session on red team operations

Laboratoire personnel

  • Building an Effective Active Directory Lab Environment for Testing
  • Setting up DetectionLab
  • vulnerable-AD - Script to make your home AD Lab vulnerable

↑ Certification

  • CREST Certified Simulated Attack Specialist
  • CREST Certified Simulated Attack Manager
  • SEC564: Red Team Operations and Threat Emulation
  • ELearn Security Penetration Testing eXtreme
  • Certified Red Team Professional
  • Certified Red Teaming Expert
  • PentesterAcademy Certified Enterprise Security Specialist (PACES)
Télécharger l’outil
  • Abusing Microsoft Word Features for Phishing: "subDoc"
  • Phishing Against Protected View
  • POWERSHELL EMPIRE STAGERS 1: PHISHING WITH AN OFFICE MACRO AND EVADING AVS
  • The PlugBot: Hardware Botnet Research Project
  • Luckystrike: An Evil Office Document Generator
  • The Absurdly Underestimated Dangers of CSV Injection
  • Macroless DOC malware that avoids detection with Yara rule
  • Phishing between the app whitelists
  • Executing Metasploit & Empire Payloads from MS Office Document Properties (part 1 of 2)
  • Executing Metasploit & Empire Payloads from MS Office Document Properties (part 2 of 2)
  • Social Engineer Portal
  • 7 Best social Engineering attack
  • Using Social Engineering Tactics For Big Data Espionage - RSA Conference Europe 2012
  • USING THE DDE ATTACK WITH POWERSHELL EMPIRE
  • Phishing on Twitter - POT
  • Microsoft Office – NTLM Hashes via Frameset
  • Defense-In-Depth write-up
  • Spear Phishing 101
  • AppLocker – Case study – How insecure is it really? – Part 1
  • AppLocker – Case study – How insecure is it really? – Part 2
  • Harden Windows with AppLocker – based on Case study part 2
  • Harden Windows with AppLocker – based on Case study part 2
  • Office 365 Safe links bypass
  • Windows Defender Attack Surface Reduction Rules bypass
  • Bypassing Device guard UMCI using CHM – CVE-2017-8625
  • Bypassing Application Whitelisting with BGInfo
  • Cloning and Hosting Evil Captive Portals using a Wifi PineApple
  • https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/
  • Executing Commands and Bypassing AppLocker with PowerShell Diagnostic Scripts
  • mavinject.exe Functionality Deconstructed
  • Abusing Active Directory Permissions with PowerView
  • Roasting AS-REPs
  • Getting the goods with CrackMapExec: Part 1
  • Getting the goods with CrackMapExec: Part 2
  • DiskShadow: The Return of VSS Evasion, Persistence, and Active Directory Database Extraction
  • Abusing Exported Functions and Exposed DCOM Interfaces for Pass-Thru Command Execution and Lateral Movement
  • a guide to attacking domain trusts
  • Outlook Home Page – Another Ruler Vector
  • Outlook Forms and Shells
  • Abusing the COM Registry Structure: CLSID, LocalServer32, & InprocServer32
  • LethalHTA - A new lateral movement technique using DCOM and HTA
  • Abusing DCOM For Yet Another Lateral Movement Technique
  • RTOps : Automatisation du déploiement de redirecteurs avec Ansible
  • Servir des charges utiles aléatoires avec Apache mod_rewrite
  • Serveurs de messagerie rendus faciles
  • Sécuriser votre C2 Empire avec Apache mod_rewrite
  • Automatiser les releases Gophish avec Ansible et Docker
  • Comment écrire des profils C2 malléables pour Cobalt Strike
  • Comment créer des profils de communication pour Empire
  • Un nouveau monde : C2 malléable
  • Commande et Contrôle malléable