Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
APT-GUID — APT-GUID | Kitploit
उपकरण/GitHubGitHub/al1ex/apt-guid
OSINT (खुला स्रोत खुफिया)विशेषाधिकार वृद्धिभेद्यता विश्लेषणशोषणजानकारी एकत्र करनापोस्ट-शोषणकमांड एंड कंट्रोलसामाजिक इंजीनियरिंगलर्निंग और शिक्षारेड टीमिंगचयनित संसाधन
231275 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
GitHub
al1ex/apt-guid

APT-GUID

APT-GUID

रिपॉजिटरी देखें

परियोजना परिचय

APT क्षेत्र के कुछ संसाधनों का संकलन, निम्नलिखित पहलुओं से संबंधित लेकिन इन्हीं तक सीमित नहीं:

  • APT हमला उपकरण

  • APT विश्लेषण रिपोर्ट

  • APT हमला तकनीक

उपकरण संग्रह

सूचना संग्रह

सक्रिय खुफिया संग्रह
  • EyeWitness वेबसाइटों के स्क्रीनशॉट प्राप्त कर सकता है, कुछ सर्वर जानकारी प्रदान करता है, और संभव होने पर डिफ़ॉल्ट क्रेडेंशियल की पहचान करता है https://github.com/ChrisTruncer/EyeWitness
  • AWSBucketDump AWS S3 बकेट्स को तुरंत enumerate करने के लिए उपयोगी उपकरण है ताकि खजाने की तलाश की जा सके https://github.com/jordanpotti/AWSBucketDump
  • AQUATONE डोमेन नामों पर सूचना संग्रह करने का उपकरण है https://github.com/michenriksen/aquatone
  • Spoofcheck, यह जाँचने के लिए कि क्या डोमेन स्पूफ किया जा सकता है; यह प्रोग्राम SPF और DMARC रिकॉर्ड में कमजोर कॉन्फ़िगरेशन की जाँच करता है जो स्पूफिंग की अनुमति देते हैं https://github.com/BishopFox/spoofcheck
  • Nmap कंप्यूटर नेटवर्क पर होस्ट और सेवाओं की खोज के लिए उपयोग किया जाता है https://github.com/nmap/nmap
  • dnsrecon एक DNS enumeration स्क्रिप्ट है https://github.com/darkoperator/dnsrecon
  • dirsearch एक सरल कमांड-लाइन उपकरण है जो वेबसाइट निर्देशिकाओं को ब्रूट-फोर्स करता है https://github.com/maurosoria/dirsearch
  • Sn1per एक स्वचालित पेनेट्रेशन उपकरण है https://github.com/1N3/Sn1per
निष्क्रिय खुफिया संग्रह
  • Social Mapper OSINT सोशल मीडिया मैपिंग उपकरण है, जो उपयोगकर्ता नाम और चित्रों (या LinkedIn कंपनी नाम) की सूची लेता है और कई सोशल मीडिया वेबसाइटों पर बड़े पैमाने पर स्वचालित लक्ष्य खोज करता है। यह API सीमाओं से मुक्त है क्योंकि यह Selenium का उपयोग करता है। https://github.com/SpiderLabs/social_mapper
  • skiptracer OSINT शोषण ढांचा https://github.com/xillwillx/skiptracer
  • FOCA मुख्य रूप से स्कैन किए गए दस्तावेज़ों में मेटाडेटा और छिपी जानकारी खोजने के लिए उपयोग किया जाता है। https://github.com/ElevenPaths/FOCA
  • theHarvester विभिन्न सार्वजनिक स्रोतों से सबडोमेन, ईमेल पते, वर्चुअल होस्ट, पोर्ट/बैनर और कर्मचारी नाम एकत्र करने के लिए उपयोग किया जाता है। https://github.com/laramies/theHarvester
  • Metagoofil लक्ष्य वेबसाइट में उपलब्ध सार्वजनिक दस्तावेज़ों (pdf, doc, xls, ppt आदि) का मेटाडेटा निकालने का उपकरण है। https://github.com/laramies/metagoofil
  • SimplyEmail ईमेल रिकॉनिसेंस। https://github.com/killswitch-GUI/SimplyEmail
  • truffleHog git रिपॉजिटरी में संवेदनशील डेटा खोजता है, कमिट इतिहास और शाखाओं में गहराई से खोज करता है। https://github.com/dxa4481/truffleHog
  • Just-Metadata IP पते के बारे में मेटाडेटा एकत्र करने और उसका विश्लेषण करने का उपकरण है। यह बड़े डेटासेट में सिस्टम के बीच संबंध खोजने का प्रयास करता है। https://github.com/ChrisTruncer/Just-Metadata
  • typofinder IP पते का देश/क्षेत्र दिखाता है। https://github.com/nccgroup/typofinder
  • pwnedOrNot एक python स्क्रिप्ट है जो जाँचती है कि क्या ईमेल खाता डेटा उल्लंघन के कारण समझौता हुआ है; यदि ईमेल खाता समझौता हुआ है, तो यह उस खाते का पासवर्ड खोजने के लिए आगे बढ़ता है। https://github.com/thewhiteh4t/pwnedOrNot
  • GitHarvester यह उपकरण GitHub से जानकारी एकत्र करने के लिए है, जैसे google dork। https://github.com/metac0rtex/GitHarvester

शोषण

  • WinRAR Remote Code Execution CVE-2018-20250 के लिए प्रूफ ऑफ कॉन्सेप्ट एक्सप्लॉइट। https://github.com/WyAtu/CVE-2018-20250
  • Composite Moniker CVE-2017-8570 के लिए प्रूफ ऑफ कॉन्सेप्ट एक्सप्लॉइट। https://github.com/rxwx/CVE-2017-8570
  • Exploit toolkit CVE-2017-8759 https://github.com/bhdresh/CVE-2017-8759
  • CVE-2017-11882 Exploit https://github.com/unamer/CVE-2017-11882
  • Adobe Flash Exploit CVE-2018-4878. https://github.com/anbai-inc/CVE-2018-4878
  • Exploit toolkit CVE-2017-0199 एक सुविधाजनक python स्क्रिप्ट है, जो पेनेट्रेशन टेस्टर्स और सुरक्षा शोधकर्ताओं को Microsoft Office RCE का परीक्षण करने का त्वरित और प्रभावी तरीका प्रदान करती है।https://github.com/bhdresh/CVE-2017-0199
  • demiguise HTA एन्क्रिप्शन उपकरण https://github.com/nccgroup/demiguise
  • Office-DDE-Payloads स्क्रिप्ट और टेम्पलेट एकत्र करता है, ऐसे Office दस्तावेज़ उत्पन्न करता है जिनमें DDE (मैक्रो-मुक्त कमांड निष्पादन तकनीक) एम्बेडेड होती है।https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads
  • CACTUSTORCH प्रतिद्वंद्वी सिमुलेशन के लिए payload जनरेशन।https://github.com/mdsecactivebreach/CACTUSTORCH
  • SharpShooter एक payload निर्माण ढांचा है, जिसका उपयोग मनमाना CSharp स्रोत कोड निष्पादित करने के लिए किया जाता है।https://github.com/mdsecactivebreach/SharpShooter
  • DKMC, यह ऑब्सफस्केटेड shellcode उत्पन्न करने का एक उपकरण है, जो छवियों में संग्रहीत होता है। यह छवि 100% मान्य है और 100% मान्य shellcode भी है।https://github.com/Mr-Un1k0d3r/DKMC
  • दुर्भावनापूर्ण मैक्रो जनरेटर ऑब्सफस्केटेड मैक्रो उत्पन्न करने के लिए उपयोग किया जाता है, जिसमें AV/सैंडबॉक्स बाईपास तंत्र भी शामिल हैं।

सोशल इंजीनियरिंग फ़िशिंग

  • King Phisher https://github.com/securestate/king-phisher
  • FiercePhish https://github.com/Raikia/FiercePhish
  • ReelPhish https://github.com/fireeye/ReelPhish/
  • Gophish https://github.com/gophish/gophish
  • CredSniper https://github.com/ustayready/CredSniper
  • PwnAuth https://github.com/fireeye/PwnAuth
  • Phishing Frenzy https://github.com/pentestgeek/phishing-frenzy
  • Phishing Pretexts https://github.com/L4bF0x/PhishingPretexts
  • Modlishka https://github.com/drk1wi/Modlishka
  • Evilginx2 https://github.com/kgretzky/evilginx2

C2 फ्रेमवर्क

  • Cobalt Strike https://cobaltstrike.com/

  • Empire https://github.com/EmpireProject/Empire

  • Metasploit Framework https://github.com/rapid7/metasploit-framework

  • SILENTTRINITY https://github.com/byt3bl33d3r/SILENTTRINITY

  • Pupy https://github.com/n1nj4sec/pupy

  • Koadic https://github.com/zerosum0x0/koadic

  • PoshC2 https://github.com/nettitude/PoshC2_Python

  • Gcat https://github.com/byt3bl33d3r/gcat

  • TrevorC2 https://github.com/trustedsec/trevorc2

  • Merlin https://github.com/Ne0nd0g/merlin

  • Quasar https://github.com/quasar/QuasarRAT

  • Covenant https://github.com/cobbr/Covenant

  • FactionC2 https://github.com/FactionC2/

  • DNScat2 https://github.com/iagox86/dnscat2

  • Sliver https://github.com/BishopFox/sliver

  • EvilOSX

पोस्ट-एक्सप्लॉइटेशन

  • CrackMapExec https://github.com/byt3bl33d3r/CrackMapExec
  • PowerLessShell https://github.com/Mr-Un1k0d3r/PowerLessShell
  • GoFetch BloodHound द्वारा उत्पन्न हमले की योजनाओं को स्वचालित रूप से निष्पादित करता है। https://github.com/GoFetchAD/GoFetch
  • ANGRYPUPPY CobaltStrike में BloodHound हमला पथ स्वचालन। https://github.com/vysec/ANGRYPUPPY
  • DeathStar https://github.com/byt3bl33d3r/DeathStar
  • SharpHound https://github.com/BloodHoundAD/SharpHound
  • BloodHound.py Impacket-आधारित Python BloodHound ingestor है। https://github.com/fox-it/BloodHound.py
  • Responder मैन-इन-द-मिडिल अटैक उपकरण https://github.com/SpiderLabs/Responder
  • SessionGopher एक PowerShell उपकरण है, जो WMI का उपयोग करके रिमोट एक्सेस उपकरणों (जैसे WinSCP, PuTTY, SuperPuTTY, FileZilla और Microsoft रिमोट डेस्कटॉप) से सहेजी गई सत्र जानकारी निकालता है। https://github.com/fireeye/SessionGopher
  • PowerSploit pwsh टूलसेट https://github.com/PowerShellMafia/PowerSploit
  • Nishang https://github.com/samratashok/nishang
  • Inveigh मैन-इन-द-मिडिल अटैक उपकरण https://github.com/Kevin-Robertson/Inveigh
  • PowerUpSQL SQL सर्वर पर हमला करने के लिए एक PowerShell टूलकिट। https://github.com/NetSPI/PowerUpSQL
  • MailSniper https://github.com/dafthack/MailSniper

नेटवर्क प्रॉक्सी

  • Tunna फ़ायरवॉल वातावरण में नेटवर्क प्रतिबंधों को बायपास करने के लिए उपयोग किया जाता है https://github.com/SECFORCE/Tunna
  • reGeorg socks प्रॉक्सी उपकरण https://github.com/sensepost/reGeorg
  • Blade Webshell प्रबंधन उपकरण https://github.com/wonderqs/Blade
  • TinyShell Web Shell ढांचा. https://github.com/threatexpress/tinyshell
  • PowerLurk दुर्भावनापूर्ण WMI PowerShell टूलसेट बनाने के लिए. https://github.com/Sw4mpf0x/PowerLurk
  • DAMP होस्ट-आधारित सुरक्षा डिस्क्रिप्टर संशोधन के माध्यम से पर्सिस्टेंस प्राप्त करता है https://github.com/HarmJ0y/DAMP

विशेषाधिकार वृद्धि

डोमेन के भीतर विशेषाधिकार वृद्धि
  • PowerView https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1
  • Get-GPPPassword https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-GPPPassword.ps1
  • Invoke-ACLpwn https://github.com/fox-it/Invoke-ACLPwn
  • BloodHound https://github.com/BloodHoundAD/BloodHound
  • PyKEK https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS14-068/pykek
  • Grouper समूह नीति कमजोरियों को स्वचालित रूप से खोजने का उपकरण https://github.com/l0ss/Grouper
  • ADRecon https://github.com/sense-of-security/ADRecon
  • ADACLScanner https://github.com/canix1/ADACLScanner
  • ACLight डोमेन विशेषाधिकार प्राप्त खातों को खोजने के लिए उपयोग किया जाता है, जिन्हें लक्षित किया जा सकता है - जिसमें Shadow Admins भी शामिल हैं।https://github.com/cyberark/ACLight
  • LAPSToolkit https://github.com/leoloobeek/LAPSToolkit
  • PingCastle https://www.pingcastle.com/download
  • RiskySPNs PowerShell स्क्रिप्ट का संग्रह है, जो SPN (सर्विस प्रिंसिपल नेम) से जुड़े खातों का पता लगाने और क्वेरी करने पर केंद्रित है। https://github.com/cyberark/RiskySPN
  • Mystique एक PowerShell उपकरण है जो Kerberos S4U एक्सटेंशन के साथ काम कर सकता है। यह मॉड्यूल KCD को प्रोटोकल ट्रांज़िशन के साथ जोड़कर, ब्लू टीम को खतरनाक Kerberos डेलीगेशन कॉन्फ़िगरेशन की पहचान करने और रेड टीम को किसी भी उपयोगकर्ता की नकल करने में सहायता करता है।
Linux विशेषाधिकार वृद्धि
  • https://github.com/Al1ex/Heptagram/tree/master/Linux/Elevation Linux विशेषाधिकार वृद्धि संग्रह
  • https://github.com/AlessandroZ/BeRoot py, सामान्य गलत कॉन्फ़िगरेशन की जाँच करके विशेषाधिकार वृद्धि के तरीके खोजता है. Windows/Linux/Mac समर्थित हैं।
  • https://github.com/mschwager/0wned python पैकेज का उपयोग करके उच्च विशेषाधिकार वाले उपयोगकर्ता बनाना
  • https://github.com/mzet-/linux-exploit-suggester यह पता लगाने की स्क्रिप्ट कि Linux पर कौन से पैच नहीं लगाए गए हैं
  • https://github.com/belane/linux-soft-exploit-suggester यह पता लगाने के लिए कि Linux पर कौन से सॉफ़्टवेयर कमजोर हैं
  • https://github.com/dirtycow/dirtycow.github.io डर्टी काउ विशेषाधिकार वृद्धि भेद्यता exp
  • https://github.com/FireFart/dirtycow डर्टी काउ विशेषाधिकार वृद्धि भेद्यता exp
  • https://github.com/stanleyb0y/sushell su चोर का उपयोग करके कम विशेषाधिकार वाले उपयोगकर्ता द्वारा root उपयोगकर्ता का पासवर्ड चुराना
  • https://github.com/jas502n/CVE-2018-17182/ Linux कर्नेल VMA-UAF विशेषाधिकार वृद्धि भेद्यता CVE-2018-17182
  • https://github.com/jas502n/CVE-2018-14665 CVE-2018-14665, Linux पर Xorg X सर्वर विशेषाधिकार वृद्धि एक्सप्लॉइट
  • https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897 Linux सिस्टम Syscall का उपयोग करके विशेषाधिकार वृद्धि
  • https://github.com/can1357/CVE-2018-8897 Linux सिस्टम Syscall का उपयोग करके विशेषाधिकार वृद्धि
  • https://github.com/SecWiki/linux-kernel-exploits linux-kernel-exploits Linux प्लेटफ़ॉर्म विशेषाधिकार वृद्धि भेद्यता संग्रह
  • https://github.com/nilotpalbiswas/Auto-Root-Exploit Linux स्वचालित विशेषाधिकार वृद्धि स्क्रिप्ट
Windows विशेषाधिकार वृद्धि
  • https://github.com/Al1ex/Heptagram/tree/master/Windows/Elevation Windows विशेषाधिकार वृद्धि संग्रह
  • http://www.fuzzysecurity.com/tutorials/16.html Windows प्लेटफ़ॉर्म के लिए ट्यूटोरियल-स्तरीय विशेषाधिकार वृद्धि संदर्भ लेख
  • https://github.com/SecWiki/windows-kernel-exploits Windows प्लेटफ़ॉर्म विशेषाधिकार वृद्धि भेद्यता Exp संग्रह
  • https://github.com/51x/WHP Windows पर विभिन्न विशेषाधिकार वृद्धि और शोषण उपकरण
  • https://github.com/rasta-mouse/Sherlock Windows विशेषाधिकार वृद्धि भेद्यता सत्यापन
  • https://github.com/WindowsExploits/Exploits Microsoft CVE-2012-0217, CVE-2016-3309, CVE-2016-3371, CVE-2016-7255, CVE-2017-0213 विशेषाधिकार वृद्धि शोषण
  • https://github.com/decoder-it/lonelypotato RottenPotatoNG वेरिएंट, NBNS स्थानीय डोमेन स्पूफिंग और WPAD प्रॉक्सी स्पूफिंग का उपयोग करके विशेषाधिकार वृद्धि
  • https://github.com/ohpe/juicy-potato RottenPotatoNG वेरिएंट, COM ऑब्जेक्ट और उपयोगकर्ता टोकन का उपयोग करके विशेषाधिकार वृद्धि
  • https://github.com/foxglovesec/Potato RottenPotatoNG वेरिएंट, स्थानीय डोमेन स्पूफिंग और प्रॉक्सी स्पूफिंग का उपयोग करके विशेषाधिकार वृद्धि
  • https://github.com/DanMcInerney/icebreaker यदि आप आंतरिक नेटवर्क में हैं लेकिन AD वातावरण के बाहर हैं, तो icebreaker आपको प्लेनटेक्स्ट Active Directory क्रेडेंशियल प्राप्त करने में मदद करेगा (Active Directory डोमेन कंट्रोलर सर्वर में संग्रहीत होता है और विशेषाधिकार वृद्धि के लिए उपयोग किया जा सकता है)
  • https://github.com/hausec/ADAPE-Script Active Directory विशेषाधिकार वृद्धि स्क्रिप्ट
  • https://github.com/klionsec/BypassAV-AllThings aspx वन-लाइनर को विशेषाधिकार वृद्धि payload के साथ उपयोग करके विशेषाधिकार वृद्धि
  • https://github.com/St0rn/Windows-10-Exploit msf प्लगइन, Windows 10 UAC बायपास

डेटा एक्सफ़िल्ट्रेशन

  • CloakifyFactory और Cloakify टूलसेट - https://github.com/TryCatchHCF/Cloakify
  • DET (जैसा है वैसा ही प्रदान किया गया है), एक ही समय में एक या कई चैनलों का उपयोग करके डेटा एक्सफ़िल्ट्रेशन निष्पादित करने वाला POC है। https://github.com/sensepost/DET
  • DNSExfiltrator . https://github.com/Arno0x/DNSExfiltrator
  • PyExfil डेटा एक्सफ़िल्ट्रेशन के लिए एक Python पैकेज। https://github.com/ytisf/PyExfil
  • Egress-Assess आउटबाउंड डेटा डिटेक्शन क्षमताओं का परीक्षण करने का उपकरण है। https://github.com/ChrisTruncer/Egress-Assess
  • Powershell RAT python-आधारित बैकडोर, जो Gmail का उपयोग करके डेटा को ईमेल अटैचमेंट के रूप में स्थानांतरित करता है।https://github.com/Viralmaniar/Powershell-RAT

अन्य

प्रतिद्वंद्वी सिमुलेशन
  • MITRE CALDERA हमलावर की हमला तकनीकों का अनुकरण करता है और उनका विश्लेषण करता है https://github.com/mitre/caldera
  • APTSimulator https://github.com/NextronSystems/APTSimulator
  • Atomic Red Team - https://github.com/redcanaryco/atomic-red-team
  • Network Flight Simulator https://github.com/alphasoc/flightsim
  • Metta - https://github.com/uber-common/metta
  • Red Team Automation (RTA) - RTA एक स्क्रिप्ट ढांचा प्रदान करता है, जो ब्लू टीम को MITER ATT&CK के अनुसार मॉडल बनाने और दुर्भावनापूर्ण टूल्स के खिलाफ अपनी डिटेक्शन क्षमताओं का परीक्षण करने की अनुमति देता है। https://github.com/endgameinc/RTA
वायरलेस हमले
  • Wifiphisher WIFI स्वचालित एसोसिएशन हमला उपकरण. https://github.com/wifiphisher/wifiphisher
  • mana मैन-इन-द-मिडिल हमला. https://github.com/sensepost/mana
एम्बेडेड हमले- magspoof https://github.com/samyk/magspoof
  • WarBerryPi https://github.com/secgroundzero/warberry
  • P4wnP1 https://github.com/mame82/P4wnP1
  • malusb https://github.com/ebursztein/malusb
  • Fenrir https://github.com/Orange-Cyberdefense/fenrir-ocd
  • poisontap https://github.com/samyk/poisontap
  • WHID https://github.com/whid-injector/WHID
  • PhanTap https://github.com/nccgroup/phantap
संचार छुपाव
  • RocketChat https://rocket.chat
  • Etherpad https://etherpad.org/
लॉग प्रबंधन
  • RedELK https://github.com/outflanknl/RedELK/
  • CobaltSplunk https://github.com/vysec/CobaltSplunk
  • Red Team Telemetry https://github.com/ztgrace/red_team_telemetry
  • Elastic for Red Teaming https://github.com/SecurityRiskAdvisors/RedTeamSIEM
  • Ghostwriter https://github.com/GhostManager/Ghostwriter
C# शस्त्रीकरण
  • SharpSploit .NET पोस्ट-एक्सप्लॉइटेशन फ्रेमवर्क https://github.com/cobbr/SharpSploit
  • GhostPack Csharp टूलसेट https://github.com/GhostPack
  • SharpWeb सामान्य ब्राउज़र पासवर्ड पढ़ता है https://github.com/djhohnstein/SharpWeb
  • reconerator https://github.com/stufus/reconerator
  • SharpView PowerView का C# संस्करण। https://github.com/tevora-threat/SharpView
  • Watson https://github.com/rasta-mouse/Watson
LABS
  • Detection Lab स्वचालित रूप से एक लैब बनाता है https://github.com/clong/DetectionLab ---पांच सितारा अनुशंसा
  • Modern Windows Attacks and Defense Labhttps://github.com/jaredhaight/WindowsAttackAndDefenseLab
  • Invoke-UserSimulator https://github.com/ubeeri/Invoke-UserSimulator
  • Invoke-ADLabDeployer AD वातावरण स्वचालित रूप से तैनात करें https://github.com/outflanknl/Invoke-ADLabDeployer
  • Sheepl https://github.com/SpiderLabs/sheepl
Script
Aggressor Scripts
  • https://github.com/invokethreatguy/CSASC
  • https://github.com/secgroundzero/CS-Aggressor-Scripts
  • https://github.com/Und3rf10w/Aggressor-scripts
  • https://github.com/harleyQu1nn/AggressorScripts
  • https://github.com/rasta-mouse/Aggressor-Script
  • https://github.com/RhinoSecurityLabs/Aggressor-Scripts
  • https://github.com/bluscreenofjeff/AggressorScripts
  • https://github.com/001SPARTaN/aggressor_scripts
  • https://github.com/360-A-Team/CobaltStrike-Toolset
  • https://github.com/FortyNorthSecurity/AggressorAssessor
  • https://github.com/ramen0x3f/AggressorScripts
Red-Team
  • https://github.com/FuzzySecurity/PowerShell-Suite
  • https://github.com/nettitude/Powershell
  • https://github.com/Mr-Un1k0d3r/RedTeamPowershellScripts
  • https://github.com/threatexpress/red-team-scripts
  • https://github.com/SadProcessor/SomeStuff
  • https://github.com/rvrsh3ll/Misc-Powershell-Scripts
  • https://github.com/enigma0x3/Misc-PowerShell-Stuff
  • https://github.com/ChrisTruncer/PenTestScripts
  • https://github.com/bluscreenofjeff/Scripts
  • https://github.com/xorrior/RandomPS-Scripts
  • https://github.com/xorrior/Random-CSharpTools
  • https://github.com/leechristensen/Random
  • https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/social-engineering
टूल डाउनलोड करें
  • pwndb एक python कमांड-लाइन उपकरण है जिसका उपयोग उसी नाम की Onion सेवा का उपयोग करके लीक हुए क्रेडेंशियल्स खोजने के लिए किया जाता है। https://github.com/davidtavarez/pwndb/
  • LinkedInt LinkedIn Recon उपकरण। https://github.com/vysecurity/LinkedInt
  • CrossLinked LinkedIn enumeration उपकरण, जो खोज इंजन स्क्रैपिंग के माध्यम से संगठन से वैध कर्मचारी नाम निकालता है। https://github.com/m8r0wn/CrossLinked
  • findomain तेज़ सबडोमेन enumeration उपकरण है, यह सर्टिफिकेट पारदर्शिता लॉग और कुछ API का उपयोग करता है। https://github.com/Edu4rdSHL/findomain
  • https://github.com/Mr-Un1k0d3r/MaliciousMacroGenerator
  • SCT-obfuscator Cobalt Strike SCT payload ऑब्सफस्केटर।https://github.com/Mr-Un1k0d3r/SCT-obfuscator
  • Invoke-Obfuscation PowerShell ऑब्सफस्केटर।https://github.com/danielbohannon/Invoke-Obfuscation
  • Invoke-CradleCrafter PowerShell रिमोट डाउनलोड जनरेटर और ऑब्सफस्केटर।https://github.com/danielbohannon/Invoke-CradleCrafter
  • Invoke-DOSfuscation cmd.exe कमांड ऑब्सफस्केशन जनरेटर और डिटेक्शन टेस्टिंग उपकरण।https://github.com/danielbohannon/Invoke-DOSfuscation
  • morphHTA.https://github.com/vysec/morphHTA
  • Unicorn PowerShell डाउनग्रेड अटैक का उपयोग करके shellcode को सीधे मेमोरी में इंजेक्ट करने वाला सरल उपकरण है।https://github.com/trustedsec/unicorn
  • Shellter एक डायनेमिक Shellcode इंजेक्शन उपकरण है, और अब तक का पहला सच्चा डायनेमिक PE इंफेक्टर है।https://www.shellterproject.com/
  • EmbedInHTML HTML में किसी भी फ़ाइल को एम्बेड और छिपाता है।https://github.com/Arno0x/EmbedInHTML
  • SigThief हस्ताक्षर चुराता है और एक अमान्य हस्ताक्षर बनाता है।https://github.com/secretsquirrel/SigThief
  • Veil,https://github.com/Veil-Framework/Veil
  • CheckPlease PowerShell, Python, Go, Ruby, C, C#, Perl और Rust में लिखा गया सैंडबॉक्स बाईपास मॉड्यूल।https://github.com/Arvanaghi/CheckPlease
  • Invoke-PSImage एक ऐसा उपकरण है जो PowerShell स्क्रिप्ट को PNG फ़ाइल के पिक्सेल में एम्बेड करता है और उसे निष्पादित कर सकता है।https://github.com/peewpw/Invoke-PSImage
  • LuckyStrike PowerShell-आधारित उपयोगिता है, जिसका उपयोग दुर्भावनापूर्ण Office मैक्रो दस्तावेज़ बनाने के लिए किया जाता है। केवल पेनेट्रेशन या शैक्षिक उद्देश्यों के लिए।https://github.com/curi0usJack/luckystrike
  • ClickOnceGenerator https://github.com/Mr-Un1k0d3r/ClickOnceGenerator
  • macro_pack @EmericNasi का उपकरण है, जिसका उपयोग MS Office दस्तावेज़ों, VB स्क्रिप्ट और अन्य प्रारूपों के स्वचालित ऑब्सफस्केशन और जनरेशन के लिए पेनेट्रेशन टेस्टिंग, डेमो और सोशल इंजीनियरिंग मूल्यांकन हेतु किया जाता है।https://github.com/sevagas/macro_pack
  • StarFighters JavaScript और VBScript पर आधारित एक Empire Launcher।https://github.com/Cn33liz/StarFighters
  • nps_payload यह स्क्रिप्ट बुनियादी घुसपैठ का पता लगाने से बचने के लिए payload उत्पन्न करेगी। यह कई अलग-अलग स्रोतों से सार्वजनिक रूप से प्रदर्शित तकनीकों का उपयोग करती है।https://github.com/trustedsec/nps_payload
  • SocialEngineeringPay क्रेडेंशियल चोरी और स्पीयर फ़िशिंग हमलों के लिए सोशल इंजीनियरिंग तकनीकों और payload की एक श्रृंखला लोड करता है।https://github.com/bhdresh/SocialEngineeringPayloads
  • Social-Engineer Toolkit सोशल इंजीनियरिंग के लिए डिज़ाइन किया गया एक ओपन-सोर्स पेनेट्रेशन टेस्टिंग ढांचा है।https://github.com/trustedsec/social-engineer-toolkit
  • phishery एक सरल SSL-सक्षम HTTP सर्वर है, जिसका मुख्य उद्देश्य बेसिक ऑथेंटिकेशन के माध्यम से क्रेडेंशियल्स फ़िश करना है। https://github.com/ryhanson/phishery
  • PowerShdll rundll32 के साथ PowerShell चलाता है। सॉफ़्टवेयर प्रतिबंधों को बायपास करता है।https://github.com/p3nt4/PowerShdll
  • UltimateAppLockerByPassList AppLocker को बायपास करने की सबसे सामान्य तकनीकों का दस्तावेजीकरण करता है।https://github.com/api0cradle/UltimateAppLockerByPassList
  • ruler, आपको MAPI/HTTP या RPC/HTTP प्रोटोकॉल के माध्यम से Exchange सर्वर के साथ दूरस्थ रूप से इंटरैक्ट करने की अनुमति देता है।https://github.com/sensepost/ruler
  • Generate-Macro एक स्टैंडअलोन PowerShell स्क्रिप्ट है, जो निर्दिष्ट payload और पर्सिस्टेंस विधि के साथ दुर्भावनापूर्ण Microsoft Office दस्तावेज़ उत्पन्न करेगी।https://github.com/enigma0x3/Generate-Macro
  • MaliciousMacroMSBuild दुर्भावनापूर्ण मैक्रो उत्पन्न करता है और MSBuild एप्लिकेशन व्हाइटलिस्टिंग बायपास के माध्यम से Powershell या Shellcode निष्पादित करता है।https://github.com/infosecn1nja/MaliciousMacroMSBuild
  • Meta Twin फ़ाइल संसाधन क्लोनर। एक फ़ाइल से डिजिटल हस्ताक्षर सहित मेटाडेटा निकालता है, फिर उसे दूसरी फ़ाइल में इंजेक्ट करता है।https://github.com/threatexpress/metatwin
  • WePWNise आर्किटेक्चर-स्वतंत्र VBA कोड उत्पन्न करता है, जिसका उपयोग Office दस्तावेज़ों या टेम्पलेट्स में किया जाता है, और स्वचालित रूप से एप्लिकेशन नियंत्रण को बायपास करता है।https://github.com/mwrlabs/wePWNise
  • DotNetToJScript, एक JScript फ़ाइल बनाने के लिए, जो मेमोरी से .NET v2 असेंबली लोड करती है।https://github.com/tyranid/DotNetToJScript
  • PSAmsi AMSI हस्ताक्षरों का ऑडिट और विघटन करने का उपकरण है।https://github.com/cobbr/PSAmsi
  • ReflectiveDLLInjection https://github.com/stephenfewer/ReflectiveDLLInjection
  • ps1encode powershell-आधारित metasploit payload उत्पन्न करने और एन्कोड करने के लिए उपयोग किया जाता है।https://github.com/CroweCybersecurity/ps1encode
  • Worse-PDF. Windows मशीनों से Net-NTLM हैश चुराने के लिए उपयोग किया जाता है।https://github.com/3gstudent/Worse-PDF
  • SpookFlare सुरक्षा उपायों को बायपास करने के लिए विभिन्न दृष्टिकोण रखता है।https://github.com/hlldz/SpookFlare
  • GreatSCT एक ओपन-सोर्स प्रोजेक्ट है, जिसका उपयोग एप्लिकेशन व्हाइटलिस्टिंग बायपास उत्पन्न करने के लिए किया जाता है।https://github.com/GreatSCT/GreatSCT
  • NPS Powershell के बिना Powershell चलाता है।https://github.com/Ben0xA/nps
  • Meterpreter_Paranoid_Mode.sh Meterpreter के स्टेज्ड/स्टेजलेस कनेक्शन की सुरक्षा करता है।https://github.com/r00t-3xp10it/Meterpreter_Paranoid_Mode-SSL
  • backdoor-factory (BDF) उपयोगकर्ता द्वारा आवश्यक shellcode के साथ निष्पादन योग्य बाइनरी को पैच करेगा, और पैच से पहले की स्थिति को सामान्य रूप से निष्पादित करना जारी रखेगा।https://github.com/secretsquirrel/the-backdoor-factory
  • MacroShop स्क्रिप्ट संग्रह, Office मैक्रो के माध्यम से payload डिलीवर करने में सहायता के लिए।https://github.com/khr0x40sh/MacroShop
  • UnmanagedPowerShell अनमैनेज्ड प्रोसेस से PowerShell निष्पादित करता है।https://github.com/leechristensen/UnmanagedPowerShell
  • evil-ssdp Spoof SSDP नेटवर्क पर NTLM हैश के लिए फ़िशिंग के उत्तर देता है। एक नकली UPNP डिवाइस बनाता है, जो उपयोगकर्ताओं को दुर्भावनापूर्ण वेब फ़िशिंग पेज पर जाने के लिए लुभाता है।https://gitlab.com/initstring/evil-ssdp
  • Ebowla पर्यावरण-महत्वपूर्ण payload बनाने का ढांचा।https://github.com/Genetic-Malware/Ebowla
  • make-pdf एम्बेडेड उपकरण एम्बेडेड फ़ाइलों वाले PDF दस्तावेज़ बनाने के लिए उपयोग किया जा सकता है।https://github.com/DidierStevens/DidierStevensSuite/blob/master/make-pdf-embedded.py
  • avet (AntiVirusEvasionTool) विभिन्न बायपास तकनीकों का उपयोग करके Windows मशीनों को लक्ष्य बनाता है।https://github.com/govolution/avet
  • EvilClippy दुर्भावनापूर्ण MS Office दस्तावेज़ बनाने के लिए क्रॉस-प्लेटफ़ॉर्म सहायक है। VBA मैक्रो छिपा सकता है, मैक्रो को ऑब्सफस्केट कर सकता है। Linux, OSX और Windows पर चलता है।https://github.com/outflanknl/EvilClippy
  • CallObfuscator स्थैतिक विश्लेषण उपकरणों और डिबगर्स से Windows API को ऑब्सफस्केट करता है।https://github.com/d35ha/CallObfuscator
  • Donut एक Shellcode जनरेशन उपकरण है, जो .NET असेंबली से पोजीशन-इंडिपेंडेंट Shellcode payload बना सकता है। यह shellcode Assembly को किसी भी Windows प्रोसेस में इंजेक्ट करने के लिए उपयोग किया जा सकता है।https://github.com/TheWover/donut
  • https://github.com/Marten4n6/EvilOSX
  • EggShell https://github.com/neoneggplant/EggShell

  • Rapid Attack Infrastructure (RAI) रेड टीम इन्फ्रास्ट्रक्चर टूलसेट https://github.com/obscuritylabs/RAI

  • Red Baron https://github.com/byt3bl33d3r/Red-Baron

  • EvilURL IDN होमोग्लिफ अटैक के लिए यूनिकोड दुर्भावनापूर्ण डोमेन उत्पन्न करता है और उनका पता लगाता है. https://github.com/UndeadSec/EvilURL

  • Domain Hunter समाप्त डोमेन, Bluecoat वर्गीकरण और Archive.org इतिहास की जाँच करता है, ताकि फ़िशिंग और C2 डोमेन के लिए सर्वोत्तम विकल्प निर्धारित किए जा सकें।https://github.com/threatexpress/domainhunter

  • PowerDNS https://github.com/mdsecactivebreach/PowerDNS

  • Chameleon प्रॉक्सी वर्गीकरण से बचने का उपकरण। https://github.com/mdsecactivebreach/Chameleon

  • CatMyFish https://github.com/Mr-Un1k0d3r/CatMyFish

  • Malleable C2 C2 Profiles https://github.com/rsmudge/Malleable-C2-Profiles

  • Malleable-C2-Randomizer https://github.com/bluscreenofjeff/Malleable-C2-Randomizer

  • FindFrontableDomains संभावित फ्रंटेबल डोमेन खोजता है। https://github.com/rvrsh3ll/FindFrontableDomains

  • Postfix-Server-Setup तेज़ी से फ़िशिंग सर्वर स्थापित करें https://github.com/n0pe-sled/Postfix-Server-Setup

  • DomainFrontingLists उपलब्ध CDN फ्रंटिंग डोमेन सूचीhttps://github.com/vysec/DomainFrontingLists

  • Apache2-Mod-Rewrite-Setup C2 रीडायरेक्शन https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup

  • mod_rewrite rule सैंडबॉक्स बायपास https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10

  • external_c2 framework python में लिखा गया External C2. https://github.com/Und3rf10w/external_c2_framework

  • Malleable-C2-Profiles https://www.cobaltstrike.com/. https://github.com/xx0hcd/Malleable-C2-Profiles

  • ExternalC2 https://github.com/ryhanson/ExternalC2

  • cs2modrewrite https://github.com/threatexpress/cs2modrewrite

  • e2modrewrite https://github.com/infosecn1nja/e2modrewrite

  • redi CobaltStrike रीडायरेक्शन सेट करेंhttps://github.com/taherio/redi

  • cat-sites वर्गीकरण के लिए साइट लाइब्रेरी। https://github.com/audrummer15/cat-sites

  • ycsm तेज़ी से nginx रिवर्स प्रॉक्सी सेट करें https://github.com/infosecn1nja/ycsm

  • Domain Fronting Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting

  • DomainFrontDiscover https://github.com/peewpw/DomainFrontDiscover

  • Automated Empire Infrastructure https://github.com/bneg/RedTeam-Automation

  • Serving Random Payloads with NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9

  • meek https://github.com/arlolra/meek

  • CobaltStrike-ToolKit CS स्क्रिप्ट https://github.com/killswitch-GUI/CobaltStrike-ToolKit

  • mkhtaccess_red स्वचालित रूप से HTaccess उत्पन्न करता है payload डिलीवरी के लिए - स्वचालित रूप से पहले देखी गई सैंडबॉक्स कंपनियों/स्रोतों से ips/nets आदि निकालता है, और उन्हें हानिरहित payload पर रीडायरेक्ट करता है।https://github.com/violentlydave/mkhtaccess_red

  • RedFile Payload सेवा https://github.com/outflanknl/RedFile

  • keyserver https://github.com/leoloobeek/keyserver

  • DoHC2 https://github.com/SpiderLabs/DoHC2

  • HTran https://github.com/HiwinCN/HTran

  • DomainPasswordSpray https://github.com/dafthack/DomainPasswordSpray
  • WMIOps https://github.com/ChrisTruncer/WMIOps
  • Mimikatz https://github.com/gentilkiwi/mimikatz
  • LaZagne https://github.com/AlessandroZ/LaZagne
  • mimipenguin Linux पासवर्ड निकालता है https://github.com/huntergregal/mimipenguin
  • PsExec https://docs.microsoft.com/en-us/sysinternals/downloads/psexec
  • KeeThief https://github.com/HarmJ0y/KeeThief
  • PSAttack https://github.com/jaredhaight/PSAttack
  • Internal Monologue Attack LSASS को छुए बिना NTLM हैश प्राप्त कर सकता है।https://github.com/eladshamir/Internal-Monologue
  • Impacket python टूलकिट https://github.com/CoreSecurity/impacket
  • icebreaker यदि आप आंतरिक नेटवर्क पर हैं लेकिन AD वातावरण में नहीं हैं, तो यह प्लेनटेक्स्ट Active Directory क्रेडेंशियल प्राप्त करेगा। https://github.com/DanMcInerney/icebreaker
  • **Living Off The Land Binaries and Scripts (and now also Libraries)**https://github.com/api0cradle/LOLBAS
  • WSUSpendu https://github.com/AlsidOfficial/WSUSpendu
  • Evilgrade https://github.com/infobyte/evilgrade
  • NetRipper Windows सिस्टम के लिए पोस्ट-एक्सप्लॉइटेशन उपकरण है, जो API hook का उपयोग करके कम विशेषाधिकार वाले उपयोगकर्ताओं के नेटवर्क ट्रैफ़िक और एन्क्रिप्शन-संबंधित कार्यों को इंटरसेप्ट करता है, ताकि एन्क्रिप्शन से पहले/डिक्रिप्शन के बाद प्लेनटेक्स्ट ट्रैफ़िक और एन्क्रिप्टेड ट्रैफ़िक को कैप्चर किया जा सके।https://github.com/NytroRST/NetRipper
  • LethalHTA DCOM और HTA का उपयोग करने वाली लेटरल मूवमेंट तकनीक। https://github.com/codewhitesec/LethalHTA
  • Invoke-PowerThIEf https://github.com/nettitude/Invoke-PowerThIEf
  • RedSnarf https://github.com/nccgroup/redsnarf
  • HoneypotBuster रेड टीम के लिए डिज़ाइन किया गया Microsoft PowerShell मॉड्यूल है, जिसका उपयोग नेटवर्क या होस्ट में हनीपॉट और टोकन खोजने के लिए किया जा सकता है। https://github.com/JavelinNetworks/HoneypotBuster
  • PAExec रिमोट Windows कंप्यूटर पर Windows प्रोग्राम शुरू करता है, बिना पहले रिमोट कंप्यूटर पर सॉफ़्टवेयर इंस्टॉल किए। https://www.poweradmin.com/paexec/
  • https://github.com/machosec/Mystique
  • Rubeus https://github.com/GhostPack/Rubeus
  • kekeo https://github.com/gentilkiwi/kekeo
  • https://github.com/WazeHell/PE-Linux Linux विशेषाधिकार वृद्धि उपकरण
  • https://guif.re/linuxeop Linux विशेषाधिकार वृद्धि कमांड संग्रह
  • https://github.com/sam-b/CVE-2014-4113 Win32k.sys कर्नेल भेद्यता का उपयोग करके विशेषाधिकार वृद्धि, ms14-058
  • https://github.com/breenmachine/RottenPotatoNG NBNS स्थानीय डोमेन स्पूफिंग और WPAD प्रॉक्सी स्पूफिंग का उपयोग करके विशेषाधिकार वृद्धि
  • https://github.com/unamer/CVE-2018-8120 Win32k घटक को प्रभावित करता है, Windows 7 और Windows 2008 के लिए विशेषाधिकार वृद्धि
  • https://github.com/alpha1ab/CVE-2018-8120 Windows 7 और Windows 2008 के आधार पर Windows XP और Windows 2003 जोड़ता है
  • https://github.com/0xbadjuju/Tokenvator Windows टोकन का उपयोग करके विशेषाधिकार बढ़ाने का उपकरण, एक इंटरैक्टिव कमांड-लाइन इंटरफ़ेस प्रदान करता है