
APT-GUID
Raccolta di alcune risorse nel campo APT, che coprono ma non si limitano ai seguenti aspetti
Strumenti di attacco APT
Report di analisi APT
Tecniche di attacco APT
Cobalt Strike https://cobaltstrike.com/
Metasploit Framework https://github.com/rapid7/metasploit-framework
SILENTTRINITY https://github.com/byt3bl33d3r/SILENTTRINITY
Covenant https://github.com/cobbr/Covenant
FactionC2 https://github.com/FactionC2/
EvilOSX
Rapid Attack Infrastructure (RAI) set di strumenti per l'infrastruttura red team https://github.com/obscuritylabs/RAI
Red Baron https://github.com/byt3bl33d3r/Red-Baron
EvilURL genera e rileva domini Unicode malevoli per attacchi di omografi IDN. https://github.com/UndeadSec/EvilURL
Domain Hunter controlla i domini scaduti, la classificazione Bluecoat e la cronologia di Archive.org per determinare le scelte migliori per domini di phishing e C2. https://github.com/threatexpress/domainhunter
Chameleon strumento per eludere la classificazione dei proxy. https://github.com/mdsecactivebreach/Chameleon
CatMyFish https://github.com/Mr-Un1k0d3r/CatMyFish
Malleable C2 C2 Profiles https://github.com/rsmudge/Malleable-C2-Profiles
Malleable-C2-Randomizer https://github.com/bluscreenofjeff/Malleable-C2-Randomizer
FindFrontableDomains cerca potenziali domini frontabili. https://github.com/rvrsh3ll/FindFrontableDomains
Postfix-Server-Setup per configurare rapidamente un server di phishing https://github.com/n0pe-sled/Postfix-Server-Setup
DomainFrontingLists elenco di domini CDN frontabili disponibili https://github.com/vysec/DomainFrontingLists
Apache2-Mod-Rewrite-Setup redirect C2 https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup
mod_rewrite rule per eludere le sandbox https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10
external_c2 framework External C2 scritto in Python. https://github.com/Und3rf10w/external_c2_framework
Malleable-C2-Profiles https://www.cobaltstrike.com/. https://github.com/xx0hcd/Malleable-C2-Profiles
ExternalC2 https://github.com/ryhanson/ExternalC2
cs2modrewrite https://github.com/threatexpress/cs2modrewrite
e2modrewrite https://github.com/infosecn1nja/e2modrewrite
redi configura i redirect di CobaltStrike https://github.com/taherio/redi
cat-sites libreria di siti per la categorizzazione. https://github.com/audrummer15/cat-sites
ycsm configura rapidamente un proxy inverso nginx https://github.com/infosecn1nja/ycsm
Domain Fronting Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting
DomainFrontDiscover https://github.com/peewpw/DomainFrontDiscover
Automated Empire Infrastructure https://github.com/bneg/RedTeam-Automation
Serving Random Payloads con NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9
CobaltStrike-ToolKit script CS https://github.com/killswitch-GUI/CobaltStrike-ToolKit
mkhtaccess_red genera automaticamente .htaccess per la distribuzione di payload, estrae automaticamente IP/reti da aziende/fonti sandbox già viste e li reindirizza a payload benigni. https://github.com/violentlydave/mkhtaccess_red
RedFile servizio di payload https://github.com/outflanknl/RedFile
keyserver https://github.com/leoloobeek/keyserver