Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Strumenti/GitHubGitHub/al1ex/apt-guid
OSINT (Open Source Intelligence)Privilege EscalationVulnerability AnalysisExploitationInformation GatheringPost-ExploitationCommand and ControlSocial EngineeringLearning & EducationRed TeamingCurated Resources
23125 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
GitHub
al1ex/apt-guid

APT-GUID

APT-GUID

Vedi Repository

Introduzione al progetto

Raccolta di alcune risorse nel campo APT, che coprono ma non si limitano ai seguenti aspetti

  • Strumenti di attacco APT

  • Report di analisi APT

  • Tecniche di attacco APT

Strumenti

Raccolta informazioni

Raccolta attiva di intelligence
  • EyeWitness può acquisire screenshot di siti web, fornire alcune informazioni sul server e identificare le credenziali predefinite quando possibile https://github.com/ChrisTruncer/EyeWitness
  • AWSBucketDump è uno strumento per enumerare rapidamente i bucket AWS S3 alla ricerca di dati utili https://github.com/jordanpotti/AWSBucketDump
  • AQUATONE è uno strumento per la raccolta di informazioni sui domini https://github.com/michenriksen/aquatone
  • Spoofcheck, usato per verificare se un dominio può essere spoofato; il programma controlla se nei record SPF e DMARC esistono configurazioni deboli che consentono lo spoofing https://github.com/BishopFox/spoofcheck
  • Nmap è usato per scoprire host e servizi su reti di computer https://github.com/nmap/nmap
  • dnsrecon è uno script di enumerazione DNS https://github.com/darkoperator/dnsrecon
  • dirsearch è un semplice strumento a riga di comando per il brute force delle directory dei siti web https://github.com/maurosoria/dirsearch
  • Sn1per è uno strumento di penetration test automatizzato https://github.com/1N3/Sn1per
Raccolta passiva di intelligence
  • Social Mapper è uno strumento OSINT per la mappatura dei social media che prende un elenco di nomi utente e immagini (o nomi di aziende LinkedIn) ed esegue ricerche automatiche di massa su più siti di social media. Non è limitato dalle API perché usa Selenium. https://github.com/SpiderLabs/social_mapper
  • skiptracer è un framework di sfruttamento OSINT https://github.com/xillwillx/skiptracer
  • FOCA è usato principalmente per trovare metadati e informazioni nascoste nei documenti scansionati. https://github.com/ElevenPaths/FOCA
  • theHarvester è usato per raccogliere sottodomini, indirizzi email, host virtuali, porte/banner e nomi di dipendenti da diverse fonti pubbliche. https://github.com/laramies/theHarvester
  • Metagoofil è uno strumento per estrarre i metadati dei documenti pubblici disponibili nei siti web target (pdf, doc, xls, ppt, ecc.). https://github.com/laramies/metagoofil
  • SimplyEmail per la ricognizione delle email. https://github.com/killswitch-GUI/SimplyEmail
  • truffleHog cerca dati sensibili nei repository git, esaminando a fondo la cronologia dei commit e i branch. https://github.com/dxa4481/truffleHog
  • Just-Metadata è uno strumento per raccogliere e analizzare metadati relativi agli indirizzi IP. Tenta di trovare relazioni tra sistemi in grandi set di dati. https://github.com/ChrisTruncer/Just-Metadata
  • typofinder mostra il paese/regione in cui si trova un indirizzo IP. https://github.com/nccgroup/typofinder
  • pwnedOrNot è uno script Python che verifica se un account email è stato compromesso a causa di una violazione dei dati; se l'account email è compromesso, procede alla ricerca della password di quell'account. https://github.com/thewhiteh4t/pwnedOrNot
  • GitHarvester è uno strumento per raccogliere informazioni da GitHub, ad esempio con Google dork.

Sfruttamento di vulnerabilità

  • WinRAR Remote Code Execution Proof of Concept exploit for CVE-2018-20250. https://github.com/WyAtu/CVE-2018-20250
  • Composite Moniker Proof of Concept exploit for CVE-2017-8570. https://github.com/rxwx/CVE-2017-8570
  • Exploit toolkit CVE-2017-8759 https://github.com/bhdresh/CVE-2017-8759
  • CVE-2017-11882 Exploit https://github.com/unamer/CVE-2017-11882
  • Adobe Flash Exploit CVE-2018-4878. https://github.com/anbai-inc/CVE-2018-4878
  • Exploit toolkit CVE-2017-0199 è un comodo script Python che offre a penetration tester e ricercatori di sicurezza un modo rapido ed efficace per testare l'RCE di Microsoft Office. https://github.com/bhdresh/CVE-2017-0199
  • demiguise strumento di crittografia HTA https://github.com/nccgroup/demiguise
  • Office-DDE-Payloads raccoglie script e template per generare documenti Office con DDE incorporato (tecnica di esecuzione di comandi senza macro). https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads
  • CACTUSTORCH per la generazione di payload per la simulazione di avversari. https://github.com/mdsecactivebreach/CACTUSTORCH
  • SharpShooter è un framework per la creazione di payload per eseguire codice sorgente CSharp arbitrario. https://github.com/mdsecactivebreach/SharpShooter
  • DKMC, uno strumento per generare shellcode offuscati memorizzati nelle immagini. L'immagine è valida al 100% ed è anche shellcode valido al 100%. https://github.com/Mr-Un1k0d3r/DKMC
  • Malicious Macro Generator viene usato per generare macro offuscate, includendo anche meccanismi di evasione AV/sandbox. https://github.com/Mr-Un1k0d3r/MaliciousMacroGenerator

Social Engineering e Phishing

  • King Phisher https://github.com/securestate/king-phisher
  • FiercePhish https://github.com/Raikia/FiercePhish
  • ReelPhish https://github.com/fireeye/ReelPhish/
  • Gophish https://github.com/gophish/gophish
  • CredSniper https://github.com/ustayready/CredSniper
  • PwnAuth https://github.com/fireeye/PwnAuth
  • Phishing Frenzy https://github.com/pentestgeek/phishing-frenzy
  • Phishing Pretexts https://github.com/L4bF0x/PhishingPretexts
  • Modlishka https://github.com/drk1wi/Modlishka
  • Evilginx2 https://github.com/kgretzky/evilginx2

Framework C2

  • Cobalt Strike https://cobaltstrike.com/

  • Empire https://github.com/EmpireProject/Empire

  • Metasploit Framework https://github.com/rapid7/metasploit-framework

  • SILENTTRINITY https://github.com/byt3bl33d3r/SILENTTRINITY

  • Pupy https://github.com/n1nj4sec/pupy

  • Koadic https://github.com/zerosum0x0/koadic

  • PoshC2 https://github.com/nettitude/PoshC2_Python

  • Gcat https://github.com/byt3bl33d3r/gcat

  • TrevorC2 https://github.com/trustedsec/trevorc2

  • Merlin https://github.com/Ne0nd0g/merlin

  • Quasar https://github.com/quasar/QuasarRAT

  • Covenant https://github.com/cobbr/Covenant

  • FactionC2 https://github.com/FactionC2/

  • DNScat2 https://github.com/iagox86/dnscat2

  • Sliver https://github.com/BishopFox/sliver

  • EvilOSX

Post-esploitazione

  • CrackMapExec https://github.com/byt3bl33d3r/CrackMapExec
  • PowerLessShell https://github.com/Mr-Un1k0d3r/PowerLessShell
  • GoFetch automatizza l'esecuzione dei piani di attacco generati da BloodHound. https://github.com/GoFetchAD/GoFetch
  • ANGRYPUPPY automazione dei percorsi di attacco BloodHound in CobaltStrike. https://github.com/vysec/ANGRYPUPPY
  • DeathStar https://github.com/byt3bl33d3r/DeathStar
  • SharpHound https://github.com/BloodHoundAD/SharpHound
  • BloodHound.py è un ingestor di BloodHound basato su Python, basato su Impacket. https://github.com/fox-it/BloodHound.py
  • Responder strumento per attacchi man-in-the-middle https://github.com/SpiderLabs/Responder
  • SessionGopher è uno strumento PowerShell che usa WMI per estrarre le informazioni sulle sessioni salvate da strumenti di accesso remoto come WinSCP, PuTTY, SuperPuTTY, FileZilla e Microsoft Remote Desktop. https://github.com/fireeye/SessionGopher
  • PowerSploit insieme di strumenti PowerShell https://github.com/PowerShellMafia/PowerSploit
  • Nishang https://github.com/samratashok/nishang
  • Inveigh strumento per attacchi man-in-the-middle https://github.com/Kevin-Robertson/Inveigh
  • PowerUpSQL un toolkit PowerShell per attaccare SQL Server. https://github.com/NetSPI/PowerUpSQL
  • MailSniper https://github.com/dafthack/MailSniper

Proxy di rete

  • Tunna usato per bypassare le restrizioni di rete in ambienti con firewall https://github.com/SECFORCE/Tunna
  • reGeorg strumento proxy SOCKS https://github.com/sensepost/reGeorg
  • Blade strumento di gestione webshell https://github.com/wonderqs/Blade
  • TinyShell framework per Web Shell. https://github.com/threatexpress/tinyshell
  • PowerLurk un insieme di strumenti PowerShell per costruire WMI dannosi. https://github.com/Sw4mpf0x/PowerLurk
  • DAMP persistenza tramite modifica dei descrittori di sicurezza basati su host https://github.com/HarmJ0y/DAMP

Privilege Escalation

Privilege Escalation nel dominio
  • PowerView https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1
  • Get-GPPPassword https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-GPPPassword.ps1
  • Invoke-ACLpwn https://github.com/fox-it/Invoke-ACLPwn
  • BloodHound https://github.com/BloodHoundAD/BloodHound
  • PyKEK https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS14-068/pykek
  • Grouper strumento per trovare automaticamente vulnerabilità dei criteri di gruppo https://github.com/l0ss/Grouper
  • ADRecon https://github.com/sense-of-security/ADRecon
  • ADACLScanner https://github.com/canix1/ADACLScanner
  • ACLight usato per scoprire account privilegiati di dominio che possono essere presi di mira, inclusi gli Shadow Admins. https://github.com/cyberark/ACLight
  • LAPSToolkit https://github.com/leoloobeek/LAPSToolkit
  • PingCastle https://www.pingcastle.com/download
  • RiskySPNs è una raccolta di script PowerShell focalizzata sul rilevamento e l'interrogazione degli account associati agli SPN (Service Principal Names). https://github.com/cyberark/RiskySPN
  • Mystique è uno strumento PowerShell che funziona con le estensioni Kerberos S4U. Questo modulo, combinando KCD con la conversione di protocollo, aiuta i blue team a identificare configurazioni pericolose di delega Kerberos e i red team a impersonare qualsiasi utente.
Privilege Escalation su Linux
  • https://github.com/Al1ex/Heptagram/tree/master/Linux/Elevation Raccolta di tecniche di privilege escalation su Linux
  • https://github.com/AlessandroZ/BeRoot py, trova metodi di privilege escalation controllando configurazioni errate comuni. Supporta Windows/Linux/Mac
  • https://github.com/mschwager/0wned usa un pacchetto Python per creare utenti con privilegi elevati
  • https://github.com/mzet-/linux-exploit-suggester script per trovare quali patch mancano a Linux
  • https://github.com/belane/linux-soft-exploit-suggester trova quali software vulnerabili sono presenti su Linux
  • https://github.com/dirtycow/dirtycow.github.io exploit per la vulnerabilità di privilege escalation Dirty Cow
  • https://github.com/FireFart/dirtycow exploit per la vulnerabilità di privilege escalation Dirty Cow
  • https://github.com/stanleyb0y/sushell usa un ladro di su per permettere a utenti con privilegi bassi di rubare la password di root
  • https://github.com/jas502n/CVE-2018-17182/ vulnerabilità di privilege escalation VMA-UAF nel kernel Linux CVE-2018-17182
  • https://github.com/jas502n/CVE-2018-14665 CVE-2018-14665, exploit di privilege escalation per il server X Xorg su Linux
  • https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897 sfrutta le Syscall per ottenere privilege escalation su Linux
  • https://github.com/can1357/CVE-2018-8897 sfrutta le Syscall per ottenere privilege escalation su Linux
  • https://github.com/SecWiki/linux-kernel-exploits linux-kernel-exploits raccolta di vulnerabilità di privilege escalation per piattaforma Linux
  • https://github.com/nilotpalbiswas/Auto-Root-Exploit script automatico di privilege escalation per Linux
Privilege Escalation su Windows
  • https://github.com/Al1ex/Heptagram/tree/master/Windows/Elevation Raccolta di tecniche di privilege escalation su Windows
  • http://www.fuzzysecurity.com/tutorials/16.html articolo di riferimento a livello di tutorial per la privilege escalation su piattaforma Windows
  • https://github.com/SecWiki/windows-kernel-exploits raccolta di exploit di vulnerabilità di privilege escalation su piattaforma Windows
  • https://github.com/51x/WHP vari strumenti di privilege escalation e exploitation per Windows
  • https://github.com/rasta-mouse/Sherlock verifica delle vulnerabilità di privilege escalation su Windows
  • https://github.com/WindowsExploits/Exploits exploit di privilege escalation per Microsoft CVE-2012-0217, CVE-2016-3309, CVE-2016-3371, CVE-2016-7255, CVE-2017-0213
  • https://github.com/decoder-it/lonelypotato variante di RottenPotatoNG, sfrutta lo spoofing del dominio locale NBNS e lo spoofing del proxy WPAD per la privilege escalation
  • https://github.com/ohpe/juicy-potato variante di RottenPotatoNG, usa oggetti COM e token utente per la privilege escalation
  • https://github.com/foxglovesec/Potato variante di RottenPotatoNG, sfrutta lo spoofing del dominio locale e il proxy spoofing per la privilege escalation
  • https://github.com/DanMcInerney/icebreaker se ti trovi in una rete interna ma fuori dall'ambiente AD, icebreaker ti aiuterà a ottenere credenziali Active Directory in chiaro (l'Active Directory memorizzata nei controller di dominio può essere usata per la privilege escalation)
  • https://github.com/hausec/ADAPE-Script script di privilege escalation per Active Directory
  • https://github.com/klionsec/BypassAV-AllThings usa una webshell aspx one-liner insieme a payload di privilege escalation
  • https://github.com/St0rn/Windows-10-Exploit plugin per MSF, bypass UAC su Windows 10

Esfiltrazione dati

  • CloakifyFactory & the Cloakify Toolset - https://github.com/TryCatchHCF/Cloakify
  • DET (è fornito così com'è), è una POC per eseguire esfiltrazione di dati usando uno o più canali contemporaneamente. https://github.com/sensepost/DET
  • DNSExfiltrator . https://github.com/Arno0x/DNSExfiltrator
  • PyExfil un pacchetto Python per l'esfiltrazione di dati. https://github.com/ytisf/PyExfil
  • Egress-Assess è uno strumento per testare le capacità di rilevamento dei dati in uscita. https://github.com/ChrisTruncer/Egress-Assess
  • Powershell RAT backdoor basato su Python che usa Gmail per trasferire dati come allegati email. https://github.com/Viralmaniar/Powershell-RAT

Altro

Simulazione di avversari
  • MITRE CALDERA simula le tecniche di attacco degli intrusi e le analizza https://github.com/mitre/caldera
  • APTSimulator https://github.com/NextronSystems/APTSimulator
  • Atomic Red Team - https://github.com/redcanaryco/atomic-red-team
  • Network Flight Simulator https://github.com/alphasoc/flightsim
  • Metta - https://github.com/uber-common/metta
  • Red Team Automation (RTA) - RTA fornisce un framework di script che permette ai blue team di modellare le proprie difese secondo MITRE ATT&CK e testare le capacità di rilevamento contro strumenti dannosi. https://github.com/endgameinc/RTA
Attacchi wireless
  • Wifiphisher strumento di attacco automatico di associazione WIFI. https://github.com/wifiphisher/wifiphisher
  • mana attacco man-in-the-middle. https://github.com/sensepost/mana
Attacchi embedded- magspoof https://github.com/samyk/magspoof
  • WarBerryPi https://github.com/secgroundzero/warberry
  • P4wnP1 https://github.com/mame82/P4wnP1
  • malusb https://github.com/ebursztein/malusb
  • Fenrir https://github.com/Orange-Cyberdefense/fenrir-ocd
  • poisontap https://github.com/samyk/poisontap
  • WHID https://github.com/whid-injector/WHID
  • PhanTap https://github.com/nccgroup/phantap
Comunicazioni occulte
  • RocketChat https://rocket.chat
  • Etherpad https://etherpad.org/
Gestione dei log
  • RedELK https://github.com/outflanknl/RedELK/
  • CobaltSplunk https://github.com/vysec/CobaltSplunk
  • Red Team Telemetry https://github.com/ztgrace/red_team_telemetry
  • Elastic for Red Teaming https://github.com/SecurityRiskAdvisors/RedTeamSIEM
  • Ghostwriter https://github.com/GhostManager/Ghostwriter
Weaponizzazione in C#
  • SharpSploit framework di post-exploitation .NET https://github.com/cobbr/SharpSploit
  • GhostPack set di strumenti C# https://github.com/GhostPack
  • SharpWeb recupera le password dei browser comuni https://github.com/djhohnstein/SharpWeb
  • reconerator https://github.com/stufus/reconerator
  • SharpView versione C# di PowerView. https://github.com/tevora-threat/SharpView
  • Watson https://github.com/rasta-mouse/Watson
LABS
  • Detection Lab automatizza la creazione di un lab https://github.com/clong/DetectionLab ---consigliato a cinque stelle
  • Modern Windows Attacks and Defense Labhttps://github.com/jaredhaight/WindowsAttackAndDefenseLab
  • Invoke-UserSimulator https://github.com/ubeeri/Invoke-UserSimulator
  • Invoke-ADLabDeployer distribuzione automatizzata di ambienti AD https://github.com/outflanknl/Invoke-ADLabDeployer
  • Sheepl https://github.com/SpiderLabs/sheepl
Script
Aggressor Scripts
  • https://github.com/invokethreatguy/CSASC
  • https://github.com/secgroundzero/CS-Aggressor-Scripts
  • https://github.com/Und3rf10w/Aggressor-scripts
  • https://github.com/harleyQu1nn/AggressorScripts
  • https://github.com/rasta-mouse/Aggressor-Script
  • https://github.com/RhinoSecurityLabs/Aggressor-Scripts
  • https://github.com/bluscreenofjeff/AggressorScripts
  • https://github.com/001SPARTaN/aggressor_scripts
  • https://github.com/360-A-Team/CobaltStrike-Toolset
  • https://github.com/FortyNorthSecurity/AggressorAssessor
  • https://github.com/ramen0x3f/AggressorScripts
Red-Team
  • https://github.com/FuzzySecurity/PowerShell-Suite
  • https://github.com/nettitude/Powershell
  • https://github.com/Mr-Un1k0d3r/RedTeamPowershellScripts
  • https://github.com/threatexpress/red-team-scripts
  • https://github.com/SadProcessor/SomeStuff
  • https://github.com/rvrsh3ll/Misc-Powershell-Scripts
  • https://github.com/enigma0x3/Misc-PowerShell-Stuff
  • https://github.com/ChrisTruncer/PenTestScripts
  • https://github.com/bluscreenofjeff/Scripts
  • https://github.com/xorrior/RandomPS-Scripts
  • https://github.com/xorrior/Random-CSharpTools
  • https://github.com/leechristensen/Random
  • https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/social-engineering
Scarica lo strumento
https://github.com/metac0rtex/GitHarvester
  • pwndb è uno strumento a riga di comando in Python per cercare credenziali trapelate utilizzando il servizio Onion con lo stesso nome. https://github.com/davidtavarez/pwndb/
  • LinkedInt è uno strumento di ricognizione per LinkedIn. https://github.com/vysecurity/LinkedInt
  • CrossLinked è uno strumento di enumerazione LinkedIn che estrae nomi di dipendenti validi da un'organizzazione tramite lo scraping dei motori di ricerca. https://github.com/m8r0wn/CrossLinked
  • findomain è uno strumento rapido per l'enumerazione dei sottodomini; utilizza i log di trasparenza dei certificati e alcune API. https://github.com/Edu4rdSHL/findomain
  • SCT-obfuscator offuscatore di payload SCT per Cobalt Strike. https://github.com/Mr-Un1k0d3r/SCT-obfuscator
  • Invoke-Obfuscation offuscatore PowerShell. https://github.com/danielbohannon/Invoke-Obfuscation
  • Invoke-CradleCrafter generatore e offuscatore per il download remoto di PowerShell. https://github.com/danielbohannon/Invoke-CradleCrafter
  • Invoke-DOSfuscation generatore di offuscamento dei comandi di cmd.exe e strumento per testare il rilevamento. https://github.com/danielbohannon/Invoke-DOSfuscation
  • morphHTA。https://github.com/vysec/morphHTA
  • Unicorn è un semplice strumento che usa l'attacco di downgrade di PowerShell per iniettare direttamente shellcode in memoria. https://github.com/trustedsec/unicorn
  • Shellter è uno strumento dinamico di iniezione di shellcode e il primo vero infector dinamico di PE della storia. https://www.shellterproject.com/
  • EmbedInHTML incorpora e nasconde qualsiasi file nell'HTML. https://github.com/Arno0x/EmbedInHTML
  • SigThief ruba le firme e crea una firma non valida. https://github.com/secretsquirrel/SigThief
  • Veil,https://github.com/Veil-Framework/Veil
  • CheckPlease è un modulo di evasione sandbox scritto in PowerShell, Python, Go, Ruby, C, C#, Perl e Rust. https://github.com/Arvanaghi/CheckPlease
  • Invoke-PSImage è uno strumento che incorpora uno script PowerShell nei pixel di un file PNG e può eseguirlo. https://github.com/peewpw/Invoke-PSImage
  • LuckyStrike è un'utility basata su PowerShell per creare documenti Office con macro dannose. Da usare solo per penetration test o scopi educativi. https://github.com/curi0usJack/luckystrike
  • ClickOnceGenerator https://github.com/Mr-Un1k0d3r/ClickOnceGenerator
  • macro_pack è uno strumento di @EmericNasi per automatizzare l'offuscamento e la generazione di documenti MS Office, script VB e altri formati per penetration test, demo e valutazioni di social engineering. https://github.com/sevagas/macro_pack
  • StarFighters è un launcher di Empire basato su JavaScript e VBScript. https://github.com/Cn33liz/StarFighters
  • nps_payload Questo script genera payload per evitare i sistemi di rilevamento delle intrusioni di base. Sfrutta tecniche pubblicamente dimostrate da diverse fonti. https://github.com/trustedsec/nps_payload
  • SocialEngineeringPay raccoglie una serie di tecniche di social engineering e payload per il furto di credenziali e attacchi di spear phishing. https://github.com/bhdresh/SocialEngineeringPayloads
  • Social-Engineer Toolkit è un framework open source di penetration test progettato per il social engineering. https://github.com/trustedsec/social-engineer-toolkit
  • phishery è un semplice server HTTP con SSL il cui scopo principale è il phishing delle credenziali tramite autenticazione di base. https://github.com/ryhanson/phishery
  • PowerShdll esegue PowerShell con rundll32. Bypassa le restrizioni software. https://github.com/p3nt4/PowerShdll
  • UltimateAppLockerByPassList documenta le tecniche più comuni per bypassare AppLocker. https://github.com/api0cradle/UltimateAppLockerByPassList
  • ruler, consente di interagire da remoto con i server Exchange tramite i protocolli MAPI/HTTP o RPC/HTTP. https://github.com/sensepost/ruler
  • Generate-Macro è uno script PowerShell autonomo che genererà documenti Microsoft Office dannosi con payload e metodo di persistenza specificati. https://github.com/enigma0x3/Generate-Macro
  • MaliciousMacroMSBuild genera macro dannose ed esegue PowerShell o shellcode bypassando l'applicazione whitelist di MSBuild. https://github.com/infosecn1nja/MaliciousMacroMSBuild
  • Meta Twin è un cloner di risorse di file. Estrae i metadati da un file, inclusa la firma digitale, e li inietta in un altro file. https://github.com/threatexpress/metatwin
  • WePWNise genera codice VBA indipendente dall'architettura da utilizzare in documenti o modelli Office, bypassando automaticamente i controlli delle applicazioni. https://github.com/mwrlabs/wePWNise
  • DotNetToJScript, usato per creare un file JScript che carica un assembly .NET v2 dalla memoria. https://github.com/tyranid/DotNetToJScript
  • PSAmsi è uno strumento per controllare e rompere le firme AMSI. https://github.com/cobbr/PSAmsi
  • ReflectiveDLLInjection https://github.com/stephenfewer/ReflectiveDLLInjection
  • ps1encode è usato per generare e codificare payload Metasploit basati su PowerShell. https://github.com/CroweCybersecurity/ps1encode
  • Worse-PDF。Usato per rubare hash Net-NTLM da macchine Windows. https://github.com/3gstudent/Worse-PDF
  • SpookFlare ha diversi approcci per bypassare le misure di sicurezza. https://github.com/hlldz/SpookFlare
  • GreatSCT è un progetto open source per generare bypass delle whitelist delle applicazioni. https://github.com/GreatSCT/GreatSCT
  • NPS esegue PowerShell senza PowerShell. https://github.com/Ben0xA/nps
  • Meterpreter_Paranoid_Mode.sh protegge le connessioni staged/stageless di Meterpreter. https://github.com/r00t-3xp10it/Meterpreter_Paranoid_Mode-SSL
  • backdoor-factory (BDF) applica la shellcode desiderata dall'utente ai binari eseguibili e continua a eseguirli normalmente come prima della patch. https://github.com/secretsquirrel/the-backdoor-factory
  • MacroShop è una raccolta di script per facilitare la distribuzione di payload tramite macro Office. https://github.com/khr0x40sh/MacroShop
  • UnmanagedPowerShell esegue PowerShell da processi non gestiti. https://github.com/leechristensen/UnmanagedPowerShell
  • evil-ssdp Spoof usa SSDP per rispondere con hash NTLM al phishing sulla rete. Crea un dispositivo UPNP falso che induce gli utenti a visitare pagine web dannose di phishing. https://gitlab.com/initstring/evil-ssdp
  • Ebowla è un framework per creare payload dipendenti dall'ambiente. https://github.com/Genetic-Malware/Ebowla
  • make-pdf è uno strumento incorporato per creare documenti PDF con file incorporati. https://github.com/DidierStevens/DidierStevensSuite/blob/master/make-pdf-embedded.py
  • avet (AntiVirusEvasionTool) usa diverse tecniche di evasione per colpire macchine Windows con file eseguibili. https://github.com/govolution/avet
  • EvilClippy è un assistente multipiattaforma per creare documenti MS Office dannosi. Può nascondere macro VBA e offuscare le macro. Funziona su Linux, OSX e Windows. https://github.com/outflanknl/EvilClippy
  • CallObfuscator offusca le API di Windows dagli strumenti di analisi statica e dai debugger. https://github.com/d35ha/CallObfuscator
  • Donut è uno strumento di generazione di shellcode che crea payload shellcode indipendenti dalla posizione a partire da assembly .NET. Questo shellcode può essere usato per iniettare l'assembly in qualsiasi processo Windows. https://github.com/TheWover/donut
  • https://github.com/Marten4n6/EvilOSX
  • EggShell https://github.com/neoneggplant/EggShell

  • Rapid Attack Infrastructure (RAI) set di strumenti per l'infrastruttura red team https://github.com/obscuritylabs/RAI

  • Red Baron https://github.com/byt3bl33d3r/Red-Baron

  • EvilURL genera e rileva domini Unicode malevoli per attacchi di omografi IDN. https://github.com/UndeadSec/EvilURL

  • Domain Hunter controlla i domini scaduti, la classificazione Bluecoat e la cronologia di Archive.org per determinare le scelte migliori per domini di phishing e C2. https://github.com/threatexpress/domainhunter

  • PowerDNS https://github.com/mdsecactivebreach/PowerDNS

  • Chameleon strumento per eludere la classificazione dei proxy. https://github.com/mdsecactivebreach/Chameleon

  • CatMyFish https://github.com/Mr-Un1k0d3r/CatMyFish

  • Malleable C2 C2 Profiles https://github.com/rsmudge/Malleable-C2-Profiles

  • Malleable-C2-Randomizer https://github.com/bluscreenofjeff/Malleable-C2-Randomizer

  • FindFrontableDomains cerca potenziali domini frontabili. https://github.com/rvrsh3ll/FindFrontableDomains

  • Postfix-Server-Setup per configurare rapidamente un server di phishing https://github.com/n0pe-sled/Postfix-Server-Setup

  • DomainFrontingLists elenco di domini CDN frontabili disponibili https://github.com/vysec/DomainFrontingLists

  • Apache2-Mod-Rewrite-Setup redirect C2 https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup

  • mod_rewrite rule per eludere le sandbox https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10

  • external_c2 framework External C2 scritto in Python. https://github.com/Und3rf10w/external_c2_framework

  • Malleable-C2-Profiles https://www.cobaltstrike.com/. https://github.com/xx0hcd/Malleable-C2-Profiles

  • ExternalC2 https://github.com/ryhanson/ExternalC2

  • cs2modrewrite https://github.com/threatexpress/cs2modrewrite

  • e2modrewrite https://github.com/infosecn1nja/e2modrewrite

  • redi configura i redirect di CobaltStrike https://github.com/taherio/redi

  • cat-sites libreria di siti per la categorizzazione. https://github.com/audrummer15/cat-sites

  • ycsm configura rapidamente un proxy inverso nginx https://github.com/infosecn1nja/ycsm

  • Domain Fronting Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting

  • DomainFrontDiscover https://github.com/peewpw/DomainFrontDiscover

  • Automated Empire Infrastructure https://github.com/bneg/RedTeam-Automation

  • Serving Random Payloads con NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9

  • meek https://github.com/arlolra/meek

  • CobaltStrike-ToolKit script CS https://github.com/killswitch-GUI/CobaltStrike-ToolKit

  • mkhtaccess_red genera automaticamente .htaccess per la distribuzione di payload, estrae automaticamente IP/reti da aziende/fonti sandbox già viste e li reindirizza a payload benigni. https://github.com/violentlydave/mkhtaccess_red

  • RedFile servizio di payload https://github.com/outflanknl/RedFile

  • keyserver https://github.com/leoloobeek/keyserver

  • DoHC2 https://github.com/SpiderLabs/DoHC2

  • HTran https://github.com/HiwinCN/HTran

  • DomainPasswordSpray https://github.com/dafthack/DomainPasswordSpray
  • WMIOps https://github.com/ChrisTruncer/WMIOps
  • Mimikatz https://github.com/gentilkiwi/mimikatz
  • LaZagne https://github.com/AlessandroZ/LaZagne
  • mimipenguin recupera le password di Linux https://github.com/huntergregal/mimipenguin
  • PsExec https://docs.microsoft.com/en-us/sysinternals/downloads/psexec
  • KeeThief https://github.com/HarmJ0y/KeeThief
  • PSAttack https://github.com/jaredhaight/PSAttack
  • Internal Monologue Attack recupera gli hash NTLM senza toccare LSASS. https://github.com/eladshamir/Internal-Monologue
  • Impacket toolkit Python https://github.com/CoreSecurity/impacket
  • icebreaker se ti trovi su una rete interna ma non in un ambiente AD, otterrà le credenziali Active Directory in chiaro. https://github.com/DanMcInerney/icebreaker
  • **Living Off The Land Binaries and Scripts (and now also Libraries)**https://github.com/api0cradle/LOLBAS
  • WSUSpendu https://github.com/AlsidOfficial/WSUSpendu
  • Evilgrade https://github.com/infobyte/evilgrade
  • NetRipper è uno strumento post-esploitazione per sistemi Windows che usa API hook per intercettare il traffico di rete e le funzioni correlate alla crittografia di utenti con privilegi bassi, consentendo di catturare traffico in chiaro prima della crittografia e dopo la decrittazione. https://github.com/NytroRST/NetRipper
  • LethalHTA tecnica di movimento laterale che usa DCOM e HTA. https://github.com/codewhitesec/LethalHTA
  • Invoke-PowerThIEf https://github.com/nettitude/Invoke-PowerThIEf
  • RedSnarf https://github.com/nccgroup/redsnarf
  • HoneypotBuster è un modulo Microsoft PowerShell progettato per i red team, utilizzabile per trovare honeypot e token nella rete o negli host. https://github.com/JavelinNetworks/HoneypotBuster
  • PAExec avvia programmi Windows su computer remoti senza dover installare software sul computer remoto. https://www.poweradmin.com/paexec/
  • https://github.com/machosec/Mystique
  • Rubeus https://github.com/GhostPack/Rubeus
  • kekeo https://github.com/gentilkiwi/kekeo
  • https://github.com/WazeHell/PE-Linux strumento di privilege escalation per Linux
  • https://guif.re/linuxeop raccolta di comandi per la privilege escalation su Linux
  • https://github.com/sam-b/CVE-2014-4113 sfrutta la vulnerabilità del kernel Win32k.sys per l'escalation, MS14-058
  • https://github.com/breenmachine/RottenPotatoNG sfrutta lo spoofing del dominio locale NBNS e lo spoofing del proxy WPAD per la privilege escalation
  • https://github.com/unamer/CVE-2018-8120 colpisce il componente Win32k, privilege escalation per Windows 7 e Windows Server 2008
  • https://github.com/alpha1ab/CVE-2018-8120 aggiunge Windows XP e Windows Server 2003 oltre a Windows 7 e Windows Server 2008
  • https://github.com/0xbadjuju/Tokenvator strumento per elevare i privilegi usando i token di Windows, fornisce un'interfaccia a riga di comando interattiva