Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
Awesome-Red-Team-Operations — Raccolta curata di strumenti red team e pentest raggruppati per fase: payload, bypass AMSI, pivoting, persistenza, escalation dei privilegi, raccolta di credenziali ed esfiltrazione. | Kitploit
Strumenti/GitHubGitHub/joasasantos/awesome-red-team-operations
Strumenti di PhishingEscalation di PrivilegiScanner di VulnerabilitàExploitEsfiltrazione DatiRaccolta InformazioniPost-ExploitPenetration TestingCommand and Control

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Red Teaming
Risorse Curate
Sviluppo Payload
GitHubjoasasantos/awesome-red-team-operations

Awesome-Red-Team-Operations

Raccolta curata di strumenti red team e pentest raggruppati per fase: payload, bypass AMSI, pivoting, persistenza, escalation dei privilegi, raccolta di credenziali ed esfiltrazione.

Vedi Repository
1.7k3314 anni faRevisionato da Kitploit
Condividi

Awesome-Red-Team-Operation

Strumenti PenTest e Red Team di Joas e S3cur3Th1sSh1t

Script di PowerShell

  • https://github.com/S3cur3Th1sSh1t/WinPwn

  • https://github.com/dafthack/MailSniper

  • https://github.com/putterpanda/mimikittenz

  • https://github.com/dafthack/DomainPasswordSpray

  • https://github.com/mdavis332/DomainPasswordSpray

  • https://github.com/jnqpblc/SharpSpray

  • https://github.com/Arvanaghi/SessionGopher

  • https://github.com/samratashok/nishang

  • https://github.com/PowerShellMafia/PowerSploit

  • https://github.com/fdiskyou/PowerOPS

  • https://github.com/giMini/PowerMemory

  • https://github.com/Kevin-Robertson/Inveigh

  • https://github.com/MichaelGrafnetter/DSInternals

  • https://github.com/PowerShellEmpire/PowerTools

  • https://github.com/FuzzySecurity/PowerShell-Suite

  • https://github.com/hlldz/Invoke-Phant0m

  • https://github.com/leoloobeek/LAPSToolkit

  • https://github.com/n00py/LAPSDumper

  • https://github.com/sense-of-security/ADRecon

  • https://github.com/adrecon/ADRecon

  • https://github.com/S3cur3Th1sSh1t/Grouper

  • https://github.com/l0ss/Grouper2

  • https://github.com/NetSPI/PowerShell

  • https://github.com/NetSPI/PowerUpSQL

  • https://github.com/GhostPack

  • https://github.com/Kevin-Robertson/Powermad

Bypass di AMSI

  • https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell

  • https://github.com/Flangvik/AMSI.fail

  • https://github.com/p3nt4/PowerShdll

  • https://github.com/jaredhaight/PSAttack

  • https://github.com/Cn33liz/p0wnedShell

  • https://github.com/cobbr/InsecurePowerShell

  • https://github.com/bitsadmin/nopowershell

  • https://github.com/Mr-Un1k0d3r/PowerLessShell

  • https://github.com/OmerYa/Invisi-Shell

  • https://github.com/Hackplayers/Salsa-tools

  • https://github.com/padovah4ck/PSByPassCLM

  • https://github.com/rasta-mouse/AmsiScanBufferBypass

  • https://github.com/itm4n/VBA-RunPE

  • https://github.com/cfalta/PowerShellArmoury

  • https://github.com/Mr-B0b/SpaceRunner

  • https://github.com/RythmStick/AMSITrigger

  • https://github.com/rmdavy/AMSI_Ordinal_Bypass

  • https://github.com/mgeeky/Stracciatella

Hosting di Payload

  • https://github.com/kgretzky/pwndrop

  • https://github.com/sc0tfree/updog

Scanner di Condivisioni di Rete

  • https://github.com/SnaffCon/Snaffler

  • https://github.com/djhohnstein/SharpShares

  • https://github.com/vivami/SauronEye

  • https://github.com/leftp/VmdkReader

Reverse Shell

  • https://github.com/xct/xc

  • https://github.com/cytopia/pwncat

  • https://github.com/Kudaes/LOLBITS

Rilevatore di Backdoor

  • https://github.com/linuz/Sticky-Keys-Slayer

  • https://github.com/ztgrace/sticky_keys_hunter

  • https://github.com/countercept/doublepulsar-detection-script

Pivoting

  • https://github.com/0x36/VPNPivot

  • https://github.com/securesocketfunneling/ssf

  • https://github.com/p3nt4/Invoke-SocksProxy

  • https://github.com/sensepost/reGeorg

  • https://github.com/hayasec/reGeorg-Weblogic

  • https://github.com/nccgroup/ABPTTS

  • https://github.com/RedTeamOperations/PivotSuite

  • https://github.com/trustedsec/egressbuster

  • https://github.com/vincentcox/bypass-firewalls-by-DNS-history

  • https://github.com/shantanu561993/SharpChisel

  • https://github.com/jpillora/chisel

  • https://github.com/esrrhs/pingtunnel

  • https://github.com/sysdream/ligolo

  • https://github.com/nccgroup/SocksOverRDP

  • https://github.com/blackarrowsec/mssqlproxy

Persistenza su Windows

  • https://github.com/fireeye/SharPersist

  • https://github.com/outflanknl/SharpHide

  • https://github.com/HarmJ0y/DAMP

Scoperta di Framework

  • https://github.com/Tuhinshubhra/CMSeeK

  • https://github.com/Dionach/CMSmap - Scanner per Wordpress, Joomla, Drupal

  • https://github.com/wpscanteam/wpscan

  • https://github.com/Ekultek/WhatWaf

  • https://github.com/KingOfBugbounty/KingOfBugBountyTips

Scanner / Exploit di Framework

  • https://github.com/wpscanteam/wpscan - wordpress

  • https://github.com/n00py/WPForce

  • https://github.com/m4ll0k/WPSeku https://github.com/swisskyrepo/Wordpresscan

  • https://github.com/rastating/wordpress-exploit-framework

  • https://github.com/coldfusion39/domi-owned - lotus domino

  • https://github.com/droope/droopescan - Drupal

  • https://github.com/whoot/Typo-Enumerator - Typo3

  • https://github.com/rezasp/joomscan - Joomla

Scoperta di File / Directory / Parametri

  • https://github.com/OJ/gobuster

  • https://github.com/nccgroup/dirble

  • https://github.com/maK-/parameth

  • https://github.com/devanshbatham/ParamSpider - Estrazione di parametri dagli angoli oscuri degli archivi Web

  • https://github.com/s0md3v/Arjun - 💗

  • https://github.com/Cillian-Collins/dirscraper - Ricerca di directory da file JavaScript

  • https://github.com/hannob/snallygaster

  • https://github.com/maurosoria/dirsearch

  • https://github.com/s0md3v/Breacher - Ricerca di pannelli di amministrazione

  • https://github.com/mazen160/server-status_PWN

  • https://github.com/helviojunior/turbosearch

Audit delle API REST

  • https://github.com/microsoft/restler-fuzzer - RESTler è il primo strumento di fuzzing stateful per API REST che testa automaticamente i servizi cloud tramite le loro API REST e trova bug di sicurezza e affidabilità in questi servizi.

  • https://github.com/flipkart-incubator/Astra

Escalation dei Privilegi su Windows / Audit

  • https://github.com/itm4n/PrivescCheck - Script di enumerazione per l'escalation dei privilegi su Windows

  • https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS - potente script di controllo per l'escalation dei privilegi con un ottimo output

  • https://github.com/AlessandroZ/BeRoot

  • https://github.com/rasta-mouse/Sherlock

  • https://github.com/hfiref0x/UACME - UAC

  • https://github.com/rootm0s/WinPwnage - UAC

  • https://github.com/abatchy17/WindowsExploits

  • https://github.com/dafthack/HostRecon

  • https://github.com/sensepost/rattler - trova DLL vulnerabili per attacchi di preloading

  • https://github.com/WindowsExploits/Exploits

  • https://github.com/Cybereason/siofra - scanner per DLL hijacking

  • https://github.com/0xbadjuju/Tokenvator - da admin a system

  • https://github.com/MojtabaTajik/Robber

  • https://github.com/411Hall/JAWS

  • https://github.com/GhostPack/SharpUp

  • https://github.com/GhostPack/Seatbelt

LinkedIn

  • https://www.linkedin.com/in/joas-antonio-dos-santos

Abuso dei Privilegi di Windows (Escalation dei Privilegi)

  • https://github.com/gtworek/Priv2Admin - Abusa dei privilegi di Windows

  • https://github.com/itm4n/UsoDllLoader - carica DLL dannose da system32

  • https://github.com/TsukiCTF/Lovely-Potato - Sfrutta i Potato con automazione

  • https://github.com/antonioCoco/RogueWinRM - da account di servizio a System

  • https://github.com/antonioCoco/RoguePotato - Un'altra escalation dei privilegi locale di Windows da account di servizio a System

  • https://github.com/itm4n/PrintSpoofer - Abuso dei privilegi di impersonificazione su Windows 10 e Server 2019

  • https://github.com/BeichenDream/BadPotato - il PrintSpoofer di itm4n in C#

  • https://github.com/itm4n/FullPowers - Recupera il set di privilegi predefinito di un account LOCAL/NETWORK SERVICE

Esfiltrazione

  • https://github.com/gentilkiwi/mimikatz

  • https://github.com/GhostPack/SafetyKatz

  • https://github.com/Flangvik/BetterSafetyKatz - Fork di SafetyKatz che recupera dinamicamente l'ultima release precompilata di Mimikatz direttamente dal repository GitHub di gentilkiwi, applica patch alle firme a runtime e usa SharpSploit DInvoke per il PE-Load in memoria.

  • https://github.com/GhostPack/Rubeus

  • https://github.com/Arvanaghi/SessionGopher

  • https://github.com/peewpw/Invoke-WCMDump

  • https://github.com/tiagorlampert/sAINT

  • https://github.com/AlessandroZ/LaZagneForensic - lazagne remoto

  • https://github.com/eladshamir/Internal-Monologue

  • https://github.com/djhohnstein/SharpWeb - Raccolta di credenziali del browser

  • https://github.com/moonD4rk/HackBrowserData - hack-browser-data è uno strumento open-source che può aiutarti a decrittare i dati [passwords|bookmarks|cookies|history] dal browser.

  • https://github.com/mwrlabs/SharpClipHistory - La funzionalità ClipHistory recupera le ultime 25 azioni di copia e incolla

  • https://github.com/outflanknl/Dumpert - dump di LSASS utilizzando chiamate di sistema dirette e API unhooking

  • https://github.com/b4rtik/SharpMiniDump - Crea un minidump del processo LSASS dalla memoria - usando Dumpert

Staging

  • Rapid Attack Infrastructure (RAI) Infrastruttura Red Team... Veloce... Rapida... Semplificata. Una delle fasi più noiose di un'operazione Red Team è di solito la configurazione dell'infrastruttura. Questo di solito comporta un teamserver o controller, domini, redirector e un server di phishing. https://github.com/obscuritylabs/RAI

  • Red Baron è un insieme di moduli e provider personalizzati/di terze parti per Terraform che tenta di automatizzare la creazione di infrastrutture resilienti, usa e getta, sicure e agili per i Red Team. https://github.com/byt3bl33d3r/Red-Baron

  • EvilURL genera domini dannosi unicode per l'IDN Homograph Attack e li rileva. https://github.com/UndeadSec/EvilURL

  • Domain Hunter controlla i domini scaduti, la categorizzazione Bluecoat e la cronologia di Archive.org per determinare buoni candidati per nomi di dominio di phishing e C2. https://github.com/threatexpress/domainhunter

  • PowerDNS è una semplice proof of concept per dimostrare l'esecuzione di script PowerShell utilizzando solo DNS. https://github.com/mdsecactivebreach/PowerDNS

  • Chameleon è uno strumento per eludere la categorizzazione dei proxy. https://github.com/mdsecactivebreach/Chameleon

  • CatMyFish cerca domini categorizzati che possono essere utilizzati durante un engagement di red teaming. Perfetto per configurare un dominio in whitelist per il C&C del tuo beacon Cobalt Strike. https://github.com/Mr-Un1k0d3r/CatMyFish

  • Malleable C2 è un linguaggio specifico di dominio per ridefinire gli indicatori nella comunicazione di Beacon. https://github.com/rsmudge/Malleable-C2-Profiles

  • Malleable-C2-Randomizer Questo script randomizza i profili Malleable C2 di Cobalt Strike tramite l'uso di un metalinguaggio, riducendo così le possibilità di attivare i controlli di rilevamento basati su firme. https://github.com/bluscreenofjeff/Malleable-C2-Randomizer

  • FindFrontableDomains cerca potenziali domini frontable.

Buffer Overflow e Sviluppo di Exploit

  • https://github.com/CyberSecurityUP/Buffer-Overflow-Labs

  • https://github.com/gh0x0st/Buffer_Overflow

  • https://github.com/freddiebarrsmith/Buffer-Overflow-Exploit-Development-Practice

  • https://github.com/21y4d/Windows_BufferOverflowx32

  • https://github.com/johnjhacking/Buffer-Overflow-Guide

  • https://github.com/npapernot/buffer-overflow-attack

  • https://github.com/V1n1v131r4/OSCP-Buffer-Overflow

  • https://github.com/KINGSABRI/BufferOverflow-Kit

  • https://github.com/FabioBaroni/awesome-exploit-development

  • https://github.com/Gallopsled/pwntools

  • https://github.com/hardenedlinux/linux-exploit-development-tutorial

  • https://github.com/Billy-Ellis/Exploit-Challenges

  • https://github.com/wtsxDev/Exploit-Development

MindMaps di Joas

  • https://www.mindmeister.com/pt/1746180947/web-attacks-bug-bounty-and-appsec-by-joas-antonio

  • https://www.mindmeister.com/pt/1760781948/information-security-certifications-by-joas-antonio

  • https://www.mindmeister.com/pt/1781013629/the-best-labs-and-ctf-red-team-and-pentest

  • https://www.mindmeister.com/pt/1760781948/information-security-certifications-by-joas-antonio

  • https://www.mindmeister.com/pt/1746187693/cyber-security-career-knowledge-by-joas-antonio

Movimento Laterale

  • https://github.com/0xthirteen/SharpRDP

  • https://github.com/0xthirteen/MoveKit

  • https://github.com/0xthirteen/SharpMove

  • https://github.com/rvrsh3ll/SharpCOM

  • https://github.com/malcomvetter/CSExec

  • https://github.com/byt3bl33d3r/CrackMapExec

  • https://github.com/cube0x0/SharpMapExec

  • https://github.com/nccgroup/WMIcmd

  • https://github.com/rasta-mouse/MiscTools

  • https://github.com/byt3bl33d3r/DeathStar

  • https://github.com/SpiderLabs/portia

  • https://github.com/Screetsec/Vegile

  • https://github.com/DanMcInerney/icebreaker

  • https://github.com/MooseDojo/apt2

  • https://github.com/hdm/nextnet

  • https://github.com/mubix/IOXIDResolver

  • https://github.com/Hackplayers/evil-winrm

  • https://github.com/bohops/WSMan-WinRM

  • https://github.com/dirkjanm/krbrelayx

Post-Exploitation

  • https://github.com/mubix/post-exploitation

  • https://github.com/emilyanncr/Windows-Post-Exploitation

  • https://github.com/nettitude/Invoke-PowerThIEf

  • https://github.com/ThunderGunExpress/BADministration

  • https://github.com/bohops/SharpRDPHijack

  • https://github.com/antonioCoco/RunasCs

  • https://github.com/klsecservices/Invoke-Vnc

  • https://github.com/mandatoryprogrammer/CursedChrome

  • https://github.com/djhohnstein/WireTap

  • https://github.com/GhostPack/Lockless

  • https://github.com/infosecn1nja/SharpDoor

  • Strumenti di Phishing

  • https://github.com/hlldz/pickl3

  • https://github.com/shantanu561993/SharpLoginPrompt

  • https://github.com/Dviros/CredsLeaker

  • https://github.com/bitsadmin/fakelogonscreen

  • https://github.com/CCob/PinSwipe

Wrapper per vari strumenti

  • https://github.com/bohops/GhostBuild

  • https://github.com/S3cur3Th1sSh1t/PowerSharpPack

  • https://github.com/rvrsh3ll/Rubeus-Rundll32## Strumenti di audit ed exploit di Active Directory

  • https://github.com/checkymander/Zolom

  • https://github.com/mwrlabs/SharpGPOAbuse

  • https://github.com/BloodHoundAD/BloodHound

  • https://github.com/BloodHoundAD/SharpHound3

  • https://github.com/chryzsh/awesome-bloodhound

  • https://github.com/hausec/Bloodhound-Custom-Queries

  • https://github.com/CompassSecurity/BloodHoundQueries

  • https://github.com/vletoux/pingcastle

  • https://github.com/cyberark/ACLight

  • https://github.com/canix1/ADACLScanner

  • https://github.com/fox-it/Invoke-ACLPwn

  • https://github.com/NinjaStyle82/rbcd_permissions

  • https://github.com/NotMedic/NetNTLMtoSilverTicket

  • https://github.com/dirkjanm/ldapdomaindump

Scanner di vulnerabilità web / Plugin Burp

  • https://github.com/m4ll0k/WAScan - scanner tutto in uno

  • https://github.com/s0md3v/XSStrike - rilevamento XSS

  • https://github.com/federicodotta/Java-Deserialization-Scanner

  • https://github.com/d3vilbug/HackBar

  • https://github.com/gyoisamurai/GyoiThon

  • https://github.com/snoopysecurity/awesome-burp-extensions

  • https://github.com/sting8k/BurpSuite_403Bypasser - Estensione BurpSuite per bypassare le directory ristrette con errore 403

  • https://github.com/BishopFox/GadgetProbe

Strumenti di sfruttamento web

  • https://github.com/OsandaMalith/LFiFreak - lfi

  • https://github.com/enjoiz/XXEinjector - xxe

  • https://github.com/tennc/webshell - shellz

  • https://github.com/flozz/p0wny-shell

  • https://github.com/epinna/tplmap - ssti

  • https://github.com/orf/xcat - iniezione XPath

  • https://github.com/almandin/fuxploider - Caricamento di file

  • https://github.com/nccgroup/freddy - deserializzazione

  • https://github.com/irsdl/IIS-ShortName-Scanner - sfruttamento della vulnerabilità dei nomi brevi di IIS

  • https://github.com/frohoff/ysoserial - Exploit di deserializzazione Java

  • https://github.com/pwntester/ysoserial.net - Exploit di deserializzazione .NET

  • https://github.com/internetwache/GitTools - Sfruttamento dell'esistenza della cartella .git

  • https://github.com/cujanovic/SSRF-Testing - Tutorial su SSRF

  • https://github.com/ambionics/phpggc - Generatore di payload PHP Unserialize

  • https://github.com/BuffaloWill/oxml_xxe - Generatore di payload XXE per Office malevoli

  • https://github.com/tijme/angularjs-csti-scanner - Scanner CSTI per AngularJS

Escalation dei privilegi Linux / Audit

  • https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS - potente script di check dell'escalation dei privilegi con un bell'output

  • https://github.com/mzet-/linux-exploit-suggester

  • https://github.com/rebootuser/LinEnum

  • https://github.com/diego-treitos/linux-smart-enumeration

  • https://github.com/CISOfy/lynis

  • https://github.com/AlessandroZ/BeRoot

  • https://github.com/future-architect/vuls

  • https://github.com/ngalongc/AutoLocalPrivilegeEscalation

  • https://github.com/b3rito/yodo

  • https://github.com/belane/linux-soft-exploit-suggester - ricerca di software installato vulnerabile

  • https://github.com/sevagas/swap_digger

  • https://github.com/NullArray/RootHelper

  • https://github.com/NullArray/MIDA-Multitool

  • https://github.com/initstring/dirty_sock

  • https://github.com/jondonas/linux-exploit-suggester-2

  • https://github.com/sosdave/KeyTabExtract

Comando e Controllo

  • Cobalt Strike è un software per simulazioni di avversari (Adversary Simulation) e operazioni di Red Team. https://cobaltstrike.com/

  • Empire è un framework post-exploitation che include un agente Windows in puro PowerShell 2.0 e un agente Linux/OS X in puro Python 2.6/2.7. https://github.com/EmpireProject/Empire

  • Metasploit Framework è un progetto di sicurezza informatica che fornisce informazioni sulle vulnerabilità di sicurezza e aiuta nel test di penetrazione e nello sviluppo di firme IDS. https://github.com/rapid7/metasploit-framework

  • SILENTTRINITY è un agente post-exploitation basato su Python, IronPython, C#/.NET. https://github.com/byt3bl33d3r/SILENTTRINITY

  • Pupy è uno strumento open source, multipiattaforma (Windows, Linux, OSX, Android) di amministrazione remota e post-exploitation, scritto principalmente in Python. https://github.com/n1nj4sec/pupy

  • Koadic, o COM Command & Control, è un rootkit post-exploitation per Windows simile ad altri strumenti di test di penetrazione come Meterpreter e PowerShell Empire. https://github.com/zerosum0x0/koadic

  • PoshC2 è un framework C2 compatibile con i proxy, scritto interamente in PowerShell, per assistere i penetration tester in red teaming, post-exploitation e movimento laterale. https://github.com/nettitude/PoshC2_Python

  • Gcat è una backdoor stealth basata su Python che utilizza Gmail come server di comando e controllo. https://github.com/byt3bl33d3r/gcat

  • TrevorC2 è un sito web legittimo (navigabile) che incanala le comunicazioni client/server per l'esecuzione occulta di comandi. https://github.com/trustedsec/trevorc2

  • Merlin è un server Command & Control HTTP/2 e agente post-exploitation multipiattaforma scritto in Go. https://github.com/Ne0nd0g/merlin

  • Quasar è uno strumento di amministrazione remota veloce e leggero scritto in C#. Grazie all'elevata stabilità e a un'interfaccia utente facile da usare, Quasar è la soluzione perfetta di amministrazione remota per te.

Emulazione degli avversari

  • MITRE CALDERA - Un sistema automatizzato di emulazione degli avversari che esegue comportamenti avversari post-compromissione all'interno di reti Windows Enterprise. https://github.com/mitre/caldera

  • APTSimulator - Uno script Batch di Windows che utilizza un insieme di strumenti e file di output per far sembrare un sistema compromesso. https://github.com/NextronSystems/APTSimulator

  • Atomic Red Team - Test di rilevamento piccoli e altamente portabili mappati sul framework Mitre ATT&CK. https://github.com/redcanaryco/atomic-red-team

  • Network Flight Simulator - flightsim è un'utilità leggera utilizzata per generare traffico di rete malevolo e aiutare i team di sicurezza a valutare i controlli di sicurezza e la visibilità della rete. https://github.com/alphasoc/flightsim

  • Metta - Uno strumento di preparazione alla sicurezza per eseguire simulazioni avversarie. https://github.com/uber-common/metta

  • Red Team Automation (RTA) - RTA fornisce un framework di script progettato per consentire ai blue team di testare le proprie capacità di rilevamento contro tecniche malevole, modellato su MITRE ATT&CK. https://github.com/endgameinc/RTA

Repository

  • https://github.com/infosecn1nja/Red-Teaming-Toolkit

  • https://github.com/S3cur3Th1sSh1t/Pentest-Tools

  • https://github.com/yeyintminthuhtut/Awesome-Red-Teaming

  • https://github.com/enaqx/awesome-pentest

  • https://github.com/Muhammd/Awesome-Pentest

  • https://github.com/CyberSecurityUP/Awesome-PenTest-Practice

  • https://drive.google.com/drive/u/0/folders/12Mvq6kE2HJDwN2CZhEGWizyWt87YunkU

  • https://github.com/0x4D31/awesome-oscp

  • https://github.com/six2dez/OSCP-Human-Guide

  • https://github.com/RustyShackleford221/OSCP-Prep

  • https://github.com/wwong99/pentest-notes/blob/master/oscp_resources/OSCP-Survival-Guide.md

Analisi di malware e reverse engineering

  • https://github.com/rshipp/awesome-malware-analysis

  • https://github.com/topics/malware-analysis

  • https://github.com/Apress/malware-analysis-detection-engineering

  • https://github.com/SpiderLabs/malware-analysis

  • https://github.com/ytisf/theZoo

  • https://github.com/arxlan786/Malware-Analysis

  • https://github.com/nheijmans/malzoo

  • https://github.com/mikesiko/PracticalMalwareAnalysis-Labs

  • https://github.com/secrary/SSMA

  • https://github.com/merces/aleph

  • https://github.com/mentebinaria/retoolkit

  • https://github.com/mytechnotalent/Reverse-Engineering

  • https://github.com/wtsxDev/reverse-engineering

  • https://github.com/mentebinaria/retoolkit

  • https://github.com/topics/reverse-engineering

  • https://github.com/0xZ0F/Z0FCourse_ReverseEngineering

  • https://github.com/NationalSecurityAgency/ghidra

Scarica lo strumento
  • https://github.com/med0x2e/NoAmci

  • https://github.com/rvrsh3ll/NoMSBuild

  • https://github.com/bohops/UltimateWDACBypassList

  • https://github.com/jxy-s/herpaderping

  • https://github.com/Cn33liz/MSBuildShell

  • https://github.com/A-mIn3/WINspect
  • https://github.com/hausec/ADAPE-Script

  • https://github.com/SecWiki/windows-kernel-exploits

  • https://github.com/bitsadmin/wesng

  • https://github.com/rasta-mouse/Watson

  • https://github.com/b4rtik/ATPMiniDump - Elude il rilevamento di furto di credenziali di WinDefender ATP

  • https://github.com/aas-n/spraykatz - procdump.exe remoto, copia del file di dump nel sistema locale e pypykatz per analisi/estrazione

  • https://github.com/0x09AL/RdpThief - estrae login RDP in tempo reale

  • https://github.com/chrismaddalena/SharpCloud - Semplice C# per verificare l'esistenza di file di credenziali relativi ad AWS, Microsoft Azure e Google Compute.

  • https://github.com/djhohnstein/SharpChromium - Progetto .NET 4.0 CLR per recuperare i dati di Chromium, come cookie, cronologia e login salvati.

  • https://github.com/jfmaes/SharpHandler - Questo progetto riutilizza gli handle aperti su LSASS per analizzare o creare un minidump di LSASS

  • https://github.com/V1V1/SharpScribbles - ThunderFox per le credenziali di Firefox, SitkyNotesExtract per "Note come password"

  • https://github.com/securesean/DecryptAutoLogon - Strumento a riga di comando per estrarre/decrittare la password che è stata memorizzata nella LSA da SysInternals AutoLogon

  • https://github.com/G0ldenGunSec/SharpSecDump - Porting .NET della funzionalità di dump remoto di SAM + LSA Secrets di secretsdump.py di impacket

  • https://github.com/EncodeGroup/Gopher - Strumento C# per scoprire obiettivi facili come SessionGopher

  • https://github.com/GhostPack/SharpDPAPI - Credenziali DPAPI via C#

  • Dump di LSASS senza Mimikatz

  • https://github.com/Hackndo/lsassy

  • https://github.com/aas-n/spraykatz

  • https://github.com/b4rtik/SharpKatz - Porting C# dei comandi sekurlsa::logonpasswords, sekurlsa::ekeys e lsadump::dcsync di mimikatz

  • Raccolta di credenziali specifica per Linux

  • https://github.com/huntergregal/mimipenguin

  • https://github.com/n1nj4sec/mimipy

  • https://github.com/dirtycow/dirtycow.github.io

  • https://github.com/mthbernardes/sshLooterC - Furto di credenziali SSH

  • https://github.com/blendin/3snake - Furto di credenziali SSH / Sudo / SU

  • https://github.com/0xmitsurugi/gimmecredz

  • https://github.com/TarlogicSecurity/tickey - Strumento per estrarre i ticket Kerberos dalle chiavi del kernel Linux.

  • Esfiltrazione Dati - Esfiltrazione DNS/ICMP/Wifi

  • https://github.com/FortyNorthSecurity/Egress-Assess

  • https://github.com/p3nt4/Invoke-TmpDavFS

  • https://github.com/DhavalKapil/icmptunnel

  • https://github.com/iagox86/dnscat2

  • https://github.com/Arno0x/DNSExfiltrator

  • https://github.com/spieglt/FlyingCarpet - Esfiltrazione Wifi

  • https://github.com/SECFORCE/Tunna - Tunna è un insieme di strumenti che incapsulano e instradano qualsiasi comunicazione TCP su HTTP

  • https://github.com/sysdream/chashell

  • https://github.com/no0be/DNSlivery - Consegna semplice di file e payload via DNS

  • https://github.com/rvrsh3ll/FindFrontableDomains
  • Postfix-Server-Setup La configurazione di un server di phishing è un processo molto lungo e noioso. Può richiedere ore per l'impostazione e può essere compromesso in pochi minuti. https://github.com/n0pe-sled/Postfix-Server-Setup

  • DomainFrontingLists un elenco di domini frontable per CDN. https://github.com/vysec/DomainFrontingLists

  • Apache2-Mod-Rewrite-Setup Implementa rapidamente Mod-Rewrite nella tua infrastruttura. https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup

  • regola mod_rewrite per aggirare le sandbox dei vendor. https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10

  • external_c2 framework un framework Python per l'uso con l'External C2 di Cobalt Strike. https://github.com/Und3rf10w/external_c2_framework

  • Malleable-C2-Profiles Una raccolta di profili utilizzati in diversi progetti con Cobalt Strike https://www.cobaltstrike.com/. https://github.com/xx0hcd/Malleable-C2-Profiles

  • ExternalC2 una libreria per integrare canali di comunicazione con il server External C2 di Cobalt Strike. https://github.com/ryhanson/ExternalC2

  • cs2modrewrite uno strumento per convertire i profili Cobalt Strike in script mod_rewrite. https://github.com/threatexpress/cs2modrewrite

  • e2modrewrite uno strumento per convertire i profili Empire in script mod_rewrite di Apache. https://github.com/infosecn1nja/e2modrewrite

  • redi script automatizzato per configurare i redirector CobaltStrike (nginx reverse proxy, letsencrypt). https://github.com/taherio/redi

  • cat-sites Libreria di siti per la categorizzazione. https://github.com/audrummer15/cat-sites

  • ycsm è una rapida installazione tramite script per un redirector resiliente che utilizza nginx reverse proxy e letsencrypt, compatibile con alcuni popolari strumenti Post-Ex (Cobalt Strike, Empire, Metasploit, PoshC2). https://github.com/infosecn1nja/ycsm

  • Domain Fronting su Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting

  • DomainFrontDiscover Script e risultati per trovare domini CloudFront frontable. https://github.com/peewpw/DomainFrontDiscover

  • Infrastruttura Empire automatizzata https://github.com/bneg/RedTeam-Automation

  • Servire payload casuali con NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9

  • meek è un trasporto pluggable resistente al blocco per Tor. Codifica un flusso di dati come una sequenza di richieste e risposte HTTPS. https://github.com/arlolra/meek

  • CobaltStrike-ToolKit Alcuni script utili per CobaltStrike. https://github.com/killswitch-GUI/CobaltStrike-ToolKit

  • mkhtaccess_red Genera automaticamente un file HTaccess per la consegna di payload -- recupera automaticamente IP/reti/ecc. da aziende/fonti di sandbox note che sono state viste in precedenza e le reindirizza a un payload benigno. https://github.com/violentlydave/mkhtaccess_red

  • RedFile un'applicazione Flask WSGI che serve file in modo intelligente, ottima per fornire payload RedTeam condizionali. https://github.com/outflanknl/RedFile

  • keyserver Serve facilmente chiavi HTTP e DNS per una corretta protezione dei payload. https://github.com/leoloobeek/keyserver

  • DoHC2 consente di utilizzare la libreria ExternalC2 di Ryan Hanson (https://github.com/ryhanson/ExternalC2) per il command and control (C2) tramite DNS su HTTPS (DoH). È progettato per il popolare software di Adversary Simulation e Red Team Operations Cobalt Strike (https://www.cobaltstrike.com). https://github.com/SpiderLabs/DoHC2

  • HTran è un connection bouncer, una sorta di server proxy. Un programma "listener" viene installato furtivamente su un host ignaro in qualsiasi punto di Internet. https://github.com/HiwinCN/HTran

  • https://github.com/Mr-Un1k0d3r/SCShell

  • https://github.com/rvazarkar/GMSAPasswordReader

  • https://github.com/fdiskyou/hunter

  • https://github.com/360-Linton-Lab/WMIHACKER

  • https://github.com/leechristensen/SpoolSample

  • https://github.com/leftp/SpoolSamplerNET

  • https://github.com/lexfo/rpc2socks

  • https://github.com/checkymander/sshiva

  • https://github.com/dev-2null/ADCollector

  • https://github.com/0xacb/viewgen - Deserializzazione ViewState .NET

  • https://github.com/Illuminopi/RCEvil.NET - Deserializzazione ViewState .NET

  • https://github.com/DominicBreuker/pspy

  • https://github.com/itsKindred/modDetective

  • https://github.com/nongiach/sudo_inject

  • https://github.com/Anon-Exploiter/SUID3NUM - trova i binari SUID e li verifica su gtfobins / sfruttabili o meno

  • https://github.com/nccgroup/GTFOBLookup - GTFOBins offline

  • https://github.com/TH3xACE/SUDO_KILLER - sfruttamento delle configurazioni errate di sudo

  • https://raw.githubusercontent.com/sleventyeleven/linuxprivchecker/master/linuxprivchecker.py

  • https://github.com/inquisb/unix-privesc-check

  • https://github.com/hc0d3r/tas - manipola facilmente la tty e crea binari fake

  • https://github.com/SecWiki/linux-kernel-exploits

  • https://github.com/initstring/uptux

  • https://github.com/andrew-d/static-binaries - non è proprio privesc ma utile

  • https://github.com/quasar/QuasarRAT
  • Covenant è un framework di comando e controllo .NET che mira a evidenziare la superficie d'attacco di .NET, semplificare l'uso delle tecniche offensive .NET e fungere da piattaforma collaborativa di comando e controllo per i red teamer. https://github.com/cobbr/Covenant

  • FactionC2 è un framework C2 che utilizza un'API basata su websocket che consente di interagire con agenti e trasporti. https://github.com/FactionC2/

  • DNScat2 è uno strumento progettato per creare un canale di comando e controllo (C&C) cifrato tramite il protocollo DNS. https://github.com/iagox86/dnscat2

  • Sliver è un framework di implant multipiattaforma generico che supporta C2 su Mutual-TLS, HTTP(S) e DNS. https://github.com/BishopFox/sliver

  • EvilOSX è un RAT malevolo (Remote Administration Tool) per macOS / OS X. https://github.com/Marten4n6/EvilOSX

  • EggShell è uno strumento di sorveglianza post-exploitation scritto in Python. Fornisce una sessione da riga di comando con funzionalità extra tra te e la macchina target. https://github.com/neoneggplant/EggShell

  • https://github.com/hax0rtahm1d/Reverse-Engineering

  • https://github.com/tylerha97/awesome-reversing