Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
ツール/GitHubGitHub/al1ex/apt-guid
OSINT (オープンソースインテリジェンス)特権昇格脆弱性分析エクスプロイト情報収集ポストエクスプロイトコマンド&コントロールソーシャルエンジニアリング学習と教育レッドチーミング厳選リソース
GitHub
231265年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
al1ex/apt-guid

APT-GUID

APT-GUID

リポジトリを見る

プロジェクト概要

APT分野の資料を整理する。以下の側面を含むが、これらに限定されない。

  • APT攻撃ツール

  • APT分析レポート

  • APT攻撃テクニック

ツール整理

情報収集

能動的情報収集
  • EyeWitness はWebサイトのスクリーンショットを取得し、サーバー情報を提供し、可能な場合はデフォルトの認証情報を特定します https://github.com/ChrisTruncer/EyeWitness
  • AWSBucketDump は、戦利品を探すためにAWS S3バケットをすばやく列挙するために使用できるツールです https://github.com/jordanpotti/AWSBucketDump
  • AQUATONE は、ドメイン名の情報収集に使用されるツールです https://github.com/michenriksen/aquatone
  • Spoofcheck は、ドメインを偽装できるかどうかをチェックするためのもので、このプログラムはSPFおよびDMARCレコードに偽装を許可する脆弱な構成が存在するかどうかをチェックします https://github.com/BishopFox/spoofcheck
  • Nmap は、コンピュータネットワーク上のホストとサービスを発見するために使用されます https://github.com/nmap/nmap
  • dnsrecon はDNS列挙スクリプトです https://github.com/darkoperator/dnsrecon
  • dirsearch はWebサイトのディレクトリを総当たりするシンプルなコマンドラインツールです https://github.com/maurosoria/dirsearch
  • Sn1per は自動化されたペネトレーションテストツールです https://github.com/1N3/Sn1per
受動的情報収集
  • Social Mapper OSINTソーシャルメディアマッピングツール。ユーザー名と画像(またはLinkedInの会社名)のリストを取得し、複数のソーシャルメディアサイトで大規模な自動ターゲット検索を実行します。Seleniumを使用しているため、APIの制限を受けません。 https://github.com/SpiderLabs/social_mapper
  • skiptracer OSINT活用フレームワーク https://github.com/xillwillx/skiptracer
  • FOCA は主に、スキャンした文書内のメタデータや非表示情報を探すために使用されます。 https://github.com/ElevenPaths/FOCA
  • theHarvester は、さまざまな公開ソースからサブドメイン、メールアドレス、仮想ホスト、ポート/バナー、従業員名を収集するために使用されます。 https://github.com/laramies/theHarvester
  • Metagoofil は、対象Webサイトで利用可能な公開ドキュメント(pdf、doc、xls、pptなど)のメタデータを抽出するためのツールです。 https://github.com/laramies/metagoofil
  • SimplyEmail メール偵察。 https://github.com/killswitch-GUI/SimplyEmail
  • truffleHog は、gitリポジトリ内の機密データを検索し、コミット履歴とブランチを深く調査します。 https://github.com/dxa4481/truffleHog
  • Just-Metadata IPアドレスに関するメタデータを収集・分析するツールです。大規模なデータセット内のシステム間の関係を見つけようとします。 https://github.com/ChrisTruncer/Just-Metadata
  • typofinder はIPアドレスが存在する国/地域を表示します。 https://github.com/nccgroup/typofinder
  • pwnedOrNot は、データ漏洩によりメールアカウントが侵害されたかどうかをチェックするPythonスクリプトです。メールアカウントが侵害された場合、そのアカウントのパスワードを探し続けます。 https://github.com/thewhiteh4t/pwnedOrNot
  • GitHarvester このツールは、Google dorkなどの情報をGitHubから収集するために使用されます。 https://github.com/metac0rtex/GitHarvester
  • pwndb は、同じ名前のOnionサービスを使用して漏洩した認証情報を検索するためのPythonコマンドラインツールです。 https://github.com/davidtavarez/pwndb/
  • LinkedInt LinkedIn偵察ツール。 https://github.com/vysecurity/LinkedInt
  • LinkedIn列挙ツール。検索エンジンのスクレイピングにより、組織から有効な従業員名を抽出します。

脆弱性の悪用

  • WinRAR Remote Code Execution CVE-2018-20250の概念実証エクスプロイト。 https://github.com/WyAtu/CVE-2018-20250
  • Composite Moniker CVE-2017-8570の概念実証エクスプロイト。 https://github.com/rxwx/CVE-2017-8570
  • Exploit toolkit CVE-2017-8759 https://github.com/bhdresh/CVE-2017-8759
  • CVE-2017-11882 Exploit https://github.com/unamer/CVE-2017-11882
  • Adobe Flash Exploit CVE-2018-4878. https://github.com/anbai-inc/CVE-2018-4878
  • Exploit toolkit CVE-2017-0199 は、ペネトレーションテスターとセキュリティ研究者にMicrosoft Office RCEをテストするための迅速かつ効果的な方法を提供する便利なPythonスクリプトです。https://github.com/bhdresh/CVE-2017-0199
  • demiguise HTA暗号化ツール https://github.com/nccgroup/demiguise
  • Office-DDE-Payloads は、DDE(マクロを使用しないコマンド実行テクニック)を埋め込んだOffice文書を生成するスクリプトとテンプレートのコレクションです。https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads
  • CACTUSTORCH は、敵対者シミュレーション用のペイロード生成に使用されます。https://github.com/mdsecactivebreach/CACTUSTORCH
  • SharpShooter は、任意のC#ソースコードを実行するためのペイロード作成フレームワークです。https://github.com/mdsecactivebreach/SharpShooter
  • DKMC は、難読化されたshellcodeを生成するツールで、そのshellcodeは画像に格納されます。この画像は100%有効であり、shellcodeも100%有効です。https://github.com/Mr-Un1k0d3r/DKMC
  • 恶意宏生成器 は、難読化されたマクロを生成するために使用され、AV/サンドボックス回避メカニズムも含まれます。https://github.com/Mr-Un1k0d3r/MaliciousMacroGenerator
  • SCT-obfuscator Cobalt Strike SCTペイロード難読化ツール。https://github.com/Mr-Un1k0d3r/SCT-obfuscator

ソーシャルエンジニアリングフィッシング

  • King Phisher https://github.com/securestate/king-phisher
  • FiercePhish https://github.com/Raikia/FiercePhish
  • ReelPhish https://github.com/fireeye/ReelPhish/
  • Gophish https://github.com/gophish/gophish
  • CredSniper https://github.com/ustayready/CredSniper
  • PwnAuth https://github.com/fireeye/PwnAuth
  • Phishing Frenzy https://github.com/pentestgeek/phishing-frenzy
  • Phishing Pretexts https://github.com/L4bF0x/PhishingPretexts
  • Modlishka https://github.com/drk1wi/Modlishka
  • Evilginx2 https://github.com/kgretzky/evilginx2

C2フレームワーク

  • Cobalt Strike https://cobaltstrike.com/

  • Empire https://github.com/EmpireProject/Empire

  • Metasploit Framework https://github.com/rapid7/metasploit-framework

  • SILENTTRINITY https://github.com/byt3bl33d3r/SILENTTRINITY

  • Pupy https://github.com/n1nj4sec/pupy

  • Koadic https://github.com/zerosum0x0/koadic

  • PoshC2 https://github.com/nettitude/PoshC2_Python

  • Gcat https://github.com/byt3bl33d3r/gcat

  • TrevorC2 https://github.com/trustedsec/trevorc2

  • Merlin https://github.com/Ne0nd0g/merlin

  • Quasar https://github.com/quasar/QuasarRAT

  • Covenant https://github.com/cobbr/Covenant

  • FactionC2 https://github.com/FactionC2/

  • DNScat2 https://github.com/iagox86/dnscat2

  • Sliver https://github.com/BishopFox/sliver

  • EvilOSX

ポストエクスプロイテーション

  • CrackMapExec https://github.com/byt3bl33d3r/CrackMapExec
  • PowerLessShell https://github.com/Mr-Un1k0d3r/PowerLessShell
  • GoFetch BloodHoundが生成した攻撃計画を自動実行します。 https://github.com/GoFetchAD/GoFetch
  • ANGRYPUPPY CobaltStrike内のbloodhound攻撃パス自動化。 https://github.com/vysec/ANGRYPUPPY
  • DeathStar https://github.com/byt3bl33d3r/DeathStar
  • SharpHound https://github.com/BloodHoundAD/SharpHound
  • BloodHound.py は、ImpacketベースのPython製BloodHoundインジェスターです。 https://github.com/fox-it/BloodHound.py
  • Responder 中間者攻撃ツール https://github.com/SpiderLabs/Responder
  • SessionGopher は、WMIを使用してWinSCP、PuTTY、SuperPuTTY、FileZilla、Microsoftリモートデスクトップなどのリモートアクセスツールの保存済みセッション情報を抽出するPowerShellツールです。 https://github.com/fireeye/SessionGopher
  • PowerSploit PowerShellツールセット https://github.com/PowerShellMafia/PowerSploit
  • Nishang https://github.com/samratashok/nishang
  • Inveigh 中間者攻撃ツール https://github.com/Kevin-Robertson/Inveigh
  • PowerUpSQL SQL Serverを攻撃するためのPowerShellツールキット。 https://github.com/NetSPI/PowerUpSQL
  • MailSniper https://github.com/dafthack/MailSniper
  • DomainPasswordSpray https://github.com/dafthack/DomainPasswordSpray

ネットワークプロキシ

  • Tunna ファイアウォール環境でのネットワーク制限を回避するために使用されます https://github.com/SECFORCE/Tunna
  • reGeorg SOCKSプロキシツール https://github.com/sensepost/reGeorg
  • Blade Webshell管理ツール https://github.com/wonderqs/Blade
  • TinyShell Web Shellフレームワーク。 https://github.com/threatexpress/tinyshell
  • PowerLurk 悪意のあるWMI PowerShellツールセットを構築するために使用されます。 https://github.com/Sw4mpf0x/PowerLurk
  • DAMP ホストベースのセキュリティ記述子の変更による永続化を実現します https://github.com/HarmJ0y/DAMP

権限昇格

ドメイン内権限昇格
  • PowerView https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1
  • Get-GPPPassword https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-GPPPassword.ps1
  • Invoke-ACLpwn https://github.com/fox-it/Invoke-ACLPwn
  • BloodHound https://github.com/BloodHoundAD/BloodHound
  • PyKEK https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS14-068/pykek
  • Grouper グループポリシーの脆弱性を自動的に探すツール https://github.com/l0ss/Grouper
  • ADRecon https://github.com/sense-of-security/ADRecon
  • ADACLScanner https://github.com/canix1/ADACLScanner
  • ACLight 標的となり得るドメイン特権アカウントを発見するために使用されます(Shadow Adminsを含む)。https://github.com/cyberark/ACLight
  • LAPSToolkit https://github.com/leoloobeek/LAPSToolkit
  • PingCastle https://www.pingcastle.com/download
  • RiskySPNs は、SPN(サービスプリンシパル名)に関連付けられたアカウントの検出と照会に焦点を当てたPowerShellスクリプトのコレクションです。 https://github.com/cyberark/RiskySPN
  • Mystique は、Kerberos S4U拡張機能と連携できるPowerShellツールです。このモジュールは、KCDとプロトコル変換を組み合わせて、ブルーチームが危険なKerberos委任構成を特定し、レッドチームが任意のユーザーを偽装するのを支援します。 https://github.com/machosec/Mystique
  • Rubeus https://github.com/GhostPack/Rubeus
Linux権限昇格
  • https://github.com/Al1ex/Heptagram/tree/master/Linux/Elevation Linux権限昇格のコレクション
  • https://github.com/AlessandroZ/BeRoot py、一般的な誤構成をチェックして権限昇格の方法を探します。Windows/Linux/Macをサポート
  • https://github.com/mschwager/0wned Pythonパッケージを使用した高特権ユーザー作成
  • https://github.com/mzet-/linux-exploit-suggester Linuxに未適用のパッチを探すスクリプト
  • https://github.com/belane/linux-soft-exploit-suggester Linuxに脆弱性のあるソフトウェアを探す
  • https://github.com/dirtycow/dirtycow.github.io Dirty Cow権限昇格脆弱性エクスプロイト
  • https://github.com/FireFart/dirtycow Dirty Cow権限昇格脆弱性エクスプロイト
  • https://github.com/stanleyb0y/sushell suスニファーを利用して低権限ユーザーがrootユーザーのパスワードを窃取する
  • https://github.com/jas502n/CVE-2018-17182/ LinuxカーネルVMA-UAF権限昇格脆弱性 CVE-2018-17182
  • https://github.com/jas502n/CVE-2018-14665 CVE-2018-14665、LinuxにおけるXorg Xサーバーの権限昇格エクスプロイト
  • https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897 LinuxシステムでSyscallを利用して権限昇格を実現
  • https://github.com/can1357/CVE-2018-8897 LinuxシステムでSyscallを利用して権限昇格を実現
  • https://github.com/SecWiki/linux-kernel-exploits linux-kernel-exploits Linuxプラットフォームの権限昇格脆弱性コレクション
  • https://github.com/nilotpalbiswas/Auto-Root-Exploit Linux自動権限昇格スクリプト
  • https://github.com/WazeHell/PE-Linux Linux権限昇格ツール
  • https://guif.re/linuxeop Linux権限昇格コマンドの集合
Windows権限昇格
  • https://github.com/Al1ex/Heptagram/tree/master/Windows/Elevation Windows権限昇格のコレクション
  • http://www.fuzzysecurity.com/tutorials/16.html Windowsプラットフォームのチュートリアルレベルの権限昇格参考記事
  • https://github.com/SecWiki/windows-kernel-exploits Windowsプラットフォームの権限昇格脆弱性エクスプロイトコレクション
  • https://github.com/51x/WHP Windows向けの各種権限昇格および悪用ツール
  • https://github.com/rasta-mouse/Sherlock Windows権限昇格脆弱性の検証
  • https://github.com/WindowsExploits/Exploits Microsoft CVE-2012-0217、CVE-2016-3309、CVE-2016-3371、CVE-2016-7255、CVE-2017-0213の権限昇格エクスプロイト
  • https://github.com/decoder-it/lonelypotato RottenPotatoNGの亜種。NBNSローカルドメイン偽装とWPADプロキシ偽装を利用した権限昇格
  • https://github.com/ohpe/juicy-potato RottenPotatoNGの亜種。COMオブジェクトとユーザートークンを利用した権限昇格
  • https://github.com/foxglovesec/Potato RottenPotatoNGの亜種。ローカルドメイン偽装とプロキシ偽装を利用した権限昇格
  • https://github.com/DanMcInerney/icebreaker 内部ネットワーク環境にいるがAD環境外にいる場合、icebreakerは平文のActive Directory認証情報(ドメインコントローラに保存されており権限昇格に使用可能)の取得を支援します
  • https://github.com/hausec/ADAPE-Script Active Directory権限昇格スクリプト
  • https://github.com/klionsec/BypassAV-AllThings aspxワンライナーシェルと権限昇格ペイロードを組み合わせて権限昇格を実行
  • https://github.com/St0rn/Windows-10-Exploit msfプラグイン。Windows 10 UACバイパス
  • https://github.com/sam-b/CVE-2014-4113 Win32k.sysカーネル脆弱性を利用して権限昇格を実行。ms14-058
  • https://github.com/breenmachine/RottenPotatoNG NBNSローカルドメイン偽装とWPADプロキシ偽装を利用した権限昇格
  • https://github.com/unamer/CVE-2018-8120 Win32kコンポーネントに影響し、Windows 7とWindows 2008を対象とした権限昇格

データ外部送信

  • CloakifyFactory & the Cloakify Toolset - https://github.com/TryCatchHCF/Cloakify
  • DET(現状のまま提供されます)は、単一または複数のチャネルを同時に使用してデータ外部送信を実行するPOCです。 https://github.com/sensepost/DET
  • DNSExfiltrator . https://github.com/Arno0x/DNSExfiltrator
  • PyExfil データ外部送信のためのPythonパッケージ。 https://github.com/ytisf/PyExfil
  • Egress-Assess は、出口データ検出機能をテストするためのツールです。 https://github.com/ChrisTruncer/Egress-Assess
  • Powershell RAT Pythonベースのバックドアで、Gmailを使用してデータを電子メールの添付ファイルとして転送します。https://github.com/Viralmaniar/Powershell-RAT

その他

敵対者シミュレーション
  • MITRE CALDERA 侵入者の攻撃手法をシミュレートし、分析を行います https://github.com/mitre/caldera
  • APTSimulator https://github.com/NextronSystems/APTSimulator
  • Atomic Red Team - https://github.com/redcanaryco/atomic-red-team
  • Network Flight Simulator https://github.com/alphasoc/flightsim
  • Metta - https://github.com/uber-common/metta
  • Red Team Automation (RTA) - RTAは、ブルーチームがMITER ATT&CKに基づいてモデル化し、悪意のあるツールに対して検出能力をテストできるスクリプトフレームワークを提供します。 https://github.com/endgameinc/RTA
ワイヤレス攻撃
  • Wifiphisher WiFi自動関連付け攻撃ツール。 https://github.com/wifiphisher/wifiphisher
  • mana 中間者攻撃。 https://github.com/sensepost/mana
組み込み機器攻撃- magspoof https://github.com/samyk/magspoof
  • WarBerryPi https://github.com/secgroundzero/warberry
  • P4wnP1 https://github.com/mame82/P4wnP1
  • malusb https://github.com/ebursztein/malusb
  • Fenrir https://github.com/Orange-Cyberdefense/fenrir-ocd
  • poisontap https://github.com/samyk/poisontap
  • WHID https://github.com/whid-injector/WHID
  • PhanTap https://github.com/nccgroup/phantap
通信秘匿
  • RocketChat https://rocket.chat
  • Etherpad https://etherpad.org/
ログ整理
  • RedELK https://github.com/outflanknl/RedELK/
  • CobaltSplunk https://github.com/vysec/CobaltSplunk
  • Red Team Telemetry https://github.com/ztgrace/red_team_telemetry
  • Elastic for Red Teaming https://github.com/SecurityRiskAdvisors/RedTeamSIEM
  • Ghostwriter https://github.com/GhostManager/Ghostwriter
C#の武器化
  • SharpSploit .NET用ポストエクスプロイテーションフレームワーク https://github.com/cobbr/SharpSploit
  • GhostPack C#用ツールセット https://github.com/GhostPack
  • SharpWeb 一般的なブラウザのパスワードを読み取る https://github.com/djhohnstein/SharpWeb
  • reconerator https://github.com/stufus/reconerator
  • SharpView C#版のPowerView。 https://github.com/tevora-threat/SharpView
  • Watson https://github.com/rasta-mouse/Watson
LABS
  • Detection Lab labを自動的に構築 https://github.com/clong/DetectionLab ---五つ星のおすすめ
  • Modern Windows Attacks and Defense Labhttps://github.com/jaredhaight/WindowsAttackAndDefenseLab
  • Invoke-UserSimulator https://github.com/ubeeri/Invoke-UserSimulator
  • Invoke-ADLabDeployer AD環境を自動的にデプロイ https://github.com/outflanknl/Invoke-ADLabDeployer
  • Sheepl https://github.com/SpiderLabs/sheepl
スクリプト
Aggressor Scripts
  • https://github.com/invokethreatguy/CSASC
  • https://github.com/secgroundzero/CS-Aggressor-Scripts
  • https://github.com/Und3rf10w/Aggressor-scripts
  • https://github.com/harleyQu1nn/AggressorScripts
  • https://github.com/rasta-mouse/Aggressor-Script
  • https://github.com/RhinoSecurityLabs/Aggressor-Scripts
  • https://github.com/bluscreenofjeff/AggressorScripts
  • https://github.com/001SPARTaN/aggressor_scripts
  • https://github.com/360-A-Team/CobaltStrike-Toolset
  • https://github.com/FortyNorthSecurity/AggressorAssessor
  • https://github.com/ramen0x3f/AggressorScripts
Red-Team
  • https://github.com/FuzzySecurity/PowerShell-Suite
  • https://github.com/nettitude/Powershell
  • https://github.com/Mr-Un1k0d3r/RedTeamPowershellScripts
  • https://github.com/threatexpress/red-team-scripts
  • https://github.com/SadProcessor/SomeStuff
  • https://github.com/rvrsh3ll/Misc-Powershell-Scripts
  • https://github.com/enigma0x3/Misc-PowerShell-Stuff
  • https://github.com/ChrisTruncer/PenTestScripts
  • https://github.com/bluscreenofjeff/Scripts
  • https://github.com/xorrior/RandomPS-Scripts
  • https://github.com/xorrior/Random-CSharpTools
  • https://github.com/leechristensen/Random
  • https://github.com/mgeeky/Penetration-Testing-Tools/tree/master/social-engineering
ツールをダウンロード
CrossLinked
https://github.com/m8r0wn/CrossLinked
  • findomain 高速サブドメイン列挙ツール。証明書の透明性ログといくつかのAPIを使用します。 https://github.com/Edu4rdSHL/findomain
  • Invoke-Obfuscation PowerShell難読化ツール。https://github.com/danielbohannon/Invoke-Obfuscation
  • Invoke-CradleCrafter PowerShellリモートダウンロードの生成器および難読化ツール。https://github.com/danielbohannon/Invoke-CradleCrafter
  • Invoke-DOSfuscation cmd.exeコマンド難読化ジェネレータおよび検出テストツール。https://github.com/danielbohannon/Invoke-DOSfuscation
  • morphHTA。https://github.com/vysec/morphHTA
  • Unicorn は、PowerShellダウングレード攻撃を使用してshellcodeをメモリに直接注入するシンプルなツールです。https://github.com/trustedsec/unicorn
  • Shellter は動的なShellcodeインジェクションツールであり、史上初の真の動的PE感染ツールです。https://www.shellterproject.com/
  • EmbedInHTML HTML内に任意のファイルを埋め込んで隠します。https://github.com/Arno0x/EmbedInHTML
  • SigThief は署名を盗み、無効な署名を作成します。https://github.com/secretsquirrel/SigThief
  • Veil、https://github.com/Veil-Framework/Veil
  • CheckPlease は、PowerShell、Python、Go、Ruby、C、C#、Perl、Rustで書かれたサンドボックス回避モジュールです。https://github.com/Arvanaghi/CheckPlease
  • Invoke-PSImage は、PowerShellスクリプトをPNGファイルのピクセルに埋め込んで実行できるツールです。https://github.com/peewpw/Invoke-PSImage
  • LuckyStrike は、悪意のあるOfficeマクロ文書を作成するためのPowerShellベースのユーティリティです。ペネトレーションテストまたは教育目的のみに使用されます。https://github.com/curi0usJack/luckystrike
  • ClickOnceGenerator https://github.com/Mr-Un1k0d3r/ClickOnceGenerator
  • macro_pack は@EmericNasi氏によるツールで、MS Office文書、VBスクリプト、その他の形式のペネトレーションテスト、デモ、ソーシャルエンジニアリング評価のために自動的に難読化および生成します。https://github.com/sevagas/macro_pack
  • StarFighters はJavaScriptとVBScriptに基づくEmpireランチャーです。https://github.com/Cn33liz/StarFighters
  • nps_payload このスクリプトは、基本的な侵入検知を回避するためのペイロードを生成します。複数の異なるソースからの公開されたテクニックを利用します。https://github.com/trustedsec/nps_payload
  • SocialEngineeringPay 一連の認証情報窃取とスピアフィッシング攻撃のためのソーシャルエンジニアリング手法とペイロードを読み込みます。https://github.com/bhdresh/SocialEngineeringPayloads
  • Social-Engineer Toolkit は、ソーシャルエンジニアリング用に設計されたオープンソースのペネトレーションテストフレームワークです。https://github.com/trustedsec/social-engineer-toolkit
  • phishery は、SSL対応のシンプルなHTTPサーバーであり、その主な目的は基本認証を介してフィッシング認証情報を取得することです。 https://github.com/ryhanson/phishery
  • PowerShdll はrundll32 と一緒にPowerShellを実行します。ソフトウェア制限を回避します。https://github.com/p3nt4/PowerShdll
  • UltimateAppLockerByPassList はAppLockerを回避するための最も一般的なテクニックを記録します。https://github.com/api0cradle/UltimateAppLockerByPassList
  • ruler は、MAPI/HTTPまたはRPC/HTTPプロトコルを介してExchangeサーバーとリモートで対話できるようにします。https://github.com/sensepost/ruler
  • Generate-Macro は、指定されたペイロードと永続化メソッドを持つ悪意のあるMicrosoft Office文書を生成するスタンドアロンのPowerShellスクリプトです。https://github.com/enigma0x3/Generate-Macro
  • MaliciousMacroMSBuild は悪意のあるマクロを生成し、MSBuildアプリケーション許可リストを介してPowerShellまたはShellcodeをバイパス実行します。https://github.com/infosecn1nja/MaliciousMacroMSBuild
  • Meta Twin ファイルリソースクローナー。あるファイルからデジタル署名を含むメタデータを抽出し、それを別のファイルに注入します。https://github.com/threatexpress/metatwin
  • WePWNise は、Office文書またはテンプレートで使用するためのアーキテクチャに依存しないVBAコードを生成し、アプリケーション制御を自動的にバイパスします。https://github.com/mwrlabs/wePWNise
  • DotNetToJScript は、メモリから.NET v2アセンブリをロードするJScriptファイルを作成するために使用されます。https://github.com/tyranid/DotNetToJScript
  • PSAmsi はAMSIシグネチャを監査および破壊するためのツールです。https://github.com/cobbr/PSAmsi
  • ReflectiveDLLInjection https://github.com/stephenfewer/ReflectiveDLLInjection
  • ps1encode は、PowerShellベースのMetasploitペイロードを生成およびエンコードするために使用されます。https://github.com/CroweCybersecurity/ps1encode
  • Worse-PDF は、WindowsマシンからNet-NTLMハッシュを窃取するために使用されます。https://github.com/3gstudent/Worse-PDF
  • SpookFlare は、セキュリティ対策を回避するためのさまざまなアプローチを備えています。https://github.com/hlldz/SpookFlare
  • GreatSCT は、アプリケーション許可リストのバイパスを生成するためのオープンソースプロジェクトです。https://github.com/GreatSCT/GreatSCT
  • NPS は、PowerShellなしでPowerShellを実行します。https://github.com/Ben0xA/nps
  • Meterpreter_Paranoid_Mode.sh は、Meterpreterのステージド/ステージレス接続を保護します。https://github.com/r00t-3xp10it/Meterpreter_Paranoid_Mode-SSL
  • backdoor-factory(BDF)は、ユーザーが望むshellcodeで実行可能バイナリにパッチを適用し、パッチ適用前の状態を正常に実行し続けます。https://github.com/secretsquirrel/the-backdoor-factory
  • MacroShop は、Officeマクロを介してペイロードを配信するのに役立つスクリプトコレクションです。https://github.com/khr0x40sh/MacroShop
  • UnmanagedPowerShell は、アンマネージドプロセスからPowerShellを実行します。https://github.com/leechristensen/UnmanagedPowerShell
  • evil-ssdp Spoof SSDPは、ネットワーク上のNTLMハッシュを狙ったフィッシング応答を行います。偽のUPnPデバイスを作成し、ユーザーを悪意のあるWebフィッシングページに誘導します。https://gitlab.com/initstring/evil-ssdp
  • Ebowla は、環境に依存したペイロードを作成するためのフレームワークです。https://github.com/Genetic-Malware/Ebowla
  • make-pdf 組み込みツールは、埋め込みファイルを含むPDF文書を作成するために使用できます。https://github.com/DidierStevens/DidierStevensSuite/blob/master/make-pdf-embedded.py
  • avet(AntiVirusEvasionTool)は、さまざまな回避技術を使用して、実行ファイルを使ってWindowsマシンを標的にします。https://github.com/govolution/avet
  • EvilClippy は、悪意のあるMS Office文書を作成するためのクロスプラットフォームアシスタントです。VBAマクロを隠したり、マクロを難読化したりできます。Linux、OSX、Windowsで動作します。https://github.com/outflanknl/EvilClippy
  • CallObfuscator は、静的解析ツールやデバッガからWindows APIを難読化します。https://github.com/d35ha/CallObfuscator
  • Donut は、.NETアセンブリから位置に依存しないShellcodeペイロードを作成するShellcode生成ツールです。このshellcodeを使用して、アセンブリを任意のWindowsプロセスに注入できます。https://github.com/TheWover/donut
  • https://github.com/Marten4n6/EvilOSX
  • EggShell https://github.com/neoneggplant/EggShell

  • Rapid Attack Infrastructure (RAI) レッドチームインフラストラクチャツールセット https://github.com/obscuritylabs/RAI

  • Red Baron https://github.com/byt3bl33d3r/Red-Baron

  • EvilURL は、IDNホモグラフ攻撃用のUnicodeの悪意のあるドメインを生成し、それを検出します。 https://github.com/UndeadSec/EvilURL

  • Domain Hunter は、期限切れドメイン、bluecoat分類、Archive.org履歴をチェックして、フィッシングおよびC2ドメインに最適な選択肢を特定します。https://github.com/threatexpress/domainhunter

  • PowerDNS https://github.com/mdsecactivebreach/PowerDNS

  • Chameleon プロキシ分類を回避するためのツール。 https://github.com/mdsecactivebreach/Chameleon

  • CatMyFish https://github.com/Mr-Un1k0d3r/CatMyFish

  • Malleable C2 C2 Profiles https://github.com/rsmudge/Malleable-C2-Profiles

  • Malleable-C2-Randomizer https://github.com/bluscreenofjeff/Malleable-C2-Randomizer

  • FindFrontableDomains 潜在的な拡張可能なドメインを検索します。 https://github.com/rvrsh3ll/FindFrontableDomains

  • Postfix-Server-Setup フィッシングサーバーを迅速に構築 https://github.com/n0pe-sled/Postfix-Server-Setup

  • DomainFrontingLists 利用可能なCDNフロンティング用ドメインリスト https://github.com/vysec/DomainFrontingLists

  • Apache2-Mod-Rewrite-Setup C2リダイレクト https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup

  • mod_rewrite rule サンドボックス回避 https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10

  • external_c2 framework Pythonで書かれたExternal C2。 https://github.com/Und3rf10w/external_c2_framework

  • Malleable-C2-Profiles https://www.cobaltstrike.com/. https://github.com/xx0hcd/Malleable-C2-Profiles

  • ExternalC2 https://github.com/ryhanson/ExternalC2

  • cs2modrewrite https://github.com/threatexpress/cs2modrewrite

  • e2modrewrite https://github.com/infosecn1nja/e2modrewrite

  • redi CobaltStrike リダイレクトを設定https://github.com/taherio/redi

  • cat-sites 分類用のサイトライブラリ。 https://github.com/audrummer15/cat-sites

  • ycsm nginxリバースプロキシをすばやく設定 https://github.com/infosecn1nja/ycsm

  • Domain Fronting Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting

  • DomainFrontDiscover https://github.com/peewpw/DomainFrontDiscover

  • Automated Empire Infrastructure https://github.com/bneg/RedTeam-Automation

  • Serving Random Payloads with NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9

  • meek https://github.com/arlolra/meek

  • CobaltStrike-ToolKit CSスクリプト https://github.com/killswitch-GUI/CobaltStrike-ToolKit

  • mkhtaccess_red ペイロード配信用のHTaccessを自動生成します。これまでに確認されたサンドボックス企業/ソースからIP/netなどを自動的に抽出し、無害なペイロードへリダイレクトします。https://github.com/violentlydave/mkhtaccess_red

  • RedFile ペイロードサービス https://github.com/outflanknl/RedFile

  • keyserver https://github.com/leoloobeek/keyserver

  • DoHC2 https://github.com/SpiderLabs/DoHC2

  • HTran https://github.com/HiwinCN/HTran

  • WMIOps https://github.com/ChrisTruncer/WMIOps
  • Mimikatz https://github.com/gentilkiwi/mimikatz
  • LaZagne https://github.com/AlessandroZ/LaZagne
  • mimipenguin Linuxパスワードを取得 https://github.com/huntergregal/mimipenguin
  • PsExec https://docs.microsoft.com/en-us/sysinternals/downloads/psexec
  • KeeThief https://github.com/HarmJ0y/KeeThief
  • PSAttack https://github.com/jaredhaight/PSAttack
  • Internal Monologue Attack LSASSに触れずにNTLMハッシュを取得できます。https://github.com/eladshamir/Internal-Monologue
  • Impacket Pythonツールキット https://github.com/CoreSecurity/impacket
  • icebreaker 内部ネットワーク上にいるがAD環境にいない場合、平文のActive Directory認証情報を取得します。 https://github.com/DanMcInerney/icebreaker
  • **Living Off The Land Binaries and Scripts (and now also Libraries)**https://github.com/api0cradle/LOLBAS
  • WSUSpendu https://github.com/AlsidOfficial/WSUSpendu
  • Evilgrade https://github.com/infobyte/evilgrade
  • NetRipper は、Windowsシステム向けのポストエクスプロイテーションツールです。APIフックを使用して低権限ユーザーのネットワークトラフィックと暗号化関連機能を傍受し、暗号化前/復号化後に平文トラフィックと暗号化トラフィックをキャプチャできるようにします。https://github.com/NytroRST/NetRipper
  • LethalHTA DCOMとHTAを使用したラテラルムーブメント(横移動)テクニック。 https://github.com/codewhitesec/LethalHTA
  • Invoke-PowerThIEf https://github.com/nettitude/Invoke-PowerThIEf
  • RedSnarf https://github.com/nccgroup/redsnarf
  • HoneypotBuster レッドチーム向けに設計されたMicrosoft PowerShellモジュールで、ネットワークまたはホスト内のハニーポットとトークンを見つけるために使用できます。 https://github.com/JavelinNetworks/HoneypotBuster
  • PAExec リモートのWindowsコンピュータにソフトウェアを事前にインストールすることなく、リモートでWindowsプログラムを起動します。 https://www.poweradmin.com/paexec/
  • kekeo https://github.com/gentilkiwi/kekeo
  • https://github.com/alpha1ab/CVE-2018-8120 Windows 7とWindows 2008に加えて、Windows XPとWindows 2003を追加
  • https://github.com/0xbadjuju/Tokenvator Windowsトークンを使用して権限を昇格させるツール。対話型コマンドラインインターフェースを提供