
Red-Team Attack Guid
项目用于收集和归纳Red Team的以下几个方面
Red Team攻击思维
Red Team攻击工具
Red Team攻击方法
https://github.com/vulhub/vulhub Vulhubは一般向けのオープンソース脆弱性演習場。dockerの知識は不要で、2つのコマンドを実行するだけで完全な脆弱性演習場イメージをコンパイル・実行できる
https://github.com/Medicean/VulApps さまざまな脆弱性環境を収集。使いやすさのため、統一してDockerfile形式を採用。セキュリティツールの環境も収集している。
https://github.com/bingohuang/docker-labs オンラインdockerプラットフォームの制作
https://github.com/Al1ex/CSPlugins CobaltStrikeの各種プラグイン
https://mp.weixin.qq.com/s/CEI1XYkq2PZmYsP0DRU7jg Aggressorスクリプトを使用してCobalt Strikeをカスタマイズ
https://github.com/rsmudge/armitage CobaltStrikeコミュニティ版。msfを呼び出し、1対多のGUI付き
https://github.com/anbai-inc/CobaltStrike_Hanization CobaltStrike 2.5の中国語化版。msfライブラリをベースとしており、3.0以降でリニューアル
https://github.com/rsmudge/cortana-scripts cs2.xとarmitage用の拡張可能なプラグイン。cvs3.x用はAggressorScripts
https://github.com/harleyQu1nn/AggressorScripts cs3.0以降のスクリプト収集
https://github.com/FortyNorthSecurity/AggressorAssessor cs3.xの自動化攻撃スクリプト集
https://github.com/Ridter/CS_Chinese_support/ cs3.0の表示情報を中国語化するプラグイン
https://github.com/verctor/CS_xor64 cobaltstrikeに必要なxor64.binを生成
https://github.com/ryhanson/ExternalC2 通信チャネルとCobalt Strike External C2サーバーを統合するためのライブラリ
https://github.com/threatexpress/cs2modrewrite Cobalt Strikeの設定ファイルをmod_rewriteスクリプトに変換するツール
https://github.com/Mr-Un1k0d3r/CatMyFish 分類済みドメインを検索し、Cobalt Strike beacon C&C用にホワイトリストドメインを設定
https://github.com/threatexpress/malleable-c2 jqueryファイルを利用してC2通信を行い、ファイル内でJS難読化によりファイアウォールを回避
https://github.com/dcsync/pycobalt py3、Cobalt Strike用のPython API
https://www.cobaltstrike.com/aggressor-script/cobaltstrike.html CobaltStrike関連プラグインの作成、1対多のGUI付き
https://attack.mitre.org/wiki/Lateral_Movement mitre機構による横移動のまとめ
https://payloads.online/archivers/2018-11-30/1 Windows認証を徹底的に理解する - トピックの解説
https://github.com/klionsec/klionsec.github.io 内部ネットワークのエキスパートの学習の軌跡
https://github.com/l3m0n/pentest_study ゼロから始める内部ネットワークペネトレーション学習
https://github.com/Ridter/Intranet_Penetration_Tips 内部ネットワークペネトレーションTIPS
https://github.com/OpenWireSec/metasploit ポストエクスプロイテーションフレームワーク
https://github.com/EmpireProject/Empire PowerShellベースのコマンド実行フレームワーク
https://github.com/TheSecondSun/Bashark 純Bashスクリプトで書かれたポストエクスプロイテーションフレームワーク、大ザメ
https://github.com/JusticeRage/FFM py3、ダウンロード・アップロード機能を持ち、実行可能なpyスクリプトのバックドアを生成するポストエクスプロイテーションフレームワーク
https://github.com/DarkSpiritz/DarkSpiritz py2、ポストエクスプロイテーションフレームワーク
https://github.com/byt3bl33d3r/CrackMapExec ネットワークテストにおけるスイスアーミーナイフ。impacket、PowerSploitなど多種多様なモジュールを含む
https://github.com/SpiderLabs/scavenger CrackMapExecを二次開発してラップし、内部ネットワークの機密情報をスキャン
https://github.com/jmortega/python-pentesting python-pentesting-tool、Pythonセキュリティツール関連の機能モジュール
https://github.com/0xdea/tactical-exploitation Python/PowerShellのテストスクリプト集
https://github.com/PowerShellMafia/PowerSploit PowerShellテストスクリプト集と開発フレームワークのまとめ
https://github.com/Al1ex/Heptagram/tree/master/Linux/Elevation Linux権限昇格のまとめ
https://github.com/AlessandroZ/BeRoot py、一般的な誤設定をチェックして権限昇格方法を探す。Windows/Linux/Macに対応
https://github.com/mschwager/0wned pythonパッケージを利用して高権限ユーザーを作成
https://github.com/mzet-/linux-exploit-suggester Linuxに適用されていないパッチを探すスクリプト
https://github.com/belane/linux-soft-exploit-suggester Linuxに存在する脆弱性のあるソフトウェアを探す
https://github.com/dirtycow/dirtycow.github.io Dirty COW(ダーティ・カウ)権限昇格脆弱性エクスプロイト
https://github.com/FireFart/dirtycow Dirty COW(ダーティ・カウ)権限昇格脆弱性エクスプロイト
https://github.com/stanleyb0y/sushell suスニファを利用して低権限ユーザーがrootユーザーのパスワードを窃取
https://github.com/jas502n/CVE-2018-17182/ LinuxカーネルのVMA-UAF権限昇格脆弱性 CVE-2018-17182
https://github.com/jas502n/CVE-2018-14665 CVE-2018-14665、LinuxにおけるXorg Xサーバーの権限昇格エクスプロイト
https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897 LinuxシステムでSyscallを利用して権限昇格を実現
https://github.com/can1357/CVE-2018-8897 LinuxシステムでSyscallを利用して権限昇格を実現
https://github.com/SecWiki/linux-kernel-exploits linux-kernel-exploits、Linuxプラットフォームの権限昇格脆弱性エクスプロイト集
https://github.com/nilotpalbiswas/Auto-Root-Exploit Linux自動権限昇格スクリプト
https://github.com/WazeHell/PE-Linux Linux権限昇格ツール
https://github.com/samratashok/nishang PowerShellスクリプト集とエクスプロイトフレームワーク
https://github.com/PowerShellEmpire/PowerTools PowerShellスクリプト集、更新停止
https://github.com/FuzzySecurity/PowerShell-Suite PowerShellスクリプト集
https://github.com/rvrsh3ll/Misc-Powershell-Scripts PowerShellスクリプト集
https://github.com/nccgroup/redsnarf ハッシュの窃取、パスワードの復号、キウイ(mimikatz)などのプログラムを密かに呼び出し、RDPの多様な利用方法、リモートでのシェル起動、痕跡の消去
https://github.com/BloodHoundAD/BloodHound ドメインメンバーとユーザー間の関係を分析するプログラム。PowerShellスクリプトを使用してドメイン内のsession、computer、group、userなどの情報をエクスポートし、データベースに格納して可視化分析することで、ピンポイント攻撃が可能になる。
https://github.com/xorrior/RemoteRecon DotNetToJScriptを利用して、スクリーンショット、キーロギング、トークン窃取、DLLと悪意のあるコードの注入を実行
https://github.com/SkyLined/LocalNetworkScanner ブラウザの脆弱性を利用し、相手がURLを開いたときに相手の内部ネットワーク情報をスキャン
https://github.com/fdiskyou/hunter Windows APIを呼び出して内部ネットワーク情報を包括的に収集
https://github.com/0xwindows/VulScritp 内部ネットワークペネトレーションスクリプト。バナースキャン、ポートスキャン、phpmyadmin、jenkinsなどの一般的な脆弱性エクスプロイトを含む
https://github.com/lcatro/network_backdoor_scanner ネットワークトラフィックに基づく内部ネットワーク探索フレームワーク
https://github.com/sowish/LNScan 詳細な内部ネットワーク情報スキャナ
https://github.com/rootlabs/nWatch nmapと連携し、組織の内部ネットワークをスキャン
https://github.com/m8r0wn/nullinux Linux用の内部ペネトレーションテストツール。SMBを介してOS情報、ドメイン情報、共有、ディレクトリ、ユーザーを列挙できる。
https://github.com/zMarch/Orc bash、Linux向けのポストエクスプロイテーションコマンド集
https://guif.re/linuxeop Linux権限昇格コマンド集