
レッドチームおよびペンテストツールの厳選コレクション。フェーズごとに分類: ペイロード、AMSIバイパス、ピボット、永続化、権限昇格(privesc)、認証情報の収集、データ外部流出。
https://github.com/Dionach/CMSmap - Wordpress、Joomla、Drupal スキャナ
https://github.com/wpscanteam/wpscan - wordpress
https://github.com/m4ll0k/WPSeku https://github.com/swisskyrepo/Wordpresscan
https://github.com/coldfusion39/domi-owned - lotus domino
https://github.com/droope/droopescan - Drupal
https://github.com/rezasp/joomscan - Joomla
https://github.com/devanshbatham/ParamSpider - Web アーカイブの暗い隅からパラメータを抽出する
https://github.com/Cillian-Collins/dirscraper - JavaScript ファイルからディレクトリを検索する
https://github.com/s0md3v/Breacher - 管理パネルファインダー
https://github.com/microsoft/restler-fuzzer - RESTler は、REST API を通じてクラウドサービスを自動的にテストし、これらのサービスにおけるセキュリティおよび信頼性のバグを発見する、初のステートフル REST API ファジングツールです。
https://github.com/itm4n/PrivescCheck - Windows 用の権限昇格列挙スクリプト
https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS - 強力な権限昇格チェックスクリプト、出力も見やすい
https://github.com/sensepost/rattler - プリロード攻撃に脆弱な DLL を見つける
https://github.com/Cybereason/siofra - DLL ハイジャックスキャナ
https://github.com/0xbadjuju/Tokenvator - 管理者から SYSTEM へ
https://github.com/gtworek/Priv2Admin - Windows の特権を滥用する
https://github.com/itm4n/UsoDllLoader - system32 から悪意のある DLL をロードする
https://github.com/TsukiCTF/Lovely-Potato - potato 系エクスプロイトを自動化
https://github.com/antonioCoco/RogueWinRM - サービスアカウントから SYSTEM へ
https://github.com/antonioCoco/RoguePotato - サービスアカウントから SYSTEM へのもう 1 つの Windows ローカル権限昇格
https://github.com/itm4n/PrintSpoofer - Windows 10 および Server 2019 での偽装特権の滥用
https://github.com/BeichenDream/BadPotato - itm4n の PrintSpoofer を C# で実装
https://github.com/itm4n/FullPowers - LOCAL/NETWORK SERVICE アカウントの既定の特権セットを回復する
https://github.com/Flangvik/BetterSafetyKatz - SafetyKatz のフォーク。gentilkiwi の GitHub リポジトリから Mimikatz の最新のプリコンパイル済みリリースを動的に取得し、シグネチャを実行時にパッチし、SharpSploit DInvoke を使用してメモリに PE ロードする。
https://github.com/AlessandroZ/LaZagneForensic - リモート版 LaZagne
https://github.com/djhohnstein/SharpWeb - ブラウザ資格情報の収集
https://github.com/moonD4rk/HackBrowserData - hack-browser-data は、ブラウザからデータ [パスワード|ブックマーク|クッキー|履歴] を復号化するのに役立つオープンソースツールです。
https://github.com/mwrlabs/SharpClipHistory - ClipHistory 機能は、最後の 25 件のコピー&ペースト操作を取得します
https://github.com/outflanknl/Dumpert - 直接システムコールと API アンフックを使用して LSASS をダンプする
https://github.com/b4rtik/SharpMiniDump - Dumpert を使用して、メモリから LSASS プロセスのミニダンプを作成する
https://github.com/b4rtik/ATPMiniDump - WinDefender ATP の資格情報窃取を回避する
https://github.com/aas-n/spraykatz - リモートで procdump.exe を実行し、ダンプファイルをローカルシステムにコピーして、pypykatz で分析・抽出する
Rapid Attack Infrastructure (RAI)。レッドチームインフラストラクチャ... 迅速... 高速... シンプル。レッドチーム演習で最も面倒なフェーズの 1 つは、通常インフラストラクチャのセットアップです。これには通常、チームサーバーまたはコントローラー、ドメイン、リダイレクター、フィッシングサーバーが含まれます。 https://github.com/obscuritylabs/RAI
Red Baron は、Red Teams 向けの回復力があり、使い捨て可能で、安全かつ機動的なインフラストラクチャの作成を自動化する、Terraform 用のモジュールとカスタム/サードパーティプロバイダーのセットです。 https://github.com/byt3bl33d3r/Red-Baron
EvilURL は、IDN ホモグラフ攻撃用の Unicode の悪意あるドメインを生成し、それらを検出します。 https://github.com/UndeadSec/EvilURL
Domain Hunter は、期限切れドメイン、Bluecoat カテゴリ分類、Archive.org の履歴をチェックして、フィッシングや C2 ドメイン名に適した候補を決定します。 https://github.com/threatexpress/domainhunter
PowerDNS は、DNS のみを使用した PowerShell スクリプトの実行を実証するシンプルな概念実証です。 https://github.com/mdsecactivebreach/PowerDNS
Chameleon は、プロキシのカテゴリ分類を回避するためのツールです。 https://github.com/mdsecactivebreach/Chameleon
CatMyFish は、レッドチーム演習中に使用できるカテゴリ分類済みドメインを検索します。Cobalt Strike ビーコンの C&C 用にホワイトリスト登録されたドメインを設定するのに最適です。 https://github.com/Mr-Un1k0d3r/CatMyFish
Malleable C2 は、Beacon の通信における指標を再定義するためのドメイン固有言語です。 https://github.com/rsmudge/Malleable-C2-Profiles
Malleable-C2-Randomizer は、メタ言語を使用して Cobalt Strike Malleable C2 プロファイルをランダム化し、シグネチャベースの検出コントロールに検知される可能性を減らすことを目的としたスクリプトです。 https://github.com/bluscreenofjeff/Malleable-C2-Randomizer
FindFrontableDomains は、フロント可能なドメインを検索します。 https://github.com/rvrsh3ll/FindFrontableDomains
Postfix-Server-Setup。フィッシングサーバーのセットアップは非常に長く退屈なプロセスです。セットアップに数時間かかることがあり、数分で侵害される可能性があります。 https://github.com/n0pe-sled/Postfix-Server-Setup
DomainFrontingLists は、CDN ごとのドメインフロント可能なドメインのリストです。 https://github.com/vysec/DomainFrontingLists
https://github.com/freddiebarrsmith/Buffer-Overflow-Exploit-Development-Practice
https://github.com/hardenedlinux/linux-exploit-development-tutorial
https://www.mindmeister.com/pt/1746180947/web-attacks-bug-bounty-and-appsec-by-joas-antonio
https://www.mindmeister.com/pt/1760781948/information-security-certifications-by-joas-antonio
https://www.mindmeister.com/pt/1781013629/the-best-labs-and-ctf-red-team-and-pentest
https://www.mindmeister.com/pt/1760781948/information-security-certifications-by-joas-antonio
https://www.mindmeister.com/pt/1746187693/cyber-security-career-knowledge-by-joas-antonio
フィッシングツール
https://github.com/m4ll0k/WAScan - オールインワンスキャナー
https://github.com/federicodotta/Java-Deserialization-Scanner
https://github.com/sting8k/BurpSuite_403Bypasser - 403制限ディレクトリをバイパスするBurpsuite拡張機能
https://github.com/tennc/webshell - shellz
https://github.com/orf/xcat - XPathインジェクション
https://github.com/almandin/fuxploider - ファイルアップロード
https://github.com/nccgroup/freddy - デシリアライゼーション
https://github.com/irsdl/IIS-ShortName-Scanner - IISショートファイル名の脆弱性を悪用
https://github.com/frohoff/ysoserial - Javaデシリアライズ悪用
https://github.com/pwntester/ysoserial.net - .NETデシリアライズ悪用
https://github.com/internetwache/GitTools - .gitフォルダの存在を悪用
https://github.com/cujanovic/SSRF-Testing - SSRFチュートリアル
https://github.com/ambionics/phpggc - PHP unserializeペイロードジェネレーター
https://github.com/BuffaloWill/oxml_xxe - 悪意のあるOffice XXEペイロードジェネレーター
https://github.com/tijme/angularjs-csti-scanner - AngularJS CSTIスキャナー
https://github.com/0xacb/viewgen - .NET ViewStateのデシリアライズ
https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS - 出力が見やすい強力な権限昇格チェックスクリプト
https://github.com/belane/linux-soft-exploit-suggester - 脆弱なインストール済みソフトウェアを検索
Cobalt Strikeは、敵対的シミュレーションおよびレッドチーム運用のためのソフトウェアです。 https://cobaltstrike.com/
Empireは、純粋なPowerShell 2.0 Windowsエージェントと、純粋なPython 2.6/2.7 Linux/OS Xエージェントを含むポストエクスプロイテーションフレームワークです。 https://github.com/EmpireProject/Empire
Metasploit Frameworkは、セキュリティ脆弱性に関する情報を提供し、ペネトレーションテストやIDSシグネチャ開発を支援するコンピュータセキュリティプロジェクトです。 https://github.com/rapid7/metasploit-framework
SILENTTRINITY - Python、IronPython、C#/.NETを搭載したポストエクスプロイテーションエージェント。 https://github.com/byt3bl33d3r/SILENTTRINITY
Pupyは、主にPythonで書かれたオープンソースでクロスプラットフォーム(Windows、Linux、OSX、Android)のリモート管理およびポストエクスプロイテーションツールです。 https://github.com/n1nj4sec/pupy
Koadic(COM Command & Control)は、MeterpreterやPowershell Empireなどの他のペネトレーションテストツールに類似したWindowsポストエクスプロイテーションルートキットです。 https://github.com/zerosum0x0/koadic
PoshC2は、レッドチーミング、ポストエクスプロイテーション、ラテラルムーブメントを支援するために完全にPowerShellで書かれたプロキシ対応C2フレームワークです。 https://github.com/nettitude/PoshC2_Python
Gcat - Gmailをコマンド&コントロールサーバーとして使用するステルス性の高いPythonベースのバックドア。 https://github.com/byt3bl33d3r/gcat
TrevorC2は、隠密なコマンド実行のためにクライアント/サーバー間の通信をトンネリングする正当なWebサイト(閲覧可能)です。 https://github.com/trustedsec/trevorc2
Merlinは、golangで書かれたクロスプラットフォームのポストエクスプロイテーションHTTP/2コマンド&コントロールサーバーおよびエージェントです。 https://github.com/Ne0nd0g/merlin
Quasarは、C#で書かれた高速で軽量なリモート管理ツールです。高い安定性と使いやすいユーザーインターフェースを備えたQuasarは、最適なリモート管理ソリューションです。 https://github.com/quasar/QuasarRAT
Covenantは、.NETの攻撃対象領域を浮き彫りにし、攻撃的な.NETのトレードクラフトをより簡単に使用できるようにし、レッドチーム向けの協調型コマンド&コントロールプラットフォームとして機能することを目的とした.NETコマンド&コントロールフレームワークです。 https://github.com/cobbr/Covenant
FactionC2は、エージェントやトランスポートとの対話を可能にするwebsocketベースのAPIを使用するC2フレームワークです。
MITRE CALDERA - Windows Enterpriseネットワーク内で侵害後の敵対的行動を実行する自動化された敵対的エミュレーションシステム。 https://github.com/mitre/caldera
APTSimulator - 一連のツールと出力ファイルを使用して、システムが侵害されたかのように見せかけるWindowsバッチスクリプト。 https://github.com/NextronSystems/APTSimulator
Atomic Red Team - Mitre ATT&CKフレームワークに対応した、小さくて移植性の高い検出テスト。 https://github.com/redcanaryco/atomic-red-team
Network Flight Simulator - flightsimは、悪意のあるネットワークトラフィックを生成し、セキュリティチームがセキュリティコントロールとネットワーク可視性を評価するのに役立つ軽量ユーティリティです。 https://github.com/alphasoc/flightsim
Metta - 敵対的シミュレーションを行うためのセキュリティ準備ツール。 https://github.com/uber-common/metta
Red Team Automation (RTA) - RTAは、MITRE ATT&CKをモデルに、ブルーチームが悪意のあるトレードクラフトに対する検出能力をテストできるように設計されたスクリプトのフレームワークを提供します。 https://github.com/endgameinc/RTA
https://drive.google.com/drive/u/0/folders/12Mvq6kE2HJDwN2CZhEGWizyWt87YunkU
https://github.com/wwong99/pentest-notes/blob/master/oscp_resources/OSCP-Survival-Guide.md
https://github.com/0x09AL/RdpThief - アクティブな RDP ログインを抽出する
https://github.com/chrismaddalena/SharpCloud - AWS、Microsoft Azure、Google Compute に関連する資格情報ファイルの存在を確認するためのシンプルな C# ツール
https://github.com/djhohnstein/SharpChromium - Cookie、履歴、保存済みログインなどの Chromium データを取得する .NET 4.0 CLR プロジェクト
https://github.com/jfmaes/SharpHandler - このプロジェクトは、lsass へのオープンハンドルを再利用して、lsass を解析またはミニダンプする
https://github.com/V1V1/SharpScribbles - Firefox 資格情報向けの ThunderFox、「メモをパスワードとして」抽出する SitkyNotesExtract
https://github.com/securesean/DecryptAutoLogon - SysInternals AutoLogon によって LSA に保存されたパスワードを抽出・復号化するコマンドラインツール
https://github.com/G0ldenGunSec/SharpSecDump - impacket の secretsdump.py が持つリモート SAM + LSA シークレットのダンプ機能を .NET に移植したもの
https://github.com/EncodeGroup/Gopher - SessionGopher のような簡単に取得できる成果を発見する C# ツール
https://github.com/GhostPack/SharpDPAPI - C# を使用した DPAPI 資格情報
Mimikatz を使用しない LSASS ダンプ
https://github.com/b4rtik/SharpKatz - mimikatz の sekurlsa::logonpasswords、sekurlsa::ekeys、lsadump::dcsync コマンドを C# に移植
Linux 固有の資格情報収集
https://github.com/mthbernardes/sshLooterC - SSH 資格情報の収集
https://github.com/blendin/3snake - SSH / Sudo / SU 資格情報の収集
https://github.com/TarlogicSecurity/tickey - Linux カーネルキーから Kerberos チケットを抽出するツール
データ流出 - DNS/ICMP/Wi-Fi データ流出
https://github.com/spieglt/FlyingCarpet - Wi-Fi によるデータ流出
https://github.com/SECFORCE/Tunna - Tunna は、任意の TCP 通信を HTTP 上でラップしてトンネリングするツール群です
https://github.com/no0be/DNSlivery - DNS を介したファイルとペイロードの簡単な配信
Apache2-Mod-Rewrite-Setup。インフラストラクチャに Mod-Rewrite をすばやく実装します。 https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup
ベンダーのサンドボックスを回避するための mod_rewrite ルール。 https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10
external_c2 framework は、Cobalt Strike の External C2 を使用するための Python フレームワークです。 https://github.com/Und3rf10w/external_c2_framework
Malleable-C2-Profiles は、Cobalt Strike (https://www.cobaltstrike.com/) を使用したさまざまなプロジェクトで使用されるプロファイルのコレクションです。 https://github.com/xx0hcd/Malleable-C2-Profiles
ExternalC2 は、Cobalt Strike External C2 サーバーと通信チャネルを統合するためのライブラリです。 https://github.com/ryhanson/ExternalC2
cs2modrewrite は、Cobalt Strike プロファイルを modrewrite スクリプトに変換するためのツールです。 https://github.com/threatexpress/cs2modrewrite
e2modrewrite は、Empire プロファイルを Apache modrewrite スクリプトに変換するためのツールです。 https://github.com/infosecn1nja/e2modrewrite
redi は、CobaltStrike リダイレクタ(nginx リバースプロキシ、letsencrypt)をセットアップするための自動化スクリプトです。 https://github.com/taherio/redi
cat-sites は、カテゴリ分類用のサイトのライブラリです。 https://github.com/audrummer15/cat-sites
ycsm は、nginx リバースプロキシと letsencrypt を使用した回復力のあるリダイレクタをすばやくインストールするスクリプトで、一般的な Post-Ex ツール(Cobalt Strike、Empire、Metasploit、PoshC2)と互換性があります。 https://github.com/infosecn1nja/ycsm
Google App Engine を使用したドメインフロンティング。 https://github.com/redteam-cyberark/Google-Domain-fronting
DomainFrontDiscover は、ドメインフロント可能な CloudFront ドメインを見つけるためのスクリプトと結果です。 https://github.com/peewpw/DomainFrontDiscover
自動化された Empire インフラストラクチャ https://github.com/bneg/RedTeam-Automation
NGINX でランダムなペイロードを配信する。 https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9
meek は、Tor 向けのブロック耐性を持つプラガブルトランスポートです。データストリームを一連の HTTPS リクエストとレスポンスとしてエンコードします。 https://github.com/arlolra/meek
CobaltStrike-ToolKit は、CobaltStrike 用の便利なスクリプト集です。 https://github.com/killswitch-GUI/CobaltStrike-ToolKit
mkhtaccess_red は、ペイロード配信のための HTaccess を自動生成します。過去に確認された既知のサンドボックス企業/ソースから IP/ネットワークなどを自動的に取得し、それらを良性のペイロードへリダイレクトします。 https://github.com/violentlydave/mkhtaccess_red
RedFile は、インテリジェンスを備えてファイルを配信する Flask WSGI アプリケーションで、条件付きの RedTeam ペイロードの配信に適しています。 https://github.com/outflanknl/RedFile
keyserver は、適切なペイロード保護のために HTTP および DNS キーを簡単に配信します。 https://github.com/leoloobeek/keyserver
DoHC2 は、Ryan Hanson の ExternalC2 ライブラリ (https://github.com/ryhanson/ExternalC2) を、DNS over HTTPS (DoH) を介したコマンド&コントロール (C2) に利用できるようにします。これは、人気の Adversary Simulation および Red Team Operations ソフトウェアである Cobalt Strike (https://www.cobaltstrike.com) 向けに構築されています。 https://github.com/SpiderLabs/DoHC2
HTran は、コネクションバウンサー、一種のプロキシサーバーです。「リスナー」プログラムは、インターネット上のどこかの無防備なホストにステルス的に埋め込まれます。 https://github.com/HiwinCN/HTran
https://github.com/Illuminopi/RCEvil.NET - .NET ViewStateのデシリアライズ
https://github.com/Anon-Exploiter/SUID3NUM - SUIDバイナリを検索し、gtfobinsで悪用可能かどうかを調べる
https://github.com/nccgroup/GTFOBLookup - オフラインGTFOBins
https://github.com/TH3xACE/SUDO_KILLER - sudoの設定ミスを悪用
https://github.com/hc0d3r/tas - ttyを簡単に操作し、偽のバイナリを作成
https://github.com/andrew-d/static-binaries - 厳密には権限昇格ではないが便利
DNScat2は、DNSプロトコルを介して暗号化されたコマンド&コントロール(C&C)チャネルを作成するように設計されたツールです。 https://github.com/iagox86/dnscat2
Sliverは、相互TLS、HTTP(S)、DNSを介したC2をサポートする汎用クロスプラットフォームインプラントフレームワークです。 https://github.com/BishopFox/sliver
EvilOSX - macOS / OS X向けの悪意のあるRAT(リモート管理ツール)。 https://github.com/Marten4n6/EvilOSX
EggShellは、Pythonで書かれたポストエクスプロイテーション監視ツールです。対象マシンとの間に追加機能を備えたコマンドラインセッションを提供します。 https://github.com/neoneggplant/EggShell