Skip to content
KitploitKITPLOIT
ИнструментыБлог
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
Инструменты/GitHubGitHub/joasasantos/awesome-red-team-operations
Инструменты фишингаПовышение привилегийСканеры уязвимостейЭксплуатацияЭксфильтрация данныхСбор информацииПост-эксплуатацияТестирование на ПроникновениеКомандование и Управление

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Red Teaming
Подобранные Ресурсы
Разработка Полезной Нагрузки
GitHubjoasasantos/awesome-red-team-operations

Awesome-Red-Team-Operations

Курируемая подборка инструментов для red team и пентеста, сгруппированных по фазам: полезные нагрузки (payloads), обходы AMSI, пивотинг, закрепление (persistence), повышение привилегий (privesc), сбор учётных данных и эксфильтрация.

Репозиторий
1.7k3314 лет назадПроверено Kitploit
Поделиться

Awesome-Red-Team-Operation

Инструменты для пентеста и Red Team от Joas и S3cur3Th1sSh1t

Скрипты PowerShell

  • https://github.com/S3cur3Th1sSh1t/WinPwn

  • https://github.com/dafthack/MailSniper

  • https://github.com/putterpanda/mimikittenz

  • https://github.com/dafthack/DomainPasswordSpray

  • https://github.com/mdavis332/DomainPasswordSpray

  • https://github.com/jnqpblc/SharpSpray

  • https://github.com/Arvanaghi/SessionGopher

  • https://github.com/samratashok/nishang

  • https://github.com/PowerShellMafia/PowerSploit

  • https://github.com/fdiskyou/PowerOPS

  • https://github.com/giMini/PowerMemory

  • https://github.com/Kevin-Robertson/Inveigh

  • https://github.com/MichaelGrafnetter/DSInternals

  • https://github.com/PowerShellEmpire/PowerTools

  • https://github.com/FuzzySecurity/PowerShell-Suite

  • https://github.com/hlldz/Invoke-Phant0m

  • https://github.com/leoloobeek/LAPSToolkit

  • https://github.com/n00py/LAPSDumper

  • https://github.com/sense-of-security/ADRecon

  • https://github.com/adrecon/ADRecon

  • https://github.com/S3cur3Th1sSh1t/Grouper

  • https://github.com/l0ss/Grouper2

  • https://github.com/NetSPI/PowerShell

  • https://github.com/NetSPI/PowerUpSQL

  • https://github.com/GhostPack

  • https://github.com/Kevin-Robertson/Powermad

Обход AMSI

  • https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell

  • https://github.com/Flangvik/AMSI.fail

  • https://github.com/p3nt4/PowerShdll

  • https://github.com/jaredhaight/PSAttack

  • https://github.com/Cn33liz/p0wnedShell

  • https://github.com/cobbr/InsecurePowerShell

  • https://github.com/bitsadmin/nopowershell

  • https://github.com/Mr-Un1k0d3r/PowerLessShell

  • https://github.com/OmerYa/Invisi-Shell

  • https://github.com/Hackplayers/Salsa-tools

  • https://github.com/padovah4ck/PSByPassCLM

  • https://github.com/rasta-mouse/AmsiScanBufferBypass

  • https://github.com/itm4n/VBA-RunPE

  • https://github.com/cfalta/PowerShellArmoury

  • https://github.com/Mr-B0b/SpaceRunner

  • https://github.com/RythmStick/AMSITrigger

  • https://github.com/rmdavy/AMSI_Ordinal_Bypass

  • https://github.com/mgeeky/Stracciatella

Размещение полезных нагрузок

  • https://github.com/kgretzky/pwndrop

  • https://github.com/sc0tfree/updog

Сканер сетевых ресурсов

  • https://github.com/SnaffCon/Snaffler

  • https://github.com/djhohnstein/SharpShares

  • https://github.com/vivami/SauronEye

  • https://github.com/leftp/VmdkReader

Обратные шеллы

  • https://github.com/xct/xc

  • https://github.com/cytopia/pwncat

  • https://github.com/Kudaes/LOLBITS

Поиск бэкдоров

  • https://github.com/linuz/Sticky-Keys-Slayer

  • https://github.com/ztgrace/sticky_keys_hunter

  • https://github.com/countercept/doublepulsar-detection-script

Пивотинг

  • https://github.com/0x36/VPNPivot

  • https://github.com/securesocketfunneling/ssf

  • https://github.com/p3nt4/Invoke-SocksProxy

  • https://github.com/sensepost/reGeorg

  • https://github.com/hayasec/reGeorg-Weblogic

  • https://github.com/nccgroup/ABPTTS

  • https://github.com/RedTeamOperations/PivotSuite

  • https://github.com/trustedsec/egressbuster

  • https://github.com/vincentcox/bypass-firewalls-by-DNS-history

  • https://github.com/shantanu561993/SharpChisel

  • https://github.com/jpillora/chisel

  • https://github.com/esrrhs/pingtunnel

  • https://github.com/sysdream/ligolo

  • https://github.com/nccgroup/SocksOverRDP

  • https://github.com/blackarrowsec/mssqlproxy

Закрепление в Windows

  • https://github.com/fireeye/SharPersist

  • https://github.com/outflanknl/SharpHide

  • https://github.com/HarmJ0y/DAMP

Обнаружение фреймворков

  • https://github.com/Tuhinshubhra/CMSeeK

  • https://github.com/Dionach/CMSmap — сканер WordPress, Joomla и Drupal

  • https://github.com/wpscanteam/wpscan

  • https://github.com/Ekultek/WhatWaf

  • https://github.com/KingOfBugbounty/KingOfBugBountyTips

Сканер и эксплуатация фреймворков

  • https://github.com/wpscanteam/wpscan — WordPress

  • https://github.com/n00py/WPForce

  • https://github.com/m4ll0k/WPSeku https://github.com/swisskyrepo/Wordpresscan

  • https://github.com/rastating/wordpress-exploit-framework

  • https://github.com/coldfusion39/domi-owned — Lotus Domino

  • https://github.com/droope/droopescan — Drupal

  • https://github.com/whoot/Typo-Enumerator — Typo3

  • https://github.com/rezasp/joomscan — Joomla

Обнаружение файлов, каталогов и параметров

  • https://github.com/OJ/gobuster

  • https://github.com/nccgroup/dirble

  • https://github.com/maK-/parameth

  • https://github.com/devanshbatham/ParamSpider — извлечение параметров из тёмных уголков веб-архивов

  • https://github.com/s0md3v/Arjun — 💗

  • https://github.com/Cillian-Collins/dirscraper — поиск каталогов в JavaScript-файлах

  • https://github.com/hannob/snallygaster

  • https://github.com/maurosoria/dirsearch

  • https://github.com/s0md3v/Breacher — поиск панелей администратора

  • https://github.com/mazen160/server-status_PWN

  • https://github.com/helviojunior/turbosearch

Аудит REST API

  • https://github.com/microsoft/restler-fuzzer — RESTler — это первый инструмент фаззинга REST API с сохранением состояния, предназначенный для автоматического тестирования облачных сервисов через их REST API и поиска в этих сервисах ошибок безопасности и надёжности.

  • https://github.com/flipkart-incubator/Astra

Повышение привилегий / аудит Windows

  • https://github.com/itm4n/PrivescCheck — скрипт перечисления возможностей повышения привилегий для Windows

  • https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS — мощный скрипт проверки повышения привилегий с красивым выводом

  • https://github.com/AlessandroZ/BeRoot

  • https://github.com/rasta-mouse/Sherlock

  • https://github.com/hfiref0x/UACME — UAC

  • https://github.com/rootm0s/WinPwnage — UAC

  • https://github.com/abatchy17/WindowsExploits

  • https://github.com/dafthack/HostRecon

  • https://github.com/sensepost/rattler — ищет уязвимые DLL для атаки с предварительной загрузкой

  • https://github.com/WindowsExploits/Exploits

  • https://github.com/Cybereason/siofra — сканер перехвата DLL

  • https://github.com/0xbadjuju/Tokenvator — от администратора до SYSTEM

  • https://github.com/MojtabaTajik/Robber

  • https://github.com/411Hall/JAWS

  • https://github.com/GhostPack/SharpUp

  • https://github.com/GhostPack/Seatbelt

  • https://github.com/A-mIn3/WINspect

LinkedIn

  • https://www.linkedin.com/in/joas-antonio-dos-santos

Злоупотребление привилегиями Windows (повышение привилегий)

  • https://github.com/gtworek/Priv2Admin — злоупотребление привилегиями Windows

  • https://github.com/itm4n/UsoDllLoader — загрузка вредоносных DLL из system32

  • https://github.com/TsukiCTF/Lovely-Potato — автоматизированная эксплуатация уязвимостей Potato

  • https://github.com/antonioCoco/RogueWinRM — от сервисной учётной записи до SYSTEM

  • https://github.com/antonioCoco/RoguePotato — ещё один способ локального повышения привилегий в Windows от сервисной учётной записи до SYSTEM

  • https://github.com/itm4n/PrintSpoofer — злоупотребление привилегиями олицетворения в Windows 10 и Server 2019

  • https://github.com/BeichenDream/BadPotato — PrintSpoofer от itm4n на C#

  • https://github.com/itm4n/FullPowers — восстановление набора привилегий по умолчанию для учётной записи LOCAL/NETWORK SERVICE

Экфильтрация

  • https://github.com/gentilkiwi/mimikatz

  • https://github.com/GhostPack/SafetyKatz

  • https://github.com/Flangvik/BetterSafetyKatz — форк SafetyKatz, который динамически загружает последнюю предварительно скомпилированную версию Mimikatz прямо из репозитория gentilkiwi на GitHub, во время выполнения пропатчивает сигнатуры и использует SharpSploit DInvoke для PE-загрузки в память.

  • https://github.com/GhostPack/Rubeus

  • https://github.com/Arvanaghi/SessionGopher

  • https://github.com/peewpw/Invoke-WCMDump

  • https://github.com/tiagorlampert/sAINT

  • https://github.com/AlessandroZ/LaZagneForensic — удалённый LaZagne

  • https://github.com/eladshamir/Internal-Monologue

  • https://github.com/djhohnstein/SharpWeb — сбор учётных данных браузеров

  • https://github.com/moonD4rk/HackBrowserData — hack-browser-data — это инструмент с открытым исходным кодом, который помогает расшифровывать данные браузера: пароли, закладки, куки, историю.

  • https://github.com/mwrlabs/SharpClipHistory — функция ClipHistory извлекает последние 25 действий копирования/вставки

  • https://github.com/outflanknl/Dumpert — дампит LSASS с помощью прямых системных вызовов и снятия хуков API

  • https://github.com/b4rtik/SharpMiniDump — создание минидампа процесса LSASS из памяти с использованием Dumpert

Подготовка инфраструктуры

  • Rapid Attack Infrastructure (RAI) — инфраструктура для Red Team... Быстро... Оперативно... Упрощённо. Один из самых утомительных этапов Red Team-операции — обычно настройка инфраструктуры. Обычно это включает teamserver или контроллер, домены, редиректоры и фишинговый сервер. https://github.com/obscuritylabs/RAI

  • Red Baron — набор модулей и пользовательских/сторонних провайдеров для Terraform, который автоматизирует создание отказоустойчивой, одноразовой, безопасной и гибкой инфраструктуры для Red Team. https://github.com/byt3bl33d3r/Red-Baron

  • EvilURL генерирует Unicode-домены для IDN-атак с использованием гомоглифов и обнаруживает их. https://github.com/UndeadSec/EvilURL

  • Domain Hunter проверяет просроченные домены, категоризацию Blue Coat и историю Archive.org, чтобы определить хороших кандидатов для фишинговых доменов и доменов C2. https://github.com/threatexpress/domainhunter

  • PowerDNS — простая proof-of-concept-демонстрация выполнения PowerShell-скрипта с использованием только DNS. https://github.com/mdsecactivebreach/PowerDNS

  • Chameleon — инструмент для обхода категоризации прокси. https://github.com/mdsecactivebreach/Chameleon

  • CatMyFish ищет категоризированные домены, которые можно использовать во время Red Team-задач. Отлично подходит для настройки домена из белого списка для вашего Cobalt Strike Beacon C&C. https://github.com/Mr-Un1k0d3r/CatMyFish

  • Malleable C2 — предметно-ориентированный язык для переопределения индикаторов в коммуникации Beacon. https://github.com/rsmudge/Malleable-C2-Profiles

  • Malleable-C2-Randomizer — этот скрипт рандомизирует Malleable C2-профили Cobalt Strike с помощью метаязыка, что, вероятно, снижает шансы срабатывания сигнатурных средств обнаружения. https://github.com/bluscreenofjeff/Malleable-C2-Randomizer

  • FindFrontableDomains ищет потенциальные домены, пригодные для Domain Fronting. https://github.com/rvrsh3ll/FindFrontableDomains

Переполнение буфера и разработка эксплойтов

  • https://github.com/CyberSecurityUP/Buffer-Overflow-Labs

  • https://github.com/gh0x0st/Buffer_Overflow

  • https://github.com/freddiebarrsmith/Buffer-Overflow-Exploit-Development-Practice

  • https://github.com/21y4d/Windows_BufferOverflowx32

  • https://github.com/johnjhacking/Buffer-Overflow-Guide

  • https://github.com/npapernot/buffer-overflow-attack

  • https://github.com/V1n1v131r4/OSCP-Buffer-Overflow

  • https://github.com/KINGSABRI/BufferOverflow-Kit

  • https://github.com/FabioBaroni/awesome-exploit-development

  • https://github.com/Gallopsled/pwntools

  • https://github.com/hardenedlinux/linux-exploit-development-tutorial

  • https://github.com/Billy-Ellis/Exploit-Challenges

  • https://github.com/wtsxDev/Exploit-Development

Интеллект-карты от Joas

  • https://www.mindmeister.com/pt/1746180947/web-attacks-bug-bounty-and-appsec-by-joas-antonio

  • https://www.mindmeister.com/pt/1760781948/information-security-certifications-by-joas-antonio

  • https://www.mindmeister.com/pt/1781013629/the-best-labs-and-ctf-red-team-and-pentest

  • https://www.mindmeister.com/pt/1760781948/information-security-certifications-by-joas-antonio

  • https://www.mindmeister.com/pt/1746187693/cyber-security-career-knowledge-by-joas-antonio

Латеральное перемещение

  • https://github.com/0xthirteen/SharpRDP

  • https://github.com/0xthirteen/MoveKit

  • https://github.com/0xthirteen/SharpMove

  • https://github.com/rvrsh3ll/SharpCOM

  • https://github.com/malcomvetter/CSExec

  • https://github.com/byt3bl33d3r/CrackMapExec

  • https://github.com/cube0x0/SharpMapExec

  • https://github.com/nccgroup/WMIcmd

  • https://github.com/rasta-mouse/MiscTools

  • https://github.com/byt3bl33d3r/DeathStar

  • https://github.com/SpiderLabs/portia

  • https://github.com/Screetsec/Vegile

  • https://github.com/DanMcInerney/icebreaker

  • https://github.com/MooseDojo/apt2

  • https://github.com/hdm/nextnet

  • https://github.com/mubix/IOXIDResolver

  • https://github.com/Hackplayers/evil-winrm

  • https://github.com/bohops/WSMan-WinRM

  • https://github.com/dirkjanm/krbrelayx

Пост-эксплуатация

  • https://github.com/mubix/post-exploitation

  • https://github.com/emilyanncr/Windows-Post-Exploitation

  • https://github.com/nettitude/Invoke-PowerThIEf

  • https://github.com/ThunderGunExpress/BADministration

  • https://github.com/bohops/SharpRDPHijack

  • https://github.com/antonioCoco/RunasCs

  • https://github.com/klsecservices/Invoke-Vnc

  • https://github.com/mandatoryprogrammer/CursedChrome

  • https://github.com/djhohnstein/WireTap

  • https://github.com/GhostPack/Lockless

  • https://github.com/infosecn1nja/SharpDoor

  • Фишинговые инструменты

  • https://github.com/hlldz/pickl3

  • https://github.com/shantanu561993/SharpLoginPrompt

  • https://github.com/Dviros/CredsLeaker

  • https://github.com/bitsadmin/fakelogonscreen

  • https://github.com/CCob/PinSwipe

Обёртки для различных инструментов

  • https://github.com/bohops/GhostBuild

  • https://github.com/S3cur3Th1sSh1t/PowerSharpPack

  • https://github.com/rvrsh3ll/Rubeus-Rundll32- https://github.com/checkymander/Zolom

Инструменты аудита и эксплуатации Active Directory

  • https://github.com/mwrlabs/SharpGPOAbuse

  • https://github.com/BloodHoundAD/BloodHound

  • https://github.com/BloodHoundAD/SharpHound3

  • https://github.com/chryzsh/awesome-bloodhound

  • https://github.com/hausec/Bloodhound-Custom-Queries

  • https://github.com/CompassSecurity/BloodHoundQueries

  • https://github.com/vletoux/pingcastle

  • https://github.com/cyberark/ACLight

  • https://github.com/canix1/ADACLScanner

  • https://github.com/fox-it/Invoke-ACLPwn

  • https://github.com/NinjaStyle82/rbcd_permissions

  • https://github.com/NotMedic/NetNTLMtoSilverTicket

  • https://github.com/dirkjanm/ldapdomaindump

Веб-сканеры уязвимостей / плагины для Burp

  • https://github.com/m4ll0k/WAScan - всё-в-одном сканер

  • https://github.com/s0md3v/XSStrike - обнаружение XSS

  • https://github.com/federicodotta/Java-Deserialization-Scanner

  • https://github.com/d3vilbug/HackBar

  • https://github.com/gyoisamurai/GyoiThon

  • https://github.com/snoopysecurity/awesome-burp-extensions

  • https://github.com/sting8k/BurpSuite_403Bypasser - расширение Burp Suite для обхода каталогов с запретом 403

  • https://github.com/BishopFox/GadgetProbe

Инструменты эксплуатации веб-приложений

  • https://github.com/OsandaMalith/LFiFreak - LFI

  • https://github.com/enjoiz/XXEinjector - XXE

  • https://github.com/tennc/webshell - шеллы

  • https://github.com/flozz/p0wny-shell

  • https://github.com/epinna/tplmap - SSTI

  • https://github.com/orf/xcat - XPath-инъекции

  • https://github.com/almandin/fuxploider - загрузка файлов

  • https://github.com/nccgroup/freddy - десериализация

  • https://github.com/irsdl/IIS-ShortName-Scanner - эксплуатация уязвимости коротких имён файлов IIS

  • https://github.com/frohoff/ysoserial - эксплуатация десериализации Java

  • https://github.com/pwntester/ysoserial.net - эксплуатация десериализации .NET

  • https://github.com/internetwache/GitTools - эксплуатация наличия папки .git

  • https://github.com/cujanovic/SSRF-Testing - SSRF-туториалы

  • https://github.com/ambionics/phpggc - генератор payload для PHP Unserialize

  • https://github.com/BuffaloWill/oxml_xxe - генератор вредоносных XXE-payload для Office

  • https://github.com/tijme/angularjs-csti-scanner - сканер CSTI для AngularJS

Повышение привилегий в Linux / аудит

  • https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS - мощный скрипт проверки повышения привилегий с удобным выводом

  • https://github.com/mzet-/linux-exploit-suggester

  • https://github.com/rebootuser/LinEnum

  • https://github.com/diego-treitos/linux-smart-enumeration

  • https://github.com/CISOfy/lynis

  • https://github.com/AlessandroZ/BeRoot

  • https://github.com/future-architect/vuls

  • https://github.com/ngalongc/AutoLocalPrivilegeEscalation

  • https://github.com/b3rito/yodo

  • https://github.com/belane/linux-soft-exploit-suggester - поиск уязвимого установленного ПО

  • https://github.com/sevagas/swap_digger

  • https://github.com/NullArray/RootHelper

  • https://github.com/NullArray/MIDA-Multitool

  • https://github.com/initstring/dirty_sock

  • https://github.com/jondonas/linux-exploit-suggester-2

  • https://github.com/sosdave/KeyTabExtract

  • https://github.com/DominicBreuker/pspy

Command and Control

  • Cobalt Strike — это программное обеспечение для симуляции действий противника и Red Team-операций. https://cobaltstrike.com/

  • Empire — это постэксплуатационный фреймворк, включающий агент для Windows на чистом PowerShell 2.0 и агент для Linux/OS X на чистом Python 2.6/2.7. https://github.com/EmpireProject/Empire

  • Metasploit Framework — это проект в области компьютерной безопасности, который предоставляет информацию об уязвимостях и помогает в пентесте и разработке сигнатур IDS. https://github.com/rapid7/metasploit-framework

  • SILENTTRINITY — постэксплуатационный агент на базе Python, IronPython, C#/.NET. https://github.com/byt3bl33d3r/SILENTTRINITY

  • Pupy — это опенсорсный кроссплатформенный (Windows, Linux, OSX, Android) инструмент удалённого администрирования и постэксплуатации, написанный в основном на Python. https://github.com/n1nj4sec/pupy

  • Koadic, или COM Command & Control, — это постэксплуатационный руткит для Windows, похожий на другие инструменты пентеста, такие как Meterpreter и Powershell Empire. https://github.com/zerosum0x0/koadic

  • PoshC2 — это C2-фреймворк с поддержкой прокси, полностью написанный на PowerShell и предназначенный для помощи пентестерам в red teaming, постэксплуатации и горизонтальном перемещении. https://github.com/nettitude/PoshC2_Python

  • Gcat — это скрытный бэкдор на Python, использующий Gmail в качестве C2-сервера. https://github.com/byt3bl33d3r/gcat

  • TrevorC2 — это легитимный (просматриваемый) веб-сайт, который туннелирует клиент-серверное взаимодействие для скрытного выполнения команд. https://github.com/trustedsec/trevorc2

  • Merlin — это кроссплатформенный постэксплуатационный HTTP/2 Command & Control-сервер и агент, написанный на golang. https://github.com/Ne0nd0g/merlin

  • Quasar — это быстрый и лёгкий инструмент удалённого администрирования, написанный на C#. Благодаря высокой стабильности и простому интерфейсу Quasar — идеальное решение для удалённого администрирования.

Имитация действий противника

  • MITRE CALDERA - автоматизированная система имитации действий противника, выполняющая посткомпрометационное поведение в корпоративных сетях Windows. https://github.com/mitre/caldera

  • APTSimulator - Windows Batch-скрипт, использующий набор инструментов и выходных файлов, чтобы система выглядела скомпрометированной. https://github.com/NextronSystems/APTSimulator

  • Atomic Red Team - небольшие и легко переносимые тесты обнаружения, сопоставленные с фреймворком Mitre ATT&CK. https://github.com/redcanaryco/atomic-red-team

  • Network Flight Simulator - flightsim — это лёгкая утилита, используемая для генерации вредоносного сетевого трафика и помощи командам безопасности в оценке средств защиты и видимости сети. https://github.com/alphasoc/flightsim

  • Metta - инструмент подготовки к безопасности для имитации действий противника. https://github.com/uber-common/metta

  • Red Team Automation (RTA) - RTA предоставляет набор скриптов, позволяющих blue teams проверять свои возможности обнаружения против вредоносных техник, смоделированных по мотивам MITRE ATT&CK. https://github.com/endgameinc/RTA

Репозитории

  • https://github.com/infosecn1nja/Red-Teaming-Toolkit

  • https://github.com/S3cur3Th1sSh1t/Pentest-Tools

  • https://github.com/yeyintminthuhtut/Awesome-Red-Teaming

  • https://github.com/enaqx/awesome-pentest

  • https://github.com/Muhammd/Awesome-Pentest

  • https://github.com/CyberSecurityUP/Awesome-PenTest-Practice

  • https://drive.google.com/drive/u/0/folders/12Mvq6kE2HJDwN2CZhEGWizyWt87YunkU

  • https://github.com/0x4D31/awesome-oscp

  • https://github.com/six2dez/OSCP-Human-Guide

  • https://github.com/RustyShackleford221/OSCP-Prep

  • https://github.com/wwong99/pentest-notes/blob/master/oscp_resources/OSCP-Survival-Guide.md

Анализ вредоносного ПО и реверс-инжиниринг

  • https://github.com/rshipp/awesome-malware-analysis

  • https://github.com/topics/malware-analysis

  • https://github.com/Apress/malware-analysis-detection-engineering

  • https://github.com/SpiderLabs/malware-analysis

  • https://github.com/ytisf/theZoo

  • https://github.com/arxlan786/Malware-Analysis

  • https://github.com/nheijmans/malzoo

  • https://github.com/mikesiko/PracticalMalwareAnalysis-Labs

  • https://github.com/secrary/SSMA

  • https://github.com/merces/aleph

  • https://github.com/mentebinaria/retoolkit

  • https://github.com/mytechnotalent/Reverse-Engineering

  • https://github.com/wtsxDev/reverse-engineering

  • https://github.com/mentebinaria/retoolkit

  • https://github.com/topics/reverse-engineering

  • https://github.com/0xZ0F/Z0FCourse_ReverseEngineering

  • https://github.com/NationalSecurityAgency/ghidra

Скачать инструмент
  • https://github.com/med0x2e/NoAmci

  • https://github.com/rvrsh3ll/NoMSBuild

  • https://github.com/bohops/UltimateWDACBypassList

  • https://github.com/jxy-s/herpaderping

  • https://github.com/Cn33liz/MSBuildShell

  • https://github.com/hausec/ADAPE-Script

  • https://github.com/SecWiki/windows-kernel-exploits

  • https://github.com/bitsadmin/wesng

  • https://github.com/rasta-mouse/Watson

  • https://github.com/b4rtik/ATPMiniDump — обход защиты учётных данных WinDefender ATP

  • https://github.com/aas-n/spraykatz — удалённый procdump.exe, копирование файла дампа в локальную систему и pypykatz для анализа/извлечения

  • https://github.com/0x09AL/RdpThief — извлечение учётных данных из активных RDP-сессий

  • https://github.com/chrismaddalena/SharpCloud — простой инструмент на C# для проверки наличия файлов с учётными данными AWS, Microsoft Azure и Google Compute.

  • https://github.com/djhohnstein/SharpChromium — проект на .NET 4.0 CLR для получения данных Chromium: куки, история и сохранённые пароли.

  • https://github.com/jfmaes/SharpHandler — этот проект использует открытые дескрипторы LSASS для анализа или создания минидампа LSASS

  • https://github.com/V1V1/SharpScribbles — ThunderFox для учётных данных Firefox, SitkyNotesExtract для «заметок в качестве паролей»

  • https://github.com/securesean/DecryptAutoLogon — инструмент командной строки для извлечения/расшифровки пароля, сохранённого в LSA с помощью SysInternals AutoLogon

  • https://github.com/G0ldenGunSec/SharpSecDump — .NET-порт функциональности удалённого дампа SAM + LSA Secrets из impacket secretsdump.py

  • https://github.com/EncodeGroup/Gopher — инструмент на C# для поиска лёгких целей, как SessionGopher

  • https://github.com/GhostPack/SharpDPAPI — учётные данные DPAPI через C#

  • Дампинг LSASS без Mimikatz

  • https://github.com/Hackndo/lsassy

  • https://github.com/aas-n/spraykatz

  • https://github.com/b4rtik/SharpKatz — портирование на C# команд mimikatz sekurlsa::logonpasswords, sekurlsa::ekeys и lsadump::dcsync

  • Сбор учётных данных в Linux

  • https://github.com/huntergregal/mimipenguin

  • https://github.com/n1nj4sec/mimipy

  • https://github.com/dirtycow/dirtycow.github.io

  • https://github.com/mthbernardes/sshLooterC — похищение учётных данных SSH

  • https://github.com/blendin/3snake — похищение учётных данных SSH / Sudo / SU

  • https://github.com/0xmitsurugi/gimmecredz

  • https://github.com/TarlogicSecurity/tickey — инструмент для извлечения билетов Kerberos из ключей ядра Linux.

  • Экфильтрация данных — DNS/ICMP/Wi-Fi

  • https://github.com/FortyNorthSecurity/Egress-Assess

  • https://github.com/p3nt4/Invoke-TmpDavFS

  • https://github.com/DhavalKapil/icmptunnel

  • https://github.com/iagox86/dnscat2

  • https://github.com/Arno0x/DNSExfiltrator

  • https://github.com/spieglt/FlyingCarpet — экфильтрация через Wi-Fi

  • https://github.com/SECFORCE/Tunna — Tunna — это набор инструментов, которые упаковывают и туннелируют любой TCP-трафик через HTTP

  • https://github.com/sysdream/chashell

  • https://github.com/no0be/DNSlivery — простая доставка файлов и полезных нагрузок через DNS

  • Postfix-Server-Setup. Настройка фишингового сервера — очень долгий и утомительный процесс. На установку могут уйти часы, а скомпрометирован он может быть за минуты. https://github.com/n0pe-sled/Postfix-Server-Setup

  • DomainFrontingLists — список доменов, пригодных для Domain Fronting, по CDN. https://github.com/vysec/DomainFrontingLists

  • Apache2-Mod-Rewrite-Setup — быстро внедрите Mod-Rewrite в вашу инфраструктуру. https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup

  • правило mod_rewrite для обхода песочниц вендоров. https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10

  • external_c2 framework — Python-фреймворк для использования с External C2 от Cobalt Strike. https://github.com/Und3rf10w/external_c2_framework

  • Malleable-C2-Profiles — коллекция профилей, используемых в различных проектах на Cobalt Strike https://www.cobaltstrike.com/. https://github.com/xx0hcd/Malleable-C2-Profiles

  • ExternalC2 — библиотека для интеграции каналов связи с сервером Cobalt Strike External C2. https://github.com/ryhanson/ExternalC2

  • cs2modrewrite — инструмент для преобразования профилей Cobalt Strike в скрипты mod_rewrite. https://github.com/threatexpress/cs2modrewrite

  • e2modrewrite — инструмент для преобразования профилей Empire в скрипты Apache mod_rewrite. https://github.com/infosecn1nja/e2modrewrite

  • redi — автоматизированный скрипт для настройки редиректоров Cobalt Strike (nginx reverse proxy, Let's Encrypt). https://github.com/taherio/redi

  • cat-sites — библиотека сайтов для категоризации. https://github.com/audrummer15/cat-sites

  • ycsm — быстрая скриптовая установка отказоустойчивого редиректора на базе nginx reverse proxy и Let's Encrypt, совместимая с некоторыми популярными постэксплуатационными инструментами (Cobalt Strike, Empire, Metasploit, PoshC2). https://github.com/infosecn1nja/ycsm

  • Domain Fronting для Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting

  • DomainFrontDiscover — скрипты и результаты поиска доменов CloudFront, пригодных для Domain Fronting. https://github.com/peewpw/DomainFrontDiscover

  • Автоматизированная инфраструктура Empire https://github.com/bneg/RedTeam-Automation

  • Раздача случайных полезных нагрузок с помощью NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9

  • meek — устойчивый к блокировке подключаемый транспорт для Tor. Он кодирует поток данных как последовательность HTTPS-запросов и ответов. https://github.com/arlolra/meek

  • CobaltStrike-ToolKit — несколько полезных скриптов для Cobalt Strike. https://github.com/killswitch-GUI/CobaltStrike-ToolKit

  • mkhtaccess_red — автоматическая генерация .htaccess для доставки полезных нагрузок: автоматически подтягивает IP-адреса/сети и т.п. из известных песочниц/источников, которые встречались ранее, и перенаправляет их на безвредную полезную нагрузку. https://github.com/violentlydave/mkhtaccess_red

  • RedFile — WSGI-приложение на Flask, которое раздаёт файлы с учётом контекста; отлично подходит для раздачи условных Red Team-полезных нагрузок. https://github.com/outflanknl/RedFile

  • keyserver — простой способ раздачи ключей через HTTP и DNS для надёжной защиты полезных нагрузок. https://github.com/leoloobeek/keyserver

  • DoHC2 позволяет использовать библиотеку ExternalC2 от Райана Хэнсона (https://github.com/ryhanson/ExternalC2) для управления и контроля (C2) через DNS over HTTPS (DoH). Этот инструмент создан для популярного ПО для симуляции противника и Red Team-операций Cobalt Strike (https://www.cobaltstrike.com). https://github.com/SpiderLabs/DoHC2

  • HTran — ретранслятор соединений, своего рода прокси-сервер. Программа-«слушатель» незаметно устанавливается на ничего не подозревающий хост в любом месте Интернета. https://github.com/HiwinCN/HTran

  • https://github.com/Mr-Un1k0d3r/SCShell

  • https://github.com/rvazarkar/GMSAPasswordReader

  • https://github.com/fdiskyou/hunter

  • https://github.com/360-Linton-Lab/WMIHACKER

  • https://github.com/leechristensen/SpoolSample

  • https://github.com/leftp/SpoolSamplerNET

  • https://github.com/lexfo/rpc2socks

  • https://github.com/checkymander/sshiva

  • https://github.com/dev-2null/ADCollector

  • https://github.com/0xacb/viewgen - десериализация .NET ViewState

  • https://github.com/Illuminopi/RCEvil.NET - десериализация .NET ViewState

  • https://github.com/itsKindred/modDetective

  • https://github.com/nongiach/sudo_inject

  • https://github.com/Anon-Exploiter/SUID3NUM - находит SUID-бинарники и проверяет их по GTFOBins / эксплуатируемые или нет

  • https://github.com/nccgroup/GTFOBLookup - офлайн-версия GTFOBins

  • https://github.com/TH3xACE/SUDO_KILLER - эксплуатация ошибок конфигурации sudo

  • https://raw.githubusercontent.com/sleventyeleven/linuxprivchecker/master/linuxprivchecker.py

  • https://github.com/inquisb/unix-privesc-check

  • https://github.com/hc0d3r/tas - легко манипулировать tty и создавать поддельные бинарники

  • https://github.com/SecWiki/linux-kernel-exploits

  • https://github.com/initstring/uptux

  • https://github.com/andrew-d/static-binaries - не совсем повышение привилегий, но полезно

  • https://github.com/quasar/QuasarRAT
  • Covenant — это .NET C2-фреймворк, цель которого — продемонстрировать поверхность атаки .NET, упростить применение наступательных .NET-техник и стать совместной C2-платформой для red team-специалистов. https://github.com/cobbr/Covenant

  • FactionC2 — это C2-фреймворк, использующий API на основе веб-сокетов для взаимодействия с агентами и транспортами. https://github.com/FactionC2/

  • DNScat2 — это инструмент, предназначенный для создания зашифрованного канала управления (C&C) поверх протокола DNS. https://github.com/iagox86/dnscat2

  • Sliver — это универсальный кроссплатформенный фреймворк для имплантов, поддерживающий C2 через Mutual-TLS, HTTP(S) и DNS. https://github.com/BishopFox/sliver

  • EvilOSX — RAT (инструмент удалённого администрирования) для macOS / OS X. https://github.com/Marten4n6/EvilOSX

  • EggShell — это постэксплуатационный инструмент слежения, написанный на Python. Он предоставляет вам сеанс командной строки с дополнительными функциями между вами и целевой машиной. https://github.com/neoneggplant/EggShell

  • https://github.com/hax0rtahm1d/Reverse-Engineering

  • https://github.com/tylerha97/awesome-reversing