APT-GUID
整理APT领域的一些资料,涉及但不仅限于以下几个方面
APT攻击工具
APT分析报告
APT攻击技巧
Cobalt Strike https://cobaltstrike.com/
Metasploit Framework https://github.com/rapid7/metasploit-framework
SILENTTRINITY https://github.com/byt3bl33d3r/SILENTTRINITY
Covenant https://github.com/cobbr/Covenant
FactionC2 https://github.com/FactionC2/
EvilOSX
Rapid Attack Infrastructure (RAI) 红队基础设施工具集 https://github.com/obscuritylabs/RAI
Red Baron https://github.com/byt3bl33d3r/Red-Baron
EvilURL 为IDN同形文字攻击生成unicode邪恶的域名并对其进行检测. https://github.com/UndeadSec/EvilURL
Domain Hunter 检查过期的域名,bluecoat分类和Archive.org历史记录,以确定网络钓鱼和C2域名的最佳选择。https://github.com/threatexpress/domainhunter
Chameleon 逃避代理分类的工具。 https://github.com/mdsecactivebreach/Chameleon
CatMyFish https://github.com/Mr-Un1k0d3r/CatMyFish
Malleable C2 C2 Profiles https://github.com/rsmudge/Malleable-C2-Profiles
Malleable-C2-Randomizer https://github.com/bluscreenofjeff/Malleable-C2-Randomizer
FindFrontableDomains 搜索潜在的可扩展域。 https://github.com/rvrsh3ll/FindFrontableDomains
Postfix-Server-Setup 快速建立钓鱼服务器 https://github.com/n0pe-sled/Postfix-Server-Setup
DomainFrontingLists 可用的CDN前置域名列表https://github.com/vysec/DomainFrontingLists
Apache2-Mod-Rewrite-Setup C2重定向 https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup
mod_rewrite rule 规避沙盒 https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10
external_c2 framework python写的External C2. https://github.com/Und3rf10w/external_c2_framework
Malleable-C2-Profiles https://www.cobaltstrike.com/. https://github.com/xx0hcd/Malleable-C2-Profiles
ExternalC2 https://github.com/ryhanson/ExternalC2
cs2modrewrite https://github.com/threatexpress/cs2modrewrite
e2modrewrite https://github.com/infosecn1nja/e2modrewrite
redi 设置 CobaltStrike 重定向https://github.com/taherio/redi
cat-sites 用于分类的站点库。 https://github.com/audrummer15/cat-sites
ycsm 快速设置nginx反向代理 https://github.com/infosecn1nja/ycsm
Domain Fronting Google App Engine. https://github.com/redteam-cyberark/Google-Domain-fronting
DomainFrontDiscover https://github.com/peewpw/DomainFrontDiscover
Automated Empire Infrastructure https://github.com/bneg/RedTeam-Automation
Serving Random Payloads with NGINX. https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9
CobaltStrike-ToolKit CS脚本 https://github.com/killswitch-GUI/CobaltStrike-ToolKit
mkhtaccess_red 自动生成HTaccess进行payload传递-自动从以前见过的沙盒公司/源中提取ips / nets等,并将其重定向到良性的payload。https://github.com/violentlydave/mkhtaccess_red
RedFile Payload 服务 https://github.com/outflanknl/RedFile
keyserver https://github.com/leoloobeek/keyserver