项目用于收集和归纳Red Team的以下几个方面
Red Team攻击思维
Red Team攻击工具
Red Team攻击方法
https://github.com/vulhub/vulhub Vulhub是一个面向大众的开源漏洞靶场,无需docker知识,执行两条命令即可编译、运行一个完整的漏洞靶场镜像
https://github.com/Medicean/VulApps 收集各种漏洞环境,为方便使用,统一采用 Dockerfile 形式。同时也收集了安全工具环境。
https://github.com/bingohuang/docker-labs 制作在线docker平台
https://github.com/Al1ex/CSPlugins CobaltStrike各种插件
https://mp.weixin.qq.com/s/CEI1XYkq2PZmYsP0DRU7jg 使用Aggressor脚本雕饰Cobalt Strike
https://github.com/rsmudge/armitage CobaltStrike社区版,调用msf,一对多带界面
https://github.com/anbai-inc/CobaltStrike_Hanization CobaltStrike2.5汉化版,以msf库为基础,3.0以后改版
https://github.com/rsmudge/cortana-scripts 用于cs2.x与armitage的可拓展插件,cvs3.x的为AggressorScripts
https://github.com/harleyQu1nn/AggressorScripts cs3.0以后的脚本搜集
https://github.com/FortyNorthSecurity/AggressorAssessor cs3.x自动化攻击脚本集合
https://github.com/Ridter/CS_Chinese_support/ cs3.0传输信息的汉化插件
https://github.com/verctor/CS_xor64 生成cobaltstrike所需的xor64.bin
https://github.com/ryhanson/ExternalC2 一个用于将通信渠道与Cobalt Strike External C2服务器集成的库
https://github.com/threatexpress/cs2modrewrite 用于将Cobalt Strike配置文件转换为mod_rewrite脚本的工具
https://github.com/Mr-Un1k0d3r/CatMyFish 搜索分类域,为Cobalt Strike beacon C&C设置白名单域
https://github.com/threatexpress/malleable-c2 利用jquery文件进行C2通讯,在文件内做了JS混淆绕过防火墙
https://github.com/dcsync/pycobalt py3,Python API for Cobalt Strike
https://www.cobaltstrike.com/aggressor-script/cobaltstrike.html CobaltStrike相关插件编写,一对多带界面
https://attack.mitre.org/wiki/Lateral_Movement mitre机构对横向移动的总结
https://payloads.online/archivers/2018-11-30/1 彻底理解Windows认证 - 议题解读
https://github.com/l3m0n/pentest_study 从零开始内网渗透学习
https://github.com/Ridter/Intranet_Penetration_Tips 内网渗透TIPS
https://github.com/EmpireProject/Empire 基于poweshell的命令执行框架
https://github.com/TheSecondSun/Bashark 纯Bash脚本编写的后渗透框架,大鲨鱼
https://github.com/JusticeRage/FFM py3,拥有下载、上传功能,生成可执行py脚本的后门的后渗透框架
https://github.com/byt3bl33d3r/CrackMapExec 网络测试中的瑞士军刀,包含impacket、PowerSploit等多种模块
https://github.com/SpiderLabs/scavenger 对CrackMapExec进行二次包装开发进行内网敏感信息扫描
https://github.com/jmortega/python-pentesting python-pentesting-tool python安全工具相关功能模块
https://github.com/0xdea/tactical-exploitation Python/PowerShell的测试脚本集
https://github.com/PowerShellMafia/PowerSploit powershell测试脚本集与开发框架汇总
https://github.com/samratashok/nishang powershell脚本集与利用框架
https://github.com/Al1ex/Heptagram/tree/master/Linux/Elevation Linux提权收集
https://github.com/AlessandroZ/BeRoot py,通过检查常见的错误配置来查找提权方法. 支持Windows/Linux/Mac
https://github.com/mschwager/0wned 利用python包进行高权限用户创建
https://github.com/mzet-/linux-exploit-suggester 查找linux有哪些补丁没有打的脚本
https://github.com/belane/linux-soft-exploit-suggester 查找linux有哪些有漏洞的软件
https://github.com/FireFart/dirtycow 脏牛提权漏洞exp
https://github.com/stanleyb0y/sushell 利用su小偷实现低权限用户窃取root用户口令
https://github.com/jas502n/CVE-2018-17182/ Linux 内核VMA-UAF 提权漏洞 CVE-2018-17182
https://github.com/jas502n/CVE-2018-14665 CVE-2018-14665,linux下Xorg X服务器提权利用
https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897 Linux系统利用Syscall实现提权
https://github.com/can1357/CVE-2018-8897 Linux系统利用Syscall实现提权
https://github.com/SecWiki/linux-kernel-exploits linux-kernel-exploits Linux平台提权漏洞集合
https://github.com/nilotpalbiswas/Auto-Root-Exploit linux自动提权脚本
https://github.com/WazeHell/PE-Linux Linux提权工具
个人维护的安全预警维基百科,根据中华人民共和国《网络安全法》相关政策规定,本文章只做安全预警,不被允许通过本文章技术手段进行非法行为,使用技术的风险由您自行承担
https://github.com/PowerShellEmpire/PowerTools PowerShell脚本集,停止更新
https://github.com/FuzzySecurity/PowerShell-Suite PowerShell脚本集
https://github.com/rvrsh3ll/Misc-Powershell-Scripts PowerShell脚本集
https://github.com/nccgroup/redsnarf 窃取哈希,密码解密,偷偷调用猕猴桃等程序,rdp多方法利用,远程启动shell,清楚痕迹
https://github.com/BloodHoundAD/BloodHound 用于分析域成员和用用户关系的程序,通过用powershell脚本导出域内的session、computer、group、user等信息,入库后进行可视化分析可以做到定点攻击。
https://github.com/xorrior/RemoteRecon 利用DotNetToJScript进行截图、key记录、token窃取、dll与恶意代码注入
https://github.com/SkyLined/LocalNetworkScanner 利用浏览器漏洞当对方打开网址时,扫描对方内网信息
https://github.com/fdiskyou/hunter 调用 Windows API 对内网信息进行搜集很全面
https://github.com/0xwindows/VulScritp 内网渗透脚本,包括banner扫描、端口扫描;phpmyadmin、jenkins等通用漏洞利用等
https://github.com/lcatro/network_backdoor_scanner 基于网络流量的内网探测框架
https://github.com/sowish/LNScan 详细的内部网络信息扫描器
https://github.com/rootlabs/nWatch 联动nmap,并对组织内网进行扫描
https://github.com/m8r0wn/nullinux 用于Linux的内部渗透测试工具,可用于通过SMB枚举操作系统信息,域信息,共享,目录和用户。
https://github.com/zMarch/Orc bash,Linux下后渗透命令集合
https://guif.re/linuxeop linux提权命令集合