
GoRedOps
🦫 | GoRedOps 是一个致力于收集和分享红队高级技术与攻击性恶意软件的仓库,特别专注于 Go 编程语言,所有内容仅用于教育目的。

Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance…

Fuzz 401/403/404 pages for bypasses

一个可以绕过AMSI(反恶意软件扫描接口)和PowerShell CLM(受限语言模式)的工具,并为您提供一个全语言PowerShell反向shell。

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

.NET/PowerShell/VBA 攻击性安全混淆器

Shellcode注入技术。以C++头文件、独立的Rust程序或库的形式提供。

以编程方式创建用于反序列化利用的搜索规则,支持多种关键词、利用链、对象类型、编码和规则类型

RefleXXion is a utility designed to aid in bypassing user-mode hooks utilised by AV/EPP/EDR etc. In order to bypass the user-mode hooks, it first…

Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-software in…

Spray365 通过其可自定义的两步式密码喷洒方法,使针对 Microsoft 帐户(Office 365 / Azure AD)的密码喷洒变得简单。其内置的执行计划提供了一些选项,可尝试绕过 Azure Smart Lockout 和不安全的条件访问策略。


Gorsair gives root access on remote docker containers that expose their APIs

Cobalt Strike C2 反向代理,通过数据包检查与可扩展配置文件关联,抵御蓝队、杀毒软件、EDR、扫描器。


基于浏览器的C2隧道,通过Firefox的cookie.sqlite文件窃取payload,并自动提交HTML/JS,实现隐蔽的防火墙绕过,用于红队行动。

自动化工具,生成完美的 Meterpreter PowerShell Payload