#red-team (30 Repositories)
Ranked open-source repositories tagged with #red-team, scored by pull request acceptance likelihood and maintainer engagement velocity.
17.7%
14.1h
30 repositories tagged #red-team
ashirt-ops/ashirt-server
Adversary Simulators High-Fidelity Intelligence and Reporting Toolkit
leebaird/discover
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Kali Linux and Ubuntu.
praetorian-inc/titus
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
The-Z-Labs/bof-launcher
[ BOF-LAUNCHER ] -> an API for loading, executing and in-memory masking BOFs on Windows and Linux for use in C/Zig/Go/Rust agents/implants. [ Z-BEAC0N ] -> a custom-written stage-1 (aka pre-C2) solution engineered with a small footprint, stealth and modularity in mind. [ DEVELOPED BOFS ] -> cross-platform (12), Linux-only (10), Win-only (2)
BlackArch/blackarch
An ArchLinux based distribution for penetration testers and security researchers.
BishopFox/sliver
Adversary Emulation Framework
halilkirazkaya/arsenal-ng
The classic launcher, evolved. Fast, Go-based command library equipped with 200+ cybersecurity cheat-sheets. Just install and start hacking.
ricardojoserf/SAMDump
Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. Implemented in C#, C++, Crystal and Python
Dest1ny-Sec/DesJsFinder
被动JS分析 + 框架识别 + 主动Fuzz + 响应指纹 — 红队API挖掘利器
ricardojoserf/AutoPtT
Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. Implemented in C#, C++, Crystal, Python and Rust
vectra-ai-research/MAAD-AF
MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).
umutcamliyurt/PingRAT
PingRAT secretly passes C2 traffic through firewalls using ICMP payloads.
Pnwcomputers/ULTIMATE-CYBERSECURITY-MASTER-GUIDE
This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and Step-by-Step Guides across various critical security domains. Content is sourced from industry-leading books and technical presentations, focusing on practical application rather than JUST theory.
f1zm0/acheron
indirect syscalls for AV/EDR evasion in Go assembly
kfallahi/UnderlayCopy
PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads
RiccardoAncarani/LiquidSnake
LiquidSnake is a tool that allows operators to perform fileless lateral movement using WMI Event Subscriptions and GadgetToJScript
Puliczek/CVE-2022-0337-PoC-Google-Chrome-Microsoft-Edge-Opera
🎩 🤟🏻 [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak - CVE-2022-0337
GetRektBoy724/SharpUnhooker
C# Based Universal API Unhooker
rubyfu/RubyFu
Rubyfu, where Ruby goes evil!
CommonHuman-Lab/nyxstrike
AI Powered penetration testing Platform for offensive security research
Whispergate/InfraGuard
InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution
itaymigdal/Nimbo-C2
Nimbo-C2 is yet another (simple and lightweight) C2 framework
getagentseal/agentseal
Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection resistance, and audit live MCP servers for tool poisoning.
ReversecLabs/dref
DNS Rebinding Exploitation Framework
ghostvectoracademy/DLLHijackHunter
Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.
redcode-labs/RedNixOS
NixOS-based 'distro' for cybersecurity enthusiasts
ReversecLabs/physmem2profit
Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely
wavvs/nanorobeus
COFF file (BOF) for managing Kerberos tickets.
MatheuZSecurity/D3m0n1z3dShell
Demonized Shell is an Advanced Tool for persistence in linux.