Stars
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …
SSLScrape | A scanning tool for scaping hostnames from SSL certificates.
⚡ Perform subdomain enumeration using the certificate transparency logs from Censys.
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
PowerShell Runspace Post Exploitation Toolkit
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources
A script to randomize Cobalt Strike Malleable C2 profiles and reduce the chances of flagging signature-based detection controls
Cobalt Strike is a post-exploitation framework designed to be extended and customized by the user community. Several excellent tools and scripts have been written and published, but they can be cha…
byt3bl33d3r / Red-Baron
Forked from Coalfire-Research/Red-BaronAutomate creating resilient, disposable, secure and agile infrastructure for Red Teams
Tools & Interesting Things for RedTeam Ops
Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and th…
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C
Run PowerShell command without invoking powershell.exe
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
C# Azure Function with an HTTP trigger that generates obfuscated PowerShell snippets that break or disable AMSI for the current process.
Bypass AMSI by patching AmsiScanBuffer
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique present…
The FLARE team's open-source tool to identify capabilities in executable files.