- India
Stars
Automatically Download & Compile Useful BOFs for CS
🚀🤖 Crawl4AI: Open-source LLM Friendly Web Crawler & Scraper. Don't be shy, join here: https://discord.gg/jP8KfhDhyN
A python script that automates a C2 Profile build
Pure-impacket parallel local-admin discovery via RBCD.
Tunneling tool for red teaming, designed to run in memory on a windows target and connect back to a Linux VPS so you can proxy tools into a network securely and reliably.
Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!
Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking
Certified Red Team Operator (CRTO) Cheatsheet and Checklist
Point it at any web page and it finds the video, extracts the stream, transcodes it and casts in real time to your TV. It even burns subtitles….
Domain-fronted HTTP/SOCKS5 proxy tunneling traffic through Google Apps Script with MITM TLS interception, HTTP/1-2 multiplexing, and DPI evasion.
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
Azure AiTM Function PoC to phish Entra ID Credentials
This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim opens the phishing link and instantly redirects them to the …
OAuthBandit is a post-exploitation tool designed for Red Team operations and penetration testing engagements. It automates the extraction, validation, and exploitation of Microsoft OAuth tokens fro…
Dump TGTs remotely and convert Windows' klist binary output to ccache.
List of Awesome Red Team / Red Teaming Resources This list is for anyone wishing to learn about Red Teaming but do not have a starting point.
Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64, MIPS, PowerPC, SPARC64). For disassembly ropper us…
Some useful scripts for CobaltStrike
SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.
Adaptix C2 extender to support Cobalt Strike Malleable C2 profiles
Ghost Framework is a powerful, user-friendly Python-based tool designed for remotely controlling Android devices. It allows users to effortlessly connect, monitor, and manage Android devices over a…
TheHulk is a dynamic analysis tool designed to detect and exploit DOM Clobbering vulnerabilities.
This is a VxLAN PoC code for Talks: From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion
This is a PoC code for Talks: From Spoofing to Tunneling: New Red Team's Networking Techniques for Initial Access and Evasion