OffSec
BlueHound - pinpoint the security issues that actually matter
List of Awesome Red Teaming Resources
CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into product…
Interactive visualizations of Terraform dependency graphs using d3.js
KubeTaK - Kube Attack. Exploit your K8s cluster and workloads running in it. PenTest K8s. Inspired by the concept of kubesploit by CyberArk and StackHawk.
Fast passive subdomain enumeration tool.
A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests
An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.
VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios
A GPT-empowered penetration testing tool
In-depth attack surface mapping and asset discovery
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
Attack Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by developing a representation of attack flows, modeling attack flow…
A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.
Small and highly portable detection tests based on MITRE's ATT&CK.
Enumeration/exploit/analysis/download/etc pentesting framework for GCP; modeled like Pacu for AWS; a product of numerous hours via @WebbinRoot
Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native executables.
Verizon Burp Extensions: AI Suite
DeepTeam is a framework to red team LLMs and LLM systems.