🕵️ Red Team - TTPs
FindUncommonShares is a Python script allowing to quickly find uncommon shares in vast Windows Domains, and filter by READ or WRITE accesses.
The SpecterOps project management and reporting engine
Find, verify, and analyze leaked credentials
Custom Queries - Brought Up to BH4.1 syntax
Collection of Beacon Object Files (BOF) for Cobalt Strike
OfensivePipeline allows you to download and build C# tools, applying certain modifications in order to improve their evasion for Red Team exercises.
A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs.
Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel
Situational Awareness commands implemented using Beacon Object Files
Six Degrees of Domain Admin
A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, i…
A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a tenant doesn't exist, if a user doesn't exist, i…
PowerSploit - A PowerShell Post-Exploitation Framework
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
This aggressor script uses a beacon's note field to indicate the health status of a beacon.
official repo for the AdHuntTool (part of the old RedTeamCSharpScripts repo)
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
Portable Executable reversing tool with a friendly GUI
Signing-key abuse and update exploitation framework
A tool that shows detailed information about named pipes in Windows
Burp Suite Certified Practitioner Exam Study
Red Teaming Tactics and Techniques
One stop place for exploiting Jira instances in your proximity
A tool for checking if MFA is enabled on multiple Microsoft Services