Redteam Open Source Projects
Browse 329 Redteam open source projects, ranked by GitHub stars. Find the most popular Redteam tools and libraries.
bettercap/bettercap
The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.
Metrics details
| Stars | 19,534 |
laramies/theHarvester
E-mails, subdomains and names Harvester - OSINT
Metrics details
| Stars | 16,843 |
maurosoria/dirsearch
Web path scanner
Metrics details
| Stars | 14,521 |
GTFOBins/GTFOBins.github.io
GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
Metrics details
| Stars | 13,464 |
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
Metrics details
| Stars | 10,921 |
samratashok/nishang
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
Metrics details
| Stars | 10,007 |
A-poc/RedTeam-Tools
Tools and Techniques for Red Team / Penetration Testing
Metrics details
| Stars | 9,487 |
LOLBAS-Project/LOLBAS
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Metrics details
| Stars | 8,694 |
yeyintminthuhtut/Awesome-Red-Teaming
List of Awesome Red Teaming Resources
Metrics details
| Stars | 7,986 |
yaklang/yakit
Cyber Security ALL-IN-ONE Platform
Metrics details
| Stars | 7,612 |
LasCC/HackTools
The all-in-one browser extension for offensive security professionals 🛠
Metrics details
| Stars | 6,893 |
madhuakula/kubernetes-goat
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
Metrics details
| Stars | 5,719 |
ffffffff0x/1earn
ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
Metrics details
| Stars | 5,702 |
FunnyWolf/Viper
Adversary simulation and Red teaming platform with AI
Metrics details
| Stars | 5,136 |
nicocha30/ligolo-ng
An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
Metrics details
| Stars | 4,757 |
mantvydasb/RedTeaming-Tactics-and-Techniques
Red Teaming Tactics and Techniques
Metrics details
| Stars | 4,648 |
wgpsec/ENScan_GO
一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。支持MCP接入
Metrics details
| Stars | 4,571 |
zer0yu/Awesome-CobaltStrike
List of Awesome CobaltStrike Resources
Metrics details
| Stars | 4,431 |
t3l3machus/Villain
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
Metrics details
| Stars | 4,412 |
lcvvvv/kscan
Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹20000+,暴力破解协议10余种。
Metrics details
| Stars | 4,291 |
PeiQi0/PeiQi-WIKI-Book
面向网络安全从业者的知识文库🍃 (停止更新)
Metrics details
| Stars | 4,115 |
jonaslejon/malicious-pdf
💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
Metrics details
| Stars | 4,113 |
snooppr/snoop
Snoop — инструмент разведки на основе открытых данных (OSINT world)
Metrics details
| Stars | 3,970 |
S3cur3Th1sSh1t/WinPwn
Automation for internal Windows Penetrationtest / AD-Security
Metrics details
| Stars | 3,681 |
vaib25vicky/awesome-mobile-security
An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
Metrics details
| Stars | 3,513 |
ph4ntonn/Stowaway
👻Stowaway -- Multi-hop Proxy Tool for pentesters
Metrics details
| Stars | 3,394 |
matro7sh/BypassAV
This map lists the essential techniques to bypass anti-virus and EDR
Metrics details
| Stars | 3,364 |
mgeeky/Penetration-Testing-Tools
A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.
Metrics details
| Stars | 2,989 |
kurogai/100-redteam-projects
Projects for security students
Metrics details
| Stars | 2,891 |
opsdisk/the_cyber_plumbers_handbook
Free copy of The Cyber Plumber's Handbook - The definitive guide to Secure Shell (SSH) tunneling, port redirection, and bending traffic like a boss.
Metrics details
| Stars | 2,879 |
gloxec/CrossC2
generate CobaltStrike's cross-platform payload
Metrics details
| Stars | 2,562 |
r0eXpeR/redteam_vul
红队作战中比较常遇到的一些重点系统漏洞整理。
Metrics details
| Stars | 2,523 |
nil0x42/phpsploit
Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor
Metrics details
| Stars | 2,484 |
Idov31/Nidhogg
Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.
Metrics details
| Stars | 2,441 |
m0nad/Diamorphine
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)
Metrics details
| Stars | 2,419 |
tr0uble-mAker/POC-bomber
利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点
Metrics details
| Stars | 2,368 |
MegaManSec/SSH-Snake
SSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.
Metrics details
| Stars | 2,336 |
ssl/ezXSS
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
Metrics details
| Stars | 2,323 |
swisskyrepo/InternalAllTheThings
Active Directory and Internal Pentest Cheatsheets
Metrics details
| Stars | 2,323 |
hisxo/gitGraber
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
Metrics details
| Stars | 2,317 |
sevagas/macro_pack
macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research.
Metrics details
| Stars | 2,306 |
bigb0sss/RedTeam-OffensiveSecurity
Tools & Interesting Things for RedTeam Ops
Metrics details
| Stars | 2,293 |
kgretzky/pwndrop
Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.
Metrics details
| Stars | 2,271 |
Dliv3/Venom
Venom - A Multi-hop Proxy for Penetration Testers
Metrics details
| Stars | 2,164 |
zhzyker/dismap
Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点
Metrics details
| Stars | 2,157 |
phra/PEzor
Open-Source Shellcode & PE Packer
Metrics details
| Stars | 2,116 |
nettitude/PoshC2
A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
Metrics details
| Stars | 2,114 |
tom0li/collection-document
Collection of quality safety articles. Awesome articles.
Metrics details
| Stars | 2,109 |
teamssix/cf
Cloud Exploitation Framework 云环境利用框架,方便安全人员在获得 AK 的后续工作
Metrics details
| Stars | 2,077 |
api0cradle/UltimateAppLockerByPassList
The goal of this repository is to document the most common techniques to bypass AppLocker.
Metrics details
| Stars | 2,075 |
r00t-3xp10it/venom
venom - C2 shellcode generator/compiler/handler
Metrics details
| Stars | 1,958 |
zer0yu/CyberSecurityRSS
CyberSecurityRSS: A collection of cybersecurity rss to make you better!
Metrics details
| Stars | 1,937 |
ihebski/A-Red-Teamer-diaries
RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
Metrics details
| Stars | 1,928 |
joaoviictorti/RustRedOps
Repository for advanced Red Team techniques focused on Rust
Metrics details
| Stars | 1,891 |
wgpsec/fofa_viewer
A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.
Metrics details
| Stars | 1,799 |
piaolin/DetectDee
DetectDee: Hunt down social media accounts by username, email or phone across social networks.
Metrics details
| Stars | 1,786 |
mthcht/awesome-lists
Awesome Security lists for SOC/CERT/CTI
Metrics details
| Stars | 1,751 |
jm33-m0/emp3r0r
Self‑healing Gossip Mesh C2 with Assisted Peer Discovery, Modular Post‑Exploitation, and Scriptable Agents.
Metrics details
| Stars | 1,714 |
WADComs/WADComs.github.io
WADComs is an interactive cheat sheet, containing a curated list of offensive security tools and their respective commands, to be used against Windows/AD environments.
Metrics details
| Stars | 1,691 |
veo/vscan
开源、轻量、快速、跨平台 的网站漏洞扫描工具,帮助您快速检测网站安全隐患。功能 端口扫描(port scan) 指纹识别(fingerprint) 漏洞检测(nday check) 智能爆破 (admin brute) 敏感文件扫描(file fuzz)
Metrics details
| Stars | 1,630 |
