> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

DecryptRDCManager

DecryptRDCManager is a .NET tool designed to decrypt credentials stored in Remote Desktop Manager (.rdg) files, leveraging the functionality of RDCMan.DLL. Its primary use case is to extract and read encrypted user credentials, particularly those contained within the more reliable `<credentialsProfile>` section, while also providing an option to automate file detection via user settings. Notable features include the ease of building the tool and its ability to handle paths for .rdg files seamlessly, along with a focus on credential profile extraction for enhanced reliability.

DeathNote

DeathNote is a penetration testing cheat sheet tool that provides a collection of resources and techniques essential for conducting security assessments. Its primary use case is to streamline the penetration testing process by offering organized references for various attack vectors, including reverse shells, PowerShell exploits, Active Directory, brute-forcing, and persistence methods. Notable features include compatibility with both Python 2.7 and 3.7, straightforward installation, and customizable configurations.

Crowbar

Crowbar is a comprehensive Windows post-exploitation tool designed to facilitate various tasks such as privilege escalation and system command execution via PowerShell. It includes an extensive range of scripts and utilities, notably the 'Hail Mary' feature for launching multiple scripts simultaneously, and checks for the presence of Windows Subsystem for Linux on the target machine. The tool is actively maintained, with regular updates that introduce new scripts and enhancements to improve functionality.

Coyote

Coyote is a C# post-exploitation implant designed for maintaining access to compromised Windows systems during red team operations. Its notable features include bypassing application whitelisting through InstallUtil.exe, utilizing a recursive DNS tunnel to retrieve encrypted commands, and maintaining a small footprint on both memory and network resources. The tool leverages a DLL that periodically polls a DNS TXT record for remote instructions, allowing operators to execute various payloads, such as spawning a reverse shell, while potentially evading detection.

covermyass

Covermyass is a post-exploitation tool designed for penetration testers to securely delete log files across multiple operating systems, including Linux, macOS, and Windows. It enables users to identify and overwrite log files with random data to obscure their activities before exiting a compromised server. Notable features include multiple overwrite iterations and the ability to handle file permissions, ensuring thorough data eradication.

Cobalt-Strike-Aggressor-Script-Collection

The Cobalt Strike Aggressor Script Collection provides a set of scripts designed to enhance post-exploitation capabilities within the Cobalt Strike framework. Key features include techniques for privilege escalation, persistence, and situational awareness, along with accessible notes that facilitate streamlined operations during engagements. This tool is primarily used by security professionals for advanced exploitation and operational efficiency in red team scenarios.

C2_Server

The C2 Server is a Command and Control framework that enables attackers to manage compromised target machines through a reverse shell connection. It supports various commands for file management, directory navigation, and even malicious functions like keylogging and credential spoofing, enhancing the attacker's ability to interact with the victim's system. Written in Python, it provides a user-friendly interface for executing predefined commands and extracting sensitive information from infected devices.

Bifrost

Bifrost is an open-source command and control (C2) tool implemented as a Discord bot, allowing users to manage and communicate with compromised clients through the Discord API. It supports multiple platforms and provides features such as keylogging, antivirus enumeration, real-time encrypted communication, and file management capabilities. Designed for educational and authorized security testing purposes, Bifrost leverages the Discord infrastructure to maintain a stealthy connection with clients.

Bella

Bella is a potent post-exploitation and remote administration tool designed specifically for macOS, leveraging Python for high-level automation and ease of use. Its primary use case involves establishing SSL/TLS encrypted reverse shells to facilitate comprehensive data extraction, including passwords, system information, and iCloud services, while offering features like multi-user support, reverse VNC connections, and extensive logging capabilities. Notably, Bella can gain root access to expand its functionalities and maintain persistent control over the target system, all while operating undetectably.

AWS-Attack

AWSATT&CK is a modified version of the open-source AWS exploitation framework, Pacu, designed to add MITRE ATT&CK context to its tactics and enhance logging capabilities. This tool is primarily used for post-exploitation within AWS environments, featuring quick execution functions, event logging to SIEM solutions, and scalability enhancements to streamline security operations. Notable features include the integration of MITRE ATT&CK techniques, agile deployment options, and a focus on flexibility for security professionals tackling diverse IT and cloud-native challenges.

awesome-malware

Awesome Malware is a curated repository of various malware, botnets, and post-exploitation tools designed for research and educational purposes. It offers extensive categories such as analysis tools, banking trojans, C2 frameworks, credential stuffing checkers, and more, enabling users to explore and understand malicious software dynamics. Noteworthy features include a focus on free software projects and the inclusion of both historical and contemporary malware resources for comprehensive analysis.

autoMetasploit

autoMetasploit is a Ruby script designed to streamline the processes of scanning, exploiting, and conducting post-exploitation activities with Metasploit. It automates key tasks by requiring configuration of plugins and supports report generation by integrating with external templates and email functionalities. Notable features include customizable brute force scripts, LDAP user enumeration capabilities, and the ability to send PDF reports via email.

AtlasC2

AtlasC2 is a C# command and control (C2) framework designed for Stage 1 operations, primarily used for establishing footholds within Windows environments and executing C# payloads through HTTP-based implants. Notable features include the ability to manage listeners, connect to multiple implants, execute system commands via PowerShell or CMD, and dynamically load C# assemblies into memory, making it a potent tool for post-exploitation scenarios despite current OPSEC limitations.

AdbNet

AdbNet is an exploitation tool designed for identifying and compromising vulnerable Android devices across the globe. Key features include post-exploitation modules, device scanning functionalities, IP address management, and integration with APIs from Censys and Shodan for discovering susceptible devices. Users can connect to these devices through common ports, execute commands, and utilize various exploits to gain control over the target systems.

ghost

Ghost Framework is an Android post-exploitation tool that leverages the Android Debug Bridge for remote device administration. It provides a user-friendly interface to execute various remote management tasks such as accessing the device shell, installing applications, capturing screenshots, and managing device settings. Notable features include password removal capabilities and comprehensive system information retrieval.

ZeroPulse

ZeroPulse is a modern Command & Control (C2) platform designed for secure remote management and monitoring of systems, utilizing Cloudflare Tunnel technology for encrypted connections. Key features include built-in authentication, support for WinRM and SSH interactions, a responsive React interface with real-time terminal integration, and comprehensive DNS management. The tool is currently in active development and is intended primarily for testing and evaluation purposes.

XENA

XENA is a cross-platform cybersecurity automation framework designed for adversary simulations and red team operations, featuring a built-in post-exploitation agent and a command-and-control (C2) server. Notable features include an elegant dark-themed user interface that supports desktop, web, and mobile formats, along with high-level automation capabilities for orchestrating C2 clusters. This community edition serves as an integrated tool for penetration testing, facilitating a comprehensive approach to security assessment.

WindowSpy

WindowSpy is a Cobalt Strike Beacon Object File designed for targeted user surveillance, facilitating stealthy detection of significant user activities such as entering credentials or accessing confidential documents. It operates by comparing active window titles against a customizable list to trigger specific actions, like screenshots, only when relevant activities are detected, thus minimizing unnecessary data collection. Key features include easy integration with Cobalt Strike, a configurable keyword list for triggering surveillance, and the ability to customize the actions performed upon detection.

WebcamBOF

WebcamBOF is a Beacon Object File (BOF) for Cobalt Strike that enables webcam capture functionality. Its primary use case is to facilitate remote image acquisition by allowing users to save webcam images either to disk or download them directly over the Cobalt Strike beacon. Notable features include multiple save methods, including capturing images as screenshots, and the ability to enumerate connected webcam devices.

venus

Venus is a VS Code extension designed to serve as an agent for the Mythic C2 framework, enabling operators to create and deliver payloads to target systems. This tool automates the packaging of VS Code extensions and supports various commands for interacting with the system environment, although it currently lacks support for encrypted payloads. Notably, Venus is cross-platform compatible and requires manual installation on target machines after preparation.

Unicorn

Unicorn is a Command and Control (C2) framework designed for post-exploitation and remote control operations. Built using Python and Flask, it features a client-server architecture that supports multiple listeners, dynamic command execution, and client chat synchronization, while still being in development with planned enhancements such as a proxy server and GUI integration. This tool is aimed at cybersecurity professionals for managing agents and executing commands in compromised environments.

TTPs

The FreeZeroDays/TTPs repository serves as a curated collection of offensive security notes, focusing on Tactics, Techniques, and Procedures (TTPs). It provides a repository of validated commands and resources targeted towards researchers and practitioners in offensive security. Notably, the documentation emphasizes accuracy and reliability, and it draws inspiration from other established collections in the field.

sshimpanzee

Sshimpanzee is a tool for creating a static reverse SSH server that initiates connections from the victim machine to an attacker's IP, bypassing the need for incoming connection requests. It provides all standard SSH functionalities, including port forwarding and dynamic SOCKS proxies, while also offering advanced tunneling methods like DNS Tunneling, ICMP Tunneling, and HTTP encapsulation to facilitate communication in restrictive network environments. Notable features include customizable build configurations, support for multiple tunneling mechanisms, and the ability to generate new SSH keys upon build.

SoundShell

SoundShell is a Command-and-Control (C2) tool developed in Go that utilizes the Spotify Web API to execute encoded commands and generate corresponding playlists. Its primary use case is to dynamically create playlists based on user-inputted commands, with notable features including custom command execution, command encoding for playlist generation, and random track selection from a predefined song pool.

silkwire

Silkwire is a gRPC-based Command and Control (C2) framework designed for authorized penetration testing and red team operations. It supports multiple platforms (Windows, Linux, macOS) and offers advanced features including dynamic implant generation, post-exploitation modules, keylogging, and enhanced evasion techniques against detection mechanisms. The tool emphasizes encryption for communications and session management, making it a robust option for security professionals in performing comprehensive security assessments.