@cevenif: Friends who engage in offense and defense, penetration testing, and red teaming — this repository is a must-read. A user named A-poc on GitHub has organized over 150 commonly used red team tools by phase, from initial information gathering to post-exploitation cleanup, with comprehensive categories. The reconnaissance phase includes over 24 tools like SpiderFoot, Nuclei, S…

X AI KOLs Timeline Tools

Summary

A GitHub user named A-poc has compiled over 150 commonly used red team tools, categorized by phase from information gathering to cleanup, along with 19 practical tips for security professionals to learn and research.

Friends who engage in offense and defense, penetration testing, and red teaming — this repository is a must-read. A user named A-poc on GitHub has organized over 150 commonly used red team tools by phase, from initial information gathering to post-exploitation cleanup, with comprehensive categories. In the reconnaissance phase, there are 24 tools such as SpiderFoot, Nuclei, Shodan, and Gobuster, covering various angles of information gathering. For initial access, tools like CredMaster for password spraying, EvilGoPhish and SET for phishing, and Hydra for brute-forcing are included. For defense evasion, Invoke-Obfuscation, Veil, SharpBlock, and AMSIFail are specifically designed to counter EDR and antivirus software. Persistence and privilege escalation are covered by classics like Impacket, Empire, Mimikatz, LinPEAS, and WinPEAS. The C2 frameworks section includes 9 options such as Havoc, Covenant, Merlin, and Metasploit, giving you plenty to choose from. Most valuable are the 19 practical tips included, all private tricks from seasoned pros — for example, using mouse movement events to trigger HTML smuggling, modifying the registry to hide local admin accounts, and deleting the Windows Defender signature database with a single command. Every trick is practical. Disclaimer: This repository is for learning and research purposes only. Do not use it for illegal activities. :
Original Article
View Cached Full Text

Cached at: 07/24/26, 11:19 PM

Improved HTML smuggling with mouse move eventlistener @pr0xylife

Google translate for phishing @malmoeb

Hiding the local admin account @Alh4zr3d

Cripple windows defender by deleting signatures @Alh4zr3d

Enable multiple RDP sessions per user @Alh4zr3d

Sysinternals PsExec.exe local alternative @GuhnooPlusLinux

Live off the land port scanner @Alh4zr3d

Proxy aware PowerShell DownloadString @Alh4zr3d

Looking for internal endpoints in browser bookmarks @Alh4zr3d

Query DNS records for enumeration @Alh4zr3d

Unquoted service paths without PowerUp @Alh4zr3d

Bypass a disabled command prompt with /k Martin Sohn Christensen

Stop windows defender deleting mimikatz.exe @GuhnooPlusLinux

Check if you are in a virtual machine @dmcxblue

Enumerate AppLocker rules @Alh4zr3d

CMD shortcut with 6 pixels via mspaint PenTestPartners

Link spoofing with PreventDefault JavaScript method

Check SMB firewall rules with Responder @malmoeb

Disable AV with SysInternals PsSuspend @0gtweet

spiderfoot Automated OSINT and attack surface mapping

reconftw Automated subdomain and vulnerability recon tool

subzy Subdomain takeover vulnerability checker

smtp-user-enum SMTP user enumeration

crt.sh -> httprobe -> EyeWitness Automated domain screenshotting

jsendpoints Extract page DOM links

nuclei Vulnerability scanner

certSniff Certificate transparency log keyword sniffer

gobuster Website path brute force

feroxbuster Fast content discovery tool written in Rust

CloudBrute Cloud infrastructure brute force

dnsrecon Enumerate DNS records

Shodan.io Public facing system knowledge base

AORT (All in One Recon Tool) Subdomain enumeration

spoofcheck SPF/DMARC record checker

AWSBucketDump S3 bucket enumeration

GitHarvester GitHub credential searcher

truffleHog GitHub credential scanner

Dismap Asset discovery/identification

enum4linux Windows/samba enumeration

skanuvaty Dangerously fast dns/network/port scanner

Metabigor OSINT tool without API

Gitrob GitHub sensitive information scanner

gowitness Web screenshot utility using Chrome Headless

remoteinjector Inject remote template link into word document

Chimera PowerShell obfuscation

msfvenom Payload creation

Shellter Dynamic shellcode injection tool

Freeze Payload creation (circumventing EDR)

WordSteal Steal NTML hashes with Microsoft Word

NTAPI Undocumented Functions Windows NT Kernel, Native API and drivers

Kernel Callback Functions Undocumented Windows APIs

OffensiveVBA Office macro code execution and evasion techniques

WSH Wsh payload

HTA Hta payload

VBA Vba payload

CredMaster CredKing password spraying tool

TREVORspray Password sprayer with threading

evilqr QRLJacking phishing PoC

CUPP Common User Passwords Profiler (CUPP)

Bash Bunny USB attack tool

EvilGoPhish Phishing campaign framework

The Social-Engineer Toolkit Phishing campaign framework

Hydra Brute force tool

SquarePhish OAuth/QR code phishing framework

King Phisher Phishing campaign framework

Responder LLMNR, NBT-NS and MDNS poisoner

secretsdump Remote hash dumper

evil-winrm WinRM shell

Donut In-memory .NET execution

Macro_pack Macro obfuscation

PowerSploit PowerShell script suite

Rubeus Active directory hack tool

SharpUp Windows vulnerability identifier

SQLRecon Offensive MS-SQL toolkit

UltimateAppLockerByPassList Common AppLocker Bypass Techniques

StarFighters JavaScript and VBScript Based Empire Launcher

demiguise HTA encryption tool

PowerZure PowerShell framework to assess Azure security

Impacket Python script suite

Empire Post-exploitation framework

SharPersist Windows persistence toolkit

ligolo-ng Tunneling tool that uses a TUN interface

Crassus Windows privilege escalation discovery tool

LinPEAS Linux privilege escalation

WinPEAS Windows privilege escalation

linux-smart-enumeration Linux privilege escalation

Certify Active directory privilege escalation

Get-GPPPassword Windows password extraction

Sherlock PowerShell privilege escalation tool

Watson Windows privilege escalation tool

ImpulsiveDLLHijack DLL Hijack tool

ADFSDump AD FS dump tool

BeRoot Multi OS Privilege Escalation Project

Invoke-Obfuscation Script obfuscator

Veil Metasploit payload obfuscator

SharpBlock EDR bypass via entry point execution prevention

Alcatraz GUI x64 binary obfuscator

Mangle Compiled executable manipulation

AMSI Fail PowerShell snippets that break or disable AMSI

ScareCrow Payload creation framework designed around EDR bypass

moonwalk Linux system log and filesystem timestamp remover

Mimikatz Windows credential extractor

LaZagne Local password extractor

hashcat Password hash cracking

John the Ripper Password hash cracking

SCOMDecrypt SCOM Credential Decryption Tool

nanodump LSASS process minidump creation

eviltree Tree remake for credential discovery

SeeYouCM-Thief Cisco phone systems configuration file parsing

MailSniper Microsoft Exchange Mail Searcher

SharpChromium Cookie, history and saved login chromium extractor

dploot DPAPI looting remotely in Python

PCredz Credential discovery PCAP/live interface

PingCastle Active directory assessor

Seatbelt Local vulnerability scanner

ADRecon Active directory recon

adidnsdump Active Directory Integrated DNS dumping

scavenger Scanning tool for scavenging systems

crackmapexec Windows/Active directory lateral movement toolkit

WMIOps WMI remote commands

PowerLessShell Remote PowerShell without PowerShell

PsExec Light-weight telnet-replacement

LiquidSnake Fileless lateral movement

Enabling RDP Windows RDP enable command

Upgrading shell to meterpreter Reverse shell improvement

Forwarding Ports Local port forward command

Jenkins reverse shell Jenkins shell command

ADFSpoof Forge AD FS security tokens

kerbrute A tool to perform Kerberos pre-auth bruteforcing

Coercer Coerce a Windows server to authenticate

WMIOps WMI remote commands

BloodHound Active directory visualisation

Snaffler Active directory credential collector

linWinPwn Active Directory Enumeration and Vulnerability checks

Living Off Trusted Sites Project Leverage legitimate domains for your C2

Havoc Command and control framework

Covenant Command and control framework (.NET)

Merlin Command and control framework (Golang)

Metasploit Framework Command and control framework (Ruby)

Pupy Command and control framework (Python)

Brute Ratel Command and control framework ($$$)

NimPlant C2 implant written in Nim

Hoaxshell PowerShell reverse shell

Dnscat2 C2 via DNS tunneling

Cloakify Data transformation for exfiltration

PyExfil Data exfiltration PoC

Powershell RAT Python based backdoor

GD-Thief Google drive exfiltration

goshs Single-binary multi-protocol server for file transfer and exfiltration

Conti Pentester Guide Leak Conti ransomware group affilate toolkit

SlowLoris Simple denial of service

usbkill Anti-forensic kill-switch

Keytap Get pressed keyboard keys from typing audio

Similar Articles

@wsl8297: Want to learn cybersecurity? Most of the time isn't spent on learning itself, but on finding materials: tutorials in one place, tools in another, and practice environments elsewhere—piecing them together already wastes half a day. The h4cker project on GitHub, long maintained by renowned security author Omar Santos, compiles commonly used resources into a one-stop guide...

X AI KOLs Timeline

This article introduces the h4cker GitHub project maintained by Omar Santos, a one-stop cybersecurity resource navigation covering offensive and defensive techniques, cloud security, application security, AI security, and preparation materials for mainstream security certifications, helping learners efficiently find tutorials, tools, and lab environments.

@FakeMaidenMaker: the-book-of-secret-knowledge: Engineer's Secret Recipe Collection. Every time I need a handy CLI tool or trick, I end up Googling a bunch of stuff, find it but can't remember it, and have to search again next time. Recently I discovered a super useful resource library that categorizes all the CLI tools, cheatsheets, one-liners, and tutorials you need for daily command-line work. It's ready to browse and use anytime.

X AI KOLs Timeline

Introduces the the-book-of-secret-knowledge repository on GitHub, which collects a large number of CLI tools, cheatsheets, operations tips, and security resources, suitable for daily reference by engineers.

@aronhouyu: https://x.com/aronhouyu/status/2063561548145275255

X AI KOLs Following

Introduces an open-source repository called awesome-codex-skills, which contains thousands of preset skills for Codex (as well as Claude Code, Gemini CLI, etc.), covering development, data, collaboration, and other scenarios. It also provides installation and usage guides to help users reuse workflows.