@cevenif: Friends who engage in offense and defense, penetration testing, and red teaming — this repository is a must-read. A user named A-poc on GitHub has organized over 150 commonly used red team tools by phase, from initial information gathering to post-exploitation cleanup, with comprehensive categories. The reconnaissance phase includes over 24 tools like SpiderFoot, Nuclei, S…
Summary
A GitHub user named A-poc has compiled over 150 commonly used red team tools, categorized by phase from information gathering to cleanup, along with 19 practical tips for security professionals to learn and research.
View Cached Full Text
Cached at: 07/24/26, 11:19 PM
Improved HTML smuggling with mouse move eventlistener @pr0xylife
Google translate for phishing @malmoeb
Hiding the local admin account @Alh4zr3d
Cripple windows defender by deleting signatures @Alh4zr3d
Enable multiple RDP sessions per user @Alh4zr3d
Sysinternals PsExec.exe local alternative @GuhnooPlusLinux
Live off the land port scanner @Alh4zr3d
Proxy aware PowerShell DownloadString @Alh4zr3d
Looking for internal endpoints in browser bookmarks @Alh4zr3d
Query DNS records for enumeration @Alh4zr3d
Unquoted service paths without PowerUp @Alh4zr3d
Bypass a disabled command prompt with /k Martin Sohn Christensen
Stop windows defender deleting mimikatz.exe @GuhnooPlusLinux
Check if you are in a virtual machine @dmcxblue
Enumerate AppLocker rules @Alh4zr3d
CMD shortcut with 6 pixels via mspaint PenTestPartners
Link spoofing with PreventDefault JavaScript method
Check SMB firewall rules with Responder @malmoeb
Disable AV with SysInternals PsSuspend @0gtweet
spiderfoot Automated OSINT and attack surface mapping
reconftw Automated subdomain and vulnerability recon tool
subzy Subdomain takeover vulnerability checker
smtp-user-enum SMTP user enumeration
crt.sh -> httprobe -> EyeWitness Automated domain screenshotting
jsendpoints Extract page DOM links
nuclei Vulnerability scanner
certSniff Certificate transparency log keyword sniffer
gobuster Website path brute force
feroxbuster Fast content discovery tool written in Rust
CloudBrute Cloud infrastructure brute force
dnsrecon Enumerate DNS records
Shodan.io Public facing system knowledge base
AORT (All in One Recon Tool) Subdomain enumeration
spoofcheck SPF/DMARC record checker
AWSBucketDump S3 bucket enumeration
GitHarvester GitHub credential searcher
truffleHog GitHub credential scanner
Dismap Asset discovery/identification
enum4linux Windows/samba enumeration
skanuvaty Dangerously fast dns/network/port scanner
Metabigor OSINT tool without API
Gitrob GitHub sensitive information scanner
gowitness Web screenshot utility using Chrome Headless
remoteinjector Inject remote template link into word document
Chimera PowerShell obfuscation
msfvenom Payload creation
Shellter Dynamic shellcode injection tool
Freeze Payload creation (circumventing EDR)
WordSteal Steal NTML hashes with Microsoft Word
NTAPI Undocumented Functions Windows NT Kernel, Native API and drivers
Kernel Callback Functions Undocumented Windows APIs
OffensiveVBA Office macro code execution and evasion techniques
WSH Wsh payload
HTA Hta payload
VBA Vba payload
CredMaster CredKing password spraying tool
TREVORspray Password sprayer with threading
evilqr QRLJacking phishing PoC
CUPP Common User Passwords Profiler (CUPP)
Bash Bunny USB attack tool
EvilGoPhish Phishing campaign framework
The Social-Engineer Toolkit Phishing campaign framework
Hydra Brute force tool
SquarePhish OAuth/QR code phishing framework
King Phisher Phishing campaign framework
Responder LLMNR, NBT-NS and MDNS poisoner
secretsdump Remote hash dumper
evil-winrm WinRM shell
Donut In-memory .NET execution
Macro_pack Macro obfuscation
PowerSploit PowerShell script suite
Rubeus Active directory hack tool
SharpUp Windows vulnerability identifier
SQLRecon Offensive MS-SQL toolkit
UltimateAppLockerByPassList Common AppLocker Bypass Techniques
StarFighters JavaScript and VBScript Based Empire Launcher
demiguise HTA encryption tool
PowerZure PowerShell framework to assess Azure security
Impacket Python script suite
Empire Post-exploitation framework
SharPersist Windows persistence toolkit
ligolo-ng Tunneling tool that uses a TUN interface
Crassus Windows privilege escalation discovery tool
LinPEAS Linux privilege escalation
WinPEAS Windows privilege escalation
linux-smart-enumeration Linux privilege escalation
Certify Active directory privilege escalation
Get-GPPPassword Windows password extraction
Sherlock PowerShell privilege escalation tool
Watson Windows privilege escalation tool
ImpulsiveDLLHijack DLL Hijack tool
ADFSDump AD FS dump tool
BeRoot Multi OS Privilege Escalation Project
Invoke-Obfuscation Script obfuscator
Veil Metasploit payload obfuscator
SharpBlock EDR bypass via entry point execution prevention
Alcatraz GUI x64 binary obfuscator
Mangle Compiled executable manipulation
AMSI Fail PowerShell snippets that break or disable AMSI
ScareCrow Payload creation framework designed around EDR bypass
moonwalk Linux system log and filesystem timestamp remover
Mimikatz Windows credential extractor
LaZagne Local password extractor
hashcat Password hash cracking
John the Ripper Password hash cracking
SCOMDecrypt SCOM Credential Decryption Tool
nanodump LSASS process minidump creation
eviltree Tree remake for credential discovery
SeeYouCM-Thief Cisco phone systems configuration file parsing
MailSniper Microsoft Exchange Mail Searcher
SharpChromium Cookie, history and saved login chromium extractor
dploot DPAPI looting remotely in Python
PCredz Credential discovery PCAP/live interface
PingCastle Active directory assessor
Seatbelt Local vulnerability scanner
ADRecon Active directory recon
adidnsdump Active Directory Integrated DNS dumping
scavenger Scanning tool for scavenging systems
crackmapexec Windows/Active directory lateral movement toolkit
WMIOps WMI remote commands
PowerLessShell Remote PowerShell without PowerShell
PsExec Light-weight telnet-replacement
LiquidSnake Fileless lateral movement
Enabling RDP Windows RDP enable command
Upgrading shell to meterpreter Reverse shell improvement
Forwarding Ports Local port forward command
Jenkins reverse shell Jenkins shell command
ADFSpoof Forge AD FS security tokens
kerbrute A tool to perform Kerberos pre-auth bruteforcing
Coercer Coerce a Windows server to authenticate
WMIOps WMI remote commands
BloodHound Active directory visualisation
Snaffler Active directory credential collector
linWinPwn Active Directory Enumeration and Vulnerability checks
Living Off Trusted Sites Project Leverage legitimate domains for your C2
Havoc Command and control framework
Covenant Command and control framework (.NET)
Merlin Command and control framework (Golang)
Metasploit Framework Command and control framework (Ruby)
Pupy Command and control framework (Python)
Brute Ratel Command and control framework ($$$)
NimPlant C2 implant written in Nim
Hoaxshell PowerShell reverse shell
Dnscat2 C2 via DNS tunneling
Cloakify Data transformation for exfiltration
PyExfil Data exfiltration PoC
Powershell RAT Python based backdoor
GD-Thief Google drive exfiltration
goshs Single-binary multi-protocol server for file transfer and exfiltration
Conti Pentester Guide Leak Conti ransomware group affilate toolkit
SlowLoris Simple denial of service
usbkill Anti-forensic kill-switch
Keytap Get pressed keyboard keys from typing audio
Similar Articles
@wsl8297: Want to learn cybersecurity? Most of the time isn't spent on learning itself, but on finding materials: tutorials in one place, tools in another, and practice environments elsewhere—piecing them together already wastes half a day. The h4cker project on GitHub, long maintained by renowned security author Omar Santos, compiles commonly used resources into a one-stop guide...
This article introduces the h4cker GitHub project maintained by Omar Santos, a one-stop cybersecurity resource navigation covering offensive and defensive techniques, cloud security, application security, AI security, and preparation materials for mainstream security certifications, helping learners efficiently find tutorials, tools, and lab environments.
@FakeMaidenMaker: the-book-of-secret-knowledge: Engineer's Secret Recipe Collection. Every time I need a handy CLI tool or trick, I end up Googling a bunch of stuff, find it but can't remember it, and have to search again next time. Recently I discovered a super useful resource library that categorizes all the CLI tools, cheatsheets, one-liners, and tutorials you need for daily command-line work. It's ready to browse and use anytime.
Introduces the the-book-of-secret-knowledge repository on GitHub, which collects a large number of CLI tools, cheatsheets, operations tips, and security resources, suitable for daily reference by engineers.
@seekjourney: Found a treasure trove! There's also a large collection of Codex practical case studies! Key steps are all with screenshots. https://codexguide.ai/recipes/ https://github.com/freestylefly/CodexGuide…
Shared a case library containing 16 Codex hands-on examples, covering PPT generation, MCP, browser automation, knowledge base, and other functions, with screenshots and step-by-step guides.
@aronhouyu: https://x.com/aronhouyu/status/2063561548145275255
Introduces an open-source repository called awesome-codex-skills, which contains thousands of preset skills for Codex (as well as Claude Code, Gemini CLI, etc.), covering development, data, collaboration, and other scenarios. It also provides installation and usage guides to help users reuse workflows.
@_zheergen: Guys! I just stumbled upon an open-source project that really made me pause. It's Everything Claude Code (ECC) by cogsec veteran @affaan. GitHub 205K stars. Project repo: https://github.com/…
An open-source project called ECC (Everything Claude Code) integrates 63 agents, 249 skills, and built-in security tests. It supports multiple AI coding tools like Claude Code, Codex, and Cursor, aiming to simplify the setup of AI programming workflows.