Link |
Description |
alphasoc/flightsim |
A utility to generate malicious network traffic and evaluate controls |
Attack Simulatorin Office 365 |
Simulate realistic attacks on Office 365 environment |
Blue Team Training Toolkit |
Blue Team Training Toolkit (BT3) is designed for network analysis training sessions, incident response drills and red team engagements |
Coalfire-Research/Red-Baron |
Automate creating resilient, disposable, secure and agile infrastructure for Red Teams |
Cyb3rWard0g/Invoke-ATTACKAPI |
A PowerShell script to interact with the MITRE ATT&CK Framework via its own API |
Cyb3rWard0g/mordor |
Re-play Adversarial Techniques |
chryzsh/DarthSidious |
Building an Active Directory domain and hacking it |
d3vzer0/reternal-quickstart |
Repo containing docker-compose files and setup scripts without having to clone the individual reternal components |
endgameinc/RTA |
RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK |
jymchoeng/AutoTTP |
Automated Tactics Techniques & Procedures |
mdsecactivebreach/CACTUSTORCH |
CACTUSTORCH: Payload Generation for Adversary Simulations |
mitre/caldera |
An automated adversary emulation system |
NextronSystems/APTSimulator |
A toolset to make a system look as if it was the victim of an APT attack |
n0dec/MalwLess |
Test blue team detections without running any attack |
praetorian-code/purple-team-attack-automation |
Praetorian's public release of our Metasploit automation of MITRE ATT&CK™ TTPs |
TryCatchHCF/DumpsterFire |
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. |
redcanaryco/atomic-red-team |
Small and highly portable detection tests based on MITRE's ATT&CK. |
redhuntlabs/RedHunt-OS |
Virtual Machine for Adversary Emulation and Threat Hunting |
SpiderLabs/sheepl |
Sheepl : Creating realistic user behaviour for supporting tradecraft development within lab environments |
uber-common/metta |
An information security preparedness tool to do adversarial simulation. |
Unfetter |
Unfetter is a project designed to help network defenders, cyber security professionals, and decision makers identify and analyze defensive gaps in a more scalable and repeatable way |
## Binary Analysis
Link |
Description |
avast-tl/retdec |
RetDec is a retargetable machine-code decompiler based on LLVM |
bootleg/ret-sync |
ret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA/Ghidra disassemblers. |
Cisco-Talos/GhIDA |
GhIDA is an IDA Pro plugin that integrates the Ghidra decompiler in IDA. |
Cisco-Talos/Ghidraaas |
Ghidraaas is a simple web server that exposes Ghidra analysis through REST APIs. The project includes three Ghidra plugins to analyze a sample, get the list of functions and to decompile a function. |
Comsecuris/gdbida |
gdbida - a visual bridge between a GDB session and IDA Pro's disassembler |
Cutter |
Free and Open Source RE Platform powered by radare2 |
enkomio/shed |
.NET runtine inspector. Shed - Inspect .NET malware like a Sir |
fireeye/flare-floss |
FireEye Labs Obfuscated String Solver - Automatically extract obfuscated strings from malware. |
fireeye/flare-fakenet-ng |
FakeNet-NG - Next Generation Dynamic Network Analysis Tool |
GHIDRA |
A software reverse engineering (SRE) suite of tools developed by NSA's Research Directorate in support of the Cybersecurity mission |
Go Reverse Engineering Toolkit |
A Reverse Engineering Tool Kit for Go, Written in Go. |
hasherezade/hollows_hunter |
A process scanner detecting and dumping hollowed PE modules. |
hasherezade/hook_finder |
a small tool for investigating inline hooks (and other in-memory code patches) |
LIEF |
Library to Instrument Executable Formats |
Microsoft/binskim |
A binary static analysis tool that provides security and correctness results for Windows portable executables |
Microsoft/ProcDump-for-Linux |
A Linux version of the ProcDump Sysinternals tool |
mxmssh/drltrace |
Drltrace is a library calls tracer for Windows and Linux applications |
NASA-SW-VnV/ikos |
IKOS (Inference Kernel for Open Static Analyzers) is a static analyzer for C/C++ based on the theory of Abstract Interpretation |
pierrezurek/Signsrch |
tool for searching signatures inside files, extremely useful in reversing engineering for figuring or having an initial idea of what encryption/compression algorithm is used for a proprietary protocol or file. it can recognize tons of compression, multimedia and encryption algorithms and many other things like known strings and anti-debugging code which can be also manually added since it's all based on a text signature file read at runtime and easy to modify. |
pygore |
Python library for analyzing Go binaries |
taviso/loadlibrary |
Porting Windows Dynamic Link Libraries to Linux |
secretsquirrel/recomposer |
Randomly changes Win32/64 PE Files for 'safer' uploading to malware and sandbox sites. |
VisUAL |
A highly visual ARM emulator |
williballenthin/python-idb
|
Pure Python parser and analyzer for IDA Pro database files (.idb).
|
## Cloud Security
Link |
Description |
Alfresco/prowler |
Tool for AWS security assessment, auditing and hardening. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark. |
andresriancho/nimbostratus |
Tools for fingerprinting and exploiting Amazon cloud infrastructures |
asecure.cloud |
A free repository of customizable AWS security configurations and best practices |
asecurityteam/spacecrab |
Bootstraps an AWS account with everything you need to generate, mangage, and distribute and alert on AWS honey tokens. Made with breakfast roti by the Atlassian security team. |
awslabs/aws-security-benchmark |
Open source demos, concept and guidance related to the AWS CIS Foundation framework. |
carnal0wnage/weirdAAL |
WeirdAAL [AWS Attack Library] wiki! |
cloudsploit/scans |
AWS security scanning checks |
cyberark/SkyArk |
SkyArk is a cloud security tool, helps to discover, assess and secure the most privileged entities in AWS |
dagrz/aws_pwn |
A collection of AWS penetration testing junk |
disruptops/cred_scanner |
A simple file-based scaner to look for potential AWS accesses and secret keys in files |
duo-labs/cloudtracker |
CloudTracker helps you find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies. |
duo-labs/cloudmapper |
CloudMapper helps you analyze your Amazon Web Services (AWS) environments. |
eth0izzle/bucket-stream |
Find interesting Amazon S3 Buckets by watching certificate transparency logs. |
FishermansEnemy/bucket_finder |
Amazon bucket brute force tool |
glen-mac/goGetBucket |
A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain. |
kromtech/s3-inspector |
Tool to check AWS S3 bucket permissions |
jordanpotti/AWSBucketDump |
Security Tool to Look For Interesting Files in S3 Buckets |
jordanpotti/CloudScraper |
CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space. |
lyft/metadataproxy |
A proxy for AWS's metadata service that gives out scoped IAM credentials from STS |
MindPointGroup/cloudfrunt |
A tool for identifying misconfigured CloudFront domains |
nccgroup/aws-inventory |
Discover resources created in an AWS account |
nccgroup/PMapper |
A tool for quickly evaluating IAM permissions in AWS. |
sendgrid/krampus |
The original AWS security enforcer™ |
nccgroup/Scout2 |
Security auditing tool for AWS environments |
nccgroup/ScoutSuite |
Scout Suite is an open source multi-cloud security-auditing tool, which enables security posture assessment of cloud environments |
Netflix-Skunkworks/diffy |
Diffy is a digital forensics and incident response (DFIR) tool developed by Netflix's Security Intelligence and Response Team (SIRT). |
Netflix/security_monkey |
Security Monkey monitors your AWS and GCP accounts for policy changes and alerts on insecure configurations. |
prevade/cloudjack |
Route53/CloudFront Vulnerability Assessment Utility |
sa7mon/S3Scanner |
Scan for open S3 buckets and dump |
random-robbie/slurp |
Enumerate S3 buckets via certstream, domain, or keywords |
RhinoSecurityLabs/pacu |
Rhino Security Labs' AWS penetration testing toolkit |
RiotGames/cloud-inquisitor |
Enforce ownership and data security within AWS |
toniblyx/prowler |
Tool based on AWS-CLI commands for AWS account security assessment and hardening, following guidelines of the CIS Amazon Web Services Foundations Benchmark 1.1 |
SecurityFTW/cs-suite |
Cloud Security Suite - One stop tool for auditing the security posture of AWS infrastructure. |
ThreatResponse/margaritashotgun |
Remote Memory Acquisition Tool for AWS |
ThreatResponse/aws_ir |
Python installable command line utiltity for mitigation of host and key compromises. |
## Cryptography
Link |
Description |
$I File Parser |
Free Forensics Tool – $I File Parser |
AlienVault OSSIM |
AlienVault OSSIM: The World’s Most Widely Used Open Source SIEM |
andreafortuna/autotimeliner |
Automagically extract forensic timeline from volatile memory dump |
ANSSI-FR/bits_parser |
Extract BITS jobs from QMGR queue and store them as CSV records |
ANSSI-FR/bmc-tools |
RDP Bitmap Cache Parser |
bfuzzy/auditd-attack |
A Linux Auditd rule set mapped to MITRE's Attack Framework |
Broctets-and-Bytes/Darwin |
This script is designed to be run against a mounted image, live system, or device in target disk mode. The script automates the collection of key files for MacOS investigations. |
bromiley/olaf |
Office365 Log Analysis Framework: OLAF is a collection of tools, scripts, and analysis techniques dealing with O365 Investigations. |
carmaa/inception |
Inception is a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard, PC Card and any other PCI/PCIe interfaces. |
coinbase/dexter |
Forensics acquisition framework designed to be extensible and secure |
CrowdStrike/automactc |
AutoMacTC: Automated Mac Forensic Triage Collector |
CrowdStrike/Forensics |
Scripts and code referenced in CrowdStrike blog posts |
cryps1s/DARKSURGEON |
DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense. |
Cyb3rWard0g/HELK |
A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities. |
Cyber Analytics Repository |
The MITRE Cyber Analytics Repository (CAR) is a knowledge base of analytics developed by MITRE based on the MITRE ATT&CK adversary model. |
CyberDefenseInstitute/CDIR |
CDIR (Cyber Defense Institute Incident Response) Collector - live collection tool based on oss tool/library |
davehull/Kansa |
A Powershell incident response framework |
DFIR ORC |
DFIR ORC, where ORC stands for “Outil de Recherche de Compromission” in French, is a collection of specialized tools dedicated to reliably parse and collect critical artefacts such as the MFT, registry hives or event logs. It can also embed external tools and their configurations. |
DG Wingman |
DG Wingman is a free community Windows tool designed to aid in the collection of forensic evidence in order to properly investigate and scope an intrusion. |
draios/sysdig |
Linux system exploration and troubleshooting tool with first class support for containers |
fireeye/ARDvark |
ARDvark parses the Apple Remote Desktop (ARD) files to pull out application usage, user activity, and filesystem listings. |
ForensicArtifacts/artifacts |
Digital Forensics Artifact Repository |
gleeda/memtriage |
Allows you to quickly query a Windows machine for RAM artifacts |
google/docker-explorer |
A tool to help forensicate offline docker acquisitions |
google/GiftStick |
1-Click push forensics evidence to the cloud |
google/grr |
GRR is a python client (agent) that is installed on target systems, and python server infrastructure that can manage and talk to clients. |
google/rekall |
The Rekall Framework is a completely open collection of tools, implemented in Python under the Apache and GNU General Public License, for the extraction and analysis of digital artifacts computer systems. |
Graylog |
Built to open standards, Graylog’s connectivity and interoperability seamlessly collects, enhances, stores, and analyzes log data. |
Kaspersky IR's Artifacts Collector |
Kaspersky IR's Artifacts Collector |
Hibernation Recon |
The tools and techniques used for many years to analyze Microsoft Windows® hibernation files have left digital forensics experts in the dark… until now! |
Invoke-IR/ACE |
The Automated Collection and Enrichment (ACE) platform is a suite of tools for threat hunters to collect data from many endpoints in a network and automatically enrich the data. The data is collected by running scripts on each computer without installing any software on the target. ACE supports collecting from Windows, macOS, and Linux hosts. |
JPCERTCC/LogonTracer |
Investigate malicious Windows logon by visualizing and analyzing Windows event log |
JPCERTCC/SysmonSearch |
Investigate suspicious activity by visualizing Sysmon's event log |
IllusiveNetworks-Labs/HistoricProcessTree |
An Incident Response tool that visualizes historic process execution evidence (based on Event ID 4688 - Process Creation Event) in a tree view. |
intezer/linux-explorer |
Easy-to-use live forensics toolbox for Linux endpoints |
Invoke-IR/PowerForensics |
PowerForensics provides an all in one platform for live disk forensic analysis |
Live Response Collection - Cedarpelta |
Live Response Collection - Cedarpelta |
Log Parser |
Log Parser 2.2 is a powerful, versatile tool that provides universal query access to text-based data such as log files, XML files and CSV files, as well as key data sources on the Windows operating system such as the Event Log, the Registry, the file system, and Active Directory |
log2timeline/plaso |
log2timeline is a tool designed to extract timestamps from various files found on a typical computer system(s) and aggregate them. |
MAGNET App Simulator |
MAGNET App Simulator lets you load application data from Android devices in your case into a virtual environment, enabling you to view and interact with the data as the user would have seen it on their own device. |
MalwareSoup/MitreAttack |
Python wrapper for the Mitre ATT&CK framework API |
mozilla/mig |
Distributed & real time digital forensics at the speed of the cloud |
mozilla/MozDef |
MozDef: The Mozilla Defense Platform |
nannib/Imm2Virtual |
This is a GUI (for Windows 64 bit) for a procedure to virtualize your EWF(E01), DD(Raw), AFF disk image file without converting it, directly with VirtualBox, forensically proof. |
nshalabi/SysmonTools |
Utilities for Sysmon (Sysmon View and Sysmon Shell) |
NXLog |
The modern open source log collector. |
omenscan/achoir |
Windows Live Artifacts Acquisition Script |
orlikoski/CyLR |
CyLR - Live Response Collection Tool |
OSSEC |
Open Source HIDS SECurity |
ptresearch/AttackDetection |
The Attack Detection Team searches for new vulnerabilities and 0-days, reproduces it and creates PoC exploits to understand how these security flaws work and how related attacks can be detected on the network layer. Additionally, we are interested in malware and hackers’ TTPs, so we develop Suricata rules for detecting all sorts of such activities. |
PUNCH-Cyber/stoq |
An open source framework for enterprise level automated analysis. |
ROCK NSM |
Response Operation Collection Kit - An open source Network Security Monitoring platform. |
salesforce/bro-sysmon |
Bro-Sysmon enables Bro to receive Windows Event Logs. This provide a method to associate Network Monitoring and Host Monitoring. The work was spurred by the need to associate JA3 and HASSH fingerprints with the application on the host. The example below shows the hostname, Process ID, connection information, JA3 fingerprints, Application Path, and binary hashes. |
sans-blue-team/DeepBlueCLI |
DeepBlueCLI - a PowerShell Module for Threat Hunting via Windows Event Logs |
Security Onion |
Peel back the layers of your enterprise |
SecurityRiskAdvisors/TALR |
Threat Alert Logic Repository (TALR) - A public repository for the collection and sharing of detection rules in platform agnostic formats. Collected rules are appended with STIX required fields for simplified sharing over TAXII servers. |
SekoiaLab/fastir_artifacts |
Live forensic artifacts collector |
SekoiaLab/Fastir_Collector |
This tool collects different artefacts on live Windows and records the results in csv or json files. With the analyses of these artefacts, an early compromission can be detected. |
SIEMonster |
SIEMonster is an Affordable Security Monitoring Software Soulution |
philhagen/sof-elk |
Configuration files for the SOF-ELK VM, used in SANS FOR572 |
s0md3v/Orbit |
Blockchain Transactions Investigation Tool |
refractionPOINT/limacharlie |
LC is an Open Source, cross-platform (Windows, MacOS, Linux ++), realtime Endpoint Detection and Response sensor. The extra-light sensor, once installed on a system provides Flight Data Recorder type information (telemetry on all aspects of the system like processes, DNS, network IO, file IO etc). |
The Sleuth Kit |
sleuthkit.org is the official website for The Sleuth Kit®, Autopsy®, and other open source digital investigation tools. From here, you can find documents, case studies, and download the latest versions of the software. |
THIBER-ORG/userline |
Query and report user logons relations from MS Windows Security Events |
ufrisk/LeechCore |
LeechCore - Physical Memory Acquisition Library & The LeechAgent Remote Memory Acquisition Agent |
Uncoder.io |
Uncoder.IO is the online translator for SIEM saved searches, filters, queries, API requests, correlation and Sigma rules to help SOC Analysts, Threat Hunters and SIEM Engineers |
USN Analytics |
USN Analytics is a tool that specializes in USN Journal ($UsnJrnl:$J) analysis |
VSCMount |
Volume shadow copies mounter tool |
Wazuh |
Open Source Host and Endpoint Security |
williballenthin/EVTXtract |
EVTXtract recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images. |
williballenthin/INDXParse |
Tool suite for inspecting NTFS artifacts |
williballenthin/process-forest |
process-forest is a tool that processes Microsoft Windows EVTX event logs that contain process accounting events and reconstructs the historical process heirarchies. |
yampelo/beagle |
Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs. |
## Exploits
## Hardening
Link |
Description |
activecm/rita |
Real Intelligence Threat Analytics |
adamkramer/rapid_env |
Rapid deployment of Windows environment (files, registry keys, mutex etc) to facilitate malware analysis |
advanced-threat-research/IOCs |
Repository containing IOCs, MISP and Expert rules from our blogs |
alexandreborges/malwoverview |
Malwoverview.py is a simple tool to perform an initial and quick triage on either a directory containing malware samples or a specific malware sample |
APT Groups, Operations and Malware Search Engine |
APT Groups, Operations and Malware Search Engine |
ashishb/android-malware |
Collection of android malware samples |
AVCaesar |
AVCaesar is a malware analysis engine and repository |
blackorbird/APT_REPORT |
Interesting apt report collection and some special ioc express |
CapacitorSet/box-js |
A tool for studying JavaScript malware |
CAPE Sandbox |
Malware Configuration And Payload Extraction |
Contagio |
Malwarre dump |
Cryptam Document Scanner |
Encrypted/obfuscated malicious document analyzer |
cmu-sei/cyobstract |
A tool to extract structured cyber information from incident reports. |
CRXcavator |
CRXcavator automatically scans the entire Chrome Web Store every 3 hours and produces a quantified risk score for each Chrome Extension based on several factors. |
DAS MALWERK |
DAS MALWERK - your one stop shop for fresh malware samples |
DoctorWebLtd/malware-iocs |
This repository contains Indicators of Compromise (IOCs) related to our investigations. |
droidefense/engine |
Droidefense: Advance Android Malware Analysis Framework |
ecstatic-nobel/Analyst-Arsenal |
Phishing kits hunting |
eset/malware-ioc |
Indicators of Compromises (IOC) of our various investigations |
FAME |
FAME Automates Malware Evaluation |
fireeye/flashmingo |
Automatic analysis of SWF files based on some heuristics. Extensible via plugins. |
fireeye/iocs |
FireEye Publicly Shared Indicators of Compromise (IOCs) |
felixweyne/imaginaryC2 |
Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures HTTP requests towards selectively chosen domains/IPs. Additionally, the tool aims to make it easy to replay captured Command-and-Control responses/served payloads. |
FortyNorthSecurity/WMImplant |
This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is translated into a WMI-equivalent for use on a network/remote machine. WMImplant is WMI based. |
gen0cide/gscript |
Framework to rapidly implement custom droppers for all three major operating systems |
glmcdona/Process-Dump |
Windows tool for dumping malware PE files from memory back to disk for analysis. |
google/vxsig |
Automatically generate AV byte signatures from sets of similar binaries. |
GoSecure/malboxes |
Builds malware analysis Windows VMs so that you don't have to. |
GreatSCT/GreatSCT |
The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team |
Halo TI Center Beta |
IoT threat intelligence |
hasherezade/libpeconv/runpe |
RunPE (aka Process Hollowing) is a well known technique allowing to injecting a new PE into a remote processes, imprersonating this process. The given implementation works for PE 32bit as well as 64bit. |
hasherezade/pe-sieve |
Scans a given process, searching for the modules containing in-memory code modifications. When found, it dumps the modified PE. |
hegusung/AVSignSeek |
Tool written in python3 to determine where the AV signature is located in a binary/payload |
hlldz/SpookFlare |
Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures. |
Hybrid-Analysis |
Free Automated Malware Analysis Service |
InQuest/ThreatIngestor |
An extendable tool to extract and aggregate IOCs from threat feeds. |
IRIS-H |
IRIS-H is an online digital forensics tool that performs automated static analysis of files stored in a directory-based or strictly structured formats. |
jgamblin/Mirai-Source-Code |
Leaked Mirai Source Code for Research/IoC Development Purposes. |
jgamblin/JPCERTCC/MalConfScan |
Volatility plugin for extracts configuration data of known malware |
KasperskyLab/klara |
Klara project is aimed at helping Threat Intelligence researechers hunt for new malware using Yara. |
katjahahn/PortEx |
Java library to analyse Portable Executable files with a special focus on malware analysis and PE malformation robustness |
Koodous |
Koodous is a collaborative platform that combines the power of online analysis tools with social interactions between the analysts over a vast APKs repository. |
LordNoteworthy/al-khaser |
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection. |
Mac Malware |
Mac Malware by Objective-See |
Malc0de database |
Malc0de database |
maliceio/malice |
Malice's mission is to be a free open source version of VirusTotal that anyone can use at any scale from an independent researcher to a fortune 500 company. |
Malpedia |
The primary goal of Malpedia is to provide a resource for rapid identification and actionable context when investigating malware. Openness to curated contributions shall ensure an accountable level of quality in order to foster meaningful and reproducible research. |
MalShare |
A free Malware repository providing researchers access to samples, malicous feeds, and Yara results |
malware.one |
malware.one is a binary substring searchable malware catalog containing terabytes of malicious code |
MalwareCantFly/Vba2Graph |
Vba2Graph - Generate call graphs from VBA code, for easier analysis of malicious documents. |
malwaredllc/byob |
BYOB (Build Your Own Botnet) |
malwareinfosec/EKFiddle |
A framework based on the Fiddler web debugger to study Exploit Kits, malvertising and malicious traffic in general. |
Malwaretiverse |
maltiverse - Connect the dots - The definitive IoC search engine |
Malwares |
Malware SRC Database |
Malware Static Analysis |
The following interface stands in front of a live engine which takes binary files and runs them against a pletora of hundreds YARA rules. |
100 recent OSX/iOS/Mac malware samples |
This is a partial list of mac malware samples. |
MinervaLabsResearch/Mystique |
Mystique may be used to discover infection markers that can be used to vaccinate endpoints against malware. It receives as input a malicious sample and automatically generates a list of mutexes that could be used to as "vaccines" against the sample |
nbeede/BoomBox |
Automatic deployment of Cuckoo Sandbox malware lab using Packer and Vagrant |
nbulischeck/tyton |
Linux Kernel-Mode Rootkit Hunter for 4.4.0-31+ |
Neo23x0/APTSimulator |
A toolset to make a system look as if it was the victim of an APT attack |
Neo23x0/exotron |
Sandbox feature upgrade with the help of wrapped samples |
nsmfoo/antivmdetection |
Script to create templates to use with VirtualBox to make vm detection harder |
ntddk/virustream |
A script to track malware IOCs with OSINT on Twitter. |
OALabs/BlobRunner |
Quickly debug shellcode extracted during malware analysis |
OALabs/PyIATRebuild |
Automatically rebuild Import Address Table for dumped PE file. With python bindings! |
ohjeongwook/PowerShellRunBox |
Dynamic PowerShell analysis framework |
outflanknl/EvilClippy |
A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows. |
P4T12ICK/ypsilon |
Ypsilon is an Automated Security Use Case Testing Environment using real malware to test SIEM use cases in an closed environment. Different tools such as Ansible, Cuckoo, VirtualBox, Splunk and ELK are combined to determine the quality of a SIEM use case by testing any number of malware against a SIEM use case. Finally, a test report is generated giving insight to the quality of an use case. |
pan-unit42/iocs |
Indicators from Unit 42 Public Reports |
phage-nz/ph0neutria |
ph0neutria is a malware zoo builder that sources samples straight from the wild. Everything is stored in Viper for ease of access and manageability. |
python-iocextract |
Advanced Indicator of Compromise (IOC) extractor |
quasar/QuasarRAT |
Quasar is a fast and light-weight remote administration tool coded in C#. Providing high stability and an easy-to-use user interface, Quasar is the perfect remote administration solution for you. |
rastrea2r/rastrea2r |
Collecting & Hunting for IOCs with gusto and style |
SafeBreach-Labs/mkmalwarefrom |
Proof-of-concept two-stage dropper generator that uses bits from external sources |
SEKOIA Dropper Analysis |
SEKOIA Dropper Analysis |
SpiderLabs/IOCs-IDPS |
This repository will hold PCAP IOC data related with known malware samples (owner: Bryant Smith) |
t4d/PhishingKitHunter |
Find phishing kits which use your brand/organization's files and image. |
tomchop/malcom |
Malcom - Malware Communications Analyzer |
UNIT 42: Playbook Viewver |
Viewing PAN Unit 42's adversary playbook via web interface |
ytisf/theZoo |
A repository of LIVE malwares for your own joy and pleasure |
VirusBay |
VirusBay is a web-based, collaboration platform that connects security operations center (SOC) professionals with relevant malware researchers |
VirusShare |
VirusShare.com is a repository of malware samples to provide security researchers, incident responders, forensic analysts, and the morbidly curious access to samples of live malicious code |
VX Vault |
VX Vault |
zerosum0x0/smbdoor |
kernel backdoor via registering a malicious SMB handler |
## Mobile Security
Link |
Description |
ac-pm/Inspeckage |
Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module) |
AIR GO |
AIR GO detects obfuscation, vulnerabilities, open-source license issues, and malware by analyzing mobile apps and websites. It uses industry-leading technology to detect security threats and provide an improvement plan. |
apkdetect |
Android malware analysis and classification platform |
Apktool |
A tool for reverse engineering Android apk files |
chaitin/passionfruit |
Simple iOS app blackbox assessment tool. Powered by frida.re and vuejs. |
dpnishant/appmon |
AppMon is an automated framework for monitoring and tampering system API calls of native macOS, iOS and android apps. It is based on Frida. |
Cycript |
Cycript allows developers to explore and modify running applications on either iOS or Mac OS X using a hybrid of Objective-C++ and JavaScript syntax through an interactive console that features syntax highlighting and tab completion |
dmayer/idb |
idb is a tool to simplify some common tasks for iOS pentesting and research |
Drozer |
Comprehensive security and attack framework for Android |
frida/frida |
Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers. |
iSECPartners/Android-SSL-TrustKiller |
Bypass SSL certificate pinning for most applications |
KJCracks/Clutch |
Fast iOS executable dumper |
linkedin/qark |
Tool to look for several security related Android application vulnerabilities |
MobSF/Mobile-Security-Framework-MobSF |
Mobile Security Framework is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing framework capable of performing static analysis, dynamic analysis, malware analysis and web API testing |
mwrlabs/needle |
The iOS Security Testing Framework |
nccgroup/house |
A runtime mobile application analysis toolkit with a Web GUI, powered by Frida, written in Python. |
nygard/class-dump |
Generate Objective-C headers from Mach-O files |
pxb1988/dex2jar |
Tools to work with android .dex and java .class files |
sensepost/objection |
objection is a runtime mobile exploration toolkit, powered by Frida. It was built with the aim of helping assess mobile applications and their security posture without the need for a jailbroken or rooted mobile device. |
skylot/jadx |
Dex to Java decompiler |
stefanesser/dumpdecrypted |
Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. This tool is necessary for security researchers to be able to look under the hood of encryption. |
swdunlop/AndBug |
Android Debugging Library |
tcurdt/iProxy |
Let's you connect your laptop to the iPhone to surf the web. |
## Network Security
0xbadjuju/Tokenvator |
A tool to elevate privilege with Windows Tokens |
411Hall/JAWS |
JAWS is PowerShell script designed to help penetration testers (and CTFers) quickly identify potential privilege escalation vectors on Windows systems. It is written using PowerShell 2.0 so 'should' run on every Windows version since Windows 7. |
api0cradle/LOLBAS |
Living Off The Land Binaries and Scripts (and now also Libraries) |
api0cradle/UltimateAppLockerByPassList |
The goal of this repository is to document the most common techniques to bypass AppLocker. |
Arvanaghi/SessionGopher |
SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally. |
cobbr/Covenant |
Covenant is a .NET command and control framework that aims to highlight the attack surface of .NET, make the use of offensive .NET tradecraft easier, and serve as a collaborative command and control platform for red teamers. |
Cn33liz/p0wnedShell |
p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET) |
Cybellum/DoubleAgent |
DoubleAgent is a new Zero-Day technique for injecting code and maintaining persistence on a machine (i.e. auto-run). |
danielbohannon/Invoke-DOSfuscation |
Cmd.exe Command Obfuscation Generator & Detection Test Harness |
danielbohannon/Invoke-Obfuscation |
Invoke-Obfuscation is a PowerShell v2.0+ compatible PowerShell command and script obfuscator |
DanMcInerney/icebreaker |
Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment |
eladshamir/Internal-Monologue |
Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS |
fbkcs/ThunderDNS |
This tool can forward TCP traffic over DNS protocol. Non-compile clients + socks5 support. |
fireeye/SharPersist |
Windows persistence toolkit written in C#. |
FuzzySecurity/PowerShell-Suite |
There are great tools and resources online to accomplish most any task in PowerShell, sometimes however, there is a need to script together a util for a specific purpose or to bridge an ontological gap. This is a collection of PowerShell utilities I put together either for fun or because I had a narrow application in mind. |
FuzzySecurity/Sharp-Suite |
My musings with C# |
GhostPack/Seatbelt |
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives. |
google/sandbox-attacksurface-analysis-tools |
This is a small suite of tools to test various properties of sandboxes on Windows. Many of the checking tools take a -p flag which is used to specify the PID of a sandboxed process. The tool will impersonate the token of that process and determine what access is allowed from that location. Also it's recommended to run these tools as an administrator or local system to ensure the system can be appropriately enumerated. |
hlldz/Invoke-Phant0m |
Windows Event Log Killer |
huntresslabs/evading-autoruns |
Slides and reference material from Evading Autoruns presentation at DerbyCon 7 (September 2017) |
JohnLaTwC/PyPowerShellXray |
Python script to decode common encoded PowerShell scripts |
jonatan1024/clrinject |
Injects C# EXE or DLL Assembly into every CLR runtime and AppDomain of another process. |
Kevin-Robertson/Inveigh |
Windows PowerShell ADIDNS/LLMNR/mDNS/NBNS spoofer/man-in-the-middle tool |
mattifestation/PoCSubjectInterfacePackage |
A PoC subject interface package (SIP) provider designed to educate about the required components of a SIP provider. |
OmerYa/Invisi-Shell |
Hide your Powershell script in plain sight. Bypass all Powershell security features |
putterpanda/mimikittenz |
A post-exploitation powershell tool for extracting juicy info from memory. |
mdsecactivebreach/SharpShooter |
SharpShooter is a payload creation framework for the retrieval and execution of arbitrary CSharp source code. |
monoxgas/sRDI |
Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode |
nccgroup/demiguise |
HTA encryption tool for RedTeams |
NetSPI/goddi |
goddi (go dump domain info) dumps Active Directory domain information |
peewpw/Invoke-PSImage |
Embeds a PowerShell script in the pixels of a PNG file and generates a oneliner to execute |
peewpw/Invoke-WCMDump |
PowerShell Script to Dump Windows Credentials from the Credential Manager |
Plazmaz/LNKUp |
Generates malicious LNK file payloads for data exfiltration |
secretsquirrel/SigThief |
Stealing Signatures and Making One Invalid Signature at a Time |
sensepost/goDoH |
godoh - A DNS-over-HTTPS C2 |
sevagas/macro_pack |
macro_pack is a tool used to automatize obfuscation and generation of MS Office documents for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify antimalware bypass and automatize the process from vba generation to final Office document generation. |
shellster/DCSYNCMonitor |
Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events. |
stephenfewer/ReflectiveDLLInjection |
Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process |
sud0woodo/DCOMrade |
Powershell script for enumerating vulnerable DCOM Applications |
TheSecondSun/Bashark |
Bash post exploitation toolkit |
trustedsec/unicorn |
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18. |
## Social Engineering
Link |
Description |
boxug/trape |
People tracker on the Internet: Learn to track the world, to avoid being traced. |
dafthack/MailSniper |
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain. |
drk1wi/Modlishka |
Modlishka. Reverse Proxy. Phishing NG. |
certsocietegenerale/swordphish-awareness |
Swordphish is a plateform allowing to create and manage fake phishing campaigns. |
Simple Email Reputation |
Illuminate the "reputation" behind an email address |
fireeye/ReelPhish |
ReelPhish: A Real-Time Two-Factor Phishing Tool |
gophish/gophish |
Gophish is an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training |
kgretzky/evilginx2 |
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication |
Mailsploit |
TL;DR: Mailsploit is a collection of bugs in email clients that allow effective sender spoofing and code injection attacks. The spoofing is not detected by Mail Transfer Agents (MTA) aka email servers, therefore circumventing spoofing protection mechanisms such as DMARC (DKIM/SPF) or spam filters. |
mdsecactivebreach/o365-attack-toolkit |
o365-attack-toolkit allows operators to perform an OAuth phishing attack and later on use the Microsoft Graph API to extract interesting information. |
muraenateam/muraena |
Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities. |
Phishing Frenzy |
Phishing Frenzy is an Open Source Ruby on Rails application that is leveraged by penetration testers to manage email phishing campaigns |
ring0lab/catphish |
Generate similar-looking domains for phishing attacks. Check expired domains and their categorized domain status to evade proxy categorization. Whitelisted domains are perfect for your C2 servers. |
securestate/king-phisher |
Phishing Campaign Toolkit |
thelinuxchoice/blackeye |
The most complete Phishing Tool, with 32 templates +1 customizable |
thelinuxchoice/shellphish |
Phishing Tool for 18 social media: Instagram, Facebook, Snapchat, Github, Twitter, Yahoo, Protonmail, Spotify, Netflix, Linkedin, Wordpress, Origin, Steam, Microsoft, InstaFollowers, Gitlab, Pinterest |
Undeadsec/EvilURL |
An unicode domain phishing generator for IDN Homograph Attack |
UndeadSec/SocialFish |
Ultimate phishing tool. Socialize with the credentials |
ustayready/CredSniper |
CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens. |
## Vulnerable
Link |
Description |
aboul3la/Sublist3r |
Fast subdomains enumeration tool for penetration testers |
ambionics/phpggc |
PHPGGC is a library of unserialize() payloads along with a tool to generate them, from command line or programmatically. |
appsecco/spaces-finder |
A tool to hunt for publicly accessible DigitalOcean Spaces |
anatshri/svn-extractor |
Simple script to extract all web resources by means of .SVN folder exposed over network. |
brannondorsey/dns-rebind-toolkit |
A front-end JavaScript toolkit for creating DNS rebinding attacks. |
IlluminateJs |
IlluminateJs is a static javascript analysis engine (a deobfuscator so to say) aimed to help analyst understand obfuscated and potentially malicious JavaScript Code. |
ismailtasdelen/xss-payload-list |
Cross Site Scripting ( XSS ) Vulnerability Payload List |
jonluca/Anubis |
Subdomain enumeration and information gathering tool |
mazen160/bfac |
BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source code. |
mindedsecurity/JStillery |
Advanced JS Deobfuscation via Partial Evaluation. |
mwrlabs/dref |
DNS Rebinding Exploitation Framework |
NetSPI/PowerUpSQL |
PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server |
nccgroup/singularity |
A DNS rebinding attack framework |
OWASP Zed Attack Proxy Project |
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers*. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing |
Public WWW |
Source Code Search Engine |
pwntester/ysoserial.net |
Deserialization payload generator for a variety of .NET formatters |
RhinoSecurityLabs/IPRotate_Burp_Extension |
Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request. |
RhinoSecurityLabs/SleuthQL |
Python3 Burp History parsing tool to discover potential SQL injection points. To be used in tandem with SQLmap. |
Snyk |
Continuously find & fix vulnerabilities in your dependencies |
s0md3v/XSStrike |
Most advanced XSS detection suite |
subfinder/subfinder |
SubFinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. |