🚨 Sua empresa pode estar PERDENDO dinheiro AGORA e você nem percebeu. Fraudes internas, vazamentos e funcionários desleais destroem operações silenciosamente. Quando o problema aparece… o prejuízo já aconteceu. ⚠️ Verificação de Insiders ⚠️ Gerenciamento de Risco ⚠️ Inteligência Corporativa ⚠️ Compliance Investigativo Proteja sua empresa antes que seja tarde. 📲 WhatsApp: 47 89961-8255 🌐 osintbrasil.blogspot.com #Compliance #FraudeInterna #GestaoDeRisco #OSINT #InteligenciaCorporativa
Gerar link
Facebook
X
Pinterest
E-mail
Outros aplicativos
Red Teaming/Adversary Simulation Toolkit
A collection of open source and commercial tools that aid in red team operations. This repository will help you during red team engagement. If you want to contribute to this list send me a pull request.
EyeWitnessis designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.https://github.com/ChrisTruncer/EyeWitness
spoofchecka program that checks if a domain can be spoofed from. The program checks SPF and DMARC records for weak configurations that allow spoofing.https://github.com/BishopFox/spoofcheck
Nmapis used to discover hosts and services on a computer network, thus building a "map" of the network.https://github.com/nmap/nmap
Social MapperOSINT Social Media Mapping Tool, takes a list of names & images (or LinkedIn company name) and performs automated target searching on a huge scale across multiple social media sites. Not restricted by APIs as it instruments a browser using Selenium. Outputs reports to aid in correlating targets across sites.https://github.com/SpiderLabs/social_mapper
skiptracerOSINT scraping framework, utilizes some basic python webscraping (BeautifulSoup) of PII paywall sites to compile passive information on a target on a ramen noodle budget.https://github.com/xillwillx/skiptracer
FOCA(Fingerprinting Organizations with Collected Archives) is a tool used mainly to find metadata and hidden information in the documents its scans.https://github.com/ElevenPaths/FOCA
theHarvesteris a tool for gathering subdomain names, e-mail addresses, virtual hosts, open ports/ banners, and employee names from different public sources.https://github.com/laramies/theHarvester
Metagoofilis a tool for extracting metadata of public documents (pdf,doc,xls,ppt,etc) availables in the target websites.https://github.com/laramies/metagoofil
Just-Metadatais a tool that gathers and analyzes metadata about IP addresses. It attempts to find relationships between systems within a large dataset.https://github.com/ChrisTruncer/Just-Metadata
pwnedOrNotis a python script which checks if the email account has been compromised in a data breach, if the email account is compromised it proceeds to find passwords for the compromised account.https://github.com/thewhiteh4t/pwnedOrNot
CrossLinkedLinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping.https://github.com/m8r0wn/CrossLinked
Maltegois a unique platform developed to deliver a clear threat picture to the environment that an organization owns and operates.https://www.paterva.com/web7/downloads.php
datasploitis an OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and give data in multiple formats.https://github.com/DataSploit/datasploit
Exploit toolkit CVE-2017-8759is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft .NET Framework RCE.https://github.com/bhdresh/CVE-2017-8759
Exploit toolkit CVE-2017-0199is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Office RCE.https://github.com/bhdresh/CVE-2017-0199
Don't kill my catis a tool that generates obfuscated shellcode that is stored inside of polyglot images. The image is 100% valid and also 100% valid shellcode.https://github.com/Mr-Un1k0d3r/DKMC
LuckyStrikea PowerShell based utility for the creation of malicious Office macro documents. To be used for pentesting or educational purposes only.https://github.com/curi0usJack/luckystrike
ClickOnceGeneratorQuick Malicious ClickOnceGenerator for Red Team. The default application a simple WebBrowser widget that point to a website of your choice.https://github.com/Mr-Un1k0d3r/ClickOnceGenerator
macro_packis a tool by @EmericNasi used to automatize obfuscation and generation of MS Office documents, VB scripts, and other formats for pentest, demo, and social engineering assessments.https://github.com/sevagas/macro_pack
nps_payloadthis script will generate payloads for basic intrusion detection avoidance. It utilizes publicly demonstrated techniques from several different sources.https://github.com/trustedsec/nps_payload
Phisheryis a Simple SSL Enabled HTTP server with the primary purpose of phishing credentials via Basic Authentication.https://github.com/ryhanson/phishery
Ruleris a tool that allows you to interact with Exchange servers remotely, through either the MAPI/HTTP or RPC/HTTP protocol.https://github.com/sensepost/ruler
Generate-Macrois a standalone PowerShell script that will generate a malicious Microsoft Office document with a specified payload and persistence method.https://github.com/enigma0x3/Generate-Macro
Meta Twinis designed as a file resource cloner. Metadata, including digital signature, is extracted from one file and injected into another.https://github.com/threatexpress/metatwin
WePWNisegenerates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and exploit mitigation software.https://github.com/mwrlabs/wePWNise
Reflective DLL injectionis a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.https://github.com/stephenfewer/ReflectiveDLLInjection
SpookFlarehas a different perspective to bypass security measures and it gives you the opportunity to bypass the endpoint countermeasures at the client-side detection and network-side detection.https://github.com/hlldz/SpookFlare
GreatSCTis an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team.https://github.com/GreatSCT/GreatSCT
evil-ssdpSpoof SSDP replies to phish for NTLM hashes on a network. Creates a fake UPNP device, tricking users into visiting a malicious phishing page.https://gitlab.com/initstring/evil-ssdp
avet(AntiVirusEvasionTool) is targeting windows machines with executable files using different evasion techniques.https://github.com/govolution/avet
EvilClippyA cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows.https://github.com/outflanknl/EvilClippy
Donutis a shellcode generation tool that creates position-independant shellcode payloads from .NET Assemblies. This shellcode may be used to inject the Assembly into arbitrary Windows processes.https://github.com/TheWover/donut
FiercePhishis a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more.https://github.com/Raikia/FiercePhish
Gophishis an open-source phishing toolkit designed for businesses and penetration testers. It provides the ability to quickly and easily setup and execute phishing engagements and security awareness training.https://github.com/gophish/gophish
CredSniperis a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.https://github.com/ustayready/CredSniper
Modlishkais a flexible and powerful reverse proxy, that will take your ethical phishing campaigns to the next level.https://github.com/drk1wi/Modlishka
Evilginx2is a man-in-the-middle attack framework used for phishing credentials and session cookies of any web service.https://github.com/kgretzky/evilginx2
Watering Hole Attack
BeEFis short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser.https://github.com/beefproject/beef
Command and Control
Remote Access Tools
Cobalt Strikeis software for Adversary Simulations and Red Team Operations.https://cobaltstrike.com/
Empireis a post-exploitation framework that includes a pure-PowerShell2.0 Windows agent, and a pure Python 2.6/2.7 Linux/OS X agent.https://github.com/EmpireProject/Empire
Metasploit Frameworkis a computer security project that provides information about security vulnerabilities and aids in penetration testing and IDS signature development.https://github.com/rapid7/metasploit-framework
Pupyis an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python.https://github.com/n1nj4sec/pupy
Koadicor COM Command & Control, is a Windows post-exploitation rootkit similar to other penetration testing tools such as Meterpreter and Powershell Empire.https://github.com/zerosum0x0/koadic
PoshC2is a proxy aware C2 framework written completely in PowerShell to aid penetration testers with red teaming, post-exploitation and lateral movement.https://github.com/nettitude/PoshC2_Python
TrevorC2is a legitimate website (browsable) that tunnels client/server communications for covert command execution.https://github.com/trustedsec/trevorc2
Merlinis a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.https://github.com/Ne0nd0g/merlin
Quasaris a fast and light-weight remote administration tool coded in C#. Providing high stability and an easy-to-use user interface, Quasar is the perfect remote administration solution for you.https://github.com/quasar/QuasarRAT
Covenantis a .NET command and control framework that aims to highlight the attack surface of .NET, make the use of offensive .NET tradecraft easier, and serve as a collaborative command and control platform for red teamers.https://github.com/cobbr/Covenant
FactionC2is a C2 framework which use websockets based API that allows for interacting with agents and transports.https://github.com/FactionC2/
DNScat2is a tool is designed to create an encrypted command-and-control (C&C) channel over the DNS protocol.https://github.com/iagox86/dnscat2
Sliveris a general purpose cross-platform implant framework that supports C2 over Mutual-TLS, HTTP(S), and DNS.https://github.com/BishopFox/sliver
EggShellis a post exploitation surveillance tool written in Python. It gives you a command line session with extra functionality between you and a target machine.https://github.com/neoneggplant/EggShell
Staging
Rapid Attack Infrastructure (RAI)Red Team Infrastructure... Quick... Fast... Simplified One of the most tedious phases of a Red Team Operation is usually the infrastructure setup. This usually entails a teamserver or controller, domains, redirectors, and a Phishing server.https://github.com/obscuritylabs/RAI
Red Baronis a set of modules and custom/third-party providers for Terraform which tries to automate creating resilient, disposable, secure and agile infrastructure for Red Teams.https://github.com/byt3bl33d3r/Red-Baron
Domain Hunterchecks expired domains, bluecoat categorization, and Archive.org history to determine good candidates for phishing and C2 domain names.https://github.com/threatexpress/domainhunter
CatMyFishSearch for categorized domain that can be used during red teaming engagement. Perfect to setup whitelisted domain for your Cobalt Strike beacon C&C.https://github.com/Mr-Un1k0d3r/CatMyFish
Malleable-C2-RandomizerThis script randomizes Cobalt Strike Malleable C2 profiles through the use of a metalanguage, hopefully reducing the chances of flagging signature-based detection controls.https://github.com/bluscreenofjeff/Malleable-C2-Randomizer
Postfix-Server-SetupSetting up a phishing server is a very long and tedious process. It can take hours to setup, and can be compromised in minutes.https://github.com/n0pe-sled/Postfix-Server-Setup
ycsmis a quick script installation for resilient redirector using nginx reverse proxy and letsencrypt compatible with some popular Post-Ex Tools (Cobalt Strike, Empire, Metasploit, PoshC2).https://github.com/infosecn1nja/ycsm
meekis a blocking-resistant pluggable transport for Tor. It encodes a data stream as a sequence of HTTPS requests and responses.https://github.com/arlolra/meek
mkhtaccess_redAuto-generate an HTaccess for payload delivery -- automatically pulls ips/nets/etc from known sandbox companies/sources that have been seen before, and redirects them to a benign payload.https://github.com/violentlydave/mkhtaccess_red
RedFilea flask wsgi application that serves files with intelligence, good for serving conditional RedTeam payloads.https://github.com/outflanknl/RedFile
HTranis a connection bouncer, a kind of proxy server. A “listener” program is hacked stealthily onto an unsuspecting host anywhere on the Internet.https://github.com/HiwinCN/HTran
DeathStaris a Python script that uses Empire's RESTful API to automate gaining Domain Admin rights in Active Directory environments using a variety of techinques.https://github.com/byt3bl33d3r/DeathStar
Responderis a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.https://github.com/SpiderLabs/Responder
SessionGopheris a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally.https://github.com/fireeye/SessionGopher
PowerSploitis a collection of Microsoft PowerShell modules that can be used to aid penetration testers during all phases of an assessment.https://github.com/PowerShellMafia/PowerSploit
Nishangis a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security, penetration testing and red teaming. Nishang is useful during all phases of penetration testing.https://github.com/samratashok/nishang
MailSniperis a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.).https://github.com/dafthack/MailSniper
WMIOpsis a powershell script that uses WMI to perform a variety of actions on hosts, local or remote, within a Windows environment. It's designed primarily for use on penetration tests or red team engagements.https://github.com/ChrisTruncer/WMIOps
mimipenguina tool to dump the login password from the current linux desktop user. Adapted from the idea behind the popular Windows tool mimikatz.https://github.com/huntergregal/mimipenguin
PsExecis a light-weight telnet-replacement that lets you execute processes on other systems, complete with full interactivity for console applications, without having to manually install client software.https://docs.microsoft.com/en-us/sysinternals/downloads/psexec
KeeThiefallows for the extraction of KeePass 2.X key material from memory, as well as the backdooring and enumeration of the KeePass trigger system.https://github.com/HarmJ0y/KeeThief
PSAttackcombines some of the best projects in the infosec powershell community into a self contained custom PowerShell console.https://github.com/jaredhaight/PSAttack
Impacketis a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (for instance NMB, SMB1-3 and MS-DCERPC) the protocol implementation itself.https://github.com/CoreSecurity/impacket
Living Off The Land Binaries and Scripts (and now also Libraries)The goal of these lists are to document every binary, script and library that can be used for other purposes than they are designed to.https://github.com/api0cradle/LOLBAS
Evilgradeis a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.https://github.com/infobyte/evilgrade
NetRipperis a post exploitation tool targeting Windows systems which uses API hooking in order to intercept network traffic and encryption related functions from a low privileged user, being able to capture both plain-text traffic and encrypted traffic before encryption/after decryption.https://github.com/NytroRST/NetRipper
PAExeclets you launch Windows programs on remote Windows computers without needing to install software on the remote computer first.https://www.poweradmin.com/paexec/
Establish Foothold
Tunnais a set of tools which will wrap and tunnel any TCP communication over HTTP. It can be used to bypass network restrictions in fully firewalled environments.https://github.com/SECFORCE/Tunna
reGeorgthe successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.https://github.com/sensepost/reGeorg
Bladeis a webshell connection tool based on console, currently under development and aims to be a choice of replacement of Chooper.https://github.com/wonderqs/Blade
Invoke-ACLpwnis a tool that automates the discovery and pwnage of ACLs in Active Directory that are unsafe configured.https://github.com/fox-it/Invoke-ACLPwn
ADReconis a tool which extracts various artifacts (as highlighted below) out of an AD environment in a specially formatted Microsoft Excel report that includes summary views with metrics to facilitate analysis.https://github.com/sense-of-security/ADRecon
ACLighta useful script for advanced discovery of Domain Privileged Accounts that could be targeted - including Shadow Admins.https://github.com/cyberark/ACLight
PingCastleis a free, Windows-based utility to audit the risk level of your AD infrastructure and check for vulnerable practices.https://www.pingcastle.com/download
RiskySPNsis a collection of PowerShell scripts focused on detecting and abusing accounts associated with SPNs (Service Principal Name).https://github.com/cyberark/RiskySPN
Mystiqueis a PowerShell tool to play with Kerberos S4U extensions, this module can assist blue teams to identify risky Kerberos delegation configurations as well as red teams to impersonate arbitrary users by leveraging KCD with Protocol Transition.https://github.com/machosec/Mystique
Rubeusis a C# toolset for raw Kerberos interaction and abuses. It is heavily adapted from Benjamin Delpy's Kekeo project.https://github.com/GhostPack/Rubeus
UACMeis an open source assessment tool that contains many methods for bypassing Windows User Account Control on multiple versions of the operating system.https://github.com/hfiref0x/UACME
The Elevate Kitdemonstrates how to use third-party privilege escalation attacks with Cobalt Strike's Beacon payload.https://github.com/rsmudge/ElevateKit
CloakifyFactory& the Cloakify Toolset - Data Exfiltration & Infiltration In Plain Sight; Evade DLP/MLS Devices; Social Engineering of Analysts; Defeat Data Whitelisting Controls; Evade AV Detection.https://github.com/TryCatchHCF/Cloakify
DET(is provided AS IS), is a proof of concept to perform Data Exfiltration using either single or multiple channel(s) at the same time.https://github.com/sensepost/DET
DNSExfiltratorallows for transfering (exfiltrate) a file over a DNS request covert channel. This is basically a data leak testing tool allowing to exfiltrate data over a covert channel.https://github.com/Arno0x/DNSExfiltrator
MITRE CALDERA- An automated adversary emulation system that performs post-compromise adversarial behavior within Windows Enterprise networks.https://github.com/mitre/caldera
Network Flight Simulator- flightsim is a lightweight utility used to generate malicious network traffic and help security teams to evaluate security controls and network visibility.https://github.com/alphasoc/flightsim
Red Team Automation (RTA)- RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK.https://github.com/endgameinc/RTA
Wireless Networks
Wifiphisheris a security tool that performs Wi-Fi automatic association attacks to force wireless clients to unknowingly connect to an attacker-controlled Access Point.https://github.com/wifiphisher/wifiphisher
magspoofa portable device that can spoof/emulate any magnetic stripe, credit card or hotel card "wirelessly", even on standard magstripe (non-NFC/RFID) readers.https://github.com/samyk/magspoof
WarBerryPiwas built to be used as a hardware implant during red teaming scenarios where we want to obtain as much information as possible in a short period of time with being as stealth as possible.https://github.com/secgroundzero/warberry
P4wnP1is a highly customizable USB attack platform, based on a low cost Raspberry Pi Zero or Raspberry Pi Zero W (required for HID backdoor).https://github.com/mame82/P4wnP1
Fenriris a tool designed to be used "out-of-the-box" for penetration tests and offensive engagements. Its main feature and purpose is to bypass wired 802.1x protection and to give you an access to the target network.https://github.com/Orange-Cyberdefense/fenrir-ocd
poisontapexploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js.https://github.com/samyk/poisontap
PhanTapis an ‘invisible’ network tap aimed at red teams. With limited physical access to a target building, this tap can be installed inline between a network device and the corporate network.https://github.com/nccgroup/phantap
Software For Team Communication
RocketChatis free, unlimited and open source. Replace email & Slack with the ultimate team chat software solution.https://rocket.chat
Etherpadis an open source, web-based collaborative real-time editor, allowing authors to simultaneously edit a text documenthttps://etherpad.org/
Log Aggregation
RedELKRed Team's SIEM - easy deployable tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.https://github.com/outflanknl/RedELK/
SharpSploitis a .NET post-exploitation library written in C# that aims to highlight the attack surface of .NET and make the use of offensive .NET easier for red teamers.https://github.com/cobbr/SharpSploit
GhostPackis (currently) a collection various C# implementations of previous PowerShell functionality, and includes six separate toolsets being released today- Seatbelt, SharpUp, SharpRoast, SharpDump, SafetyKatz, and SharpWMI.https://github.com/GhostPack
SharpWeb.NET 2.0 CLR project to retrieve saved browser credentials from Google Chrome, Mozilla Firefox and Microsoft Internet Explorer/Edge.https://github.com/djhohnstein/SharpWeb
Detection LabThis lab has been designed with defenders in mind. Its primary purpose is to allow the user to quickly build a Windows domain that comes pre-loaded with security tooling and some best practices when it comes to system logging configurations.https://github.com/clong/DetectionLab
MITRE’s ATT&CK™is a curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target.https://attack.mitre.org/wiki/Main_Page
ATT&CK for Enterprise Softwareis a generic term for custom or commercial code, operating system utilities, open-source software, or other tools used to conduct behavior modeled in ATT&CK.https://attack.mitre.org/wiki/Software
Planning a Red Team exerciseThis document helps inform red team planning by contrasting against the very specific red team style described in Red Teams.https://github.com/magoo/redteam-plan
Awesome Lockpickinga curated list of awesome guides, tools, and other resources related to the security and compromise of locks, safes, and keys.https://github.com/meitar/awesome-lockpicking
APT NotesNeed some scenario? APTnotes is a repository of publicly-available papers and blogs (sorted by year) related to malicious campaigns/activity/software that have been associated with vendor-defined APT (Advanced Persistent Threat) groups and/or tool-sets.https://github.com/aptnotes/data
TIBER-EU FRAMEWORKThe European Framework for Threat Intelligence-based Ethical Red Teaming (TIBER-EU), which is the first Europe-wide framework for controlled and bespoke tests against cyber attacks in the financial market.http://www.ecb.europa.eu/pub/pdf/other/ecb.tiber_eu_framework.en.pdf
CBEST Implementation GuideCBEST is a framework to deliver controlled, bespoke, intelligence-led cyber security tests. The tests replicate behaviours of threat actors, assessed by the UK Government and commercial intelligence providers as posing a genuine threat to systemically important financial institutions.https://www.crest-approved.org/wp-content/uploads/2014/07/CBEST-Implementation-Guide.pdf
Red Team: Adversarial Attack Simulation Exercise Guidelines for the Financial Industry in SingaporeThe Association of Banks in Singapore (ABS), with support from the Monetary Authority of Singapore (MAS), has developed a set of cybersecurity assessment guidelines today to strengthen the cyber resilience of the financial sector in Singapore. Known as the Adversarial Attack Simulation Exercises (AASE) Guidelines or “Red Teaming” Guidelines, the Guidelines provide financial institutions (FIs) with best practices and guidance on planning and conducting Red Teaming exercises to enhance their security testing.https://abs.org.sg/docs/library/abs-red-team-adversarial-attack-simulation-exercises-guidelines-v1-06766a69f299c69658b7dff00006ed795.pdf
Comentários
Postar um comentário