Terraform-deployed red team operator lab on AWS: Mythic, Sliver, and Adaptix C2 behind a production-style Apache redirector, with Kali/Windows hosts and a Guacamole portal. Built for authorized training and self-hosted cyber ranges.
☆278Jul 19, 2026Updated 3 weeks ago
Alternatives and similar repositories for redStack
Users that are interested in redStack are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution☆163Jul 15, 2026Updated last month
- Tyche is a Mythic HTTPX Profile Generator used to create Malleable C2 Profiles.☆47Mar 28, 2026Updated 4 months ago
- A modern alternative Web-UI for the Mythic Command and Control Server☆81Jul 3, 2026Updated last month
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆312Aug 6, 2026Updated last week
- Lnk crafting and research tools☆186Mar 4, 2026Updated 5 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Active Directory information dumper via ADWS for evasion purposes.☆318Jul 9, 2026Updated last month
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆135Mar 27, 2026Updated 4 months ago
- A Cobalt Strike RL built with Crystal Palac; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and stati…☆234Mar 15, 2026Updated 5 months ago
- PowerShell implementation for AD CS☆159Jul 30, 2026Updated 2 weeks ago
- Python tool to automatically perform SPN-less RBCD attacks.☆132Jan 7, 2026Updated 7 months ago
- Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal …☆102Jan 2, 2026Updated 7 months ago
- A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, wit…☆297Feb 21, 2026Updated 5 months ago
- Erebus is an Initial Access wrapper for the Mythic Command & Control Server. It converts shellcode into payloads specifically used for ph…☆149Jul 7, 2026Updated last month
- Windows protocol library, including SMB and RPC implementations, among others.☆824Aug 5, 2026Updated last week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Cobalt Strike UDC2 implementation that provides an Slack C2 channel☆69Jan 5, 2026Updated 7 months ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆511Mar 15, 2026Updated 5 months ago
- Async BOF to automatically extract or renew Kerberos TGTs on a target system.☆134Jul 23, 2026Updated 3 weeks ago
- Automated Pass-the-Ticket (PtT) attack. Standalone alternative to Rubeus and Mimikatz for this attack. Implemented in C#, C++, Crystal, P…☆154Feb 17, 2026Updated 5 months ago
- Lightweight binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy. Designed for red team operations and ephe…☆570Oct 3, 2025Updated 10 months ago
- MDE/MDI Defender setup for Ludus☆62Jul 30, 2026Updated 2 weeks ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆183May 31, 2026Updated 2 months ago
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆418Updated this week
- AdaptixC2 default beacon agent extended to support Crystal Palace loaders.☆63May 4, 2026Updated 3 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Evasion kit for Cobalt Strike☆486Jun 5, 2026Updated 2 months ago
- ☆194Oct 21, 2025Updated 9 months ago
- Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original GodPotato PoC by …☆277Apr 16, 2026Updated 3 months ago
- A Beacon Object File (BOF) that performs the complete ESC1 attack chain in a single execution: certificate request with arbitrary SAN (+S…☆119Dec 21, 2025Updated 7 months ago
- Modify machine code in binaries with alternative x64 assembly opcodes for AV evasion☆232Jul 7, 2026Updated last month
- Monitor the Windows Event Log with grep-like features or filtering for specific Event IDs☆139Mar 26, 2026Updated 4 months ago
- Repository hosting a hypothetical EDR Spoofer, as discovered originally by Nightmare-Eclipse☆41May 27, 2026Updated 2 months ago
- ProfileHound - BloodHound OpenGraph collector for user profiles stored on domain machines. Make informed decisions about looting secrets …☆163Jul 8, 2026Updated last month
- Beacon Object Files (BOFs) for Cobalt Strike and Havoc C2. Implementations of Active Directory attacks and post-exploitation techniques.☆118Jan 26, 2026Updated 6 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself☆101Apr 9, 2026Updated 4 months ago
- Shellcode injection using the Windows Debugging API☆183Jan 4, 2026Updated 7 months ago
- Rusty Armory - Beacon Object Files (BOFs) in Rust (Codename: Armory)☆74Apr 3, 2026Updated 4 months ago
- A Bloodhound alternative. BloodBash will ingest the same files bloodhound does but no server is required to use this tool. It's great for…☆365Updated this week
- A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single depe…☆705Jul 21, 2026Updated 3 weeks ago
- Nim implementation for sud0Ru's Credential Dumping from SAM/SECURITY Hives Method (a.k.a. SilentHarvest)☆106Apr 4, 2026Updated 4 months ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 3 months ago