This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2 servers, backdoors, exploitation techniques, stagers, bootloaders, and other malicious artifacts that mirror those used in real world attacks.
☆1,141Sep 21, 2026Updated this week
Alternatives and similar repositories for APTs-Adversary-Simulation
Users that are interested in APTs-Adversary-Simulation are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- BEAR-C2 is an adversary simulation and emulation framework built around real-world TTPs inspired by Russian, Chinese, North Korean, and I…☆683Updated this week
- A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive …☆1,540May 5, 2026Updated 4 months ago
- AppLocker-Based EDR Neutralization☆343Dec 19, 2025Updated 9 months ago
- This comprehensive process injection series is crafted for cybersecurity enthusiasts, researchers, and professionals who aim to stay at t…☆467Jun 10, 2026Updated 3 months ago
- ☆729Aug 20, 2026Updated last month
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- AdaptixC2 is a highly modular advanced redteam toolkit☆3,638Updated this week
- Evasion kit for Cobalt Strike☆507Jun 5, 2026Updated 3 months ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆509Mar 15, 2026Updated 6 months ago
- Lab used for workshop and CTF☆539Aug 23, 2026Updated last month
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆319Aug 31, 2026Updated 3 weeks ago
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆867May 23, 2026Updated 4 months ago
- A resource containing all the tools each ransomware gangs uses☆1,451Aug 29, 2026Updated 3 weeks ago
- Simulate the behavior of AV/EDR for malware development training.☆566Feb 15, 2024Updated 2 years ago
- Windows protocol library, including SMB and RPC implementations, among others.☆835Sep 19, 2026Updated last week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- C2 infrastructure over Microsoft Teams.☆759Jan 15, 2025Updated last year
- ↕️🤫 Stealth redirector for your red team operation security☆1,109Jul 20, 2026Updated 2 months ago
- Extract and execute a PE embedded within a PNG file using an LNK file.☆476Nov 2, 2024Updated last year
- Abusing Azure services over C2☆382Jan 20, 2026Updated 8 months ago
- A tool to transform Chromium browsers into a C2 Implant☆604Dec 17, 2025Updated 9 months ago
- A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage Power…☆820Mar 28, 2025Updated last year
- This map lists the essential techniques to bypass anti-virus and EDR☆3,470Mar 28, 2025Updated last year
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,908Nov 3, 2024Updated last year
- EDR Lab for Experimentation Purposes☆1,564Jun 10, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and co…☆836May 16, 2026Updated 4 months ago
- Mapping of open-source detection rules and atomic tests.☆215Jul 15, 2026Updated 2 months ago
- RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging☆208Mar 6, 2025Updated last year
- M365/Azure adversary simulation tool that generates realistic attack telemetry to help blue teams improve their detection and response ca…☆332Sep 2, 2026Updated 3 weeks ago
- RedInfraCraft automates the deployment of powerful red team infrastructures! It streamlines the setup of C2s, makes it easy to create adv…☆234Mar 28, 2025Updated last year
- Run TTPs, with AI!☆142Feb 23, 2026Updated 7 months ago
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆422Sep 3, 2026Updated 3 weeks ago
- AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.☆2,080Feb 13, 2026Updated 7 months ago
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆621Jan 20, 2026Updated 8 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird …☆810Jan 26, 2026Updated 8 months ago
- Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!☆603Aug 17, 2026Updated last month
- Awesome EDR Bypass Resources For Ethical Hacking☆1,588Jan 26, 2026Updated 8 months ago
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆464Jun 27, 2025Updated last year
- game of active directory☆8,384Mar 12, 2026Updated 6 months ago
- Venom C2 is a dependency‑free Python3 Command & Control framework for redteam persistence☆441Nov 7, 2025Updated 10 months ago
- ☆254Mar 29, 2025Updated last year