This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom tools, C2 servers, backdoors, exploitation techniques, stagers, bootloaders, and other malicious artifacts that mirror those used in real world attacks.
☆1,124Aug 31, 2026Updated last week
Alternatives and similar repositories for APTs-Adversary-Simulation
Users that are interested in APTs-Adversary-Simulation are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- BEAR-C2 is an adversary simulation and emulation framework built around real-world TTPs inspired by Russian, Chinese, North Korean, and I…☆543Updated this week
- A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive …☆1,534May 5, 2026Updated 4 months ago
- This comprehensive process injection series is crafted for cybersecurity enthusiasts, researchers, and professionals who aim to stay at t…☆466Jun 10, 2026Updated 2 months ago
- AppLocker-Based EDR Neutralization☆341Dec 19, 2025Updated 8 months ago
- AdaptixC2 is a highly modular advanced redteam toolkit☆3,580Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Evasion kit for Cobalt Strike☆494Jun 5, 2026Updated 3 months ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆511Mar 15, 2026Updated 5 months ago
- Lab used for workshop and CTF☆535Aug 23, 2026Updated 2 weeks ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆316Aug 31, 2026Updated last week
- EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.☆867May 23, 2026Updated 3 months ago
- A resource containing all the tools each ransomware gangs uses☆1,439Aug 29, 2026Updated last week
- Simulate the behavior of AV/EDR for malware development training.☆565Feb 15, 2024Updated 2 years ago
- Windows protocol library, including SMB and RPC implementations, among others.☆832Aug 18, 2026Updated 2 weeks ago
- C2 infrastructure over Microsoft Teams.☆758Jan 15, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ↕️🤫 Stealth redirector for your red team operation security☆1,105Jul 20, 2026Updated last month
- Extract and execute a PE embedded within a PNG file using an LNK file.☆479Nov 2, 2024Updated last year
- A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage Power…☆821Mar 28, 2025Updated last year
- This map lists the essential techniques to bypass anti-virus and EDR☆3,436Mar 28, 2025Updated last year
- A tool to transform Chromium browsers into a C2 Implant☆603Dec 17, 2025Updated 8 months ago
- Mapping of open-source detection rules and atomic tests.☆216Jul 15, 2026Updated last month
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,900Nov 3, 2024Updated last year
- Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and co…☆837May 16, 2026Updated 3 months ago
- Abusing Azure services over C2☆381Jan 20, 2026Updated 7 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- EDR Lab for Experimentation Purposes☆1,556Jun 10, 2026Updated 2 months ago
- M365/Azure adversary simulation tool that generates realistic attack telemetry to help blue teams improve their detection and response ca…☆329Updated this week
- RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging☆209Mar 6, 2025Updated last year
- Run TTPs, with AI!☆142Feb 23, 2026Updated 6 months ago
- AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.☆2,059Feb 13, 2026Updated 6 months ago
- RedInfraCraft automates the deployment of powerful red team infrastructures! It streamlines the setup of C2s, makes it easy to create adv…☆234Mar 28, 2025Updated last year
- Conquest is a feature-rich and malleable command & control/post-exploitation framework developed in Nim.☆421Updated this week
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆615Jan 20, 2026Updated 7 months ago
- ☆253Mar 29, 2025Updated last year
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird …☆810Jan 26, 2026Updated 7 months ago
- Awesome EDR Bypass Resources For Ethical Hacking☆1,583Jan 26, 2026Updated 7 months ago
- game of active directory☆8,287Mar 12, 2026Updated 5 months ago
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆462Jun 27, 2025Updated last year
- Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and book…☆558Jan 8, 2026Updated 7 months ago
- Venom C2 is a dependency‑free Python3 Command & Control framework for redteam persistence☆436Nov 7, 2025Updated 10 months ago
- Dump lsass using only NTAPI functions creating 3 JSON and 1 ZIP file... and generate the MiniDump file later!☆593Aug 17, 2026Updated 3 weeks ago