Red Teaming and Penetration Testing Checklist, Cheatsheet, Clickscript
☆144Oct 26, 2023Updated 2 years ago
Alternatives and similar repositories for RedTeam-PenTest-Cheatsheet-Checklist
Users that are interested in RedTeam-PenTest-Cheatsheet-Checklist are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Cyber Security Club, Offensive Operations Section (Red Team) learning pathway.☆30Jun 6, 2023Updated 3 years ago
- Apache Superset Auth Bypass (CVE-2023-27524)☆11May 9, 2023Updated 3 years ago
- ☆11Dec 8, 2023Updated 2 years ago
- This is the ringzer0 writeup of web exploitation catagery. The name is "Word mean something"☆14Dec 8, 2023Updated 2 years ago
- Exploits for CVE-2023-27327 and CVE-2023-27328☆15May 9, 2023Updated 3 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Offensive Security MISC Annotations and Payloads for Ethical Hackers / Security Researchers☆31Dec 12, 2024Updated last year
- Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information☆79Jul 30, 2026Updated last month
- CVE-2022-31245: RCE and domain admin privilege escalation for Mailcow☆12Jul 25, 2022Updated 4 years ago
- Tools & Resources for Cyber Security Operations☆313Aug 22, 2026Updated 2 weeks ago
- Certified Red Team Operator☆475Apr 17, 2022Updated 4 years ago
- A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techni…☆1,418Oct 27, 2023Updated 2 years ago
- Contains a collection of Bash scripts designed for comprehensive security audits and network mapping of Active Directory (AD) environment…☆150May 17, 2024Updated 2 years ago
- ☆505Oct 7, 2022Updated 3 years ago
- ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities. It crawls a target website, extracts GET…☆60Feb 22, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- impersonate trustedinstaller by fiddling with tokens☆13Aug 30, 2021Updated 5 years ago
- ☆250Aug 31, 2021Updated 5 years ago
- DNS over HTTPS targeted malware (only runs once)☆97Aug 16, 2023Updated 3 years ago
- My public notes about offensive security☆171Sep 5, 2025Updated last year
- this script adds the ability to encode shellcode (.bin) in XOR,chacha20, AES. You can choose between 2 loaders (Myph / 221b)☆83Dec 20, 2023Updated 2 years ago
- A cross-platform tool to parse and describe the contents of a raw ntSecurityDescriptor structure☆52Aug 30, 2026Updated last week
- .NET profiler DLL loading can be abused to make a legit .NET application load a malicious DLL using environment variables. This exploit i…☆50Jul 29, 2024Updated 2 years ago
- Remote operations commands implemented using Beacon Object Files☆1,183Jul 20, 2026Updated last month
- Experience the power of a PHP webshell designed to overcome the limitations of blacklisted system/exec functions.☆26Jul 14, 2024Updated 2 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- TL;DR: Mutate a binary to identify potential exploit candidates☆11Jan 12, 2026Updated 7 months ago
- Polymorphic code obfuscator for use in Red Team operations☆33Apr 13, 2022Updated 4 years ago
- sample configs showing how to colorize the output of nmap☆15Mar 25, 2021Updated 5 years ago
- ☆22Jul 28, 2023Updated 3 years ago
- Lateral Movement Using DCOM and DLL Hijacking☆329Jun 18, 2023Updated 3 years ago
- Powershell implementation of a novel technique. Invoke-GPTObfuscation is a PowerShell Obfuscator that utilizes OpenAI (and other APIs) to…☆49Dec 5, 2023Updated 2 years ago
- A simple BOF implementation of klist using Windows API☆32Jul 7, 2022Updated 4 years ago
- Collection of notes that I have gathered during my studies for the OffSec Certified Professional (PEN-200) exam.☆25Dec 9, 2024Updated last year
- Python module for running BOFs☆80Nov 28, 2025Updated 9 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆615Jan 20, 2026Updated 7 months ago
- 热门框架/组件/服务漏洞的描述/利用/修复☆12Apr 13, 2023Updated 3 years ago
- Pentester Academy notes and commands from the CRTP/CRTE/PACES courses☆16Apr 29, 2022Updated 4 years ago
- Red Teaming & Pentesting checklists for various engagements☆2,655Jul 27, 2025Updated last year
- Cobalt Strike Beacon Object File (BOF) that uses WinStationConnect API to perform local/remote RDP session hijacking.☆317Jul 8, 2022Updated 4 years ago
- Offensive Security OSWE Prep 2022☆75Sep 10, 2022Updated 3 years ago
- Scan your Windows computer for known vulnerable or malicious drivers.☆106Apr 29, 2026Updated 4 months ago