EN
ENNA
πŸ”₯

Offensive Ops

25 tools indexed

Red team and offensive operations tooling including C2 frameworks, evasion techniques, lateral movement utilities, and specialized attack tools. Built for authorized penetration testing and adversary simulation exercises.

Mythic

Go
OffensiveFeatured

Collaborative, multi-platform C2 framework. Docker-based with web UI, multiple agent types, and plugin architecture.

c2red-teammulti-operatordocker
4.4k5736d ago

Havoc

C/C++
OffensiveFeatured

Modern C2 framework. Qt-based GUI, BOF support, custom agents, and a Cobalt Strike-inspired workflow.

c2red-teamguibof
8.3k1.2k3mo ago

Rubeus

C#
OffensiveFeatured

C# toolset for raw Kerberos interaction and abuse. AS-REP roasting, Kerberoasting, ticket manipulation, delegation attacks.

kerberosactive-directoryroastingdelegation
5.0k8854mo ago

Certipy

Python
OffensiveFeatured

Active Directory Certificate Services (AD CS) abuse tool. Find and exploit certificate template misconfigurations.

active-directorycertificatesadcsprivilege-escalation
3.5k4581mo ago

Coercer

Python
Offensive

Automatically find and exploit Windows authentication coercion vulnerabilities. PetitPotam, PrinterBug, and more.

authentication-coercionntlm-relaypetitpotamactive-directory
2.2k2153mo ago

SharpHound

C#
Offensive

Official BloodHound data collector. Enumerates Active Directory objects, sessions, ACLs, and trusts for graph analysis.

active-directoryenumerationbloodhoundgraph-data
1.2k2522d ago

BeEF

Ruby
OffensiveFeatured

Browser Exploitation Framework. Hook browsers via XSS, then pivot into the network using browser-based attacks.

browserxsshooksocial-engineering
10.8k2.4k2d ago

Social-Engineer Toolkit

Python
OffensiveFeatured

Open-source social engineering framework. Spear-phishing, web attacks, USB/HID attacks, and credential harvesting.

social-engineeringphishingcredential-harvestusb-attack
14.7k3.3k1y ago

Quasar RAT

C#
Offensive

Open-source remote administration tool for Windows. Full remote desktop, keylogger, file manager, and reverse proxy.

ratremote-accesskeyloggerremote-desktop
9.8k2.6k2y ago

Donut

C
OffensiveFeatured

Generates position-independent shellcode from .NET assemblies, PE files, and DLLs. Load anything in memory.

shellcodein-memoryevasiondotnet
4.5k7369mo ago

ScareCrow

Go
OffensiveFeatured

Payload creation framework for EDR bypass. Generates loaders using WinAPI syscalls to evade userland hooks.

edr-bypasssyscallsloaderevasion
2.9k5292y ago

SharpCollection

C#
Offensive

Nightly builds of common C# offensive tools. Pre-compiled Rubeus, Seatbelt, SharpUp, Certify, and 50+ more.

dotnetpre-compiledred-teamcollection
2.8k3864d ago

Seatbelt

C#
Offensive

C# safety checks for offensive operations. Enumerates host security config, credentials, and interesting data.

enumerationhost-surveysecurity-checkscredentials
4.5k7641y ago

HackRF One

C
OffensiveFeatured

Open-source software-defined radio platform. Transmit and receive 1 MHz to 6 GHz. The hardware hacker's SDR.

sdrradiohardwaresub-ghz
7.8k1.7k2d ago

USB Rubber Ducky Payloads

DuckyScript
Offensive

Payload repository for USB Rubber Ducky and BadUSB devices. Keystroke injection scripts for every scenario.

badusbhidkeystroke-injectionphysical-access
5.6k1.6k16d ago

pwncat

Python
OffensiveFeatured

Post-exploitation platform and target management. Automatic privesc, persistence, file transfer β€” the smart reverse shell.

post-exploitationreverse-shellprivescpersistence
2.9k2901y ago

Villain

Python
Offensive

Windows and Linux backdoor generator and handler. Auto-obfuscation, multi-session, and reverse shell management.

backdoorreverse-shellobfuscationmulti-session
4.4k68910mo ago

Creepy

Python
Offensive

Geolocation OSINT tool. Aggregates location data from social media, photos, and online services on a map.

geolocationosintsocial-mediagps
1.4k32010y ago

pwndrop

Go
Offensive

Self-deployable file hosting for red teams. Upload payloads, host phishing files, serve implants β€” with HTTPS and Let's Encrypt.

file-hostingpayload-deliveryred-teamhttps
2.2k2903y ago

Stegseek

C++
Offensive

Lightning fast steganography brute-forcer. Cracks steghide passwords at 200+ GB/s using wordlists.

steganographybrute-forcesteghidectf
1.3k1272y ago

Peirates

Go
Offensive

Kubernetes penetration testing tool. Exploit misconfigs, steal secrets, move laterally in K8s clusters.

kubernetescloudcontainer-escapesecrets
1.4k1292mo ago

Pacu

Python
OffensiveFeatured

AWS exploitation framework. Enumerate, escalate, and exfiltrate across AWS services. The Metasploit of cloud.

awscloudprivilege-escalationiam
5.1k7786d ago

Prowler

Python
Offensive

Cloud security assessment tool. 300+ checks for AWS, Azure, GCP, and Kubernetes against CIS benchmarks.

cloud-securityawsazuregcp
13.5k2.1k3d ago

Starkiller

JavaScript
Offensive

Frontend GUI for PowerShell Empire β€” manage listeners, agents, and modules through a modern Electron interface.

c2-guiempireagent-managementred-team
1.6k2421mo ago

hoaxshell

Python
Offensive

Unconventional Windows reverse shell using HTTP(S) traffic β€” fully undetectable by Microsoft Defender.

reverse-shellevasionwindowshttp-shell
3.4k5271y ago