Resources · Reference
Red Team Tools
A reference directory of 49 offensive-security tools — what each one does, a representative command, and a link to the source. Grouped by where they fit in an engagement, from reconnaissance to command-and-control.
Recon & OSINT · 11
In-depth DNS enumeration and attack-surface mapping.
Passive subdomain discovery at scale.
Fast, multi-purpose DNS toolkit for resolution and probing.
Email, subdomain, and host OSINT gathering.
Metadata extraction from public documents.
Document metadata analysis for Windows.
OSINT investigation of Google accounts.
Automated OSINT reconnaissance engine.
Query the internet's connected devices from the terminal.
Modular web reconnaissance framework.
ARP-based host discovery on local networks.
Network Scanning · 2
Web Application · 5
Credential Access · 7
GPU-accelerated password cracking.
Fast online network login brute-forcer.
Local credential harvester.
Extract Windows credentials from memory.
Decrypt Group Policy Preferences passwords.
Extract KeePass keys and entries from memory.
Default WPA/WPS key and PIN generation.
Active Directory · 9
Swiss-army knife for AD network post-exploitation.
Python toolkit of network-protocol scripts.
AS-REP roasting via Impacket.
SMB and Windows enumeration.
Dump Active Directory contents via LDAP.
BloodHound data collector for AD attack paths.
Local Windows security enumeration.
PowerShell post-exploitation module set.
Kerberos username enumeration and password spraying.
Command & Control · 9
The exploitation and post-exploitation framework.
PowerShell and Python C2 framework.
.NET command-and-control framework.
Cross-platform adversary-emulation C2.
Collaborative, plugin-based C2 platform.
HTTP/2 cross-platform C2 written in Go.
Windows Script Host (JScript/VBScript) C2.
Cross-platform Python RAT and C2.
Lightweight .NET Windows remote-administration tool.
Exploitation & Utilities · 6
CTF and exploit-development framework.
ROP/JOP gadget finder for exploit chains.
Offline command-line search of Exploit-DB.
Embedded-device exploitation framework.
Linux local privilege-escalation enumeration.
Fast TCP/UDP tunnel over HTTP.
Skip the install. Scan from the browser.
VulnScanners runs Nmap, Nuclei, and OWASP ZAP on hosted infrastructure — point at a target, get a report. No setup.