Threat Express (threatexpress)

Threat Express

threatexpress

Geek Repo

Home Page:http://threatexpress.com

Github PK Tool:Github PK Tool

Threat Express's repositories

malleable-c2

Cobalt Strike Malleable C2 Design and Reference Guide

domainhunter

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Language:PythonLicense:BSD-3-ClauseStargazers:1502Issues:60Issues:25

red-team-scripts

A collection of Red Team focused tools, scripts, and notes

Language:PowerShellLicense:BSD-3-ClauseStargazers:1104Issues:53Issues:1

random_c2_profile

Cobalt Strike random C2 Profile generator

Language:PythonLicense:GPL-3.0Stargazers:615Issues:13Issues:6

cs2modrewrite

Convert Cobalt Strike profiles to modrewrite scripts

Language:PythonLicense:GPL-3.0Stargazers:574Issues:20Issues:4

metatwin

The project is designed as a file resource cloner. Metadata, including digital signature, is extracted from one file and injected into another.

Language:PythonLicense:NOASSERTIONStargazers:165Issues:11Issues:1

aggressor-scripts

Cobalt Strike Aggressor Scripts

Language:JavaScriptStargazers:138Issues:6Issues:0

pasties

A collection of random bits of information common to many individual penetration tests, red teams, and other assessments

Language:ShellStargazers:107Issues:9Issues:0

subshell

SubShell is a python command shell used to control and execute commands through HTTP requests to a webshell. SubShell acts as the interface to the remote webshells.

Language:PythonLicense:NOASSERTIONStargazers:73Issues:7Issues:0

threatbox

ThreatBox is a standard and controlled Linux based attack platform. I've used a version of this for years. It started as a collection of scripts, lived as a rolling virtual machine, existed as code to build a Linux ISO, and has now been converted to a set of ansible playbooks. Why Ansible? Why not? This seemed a natural evolution.

invoke-pipeshell

SMB Named Pipe shell

Language:PowerShellStargazers:63Issues:3Issues:0

portplow

PortPlow is a distributed port and system scanning & enumeration service. It enables the quick and automated enumeration of ports and services from multiple systems managed by a central console.

Language:JavaScriptStargazers:53Issues:4Issues:0

edc

Event Data Collector

Language:PythonLicense:MITStargazers:34Issues:3Issues:0

mythic2modrewrite

Generate Apache mod_rewrite rules for Mythic C2 profiles

Language:PythonLicense:MITStargazers:26Issues:2Issues:0

threat-mitigation

Threat Mitigation Strategies

procdot_sandbox

ProcDot Malware Sandbox

Language:PythonStargazers:21Issues:4Issues:0

cobaltstrike_payload_generator

Quickly generate every payload type for each listener and optionally host via HTTP.

redteamguide

Home of https://redteam.guide

Language:JavaScriptStargazers:11Issues:1Issues:0