awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to redhuntlabs/redhunt-os

Projects sharing features with RedHunt OS

30 open-source projects similar to redhuntlabs/redhunt-os, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • nextronsystems/aptsimulatorNextronSystems avatar

    NextronSystems/APTSimulator

    2,750View on GitHub↗

    A toolset to make a system look as if it was the victim of an APT attack

    Batchfile
    View on GitHub↗2,750
  • trycatchhcf/dumpsterfireTryCatchHCF avatar

    TryCatchHCF/DumpsterFire

    1,036View on GitHub↗

    "Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.

    Pythonautomationblue-teamblue-teams
    View on GitHub↗1,036
  • uber-common/mettauber-common avatar

    uber-common/metta

    1,140View on GitHub↗

    An information security preparedness tool to do adversarial simulation.

    Python
    View on GitHub↗1,140
  • alphasoc/flightsimalphasoc avatar

    alphasoc/flightsim

    1,360View on GitHub↗

    A utility to safely generate malicious network traffic patterns and evaluate controls.

    Go
    View on GitHub↗1,360
  • mitre/calderamitre avatar

    mitre/caldera

    7,047View on GitHub↗

    Caldera is an adversary emulation platform and command and control framework designed to simulate cyber attack patterns. It functions as an automated red team tool and threat framework orchestrator, executing attack sequences based on standardized cybersecurity threat frameworks to validate security defenses and detection capabilities. The platform distinguishes itself through the dynamic compilation of customized executable payloads and the use of framework-mapped adversary modeling to structure attack techniques. It manages asynchronous agents on targeted endpoints via a central server acce

    Python
    View on GitHub↗7,047

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • redcanaryco/atomic-red-teamredcanaryco avatar

    redcanaryco/atomic-red-team

    12,089View on GitHub↗

    Atomic Red Team is an adversary simulation tool and detection validation suite designed to emulate attacker behaviors. It functions as a security control testing framework that uses a library of portable tests to verify if security monitoring and alerting systems correctly identify specific malicious techniques. The project serves as a MITRE ATT&CK emulation framework, mapping individual test executions to a standardized industry taxonomy of adversary behaviors. This mapping allows for the validation of security controls against the MITRE ATT&CK matrix to identify gaps in detection and respon

    Cmitremitre-attack
    View on GitHub↗12,089
  • endgameinc/rtaendgameinc avatar

    endgameinc/RTA

    1,096View on GitHub↗

    RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK.

    Python
    View on GitHub↗1,096
  • splunk/salosplunk avatar

    splunk/salo

    92View on GitHub↗

    Synthetic Adversarial Log Objects (SALO) is a framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event. The purpose of this framework is to allow security practitioners, data scientists, and researchers the ability to…

    Python
    View on GitHub↗92
  • cyb3rward0g/invoke-attackapiC

    Cyb3rWard0g/Invoke-ATTACKAPI

    0View on GitHub↗
    View on GitHub↗0
  • guardicore/monkeyguardicore avatar

    guardicore/monkey

    7,014View on GitHub↗

    Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials. The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antiv

    Python
    View on GitHub↗7,014
  • cobbr/covenantcobbr avatar

    cobbr/Covenant

    4,699View on GitHub↗

    Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It serves as a collaborative platform for coordinating security assessments, managing remote implants, and executing tasks on compromised systems through a centralized server. The project is distinguished by its dynamic payload generator, which compiles and obfuscates executable binaries and scripts on the fly to bypass detection. It further separates itself through a collaborative environment that allows multiple authenticated operators to share a synchronized state, track operat

    C#
    View on GitHub↗4,699
  • its-a-feature/apfellits-a-feature avatar

    its-a-feature/Apfell

    4,570View on GitHub↗

    Apfell is a red teaming framework and command and control server designed for collaborative adversary simulation. It provides a centralized infrastructure to manage remote agents and distribute tasking across multiple operating systems using a message broker for real-time synchronization. The system functions as a distributed agent orchestrator, allowing teams to coordinate complex attack chains and synchronize container data. It features a multi-platform payload manager that enables the downloading and integration of custom agents and command profiles from remote repositories. The platform

    JavaScript
    View on GitHub↗4,570
  • bluscreenofjeff/red-team-infrastructure-wikibluscreenofjeff avatar

    bluscreenofjeff/Red-Team-Infrastructure-Wiki

    4,498View on GitHub↗

    This project is a collection of technical resources, blueprints, and guides for building resilient and stealthy red team infrastructure. It provides a comprehensive framework for designing offensive security environments that resist detection and remain operational throughout security engagements. The repository distinguishes itself through detailed playbooks for adversary simulation and hardening manuals. It covers advanced obfuscation techniques such as domain fronting, the use of platform-as-a-service redirectors, and the leveraging of third-party content sites to inherit domain reputation

    View on GitHub↗4,498
  • fourcorelabs/firedrillF

    FourCoreLabs/firedrill

    0View on GitHub↗
    View on GitHub↗0
  • coalfire-research/red-baronC

    Coalfire-Research/Red-Baron

    0View on GitHub↗
    View on GitHub↗0
  • blackbotinc/atomic-red-team-intelligence-c2B

    blackbotinc/Atomic-Red-Team-Intelligence-C2

    0View on GitHub↗
    View on GitHub↗0
  • clong/detectionlabclong avatar

    clong/DetectionLab

    4,904View on GitHub↗

    DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms. The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients. The environment includes a telemetry pipeline that aggre

    HTMLansibledetectiondetectionlab
    View on GitHub↗4,904
  • empireproject/empireEmpireProject avatar

    EmpireProject/Empire

    7,813View on GitHub↗

    Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It serves as a centralized platform for coordinating remote agent communication and automating the delivery of security testing payloads to target systems. The project provides a suite of modules for host reconnaissance, lateral movement, and credential harvesting across corporate environments. It functions as a remote administration tool to maintain persistence and execute commands on compromised hosts. The framework incorporates capabilities for agent orchestration and the executio

    PowerShell
    View on GitHub↗7,813
  • chryzsh/darthsidiousC

    chryzsh/DarthSidious

    0View on GitHub↗
    View on GitHub↗0
  • binarydefense/beacon-frontingB

    BinaryDefense/beacon-fronting

    0View on GitHub↗
    View on GitHub↗0
  • elevenpaths/attpwnE

    ElevenPaths/ATTPwn

    0View on GitHub↗
    View on GitHub↗0
  • datadog/stratus-red-teamDataDog avatar

    DataDog/stratus-red-team

    2,264View on GitHub↗
    Goadversary-emulationawsaws-security
    View on GitHub↗2,264
  • carbonblack/excel4-testsC

    carbonblack/excel4-tests

    0View on GitHub↗
    View on GitHub↗0
  • endgameinc/eqlE

    endgameinc/eql

    0View on GitHub↗
    View on GitHub↗0
  • endgameinc/eqllibE

    endgameinc/eqllib

    0View on GitHub↗
    View on GitHub↗0
  • danielbohannon/revoke-obfuscationD

    danielbohannon/Revoke-Obfuscation

    0View on GitHub↗
    View on GitHub↗0
  • endgameinc/varnaendgameinc avatar

    endgameinc/varna

    52View on GitHub↗

    Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)

    CSS
    View on GitHub↗52
  • fireeye/capafireeye avatar

    fireeye/capa

    6,062View on GitHub↗

    capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities such as API calls, byte sequences, and structural patterns without executing the code. It supports multiple file formats including PE, ELF, .NET, and shellcode, and can also process runtime behavior traces from sandbox reports generated by CAPE, DRAKVUF, or VMRay. The tool integrates directly with reverse engineering environments through plugins for IDA Pro and Ghidra, allowing analysts to view capability matches and author detection rules within their disassembler of choice. C

    Python
    View on GitHub↗6,062
  • d3vzer0/reternal-quickstartD

    d3vzer0/reternal-quickstart

    0View on GitHub↗
    View on GitHub↗0
  • brimsec/brimB

    brimsec/brim

    0View on GitHub↗
    View on GitHub↗0