awesome-repositories.com
Blog
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
hmaverickadams avatar

hmaverickadams/Beginner-Network-Pentesting

0
View on GitHub↗
6,205 estrellas·1,692 forks·7 vistas

Beginner Network Pentesting

This is a hands-on lab environment for learning network penetration testing techniques, centered on setting up and attacking a vulnerable Active Directory network. The project provides a structured framework for practicing the full attack chain, from initial reconnaissance and scanning through exploitation, privilege escalation, lateral movement, and credential theft, all within isolated virtual machine labs.

The lab environment is designed to simulate real-world attack scenarios, including the ability to compile and execute exploit code directly against targets without relying on Metasploit. It also integrates Metasploit for gaining shell access and maintaining persistence, and includes workflows for applying security patches to demonstrate defensive countermeasures. The project coordinates multiple tools like Nmap, Nessus, and Nikto through scripted pipelines for scanning and enumeration.

Beyond the technical attack simulation, the project includes a framework for documenting findings, attack paths, and remediation steps into a structured report suitable for client delivery. The documentation covers building the Active Directory lab, executing the full attack chain, and patching the environment to reinforce defensive practices.

Features

  • Port Scanning - Uses tools like Nmap, Nessus, and Metasploit to identify open ports and running services on target machines.
  • Active Directory Exploitation - Executes a full attack chain including reconnaissance, scanning, exploitation, and post-exploitation against an Active Directory lab.
  • Vulnerable Lab Environments - Organises penetration testing scenarios into isolated virtual machine labs with pre-configured vulnerabilities for hands-on practice.
  • Active Directory Attacks - Models a full kill chain from reconnaissance to lateral movement and persistence in a Windows domain environment.
  • Lab Environments - Provides a complete vulnerable Active Directory lab for practicing the full attack chain from reconnaissance to credential theft.
  • Active Directory Lab Builds - Sets up a Windows-based Active Directory environment with vulnerable configurations for practicing penetration testing.
  • Active Directory Security - Demonstrates defensive remediation techniques by applying security patches to a vulnerable Active Directory network.
  • Lab Remediation Workflows - Provides step-by-step patching workflows to remediate vulnerabilities in an Active Directory lab environment.
  • Lab Environments - Provides a lab environment for scanning ports and services with Nmap, Nessus, and Nikto to identify exploitable weaknesses.
  • Penetration Test Reports - Ships a framework for documenting penetration test findings into a structured client-ready report.
  • Post-Exploitation and Lateral Movement - Establishes persistent access on a compromised network and moves laterally to other segments.
  • Exploit Compilation Tooling - Downloads exploit code from public sources, compiles it, and runs it against a target without using Metasploit.
  • Metasploit Shell Integrations - Leverages Metasploit modules for shell access, privilege escalation, and post-exploitation tasks within the lab network.
  • Metasploit Shell Access - Leverages Metasploit exploit modules to obtain a command shell on a vulnerable target machine.
  • Metasploit Practice Labs - Integrates Metasploit for gaining shell access and maintaining persistence on vulnerable lab machines.
  • Manual Exploitation Labs - Provides a lab environment for compiling and executing exploit code manually against vulnerable targets.
  • Network Pivoting Tools - Establishes persistent footholds and moves laterally across network segments after initial compromise.
  • Service Enumeration Tools - Probes discovered services with tools like Nikto, Dirbuster, and Burp Suite to find exploitable weaknesses.
  • Exploit Execution Engines - Downloads exploit source code, generates shellcode, and compiles it for direct execution against targets without Metasploit.
  • Security Report Generation - Structures penetration test findings into a client-ready document with attack paths, evidence, and remediation steps.
  • Security Tool Orchestration Pipelines - Coordinates scanning, enumeration, and exploitation tools like Nmap, Metasploit, and Nikto through scripted workflows.
  • Test Result Reporters - Documents findings, vulnerabilities, and remediation steps in a structured report format for clients.
  • Penetration Test Reporters - Documents findings, attack paths, and remediation steps in a structured report suitable for client delivery.

Historial de estrellas

Gráfico del historial de estrellas de hmaverickadams/beginner-network-pentestingGráfico del historial de estrellas de hmaverickadams/beginner-network-pentesting

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Alternativas open-source a Beginner Network Pentesting

Proyectos open-source similares, clasificados según cuántas características comparten con Beginner Network Pentesting.
  • ridter/intranet_penetration_tipsAvatar de Ridter

    Ridter/Intranet_Penetration_Tips

    4,606Ver en GitHub↗

    This project is a technical guide and reference for internal network penetration testing. It serves as a collection of procedures for exploiting and navigating private corporate networks during security assessments. The repository provides specialized manuals and cheat sheets focused on active directory attacks, lateral movement, and privilege escalation. It includes a post-exploitation playbook for maintaining system persistence and clearing forensic traces. The documentation covers a broad range of security capabilities, including initial access, network pivoting and tunneling, and interna

    Ver en GitHub↗4,606
  • mantvydasb/redteaming-tactics-and-techniquesAvatar de mantvydasb

    mantvydasb/RedTeaming-Tactics-and-Techniques

    4,620Ver en GitHub↗

    This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior. It serves as a comprehensive collection of technical guides and tactics for executing red team operations. The repository provides detailed instructions for Active Directory exploitation, including Kerberos abuse and domain privilege escalation. It covers defense evasion through API unhooking and payload obfuscation, as well as Windows internals research involving the manipulation of kernel objects and system memory. The capability surface extends to network penetration testi

    PowerShelloffensive-securityoscppentesting
    Ver en GitHub↗4,620
  • 1n3/sn1perAvatar de 1N3

    1N3/Sn1per

    10,049Ver en GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Shellattack-surfaceattack-surface-managementattacksurface
    Ver en GitHub↗10,049
  • samratashok/nishangAvatar de samratashok

    samratashok/nishang

    9,951Ver en GitHub↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellactivedirectoryhackinginfosec
    Ver en GitHub↗9,951
Ver las 30 alternativas a Beginner Network Pentesting→

Preguntas frecuentes

¿Qué hace hmaverickadams/beginner-network-pentesting?

This is a hands-on lab environment for learning network penetration testing techniques, centered on setting up and attacking a vulnerable Active Directory network. The project provides a structured framework for practicing the full attack chain, from initial reconnaissance and scanning through exploitation, privilege escalation, lateral movement, and credential theft, all within isolated virtual machine labs.

¿Cuáles son las características principales de hmaverickadams/beginner-network-pentesting?

Las características principales de hmaverickadams/beginner-network-pentesting son: Port Scanning, Active Directory Exploitation, Vulnerable Lab Environments, Active Directory Attacks, Lab Environments, Active Directory Lab Builds, Active Directory Security, Lab Remediation Workflows.

¿Qué alternativas de código abierto existen para hmaverickadams/beginner-network-pentesting?

Las alternativas de código abierto para hmaverickadams/beginner-network-pentesting incluyen: ridter/intranet_penetration_tips — This project is a technical guide and reference for internal network penetration testing. It serves as a collection of… mantvydasb/redteaming-tactics-and-techniques — This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior.… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… samratashok/nishang — Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… orange-cyberdefense/goad — GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of…