awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectDespreCum realizăm clasamentulPresăServer MCP
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

30 repository-uri

Awesome GitHub RepositoriesPost Exploitation Frameworks

Tools for managing and executing tasks after gaining system access.

Explore 30 awesome GitHub repositories matching part of an awesome list · Post Exploitation Frameworks. Refine with filters or upvote what's useful.

Awesome Post Exploitation Frameworks GitHub Repositories

Găsește cele mai bune repo-uri cu AI.Vom căuta cele mai potrivite repository-uri folosind AI.
  • rapid7/metasploit-frameworkAvatar rapid7

    rapid7/metasploit-framework

    38,415Vezi pe GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    Industry-standard framework for exploitation and post-exploitation.

    Rubyhacktoberfest
    Vezi pe GitHub↗38,415
  • fortra/impacketAvatar fortra

    fortra/impacket

    15,467Vezi pe GitHub↗

    Impacket is a collection of Python classes designed for the construction, manipulation, and analysis of low-level network packets and services. It functions as a framework for building custom network tools, providing a programmatic interface to interact with communication protocols and service architectures. The library provides primitives for managing authentication, session state, and remote procedure calls within network environments. By offering a modular class hierarchy, it allows for the assembly of network packets and the implementation of specialized communication stacks. The project

    Library for network protocol manipulation and post-exploitation.

    Pythondcerpcdcomimpacket
    Vezi pe GitHub↗15,467
  • powershellmafia/powersploitAvatar PowerShellMafia

    PowerShellMafia/PowerSploit

    12,880Vezi pe GitHub↗

    PowerSploit is a collection of PowerShell modules designed for security assessment, penetration testing, and red team operations. It provides a framework for auditing Windows system configurations and evaluating the effectiveness of security defenses within an enterprise environment. The framework focuses on techniques that leverage native system administration tools and scripting environments to perform operations. It includes capabilities for executing arbitrary commands, escalating user privileges, and maintaining system persistence through event subscriptions. By utilizing in-memory execu

    Collection of PowerShell scripts for post-exploitation.

    PowerShell
    Vezi pe GitHub↗12,880
  • gtfobins/gtfobins.github.ioAvatar GTFOBins

    GTFOBins/GTFOBins.github.io

    12,669Vezi pe GitHub↗

    GTFOBins is a curated knowledge base documenting security-related techniques for Unix-based system binaries. It serves as a reference for offensive security research, detailing how standard, pre-installed system utilities can be repurposed to facilitate privilege escalation, restricted environment escapes, and post-exploitation workflows. The project distinguishes itself by cataloging insecure execution paths and misconfigured permissions inherent in common system tools. By identifying legitimate binary functions that can be leveraged to bypass security controls, the repository provides a str

    Repository of Unix binaries for living-off-the-land attacks.

    YAMLbinariesbind-shellblueteam
    Vezi pe GitHub↗12,669
  • screetsec/thefatratAvatar screetsec

    screetsec/TheFatRat

    11,038Vezi pe GitHub↗

    TheFatRat is a security exploitation framework designed to automate the creation, obfuscation, and deployment of payloads for penetration testing. It functions as a comprehensive toolkit that streamlines the exploitation lifecycle, enabling users to generate malicious executables, manage network listeners, and execute post-exploitation tasks through a unified command-line interface. The framework distinguishes itself by integrating various third-party exploitation utilities into a single, orchestrated workflow. It provides specialized capabilities for embedding code into legitimate binaries a

    Tool for generating backdoors and post-exploitation attacks.

    Caccessibilityantivirusautorun
    Vezi pe GitHub↗11,038
  • samratashok/nishangAvatar samratashok

    samratashok/nishang

    9,951Vezi pe GitHub↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShell framework for offensive security operations.

    PowerShellactivedirectoryhackinginfosec
    Vezi pe GitHub↗9,951
  • byt3bl33d3r/crackmapexecAvatar byt3bl33d3r

    byt3bl33d3r/CrackMapExec

    9,144Vezi pe GitHub↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    Tool for network-wide post-exploitation and credential testing.

    Python
    Vezi pe GitHub↗9,144
  • empireproject/empireAvatar EmpireProject

    EmpireProject/Empire

    7,813Vezi pe GitHub↗

    Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It serves as a centralized platform for coordinating remote agent communication and automating the delivery of security testing payloads to target systems. The project provides a suite of modules for host reconnaissance, lateral movement, and credential harvesting across corporate environments. It functions as a remote administration tool to maintain persistence and execute commands on compromised hosts. The framework incorporates capabilities for agent orchestration and the executio

    Framework for post-exploitation in PowerShell and Python.

    PowerShell
    Vezi pe GitHub↗7,813
  • k8gege/ladonAvatar k8gege

    k8gege/Ladon

    5,297Vezi pe GitHub↗

    Ladon este un scanner de penetrare a rețelei interne și un instrument de evaluare a vulnerabilităților conceput pentru a identifica defectele de securitate cu risc ridicat și activele din segmentele de rețea. Operează ca un scanner de securitate fileless, executându-și motorul și modulele direct în memorie pentru a evita lăsarea unei amprente pe disc pe sistemele țintă. Proiectul se distinge prin integrarea sa ca plugin pentru beacon-uri de comandă, specific în cadrul framework-ului Cobalt Strike. Acest lucru permite descoperirea rețelei și detectarea vulnerabilităților rezidente în memorie. Suportă, de asemenea, operațiuni stealth prin obfuscarea payload-urilor și a scripturilor, precum și tehnici de evitare a detectării de către sistemele de endpoint detection and response (EDR). Instrumentul oferă o suită cuprinzătoare de capabilități pentru post-exploatare, inclusiv auditarea credențialelor, extracția și executarea atacurilor Kerberos pentru penetrarea domeniului. Gestionează descoperirea activelor prin scanare multi-protocol și fingerprinting-ul serviciilor pentru a identifica sistemele de operare și tehnologiile web. În plus, suportă automatizarea mișcării laterale, escaladarea privilegiilor și implementarea payload-urilor de execuție de cod la distanță. Framework-ul este extensibil printr-o arhitectură de plugin-uri care permite încărcarea dinamică a ansamblurilor sau scripturilor externe pentru a adăuga module de scanare personalizate și dovezi de concept.

    Large-scale network scanning and exploitation framework.

    C#brute-forceexpexploit
    Vezi pe GitHub↗5,297
  • pennyw0rth/netexecAvatar Pennyw0rth

    Pennyw0rth/NetExec

    5,274Vezi pe GitHub↗

    NetExec is a framework for concurrent credential spraying and remote command execution across network protocols. It provides input sanitization and command parsing to reduce injection risks, a plugin-based protocol abstraction that dispatches credentials and commands uniformly regardless of transport, and session and token lifecycle management for long-running multi-command operations. Results from concurrent executions are collected and normalized through a result aggregation pipeline. The framework includes a concurrent job scheduler that manages worker threads for parallel execution across

    Modernized tool for network-wide post-exploitation.

    Pythonactive-directoryhackinginfosec
    Vezi pe GitHub↗5,274
  • ghostpack/rubeusAvatar GhostPack

    GhostPack/Rubeus

    4,890Vezi pe GitHub↗

    Rubeus is a comprehensive Kerberos attack toolkit for Active Directory environments, written in C#. It provides a full suite of operations for manipulating Kerberos tickets, exploiting delegation configurations, and performing credential attacks against Windows domains. The toolkit enables ticket extraction from logon sessions and memory, with real-time monitoring via Event Tracing for Windows. It supports forging golden and silver tickets with arbitrary privileges, as well as the creation of forged delegation contexts. Delegation attacks include abuse of constrained and unconstrained delegat

    Tool for Kerberos interaction and ticket manipulation.

    C#kerberos
    Vezi pe GitHub↗4,890
  • zer0yu/awesome-cobaltstrikeAvatar zer0yu

    zer0yu/Awesome-CobaltStrike

    4,419Vezi pe GitHub↗

    Acest proiect este o colecție curatoriată de instrumente, scripturi și ghiduri tehnice concepute pentru a îmbunătăți operațiunile de securitate ofensivă folosind Cobalt Strike. Servește drept hub de resurse pentru gestionarea infrastructurii de comandă și control și deployarea angajamentelor de securitate. Colecția include toolkit-uri pentru evitarea sistemelor de detecție și răspuns la endpoint-uri (EDR), alături de biblioteci pentru automatizarea sarcinilor de red team, cum ar fi recunoașterea și enumerarea host-urilor. Oferă resurse pentru dezvoltarea de framework-uri de post-exploatare, concentrându-se în mod specific pe crearea de biblioteci reflexive și cod rezident în memorie. Repository-ul acoperă o gamă largă de capabilități operaționale, inclusiv personalizarea traficului de rețea pentru a evita detecția, criminalistica memoriei pentru analiza infrastructurii și diverse tehnici de obfuscare a shellcode-ului. Include, de asemenea, ghiduri pentru configurarea serverelor de comandă și control și efectuarea injectării în procesele host.

    Curated list of Cobalt Strike extensions and resources.

    Vezi pe GitHub↗4,419
  • nextronsystems/aptsimulatorAvatar NextronSystems

    NextronSystems/APTSimulator

    2,750Vezi pe GitHub↗

    A toolset to make a system look as if it was the victim of an APT attack

    Toolset to simulate an APT attack on a system.

    Batchfile
    Vezi pe GitHub↗2,750
  • byt3bl33d3r/silenttrinityAvatar byt3bl33d3r

    byt3bl33d3r/SILENTTRINITY

    2,340Vezi pe GitHub↗

    An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR

    Asynchronous, collaborative post-exploitation agent.

    Boo
    Vezi pe GitHub↗2,340
  • bats3c/shad0wAvatar bats3c

    bats3c/shad0w

    2,175Vezi pe GitHub↗

    A post exploitation framework designed to operate covertly on heavily monitored environments

    Post-exploitation framework for covert operations.

    C
    Vezi pe GitHub↗2,175
  • mubix/post-exploitationAvatar mubix

    mubix/post-exploitation

    1,582Vezi pe GitHub↗

    Post Exploitation Collection

    Collection of post-exploitation tools and techniques.

    C
    Vezi pe GitHub↗1,582
  • deepingh0st/erebusAvatar DeEpinGh0st

    DeEpinGh0st/Erebus

    1,564Vezi pe GitHub↗

    CobaltStrike后渗透测试插件

    Cobalt Strike extension for post-exploitation tasks.

    PowerShellcobaltstrike
    Vezi pe GitHub↗1,564
  • kevin-robertson/powermadAvatar Kevin-Robertson

    Kevin-Robertson/Powermad

    1,485Vezi pe GitHub↗

    PowerShell MachineAccountQuota and DNS exploit tools

    Tool for creating and manipulating Active Directory objects.

    PowerShell
    Vezi pe GitHub↗1,485
  • funnywolf/pystingerAvatar FunnyWolf

    FunnyWolf/pystinger

    1,431Vezi pe GitHub↗

    Bypass firewall for traffic forwarding using webshell

    Tool for tunneling traffic through web servers.

    Pythoncobalt-strikeregeorgwebshell
    Vezi pe GitHub↗1,431
  • outflanknl/c2-tool-collectionAvatar outflanknl

    outflanknl/C2-Tool-Collection

    1,395Vezi pe GitHub↗

    A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

    Tools integrating with Cobalt Strike for post-exploitation.

    C
    Vezi pe GitHub↗1,395
Înapoi12Înainte
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Post Exploitation Frameworks