{"id":13510471,"url":"https://github.com/yeyintminthuhtut/Awesome-Red-Teaming","last_synced_at":"2025-03-30T16:33:36.865Z","repository":{"id":37390867,"uuid":"104987608","full_name":"yeyintminthuhtut/Awesome-Red-Teaming","owner":"yeyintminthuhtut","description":"List of Awesome Red Teaming Resources","archived":false,"fork":false,"pushed_at":"2023-12-28T18:10:52.000Z","size":205,"stargazers_count":6558,"open_issues_count":12,"forks_count":1632,"subscribers_count":342,"default_branch":"master","last_synced_at":"2024-05-18T19:58:41.867Z","etag":null,"topics":["cobalt-strike","empire","phishing","redteam","redteaming","uac"],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/yeyintminthuhtut.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2017-09-27T07:39:15.000Z","updated_at":"2024-05-18T13:48:14.000Z","dependencies_parsed_at":"2024-01-12T02:44:54.083Z","dependency_job_id":"579782d8-1221-4665-bee0-ba092e4f81db","html_url":"https://github.com/yeyintminthuhtut/Awesome-Red-Teaming","commit_stats":{"total_commits":86,"total_committers":15,"mean_commits":5.733333333333333,"dds":0.2441860465116279,"last_synced_commit":"1075eed002871aa5bf30b8b6f66a03956840f351"},"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yeyintminthuhtut%2FAwesome-Red-Teaming","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yeyintminthuhtut%2FAwesome-Red-Teaming/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yeyintminthuhtut%2FAwesome-Red-Teaming/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/yeyintminthuhtut%2FAwesome-Red-Teaming/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/yeyintminthuhtut","download_url":"https://codeload.github.com/yeyintminthuhtut/Awesome-Red-Teaming/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":221845543,"owners_count":16890639,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cobalt-strike","empire","phishing","redteam","redteaming","uac"],"created_at":"2024-08-01T02:01:40.414Z","updated_at":"2024-11-01T11:30:19.713Z","avatar_url":"https://github.com/yeyintminthuhtut.png","language":null,"funding_links":[],"categories":["Others","Awesome Repositories","🎩 Hacking","Main Resources -","Github resources","[↑](#table-of-contents) Red Team","Others (1002)","Threat Simulation","Other Lists","redteam","General","📘 Valuable Repositories","Online Resources","Useful Resources","Tools","Shell Aliases","Pentesting","Programming/Comp Sci/SE Things","Here is a collection of hackers, pentesters, security researchers, scripts and more:","[↑](#table-of-contents) Other Awesome Red Teaming Resources","Uncategorized"],"sub_categories":["Free","Posts from Hacker101 members on how to get started hacking","Exploit Development","Resources","TeX Lists","Other awesome-Collections","Other Lists Online","Security Awesome Lists","Adversary Emulation","Chess :chess_pawn:","Red Team","Hack Back","Uncategorized"],"readme":"# This List is no longer updated.\n\n## Awesome Red Teaming\n\nList of Awesome Red Team / Red Teaming Resources\n\nThis list is for anyone wishing to learn about Red Teaming but do not have a starting point.\n\nAnyway, this is a living resources and will update regularly with latest Adversarial Tactics and Techniques based on [Mitre ATT\u0026CK](https://attack.mitre.org/wiki/Main_Page)\n\nYou can help by sending Pull Requests to add more information.\n\n\nTable of Contents\n=================\n\n * [Initial Access](#-initial-access)\n * [Execution](#-execution)\n * [Persistence](#-persistence)\n * [Privilege Escalation](#-privilege-escalation)\n * [Defense Evasion](#-defense-evasion)\n * [Credential Access](#-credential-access)\n * [Discovery](#-discovery)\n * [Lateral Movement](#-lateral-movement)\n * [Collection](#-collection)\n * [Exfiltration](#-exfiltration)\n * [Command and Control](#-command-and-control)\n * [Embedded and Peripheral Devices Hacking](#-embedded-and-peripheral-devices-hacking)\n * [Misc](#-misc)\n * [RedTeam Gadgets](#-redteam-gadgets)\n * [Ebooks](#-ebooks)\n * [Training](#-training--free-)\n * [Certification](#-certification)\n \n \n## [↑](#table-of-contents) Initial Access\n* [The Hitchhiker’s Guide To Initial Access](https://posts.specterops.io/the-hitchhikers-guide-to-initial-access-57b66aa80dd6)\n* [How To: Empire’s Cross Platform Office Macro](https://www.blackhillsinfosec.com/empires-cross-platform-office-macro/)\n* [Phishing with PowerPoint](https://www.blackhillsinfosec.com/phishing-with-powerpoint/)\n* [PHISHING WITH EMPIRE](https://enigma0x3.net/2016/03/15/phishing-with-empire/)\n* [Bash Bunny](https://hakshop.com/products/bash-bunny)\n* [OWASP Presentation of Social Engineering - OWASP](https://owasp.org/www-pdf-archive/Presentation_Social_Engineering.pdf)\n* [USB Drop Attacks: The Danger of “Lost And Found” Thumb Drives](https://www.redteamsecure.com/usb-drop-attacks-the-danger-of-lost-and-found-thumb-drives/)\n* [Weaponizing data science for social engineering: Automated E2E spear phishing on Twitter - Defcon 24](https://media.defcon.org/DEF%20CON%2024/DEF%20CON%2024%20presentations/DEF%20CON%2024%20-%20Seymour-Tully-Weaponizing-Data-Science-For-Social-Engineering-WP.pdf)\n* [Cobalt Strike - Spear Phishing documentation](https://www.cobaltstrike.com/help-spear-phish)\n* [Cobalt Strike Blog - What's the go-to phishing technique or exploit?](https://blog.cobaltstrike.com/2014/12/17/whats-the-go-to-phishing-technique-or-exploit/)\n* [Spear phishing with Cobalt Strike - Raphael Mudge](https://www.youtube.com/watch?v=V7UJjVcq2Ao)\n* [EMAIL RECONNAISSANCE AND PHISHING TEMPLATE GENERATION MADE SIMPLE](https://cybersyndicates.com/2016/05/email-reconnaissance-phishing-template-generation-made-simple/)\n* [Phishing for access](http://www.rvrsh3ll.net/blog/phishing/phishing-for-access/)\n* [Excel macros with PowerShell](https://4sysops.com/archives/excel-macros-with-powershell/)\n* [PowerPoint and Custom Actions](https://phishme.com/powerpoint-and-custom-actions/)\n* [Macro-less Code Exec in MSWord](https://sensepost.com/blog/2017/macro-less-code-exec-in-msword/)\n* [Multi-Platform Macro Phishing Payloads](https://medium.com/@malcomvetter/multi-platform-macro-phishing-payloads-3b688e8eff68)\n* [Abusing Microsoft Word Features for Phishing: “subDoc”](https://rhinosecuritylabs.com/research/abusing-microsoft-word-features-phishing-subdoc/)\n* [Phishing Against Protected View](https://enigma0x3.net/2017/07/13/phishing-against-protected-view/)\n* [POWERSHELL EMPIRE STAGERS 1: PHISHING WITH AN OFFICE MACRO AND EVADING AVS](https://fzuckerman.wordpress.com/2016/10/06/powershell-empire-stagers-1-phishing-with-an-office-macro-and-evading-avs/)\n* [The PlugBot: Hardware Botnet Research Project](https://www.redteamsecure.com/the-plugbot-hardware-botnet-research-project/)\n* [Luckystrike: An Evil Office Document Generator](https://www.shellntel.com/blog/2016/9/13/luckystrike-a-database-backed-evil-macro-generator)\n* [The Absurdly Underestimated Dangers of CSV Injection](http://georgemauer.net/2017/10/07/csv-injection.html)\n* [Macroless DOC malware that avoids detection with Yara rule](https://furoner.wordpress.com/2017/10/17/macroless-malware-that-avoids-detection-with-yara-rule/amp/)\n* [Phishing between the app whitelists](https://medium.com/@vivami/phishing-between-the-app-whitelists-1b7dcdab4279)\n* [Executing Metasploit \u0026 Empire Payloads from MS Office Document Properties (part 1 of 2)](https://stealingthe.network/executing-metasploit-empire-payloads-from-ms-office-document-properties-part-1-of-2/)\n* [Executing Metasploit \u0026 Empire Payloads from MS Office Document Properties (part 2 of 2)](https://stealingthe.network/executing-metasploit-empire-payloads-from-ms-office-document-properties-part-2-of-2/)\n* [Social Engineer Portal](https://www.social-engineer.org/)\n* [7 Best social Engineering attack](http://www.darkreading.com/the-7-best-social-engineering-attacks-ever/d/d-id/1319411)\n* [Using Social Engineering Tactics For Big Data Espionage - RSA Conference Europe 2012](https://www.rsaconference.com/writable/presentations/file_upload/das-301_williams_rader.pdf)\n* [USING THE DDE ATTACK WITH POWERSHELL EMPIRE](https://1337red.wordpress.com/using-the-dde-attack-with-powershell-empire/)\n* [Phishing on Twitter - POT](https://www.kitploit.com/2018/02/pot-phishing-on-twitter.html)\n* [Microsoft Office – NTLM Hashes via Frameset](https://pentestlab.blog/2017/12/18/microsoft-office-ntlm-hashes-via-frameset/)\n* [Defense-In-Depth write-up](https://oddvar.moe/2017/09/13/defense-in-depth-writeup/)\n* [Spear Phishing 101](https://blog.inspired-sec.com/archive/2017/05/07/Phishing.html)\n\n \n## [↑](#table-of-contents) Execution \n* [Research on CMSTP.exe,](https://msitpros.com/?p=3960)\n* [Windows oneliners to download remote payload and execute arbitrary code](https://arno0x0x.wordpress.com/2017/11/20/windows-oneliners-to-download-remote-payload-and-execute-arbitrary-code/)\n* [Executing Commands and Bypassing AppLocker with PowerShell Diagnostic Scripts](https://bohops.com/2017/12/02/clickonce-twice-or-thrice-a-technique-for-social-engineering-and-untrusted-command-execution/)\n* [WSH Injection: A Case Study](https://posts.specterops.io/wsh-injection-a-case-study-fd35f79d29dd)\n* [Gscript Dropper](http://lockboxx.blogspot.com/2018/02/intro-to-using-gscript-for-red-teams.html)\n\n \n## [↑](#table-of-contents) Persistence\n* [A View of Persistence](https://rastamouse.me/blog/view-of-persistence/)\n* [hiding registry keys with psreflect](https://posts.specterops.io/hiding-registry-keys-with-psreflect-b18ec5ac8353)\n* [Persistence using RunOnceEx – Hidden from Autoruns.exe](https://oddvar.moe/2018/03/21/persistence-using-runonceex-hidden-from-autoruns-exe/)\n* [Persistence using GlobalFlags in Image File Execution Options – Hidden from Autoruns.exe](https://oddvar.moe/2018/04/10/persistence-using-globalflags-in-image-file-execution-options-hidden-from-autoruns-exe/)\n* [Putting data in Alternate data streams and how to execute it – part 2](https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/)\n* [WMI Persistence with Cobalt Strike](https://blog.inspired-sec.com/archive/2017/01/20/WMI-Persistence.html)\n* [Leveraging INF-SCT Fetch \u0026 Execute Techniques For Bypass, Evasion, \u0026 Persistence](https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/)\n* [Leveraging INF-SCT Fetch \u0026 Execute Techniques For Bypass, Evasion, \u0026 Persistence (Part 2)](https://bohops.com/2018/03/10/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence-part-2/)\n* [Vshadow: Abusing the Volume Shadow Service for Evasion, Persistence, and Active Directory Database Extraction](https://bohops.com/2018/02/10/vshadow-abusing-the-volume-shadow-service-for-evasion-persistence-and-active-directory-database-extraction/)\n \n## [↑](#table-of-contents) Privilege Escalation\n\n### User Account Control Bypass\n* [First entry: Welcome and fileless UAC bypass,](https://winscripting.blog/2017/05/12/first-entry-welcome-and-uac-bypass/)\n* [Exploiting Environment Variables in Scheduled Tasks for UAC Bypass,](https://tyranidslair.blogspot.ru/2017/05/exploiting-environment-variables-in.html)\n* Reading Your Way Around UAC in 3 parts:\n   [Part 1.](https://tyranidslair.blogspot.ru/2017/05/reading-your-way-around-uac-part-1.html)\n   [Part 2.](https://tyranidslair.blogspot.ru/2017/05/reading-your-way-around-uac-part-2.html)\n   [Part 3.](https://tyranidslair.blogspot.ru/2017/05/reading-your-way-around-uac-part-3.html)\n* [Bypassing UAC using App Paths,](https://enigma0x3.net/2017/03/14/bypassing-uac-using-app-paths/)\n* [\"Fileless\" UAC Bypass using sdclt.exe,](https://enigma0x3.net/2017/03/17/fileless-uac-bypass-using-sdclt-exe/)\n* [UAC Bypass or story about three escalations,](https://habrahabr.ru/company/pm/blog/328008/)\n* [\"Fileless\" UAC Bypass Using eventvwr.exe and Registry Hijacking,](https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/)\n* [Bypassing UAC on Windows 10 using Disk Cleanup,](https://enigma0x3.net/2016/07/22/bypassing-uac-on-windows-10-using-disk-cleanup/)\n* [Using IARPUninstallStringLauncher COM interface to bypass UAC,](http://www.freebuf.com/articles/system/116611.html)\n* [Fileless UAC Bypass using sdclt](https://posts.specterops.io/fileless-uac-bypass-using-sdclt-exe-3e9f9ad4e2b3)\n* [Eventvwr File-less UAC Bypass CNA](https://www.mdsec.co.uk/2016/12/cna-eventvwr-uac-bypass/)\n* [Windows 7 UAC whitelist](http://www.pretentiousname.com/misc/win7_uac_whitelist2.html)\n\n### Escalation\n* [Windows Privilege Escalation Checklist](https://github.com/netbiosX/Checklists/blob/master/Windows-Privilege-Escalation.md)\n* [From Patch Tuesday to DA](https://blog.inspired-sec.com/archive/2017/03/17/COM-Moniker-Privesc.html)\n* [A Path for Privilege Escalation](https://blog.cobaltstrike.com/2016/12/08/cobalt-strike-3-6-a-path-for-privilege-escalation/)\n\n## [↑](#table-of-contents) Defense Evasion\n* [Window 10 Device Guard Bypass](https://github.com/tyranid/DeviceGuardBypasses)\n* [App Locker ByPass List](https://github.com/api0cradle/UltimateAppLockerByPassList)\n* [Window Signed Binary](https://github.com/vysec/Windows-SignedBinary)\n* [Bypass Application Whitelisting Script Protections - Regsvr32.exe \u0026 COM Scriptlets (.sct files)](http://subt0x10.blogspot.sg/2017/04/bypass-application-whitelisting-script.html)\n* [Bypassing Application Whitelisting using MSBuild.exe - Device Guard Example and Mitigations](http://subt0x10.blogspot.sg/2017/04/bypassing-application-whitelisting.html)\n* [Empire without powershell](https://bneg.io/2017/07/26/empire-without-powershell-exe/)\n* [Powershell without Powershell to bypass app whitelist](https://www.blackhillsinfosec.com/powershell-without-powershell-how-to-bypass-application-whitelisting-environment-restrictions-av/)\n* [MS Signed mimikatz in just 3 steps](https://github.com/secretsquirrel/SigThief)\n* [Hiding your process from sysinternals](https://riscybusiness.wordpress.com/2017/10/07/hiding-your-process-from-sysinternals/)\n* [code signing certificate cloning attacks and defenses](https://posts.specterops.io/code-signing-certificate-cloning-attacks-and-defenses-6f98657fc6ec)\n* [userland api monitoring and code injection detection](https://0x00sec.org/t/userland-api-monitoring-and-code-injection-detection/5565)\n* [In memory evasion](https://blog.cobaltstrike.com/2018/02/08/in-memory-evasion/)\n* [Bypassing AMSI via COM Server Hijacking](https://posts.specterops.io/bypassing-amsi-via-com-server-hijacking-b8a3354d1aff)\n* [process doppelganging](https://hshrzd.wordpress.com/2017/12/18/process-doppelganging-a-new-way-to-impersonate-a-process/)\n* [Week of Evading Microsoft ATA - Announcement and Day 1 to Day 5](http://www.labofapenetrationtester.com/2017/08/week-of-evading-microsoft-ata-day1.html)\n* [VEIL-EVASION AES ENCRYPTED HTTPKEY REQUEST: SAND-BOX EVASION](https://cybersyndicates.com/2015/06/veil-evasion-aes-encrypted-httpkey-request-module/)\n* [Putting data in Alternate data streams and how to execute it](https://oddvar.moe/2018/01/14/putting-data-in-alternate-data-streams-and-how-to-execute-it/)\n* [AppLocker – Case study – How insecure is it really? – Part 1](https://oddvar.moe/2017/12/13/applocker-case-study-how-insecure-is-it-really-part-1/)\n* [AppLocker – Case study – How insecure is it really? – Part 2](https://oddvar.moe/2017/12/21/applocker-case-study-how-insecure-is-it-really-part-2/)\n* [Harden Windows with AppLocker – based on Case study part 2](https://oddvar.moe/2017/12/13/harden-windows-with-applocker-based-on-case-study-part-1/)\n* [Harden Windows with AppLocker – based on Case study part 2](https://oddvar.moe/2017/12/21/harden-windows-with-applocker-based-on-case-study-part-2/)\n* [Office 365 Safe links bypass](https://oddvar.moe/2018/01/03/office-365-safe-links-bypass/)\n* [Windows Defender Attack Surface Reduction Rules bypass](https://oddvar.moe/2018/03/15/windows-defender-attack-surface-reduction-rules-bypass/)\n* [Bypassing Device guard UMCI using CHM – CVE-2017-8625](https://oddvar.moe/2017/08/13/bypassing-device-guard-umci-using-chm-cve-2017-8625/)\n* [Bypassing Application Whitelisting with BGInfo](https://oddvar.moe/2017/05/18/bypassing-application-whitelisting-with-bginfo/)\n* [Cloning and Hosting Evil Captive Portals using a Wifi PineApple](https://blog.inspired-sec.com/archive/2017/01/10/cloning-captive-portals.html)\n* [https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/](https://bohops.com/2018/01/23/loading-alternate-data-stream-ads-dll-cpl-binaries-to-bypass-applocker/)\n* [Executing Commands and Bypassing AppLocker with PowerShell Diagnostic Scripts](https://bohops.com/2018/01/07/executing-commands-and-bypassing-applocker-with-powershell-diagnostic-scripts/)\n* [mavinject.exe Functionality Deconstructed](https://posts.specterops.io/mavinject-exe-functionality-deconstructed-c29ab2cf5c0e)\n  \n## [↑](#table-of-contents) Credential Access\n* [Windows Access Tokens and Alternate credentials](https://blog.cobaltstrike.com/2015/12/16/windows-access-tokens-and-alternate-credentials/)\n* [Bringing the hashes home with reGeorg \u0026 Empire](https://sensepost.com/blog/2016/bringing-the-hashes-home-with-regeorg-empire/)\n* [Intercepting passwords with Empire and winning](https://sensepost.com/blog/2016/intercepting-passwords-with-empire-and-winning/)\n* [Local Administrator Password Solution (LAPS) Part 1](https://rastamouse.me/blog/laps-pt1/)\n* [Local Administrator Password Solution (LAPS) Part 2](https://rastamouse.me/blog/laps-pt2/)\n* [USING A SCF FILE TO GATHER HASHES](https://1337red.wordpress.com/using-a-scf-file-to-gather-hashes/)\n* [Remote Hash Extraction On Demand Via Host Security Descriptor Modification](https://www.harmj0y.net/blog/)\n* [Offensive Encrypted Data Storage](https://www.harmj0y.net/blog/redteaming/offensive-encrypted-data-storage/)\n* [Practical guide to NTLM Relaying](https://byt3bl33d3r.github.io/practical-guide-to-ntlm-relaying-in-2017-aka-getting-a-foothold-in-under-5-minutes.html)\n* [Dump Clear-Text Passwords for All Admins in the Domain Using Mimikatz DCSync](https://adsecurity.org/?p=2053)\n* [Dumping Domain Password Hashes](https://pentestlab.blog/2018/07/04/dumping-domain-password-hashes/)\n  \n## [↑](#table-of-contents) Discovery\n* [Red Team Operating in a Modern Environment](https://www.owasp.org/images/4/4b/Red_Team_Operating_in_a_Modern_Environment.pdf)\n* [My First Go with BloodHound](https://blog.cobaltstrike.com/2016/12/14/my-first-go-with-bloodhound/)\n* [Introducing BloodHound](https://wald0.com/?p=68)\n* [A Red Teamer’s Guide to GPOs and OUs](https://wald0.com/?p=179)\n* [Automated Derivative Administrator Search](https://wald0.com/?p=14)\n* [A Pentester’s Guide to Group Scoping](https://www.harmj0y.net/blog/activedirectory/a-pentesters-guide-to-group-scoping/)\n* [Local Group Enumeration](https://www.harmj0y.net/blog/redteaming/local-group-enumeration/)\n* [The PowerView PowerUsage Series #1 - Mass User Profile Enumeration](http://www.harmj0y.net/blog/powershell/the-powerview-powerusage-series-1/)\n* [The PowerView PowerUsage Series #2 – Mapping Computer Shortnames With the Global Catalog](http://www.harmj0y.net/blog/powershell/the-powerview-powerusage-series-2/)\n* [The PowerView PowerUsage Series #3 – Enumerating GPO edit rights in a foreign domain](http://www.harmj0y.net/blog/powershell/the-powerview-powerusage-series-3/)\n* [The PowerView PowerUsage Series #4 – Finding cross-trust ACEs](http://www.harmj0y.net/blog/powershell/the-powerview-powerusage-series-3/)\n* [Aggressor PowerView](http://threat.tevora.com/aggressor-powerview/)\n* [Lay of the Land with BloodHound](http://threat.tevora.com/lay-of-the-land-with-bloodhound/)\n* [Scanning for Active Directory Privileges \u0026 Privileged Accounts](https://adsecurity.org/?p=3658)\n* [Microsoft LAPS Security \u0026 Active Directory LAPS Configuration Recon](https://adsecurity.org/?p=3164)\n* [Trust Direction: An Enabler for Active Directory Enumeration and Trust Exploitation](https://bohops.com/2017/12/02/trust-direction-an-enabler-for-active-directory-enumeration-and-trust-exploitation/)\n* [SPN Discovery](https://pentestlab.blog/2018/06/04/spn-discovery/)\n   \n## [↑](#table-of-contents) Lateral Movement \n\n* [A Citrix Story](https://rastamouse.me/blog/a-citrix-story/)\n* [Jumping Network Segregation with RDP](https://rastamouse.me/blog/rdp-jump-boxes/)\n* [Pass hash pass ticket no pain](http://resources.infosecinstitute.com/pass-hash-pass-ticket-no-pain/)\n* [Abusing DNSAdmins privilege for escalation in Active Directory](http://www.labofapenetrationtester.com/2017/05/abusing-dnsadmins-privilege-for-escalation-in-active-directory.html)\n* [Using SQL Server for attacking a Forest Trust](http://www.labofapenetrationtester.com/2017/03/using-sql-server-for-attacking-forest-trust.html)\n* [Extending BloodHound for Red Teamers](https://www.youtube.com/watch?v=Pn7GWRXfgeI)\n* [OPSEC Considerations for beacon commands](https://blog.cobaltstrike.com/2017/06/23/opsec-considerations-for-beacon-commands/)\n* [My First Go with BloodHound](https://blog.cobaltstrike.com/2016/12/14/my-first-go-with-bloodhound/)\n* [Kerberos Party Tricks: Weaponizing Kerberos Protocol Flaws](http://www.exumbraops.com/blog/2016/6/1/kerberos-party-tricks-weaponizing-kerberos-protocol-flaws)\n* [Lateral movement using excel application and dcom](https://enigma0x3.net/2017/09/11/lateral-movement-using-excel-application-and-dcom/)\n* [Lay of the Land with BloodHound](http://threat.tevora.com/lay-of-the-land-with-bloodhound/)\n* [The Most Dangerous User Right You (Probably) Have Never Heard Of](https://www.harmj0y.net/blog/activedirectory/the-most-dangerous-user-right-you-probably-have-never-heard-of/)\n* [Agentless Post Exploitation](https://blog.cobaltstrike.com/2016/11/03/agentless-post-exploitation/)\n* [A Guide to Attacking Domain Trusts](https://www.harmj0y.net/blog/redteaming/a-guide-to-attacking-domain-trusts/)   \n* [Pass-the-Hash Is Dead: Long Live LocalAccountTokenFilterPolicy](https://www.harmj0y.net/blog/redteaming/pass-the-hash-is-dead-long-live-localaccounttokenfilterpolicy/)\n* [Targeted Kerberoasting](https://www.harmj0y.net/blog/activedirectory/targeted-kerberoasting/)\n* [Kerberoasting Without Mimikatz](https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/)\n* [Abusing GPO Permissions](https://www.harmj0y.net/blog/redteaming/abusing-gpo-permissions/)\n* [Abusing Active Directory Permissions with PowerView](https://www.harmj0y.net/blog/redteaming/abusing-active-directory-permissions-with-powerview/)\n* [Roasting AS-REPs](https://www.harmj0y.net/blog/activedirectory/roasting-as-reps/)\n* [Getting the goods with CrackMapExec: Part 1](https://byt3bl33d3r.github.io/getting-the-goods-with-crackmapexec-part-1.html)\n* [Getting the goods with CrackMapExec: Part 2](https://byt3bl33d3r.github.io/getting-the-goods-with-crackmapexec-part-2.html)\n* [DiskShadow: The Return of VSS Evasion, Persistence, and Active Directory Database Extraction](https://bohops.com/2018/03/26/diskshadow-the-return-of-vss-evasion-persistence-and-active-directory-database-extraction/)\n* [Abusing Exported Functions and Exposed DCOM Interfaces for Pass-Thru Command Execution and Lateral Movement](https://bohops.com/2018/03/17/abusing-exported-functions-and-exposed-dcom-interfaces-for-pass-thru-command-execution-and-lateral-movement/)\n* [a guide to attacking domain trusts](https://posts.specterops.io/a-guide-to-attacking-domain-trusts-971e52cb2944)\n* [Outlook Home Page – Another Ruler Vector](https://sensepost.com/blog/2017/outlook-home-page-another-ruler-vector/)\n* [Outlook Forms and Shells](https://sensepost.com/blog/2017/outlook-forms-and-shells/)\n* [Abusing the COM Registry Structure: CLSID, LocalServer32, \u0026 InprocServer32](https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/)\n* [LethalHTA - A new lateral movement technique using DCOM and HTA](https://codewhitesec.blogspot.com/2018/07/lethalhta.html)\n* [Abusing DCOM For Yet Another Lateral Movement Technique](https://bohops.com/2018/04/28/abusing-dcom-for-yet-another-lateral-movement-technique/)\n   \n## [↑](#table-of-contents) Collection  \n* [Accessing clipboard from the lock screen in Windows 10 Part 1](https://oddvar.moe/2017/01/24/accessing-clipboard-from-the-lock-screen-in-windows-10/)\n* [Accessing clipboard from the lock screen in Windows 10 Part 2](https://oddvar.moe/2017/01/27/access-clipboard-from-lock-screen-in-windows-10-2/)\n\n  \n   \n## [↑](#table-of-contents) Exfiltration\n* [DNS Data exfiltration — What is this and How to use?](https://blog.fosec.vn/dns-data-exfiltration-what-is-this-and-how-to-use-2f6c69998822)\n* [DNS Tunnelling](http://resources.infosecinstitute.com/dns-tunnelling/)\n* [sg1: swiss army knife for data encryption, exfiltration \u0026 covert communication](https://securityonline.info/sg1-swiss-army-knife-for-data-encryption-exfiltration-covert-communication/?utm_source=ReviveOldPost\u0026utm_medium=social\u0026utm_campaign=ReviveOldPost)\n* [Data Exfiltration over DNS Request Covert Channel: DNSExfiltrator](https://n0where.net/data-exfiltration-over-dns-request-covert-channel-dnsexfiltrator)\n* [DET (extensible) Data Exfiltration Toolkit](https://github.com/PaulSec/DET)\n* [Data Exfiltration via Formula Injection Part1](https://www.notsosecure.com/data-exfiltration-formula-injection/)\n\n\n## [↑](#table-of-contents) Command and Control\n\n### Domain Fronting\n* [Empre Domain Fronting](https://www.xorrior.com/Empire-Domain-Fronting/)\n* [Escape and Evasion Egressing Restricted Networks - Tom Steele and Chris Patten](https://www.optiv.com/blog/escape-and-evasion-egressing-restricted-networks)\n* [Finding Frontable Domain](https://github.com/rvrsh3ll/FindFrontableDomains)\n* [TOR Fronting – Utilising Hidden Services for Privacy](https://www.mdsec.co.uk/2017/02/tor-fronting-utilising-hidden-services-for-privacy/)\n* [Simple domain fronting PoC with GAE C2 server](https://www.securityartwork.es/2017/01/31/simple-domain-fronting-poc-with-gae-c2-server/)\n* [Domain Fronting Via Cloudfront Alternate Domains](https://www.mdsec.co.uk/2017/02/domain-fronting-via-cloudfront-alternate-domains/)\n* [Finding Domain frontable Azure domains - thoth / Fionnbharr (@a_profligate)](https://theobsidiantower.com/2017/07/24/d0a7cfceedc42bdf3a36f2926bd52863ef28befc.html)\n* [Google Groups: Blog post on finding 2000+ Azure domains using Censys](https://groups.google.com/forum/#!topic/traffic-obf/7ygIXCPebwQ)\n* [Red Team Insights on HTTPS Domain Fronting Google Hosts Using Cobalt Strike](https://www.cyberark.com/threat-research-blog/red-team-insights-https-domain-fronting-google-hosts-using-cobalt-strike/)\n* [SSL Domain Fronting 101](http://www.rvrsh3ll.net/blog/offensive/ssl-domain-fronting-101/)\n* [How I Identified 93k Domain-Frontable CloudFront Domains](https://www.peew.pw/blog/2018/2/22/how-i-identified-93k-domain-frontable-cloudfront-domains)\n* [Validated CloudFront SSL Domains](https://medium.com/@vysec.private/validated-cloudfront-ssl-domains-27895822cea3)\n* [CloudFront Hijacking](https://www.mindpointgroup.com/blog/pen-test/cloudfront-hijacking/)\n* [CloudFrunt GitHub Repo](https://github.com/MindPointGroup/cloudfrunt)\n\n### Connection Proxy\n* [Redirecting Cobalt Strike DNS Beacons](http://www.rvrsh3ll.net/blog/offensive/redirecting-cobalt-strike-dns-beacons/)\n* [Apache2Mod Rewrite Setup](https://github.com/n0pe-sled/Apache2-Mod-Rewrite-Setup)\n* [Cobalt Strike HTTP C2 Redirectors with Apache mod_rewrite](https://bluescreenofjeff.com/2016-06-28-cobalt-strike-http-c2-redirectors-with-apache-mod_rewrite/)\n* [High-reputation Redirectors and Domain Fronting](https://blog.cobaltstrike.com/2017/02/06/high-reputation-redirectors-and-domain-fronting/)\n* [Cloud-based Redirectors for Distributed Hacking](https://blog.cobaltstrike.com/2014/01/14/cloud-based-redirectors-for-distributed-hacking/)\n* [Combatting Incident Responders with Apache mod_rewrite](https://bluescreenofjeff.com/2016-04-12-combatting-incident-responders-with-apache-mod_rewrite/)\n* [Operating System Based Redirection with Apache mod_rewrite](https://bluescreenofjeff.com/2016-04-05-operating-system-based-redirection-with-apache-mod_rewrite/)\n* [Invalid URI Redirection with Apache mod_rewrite](https://bluescreenofjeff.com/2016-03-29-invalid-uri-redirection-with-apache-mod_rewrite/)\n* [Strengthen Your Phishing with Apache mod_rewrite and Mobile User Redirection](https://bluescreenofjeff.com/2016-03-22-strengthen-your-phishing-with-apache-mod_rewrite-and-mobile-user-redirection/)\n* [mod_rewrite rule to evade vendor sandboxes](https://gist.github.com/curi0usJack/971385e8334e189d93a6cb4671238b10)\n* [Expire Phishing Links with Apache RewriteMap](https://bluescreenofjeff.com/2016-04-19-expire-phishing-links-with-apache-rewritemap/)\n* [Serving random payloads with NGINX](https://gist.github.com/jivoi/a33ace2e25515a31aa2ffbae246d98c9)\n* [Mod_Rewrite Automatic Setup](https://blog.inspired-sec.com/archive/2017/04/17/Mod-Rewrite-Automatic-Setup.html)\n* [Hybrid Cobalt Strike Redirectors](https://zachgrace.com/2018/02/20/cobalt_strike_redirectors.html)\n* [Expand Your Horizon Red Team – Modern SAAS C2](https://cybersyndicates.com/2017/04/expand-your-horizon-red-team/)\n* [RTOps: Automating Redirector Deployment With Ansible](http://threat.tevora.com/automating-redirector-deployment-with-ansible/)\n\n### Web Services\n* [C2 with Dropbox](https://pentestlab.blog/2017/08/29/command-and-control-dropbox/)\n* [C2 with gmail](https://pentestlab.blog/2017/08/03/command-and-control-gmail/)\n* [C2 with twitter](https://pentestlab.blog/2017/09/26/command-and-control-twitter/)\n* [Office 365 for Cobalt Strike C2](https://labs.mwrinfosecurity.com/blog/tasking-office-365-for-cobalt-strike-c2/)\n* [Red Team Insights on HTTPS Domain Fronting Google Hosts Using Cobalt Strike](https://www.cyberark.com/threat-research-blog/red-team-insights-https-domain-fronting-google-hosts-using-cobalt-strike/)\n* [A stealthy Python based Windows backdoor that uses Github as a C\u0026C server](http://securityblog.gr/4434/a-stealthy-python-based-windows-backdoor-that-uses-github-as-a-cc-server/)\n* [External C2 (Third-Party Command and Control)](https://www.cobaltstrike.com/help-externalc2)\n* [Cobalt Strike over external C2 – beacon home in the most obscure ways](https://outflank.nl/blog/2017/09/17/blogpost-cobalt-strike-over-external-c2-beacon-home-in-the-most-obscure-ways/)\n* [External C2 for Cobalt Strike](https://github.com/ryhanson/ExternalC2/)\n* [External C2 framework for Cobalt Strike](http://www.insomniacsecurity.com/2018/01/11/externalc2.html)\n* [External C2 framework - GitHub Repo](https://github.com/Und3rf10w/external_c2_framework)\n* [Hiding in the Cloud: Cobalt Strike Beacon C2 using Amazon APIs](https://github.com/Und3rf10w/external_c2_framework)\n* [Exploring Cobalt Strike's ExternalC2 framework](https://blog.xpnsec.com/exploring-cobalt-strikes-externalc2-framework/)\n\n### Application Layer Protocol\n* [C2 WebSocket](https://pentestlab.blog/2017/12/06/command-and-control-websocket/)\n* [C2 WMI](https://pentestlab.blog/2017/11/20/command-and-control-wmi/)\n* [C2 Website](https://pentestlab.blog/2017/11/14/command-and-control-website/)\n* [C2 Image](https://pentestlab.blog/2018/01/02/command-and-control-images/)\n* [C2 Javascript](https://pentestlab.blog/2018/01/08/command-and-control-javascript/)\n* [C2 WebInterface](https://pentestlab.blog/2018/01/03/command-and-control-web-interface/)\n* [C2 with DNS](https://pentestlab.blog/2017/09/06/command-and-control-dns/)\n* [C2 with https](https://pentestlab.blog/2017/10/04/command-and-control-https/)\n* [C2 with webdav](https://pentestlab.blog/2017/09/12/command-and-control-webdav/)\n* [Introducing Merlin — A cross-platform post-exploitation HTTP/2 Command \u0026 Control Tool](https://medium.com/@Ne0nd0g/introducing-merlin-645da3c635a)\n* [InternetExplorer.Application for C2](https://adapt-and-attack.com/2017/12/19/internetexplorer-application-for-c2/)\n\n### Infrastructure\n* [Automated Red Team Infrastructure Deployment with Terraform - Part 1](https://rastamouse.me/blog/terraform-pt1/)\n* [Automated Red Team Infrastructure Deployment with Terraform - Part 2](https://rastamouse.me/blog/terraform-pt2/)\n* [Red Team Infrastructure - AWS Encrypted EBS](https://rastamouse.me/blog/encrypted-ebs/)\n* [6 RED TEAM INFRASTRUCTURE TIPS](https://cybersyndicates.com/2016/11/top-red-team-tips/)\n* [How to Build a C2 Infrastructure with Digital Ocean – Part 1](https://www.blackhillsinfosec.com/build-c2-infrastructure-digital-ocean-part-1/)\n* [Infrastructure for Ongoing Red Team Operations](https://blog.cobaltstrike.com/2014/09/09/infrastructure-for-ongoing-red-team-operations/)\n* [Attack Infrastructure Log Aggregation and Monitoring](https://posts.specterops.io/attack-infrastructure-log-aggregation-and-monitoring-345e4173044e)\n* [Randomized Malleable C2 Profiles Made Easy](https://bluescreenofjeff.com/2017-08-30-randomized-malleable-c2-profiles-made-easy/)\n* [Migrating Your infrastructure](https://blog.cobaltstrike.com/2015/10/21/migrating-your-infrastructure/)\n* [ICMP C2](https://pentestlab.blog/2017/07/28/command-and-control-icmp/)\n* [Using WebDAV features as a covert channel](https://arno0x0x.wordpress.com/2017/09/07/using-webdav-features-as-a-covert-channel/)\n* [Safe Red Team Infrastructure](https://medium.com/@malcomvetter/safe-red-team-infrastructure-c5d6a0f13fac)\n* [EGRESSING BLUECOAT WITH COBALTSTIKE \u0026 LET'S ENCRYPT](https://cybersyndicates.com/2016/12/egressing-bluecoat-with-cobaltstike-letsencrypt/)\n* [Command and Control Using Active Directory](http://www.harmj0y.net/blog/powershell/command-and-control-using-active-directory/)\n* [A Vision for Distributed Red Team Operations](https://blog.cobaltstrike.com/2013/02/12/a-vision-for-distributed-red-team-operations/)\n* [Designing Effective Covert Red Team Attack Infrastructure](https://bluescreenofjeff.com/2017-12-05-designing-effective-covert-red-team-attack-infrastructure/)\n* [Serving Random Payloads with Apache mod_rewrite](https://bluescreenofjeff.com/2017-06-13-serving-random-payloads-with-apache-mod_rewrite/)\n* [Mail Servers Made Easy](https://blog.inspired-sec.com/archive/2017/02/14/Mail-Server-Setup.html)\n* [Securing your Empire C2 with Apache mod_rewrite](https://thevivi.net/2017/11/03/securing-your-empire-c2-with-apache-mod_rewrite/)\n* [Automating Gophish Releases With Ansible and Docker](https://jordan-wright.com/blog/post/2018-02-04-automating-gophish-releases/)\n* [How to Write Malleable C2 Profiles for Cobalt Strike](https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/)\n* [How to Make Communication Profiles for Empire](https://bluescreenofjeff.com/2017-03-01-how-to-make-communication-profiles-for-empire/)\n* [A Brave New World: Malleable C2](http://www.harmj0y.net/blog/redteaming/a-brave-new-world-malleable-c2/)\n* [Malleable Command and Control](https://www.cobaltstrike.com/help-malleable-c2)\n\n\n## [↑](#table-of-contents) Embedded and Peripheral Devices Hacking\n* [Gettting in with the Proxmark3 \u0026 ProxBrute](https://www.trustwave.com/Resources/SpiderLabs-Blog/Getting-in-with-the-Proxmark-3-and-ProxBrute/)\n* [Practical Guide to RFID Badge copying](https://blog.nviso.be/2017/01/11/a-practical-guide-to-rfid-badge-copying/)\n* [Contents of a Physical Pentester Backpack](https://www.tunnelsup.com/contents-of-a-physical-pen-testers-backpack/)\n* [MagSpoof - credit card/magstripe spoofer](https://github.com/samyk/magspoof)\n* [Wireless Keyboard Sniffer](https://samy.pl/keysweeper/)\n* [RFID Hacking with The Proxmark 3](https://blog.kchung.co/rfid-hacking-with-the-proxmark-3/)\n* [Swiss Army Knife for RFID](https://www.cs.bham.ac.uk/~garciaf/publications/Tutorial_Proxmark_the_Swiss_Army_Knife_for_RFID_Security_Research-RFIDSec12.pdf)\n* [Exploring NFC Attack Surface](https://media.blackhat.com/bh-us-12/Briefings/C_Miller/BH_US_12_Miller_NFC_attack_surface_WP.pdf)\n* [Outsmarting smartcards](http://gerhard.dekoninggans.nl/documents/publications/dekoninggans.phd.thesis.pdf)\n* [Reverse engineering HID iClass Master keys](https://blog.kchung.co/reverse-engineering-hid-iclass-master-keys/)\n* [Android Open Pwn Project (AOPP)](https://www.pwnieexpress.com/aopp)\n\n\n## [↑](#table-of-contents) Misc\n* [Red Tips of Vysec](https://github.com/vysec/RedTips)\n* [Cobalt Strike Tips for 2016 ccde red teams](https://blog.cobaltstrike.com/2016/02/23/cobalt-strike-tips-for-2016-ccdc-red-teams/)\n* [Models for Red Team Operations](https://blog.cobaltstrike.com/2015/07/09/models-for-red-team-operations/)\n* [Planning a Red Team exercise](https://github.com/magoo/redteam-plan)\n* [Raphael Mudge - Dirty Red Team tricks](https://www.youtube.com/watch?v=oclbbqvawQg)\n* [introducing the adversary resilience methodology part 1](https://posts.specterops.io/introducing-the-adversary-resilience-methodology-part-one-e38e06ffd604)\n* [introducing the adversary resilience methodology part 2](https://posts.specterops.io/introducing-the-adversary-resilience-methodology-part-two-279a1ed7863d)\n* [Responsible red team](https://medium.com/@malcomvetter/responsible-red-teams-1c6209fd43cc)\n* [Red Teaming for Pacific Rim CCDC 2017](https://bluescreenofjeff.com/2017-05-02-red-teaming-for-pacific-rim-ccdc-2017/)\n* [How I Prepared to Red Team at PRCCDC 2015](https://bluescreenofjeff.com/2015-04-15-how-i-prepared-to-red-team-at-prccdc-2015/)\n* [Red Teaming for Pacific Rim CCDC 2016](https://bluescreenofjeff.com/2016-05-24-pacific-rim-ccdc_2016/)\n* [Responsible Red Teams](https://medium.com/@malcomvetter/responsible-red-teams-1c6209fd43cc)\n* [Awesome-CobaltStrike](https://github.com/zer0yu/Awesome-CobaltStrike)\n* RedTeaming from Zero to One [Part-1](https://payatu.com/redteaming-from-zero-to-one-part-1) [Part-2](https://payatu.com/redteaming-zero-one-part-2)\n\n## [↑](#table-of-contents) RedTeam Gadgets\n#### Network Implants\n* [LAN Tap Pro](https://hackerwarehouse.com/product/lan-tap-pro/)\n* [LAN Turtle](https://hakshop.com/collections/network-implants/products/lan-turtle)\n* [Bash Bunny](https://hakshop.com/collections/physical-access/products/bash-bunny)\n* [Key Croc](https://shop.hak5.org/collections/sale/products/key-croc)\n* [Packet Squirrel](https://hakshop.com/products/packet-squirrel)\n* [Shark Jack](https://shop.hak5.org/collections/sale/products/shark-jack)\n#### Wifi Auditing\n* [WiFi Pineapple](https://hakshop.com/products/wifi-pineapple)\n* [Alpha Long range Wireless USB](https://hackerwarehouse.com/product/alfa-802-11bgn-long-range-usb-wireless-adapter/)\n* [Wifi-Deauth Monster](https://www.tindie.com/products/lspoplove/dstike-wifi-deauther-monster/)\n* [Crazy PA](https://www.amazon.com/gp/product/B00VYA3A2U/ref=as_li_tl)\n* [Signal Owl](https://shop.hak5.org/products/signal-owl)\n#### IoT\n* [BLE Key](https://hackerwarehouse.com/product/blekey/)\n* [Proxmark3](https://hackerwarehouse.com/product/proxmark3-kit/)\n* [Zigbee Sniffer](https://www.attify-store.com/products/zigbee-sniffing-tool-atmel-rzraven)\n* [Attify IoT Exploit kit](https://www.attify-store.com/collections/frontpage/products/jtag-exploitation-kit-with-lab-manual)\n#### Software Defined Radio - SDR\n* [HackRF One Bundle](https://hackerwarehouse.com/product/hackrf-one-kit/)\n* [RTL-SDR](https://hackerwarehouse.com/product/rtlsdr/)\n* [YARD stick one Bundle](https://hackerwarehouse.com/product/yard-stick-one-kit/)\n* [Ubertooth](https://hackerwarehouse.com/product/ubertooth-one/)\n#### Misc\n* [Key Grabber](https://hackerwarehouse.com/product/keygrabber/)\n* [Magspoof](https://store.ryscc.com/products/magspoof%20)\n* [Poison tap](https://samy.pl/poisontap/)\n* [keysweeper](https://samy.pl/keysweeper/)\n* [USB Rubber Ducky](https://hakshop.com/collections/physical-access/products/usb-rubber-ducky-deluxe)\n* [Screen Crab](https://shop.hak5.org/collections/sale/products/screen-crab)\n* [O.MG Cable](https://shop.hak5.org/collections/featured-makers/products/o-mg-cable)\n* [Keysy](https://shop.hak5.org/collections/featured-makers/products/keysy)\n* [Dorothy for Okta SSO](https://github.com/elastic/dorothy)\n\n## [↑](#table-of-contents) Ebooks\n* [Next Generation Red Teaming](https://www.amazon.com/Next-Generation-Teaming-Henry-Dalziel/dp/0128041714)\n* [Targeted Cyber Attack](https://www.amazon.com/Targeted-Cyber-Attacks-Multi-staged-Exploits/dp/0128006048)\n* [Advanced Penetration Testing: Hacking the World's Most Secure Networks](https://www.amazon.com/Advanced-Penetration-Testing-Hacking-Networks/dp/1119367689)\n* [Social Engineers' Playbook Practical Pretexting](https://www.amazon.com/Social-Engineers-Playbook-Practical-Pretexting/dp/0692306617/)\n* [The Hacker Playbook 3: Practical Guide To Penetration Testing](https://www.amazon.com/Hacker-Playbook-Practical-Penetration-Testing-ebook/dp/B07CSPFYZ2)\n* [How to Hack Like a PORNSTAR: A step by step process for breaking into a BANK ](https://www.amazon.com/How-Hack-Like-PORNSTAR-breaking-ebook/dp/B01MTDLGQQ)\n\n## [↑](#table-of-contents) Training ( Free )\n* [Tradecraft - a course on red team operations](https://www.youtube.com/watch?v=IRpS7oZ3z0o\u0026list=PL9HO6M_MU2nesxSmhJjEvwLhUoHPHmXvz)\n* [Advanced Threat Tactics Course \u0026 Notes](https://blog.cobaltstrike.com/2015/09/30/advanced-threat-tactics-course-and-notes/)\n* [FireEye - a whiteboard session on red team operations](https://www.fireeye.com/services/red-team-assessments/red-team-operations-video-training.html)\n\n#### Home Lab\n* [Building an Effective Active Directory Lab Environment for Testing](https://adsecurity.org/?p=2653)\n* [Setting up DetectionLab](https://www.c2.lol/articles/setting-up-chris-longs-detectionlab)\n* [vulnerable-AD - Script to make your home AD Lab vulnerable](https://github.com/WazeHell/vulnerable-AD)\n\n## [↑](#table-of-contents) Certification\n* [CREST Certified Simulated Attack Specialist](http://www.crest-approved.org/examination/certified-simulated-attack-specialist/)\n* [CREST Certified Simulated Attack Manager](http://www.crest-approved.org/examination/certified-simulated-attack-manager/)\n* [SEC564: Red Team Operations and Threat Emulation](https://www.sans.org/course/red-team-operations-and-threat-emulation)\n* [ELearn Security Penetration Testing eXtreme](https://www.elearnsecurity.com/course/penetration_testing_extreme/)\n* [Certified Red Team Professional](https://www.pentesteracademy.com/activedirectorylab)\n* [Certified Red Teaming Expert](https://www.pentesteracademy.com/redteamlab)\n* [PentesterAcademy Certified Enterprise Security Specialist (PACES)](https://www.pentesteracademy.com/gcb)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyeyintminthuhtut%2FAwesome-Red-Teaming","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fyeyintminthuhtut%2FAwesome-Red-Teaming","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fyeyintminthuhtut%2FAwesome-Red-Teaming/lists"}