This repository contains cutting-edge open-source security tools (OST) that will help you during adversary simulation and as information intended for threat hunter can make detection and prevention control easier. The list of tools below that could be potentially misused by threat actors such as APT and Human-Operated Ransomware (HumOR). If you want to contribute to this list send me a pull request. Table of Contents Reconnaissance Initial Access Delivery Situational Awareness Credential Dumping Privilege Escalation Defense Evasion Persistence Lateral Movement Exfiltration Miscellaneous
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Interactive online malware sandbox for real-time analysis and threat intelligence
Advanced command and control tool for red teaming and adversary simulation with extensive features and evasion capabilities.
SauronEye helps in identifying files containing sensitive data such as passwords through targeted directory searches.
A command that builds and executes command lines from standard input, allowing for the execution of commands with multiple arguments.
BeEF is a specialized penetration testing tool for exploiting web browser vulnerabilities to assess security.
Kali Linux is a specialized Linux distribution for cybersecurity professionals, focusing on penetration testing and security auditing.
SharpPrinter enables efficient discovery of network printers for security and management purposes.
Generates randomized C2 profiles for Cobalt Strike to evade detection.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.